Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the response of some corporations when security vulnerabilities are disclosed

There's a big ethical difference between trying to exploit a piece of commercially produced software, and trying to exploit the time and actions of humans who are producing software which is given away for free.



Also, this wasn’t a vulnerability found in existing code that was disclosed. This was an attempt to introduce several of them in the form of innocent looking commits.

I don’t think the free vs commercial aspect is the main issue here; lots of kernel devs are paid for their work after all...


> Also, this wasn’t a vulnerability found in existing code that was disclosed.

You're right that the OP's analogy breaks down if the researchers were unsuccessful in getting their malicious patches accepted, because then there is arguably no vulnerability to report, and OP said "when security vulnerabilities are disclosed".

Steelmanning that analogy, though, what the researchers were doing was "probing for possible vulnerabilities", which some vendors also complain about, especially if the target is an online service rather than software running locally on the researcher's machine.

In that case, the main flaw in the analogy is still the difference between exploiting software and exploiting humans, so I probably should have focused on that. Nevertheless, there is a small ethical difference in some circumstances between software that is bought and software which is freely downloadable (regardless of the licences involved), since if you paid for something which is defective then you might deserve a refund.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: