I am a security researcher. Can I work with Linode?
I am a security researcher. I would like to use your platform for some of my research. What do I need to do to get started?
2 Replies
✓ Best Answer
If you are a security researcher, you probably should read Linode's Terms of Service (ToS) to make sure you're clear on the rules of the road. You can find a copy of the Terms here: https://www.linode.com/tos.
Specific to security research involving pentesting, if you’re running these pen tests on your own systems, you will want to be sure that your technical team is aware of these tests or ensure that any abuse reports are handled internally within your organization, rather than submitting them to the our abuse team.
If you are acting as a third-party pen tester, you will want direct permission from the owner of the network or server that is being pen tested.
You will want to be sure that the pen testing that you’re conducting is legal.
Please note, we don’t permit testing of the Linode infrastructure.
Additionally, you will want to take measures to ensure your testing won’t affect other Linodes such as consuming too much CPU, I/O, or network resources. If your pen testing is affecting the quality of service for other customers, Linode may need to take steps to limit your resource consumption.
That's why we strongly recommend reviewing our Terms of Service before conducting any pen testing on our platform: https://www.linode.com/tos
We would like the internet to be safe and secure for everyone, anything that contributes to the security of the internet as a whole, we would like to encourage. Feel free to reach out to us for additional questions.
Linode does permit security researchers to use their platform, however, it is requested that you submit additional information before starting your research. If you're interested in performing security research from your Linode, please open a Support ticket from the Linode Manager and provide answers to the following questions:
1) What type of research are you doing? Is there more than one kind of test or scan that you do?
2) What is the purpose of this research?
3) Are you conducting this research for a company, a university or for personal use?
4) What effect do you expect this research will have on the systems that are being connected to or scanned?