Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research
Florian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz, Ben Stock
IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 4
Overview
This talk, "Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research," delivered by Florian Hantke from TSPA and his co-authors, delves into the complex ethical and legal landscape surrounding large-scale server-side scanning in academic security and privacy research. The core premise is that while server-side vulnerabilities constitute a significant and growing threat—as evidenced by reports like the OWASP Top 10 and yearly ENA 1 security assessments—research into their prevalence and impact on a large scale is severely hampered. This talk aims to understand these barriers and propose a framework to enable such crucial research responsibly.

Key moments
- 0:00 Introduction: Ethical and legal challenges of server-side scanning
- 2:08 Why server-side security research faces ethical and legal hurdles
- 3:30 Research methodology: Interviews, surveys, and scanning scenarios
- 6:40 Illustrative scenario: Charlie's user ID manipulation experiment
- 8:00 Legal experts' varied interpretations of access control and legality
- 9:00 Legal experts call for legislative action to enable research
- 9:30 Absence of non-criminal white-hat hacker precedent cases
Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research
Speakers: Florian Hantke, Researcher, TSPA; Sebastian Roth; Rafael Mrowczynski; Christine Utz; Ben Stock
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=sTjepiDEuq4
Overview
This talk, "Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research," delivered by Florian Hantke from TSPA and his co-authors, delves into the complex ethical and legal landscape surrounding large-scale server-side scanning in academic security and privacy research. The core premise is that while server-side vulnerabilities constitute a significant and growing threat—as evidenced by reports like the OWASP Top 10 and yearly ENA 1 security assessments—research into their prevalence and impact on a large scale is severely hampered. This talk aims to understand these barriers and propose a framework to enable such crucial research responsibly.
The importance of this research cannot be overstated. A vast majority of critical security risks, including broken access control, cryptographic failures, and various injection vulnerabilities, originate on the server side. Despite this, existing academic literature predominantly focuses on client-side analysis, or limits server-side investigations to small, controlled datasets. The primary obstacle, as highlighted by prior work, is the fear of legal repercussions and ethical dilemmas, where academic scans could be misconstrued as malicious hacking, leading to civil lawsuits or even criminal prosecution.
Hantke and his team address this by systematically exploring the perspectives of legal experts, research ethics specialists, and server operators. Their goal is to identify the "red lines" that delineate acceptable research practices from those that cause harm, ultimately striving to create a framework that protects both researchers and server operators. This involves a deep dive into differing interpretations of legal statutes, ethical guidelines, and the practical concerns of those managing the scanned systems, culminating in a novel proposal for a pre-registration board to guide and legitimize future server-side scanning research.
Background
▶ Watch: Introduction: Ethical and legal challenges of server-side scanning (0:00)
The landscape of cybersecurity research has long been characterized by a significant disparity between the attention paid to client-side versus server-side vulnerabilities. While client-side issues, such as security headers, client-side XSS, or browser fingerprinting, have been extensively studied through large-scale scans involving thousands of websites, the server side has largely remained uncharted territory at a comparable scale. This imbalance is particularly concerning given that numerous authoritative reports, including the OWASP Top 10, consistently identify server-side vulnerabilities like Broken Access Control, Cryptographic Failures, and various forms of Injection (e.g., SQL injection, code injection) as the most prevalent and impactful threats. The ENA 1 security reports, cited in the talk, further underscore that the majority of vulnerabilities reside on the server.
The reluctance to conduct large-scale server-side scanning research stems from significant ethical and legal challenges. In many jurisdictions, probing server-side systems without explicit permission can be legally interpreted as unauthorized access or even malicious hacking, regardless of the researcher's intent. The potential for causing unintended harm—such as server crashes, data exposure, or service disruption—carries the risk of severe civil lawsuits and, in some cases, criminal prosecution for the researchers and their institutions. This creates a chilling effect, deterring academics from pursuing vital research that could lead to a better understanding and mitigation of widespread server-side risks.
