2025 Tailscale — MDM auth keys logged in 1.84.0
Data compromised
MDM auth keys (internal log exposure)
Technical writeup
macOS/iOS v1.84.0: MDM-provided config values including auth keys (for auto node registration) logged and uploaded to Tailscale log server. Logs only accessible to employees; no external leak. Fixed in 1.86.4 (redacts auth keys). Reusable keys could have been abused if stolen by employee.
Root cause
Logging of sensitive config; no redaction