Register whitehat-security and align operating boundaries

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
This commit is contained in:
tegwick 2026-08-21 22:52:37 +02:00
parent 0ce9f44ff9
commit 348738ba73
9 changed files with 474 additions and 16 deletions

View file

@ -99,8 +99,10 @@ into a liability, so the rule is structural rather than cultural.
**No target is probed without recorded authorization from whoever is
responsible for it. No exceptions.**
- **Our own estate, build mode** — standing authorization, within the declared
scope. This is the current situation.
- **Our own estate, build mode** — standing estate authorization is necessary
but not sufficient. Every live run still needs the dated engagement record,
target-owner acknowledgement and technique-specific scope required by the
rules of engagement. No live target is pre-authorized by this intent.
- **Our own estate, production** — a separate recorded authorization. Build-mode
standing consent does not carry across; the blast radius is different and so
is the decision.
@ -111,10 +113,9 @@ responsible for it. No exceptions.**
Three things that do **not** constitute authorization, written down because
each is a way teams talk themselves into it: a commercial relationship with the
target; the target being publicly reachable; and a belief that the owner "would
obviously be fine with it". Unauthorized probing of someone else's
infrastructure is a criminal matter in most jurisdictions regardless of intent,
and a white-hat facility that gets this wrong is simply an attacker with better
paperwork.
obviously be fine with it". Unauthorized probing may be unlawful regardless of
intent, and a white-hat facility that gets this wrong is simply an attacker
with better paperwork.
**The authorization record is part of the finding.** A report that cannot name
the authorization it ran under is not a finding — it is an incident, and it