Live data from Hacker News

Ethical considerations of access to the HackerOne community

hackerone.com

1–10 of 70 posts

Re: Ethical considerations of access to the HackerOne community

#3
Good to see that they are taking a clearly communicated, carefully considered stance on a messy ethical issue. I don't really have a strong opinion on this case, but I think it's refreshing that HackerOne is dealing with a case with no clear best answer in a principled way.

Re: Ethical considerations of access to the HackerOne community

#4

Good to see that they are taking a clearly communicated, carefully considered stance on a messy ethical issue. I don't really have a strong opinion on this case, but I think it's refreshing that HackerOne is dealing with a case with no clear best answer in a principled way.

Selecting your customers is always tricky.

On one hand your right to run your business as you see fit and respecting your principles.

On the other hand you have discrimination of all kinds.

Think about the recent cases of a small baker with strong religious views refusing to create cakes for gay couples.

Think about CloudFlare protecting ISIS sites.

Re: Ethical considerations of access to the HackerOne community

#5
I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes.

The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring.

A formalized bug bounty program would enable the software producer to have secure software.

Why exactly is HackerOne drawing a distinction with this software producer? I read the whole article and still miss what the controversy with this producer is.

Is all monitoring software now banned from HackerOne under the guise of a moral high ground HackerOne just created?

Re: Ethical considerations of access to the HackerOne community

#7
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

That's helpful feedback on missing context from our post. Thanks.

This series by VICE articulates the sometimes subtle distinctions between legitimate monitoring software built for enterprises and parents vs this particular software (which they deem "stalkerware").

https://motherboard.vice.com/en_us/article/inside-stalkerwar...

Re: Ethical considerations of access to the HackerOne community

#8
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

There are plenty of corporate applications; the majority of them are obvious and the user knows what's happening (in my country at least [UK] any employee would need to be specifically told and likely have to sign something before it could be used). Monitoring isn't the issue.

The problem is spying. Enabling people to more reliably spy on others is a problem.

Re: Ethical considerations of access to the HackerOne community

#9
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

Making the decision seems a lot easier to me when the monitoring software explicitly markets itself to and supports domestic abusers.

Re: Ethical considerations of access to the HackerOne community

#10
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

>Why exactly is HackerOne drawing a distinction with this software producer? I read the whole article and still miss what the controversy with this producer is.

FlexiSpy specifically marketed itself as a tool for spying on your spouse. Their front page used to include "read your partner's sms" https://web.archive.org/web/20060402200643/http://flexispy.c...

Post reply on HN