frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

We got admin access to Baseten's production GitHub in 25 minutes

https://www.strix.ai/blog/baseten-harbor-github-pat-takeover
77•bearsyankees•1h ago

Comments

bearsyankees•1h ago
We were (and still are) considering them as an inference provider and did a quick check first... but kudos to their team for the fast patch
vatsachak•1h ago
We really are entering the AI economy.

Now if only we knew if the stonks would go up or down (due to global turmoil) before I throw my savings at the SPY

dgellow•1h ago
Right now Trump is the wild card you have to take in account. He’s influencing the SPY way more than the AI trade
swyx•1h ago
> Baseten handled this well. The timeline was:

> July 13, 11:10 PM: I reported the live basetenbot token, the public Harbor project, and the repository permissions.

> July 14, morning: Baseten made the Harbor project private. I flagged that the token itself still worked.

> July 14, 4:34 PM: Anton from Baseten Security confirmed the issue as critical and said they had made the Harbor project private and rotated the token. He also asked us to securely delete the images we'd pulled.

> July 14, 5:05 PM: We confirmed deletion and sent over two lower-severity findings from the same scan.

> July 17: Baseten closed out the remaining findings.

> September: We let Baseten know we planned to disclose the finding publicly and sent them a draft of this post.

They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug.

well done all around. i think my only open question is what default security boundaries should all vibecoded internal agents follow as a learning we can take from this

mtlynch•27m ago
Good in terms of prompt communication and fix. Absurdly bad in terms of reward.

Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org?

This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.

sheepscreek•3m ago
Yeah companies need to quickly understand that having good actors try and hack you is a good thing - those hacks get reported and another door gets sealed shut for bad actors.

This is more true today than ever before as the bar for a successful attack has never been lower. We’ll see a resurgence of the script-kiddie, or shall I say, vibe-kiddie :-/

polynomial•4m ago
> They also sent us some T-shirts and sweatshirts as a thank-you for finding this critical bug.

Honestly I would have held out for a (hard to get) hardcover copy of Inference Engineering.

ramon156•58m ago
i quite liked using strix. last time i tried it, deepseek was a mess and bloated the context with nonsense. that was ~5 months ago, i wonder how it performs now
bearsyankees•36m ago
We've made a lot of awesome changes recently, would love any feedback on the latest version :)
sandeepkd•57m ago
This sounds interesting and twisted in some sense

1. A start up is validating a service provider to ensure that they are secure enough so that they can trust them before signing up for their service

2. The service provider is already trusted by so many big name companies who handed over their data, the customers data to them

Should it not be other way around?

On a different note, the finding is not just one off absolute, rather its a symptom which points to certain experience and expertise level for security practices. To be fair its hard to blame the start up folks, they are running against time and cutting corners is somewhat critical for survival for their business

bearsyankees•45m ago
Yeah... interesting paradigm
aatd86•48m ago
That is great marketing for strix, pretty bad for baseten. I don't think someone can have a better story to advertise their own security product. Did not know about strix but I am going to look it up now. Might add it to my stack.
bearsyankees•43m ago
Let us know if you have any feedback!
lukeify•17m ago
If I enter an address to "Start testing", I expect at least a preview of the report rather than being dumped on the signup page.
brewmarche•41m ago
Yeah I have seen this issue a few times. If you use Docker build arguments that way add `--provenance=false` to get rid of all that build metadata. Build secrets are still better since they allow you to scope the secret inside of the Dockerfile. Also, the metadata can be useful to inspect images.
bearsyankees•40m ago
Yeah honestly I wasn't too familiar with this beforehand but now have a sense of the best practices going forward
thrownaway22•21m ago
Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page. They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.")

From TFA:

> That token had admin and push access to Baseten's main product repo, the GitOps repo that drives their clusters, and their Homebrew tap, plus read/write access to other private repositories including specific repos per customers.

> The image build dated to March 2023, and the token still worked when we found it in July 2026.

What are the legal implications here?

conception•17m ago
Unless github had regulated data, unlikely, the legal implications are few. Document the issue, remediate and no findings on the next audit. Done.
hmokiguess•12m ago
Given the build is from 2023 one would expect that at least the token would have been rotated, and I suspect some of these compliance checks do require rotation of tokens/passwords.

That said, the whole compliance industry is a joke.

athrowaway3z•18m ago
A Markdown-as-a-Service where the interface is a Docker container.

I get how these choices might be the local optimum for a desired UX, but damn is it depressing to extrapolate where software as a whole is going.

kibac•15m ago
I wonder what model was used for this. Also as far as I know Baseten does not have any abliterated models in their repertoire.
guessmyname•10m ago
Either Mythos 5.1 or GPT 5.6 Cyber (aka. GPT Daybreak Red)
bearsyankees•3m ago
Neither, actually :)
NyxWulf•2m ago
The writing sounds like Claude to me
hmokiguess•14m ago
An easily preventable issue with proper engineering culture around defense in depth and principle of least privilege, awful look on Baseten here.

