logoalt Hacker News

giancarlostoro • today at 5:59 PM • 1 reply • view on HN

What's worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded / tax funded papers) Which is even worse, I think I'd be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.

There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.


Replies

elmer2 • today at 6:32 PM

"all he did was scrape PDFs for mostly public funded / tax funded papers"

He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.

We shouldn't support theft and he should have gotten some jail time/punishment for it.

"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."

Too many 'security researchers' demand money or threaten to release the vulnerabilities.

I don't know anyone that got into trouble going through a legit bug bounty program.

➕ show 1 reply