From e8888b100baace454a25059dd88dcc67934ed916 Mon Sep 17 00:00:00 2001 From: florian-bbs Date: Sun, 10 Apr 2022 19:49:40 +0200 Subject: [PATCH 1/2] added CHE core terms --- regional/CHE-core-terms.md | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 regional/CHE-core-terms.md diff --git a/regional/CHE-core-terms.md b/regional/CHE-core-terms.md new file mode 100644 index 0000000..1446792 --- /dev/null +++ b/regional/CHE-core-terms.md @@ -0,0 +1,19 @@ +# Introduction + +# Expectations + +# Ground Rules + +# Safe Harbor + +Consequences of complying with the Code of Conduct (Legal Safe Harbor) + +1. The owner will not take civil action or file a complaint with law enforcement authorities against participants for accidental, good faith violations of the Code of Conduct + +2. The owner interprets activities by participants that comply with the Code of Conduct as authorized access under the Swiss Penal Code. This includes Swiss Penal Code paragraphs 143, 143bis and 144bis. + +3. The owner will not file a complaint against participants for trying to circumvent the security measures deployed in order to protect the services in-scope for this program. + +4. If legal action is initiated by a third party against a participant and the participant has complied with the Code of Conduct as outlined in this document, the owner will take the necessary measures to make it known to the authorities that such participant’s actions have been conducted in compliance with this policy. + +5. Any non-compliance with the Code of Conduct may result in exclusion from the program. For minor breaches, a warning may be issued. For severe breaches, the organizers reserve the right to file criminal charges. \ No newline at end of file From 19c585b8c4cd702f21d2bba92638ac4835964bc2 Mon Sep 17 00:00:00 2001 From: florian-bbs Date: Sun, 10 Apr 2022 20:03:48 +0200 Subject: [PATCH 2/2] adapted legal safe harbor to match the original disclose terms as close as possible --- regional/CHE-core-terms.md | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/regional/CHE-core-terms.md b/regional/CHE-core-terms.md index 1446792..22f3ce6 100644 --- a/regional/CHE-core-terms.md +++ b/regional/CHE-core-terms.md @@ -6,14 +6,16 @@ # Safe Harbor -Consequences of complying with the Code of Conduct (Legal Safe Harbor) +When conducting vulnerability research according to this policy, we: -1. The owner will not take civil action or file a complaint with law enforcement authorities against participants for accidental, good faith violations of the Code of Conduct +1. will not take civil action or file a complaint with law enforcement authorities against you for accidental, good faith violations of the policy -2. The owner interprets activities by participants that comply with the Code of Conduct as authorized access under the Swiss Penal Code. This includes Swiss Penal Code paragraphs 143, 143bis and 144bis. +2. interpret activities that comply with the policy as authorized access under the Swiss Penal Code. This includes Swiss Penal Code paragraphs 143, 143bis and 144bis. -3. The owner will not file a complaint against participants for trying to circumvent the security measures deployed in order to protect the services in-scope for this program. +3. will not file a complaint against you for trying to circumvent the security measures deployed in order to protect the services in-scope according this policy. -4. If legal action is initiated by a third party against a participant and the participant has complied with the Code of Conduct as outlined in this document, the owner will take the necessary measures to make it known to the authorities that such participant’s actions have been conducted in compliance with this policy. +If legal action is initiated by a third party against you and you have complied with the policy as outlined in this document, we will take the necessary measures to make it known to the authorities that your actions have been conducted in compliance with this policy. -5. Any non-compliance with the Code of Conduct may result in exclusion from the program. For minor breaches, a warning may be issued. For severe breaches, the organizers reserve the right to file criminal charges. \ No newline at end of file +You are expected, as always, to comply with all applicable laws. + +If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further. \ No newline at end of file