Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

11–20 of 202 posts

Re: We got admin access to Baseten's production GitHub

#11

This sounds interesting and twisted in some sense 1. A start up is validating a service provider to ensure that they are secure enough so that they can trust them before signing up for their service 2. The service provider is already trusted by so many big name companies who handed over their data, the customers data to them Should it not be other way around? On a different note, the finding is not just one off absol…

Yeah... interesting paradigm

Re: We got admin access to Baseten's production GitHub

#12
post #8

That is great marketing for strix, pretty bad for baseten. I don't think someone can have a better story to advertise their own security product. Did not know about strix but I am going to look it up now. Might add it to my stack.

Let us know if you have any feedback!

Re: We got admin access to Baseten's production GitHub

#13
Yeah I have seen this issue a few times. If you use Docker build arguments that way add `--provenance=false` to get rid of all that build metadata. Build secrets are still better since they allow you to scope the secret inside of the Dockerfile. Also, the metadata can be useful to inspect images.

Re: We got admin access to Baseten's production GitHub

#14

Yeah I have seen this issue a few times. If you use Docker build arguments that way add `--provenance=false` to get rid of all that build metadata. Build secrets are still better since they allow you to scope the secret inside of the Dockerfile. Also, the metadata can be useful to inspect images.

Yeah honestly I wasn't too familiar with this beforehand but now have a sense of the best practices going forward

Re: We got admin access to Baseten's production GitHub

#15
post #6

i quite liked using strix. last time i tried it, deepseek was a mess and bloated the context with nonsense. that was ~5 months ago, i wonder how it performs now

We've made a lot of awesome changes recently, would love any feedback on the latest version :)

Re: We got admin access to Baseten's production GitHub

#16
post #4

> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…

Good in terms of prompt communication and fix. Absurdly bad in terms of reward.

Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org?

This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.

Re: We got admin access to Baseten's production GitHub

#17
Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.")

From TFA:

> That token had admin and push access to Baseten's main product repo, the GitOps repo that drives their clusters, and their Homebrew tap, plus read/write access to other private repositories including specific repos per customers.

> The image build dated to March 2023, and the token still worked when we found it in July 2026.

What are the legal implications here?

Re: We got admin access to Baseten's production GitHub

#19
post #8

That is great marketing for strix, pretty bad for baseten. I don't think someone can have a better story to advertise their own security product. Did not know about strix but I am going to look it up now. Might add it to my stack.

Let us know if you have any feedback!

If I enter an address to "Start testing", I expect at least a preview of the report rather than being dumped on the signup page.

Re: We got admin access to Baseten's production GitHub

#20

Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.") From TFA: > That token…

Unless github had regulated data, unlikely, the legal implications are few. Document the issue, remediate and no findings on the next audit. Done.
Post reply on HN