4 ms·
Hey all Philip from Baseten here. Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the re
by philipkiely 19d ago
Hey all Philip from Baseten here.
Posting this on behalf of our security team. I wanted to confirm that we collaborated with Strix on the remediation of the reported vulnerability. We thank Strix for their responsible disclosure. We took immediate steps to invalidate the leaked key and remove the public container image. Our logs confirm the vulnerability was never exploited and no customer data was exposed.
- bearsyankees 19d ago+1 -- kudos to the Baseten team for their super professional response to all of this, it is clear why they are a generational company (-- Alex from Strix)
- ej_campbell 19d agoWhat distinguishes their response from non-generational companies? Do others fail to rotate their exposed github secrets that have admin access?
- agos 19d agosee, non-generational companies often miss the chance to turn penetration testing into a marketing opportunity
- usewik 19d agoOh, the positive externalities of unsolicited penetration (testing).
- VoidWhisperer 19d agoI think that many other companies (especially larger ones, I suppose) don't respond as promptly to security issues.
- justinclift 19d ago> Our logs confirm You retain all logs back through to (at least) March 2023?
- ErroneousBosh 19d agoYou don't? For some stuff, I've got logs going back to 1993...
- bdcravens 19d agoMany companies only keep logs as long as they're legally required to. It can't be discoverable if it doesn't exist ...
- indymike 19d ago> It can't be discoverable if it doesn't exist ... This cuts both ways. I've seen plenty of litigation go south because one side had evidence and the other side had nothing because they deleted/shredded/lost the proof.
- ErroneousBosh 19d ago> It can't be discoverable if it doesn't exist ... That's great, and for some things the court can ask you "Well *why* haven't you got it?" and then you're fucked. Now you're explaining in front of a parliamentary committee why you destroyed what would turn out to be evidence.
- AdamJacobMuller 19d ago"Our standard process is to only retain logs when legally required to, either due to being notified about a litigation or through legally mandated periods" is a fully complete sentence. Unless you're required to retain logs for some reason like a litigation hold or legally or contractually mandated retention period and you violate those, while the adversarial party might be annoyed at you for not retaining logs there isn't much they can or will do beyond being annoyed. Of course if you destroy logs after being notified of litigation or inquiry, you're gonna have a bad day.
- ActionHank 19d ago“Vulnerability” isn’t really the right term for “we left something explicitly vulnerable and exposed to the internet”
- philipwhiuk 19d agoWas this part of a planned penetration test or did they just compromise your infrastructure first?