Live data from Hacker News

Ethical considerations of access to the HackerOne community

hackerone.com

21–30 of 70 posts

Re: Ethical considerations of access to the HackerOne community

#21
post #4

Good to see that they are taking a clearly communicated, carefully considered stance on a messy ethical issue. I don't really have a strong opinion on this case, but I think it's refreshing that HackerOne is dealing with a case with no clear best answer in a principled way.

Selecting your customers is always tricky. On one hand your right to run your business as you see fit and respecting your principles. On the other hand you have discrimination of all kinds. Think about the recent cases of a small baker with strong religious views refusing to create cakes for gay couples. Think about CloudFlare protecting ISIS sites.

To me, it seems to come down to:

1. there are evil people, but

2. those people frequently have more social power than nice people, and

3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.")

If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers" built into your system will mostly be used by those with power against those without it, regardless of which side is "correct."

So: If you let people speak freely, the powerful will shout down the powerless. But if you let people silence others, then the powerful will silence the powerless.

Morally, it really comes down to a choice of which kind of hammer hurts wronged innocent powerless people the least. (Which can often mean offering no hammer that can truly be used to "deal with" obviously-evil people.)

Re: Ethical considerations of access to the HackerOne community

#22
post #10

Earlier quoted context omitted.

>Why exactly is HackerOne drawing a distinction with this software producer? I read the whole article and still miss what the controversy with this producer is. FlexiSpy specifically marketed itself as a tool for spying on your spouse. Their front page used to include "read your partner's sms" https://web.archive.org/web/20060402200643/http://flexispy.c...

So the issue about how oblique they make their marketing message? If they rebrand and use lots of innuendo, then it's OK?

In some respects, yes, it's about the messaging. You'll attract certain customers, and they might be willing to press for certain things that might not be legal, depending on the message.

There's a difference between a gun company that markets their products as protection and sports, and one that markets them for revenge. In both cases, the usage of the gun is up to me, but in one case it looks like the company might be willing to assist me, or point me towards helpful information that assists me, in circumventing safeguards put in place on the purchase of weapons.

Re: Ethical considerations of access to the HackerOne community

#23
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

Why exactly is HackerOne drawing a distinction with this software producer? The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance. Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much…

[deleted]

Re: Ethical considerations of access to the HackerOne community

#24
post #10

Earlier quoted context omitted.

>Why exactly is HackerOne drawing a distinction with this software producer? I read the whole article and still miss what the controversy with this producer is. FlexiSpy specifically marketed itself as a tool for spying on your spouse. Their front page used to include "read your partner's sms" https://web.archive.org/web/20060402200643/http://flexispy.c...

So the issue about how oblique they make their marketing message? If they rebrand and use lots of innuendo, then it's OK?

You're being obtuse if you think this use-case wasn't a huge part of their thinking while designing the software and offering support to customers.

>I asked a FlexiSpy salesperson a simple question: If I wanted to, could I use their spyware to snoop on my wife's cellphone without her knowing? The answer each time was yes. When asked if it was legal, they responded with a canned disclaimer explaining it was necessary to get the permission of the target. But what if I didn't want my wife to know? They could help me anyway.

https://www.forbes.com/sites/thomasbrewster/2017/02/22/flexi...

Re: Ethical considerations of access to the HackerOne community

#25
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

Why exactly is HackerOne drawing a distinction with this software producer? The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance. Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much…

The purpose of the DoD is not to spy on people, it is to protect people. That some actions by some programs and and departments may cross the line legally during certain periods is not that same as an entity whose sole, or majority of goods or services are for, or marketed as being for, an illegal action.

Re: Ethical considerations of access to the HackerOne community

#26
post #4

Good to see that they are taking a clearly communicated, carefully considered stance on a messy ethical issue. I don't really have a strong opinion on this case, but I think it's refreshing that HackerOne is dealing with a case with no clear best answer in a principled way.

Selecting your customers is always tricky. On one hand your right to run your business as you see fit and respecting your principles. On the other hand you have discrimination of all kinds. Think about the recent cases of a small baker with strong religious views refusing to create cakes for gay couples. Think about CloudFlare protecting ISIS sites.

"Think about CloudFlare protecting ISIS sites."

I'm pretty sure the Feds are happy to have traffic to ISIS sites be routed (unencrypted) through an American company's service...

Re: Ethical considerations of access to the HackerOne community

#27
post #21
post #4

Earlier quoted context omitted.

Selecting your customers is always tricky. On one hand your right to run your business as you see fit and respecting your principles. On the other hand you have discrimination of all kinds. Think about the recent cases of a small baker with strong religious views refusing to create cakes for gay couples. Think about CloudFlare protecting ISIS sites.

To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…

I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies".

At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.

Re: Ethical considerations of access to the HackerOne community

#28

While I applaud this move, I suspect H1 will continue servicing government and law enforcement clients of all kinds. A consistently applied policy would see ties with ALL surveillance entities severed.

This is going to earn me huge downvotes, but not all surveillance is equally illegal or equally unethical.

To me it seems that groups that run spy satellites and look out for nuclear missile launches are in a different ethical category than people who make software for perpetuating domestic abuse.

Clearly, I picked two extremes. That was just to show that not all surveillance is equally bad and that some can be better than others. I will leave other kinds of surveillance are just and unjust for other discussion.

Re: Ethical considerations of access to the HackerOne community

#30
post #7
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

That's helpful feedback on missing context from our post. Thanks. This series by VICE articulates the sometimes subtle distinctions between legitimate monitoring software built for enterprises and parents vs this particular software (which they deem "stalkerware"). https://motherboard.vice.com/en_us/article/inside-stalkerwar...

There are a lot of dubious companies on HackerOne. Why did taking a stance on this one have a perceived more positive outcome than taking any stance at all?

Pretty much zero of the companies on HackerOne are part of any social responsibility index, shariah compliant index, or trendy b-corporation index. And even in the non-zero rebuttal, the vast majority can have entire dissertations written about weighing the ethical considerations for doing any business with them.

So why even make a stance at all?

The time it takes for the arbitrary nature of your ethical decisions to become apparent is simply longer than it will take for your runway to deplete.

Post reply on HN