Existing server-side research often relies on small, controlled datasets, such as open-source application catalogs like Bitnami, which, while valuable, do not accurately reflect the diversity and scale of vulnerabilities present in the wild. The lack of a clear framework or established guidelines for conducting large-scale server-side scans ethically and legally has perpetuated this research gap. The academic community, despite having institutional review boards (IRBs) or research ethics committees (RECs), finds these bodies often ill-equipped to handle the specific nuances of security research that involves interacting with external, potentially unconsenting, systems. This talk addresses this critical void by seeking to define the boundaries and establish a collaborative framework for legitimate server-side security research.
Key Findings
▶ Watch: Research methodology: Interviews, surveys, and scanning scenarios (3:30)
The research conducted by Hantke et al. yielded crucial insights into the divergent perspectives of legal experts, ethics specialists, and server operators regarding large-scale server-side scanning. These findings collectively highlight the need for a paradigm shift in how such research is approached and regulated.
From the legal experts' perspective, a primary challenge lies in the interpretation of access control in ambiguous scenarios. When presented with the "Charlie" scenario, where a researcher modifies their own user ID in a request to access or change another user's data, experts debated whether a user ID itself constitutes an access control mechanism. Some argued that if a standard internet user wouldn't know how to manipulate a user ID, it might not count as access control in the traditional sense, while others disagreed. However, there was universal agreement that any form of data manipulation via a POST request would be unequivocally illegal. A significant finding was the consensus that legislative actions are required to create exceptions for academic security research, ideally on an international scale, given the global nature of the web. Interestingly, the researchers found no non-criminal precedent cases against white-hat hackers in Germany at the time of writing, suggesting that such cases are typically closed before trial.
Ethics specialists expressed concerns about the potential for harm. In the Charlie scenario, a GET request (to retrieve data) was generally considered less harmful than a POST request (to change data). Acceptance of GET requests was contingent on the researcher having a robust process for handling any sensitive data gathered. A recurring question from ethics committees was "Is there a reason Charlie didn't create two accounts?" This points to their desire for researchers to engage in ethical discourse, explaining their methodological choices and demonstrating a clear balancing of potential harm against benefits. Experts also criticized the current system where ethical decisions are often made after the research has been conducted, and highlighted the lack of specific ethical guidelines tailored for security research involving external systems.
Server operators, the most directly affected party, presented a surprisingly open stance. A quantitative survey with 119 respondents revealed that a majority (numbers from the "Dolly" scenario, similar to Charlie's GET) would accept researchers conducting experiments like the GET request. Moreover, a significant 27-28% of operators were also amenable to the POST request scenario, with one interviewer stating, "at the end of the day, the bad guys do it," implying a pragmatic recognition of the value of research. However, operators overwhelmingly preferred to be asked for consent before scans, a preference that clashes with the feasibility of large-scale studies. While most indicated they would first seek direct communication with researchers if they detected suspicious activity, some stated they would be legally obligated by their employers to file formal complaints.
Overall, the key findings underscore a disconnect between the necessity of server-side security research, the legal frameworks, the existing ethical review processes, and the practical realities and willingness of server operators. The study clearly demonstrates that while operators are generally supportive, current systems lack the transparency and pre-emptive engagement mechanisms required to facilitate ethical and legal large-scale scanning research.
Technical Deep Dive
▶ Watch: Illustrative scenario: Charlie's user ID manipulation experiment (6:40)
While the talk itself focuses on the meta-level challenges of ethical and legal research, its "technical deep dive" lies in the rigorous methodological design employed to gather these insights, and the technical nature of the scenarios used to probe expert opinions. The researchers utilized a mixed-methods approach, combining qualitative and quantitative data collection to construct a comprehensive view of the problem.
The qualitative component involved 24 semi-structured, problem-centered interviews. These interviews were strategically distributed among legal professionals, research ethics committee (REC) members, and server operators. The legal and ethics interviews were structured as expert interviews, aiming to reconstruct their specialized knowledge concerning server-side scanning. Given the jurisdictional variations in law, the legal scope was narrowed to German law, providing a concrete legal framework for discussion. The operator interviews, conversely, sought to understand their mindsets and opinions on the practical implications of such research.
A crucial element across all interviews and the subsequent quantitative survey was the use of five example server-side scanning scenarios, presented as vignettes. These scenarios were carefully designed to cover a wide range of potential server-side scanning research, drawing from widely exploited real-world vulnerabilities such as SQL injections or invalid HTTP headers that could lead to server crashes. Each scenario was assigned a fictional security researcher's name to personalize the narrative.
