Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

91–100 of 202 posts

Re: We got admin access to Baseten's production GitHub

#91
post #67

Earlier quoted context omitted.

Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.

"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…

I agree that this notion that companies make these decisions is bad, bad on the grounds that it's people working for those companies that make the decisions, they hide themselves away, but the company itself isn't doing anything - is always a human making the decision

Re: We got admin access to Baseten's production GitHub

#92
post #42
post #28

Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.

It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious).

Suing is not what you do when someone commits a crime against you. You're confusing civil law and criminal law.

Re: We got admin access to Baseten's production GitHub

#93

Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim". It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!". Strix also crossed the line at this point: > Strix decided…

Agreed. I suppose they'd have slightly less credibility by saying "we hacked " but it strikes me as far classier than naming & shaming.

Re: We got admin access to Baseten's production GitHub

#94
post #49

So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…

So many security breaches involve Linux in one way or another. Your argument doesn't really work.

Re: We got admin access to Baseten's production GitHub

#95
post #67

Earlier quoted context omitted.

"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…

I think the point is that companies are purely legal entities, and as such, cannot feel, much less empathize, simply by virtue of them not being living things

That's nonsense. "Companies" are not something non-human, they are run by humans, who do feel, empathize, and are living beings. Without these living-being humans, there would simply be no "company".

Now how those humans that run the company behave is another thing - they are free to be greedy assholes, and a lot of them are, and some of them aren't - but that's still a human thing.

Re: We got admin access to Baseten's production GitHub

#96
post #19

Earlier quoted context omitted.

If I enter an address to "Start testing", I expect at least a preview of the report rather than being dumped on the signup page.

Yeah understood — we need to make sure you own the domain first though

Might be too nerdy for some, but a TXT DNS rule could work. That or a sample report. It looks like a cool product though, thanks for sharing.

Re: We got admin access to Baseten's production GitHub

#97

Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.") From TFA: > That token…

Given the build is from 2023 one would expect that at least the token would have been rotated, and I suspect some of these compliance checks do require rotation of tokens/passwords. That said, the whole compliance industry is a joke.

Box checking is an important business!

Re: We got admin access to Baseten's production GitHub

#98
post #67

Earlier quoted context omitted.

Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.

"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…

> The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways.

Or...to warn people away from ever expecting compassionate or empathetic behaviour from companies, and remind people not to trust them?

Re: We got admin access to Baseten's production GitHub

#100

Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.") From TFA: > That token…

Given the build is from 2023 one would expect that at least the token would have been rotated, and I suspect some of these compliance checks do require rotation of tokens/passwords. That said, the whole compliance industry is a joke.

tokens yes, password rotation, no.

In 2017:

> NIST changed the guidance with SP 800-63B, published June 2017. It explicitly said:

"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."

Instead, passwords should be changed when there is evidence they have been compromised, not every 30/60/90 days.

Post reply on HN