Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

61–70 of 202 posts

Re: We got admin access to Baseten's production GitHub

#61
post #39
post #16

Earlier quoted context omitted.

Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…

Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…

> The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature .

not always, especially if its just someone independent. iirc there was a guy here not too long ago who started dropping Windows 0days because Microsoft couldn't be assed to process his bug reports

Re: We got admin access to Baseten's production GitHub

#62

Earlier quoted context omitted.

Either Mythos 5.1 or GPT 5.6 Cyber (aka. GPT Daybreak Red)

Neither, actually :)

Chinese? I can not imagine how a western state of the art model would follow through with such a task and not require some major trickery.

Re: We got admin access to Baseten's production GitHub

#63
post #39

Earlier quoted context omitted.

Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…

[flagged]

> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we.

so it should be fought by giving them free work in the hopes that they'll finally feel guilty and then start paying proper bounties?

like to me that just seems funny, as if they'd change anything if we'd keep rewarding them for not doing the right thing

like, there's a reason regulation exists for all kinds of shit because otherwise companies would do all kinds of atrocities in hopes of cutting costs

Re: We got admin access to Baseten's production GitHub

#64
post #49

So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…

This wasn't GitHub's fault in any way.

Re: We got admin access to Baseten's production GitHub

#66
post #28

Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.

They probably negotiated a "permission to attack" before letting Strix off the leash, as pentesters usually do.

Re: We got admin access to Baseten's production GitHub

#67
post #39

Earlier quoted context omitted.

Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…

Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.

"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways.

The law doesn't say companies MUST choose the most profitable choice at every turn, and even explicitly allows for good treatment of customers, community, employees etc as a viable business strategy (even if it's sad that it must be justified in that way).

Re: We got admin access to Baseten's production GitHub

#68
post #4

> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…

This is probably still considered standard response timeline, not a rapid one.

The time window allowing for CVEs + Vulnerabilities remediation has been collapsing to days and hours perhaps even minutes[1]. Anyone who has an OpenRouter account can start using Strix + GLM 5.3 Flash to do damages at frontier Mytho 5 level cyber capabilities. [2]

This cyber patching race is on, won't stop until all the software created for the past 70 years still in active use needs to be patched up. This is happening at EVERY SINGLE software company.

The cost of not doing it? Game over.

[1]: https://news.ycombinator.com/item?id=49699402

[2]: https://news.ycombinator.com/item?id=49705036

Re: We got admin access to Baseten's production GitHub

#69
post #47
post #42

Earlier quoted context omitted.

It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious).

> It's not, in most juridictions at least What did I miss they did that's illegal? It looked like it downloaded a public docker image, searched around inside, and verified that the key it found was still valid (without making any changes), and then immediately notified them about the issue.

People have been arrested for far less. I dunno what the least offensive conviction has been though tbf. Anyone know?

Re: We got admin access to Baseten's production GitHub

#70
post #28

Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.

Your intuitution is right. At least in Germany it is not legal if not asked for permission first.

https://www.nilsbecker.de/rechtliche-grauzonen-fuer-ethische...

See also the German Criminal Code, starting with §202a "Data espionage":

https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...

Post reply on HN