Hacker News new | ask | show | jobs
by nannal 1008 days ago
I wasn't clear on the verification performed to ensure the client had authority to perform testing against the chosen target.
1 comments

You have to verify user.
I think you misunderstand the concern, suppose a user enters gov.mil as a domain to test with which they are unaffiliated.

The tools test it and with disastrous affect all governmental and military services go offline.

It would be reasonable to then take legal action against the platform rather than the user, as the user did not confirm they had permission to perform testing or that they understood the risks involved.