Does this mean anything for the legal protections of Belgian citizens who research security vulnerabilities in foreign, rather than domestic, systems?
No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.
Belgium legalises ethical hacking
11–20 of 74 posts
Re: Belgium legalises ethical hacking
#12Earlier quoted context omitted.
No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.
So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?
Belgium can’t give you a license to commit a crime in another country.
Re: Belgium legalises ethical hacking
#13Earlier quoted context omitted.
No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.
Any cloud datacenters in Belgium?
Re: Belgium legalises ethical hacking
#14Re: Belgium legalises ethical hacking
#15Earlier quoted context omitted.
So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?
Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.
Re: Belgium legalises ethical hacking
#16Re: Belgium legalises ethical hacking
#17Earlier quoted context omitted.
No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.
Any cloud datacenters in Belgium?
Re: Belgium legalises ethical hacking
#18Earlier quoted context omitted.
So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?
Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.
Re: Belgium legalises ethical hacking
#19Some progress but with some notable weaknesses (a state institution determines whether public disclosure is appropriate).
Re: Belgium legalises ethical hacking
#20> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
Otherwise, this could undermine the public disclosure concept itself, a mechanism to force a stubborn vendor to fix their vulnerabilities.