5 ms·
> Baseten handled this well. The timeline was: > July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permiss
by swyx 19d ago
> Baseten handled this well. The timeline was:
> July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions.
> July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked.
> July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the token. He also asked us to securely delete the images we'd pulled.
> July 14, 5:05 PM: We confirmed deletion and sent over two lower-severity findings from the same scan.
> July 17: Baseten closed out the remaining findings.
> September: We let Baseten know we planned to disclose the finding publicly and sent them a draft of this post.
They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug.
well done all around. i think my only open question is what default security boundaries should all vibecoded internal agents follow as a learning we can take from this
- deleted 19d ago[deleted]
- mtlynch 19d agoGood in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org? This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.
- deleted 19d ago[deleted]
- sheepscreek 19d agoYeah companies need to quickly understand that having good actors try and hack you is a good thing - those hacks get reported and another door gets sealed shut for bad actors. This is more true today than ever before as the bar for a successful attack has never been lower. We’ll see a resurgence of the script-kiddie, or shall I say, vibe-kiddie :-/
- manquer 19d agoSwag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer that doesn’t make them cheap , not everything is evaluated in purely money terms, and that is a good thing ?
- sublinear 19d agoThank you for pushing back on one of the top disruptive bad-faith comments we see on HN. The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. I'm certain most of these comments mean well (to "open eyes" or whatever), but some of them really are on principle and blatant astroturfing.
- jazzpush2 19d agoIt's nice to wax poetic, but they should absolutely pay the researchers here.
- r_lee 19d ago> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. so it should be fought by giving them free work in the hopes that they'll finally feel guilty and then start paying proper bounties? like to me that just seems funny, as if they'd change anything if we'd keep rewarding them for not doing the right thing like, there's a reason regulation exists for all kinds of shit because otherwise companies would do all kinds of atrocities in hopes of cutting costs
- sublinear 19d agoAt some point, you will realize two things. First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial. What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging pessimistic groupthink and bad faith. This is why businesses can't be more open about their flaws. It's not that they're stupid and incompetent, but that the pitchforks come out. These are the seeds of dystopia. They would have eventually figured it out, but as an unfortunate incident with an outsized effect. As much as you wish it to be true, even the worst of these incidents will not kill their business. As much as you hate these businesses, their financial momentum will eventually cause the public to depend on them more. There's more at stake here than anyone's personal gain. It's naive to think otherwise. You're just manifesting broken windows and ignoring litter thinking you're fighting the man. This is straight up ghetto punk ass behavior wearing a white collar.
- r_lee 19d agoof course not, all they can do is a lil "thx" > This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities. of course, these companies want you to sell vulns to brokers and other orgs. they don't care about bug reports. otherwise they'd pay as much or even more, right?
- ralph84 19d agoThe researcher in this case was doing a security review for their company who was a potential customer. Sending potential customers more than a token amount of cash is usually prohibited by corporate ethics rules for obvious reasons.
- jamiesonbecker 19d agoThat's incorrect. It's not only perfectly acceptable, but absolutely vital, to pay someone for their services (incl a customer) for assisting with an existential threat against the corporation. Any counsel or HR who would draft a corporate ethics rule that wouldn't allow for a bug bounty to be paid out on a massive vulnerability, merely because the person was "a potential customer", should be immediately replaced.
- Aurornis 19d ago> Absurdly bad in terms of reward This is two companies working together. Most of the comments below are assuming this was an independent security researcher doing work on their own time. This was professionals doing work for their companies on both sides. > This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities. The reason they were looking for bugs was in the context of a B2B relationship, not as a someone independent on their nights and weekends. If they give them any additional compensation it would probably be in some amount of free or discounted services, which is what they’d want anyway.
- stickfigure 19d agoThe main payment is all the viral advertising that this AI hacking tool is getting right now. Hard to put a price on that.
- LoganDark 19d agoLiterally paid in exposure.
- zzzeek 19d agoif it were my company I'd not pay a dime if the researcher was going to make a big public blog post about a security issue in my infrastructure that I promised customers was secure. I'm sure the cash value of the advertisement here is worth more than a bug bounty would pay.
- polynomial 19d ago> They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug. Honestly I would have held out for a (hard to get) hardcover copy of Inference Engineering.
- htrp 19d agosigned too!
- taoh 19d agoI’d treat a vibecoded agent like an untrusted CI job, not like a junior employee: repo-scoped identity, read-only by default, no inherited Actions token or production secrets. Any operation that turns a read into a write should require approval outside the agent’s control and produce an auditable diff. Network egress belongs in the boundary too. Read-only access is not much protection if the agent can send everything it reads to an arbitrary endpoint.
- dang 19d agoCan you please not post AI-generated or AI-edited comments to HN? It's not allowed here - see https://news.ycombinator.com/newsguidelines.html#generated https://news.ycombinator.com/newsguidelines.html#generated and https://news.ycombinator.com/item?id=47340079 https://news.ycombinator.com/item?id=47340079. Of course, it's impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.
- deleted 19d ago[deleted]
- devy 19d agoThis is probably still considered standard response timeline, not a rapid one. The time window allowing for CVEs + Vulnerabilities remediation has been collapsing to days and hours perhaps even minutes[1]. Anyone who has an OpenRouter account can start using Strix + GLM 5.3 Flash to do damages at frontier Mytho 5 level cyber capabilities. [2] This cyber patching race is on, won't stop until all the software created for the past 70 years still in active use needs to be patched up. This is happening at EVERY SINGLE software company. The cost of not doing it? Game over. [1]: https://news.ycombinator.com/item?id=49699402 https://news.ycombinator.com/item?id=49699402 [2]: https://news.ycombinator.com/item?id=49705036 https://news.ycombinator.com/item?id=49705036
- jiggawatts 19d agoMeanwhile I have customers running legacy web apps last compiled over five years ago on end-of-life operating systems… and it’s crickets chirping. Dead quiet, not even a hint of an attack, let alone a breach. I expected them to have been hacked to pieces by now, but even “maximally vulnerable” internet-facing apps seem to be relatively unmolested so far. Maybe it’s still too expensive to go after “boring” enterprise targets? Maybe the bad actors targeted crypto systems first for the immense payoffs, if successful?
- fn-mote 19d ago> it’s still too expensive to go after “boring” enterprise targets? The economic argument seems convincing to me. I can’t tell what your stance on it is. You’re the only one that knows the value of these targets, but “not worth it” seems likely to me.
- jiggawatts 19d agoIt's a risk-reward ratio, same as anything else, whether legal or illegal. You wouldn't organise the equivalent of an elaborate bank heist to break into a child's piggy bank, it's just not worth it. I have heard of a few high profile crypto heists that appear to be AI-assisted, some as far back as the GPT 3.5 era. There was an article I can't find any more about someone accidentally pushing a security fix to a public repo and getting their wallets drained via that specific mechanism within something like an hour. Malicious actors are watching crypto like a cat in front of a mouse hole, because a "success" can net them the equivalent of hundreds of millions of USD that they can instantly transfer, launder, and spend. For comparison, what would they achieve by hacking the web site of a local council or public library? Cause some embarrassment? Attempt to crypto-locker them? What are the chances of a payout? Certainly not a 100%, and you're also certain to get the attention of the local equivalent of the FBI or Homeland Security.
- sceptic123 19d agoShouldn't the first step have been to roll the token?
- mixdup 18d agoDid you get their permission before running this test?