Kudos for Strix to find it, and especially with how it chose to disclose and report it.

wxw•11m ago
> [pen-testing agent] came back with an active GitHub personal access token for basetenbot. That token had admin and push access to Baseten's main product repo, the GitOps repo that drives their clusters, and their Homebrew tap, plus read/write access to other private repositories including specific repos per customers.

And the agent found the token in Docker build history after finding a Baseten image repository.

I wonder how many of these kinds of agent-driven security exploits we're not hearing about these days (i.e. driven by bad actors), worrying.

codemog•7m ago
Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.

Show HN: An e-ink frame that hears birds and draws them as 1800s illustrations

https://github.com/arnegiacomo/fugleramme
927•arnemunthekaas•6h ago•127 comments

An Update on Wayback Machine Access

https://blog.archive.org/2026/09/15/an-update-on-wayback-machine-access/
119•ChrisArchitect•1h ago•57 comments

We got admin access to Baseten's production GitHub in 25 minutes

https://www.strix.ai/blog/baseten-harbor-github-pat-takeover
78•bearsyankees•1h ago•27 comments

Gemini 3.8 Live and 3.8 Live Extended Thinking

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-8-live-gemini-3-...
83•leumon•1h ago•40 comments

Show HN: Capsule – Single-file web apps that save their data into SQLite

https://withcapsule.app/
212•bashtian•5h ago•102 comments

GEFS on OpenBSD: A Early Preview

https://marc.info/?l=openbsd-tech&m=178948744271633&w=2
55•sippingabonedry•2h ago•22 comments

I can't stop thinking about Papua New Guinea

https://notnottalmud.substack.com/p/why-i-cant-stop-thinking-about-papua
861•networked•13h ago•350 comments

Show HN: Hacking a $20 4G wireless hotspot into a texting device

https://bkovac.github.io/modem-thing/
142•bobili1234•6h ago•21 comments

The CSS Zen Garden dream, finally shipped

https://josprague.com/blog/the-css-zen-garden-dream-finally-shipped/
71•yosito•4h ago•32 comments

Giving up on smart rings

https://notesbylex.com/giving-up-on-smart-rings
55•lexandstuff•2d ago•85 comments

Jiga (YC W21) Is Hiring Product Engineer (Remote/US)

https://jiga.io/about-us/?ashby_jid=0b75d72d-c92b-4dca-8062-09d298ada0bd
1•grmmph•2h ago

Let's make quality the norm again

https://www.forbrukerradet.no/short-life/
207•ingve•9h ago•197 comments

The Inference Hardware Revolution of 2026

https://spectrum.ieee.org/inference-hardware-revolution
51•vinhnx•5h ago•4 comments

Photographs of Atlantic City Sand Sculpture (ca. 1880–1920)

https://publicdomainreview.org/collection/atlantic-city-sand-sculpture/
8•samclemens•1d ago•0 comments

Archiving pirate radio station Kool FM

https://londonist.com/london/music/kool-fm-archives
70•rdmuser•1d ago•24 comments

A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

https://www.effort.news/irregular
249•yusufozkan•22h ago•92 comments

US confirms for first time it has deployed space weapons

https://www.bbc.com/news/articles/ck790xg41ygro
346•harporoeder•15h ago•226 comments

Chop Up Your Books

https://attainablefelicity.mattkirkland.com/20260915/cut-up-your-books.html
3•matt_kirkland•40m ago•0 comments

Most people prefer traditional architecture

https://www.worksinprogress.news/p/do-people-prefer-traditional-architecture
173•alihm•1d ago•103 comments

America's Driver's License Breach Is a National Security Disaster

https://www.lawfaremedia.org/article/america%27s-drivers-licence-breach-is-a-national-security-di...
115•hn_acker•3h ago•66 comments

Hugging Face is billing OpenAI $100M for hacking it

https://thenextweb.com/news/hugging-face-delangue-openai-100m-compute-traces-demand
61•cwwc•1h ago•20 comments

Cartesian – AI 3D Modeling for Design

https://www.formas.ai/cartesian
60•eustoria•3h ago•59 comments

Rat and Mouse Gazette: Nursing Care (1996)

https://www.rmca.org/Articles/nurse.htm
11•joebig•1d ago•1 comments

Alternatives to MinIO for single-node local S3

https://rmoff.net/2026/01/14/alternatives-to-minio-for-single-node-local-s3/
209•rmoff•11h ago•86 comments

25 years of mass surveillance is enough

https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html
635•iamnothere•7h ago•219 comments

CSS-Tricks in Limbo

https://vale.rocks/micros/20260915-0135
229•edent•11h ago•96 comments

Sony's First Computer – The SMC-70 from 1982 [video]

https://www.youtube.com/watch?v=cT2-7KkPkBc
50•ksymph•2d ago•11 comments

A rough guide for going back to the Moon

https://research.ibm.com/blog/nasa-ibm-lunar-foundation-model
47•gmays•1d ago•87 comments

Show HN: Panel – A research workspace where the agent can build its own panes

https://github.com/greentfrapp/panel
39•greentfrapp•5h ago•8 comments

How much of F-Droid is LLM generated?

https://tintotint.eu/whacky-corner/f-droid_slop/
112•_ZeD_•9h ago•138 comments