The talk highlighted the "Charlie" scenario as a representative example:
- Charlie's Scenario: A fictional researcher, Charlie, targets a social media platform.
- Experiment 1 (GET Request): Charlie changes their own user ID in a GET request (e.g.,
GET /profile?id=CHARLIE_ID) to an arbitrary other user's ID (e.g.,GET /profile?id=OTHER_USER_ID) to receive data belonging to that other user. This specifically probes broken access control and information disclosure vulnerabilities. - Experiment 2 (POST Request): In a second experiment, Charlie modifies their own user ID in a POST request (e.g.,
POST /update_profile, withuser_id=CHARLIE_IDin the body) to another user's ID (e.g.,user_id=OTHER_USER_ID) to change data belonging to that other user. This directly investigates data manipulation and more severe forms of broken access control.
For analyzing the qualitative interview data, the researchers employed qualitative content analysis with a flexible approach. An initial set of codes was derived from the interview guides, which was then enriched during the initial coding stages until the codebook became saturated. Three team members, comprising two computer scientists (one also holding a degree in German law) and a social scientist, coded all interview transcripts in three consecutive stages. After each stage, codings were compared and discussed to achieve inter-subjective agreement. This interdisciplinary team composition ensured a robust analysis from both technical and socio-legal perspectives. Key categories were identified through this process, allowing for systematic comparison across interviews and the identification of commonalities and differences. Memos written on these main topics formed the foundation for the findings.
The quantitative component involved a survey study with operators, yielding 119 fully completed questionnaires. The results of this survey were analyzed using descriptive statistics to complement and triangulate the qualitative findings, providing a broader statistical perspective on operator acceptance and concerns.
This meticulous methodological design, particularly the use of technically grounded vignettes and a multi-stage, interdisciplinary coding process, represents the "technical deep dive" of this research. It demonstrates a sophisticated approach to collecting, analyzing, and interpreting complex qualitative and quantitative data to address a pressing, yet underexplored, problem in cybersecurity research ethics.
Demo / Proof of Concept
▶ Watch: Legal experts call for legislative action to enable research (9:00)
This particular talk did not feature a traditional technical demonstration or a live proof of concept of a server-side exploit. Instead, the "demonstration" of their research methodology and its effectiveness lay in the careful construction and presentation of the five server-side scanning scenarios (vignettes) to the legal experts, ethics specialists, and server operators. The "proof of concept" was the successful elicitation of diverse and nuanced responses from these stakeholders, which formed the empirical basis for their findings and proposed solutions.
The Charlie scenario, as detailed in the "Technical Deep Dive," served as a prime example of how these vignettes operated. By presenting a concrete, technically plausible sequence of actions—modifying a user ID in GET and POST requests to access or alter another user's data—the researchers effectively simulated potential research activities. The responses gathered from the 24 interviewees and 119 survey participants to these carefully crafted scenarios served as the "proof" that their methodology could effectively map out the ethical and legal "red lines" and identify the concerns of affected parties. This approach, while not a code-level demo, was critical for validating the research questions and informing the proposed solutions.
Defensive Implications
▶ Watch: Absence of non-criminal white-hat hacker precedent cases (9:30)
The findings of this research carry significant implications for server operators and the broader defensive community, shifting the focus from simply patching vulnerabilities to understanding and engaging with the ecosystem of security research.
Firstly, the study reveals that a substantial portion of server operators are surprisingly open to legitimate security research, even when it involves probing their systems. While they prefer to be asked for consent, this willingness, particularly from 27-28% of operators being okay with even data manipulation (POST) scenarios, suggests that researchers are not universally viewed as adversaries. This insight should encourage defenders to consider establishing clearer communication channels and policies for engaging with white-hat researchers.
Secondly, the overwhelming preference for transparency and consent from operators highlights a critical gap in current research practices. Defenders need mechanisms to distinguish between malicious attacks and legitimate academic scans. The proposed pre-registration board directly addresses this by offering a centralized platform where researchers can register their studies, including their scanning time slots, IP ranges, and contact details. This would empower operators to:
- Verify the origin of suspicious scans: By cross-referencing activity logs with the board's registry, defenders could quickly ascertain if a scan is part of a known academic study or a genuine threat.
