We got admin access to Baseten's production GitHub
21–30 of 202 posts
Re: We got admin access to Baseten's production GitHub
#22Kudos for Strix to find it, and especially with how it chose to disclose and report it.
Re: We got admin access to Baseten's production GitHub
#23Secret scanning would not have caught it either. It reads repositories, not image layers sitting in a registry on your own subdomain, so the coverage stopped exactly where the leak was.
Re: We got admin access to Baseten's production GitHub
#24Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.") From TFA: > That token…
That said, the whole compliance industry is a joke.
Re: We got admin access to Baseten's production GitHub
#25> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…
Re: We got admin access to Baseten's production GitHub
#26And the agent found the token in Docker build history after finding a Baseten image repository.
I wonder how many of these kinds of agent-driven security exploits we're not hearing about these days (i.e. driven by bad actors), worrying.
Re: We got admin access to Baseten's production GitHub
#27I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.
Re: We got admin access to Baseten's production GitHub
#28Re: We got admin access to Baseten's production GitHub
#29> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
Honestly I would have held out for a (hard to get) hardcover copy of Inference Engineering.