We got admin access to Baseten's production GitHub
1–10 of 202 posts
Re: We got admin access to Baseten's production GitHub
#2Re: We got admin access to Baseten's production GitHub
#3Now if only we knew if the stonks would go up or down (due to global turmoil) before I throw my savings at the SPY
Re: We got admin access to Baseten's production GitHub
#4> July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions.
> July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked.
> July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the token. He also asked us to securely delete the images we'd pulled.
> July 14, 5:05 PM: We confirmed deletion and sent over two lower-severity findings from the same scan.
> July 17: Baseten closed out the remaining findings.
> September: We let Baseten know we planned to disclose the finding publicly and sent them a draft of this post.
They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug.
well done all around. i think my only open question is what default security boundaries should all vibecoded internal agents follow as a learning we can take from this
Re: We got admin access to Baseten's production GitHub
#5We really are entering the AI economy. Now if only we knew if the stonks would go up or down (due to global turmoil) before I throw my savings at the SPY
Re: We got admin access to Baseten's production GitHub
#6Re: We got admin access to Baseten's production GitHub
#71. A start up is validating a service provider to ensure that they are secure enough so that they can trust them before signing up for their service
2. The service provider is already trusted by so many big name companies who handed over their data, the customers data to them
Should it not be other way around?
On a different note, the finding is not just one off absolute, rather its a symptom which points to certain experience and expertise level for security practices. To be fair its hard to blame the start up folks, they are running against time and cutting corners is somewhat critical for survival for their business
Re: We got admin access to Baseten's production GitHub
#8Re: We got admin access to Baseten's production GitHub
#9> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
Re: We got admin access to Baseten's production GitHub
#10i quite liked using strix. last time i tried it, deepseek was a mess and bloated the context with nonsense. that was ~5 months ago, i wonder how it performs now