Live data from Hacker News

Belgium legalises ethical hacking

law.kuleuven.be

1–10 of 74 posts

Re: Belgium legalises ethical hacking

#3
> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations.

Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer systems there. This will be fascinating to follow.

> The second condition mandates that ethical hackers report any uncovered cybersecurity vulnerability as soon as possible to the Centre for Cyber Security Belgium (CCB), which is the national computer security incident response team of Belgium.

I really hope they will take the opportunity and publish statistics about the reports.

> The final condition is an obligation for ethical hackers to not disclose information about the uncovered vulnerability to a broader public without the consent of the CCB.

Right, I agree with OPs comment, that this is a bummer. Why not let the organization self decide this? Or one-out-of-two? This seems a bit fishy. I hope it works out.

Re: Belgium legalises ethical hacking

#5

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

The context here is "without authorisation of the owner of the system"; if they agree to publication then the additional protections [need to] don't apply

Re: Belgium legalises ethical hacking

#6

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

> Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer systems there.

I doubt it'll deter anyone from running computer systems.

After all, hacking already goes unpunished if it crosses the right jurisdictional borders, or if the attacker can't be traced. And for most attacks both are true so the cops don't do anything.

The only difference this law makes is for in-country hackers who disclose their own identity.

Re: Belgium legalises ethical hacking

#7
post #4

Does this mean anything for the legal protections of Belgian citizens who research security vulnerabilities in foreign, rather than domestic, systems?

No:

> The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

Re: Belgium legalises ethical hacking

#8
post #4

Does this mean anything for the legal protections of Belgian citizens who research security vulnerabilities in foreign, rather than domestic, systems?

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

That part is obvious, if you commit a crime somewhere else, then you commit it somewhere else. The question is whether Belgium protects you as their citizen, or doesn't.

Re: Belgium legalises ethical hacking

#9

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

Good. Make it law in every other country too. You would not believe the amount of duct tape holding systems together; crowd sourcing the inspections would at least get eyeballs on the problems, even if it caused an uptick in security incidents.

(Former pentester @matasano, though only for a little over a year.)

After witnessing the results of over 50 pentests, you’re dragged to the conclusion that (a) companies usually get pentests because they’re forced to by other companies, and (b) the security incidents that do happen tend not to affect the companies themselves.

By (b) I mean “security doesn’t matter,” in the sense that very few companies have ever died from security incidents. The cost is borne by the customers whose data is exposed, not the companies who allowed the breach.

De-legislating cybersecurity will improve security, almost by definition. As you say, you’re forced to secure your systems. This is probably a net positive, and hopefully the experiment in Belgium will show why.

Re: Belgium legalises ethical hacking

#10
post #4

Does this mean anything for the legal protections of Belgian citizens who research security vulnerabilities in foreign, rather than domestic, systems?

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

Any cloud datacenters in Belgium?
Post reply on HN