4 ms·
"The worst H1 or a client can do is kick you off the platform." As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking
by awirth 7y ago
"The worst H1 or a client can do is kick you off the platform."
As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines. I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a felony.
Now seems a little questionable about if any federal prosecutor would actually take the case, but it definitely doesn't seem like a strictly civil issue to me.
Strongly agree on all other points though.
- tptacek 7y agoI agree, if you're testing someone else's website or servers, you should comply with the scope and disclosure rules or not do the testing, unless the vendor has something else on their website that implicitly authorizes testing (like an email address to send reports to). But that doesn't apply to Steam; nothing they write can really impact your ability to conduct security research on your own computer.
- awirth 7y agoYeah, agree in this specific case about local research (baring DMCA issues). Most H1 scopes seem to be remote targets as opposed to downloadables though.
- busterarm 7y agoAnd this is why many of the researchers I know are based outside of or have left the United States and work out of places like Thailand.
- tptacek 7y agoI'm having trouble thinking of a single researcher that has left the US for legal reasons. There are lots of researchers now in Southeast Asia! But that's because bounty programs like H1 let those people work remotely.
- busterarm 7y agoThere are plenty of researchers not in the US saying "don't do your research in the US". You don't have to get into legal trouble to see which way the wind is blowing.
- anticensor 7y ago> you've retroactively committed a felony. There is no such thing as a retroactive crime in rule of law systems. Disclosure could be a considered an offense in its own, though.
- deleted 7y ago[deleted]
- tptacek 7y agoHow?
- PeterisP 7y agoCFAA could (and likely would) apply for remote vulnerabilities i.e. exploiting SQLi on someone else's servers; but in the case of local privilege escalation like this particular case all the exploiting/testing happens on systems owned and controlled by the researcher, so it doesn't violate CFAA and doesn't need any permission from Valve - the breach happened with authorization from the system owner. You need permission to pentest someone else's systems, you don't need permission to pentest software on your own systems even if that software is written by someone else. In an enterprise setting it's possible that you have signed a contract where you agree not to do such testing or not to publicize its results; but violating that would be a civil matter regarding the terms of that contract, not a felony in respect to CFAA.