Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

141–150 of 202 posts

Re: We got admin access to Baseten's production GitHub

#141
post #88

Earlier quoted context omitted.

as a lawyer, can you speculate as to why anthropic/openai aren't facing many or any consequences for their agents? I'm not asking in a "grab the pitchforks" way. more out of genuine curiosity as my uninformed recollection of the CFAA is as you describe it.

There is also the big difference here between anthropic/openai maybe being negligent, but did not purposely instruct agents to go commit crimes . The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission). Anthropic/OpenAI can reasonably claim that they had no intent and are trying t…

I never thought I'd be on the side of advocating for a strengthened CFAA, but the mens rea requirement here seems really problematic in the age of agents.

Re: We got admin access to Baseten's production GitHub

#142
Hey all Philip from Baseten here.

Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.

Re: We got admin access to Baseten's production GitHub

#143
As a security software engineer I value and have a lot of experience with disclosures like this. At the last two B2Bs I worked at, I would also work personally with prospect security teams that wanted to run their red team at us (with approval and rules of engagement)

This is a valuable disclosure but I wonder about two things:

a) was the decision to run Strix against a prospective vendor domain negotiated in advance?

b) if the answer to a) is “no” then it is apparent that while Strix want to ensure their customers only run it against domains they own (totally fair) they have a double standard for their own use.

I don’t know, I’m accustomed to getting disclosures from any Jane or Joe via bug bounties etc., but it feels like a courtesy notice would be nice before a prospective customer lets their agentic hacker off the leash.

EDIT: for typos.

Re: We got admin access to Baseten's production GitHub

#144
post #66
post #28

Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.

They probably negotiated a "permission to attack" before letting Strix off the leash, as pentesters usually do.

The fact that they don’t seem to explicitly state this fact but do go to lengths to explain how the agent didn’t do anything malicious while confirming how alive the token was makes me doubt they asked for permission to run the agent in the first place.

Re: We got admin access to Baseten's production GitHub

#145
post #16

Earlier quoted context omitted.

Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…

> Absurdly bad in terms of reward This is two companies working together. Most of the comments below are assuming this was an independent security researcher doing work on their own time. This was professionals doing work for their companies on both sides. > This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want…

The main payment is all the viral advertising that this AI hacking tool is getting right now. Hard to put a price on that.

Re: We got admin access to Baseten's production GitHub

#146
post #8

That is great marketing for strix, pretty bad for baseten. I don't think someone can have a better story to advertise their own security product. Did not know about strix but I am going to look it up now. Might add it to my stack.

I'd never heard of baseten before; now I know who they are. "There is no such thing as bad publicity".

Re: We got admin access to Baseten's production GitHub

#147

Earlier quoted context omitted.

There is also the big difference here between anthropic/openai maybe being negligent, but did not purposely instruct agents to go commit crimes . The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission). Anthropic/OpenAI can reasonably claim that they had no intent and are trying t…

I never thought I'd be on the side of advocating for a strengthened CFAA, but the mens rea requirement here seems really problematic in the age of agents.

In terms of negligence use (openai, anthropic), ya, I agree, and we really need some consideration of "reasonable expectation" of the outcome.

In terms of "We wrote a hacking agent designed only for hacking and sell it as a self-hacking service and then pointing it at someone else and omg can you believe what it did we had no intention of hacking" sense, I don't think that's really applicable.

The mens rea is explicitly there and it's not valid for them to try to hide behind an "agent".

Re: We got admin access to Baseten's production GitHub

#148

Hey all Philip from Baseten here. Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.

+1 -- kudos to the Baseten team for their super professional response to all of this, it is clear why they are a generational company (-- Alex from Strix)

Re: We got admin access to Baseten's production GitHub

#150

Earlier quoted context omitted.

> Absurdly bad in terms of reward This is two companies working together. Most of the comments below are assuming this was an independent security researcher doing work on their own time. This was professionals doing work for their companies on both sides. > This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want…

The main payment is all the viral advertising that this AI hacking tool is getting right now. Hard to put a price on that.

Literally paid in exposure.
Post reply on HN