8 ms·
Critical vulnerability in AI coding platform Base44 allowing unauthorized access
- steveBK123 1y agoI only know Base44 from the bombardment of YouTube ads for them I receive. Glad to hear its going well.
- steveBK123 1y agoJust checking back in here to note I am legitimately considering a Youtube sub just to make the Base44 ads go away. So the ads are having some impact!
- koakuma-chan 1y agoWhy not use an Adblock?
- swyx 1y agooh interesting. do you think that was a big part of their growth strategy pre acquisition or did the ads only pick up post acquisition?
- toddmorey 1y agoThis is so true. I've ONLY heard them mentioned from their own ads, never even once in the wild. Must be one hell of an ad budget.
- Frieren 1y agoFor AI companies visibility is more important than the actual product. This is a characteristic of many bubbles were getting the word out is the only thing needed to get investors. Investors are scrambling to put as much money in AI as possible, so quality is not a concern for "entrepreneurs".
- esafak 1y agoIt looks like they blew their budget on ads instead of engineers :)
- xdfgh1112 1y agoMe too. They make it seem like you can vibe code an entire web shop in one prompt. In reality they charge by the token so if you hit a wall trying to get the AI to do stuff you run up a huge bill but it's too late to get out.
- pengaru 1y ago[flagged]
- zamalek 1y agoHot on the wheels on the vibe-coded Tea breach. Things are looking great for vibe coding. Don't get me wrong, I have been been more hands off (though not completely, and very prescriptive) with an SPA side project and it's going great. Claude makes way better looking UIs than my dog ugly developer UIs. But vibing auth? That should seriously count as _legal_ gross negligence.
- IanCal 1y agoNothing here says auth was vibe coded. It’s a platform for vibe coding.
- loupol 1y agoThere's also nothing saying they are not dog fooding at least a little bit.
- bee_rider 1y agoI wonder to what extent the vibe coding folks are dogfooding. Their platforms seem too basically work in the sense that they spit out some kind of code, so I guess there must not be too much dogfooding going on.
- IanCal 1y agoThere’s nothing saying they didn’t do this deliberately, but it’d still be an unsubstantiated accusation to say that’s why there was a problem with auth.
- JohnMakin 1y agoYou don’t think they dog food their own app dev? Interesting
- zahlman 1y agoDogfooding doesn't normally produce artifacts that end up in production, surely?
- j45 1y agoIt was only a few months old, how can technical debt and discoveries not be expected? Wix was probably acquiring a growing userbase.
- waldopat 1y agoThat's my take too. Perhaps $80M for free organic users was a steal? I do think credit is due to the founder, because he was able to single handedly build and market a valuable solution. That said, he also pushed code every day without code reviews. This is how you get technical debt and security vulnerabilities so fast.
- j45 1y agoFor sure, shipping and iterating quickly to solve a problem people had vs just one's own vision and interpretation is really commendable. The scary and exciting thing is it's still possible today with other needs.
- htrp 1y agoWonder if Wix had any contractual reps/warranties around the state of the Base44 codebase.
- financetechbro 1y agoI would expect so to some degree. Part of acquisition process is tech diligence usually done by a third party firm. But it’s not the deepest review. They run some code scans and dig into security policies and procedures, and then create a report with their findings which is used for R&W, insurance, etc.
- DonHopkins 1y ago"Vibe Diligence"
- ryandrake 1y agoHA HA but seriously: I predict someone's going to start a Venture Fund where all the DD is "done by AI" with equally predicable results. I'm calling it now. Bookmark this comment.
- tracker1 1y agoSecurity analysis via AI...
- swyx 1y agosoo Wiz found a vuln in Wix? this is israeli on israeli violence
- toddmorey 1y ago"The vulnerability we discovered was remarkably simple to exploit - by providing only a non-secret app_id value to undocumented registration and email verification endpoints." So you could sign yourself up as editor / collaborator on any app once you knew the app's ID. Jeez, that's sloppy. My colleague in 2000 discovered you could browse any account on his bank's website by just changing the (sequential!) account IDs in the URL. In a lot of ways we've made great strides in security over the last 25 years... and in many ways, we haven't.
- subw00f 1y agoPrepare for a whole new era of step backs when everyone is a “prompt engineer”.
- srcport56445 1y agoHave we really made "progress" ? Even in 2000 I doubt people were allowed to walk into a bank and look at everyone's account details.
- dpoloncsak 1y ago...How long did it take a transfer to settle in the 2000s
- deleted 1y ago
- uponasmile 1y ago>he vulnerability was fixed in less than 24 hours I wonder if they fixed it manually or used Base44 to fix it
- galnagli 1y agoHappy to answer questions : )
- waldopat 1y ago^^^ Hey YC Fam, this is the author
- waldopat 1y agoI've got a question! I'd say what's happening with viebcoding is really an acceleration of move fast and break things. Uber and Snapchat both had major security vulnerabilities, resulting in millions of user records leaked, in their hey day of the mid 2010s. And that was WITH whatever DevOps pipeline, code review or other best practices likely in place. What's unique about Tea or Base44 (or Replit founder deleting his codebase) is A) the disregard for security best practices and B) the speed at which they both grew and exposed vulnerabilities. So my question is, how do you see the balance of cybersecurity and AI as everything moves faster than ever before?
- galnagli 1y agoI see companies deploy and trust AI without really investing into security, it will be very easy in the near future to find simple, devastating bugs : )
- jus3sixty 1y agoEvery single day someone dies a wrongful death, a plane crashes, a serious data breach occurs, and someone slips on a banana peel. None of these things will ever stop the billionaire gravy train because of something called “Risk Management.” I don’t think our “vibe-coded AI slopware” is an exception.
- darepublic 1y agoThese platforms feel like their authors just stick a big bow (uniquely branded ofc) on top of llms. I don't want to undervalue the importance of good glue code.. but that's all I see here. Doesn't deserve the glossy sheen or accolades imo.
- zahlman 1y ago> Platforms like Loveable, Bolt, and Base44 > Wiz Research has been looking into the security posture > (recently acquired by Wix following an amazingly rapid rise) Anyone else find all these names really surreal? (Yeah, Google is kind of a dumb name too, but at least there's a cute story behind it.) (Okay, I knew Wix had been around for quite some time, but I didn't expect it to be almost as old as YouTube....)
- an0malous 1y agoIt’ll get more surreal because the supply of domains is smaller than the growth of ideas
- dangoodmanUT 1y ago80M to wix right?
- sandeepkd 1y agoI might go to the extent of saying that this is classical example of security by obscurity, and for good or bad reasons, a lot of applications would fall into this category, one way or another.
- oc1 1y agoThis will be the golden age of hackers for lulz or money, security researchers and script kiddies (fka idea guys)
- bgwalter 1y agoFun facts: All of Wix, Wiz, base44 were founded by ex Unit 8200 members. Wix was used by the NSO group to create fake websites for targeting critics: https://www.ynetnews.com/articles/0,7340,L-5461537,00.html https://www.ynetnews.com/articles/0,7340,L-5461537,00.html
- sschueller 1y agoI wonder how many of their executives can be directly linked to war crimes and/or crimes against humanity.
- bitwize 1y agoRemember, the S in GenAI is for security.
- crook123456 1y agoBase44 is just another builder.ai scam