Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

How were the credentials stolen?


Read from the ENV variables of a container.


And someone was stupid enough to put a reusable tailscale auth key in there.


I'm willing to bet that 95% of people using tailscale for CI have a 90 day (max days) ephemeral, reusable auth key somewhere in their setup.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: