<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: thrownaway22</title><link>https://news.ycombinator.com/user?id=thrownaway22</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 17 Sep 2026 13:02:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=thrownaway22" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by thrownaway22 in "We got admin access to Baseten's production GitHub"]]></title><description><![CDATA[
<p>Baseten carries the Soc 2 Type II and HIPAA Compliant logos on its front page.  They also have logos for customers including: OpenEvidence (medical related, used by almost 2/3 of physicians in the US, claim HIPAA compliance), Harvey (legal related, claim "binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC2, ISO, GDPR and other standards.")<p>From TFA:<p>> That token had admin and push access to Baseten's main product repo, the GitOps repo that drives their clusters, and their Homebrew tap, plus read/write access to other private repositories including specific repos per customers.<p>> The image build dated to March 2023, and the token still worked when we found it in July 2026.<p>What are the legal implications here?</p>
]]></description><pubDate>Tue, 15 Sep 2026 19:04:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49717234</link><dc:creator>thrownaway22</dc:creator><comments>https://news.ycombinator.com/item?id=49717234</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49717234</guid></item></channel></rss>