Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

121–130 of 202 posts

Re: We got admin access to Baseten's production GitHub

#121
post #93

Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim". It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!". Strix also crossed the line at this point: > Strix decided…

Agreed. I suppose they'd have slightly less credibility by saying "we hacked " but it strikes me as far classier than naming & shaming.

I'm not sure this is "naming and shaming" because I don't seen an intent to shame. They disclosed the vulnerability privately, waited months for patches, and were commended by the organization with the vulnerabilities.

There's no shame here, this was a mistake, probably made by a human, and ultimately corrected. Nobody seems upset by the outcome!

Re: We got admin access to Baseten's production GitHub

#122
This fits neatly into the category of "not something an unmotivated huamn would bother to look for, but absolutely something a human could find if they were interested."

It increasingly feels like the power of these agents is less that they find things humans COULDN'T find, and more that they find many things much more quickly than humans would bother to do.

I don't know if this is a great advert for Strix over other agents - what did their agent do that Claude or Codex couldn't? It didn't do anything that I couldn't do, if I wanted to.

Re: We got admin access to Baseten's production GitHub

#123
post #82
post #16

Earlier quoted context omitted.

Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…

The researcher in this case was doing a security review for their company who was a potential customer. Sending potential customers more than a token amount of cash is usually prohibited by corporate ethics rules for obvious reasons.

That's incorrect. It's not only perfectly acceptable, but absolutely vital, to pay someone for their services (incl a customer) for assisting with an existential threat against the corporation.

Any counsel or HR who would draft a corporate ethics rule that wouldn't allow for a bug bounty to be paid out on a massive vulnerability, merely because the person was "a potential customer", should be immediately replaced.

Re: We got admin access to Baseten's production GitHub

#124
post #118

Earlier quoted context omitted.

At some point, you will realize two things. First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial. What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging…

[flagged]

> I'm saying serve yourself, not them. if you have say, a 0 day on your hands, do what serves you best. is that "ghetto punk ass behavior"?

Yes.

If you have say, managed to find an overlooked passage into an ostensibly high security building, "doing what serves you best" such as selling the information to some thugs, is in fact that kind of behavior.

Re: We got admin access to Baseten's production GitHub

#125

Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim". It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!". Strix also crossed the line at this point: > Strix decided…

shaming people for bad security practices is probably net good, whether we like it or not

Re: We got admin access to Baseten's production GitHub

#126

Earlier quoted context omitted.

The 9th Circuit Court of appeals recently published this that is somewhat related (Amazon v. Perplexity): https://cases.justia.com/federal/appellate-courts/ca9/26-144... Look at pages 10-17 to see how the law is evolving here.

In Perplexity's case everything is getting routed through the user's browser, so there is no server to server communication between Perplexity and Amazon, thus no CFAA unauthorized access was established. However, Anthropic and OpenAI did not use the pattern of routing through authorized parties, so I don't think this opinion gives them any cover.

The important bit to me is that they consider the agent running as an extension of the user. So the user is visiting Amazon, not Perplexity.

From that lens, that feels like users could be held liable for what these hacking agents are doing. Which in some cases probably makes sense, but certainly not all.

Re: We got admin access to Baseten's production GitHub

#127
post #68

Earlier quoted context omitted.

This is probably still considered standard response timeline, not a rapid one. The time window allowing for CVEs + Vulnerabilities remediation has been collapsing to days and hours perhaps even minutes[1]. Anyone who has an OpenRouter account can start using Strix + GLM 5.3 Flash to do damages at frontier Mytho 5 level cyber capabilities. [2] This cyber patching race is on, won't stop until all the software created f…

Meanwhile I have customers running legacy web apps last compiled over five years ago on end-of-life operating systems… and it’s crickets chirping. Dead quiet, not even a hint of an attack, let alone a breach. I expected them to have been hacked to pieces by now, but even “maximally vulnerable” internet-facing apps seem to be relatively unmolested so far. Maybe it’s still too expensive to go after “boring” enterprise…

Anyone can push people onto the railway tracks at a metro station but they don't. Being able to cause damage doesn't mean people will.

Re: We got admin access to Baseten's production GitHub

#128
post #61
post #39

Earlier quoted context omitted.

Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…

> The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . not always, especially if its just someone independent. iirc there was a guy here not too long ago who started dropping Windows 0days because Microsoft couldn't be assed to process his bug reports

> iirc there was a guy here not too long ago who started dropping Windows 0days because Microsoft couldn't be assed to process his bug reports

Did that ever actually happen? I remember him threatening to start dropping 0days and getting a lot of press coverage for it. When I tried to look it up I didn’t find anything at the time.

Re: We got admin access to Baseten's production GitHub

#129
post #39

Earlier quoted context omitted.

Swag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer…

Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.

Companies are 100% people. The fact that companies, their CEOs, and employees are not treated like people is exactly reason why humanity is in the shitshow show it is right now.

Re: We got admin access to Baseten's production GitHub

#130

> We build Strix, an autonomous hacking again. > But... we're a security company. > So... we pointed Strix at *.baseten.co and let it run without credentials or source code. lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws

A lawyers wet dream is when a security company.... Finds an issue, does not abuse it, and reports it to the affected party for it to be patched? I feel like people like you are more of a lawyers wet dream, in that they'll happily litigate a frivolous case for you while billing you hourly.

They did abuse if you read the article. They crossed a few lines.
Post reply on HN