Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While I'm fine with criticizing them for partial disclosure, I again have a problem mapping any of this back to ethics, because, again, independent researchers do not have an obligation to vendors or to any amorphous public. As long as they aren't literally exploiting (or arranging to have exploited) vulnerabilities to break into people's computers, or lying about what they found, I don't think ethics have much to say about what they should do.


> I don't think ethics have much to say about what they should do.

What does that even mean? What do you think "ethics" means? This is a nonsensical statement.

The consideration of what people in certain situations should or should not do, IS ethics.

Even if someone would say (for some reason) "but researchers should be able to do their work without consideration", that is making an ethical statement.

I understand why you would have a problem mapping this back to ethics, because if you'd formulate it as such, it would sound kind of bad: Researchers have no ethical responsibilities to the public.

You can't choose to not let decisions be guided by ethics, that's like claiming you choose to find your way without navigating. It makes no sense.


No obligation to vendors, no obligation to the public, so what are your ethical standards exactly? It sounds like committing crimes is it, but that’s a legal standard and not an ethical one. At what point are you less of a researcher and more of a sociopath with a keyboard? What makes researching software vulnerabilities such a uniquely non-ethical undertaking compared to all other forms of research?

You seem like a living argument for ethical standards being imposed on your industry, by law if needed.


In exactly what way are you harmed by someone discovering a vulnerability --- that existed whether or not they did the work --- and then telling you about it?

You're arguing that the force of law should prevent you from learning inconvenient things about the software you use.


You are not harmed by someone discovering a vulnerability and telling you about it. Obviously that benefits you rather than harming you.

You are harmed by them discovering a vulnerability and telling the world about it.

And if they discover a vulnerability and tell both you and the rest of the world, the harm may easily outweigh the benefit.

Suppose I go wandering around the city where you live, checking for unlocked house doors. I find that you've left your front door unlocked and gone on holiday. I then wander the streets shouting "Thomas's house is unlocked and no one's at home!". I also phone you up to let you know your house is unlocked.

It was your fault, not mine, that the house was unlocked and no one at home to deter burglars. In principle, anyone else could have come along and burgled your house, if they'd found it before I did. None the less, I think that in this scenario I have done you wrong.


> and then telling you about it?

The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem without their vendor giving out the official solution.


And if I don't want to jump through whatever random hoops message board nerds have erected and just decide not to disclose at all, exactly how are you better off?


From this and other similar responses of yours here I think that you do not have a convincing way to resolve the obvious problem with the absolutist 'i can do whatever i want with my research' stance that people here pointed out to you. So you do whataboutism directed at vendors, misrepresent people's arguments or try to pivot the discussion. Perhaps it is time to write less and let the discussion sink in a little. You may find a better way to argue your point, or even find you no longer want to do that.


I don't think anyone's arguing that a researcher has a responsibility to tell anyone. If they find a vulnerability and then decide to completely shelve it, that's fine (if maybe a little pointless?). But if they do decide to do some kind of disclosure, I (and others) would argue that researchers have an ethical responsibility to do so in a way that they believe will do the least harm.

It's certainly reasonable to argue which kind of disclosure is the best way to achieve minimal harm, but my opinion is that it's unethical to disclose without considering what method of disclosure will do the least harm, or, worse, just not caring and going for the "biggest splash", as is what it seems these researchers did.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: