Earlier quoted context omitted.
What distinguishes their response from non-generational companies? Do others fail to rotate their exposed github secrets that have admin access?
see, non-generational companies often miss the chance to turn penetration testing into a marketing opportunity
We got admin access to Baseten's production GitHub
171–180 of 202 posts
Re: We got admin access to Baseten's production GitHub
#172Re: We got admin access to Baseten's production GitHub
#173I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.
It's odd personifying Strix as the thing that found these when it's whatever model they use doing the hard work. Nobody says Claude Code hacked a company, it's Fable.
Re: We got admin access to Baseten's production GitHub
#174Earlier quoted context omitted.
You don't? For some stuff, I've got logs going back to 1993...
Many companies only keep logs as long as they're legally required to. It can't be discoverable if it doesn't exist ...
This cuts both ways. I've seen plenty of litigation go south because one side had evidence and the other side had nothing because they deleted/shredded/lost the proof.
Re: We got admin access to Baseten's production GitHub
#175Re: We got admin access to Baseten's production GitHub
#176So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…
So many security breaches involve Linux in one way or another. Your argument doesn't really work.
Re: We got admin access to Baseten's production GitHub
#177So often recent breaches involve Github in one way or another. How is it still considered a sane choice to host anything proprietary there? If your business is built around open source, ok, put a mirror on Github. But CI/CD, gitops, FDEs' stuff have no place on a public cloud. C-level execs may not know bits from bytes, but by now they should've understood that this is akin to storing ammonium nitrate in the open air…
So many security breaches involve Linux in one way or another. Your argument doesn't really work.
Meanwhile, for a software business, Github is a wide and deep attack vector and nobody seems to be concerned about it.
Of course the same can be said about any other public git hosting, especially if it combines CI/CD, artifact distribution, identity and trust management.
Re: We got admin access to Baseten's production GitHub
#178Hey all Philip from Baseten here. Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.
Re: We got admin access to Baseten's production GitHub
#179> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerab…
I'm sure the cash value of the advertisement here is worth more than a bug bounty would pay.
Re: We got admin access to Baseten's production GitHub
#180Earlier quoted context omitted.
You don't? For some stuff, I've got logs going back to 1993...
Many companies only keep logs as long as they're legally required to. It can't be discoverable if it doesn't exist ...
That's great, and for some things the court can ask you "Well *why* haven't you got it?" and then you're fucked. Now you're explaining in front of a parliamentary committee why you destroyed what would turn out to be evidence.