Earlier quoted context omitted.
Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…
[flagged]
We got admin access to Baseten's production GitHub
51–60 of 202 posts
Re: We got admin access to Baseten's production GitHub
#52> We build Strix, an autonomous hacking again. > But... we're a security company. > So... we pointed Strix at *.baseten.co and let it run without credentials or source code. lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws
I feel like people like you are more of a lawyers wet dream, in that they'll happily litigate a frivolous case for you while billing you hourly.
Re: We got admin access to Baseten's production GitHub
#53Earlier quoted context omitted.
Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…
Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…
Re: We got admin access to Baseten's production GitHub
#54Re: We got admin access to Baseten's production GitHub
#55> We build Strix, an autonomous hacking again. > But... we're a security company. > So... we pointed Strix at *.baseten.co and let it run without credentials or source code. lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws
Re: We got admin access to Baseten's production GitHub
#56> We build Strix, an autonomous hacking again. > But... we're a security company. > So... we pointed Strix at *.baseten.co and let it run without credentials or source code. lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws
A lawyers wet dream is when a security company.... Finds an issue, does not abuse it, and reports it to the affected party for it to be patched? I feel like people like you are more of a lawyers wet dream, in that they'll happily litigate a frivolous case for you while billing you hourly.
Re: We got admin access to Baseten's production GitHub
#57Earlier quoted context omitted.
Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…
Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…
Re: We got admin access to Baseten's production GitHub
#58> We build Strix, an autonomous hacking again. > But... we're a security company. > So... we pointed Strix at *.baseten.co and let it run without credentials or source code. lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws
A lawyers wet dream is when a security company.... Finds an issue, does not abuse it, and reports it to the affected party for it to be patched? I feel like people like you are more of a lawyers wet dream, in that they'll happily litigate a frivolous case for you while billing you hourly.
Re: We got admin access to Baseten's production GitHub
#59> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…
> This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.
of course, these companies want you to sell vulns to brokers and other orgs. they don't care about bug reports.
otherwise they'd pay as much or even more, right?
Re: We got admin access to Baseten's production GitHub
#60> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…