5 ms·
I guess the specifics are the letters N, D and A and what they stand for. And the fact that there's absolutely nothing in it for them. Would you even consider
by rroot 4y ago
I guess the specifics are the letters N, D and A and what they stand for. And the fact that there's absolutely nothing in it for them.
Would you even consider signing an NDA if I sent you one? I surely hope not.
- ricardobeat 4y agoThat’s not an answer to the parent’s question. HackerOne has a disclosure process despite the NDA, so what part of the process is the issue? Or is it simply “hackerone bad”?
- jknoepfler 4y agoThey have no interest in signing away their right to disclose the vulnerability at the behest of a private, for-profit entity, because they believe public disclosure of security vulnerabilities is crucial to improving security.
- ImPostingOnHN 4y agoif they have a disclosure process, what purpose is served by the non-disclosure agreement? what with non-disclosure being literally the opposite of disclosure & everything
- tptacek 4y agoThey pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.
- ImPostingOnHN 4y agoright, if you don't like the terms of the NDA, don't agree to it that is precisely the choice made by the team in the article, because the NDA was bad, for the reasons you described so it sounds like everyone is OK with this, the authoring team is just describing that issue, along with other issues, with the bug disclosure process (like lying about there being no vulnerability while simultaneously fixing it)
- thaeli 4y agoThe only reason it's a "thing" is that the reporters in this case were attempting to do a responsible, coordinated disclosure. That's important for their own brand - many clients would be reluctant to hire a security consultant who just dropped 0days without a damn good reason. So this is documentation and justification for why they did a unilateral disclosure - the expectation is that you "show your work" and be clear that you tried to work with the vendor and they wouldn't work with you in good faith so you had no choice but to unilaterally disclose.
- tptacek 4y agoNobody is going to avoid hiring a security consultancy that posts bugs with a coordinated timeline that notes they didn't engage with the bounty program.
- deleted 4y ago[deleted]