5 ms·
Good in terms of prompt communication and fix. Absurdly bad in terms of reward. Earlier in the article, it mentions that Baseten is valued at $13B. They can't
by mtlynch 19d ago
Good in terms of prompt communication and fix. Absurdly bad in terms of reward.
Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org?
This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.
- deleted 19d ago[deleted]
- sheepscreek 19d agoYeah companies need to quickly understand that having good actors try and hack you is a good thing - those hacks get reported and another door gets sealed shut for bad actors. This is more true today than ever before as the bar for a successful attack has never been lower. We’ll see a resurgence of the script-kiddie, or shall I say, vibe-kiddie :-/
- manquer 19d agoSwag packages like these are a token of appreciation not a reward. The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet . Grateful owners may buy you a beer that doesn’t make them cheap , not everything is evaluated in purely money terms, and that is a good thing ?
- sublinear 19d agoThank you for pushing back on one of the top disruptive bad-faith comments we see on HN. The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. I'm certain most of these comments mean well (to "open eyes" or whatever), but some of them really are on principle and blatant astroturfing.
- jazzpush2 19d agoIt's nice to wax poetic, but they should absolutely pay the researchers here.
- r_lee 19d ago> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. so it should be fought by giving them free work in the hopes that they'll finally feel guilty and then start paying proper bounties? like to me that just seems funny, as if they'd change anything if we'd keep rewarding them for not doing the right thing like, there's a reason regulation exists for all kinds of shit because otherwise companies would do all kinds of atrocities in hopes of cutting costs
- sublinear 19d agoAt some point, you will realize two things. First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial. What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging pessimistic groupthink and bad faith. This is why businesses can't be more open about their flaws. It's not that they're stupid and incompetent, but that the pitchforks come out. These are the seeds of dystopia. They would have eventually figured it out, but as an unfortunate incident with an outsized effect. As much as you wish it to be true, even the worst of these incidents will not kill their business. As much as you hate these businesses, their financial momentum will eventually cause the public to depend on them more. There's more at stake here than anyone's personal gain. It's naive to think otherwise. You're just manifesting broken windows and ignoring litter thinking you're fighting the man. This is straight up ghetto punk ass behavior wearing a white collar.
- cindyllm 19d ago[dead]
- 19d ago
- deleted 19d ago[deleted]
- flaunf221 19d agoWallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.
- alluro2 19d ago"and can't empathize with you" - I don't really understand why such a perception of companies has been regurgitated and reinforced so much in US public, to the point where it's a blank excuse from ever expecting such a thing from a company. It's not true that it can't. The only reason to keep repeating that kind of worldview is to absolve companies behaving in shitty, toxic or downright evil ways. The law doesn't say companies MUST choose the most profitable choice at every turn, and even explicitly allows for good treatment of customers, community, employees etc as a viable business strategy (even if it's sad that it must be justified in that way).
- ImPostingOnHN 19d agoI think the point is that companies are purely legal entities, and as such, cannot feel, much less empathize, simply by virtue of them not being living things
- leptons 19d agoThat's nonsense. "Companies" are not something non-human, they are run by humans, who do feel, empathize, and are living beings. Without these living-being humans, there would simply be no "company". Now how those humans that run the company behave is another thing - they are free to be greedy assholes, and a lot of them are, and some of them aren't - but that's still a human thing.
- ImPostingOnHN 18d ago> "Companies" are not something non-human Yes, they are not humans. They are not even living creatures. They are mostly-legal entities mostly for the purpose of contracting with humans or other legal entities. > they are run by humans, who do feel, empathize, and are living beings This is usually true, but it is orthogonal to whether the company (a legal entity) itself is a biologically living creature, which is the only thing capable of feeling*. To put a point on it: my lawnmower is also run by humans, but it does not have empathy for any grass or people that gets in its way. It mostly just goes where it is steered. A company is like that, except with less touching grass. * — unless you want to argue semantics about what "feeling" means, even though the discussion is about "feeling" and "empathy" in the way humans experience it, and how that form of "empathy" does not exist for a nonliving legal entity which may or may not employ any actual humans
- r_lee 19d ago> The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature . not always, especially if its just someone independent. iirc there was a guy here not too long ago who started dropping Windows 0days because Microsoft couldn't be assed to process his bug reports
- OkayPhysicist 19d agoThat actually supports the point that people aren't acting under purely financial motivations. If the guy was purely following financial motivations, surely he would have chosen to sell the vulnerabilities to the shadier side of things. Instead, he dumped them publicly, burning their value while amplifying the "fuck you" factor to Microsoft. Ignoring reports, or just fixing the vulnerability without acknowledging the work put in by a researcher, is rude and invites rudeness in return.
- ivlad 19d agoMicrosoft runs a bug bounty program. NightmareEclipse (that’s the researcher’s handle) allegedly participated and Microsoft did not honor their part of the bug bounty program terms. This is a completely different situation - a company evaluates the security of a prospective vendor prior to entering a business agreement.
- Aurornis 19d ago> iirc there was a guy here not too long ago who started dropping Windows 0days because Microsoft couldn't be assed to process his bug reports Did that ever actually happen? I remember him threatening to start dropping 0days and getting a lot of press coverage for it. When I tried to look it up I didn’t find anything at the time.
- Barbing 19d ago> New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access https://bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access https://bleepingcomputer.com/news/security/new-microsoft-def... “Nightmare Eclipse released these zero-day exploits as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. […] Since April, the anonymous security researcher has disclosed a long list of zero-day flaws, including ShieldBreak, LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, targeting Microsoft Defender, BitLocker, and other Windows components.”
- r_lee 19d agoof course not, all they can do is a lil "thx" > This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities. of course, these companies want you to sell vulns to brokers and other orgs. they don't care about bug reports. otherwise they'd pay as much or even more, right?
- ralph84 19d agoThe researcher in this case was doing a security review for their company who was a potential customer. Sending potential customers more than a token amount of cash is usually prohibited by corporate ethics rules for obvious reasons.
- jamiesonbecker 19d agoThat's incorrect. It's not only perfectly acceptable, but absolutely vital, to pay someone for their services (incl a customer) for assisting with an existential threat against the corporation. Any counsel or HR who would draft a corporate ethics rule that wouldn't allow for a bug bounty to be paid out on a massive vulnerability, merely because the person was "a potential customer", should be immediately replaced.
- Aurornis 19d ago> Absurdly bad in terms of reward This is two companies working together. Most of the comments below are assuming this was an independent security researcher doing work on their own time. This was professionals doing work for their companies on both sides. > This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities. The reason they were looking for bugs was in the context of a B2B relationship, not as a someone independent on their nights and weekends. If they give them any additional compensation it would probably be in some amount of free or discounted services, which is what they’d want anyway.
- stickfigure 19d agoThe main payment is all the viral advertising that this AI hacking tool is getting right now. Hard to put a price on that.
- LoganDark 19d agoLiterally paid in exposure.
- zzzeek 18d agoif it were my company I'd not pay a dime if the researcher was going to make a big public blog post about a security issue in my infrastructure that I promised customers was secure. I'm sure the cash value of the advertisement here is worth more than a bug bounty would pay.