Comment by SaucyWrong

19 hours ago

> since it's standard practice in the industry, thus it's unnecessary to state it.

I suppose so, but with a few words it would have been totally unambiguous though. "So... we pointed Strix at .baseten.co and let it run without credentials or source code (with Baseten's prior authorization, of course)*."

We're in the know about this industry convention, but Strix's prospects may not be.

> You don't want a pentester that doesn't show this kind of reserve!

Agreed! A long while back a prospective acquirer set their red team on the B2B I worked at during due-diligence (with our knowledge). I'm ashamed to say that due to a swiss-cheese-type failure in a very obscure endpoint they eventually gained broad access and exfiltrated our tenant DB. We detected this, and patched the problem, locking them out. The game was well and truly over for us at that point, and we took the loss, but they proceeded to attempt to crack customer credentials to re-infiltrate, causing an emergency that we were then bound to notify all of our customers about--they were damaging the goods! All they had to do was show us a tenant slug list and we would have known the scope of the breach, no further penetration was necessary. The acquisition did eventually go through. Though a highly capable red team they were, I haven't worked with one so reckless since then.