- Establish direct communication: The provision of researcher contact details would allow operators to reach out directly with questions or concerns, fostering dialogue rather than immediate legal action.
- Opt-out of studies: A pre-registration board could also maintain a list of companies that wish to opt out of research, allowing researchers to respect these preferences proactively, thereby reducing the risk of accidental harm or legal disputes.
Thirdly, the legal discussions around whether a user ID can constitute an access control mechanism underscore the importance of robust access control mechanisms for all parameters, even those that seem trivial or internal. The fact that experts debated this point suggests that developers and security teams should err on the side of caution, ensuring that any parameter used for identification or state management is protected by proper authorization checks, regardless of how "standard internet users" might perceive its manipulability. This reinforces the need for comprehensive security architecture reviews beyond just well-known attack vectors.
Finally, the critique from ethics experts that decisions are often made after research is conducted implies that defenders might also be reacting post-incident rather than proactively engaging. By supporting initiatives like the pre-registration board, defenders can contribute to a framework that encourages ethical foresight and minimizes the potential for harm, ultimately fostering a more collaborative environment where researchers can help identify vulnerabilities without being perceived as threats. This proactive engagement, coupled with internal policies for handling legitimate research inquiries, could significantly enhance an organization's overall defensive posture against both malicious actors and unintended consequences of research.
Key Takeaways
- Legislative Action is Crucial: Existing laws in many countries, particularly Germany as explored, are not conducive to large-scale server-side security research. International legislative changes are needed to create exceptions for ethical academic work.
- Operators Are Open, But Demand Transparency: Server operators are generally willing to support security research, even for potentially impactful scenarios, but they overwhelmingly desire transparency, pre-notification, and options for consent or opting out.
- Current Ethical Review Processes Are Inadequate: Traditional Institutional Review Boards (IRBs) or Research Ethics Committees (RECs) are often ill-equipped to handle the specific ethical considerations of security research involving external systems, frequently making decisions after research is conducted.
- A Pre-Registration Board is a Viable Solution: The proposed pre-registration board, acting as a trusted third party, could bridge the gap by reviewing ethical and legal aspects before research execution, providing transparency (IP ranges, contact details), and facilitating opt-out mechanisms.
- Ethical Discourse and Harm-Benefit Balancing are Essential: Researchers must engage in a clear ethical discourse, justifying their methodologies and meticulously balancing the potential for harm against the societal benefits of their findings.
- User IDs Can Be Access Control: The debate among legal experts on whether a user ID constitutes an access control mechanism highlights the need for robust authorization checks on all parameters, reinforcing fundamental security principles for developers and defenders.
About the Speaker(s)
The primary presenter for this talk was Florian Hantke from TSPA. He introduced his colleague Rafael Mrowczynski as being mainly responsible for the methodological design of the study. The work was also a collaborative effort with three other fantastic co-authors: Christina Utz, Sebastian Roth, and Ben Stock. While specific titles and companies for all co-authors beyond Florian Hantke's affiliation with TSPA were not detailed in the transcript, their collective expertise in computer science, social science, and German law was highlighted as crucial to the interdisciplinary nature of this research. Their combined efforts explored the complex ethical and legal dimensions of server-side security research.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research meticulously dissects the critical ethical and legal barriers crippling large-scale server-side security research. By engaging legal, ethical, and operational stakeholders, it not only defines the 'red lines' but also proposes a novel, actionable pre-registration board to enable crucial white-hat scanning, shifting the conversation from fear to legitimate, transparent inquiry. This isn't just a paper; it's a blueprint for fixing a fundamental gap in our collective defensive posture.
Heather Calloway (CISO) — STRONG ACCEPT
This research meticulously maps the ethical and legal 'red lines' hindering critical server-side vulnerability research. It proposes a pre-registration board, offering a pragmatic path to enable vital security insights while respecting operator concerns. This is a crucial step towards institutionalizing responsible research that directly impacts our understanding of systemic risk.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024