Earlier quoted context omitted.
At some point, you will realize two things. First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial. What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging…
[flagged]
We got admin access to Baseten's production GitHub
181–190 of 202 posts
Re: We got admin access to Baseten's production GitHub
#182Hey all Philip from Baseten here. Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.
Re: We got admin access to Baseten's production GitHub
#183Earlier quoted context omitted.
Suing is not what you do when someone commits a crime against you. You're confusing civil law and criminal law.
Yes, or more precisely I don't confuse the concepts but the terminology since English isn't my first language.
Re: We got admin access to Baseten's production GitHub
#184Earlier quoted context omitted.
Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.
"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say…
As for companies being shit, that's just capitalism, but plenty of people believe that's the only way.
Re: We got admin access to Baseten's production GitHub
#185Re: We got admin access to Baseten's production GitHub
#186Earlier quoted context omitted.
The important bit to me is that they consider the agent running as an extension of the user. So the user is visiting Amazon, not Perplexity. From that lens, that feels like users could be held liable for what these hacking agents are doing. Which in some cases probably makes sense, but certainly not all.
In which cases wouldn’t it make sense?
Re: We got admin access to Baseten's production GitHub
#187Earlier quoted context omitted.
Many companies only keep logs as long as they're legally required to. It can't be discoverable if it doesn't exist ...
> It can't be discoverable if it doesn't exist ... That's great, and for some things the court can ask you "Well *why* haven't you got it?" and then you're fucked. Now you're explaining in front of a parliamentary committee why you destroyed what would turn out to be evidence.
Unless you're required to retain logs for some reason like a litigation hold or legally or contractually mandated retention period and you violate those, while the adversarial party might be annoyed at you for not retaining logs there isn't much they can or will do beyond being annoyed.
Of course if you destroy logs after being notified of litigation or inquiry, you're gonna have a bad day.
Re: We got admin access to Baseten's production GitHub
#188> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions. > July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked. > July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the to…
Re: We got admin access to Baseten's production GitHub
#189Earlier quoted context omitted.
I think the only misleading part of this situation is your naive and self-centered definition of "trust", and the assumption that so many others think similarly enough that they need to be warned. I trust a business to fulfill their obligations as stated in writing for the money paid. I do not trust them in any other way. Nobody should "trust" or depend on undefined behavior. Common sense can only ever be as common a…
> your naive and self-centered definition of "trust" I never gave one? For what it's worth, I agree with your second paragraph, despite your first being needlessly aggressive.
Re: We got admin access to Baseten's production GitHub
#190Earlier quoted context omitted.
[flagged]
> I'm saying serve yourself, not them. if you have say, a 0 day on your hands, do what serves you best. is that "ghetto punk ass behavior"? Yes. If you have say, managed to find an overlooked passage into an ostensibly high security building, "doing what serves you best" such as selling the information to some thugs, is in fact that kind of behavior.
for real security bugs, like, you can literally sell them to brokers who sell them to governments. would selling stuff to the CIA be ghetto?
morally, it depends. but after seeing so many posts of e.g. Google cheapskating on bug reports, it really makes no sense to me to participate in such a broken system.
this case however is quite different as it was a B2B encounter and during vendor vetting
like to me it just seems like a fair deal, if Google wants their bugs patched (which they can definitely afford to do) they'd just pay properly for serious bugs and so on, and everybody would be happy. it's not some kind of thing where they can't do anything about.
maybe you can understand the angle I'm coming from?