Live data from Hacker News

Ethical considerations of access to the HackerOne community

hackerone.com

51–60 of 70 posts

Re: Ethical considerations of access to the HackerOne community

#51
post #49
post #27

Earlier quoted context omitted.

I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.

I see an parallel to the harassment/CoC discussion: Because that's mostly my stance on the question "should a project have a code of conduct?": It's overspecifying things because we believe we can control them better the more we're spelling it out. I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we con…

> I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we consider actionable, leaving loopholes for language lawyers (and we nerds have this tendency!) all over the place.

Thank you, you succintly worded my main issue with CoCs and why I much prefer "Community rules: Don't be an asshole" over "Community rules: [3 pages]".

I have yet to see a single situation faithfully resolved with the latter that couldn't have been with the former.

Re: Ethical considerations of access to the HackerOne community

#52
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

What's so refreshing about their post is that they admit not to have an unassailable "moral high ground". They highlight the strongest arguments, including those arguing against their decision.

They do this because they recognise that decisions often have competing trade-offs, nuances, ambiguity. There is, unfortunately, almost no recognition of this fact in public these days. You're expected to pick a side, defend it, and attack others, using whatever rhetorical tool is available.

Among those tools of destructive debate: reducing any ambiguity in your favour, i. e. "They are banning Z, and I don't know Z, so I'll argue that Z is like A and banning A would be wrong". Or, equally bad, the slippery slope: "Z may be bad, but you can't give me an algorithm that unambiguously distinguishes Z and Y, nor Y and X, or, by transitivity, Z and A. Therefore, you can't ban Z without also eventually banning A, and that would be bad".

Re: Ethical considerations of access to the HackerOne community

#53
post #11

> Companies should defer judgement to the courts rather than make arbitrary moral judgements. Uh, no. Please no. I do not want the courts to arbitrate morality. That's a far far far more dystopian world than one where corporations do (supposing I accept their false dilemma). Companies can, in theory, be created by any person, with any moral alignment. That is not the case with governments (minus authoritarian ones, w…

Thanks tetrep. I agree with your statement "would be a good time for HackerOne to write this stuff down". We just discussed it this morning internally. If you have suggestions on how to formulate such a policy, please email me at marten@hackerone.com. Thinking out loud, HackerOne stands for and supports the security and integrity of every piece of software code, for transparency and openness, for the sovereignty of e…

Don't get suckered into trying to write a 'clear set of guidelines' or a 'comprehensive community policy' or whatever they want to call it. 10 times out of 10, the people asking for such things are either looking to pin you on your own texts through language lawyering or are incapable of independent thought - not the sort of people you want to deal with anyway. The whole faux 'justice' (of this sort) rhetoric is just that - the upholding of an illusion of 'fairness', where that 'fairness' is a juvenile understanding of 'equal treatment no matter what', just like those who think that majority decisions are always right because they're 'democratic'.

The correct response is that of when people tried this trick on the SCOTUS when they asked it 'what is porn'. There, and here, the correct answer is: "I can't define it, but I recognize it when I see it." This of course is a deeply unsatisfying answer to people who can't (or won't) think for themselves, and doubly so for the aspi types that inhabit the interwebs in disproportionate numbers.

Re: Ethical considerations of access to the HackerOne community

#55
post #49
post #27

Earlier quoted context omitted.

I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.

I see an parallel to the harassment/CoC discussion: Because that's mostly my stance on the question "should a project have a code of conduct?": It's overspecifying things because we believe we can control them better the more we're spelling it out. I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we con…

It's good to have an explicit statement that the spirit of the law is important, and that if you're trying to language-lawyer your way around a code of conduct, you're missing the point.

But that doesn't mean there's no value in having clearly laid-out principles, and in particular, clear descriptions of proscribed behavior and protected groups. Because in the absence of that, the same kind of people who would language-lawyer in the presence of a code of conduct will try to slickly excuse their behavior as acceptable in the absence of one.

Some of the most insidious people around will be superficially nice to someone's face (some of the time), while taking the time in a policy process to calmly and politely inquire if it would be reasonable to treat people like them as subhuman, with ever so much justification and honeyed words. Head it off in advance, set a line for what you expect, and don't assume that "be nice to each other" will make everyone feel safe and welcome.

Re: Ethical considerations of access to the HackerOne community

#56
post #49

Earlier quoted context omitted.

