5 ms·
Anybody know their problems with the terms at HackerOne? I admit I don't know HackerOne's term exactly and I'm not that good at reading legalese.
by thisdrunkdane 4y ago
Anybody know their problems with the terms at HackerOne? I admit I don't know HackerOne's term exactly and I'm not that good at reading legalese.
- deleted 4y ago[deleted]
- red_trumpet 4y agoA bit speculative, but the word "NDA" appears four times in their post.
- marcinzm 4y agoI believe HackerOne has some restrictions on disclosure as with an NDA approval is needed.
- thisdrunkdane 4y agoYea I noticed that, but what do they specifically not like about the NDA? afaik, HackerOne still makes vulnerability disclosure possible (and automatic if taking too long?)
- rroot 4y agoI guess the specifics are the letters N, D and A and what they stand for. And the fact that there's absolutely nothing in it for them. Would you even consider signing an NDA if I sent you one? I surely hope not.
- ricardobeat 4y agoThat’s not an answer to the parent’s question. HackerOne has a disclosure process despite the NDA, so what part of the process is the issue? Or is it simply “hackerone bad”?
- jknoepfler 4y agoThey have no interest in signing away their right to disclose the vulnerability at the behest of a private, for-profit entity, because they believe public disclosure of security vulnerabilities is crucial to improving security.
- ImPostingOnHN 4y agoif they have a disclosure process, what purpose is served by the non-disclosure agreement? what with non-disclosure being literally the opposite of disclosure & everything
- tptacek 4y agoThey pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.
- ImPostingOnHN 4y agoright, if you don't like the terms of the NDA, don't agree to it that is precisely the choice made by the team in the article, because the NDA was bad, for the reasons you described so it sounds like everyone is OK with this, the authoring team is just describing that issue, along with other issues, with the bug disclosure process (like lying about there being no vulnerability while simultaneously fixing it)
- thaeli 4y agoThe only reason it's a "thing" is that the reporters in this case were attempting to do a responsible, coordinated disclosure. That's important for their own brand - many clients would be reluctant to hire a security consultant who just dropped 0days without a damn good reason. So this is documentation and justification for why they did a unilateral disclosure - the expectation is that you "show your work" and be clear that you tried to work with the vendor and they wouldn't work with you in good faith so you had no choice but to unilaterally disclose.
- deleted 4y ago[deleted]
- vorpalhex 4y agoNDAs are expensive to review, usually over broad and always badly written. Just say no to NDAs.
- rodgerd 4y agoThere have been claims that companies are abusing the HackerOne NDA process to cover up security issues: refuse to acknowledge a problem, but weild the NDA to prevent disclosure of the supposed non-existent disclosure.