| ▲ | stymaar 7 hours ago |
| It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious). |
|
| ▲ | stevage 4 hours ago | parent | next [-] |
| Suing is not what you do when someone commits a crime against you. You're confusing civil law and criminal law. |
|
| ▲ | kadoban 6 hours ago | parent | prev [-] |
| > It's not, in most juridictions at least What did I miss they did that's illegal? It looked like it downloaded a public docker image, searched around inside, and verified that the key it found was still valid (without making any changes), and then immediately notified them about the issue. |
| |
| ▲ | dwedge 6 hours ago | parent | next [-] | | If there is anything that was a crime (and it totally depends on jurisdiction), it was verifying the key. They used it to see what it could access, and by using it they had unauthorised access to a system | | | |
| ▲ | nrmitchi 2 hours ago | parent | prev | next [-] | | They "validated that the key was valid" by iterating internal repositories and listing the contents of said repos and poking around at what they do/are-for, including, apparently, iterating through customer lists/information. The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information". | |
| ▲ | IshKebab 5 hours ago | parent | prev [-] | | People have been arrested for far less. I dunno what the least offensive conviction has been though tbf. Anyone know? |
|