3 ms·
> We build Strix, an autonomous hacking again. > But... we're a security company. > So... we pointed Strix at *.baseten.co and let it run without credentials
by calvinmorrison 17d ago
> We build Strix, an autonomous hacking again.
> But... we're a security company.
> So... we pointed Strix at *.baseten.co and let it run without credentials or source code.
lawyers wet dream. and a perfect case. A security company who KNOWS the law unleashed an AI agent to violate the laws
- DaSHacka 17d agoA lawyers wet dream is when a security company.... Finds an issue, does not abuse it, and reports it to the affected party for it to be patched? I feel like people like you are more of a lawyers wet dream, in that they'll happily litigate a frivolous case for you while billing you hourly.
- usewik 17d agoFeelings don't really matter in the legal world. Statements and actions do.
- DaSHacka 17d agoAnd, most notably, intent. https://www.justice.gov/archives/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act https://www.justice.gov/archives/opa/pr/department-justice-a...
- calvinmorrison 17d agoif i find someones key on the ground and take the key and walk into their house and poke around, and make sure to leave a letter, this is a good thing?
- iJohnDoe 17d agoThey did abuse if you read the article. They crossed a few lines.
- usewik 17d agoAgreed. Pretty sure you are supposed to ask for permission before pentesting someone. Hopefully they, being a security company, know that.