Posted by bearsyankees 16 hours ago
From TFA:
> That token had admin and push access to Baseten's main product repo, the GitOps repo that drives their clusters, and their Homebrew tap, plus read/write access to other private repositories including specific repos per customers.
> The image build dated to March 2023, and the token still worked when we found it in July 2026.
What are the legal implications here?
That said, the whole compliance industry is a joke.
In 2017:
> NIST changed the guidance with SP 800-63B, published June 2017. It explicitly said:
"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
Instead, passwords should be changed when there is evidence they have been compromised, not every 30/60/90 days.
Kudos for Strix to find it, and especially with how it chose to disclose and report it.