Earlier quoted context omitted.
Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.
"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…
We got admin access to Baseten's production GitHub
91–100 of 202 posts
Re: We got admin access to Baseten's production GitHub
#92Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.
It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious).
Re: We got admin access to Baseten's production GitHub
#93Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim". It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!". Strix also crossed the line at this point: > Strix decided…
Re: We got admin access to Baseten's production GitHub
#94So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…
Re: We got admin access to Baseten's production GitHub
#95Earlier quoted context omitted.
"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…
I think the point is that companies are purely legal entities, and as such, cannot feel, much less empathize, simply by virtue of them not being living things
Now how those humans that run the company behave is another thing - they are free to be greedy assholes, and a lot of them are, and some of them aren't - but that's still a human thing.
Re: We got admin access to Baseten's production GitHub
#96Earlier quoted context omitted.
If I enter an address to "Start testing", I expect at least a preview of the report rather than being dumped on the signup page.
Yeah understood — we need to make sure you own the domain first though
Re: We got admin access to Baseten's production GitHub
#97Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.") From TFA: > That token…
Given the build is from 2023 one would expect that at least the token would have been rotated, and I suspect some of these compliance checks do require rotation of tokens/passwords. That said, the whole compliance industry is a joke.
Re: We got admin access to Baseten's production GitHub
#98Earlier quoted context omitted.
Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.
"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…
Or...to warn people away from ever expecting compassionate or empathetic behaviour from companies, and remind people not to trust them?
Re: We got admin access to Baseten's production GitHub
#99Re: We got admin access to Baseten's production GitHub
#100Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.") From TFA: > That token…
Given the build is from 2023 one would expect that at least the token would have been rotated, and I suspect some of these compliance checks do require rotation of tokens/passwords. That said, the whole compliance industry is a joke.
In 2017:
> NIST changed the guidance with SP 800-63B, published June 2017. It explicitly said:
"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
Instead, passwords should be changed when there is evidence they have been compromised, not every 30/60/90 days.