news.volyx.in

When your classmates threaten you with felony charges (miles.land)

470 points by epoch_100 · 1093 days ago · 321 comments on HN

Article summary

A security researcher shared their experience of receiving a legal threat from classmates who developed an anonymous social media app called Fizz, after the researcher and their friends discovered and disclosed security vulnerabilities in the app. The threat included claims of state and federal law violations and demands for silence in exchange for not pursuing legal action. The researcher, with the help of the Electronic Frontier Foundation, was able to respond to the threat and resolve the situation amicably. The researcher reflected on the experience, highlighting the importance of keeping research above-board and well-documented, staying calm, and seeking legal help when faced with threats.

Main themes

  • security research
  • legal threats
  • vulnerability disclosure
  • good-faith hacking
  • corporate responsibility
  • lawyer ethics
  • cybersecurity policy
  • free speech and transparency

What commenters say

  • Threatening someone with legal action for good-faith security research is a form of legal terrorism and should be subject to professional consequences for the lawyers involved.
  • Lawyers have the right to make persuasive arguments in their clients' favor, including sending demand letters that may be perceived as threats, as long as they are not baseless or extortionate.
  • The line between a legitimate threat and extortion is blurry, and the use of threats to silence security researchers can be seen as a form of bullying.
  • Security researchers who test systems without permission, even with good faith, may still be subject to civil and criminal enforcement.
  • The fact that a company claims to be '100% secure' does not necessarily mean they are committing fraud, as they may be genuinely ignorant of their security vulnerabilities.
  • The use of threats to silence security researchers can have a chilling effect on the discovery and disclosure of vulnerabilities, ultimately harming users and the security community.
  • Demand letters that include threats of legal action can be a standard part of practicing law, but should be used responsibly and not to bully or intimidate individuals.
  • The distinction between legitimate and illegitimate threats is crucial, and the law should provide clearer guidance on what constitutes an acceptable threat in the context of security research and vulnerability disclosure.