Live data from Hacker News

We got admin access to Baseten's production GitHub

strix.ai

171–180 of 202 posts

Re: We got admin access to Baseten's production GitHub

#171
post #155

Earlier quoted context omitted.

What distinguishes their response from non-generational companies? Do others fail to rotate their exposed github secrets that have admin access?

see, non-generational companies often miss the chance to turn penetration testing into a marketing opportunity

Oh, the positive externalities of unsolicited penetration (testing).

Re: We got admin access to Baseten's production GitHub

#173
post #21

I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.

It's odd personifying Strix as the thing that found these when it's whatever model they use doing the hard work. Nobody says Claude Code hacked a company, it's Fable.

[dead]

Re: We got admin access to Baseten's production GitHub

#174

Earlier quoted context omitted.

You don't? For some stuff, I've got logs going back to 1993...

Many companies only keep logs as long as they're legally required to. It can't be discoverable if it doesn't exist ...

> It can't be discoverable if it doesn't exist ...

This cuts both ways. I've seen plenty of litigation go south because one side had evidence and the other side had nothing because they deleted/shredded/lost the proof.

Re: We got admin access to Baseten's production GitHub

#175

Earlier quoted context omitted.

> Our logs confirm You retain all logs back through to (at least) March 2023?

You don't? For some stuff, I've got logs going back to 1993...

> For some stuff, I've got logs going back to 1993...

Find anything?

Re: We got admin access to Baseten's production GitHub

#176
post #94
post #49

So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…

So many security breaches involve Linux in one way or another. Your argument doesn't really work.

So many security breaches involve the internet in some way. Maybe we should just turn it off.

Re: We got admin access to Baseten's production GitHub

#177
post #94
post #49

So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…

So many security breaches involve Linux in one way or another. Your argument doesn't really work.

That was not an attack on Github itself. GH made enormous impact in the open source movement and is still beneficial for every software engineer by providing a free and very useful service.

Meanwhile, for a software business, Github is a wide and deep attack vector and nobody seems to be concerned about it.

Of course the same can be said about any other public git hosting, especially if it combines CI/CD, artifact distribution, identity and trust management.

Re: We got admin access to Baseten's production GitHub

#178

Hey all Philip from Baseten here. Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.

“Vulnerability” isn’t really the right term for “we left something explicitly vulnerable and exposed to the internet”

Re: We got admin access to Baseten's production GitHub

#179
post #16
post #4

> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…

Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…

if it were my company I'd not pay a dime if the researcher was going to make a big public blog post about a security issue in my infrastructure that I promised customers was secure.

I'm sure the cash value of the advertisement here is worth more than a bug bounty would pay.

Re: We got admin access to Baseten's production GitHub

#180

Earlier quoted context omitted.

You don't? For some stuff, I've got logs going back to 1993...

Many companies only keep logs as long as they're legally required to. It can't be discoverable if it doesn't exist ...

> It can't be discoverable if it doesn't exist ...

That's great, and for some things the court can ask you "Well *why* haven't you got it?" and then you're fucked. Now you're explaining in front of a parliamentary committee why you destroyed what would turn out to be evidence.

Post reply on HN