Live data from Hacker News

Ethical considerations of access to the HackerOne community

hackerone.com

31–40 of 70 posts

Re: Ethical considerations of access to the HackerOne community

#31
post #27
post #21

Earlier quoted context omitted.

To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…

I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.

I wasn't so much suggesting a decision-making framework, as a model that can be used to understand decisions people make intuitively. "Overthinking" is the whole point. :)

Re: Ethical considerations of access to the HackerOne community

#32
post #27
post #21

Earlier quoted context omitted.

To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…

I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.

> We just wouldn't do it. I worry that we may be overthinking things here.

I agree that going with your gut feeling is very likely good enough, but I don't agree with the term "overthinking". I think codifying the decision a bit is beneficial, as any of us is likely to run into a case that falls into a gray area, and having more fleshed-out decision lines will be helpful in that case.

I think it's the same in ethics vs morals. The ethics you inherited from society will be good enough for the vast majority of decisions, but sometimes it's good to logically deduce morality for yourself. You might realize you used to believe things that didn't stand to reason.

Re: Ethical considerations of access to the HackerOne community

#33
post #5

I looked through the task manager of a corporate issued laptop and saw tasks belonging to very similar companies, as part of the disk image IT makes. The corporation likely has a license for the software, as well as conditions for all their employees to expect monitoring. A formalized bug bounty program would enable the software producer to have secure software. Why exactly is HackerOne drawing a distinction with thi…

Why exactly is HackerOne drawing a distinction with this software producer? The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance. Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much…

[deleted]

Re: Ethical considerations of access to the HackerOne community

#34
post #28

While I applaud this move, I suspect H1 will continue servicing government and law enforcement clients of all kinds. A consistently applied policy would see ties with ALL surveillance entities severed.

This is going to earn me huge downvotes, but not all surveillance is equally illegal or equally unethical. To me it seems that groups that run spy satellites and look out for nuclear missile launches are in a different ethical category than people who make software for perpetuating domestic abuse. Clearly, I picked two extremes. That was just to show that not all surveillance is equally bad and that some can be bette…

> people who make software for perpetuating domestic abuse

That's a bit like saying the authors of Wordpress perpetuate fake news.

I've used similar products to monitor usages on teenager's devices and I can attest to their usefulness far beyond "perpetuating domestic abuse".

Re: Ethical considerations of access to the HackerOne community

#35
post #25

Earlier quoted context omitted.

Why exactly is HackerOne drawing a distinction with this software producer? The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance. Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much…

The purpose of the DoD is not to spy on people, it is to protect people. That some actions by some programs and and departments may cross the line legally during certain periods is not that same as an entity whose sole, or majority of goods or services are for, or marketed as being for, an illegal action.

Hahahahahahaha

Just some bad apples right?

Hahahahahahaha

Re: Ethical considerations of access to the HackerOne community

#36
post #2

Coming soon, a public market in bugs? How soon can I buy futures in Windows vulnerabilities?

This sounds like a very interesting theme for a novel (or novels).

Could even make it kinda like a subgenre of cyberpunk or like a modern version of it at least.

I mean, I can imagine some interesting plots regarding people trading bugs in an underground market, where the product is something that can be more dangerous than a gun, but it fits in a USB drive.

Maybe they can even be based on real stories, just changed a bit to protect identities and such. However I do think you would need to be fairly involved in this world to be able to write something interesting and based on something real.

Hopefully someone involved in the security world gets bitten by the writer's bug and writes something some day. I know Brian Krebs has written interesting articles but a book would be very cool.

Re: Ethical considerations of access to the HackerOne community

#37
post #28

Earlier quoted context omitted.

This is going to earn me huge downvotes, but not all surveillance is equally illegal or equally unethical. To me it seems that groups that run spy satellites and look out for nuclear missile launches are in a different ethical category than people who make software for perpetuating domestic abuse. Clearly, I picked two extremes. That was just to show that not all surveillance is equally bad and that some can be bette…

> people who make software for perpetuating domestic abuse That's a bit like saying the authors of Wordpress perpetuate fake news. I've used similar products to monitor usages on teenager's devices and I can attest to their usefulness far beyond "perpetuating domestic abuse".

The makers of wordpress don't say "great for fake news", but the makers of this software say "great for watching your partner".

They advertise reading your wife's SMS messages as a feature!

That and Wordpress would only be so-so for making a fake news page, I mean it could work but you would be a competitive disadvantage.

Re: Ethical considerations of access to the HackerOne community

#38
post #14

Earlier quoted context omitted.

Nah, the bugs are already traded underground. The nature of the situation means the bets might be done underground, too.

To settle those bets, you have to have a reliable spot price. The only way to know how much a Windows RCE is worth is to actually sell it.

Good point.

Re: Ethical considerations of access to the HackerOne community

#39
post #25

Earlier quoted context omitted.

Why exactly is HackerOne drawing a distinction with this software producer? The truth is: because a H1 rep went on Risky Business and did not deliver a very good performance. Patrick, who is absolutely okay with H1 having FiveEye clients like the US DoD, has a very serious problem with them also servicing an obscure spyware application provider. Because, I suppose, being murder-droned by a panopticon hegemony is much…

The purpose of the DoD is not to spy on people, it is to protect people. That some actions by some programs and and departments may cross the line legally during certain periods is not that same as an entity whose sole, or majority of goods or services are for, or marketed as being for, an illegal action.

In the first case, you have an entity that has a proven record of breaking the law (on purpose) using technology. I can also argue that the purpose of DoD now is to protect the elites, from the people, but that's another story.

In the second, the legal line is not crossed. It may be crossed at some point by an adult person that can bear responsibility for his actions.

I would not work with both; I can understand how can one not be a hypocrite by choosing to work with the latter and not the former, but not the other way around.

Is it the right moral choice to protect the privacy of a cheater? Maybe, I don't know, I'm struggling to answer that to myself, let alone judge others.

Re: Ethical considerations of access to the HackerOne community

#40
post #27
post #21

Earlier quoted context omitted.

To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…

I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.

The only question I have, in this particular case is: what about the victims of the original app? Are they possibly the subject of re-victimization if the app on their device is compromised further by 3rd parties?

Though I completely agree with HackerOne's moral stance here, does this particular scenario complicate things?

EDIT: I do see they took this into consideration in their writeup... still curious.

Post reply on HN