nrmitchi
yesterday at 10:02 PM
Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim".
It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!".
Strix also crossed the line at this point:
> Strix decided to pull an image and see what was inside.
You're going past the white-hat point here when you start active exfiltrating data and looking at it. Once you start using credentials from the exfiltrated data and start listing and poking around internal systems, you are way past it.
Listen, I get it, their product is "meant for" self-testing, so it assumes it's safe to go digging. After all, it's a self check. That is exactly why it's irresponsible, and borderline illegal, for them to point it at a third party. Even if they had "permission", I dobut that permission extended to "and also search and/or download our repos if you can".
The overall tone is less than professional. Statements like (in bold) "This is an insane amount of access to leave in a publicly downloadable image." Everyone is aware of this, and it's phrase like it was a purposeful decision.
Security tools from teams that actively shit on the people they're designed to "help" feels wrong.
Edit: For clarity on my point about "pulling repos", this post includes descriptions of the purpose and functionality of multiple repos (which is past what a name gives them), and they explicitly state: "A listing of that private repo showed a top-level customers/ directory, with subdirectory after subdirectory named after Baseten customers". Strix explicitly took action that they knew they were not permitted, and extracted confidential customer information. Claiming "We didn't clone the customer repo" when you, instead, just listed the contents of the repo, is not a valid defense.
FL410
yesterday at 10:21 PM
Agreed. I suppose they'd have slightly less credibility by saying "we hacked <unnamed company>" but it strikes me as far classier than naming & shaming.
ivraatiems
today at 12:55 AM
I'm not sure this is "naming and shaming" because I don't seen an intent to shame. They disclosed the vulnerability privately, waited months for patches, and were commended by the organization with the vulnerabilities.
There's no shame here, this was a mistake, probably made by a human, and ultimately corrected. Nobody seems upset by the outcome!
shaming people for bad security practices is probably net good, whether we like it or not
There is a big difference between "bad security practices" and "someone made a mistake 2.5 years ago"