Ethical considerations of access to the HackerOne community
61–70 of 70 posts
Re: Ethical considerations of access to the HackerOne community
#62Earlier quoted context omitted.
In the first case, you have an entity that has a proven record of breaking the law (on purpose) using technology. I can also argue that the purpose of DoD now is to protect the elites, from the people, but that's another story. In the second, the legal line is not crossed. It may be crossed at some point by an adult person that can bear responsibility for his actions. I would not work with both; I can understand how…
> Is it the right moral choice to protect the privacy of a cheater? Is this spyware used to find out if someone is cheating? If so, it means you'd install it, and violate their privacy, without knowing if they are a cheater, so the point is moot.
My point is that privacy in a relationship is a relationship thing, and the moral choice for me would be to not interfere in other peoples relationships. This includes not judging you if you use spyware on your wife.
Re: Ethical considerations of access to the HackerOne community
#63Earlier quoted context omitted.
> Is it the right moral choice to protect the privacy of a cheater? Is this spyware used to find out if someone is cheating? If so, it means you'd install it, and violate their privacy, without knowing if they are a cheater, so the point is moot.
I was not referring to the app, but in general to discover a cheater you'll most likely violate their privacy. My point is that privacy in a relationship is a relationship thing, and the moral choice for me would be to not interfere in other peoples relationships. This includes not judging you if you use spyware on your wife.
I'm not sure this is true. There are often clear boundaries, like secretly observing them in public versus accessing their private phones.
> privacy in a relationship is a relationship thing
but it's also a privacy thing. Is domestic abuse a relationship thing? That would also interfere with a relationship.
Re: Ethical considerations of access to the HackerOne community
#64Earlier quoted context omitted.
It's good to have an explicit statement that the spirit of the law is important, and that if you're trying to language-lawyer your way around a code of conduct, you're missing the point. But that doesn't mean there's no value in having clearly laid-out principles, and in particular, clear descriptions of proscribed behavior and protected groups. Because in the absence of that, the same kind of people who would langua…
As soon as you try to give your process the air of "due process" you have lost. You must never get into a debate about it (internally, sure, externally never). You're not a court of law, you're an organization, a club, whatever. This club has officers or a president. Put your foot down and make a dictatorial decision that is only announced, not discussed. You're not recognizing their "right to argue". They cannot "la…
It's worth remembering that people (rightly, I think) get far angrier about breakdowns of due process than the absence of it. Some of the people upset about the Drupal mess recently didn't seem to care much about the specifics of what happened, but were incredibly disturbed that the official process appeared to have been circumvented. At that point it would have been far better to say up front "we make decisions at our discretion, in the manner we choose".
Re: Ethical considerations of access to the HackerOne community
#65Earlier quoted context omitted.
There are a lot of dubious companies on HackerOne. Why did taking a stance on this one have a perceived more positive outcome than taking any stance at all? Pretty much zero of the companies on HackerOne are part of any social responsibility index, shariah compliant index, or trendy b-corporation index. And even in the non-zero rebuttal, the vast majority can have entire dissertations written about weighing the ethic…
shariah compliant index? Did you include that just to question the objective nature of morality?
Standard & Poors operates shariah compliant funds right over in Toronto and is also very popular in many markets.
Maybe it doesn't mean what you think it means, maybe you'll learn
Re: Ethical considerations of access to the HackerOne community
#66Earlier quoted context omitted.
shariah compliant index? Did you include that just to question the objective nature of morality?
B corporations and socially responsible investing are shariah compliant investing rebranded for an islamaphobic audience. Standard & Poors operates shariah compliant funds right over in Toronto and is also very popular in many markets. Maybe it doesn't mean what you think it means, maybe you'll learn
Shariah compliant investing follows specifically and explicitly from a religious moral basis.
SRI seems much more concerned with issues of Social Justice and human welfare, in ways not always inline with Sharia principles.
If you say they are similar, the burden is on you to demonstrate.
Re: Ethical considerations of access to the HackerOne community
#67Earlier quoted context omitted.
I understand what you're writing, and what HackerOne wrote, but to me it pretty much seems like "we won't run a security service for spyware companies". At Matasano, we wouldn't do work for the USG or arms manufacturers. We didn't have a coherent framework to fit that decision into. We just wouldn't do it. I worry that we may be overthinking things here.
I see an parallel to the harassment/CoC discussion: Because that's mostly my stance on the question "should a project have a code of conduct?": It's overspecifying things because we believe we can control them better the more we're spelling it out. I'd prefer a blanket "we're against harassment of any kind and will act if harassment comes to our attention", over many paragraphs trying to spell out what exactly we con…
To me --- and, let's be honest, to pretty much the overwhelming majority of all other people --- it's enough to say "we've decided we're not going to work with spyware companies", just as for the most part it's fine to say "we're not going to work with people who publicly lobby for racism or misogyny"† without connecting the dots on that statement all the way back through Rawls and John Stuart Mill.
I think at present it's a courtesy to announce those kinds of beliefs, preferably in the simplest way possible, just so nobody is shocked when you exercise your prerogative to enforce them. I obviously don't think the resulting "code of conduct" statements need to be formally impregnable.
† You could make the opposite statement as well, as I think at least one project has sort of done implicitly. I don't begrudge anyone that right; why would I bother? If you want to pour kerosene over your professional reputation and light a match, who am I to stop you?
Re: Ethical considerations of access to the HackerOne community
#68Earlier quoted context omitted.
B corporations and socially responsible investing are shariah compliant investing rebranded for an islamaphobic audience. Standard & Poors operates shariah compliant funds right over in Toronto and is also very popular in many markets. Maybe it doesn't mean what you think it means, maybe you'll learn
> B corporations and socially responsible investing are shariah compliant investing rebranded for an islamaphobic audience. Shariah compliant investing follows specifically and explicitly from a religious moral basis. SRI seems much more concerned with issues of Social Justice and human welfare, in ways not always inline with Sharia principles. If you say they are similar, the burden is on you to demonstrate.
Thats the demonstration. Shouldn't bother you that much.
Re: Ethical considerations of access to the HackerOne community
#69Earlier quoted context omitted.
The bugs you're talking about are already worth 5-6 figures. Their prices are so volatile and their outlook is complicated enough that no sane person would enter into a forward contract on one.
Who said OP was a sane person?
Re: Ethical considerations of access to the HackerOne community
#70Earlier quoted context omitted.
Selecting your customers is always tricky. On one hand your right to run your business as you see fit and respecting your principles. On the other hand you have discrimination of all kinds. Think about the recent cases of a small baker with strong religious views refusing to create cakes for gay couples. Think about CloudFlare protecting ISIS sites.
To me, it seems to come down to: 1. there are evil people, but 2. those people frequently have more social power than nice people, and 3. the evil people will use their social power to paint nice people as evil (i.e. "bullying.") If you're defining the laws for a community or society, or the Terms of Use for a piece infrastructure for such a community/society to use—then it behooves you to consider that any "hammers"…
https://www.reddit.com/r/rational/comments/69f7nw/d_friday_o...