3 ms·
It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the
by stymaar 18d ago
It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious).
- kadoban 18d ago> It's not, in most juridictions at least What did I miss they did that's illegal? It looked like it downloaded a public docker image, searched around inside, and verified that the key it found was still valid (without making any changes), and then immediately notified them about the issue.
- dwedge 18d agoIf there is anything that was a crime (and it totally depends on jurisdiction), it was verifying the key. They used it to see what it could access, and by using it they had unauthorised access to a system
- fragmede 18d agoThe CFAA is broad enough to make that a crime.
- IshKebab 18d agoPeople have been arrested for far less. I dunno what the least offensive conviction has been though tbf. Anyone know?
- nrmitchi 18d agoThey "validated that the key was valid" by iterating internal repositories and listing the contents of said repos and poking around at what they do/are-for, including, apparently, iterating through customer lists/information. The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".
- stevage 18d agoSuing is not what you do when someone commits a crime against you. You're confusing civil law and criminal law.
- stymaar 18d agoYes, or more precisely I don't confuse the concepts but the terminology since English isn't my first language.
- philipwhiuk 18d agoThe difference is months inside staring at four walls.