logoalt Hacker News

vayuptoday at 4:10 PM4 repliesview on HN

If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.

They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.

Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.

And also, infrastructure vulnerabilities like DNS config - no no, try harder.

I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.

https://www.flocksafety.com/legal/vulnerability-disclosure-p...


Replies

binktoday at 7:42 PM

The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely.

Testing against customers is also a common prohibition for obvious reasons.

ipdashctoday at 6:19 PM

This looks like a pretty reasonable policy to me all things considered. And no, I'm no fan of Flock. But they do run security cameras for the cops, they can't just say go ahead, go wild on all our customers' cameras. The lawyers would throw a fit.

The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.

lenerdenatortoday at 5:57 PM

It'd be interesting to know how much of that they put second to "Americans seem to like using our hardware as targets for firearms, reciprocating saws, spray paint, and garbage bags" in their list of corporate concerns.

dokyuntoday at 5:19 PM

Antisec was right.