pull down to refresh

ariard

With all the current hacks, I’m often asked at local meetups what are the ethical guidelines when you have to do responsible disclosures to a vendor, especially when there is real money on the line. To have been in the situation few times in the pre-LLM era w.r.t bitcoin L2s security research, e.g with things like CVE-2020-26895 which would have been easy to exploit for direct gain, one’s become very familiar with the rules in the infosec community, and more strictly the legal redlines.

So let’s said it clearly about the Liquid situation going to exploit a known vulnerability under the motivation to protect users funds, and keeping a substantial amount as a self-granted bounty is clearly theft, if not on the legal dimension, at the very least on an ethical ground. Indeed, it is laudable to have sent back the wide majority funds, and this is clear act that the person or the group of person acting, are not completely assholes or malevolent. Still, it’s okay to withhold users funds as a self-appointed bounty and we should not make a bad precedent of it.

Of course, the bitcoin network is living in the cypherpunk lalaland and on the wide and wild Internet there are no unified set of social rules, so generally we have only sheer ethics and principles as raw belt-and-suspenders in this kind of situations. In matters of ethics, there is the basic “Silver” rule, “do not treat others in ways that you would not like to be treated”. Somehow, I believe this rule has some universal scope, i.e whatever the culture you’ve grown within, it’s a bit valuable.

...read more at delvingbitcoin.org

Ethics should come before the reward. Good read.

reply
even if the vendor has been particularly disagreeable, condescending or lazy it doesn’t create a safe habor to justify anything

Thanks @theariard

reply