Hacker News new | past | comments | ask | show | jobs | submit login

Very easy, if its not authorized it's not a pentest or red team operation.

Any pentester or red team considers their profession an ethical one.

By the response of the Linux Foundation, this is clearly not authorized nor falling into any bug bounty rules/framework they would offer. Social engineering attacks are often out of bounds for bug bounty - and even for authorized engagements need to follow strict rules and procedures.

Wonder if there are even legal steps that could be taken by Linux foundation.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: