Live data from Hacker News

Ethical considerations of access to the HackerOne community

hackerone.com

11–20 of 70 posts

Re: Ethical considerations of access to the HackerOne community

#11
> Companies should defer judgement to the courts rather than make arbitrary moral judgements.

Uh, no. Please no. I do not want the courts to arbitrate morality. That's a far far far more dystopian world than one where corporations do (supposing I accept their false dilemma). Companies can, in theory, be created by any person, with any moral alignment. That is not the case with governments (minus authoritarian ones, which function in the context of moral-defining as more or less the same as a company).

Additionally, deferring to the courts also leads to the ever terrible "this is moral because it is legal" and "this is immoral because it is illegal."

There is not a correct authority on morality to which you can defer. You cannot offload such decisions and wash your hands. Any moral decision you make, including deferring to some other moral-decider, is entirely your responsibility.

Note: I'm doing the naughty thing of morals=ethics. I know this is pedantically not the case, but I'm 99% sure that is what the article means. And, in general, this is also what everyone means outside of targeted discussions.

> ...if someone is infected with spyware they're probably better off infected with secure spyware.

I think this is a great ethical issue within the security community. There's many arguments against working for a company you have ethical disagreements with, but that becomes much more grey when it comes to security. Sure I might not agree with the mass surveillance of the government, but wouldn't I rather help the NSA not leave piles of malware sitting around on C&C servers than let it be exposed to even more malicious actors?

Security could use a hippocratic oath.

> FlexiSPY has not published a vulnerability disclosure policy or committed to no legal action against hackers. Both protective steps would be required should their program be hosted on HackerOne.

I'm surprised HackerOne doesn't have a policy surrounding this already. Are hackers who submit issues to HackerOne not protected?

> We will not take action against them based exclusively on moral judgements.

Hooray, kinda. I think this is a maxim that HackerOne could extend to not making moral judgements relevant at all, and to instead institute policies that reflect HackerOne's current morals. This increases transparency and allows HackerOne to say "We reject you because your company's goals/actions/whatever explicitly contradict our policy that everyone wear unicorn hats on Tuesdays".

> Their business conduct is not in line with our ambition to build a safe and sound internet where the sovereignty and safety of each participant is respected.

I think now would be a good time for HackerOne to write this stuff down. A very brief look at their site and the only thing I can see relating to this is the tagline "Make the internet safer together." From which sovereignty implications can be drawn, but having such policies explicitly stated and publicly available not only allows for transparency in decisions, but also works as an advertisement, "Oh hey, this company wants to protect my digital sovereignty, neat!"

Re: Ethical considerations of access to the HackerOne community

#12
post #2

Coming soon, a public market in bugs? How soon can I buy futures in Windows vulnerabilities?

The bugs you're talking about are already worth 5-6 figures. Their prices are so volatile and their outlook is complicated enough that no sane person would enter into a forward contract on one.

Re: Ethical considerations of access to the HackerOne community

#13
post #11

> Companies should defer judgement to the courts rather than make arbitrary moral judgements. Uh, no. Please no. I do not want the courts to arbitrate morality. That's a far far far more dystopian world than one where corporations do (supposing I accept their false dilemma). Companies can, in theory, be created by any person, with any moral alignment. That is not the case with governments (minus authoritarian ones, w…

[deleted]

Re: Ethical considerations of access to the HackerOne community

#14
post #2

Coming soon, a public market in bugs? How soon can I buy futures in Windows vulnerabilities?

Nah, the bugs are already traded underground. The nature of the situation means the bets might be done underground, too.

To settle those bets, you have to have a reliable spot price. The only way to know how much a Windows RCE is worth is to actually sell it.

Re: Ethical considerations of access to the HackerOne community

#15
post #11

> Companies should defer judgement to the courts rather than make arbitrary moral judgements. Uh, no. Please no. I do not want the courts to arbitrate morality. That's a far far far more dystopian world than one where corporations do (supposing I accept their false dilemma). Companies can, in theory, be created by any person, with any moral alignment. That is not the case with governments (minus authoritarian ones, w…

> I'm surprised HackerOne doesn't have a policy surrounding this already.

I think you misread that part. They require this, so FlexySPY joining their program would mean the situation would improve.

Re: Ethical considerations of access to the HackerOne community

#16
post #12
post #2

Coming soon, a public market in bugs? How soon can I buy futures in Windows vulnerabilities?

The bugs you're talking about are already worth 5-6 figures. Their prices are so volatile and their outlook is complicated enough that no sane person would enter into a forward contract on one.

Who said OP was a sane person?

Re: Ethical considerations of access to the HackerOne community

#18
post #10
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

>Why exactly is HackerOne drawing a distinction with this software producer? I read the whole article and still miss what the controversy with this producer is. FlexiSpy specifically marketed itself as a tool for spying on your spouse. Their front page used to include "read your partner's sms" https://web.archive.org/web/20060402200643/http://flexispy.c...

So the issue about how oblique they make their marketing message? If they rebrand and use lots of innuendo, then it's OK?

Re: Ethical considerations of access to the HackerOne community

#20
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

Why exactly is HackerOne drawing a distinction with this software producer?

The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance.

Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much better than getting yelled at by an angry spouse?

Post reply on HN