Earlier quoted context omitted.
So the issue about how oblique they make their marketing message? If they rebrand and use lots of innuendo, then it's OK?
You're being obtuse if you think this use-case wasn't a huge part of their thinking while designing the software and offering support to customers. >I asked a FlexiSpy salesperson a simple question: If I wanted to, could I use their spyware to snoop on my wife's cellphone without her knowing? The answer each time was yes. When asked if it was legal, they responded with a canned disclaimer explaining it was necessary…
Ethical considerations of access to the HackerOne community
41–50 of 70 posts
Re: Ethical considerations of access to the HackerOne community
#42Earlier quoted context omitted.
To settle those bets, you have to have a reliable spot price. The only way to know how much a Windows RCE is worth is to actually sell it.
Good point.
Re: Ethical considerations of access to the HackerOne community
#43Earlier quoted context omitted.
I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.
The only question I have, in this particular case is: what about the victims of the original app? Are they possibly the subject of re-victimization if the app on their device is compromised further by 3rd parties? Though I completely agree with HackerOne's moral stance here, does this particular scenario complicate things? EDIT: I do see they took this into consideration in their writeup... still curious.
Re: Ethical considerations of access to the HackerOne community
#44Earlier quoted context omitted.
You're being obtuse if you think this use-case wasn't a huge part of their thinking while designing the software and offering support to customers. >I asked a FlexiSpy salesperson a simple question: If I wanted to, could I use their spyware to snoop on my wife's cellphone without her knowing? The answer each time was yes. When asked if it was legal, they responded with a canned disclaimer explaining it was necessary…
I have no doubt it is what they're selling. But the question is if the tool does something, then the marketing message shouldn't really be relevant. If a FlexiSpy clone comes along and is less direct about spouse-spying, and plays a stronger line of "you need authorization", then it's suddenly OK?
my point was that it isn't just marketing, this use-case was a huge part of their thinking while designing the software and offering support to customers. [repeating my comment almost verbatim]
If a clone came along that wasn't designed so that it can be totally hidden while installed, then privacy advocates would be less angry.
Re: Ethical considerations of access to the HackerOne community
#45Earlier quoted context omitted.
This is going to earn me huge downvotes, but not all surveillance is equally illegal or equally unethical. To me it seems that groups that run spy satellites and look out for nuclear missile launches are in a different ethical category than people who make software for perpetuating domestic abuse. Clearly, I picked two extremes. That was just to show that not all surveillance is equally bad and that some can be bette…
> people who make software for perpetuating domestic abuse That's a bit like saying the authors of Wordpress perpetuate fake news. I've used similar products to monitor usages on teenager's devices and I can attest to their usefulness far beyond "perpetuating domestic abuse".
(And to be honest even that sounds super creepy. I thank god my parents didn't know my complete internet history and track my every movement 24/7. I can only imagine the helicopter parenting horrors that modern technology is enabling.)
Hell this software goes well beyond that. It records every text, every phone call, every keypress, hijacks the webcam and microphone to secretly record them, etc.
It's extremely common for domestic abusers to use this. I'm having trouble finding it, but I recall in article on HN that domestic abuse shelters are requiring victims to turn off their phones because it's become a problem.
Re: Ethical considerations of access to the HackerOne community
#46Earlier quoted context omitted.
Why exactly is HackerOne drawing a distinction with this software producer? The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance. Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much…
The purpose of the DoD is not to spy on people, it is to protect people. That some actions by some programs and and departments may cross the line legally during certain periods is not that same as an entity whose sole, or majority of goods or services are for, or marketed as being for, an illegal action.
To protect the elites as the other commenter said. Start with the claims of a person who led a bunch of wars after getting Medal of Honor:
https://www.ratical.org/ratville/CAH/warisaracket.html
https://en.wikipedia.org/wiki/Smedley_Butler
The same patterns kept happening over and over from there. The politicians got to play politics. The big, war contractors made billions. Their CEO's millions. After the drafts, the eventual "volunteer" army of mostly poor or working class kept dying for their BS about protecting "freedom" and "democracy." Look up Operation Ajax and compare to how that event is treated today to know plenty about what DOD does in the world. ;)
Re: Ethical considerations of access to the HackerOne community
#47> Companies should defer judgement to the courts rather than make arbitrary moral judgements. Uh, no. Please no. I do not want the courts to arbitrate morality. That's a far far far more dystopian world than one where corporations do (supposing I accept their false dilemma). Companies can, in theory, be created by any person, with any moral alignment. That is not the case with governments (minus authoritarian ones, w…
We just discussed it this morning internally. If you have suggestions on how to formulate such a policy, please email me at marten@hackerone.com.
Thinking out loud, HackerOne stands for and supports the security and integrity of every piece of software code, for transparency and openness, for the sovereignty of each human being connected online, and for fair and equitable principles for all online activity. And probably some other aspects that I didn't think of this exact second.
If anyone has thoughts on this, we are all ears.
Marten
Re: Ethical considerations of access to the HackerOne community
#48Re: Ethical considerations of access to the HackerOne community
#49Earlier quoted context omitted.
To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…
I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.
Because that's mostly my stance on the question "should a project have a code of conduct?": It's overspecifying things because we believe we can control them better the more we're spelling it out.
I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we consider actionable, leaving loopholes for language lawyers (and we nerds have this tendency!) all over the place.
I know that you're strongly in favor of CoCs. Do you see a qualitative difference between those things?
I'll grant that harassment is a much more explosive issue today, but "who is allowed to participate in a bug bounty community" also seems to have potential for bitter quarrels.
Re: Ethical considerations of access to the HackerOne community
#50Earlier quoted context omitted.
Selecting your customers is always tricky. On one hand your right to run your business as you see fit and respecting your principles. On the other hand you have discrimination of all kinds. Think about the recent cases of a small baker with strong religious views refusing to create cakes for gay couples. Think about CloudFlare protecting ISIS sites.
To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…