I see an parallel to the harassment/CoC discussion: Because that's mostly my stance on the question "should a project have a code of conduct?": It's overspecifying things because we believe we can control them better the more we're spelling it out. I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we con…

It's good to have an explicit statement that the spirit of the law is important, and that if you're trying to language-lawyer your way around a code of conduct, you're missing the point. But that doesn't mean there's no value in having clearly laid-out principles, and in particular, clear descriptions of proscribed behavior and protected groups. Because in the absence of that, the same kind of people who would langua…

> Some of the most insidious people around will be superficially nice to someone's face (some of the time), while taking the time in a policy process to calmly and politely inquire if it would be reasonable to treat people like them as subhuman, with ever so much justification and honeyed words.

This much is true. Do codes of conduct help or hinder such efforts, on the whole?

When two people are in conflict (which is really the only case that matters), popular codes of conduct seem to favour the person who can best convince that the conflicting behaviour on their part is part of their identity while that on the other person's part is just them choosing to be mean. I'm not at all convinced that this consistently favours the person we should be favouring.

Re: Ethical considerations of access to the HackerOne community

#57
post #49

Earlier quoted context omitted.

I see an parallel to the harassment/CoC discussion: Because that's mostly my stance on the question "should a project have a code of conduct?": It's overspecifying things because we believe we can control them better the more we're spelling it out. I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we con…

It's good to have an explicit statement that the spirit of the law is important, and that if you're trying to language-lawyer your way around a code of conduct, you're missing the point. But that doesn't mean there's no value in having clearly laid-out principles, and in particular, clear descriptions of proscribed behavior and protected groups. Because in the absence of that, the same kind of people who would langua…

As soon as you try to give your process the air of "due process" you have lost. You must never get into a debate about it (internally, sure, externally never).

You're not a court of law, you're an organization, a club, whatever. This club has officers or a president.

Put your foot down and make a dictatorial decision that is only announced, not discussed.

You're not recognizing their "right to argue". They cannot "lawyer" if there is no venue open to them. Ignore their complaints on Facebook or whatever.

Re: Ethical considerations of access to the HackerOne community

#58
post #24

Earlier quoted context omitted.

You're being obtuse if you think this use-case wasn't a huge part of their thinking while designing the software and offering support to customers. >I asked a FlexiSpy salesperson a simple question: If I wanted to, could I use their spyware to snoop on my wife's cellphone without her knowing? The answer each time was yes. When asked if it was legal, they responded with a canned disclaimer explaining it was necessary…

I have no doubt it is what they're selling. But the question is if the tool does something, then the marketing message shouldn't really be relevant. If a FlexiSpy clone comes along and is less direct about spouse-spying, and plays a stronger line of "you need authorization", then it's suddenly OK?

Many tools have legitimate and illegitimate uses. There is rarely a clear sharp line; we have to make a judgement as to whether a given tool does more harm than good, on the whole, and there are no shortcuts. IMO it's entirely right to weigh the marketing message in that balance; after all, the marketing will by design affect what kind of people buy the tool with what kind of intentions.

Re: Ethical considerations of access to the HackerOne community

#59
post #30
post #7

Earlier quoted context omitted.

That's helpful feedback on missing context from our post. Thanks. This series by VICE articulates the sometimes subtle distinctions between legitimate monitoring software built for enterprises and parents vs this particular software (which they deem "stalkerware"). https://motherboard.vice.com/en_us/article/inside-stalkerwar...

There are a lot of dubious companies on HackerOne. Why did taking a stance on this one have a perceived more positive outcome than taking any stance at all? Pretty much zero of the companies on HackerOne are part of any social responsibility index, shariah compliant index, or trendy b-corporation index. And even in the non-zero rebuttal, the vast majority can have entire dissertations written about weighing the ethic…

shariah compliant index?

Did you include that just to question the objective nature of morality?

Re: Ethical considerations of access to the HackerOne community

#60
post #39
post #25

Earlier quoted context omitted.

The purpose of the DoD is not to spy on people, it is to protect people. That some actions by some programs and and departments may cross the line legally during certain periods is not that same as an entity whose sole, or majority of goods or services are for, or marketed as being for, an illegal action.

In the first case, you have an entity that has a proven record of breaking the law (on purpose) using technology. I can also argue that the purpose of DoD now is to protect the elites, from the people, but that's another story. In the second, the legal line is not crossed. It may be crossed at some point by an adult person that can bear responsibility for his actions. I would not work with both; I can understand how…

> Is it the right moral choice to protect the privacy of a cheater?

Is this spyware used to find out if someone is cheating? If so, it means you'd install it, and violate their privacy, without knowing if they are a cheater, so the point is moot.

Post reply on HN