Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.
Your intuitution is right. At least in Germany it is not legal if not asked for permission first. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-ethische... See also the German Criminal Code, starting with §202a "Data espionage": https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...
We got admin access to Baseten's production GitHub
101–110 of 202 posts
Re: We got admin access to Baseten's production GitHub
#102Earlier quoted context omitted.
A lawyers wet dream is when a security company.... Finds an issue, does not abuse it, and reports it to the affected party for it to be patched? I feel like people like you are more of a lawyers wet dream, in that they'll happily litigate a frivolous case for you while billing you hourly.
Feelings don't really matter in the legal world. Statements and actions do.
https://www.justice.gov/archives/opa/pr/department-justice-a...
Re: We got admin access to Baseten's production GitHub
#103Earlier quoted context omitted.
Your intuitution is right. At least in Germany it is not legal if not asked for permission first. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-ethische... See also the German Criminal Code, starting with §202a "Data espionage": https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...
Germany isnt a serious country though Decompilng code is illegal there
Re: We got admin access to Baseten's production GitHub
#104Earlier quoted context omitted.
"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…
> The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. Or...to warn people away from ever expecting compassionate or empathetic behaviour from companies, and remind people not to trust them?
I trust a business to fulfill their obligations as stated in writing for the money paid. I do not trust them in any other way. Nobody should "trust" or depend on undefined behavior. Common sense can only ever be as common as you expect.
Re: We got admin access to Baseten's production GitHub
#105Earlier quoted context omitted.
as a lawyer, can you speculate as to why anthropic/openai aren't facing many or any consequences for their agents? I'm not asking in a "grab the pitchforks" way. more out of genuine curiosity as my uninformed recollection of the CFAA is as you describe it.
The 9th Circuit Court of appeals recently published this that is somewhat related (Amazon v. Perplexity): https://cases.justia.com/federal/appellate-courts/ca9/26-144... Look at pages 10-17 to see how the law is evolving here.
Re: We got admin access to Baseten's production GitHub
#106> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
> They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug. Honestly I would have held out for a (hard to get) hardcover copy of Inference Engineering.
Re: We got admin access to Baseten's production GitHub
#107Earlier quoted context omitted.
Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…
Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.
So does data ? it belongs to real people.
I would imagine baseten's customers and eventually their end-users[1] were also grateful that their data was not compromised here and the disclosure was responsible.
[1] There is a pretty good chance you and I could be using services who are using baseten
Re: We got admin access to Baseten's production GitHub
#108We really are entering the AI economy. Now if only we knew if the stonks would go up or down (due to global turmoil) before I throw my savings at the SPY
Right now Trump is the wild card you have to take in account. He’s influencing the SPY way more than the AI trade
Re: We got admin access to Baseten's production GitHub
#109Earlier quoted context omitted.
> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. so it should be fought by giving them free work in the hopes that they'll finally feel guilty and then start paying proper bounties? like to me that just seems funny, as if they'd change anything if we'd keep rewarding them for not doing the right thing like, there's a reason regulation ex…
At some point, you will realize two things. First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial. What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging…
Re: We got admin access to Baseten's production GitHub
#110Earlier quoted context omitted.
[flagged]
> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. so it should be fought by giving them free work in the hopes that they'll finally feel guilty and then start paying proper bounties? like to me that just seems funny, as if they'd change anything if we'd keep rewarding them for not doing the right thing like, there's a reason regulation ex…
Don't know if I would call it that ?
This was a potential customer reporting a result of an audit of a tool they are evaluating. This is frequent and normal activity in enterprise deals. Most of the time such reports are not critical vulnerabilities it would things like tenant configuration -what business would like versus what CISO will accept or risk acceptance of the product they are buying with monitoring or other prescription on access restrictions or a DPA and so on.
It would be novel business model to spend ton of money in getting a prospect to late-deal stage where they are ready to do a security audio for you just so that part is "free" .
Most companies wouldn't disclose(to the public) even if it was serious , that is not their job, they will report to internal teams and re-review on fix. Strix.ai has a benefit in doing so as they sell a scanning tool for this purpose so we get to hear of this.