Comment by swyx
16 hours ago
> Baseten handled this well. The timeline was:
> July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions.
> July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked.
> July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the token. He also asked us to securely delete the images we'd pulled.
> July 14, 5:05 PM: We confirmed deletion and sent over two lower-severity findings from the same scan.
> July 17: Baseten closed out the remaining findings.
> September: We let Baseten know we planned to disclose the finding publicly and sent them a draft of this post.
They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug.
well done all around. i think my only open question is what default security boundaries should all vibecoded internal agents follow as a learning we can take from this
Good in terms of prompt communication and fix. Absurdly bad in terms of reward.
Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org?
This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.
> Absurdly bad in terms of reward
This is two companies working together. Most of the comments below are assuming this was an independent security researcher doing work on their own time. This was professionals doing work for their companies on both sides.
> This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.
The reason they were looking for bugs was in the context of a B2B relationship, not as a someone independent on their nights and weekends.
If they give them any additional compensation it would probably be in some amount of free or discounted services, which is what they’d want anyway.
The main payment is all the viral advertising that this AI hacking tool is getting right now. Hard to put a price on that.
1 reply →
Swag packages like these are a token of appreciation not a reward.
The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature .
Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet .
Grateful owners may buy you a beer that doesn’t make them cheap , not everything is evaluated in purely money terms, and that is a good thing ?
> The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature .
not always, especially if its just someone independent. iirc there was a guy here not too long ago who started dropping Windows 0days because Microsoft couldn't be assed to process his bug reports
4 replies →
Wallets usually belong to real people with lives. We can empathize with them. Companies are not people. And they also don't and can't empathize with you.
9 replies →
Thank you for pushing back on one of the top disruptive bad-faith comments we see on HN.
The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we.
I'm certain most of these comments mean well (to "open eyes" or whatever), but some of them really are on principle and blatant astroturfing.
8 replies →
Yeah companies need to quickly understand that having good actors try and hack you is a good thing - those hacks get reported and another door gets sealed shut for bad actors.
This is more true today than ever before as the bar for a successful attack has never been lower. We’ll see a resurgence of the script-kiddie, or shall I say, vibe-kiddie :-/
The researcher in this case was doing a security review for their company who was a potential customer. Sending potential customers more than a token amount of cash is usually prohibited by corporate ethics rules for obvious reasons.
That's incorrect. It's not only perfectly acceptable, but absolutely vital, to pay someone for their services (incl a customer) for assisting with an existential threat against the corporation.
Any counsel or HR who would draft a corporate ethics rule that wouldn't allow for a bug bounty to be paid out on a massive vulnerability, merely because the person was "a potential customer", should be immediately replaced.
of course not, all they can do is a lil "thx"
> This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.
of course, these companies want you to sell vulns to brokers and other orgs. they don't care about bug reports.
otherwise they'd pay as much or even more, right?
Shouldn't the first step have been to roll the token?
This is probably still considered standard response timeline, not a rapid one.
The time window allowing for CVEs + Vulnerabilities remediation has been collapsing to days and hours perhaps even minutes[1]. Anyone who has an OpenRouter account can start using Strix + GLM 5.3 Flash to do damages at frontier Mytho 5 level cyber capabilities. [2]
This cyber patching race is on, won't stop until all the software created for the past 70 years still in active use needs to be patched up. This is happening at EVERY SINGLE software company.
The cost of not doing it? Game over.
[1]: https://news.ycombinator.com/item?id=49705036
Meanwhile I have customers running legacy web apps last compiled over five years ago on end-of-life operating systems… and it’s crickets chirping. Dead quiet, not even a hint of an attack, let alone a breach.
I expected them to have been hacked to pieces by now, but even “maximally vulnerable” internet-facing apps seem to be relatively unmolested so far.
Maybe it’s still too expensive to go after “boring” enterprise targets? Maybe the bad actors targeted crypto systems first for the immense payoffs, if successful?
> it’s still too expensive to go after “boring” enterprise targets?
The economic argument seems convincing to me. I can’t tell what your stance on it is.
You’re the only one that knows the value of these targets, but “not worth it” seems likely to me.
1 reply →
Anyone can push people onto the railway tracks at a metro station but they don't. Being able to cause damage doesn't mean people will.
I’d treat a vibecoded agent like an untrusted CI job, not like a junior employee: repo-scoped identity, read-only by default, no inherited Actions token or production secrets. Any operation that turns a read into a write should require approval outside the agent’s control and produce an auditable diff. Network egress belongs in the boundary too. Read-only access is not much protection if the agent can send everything it reads to an arbitrary endpoint.
Can you please not post AI-generated or AI-edited comments to HN? It's not allowed here - see https://news.ycombinator.com/item?id=47340079.
Of course, it's impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.
> They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug.
Honestly I would have held out for a (hard to get) hardcover copy of Inference Engineering.
signed too!