logoalt Hacker News

mtlynchtoday at 6:57 PM5 repliesview on HN

Good in terms of prompt communication and fix. Absurdly bad in terms of reward.

Earlier in the article, it mentions that Baseten is valued at $13B. They can't dig into their couch cushions to give a few thousand dollars to the researcher privately disclosing a bug that let an attacker escalate to admin in their GitHub org?

This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.


Replies

manquertoday at 7:37 PM

Swag packages like these are a token of appreciation not a reward.

The front page post in HN here is worth far more than few thousand dollars , don’t think either organization is operating under purely financial transactional nature .

Most people who find a dropped wallet will return it without evaluating the market value of your compromised identity or the contents of the wallet .

Grateful owners may buy you a beer that doesn’t make them cheap , not everything is evaluated in purely money terms, and that is a good thing ?

show 4 replies
ralph84today at 9:58 PM

The researcher in this case was doing a security review for their company who was a potential customer. Sending potential customers more than a token amount of cash is usually prohibited by corporate ethics rules for obvious reasons.

sheepscreektoday at 7:22 PM

Yeah companies need to quickly understand that having good actors try and hack you is a good thing - those hacks get reported and another door gets sealed shut for bad actors.

This is more true today than ever before as the bar for a successful attack has never been lower. We’ll see a resurgence of the script-kiddie, or shall I say, vibe-kiddie :-/

r_leetoday at 8:23 PM

of course not, all they can do is a lil "thx"

> This sends the message that honest researchers should not waste their time looking for vulnerabilities in Baseten, but it's a good target for criminals who want to monetize these vulnerabilities.

of course, these companies want you to sell vulns to brokers and other orgs. they don't care about bug reports.

otherwise they'd pay as much or even more, right?