Earlier quoted context omitted.
Any cloud datacenters in Belgium?
Interesting to point out that Euroclear and Euronext are based in Belgium.
Belgium legalises ethical hacking
21–30 of 74 posts
Re: Belgium legalises ethical hacking
#22Re: Belgium legalises ethical hacking
#23> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
How can you expect any trust in the shady world of "vulnerabilities"? Are you serious?
Re: Belgium legalises ethical hacking
#24> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
Unicorn world. How lovely: "hackers" will start to give "vulnerabilities" for "free" to some "agencies"... I wonder how many will stay secret for those "agencies" own agenda. How can you expect any trust in the shady world of "vulnerabilities"? Are you serious?
Makeing certain things legal explicitly has it's merits.
Re: Belgium legalises ethical hacking
#25> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
Good. Make it law in every other country too. You would not believe the amount of duct tape holding systems together; crowd sourcing the inspections would at least get eyeballs on the problems, even if it caused an uptick in security incidents. (Former pentester @matasano, though only for a little over a year.) After witnessing the results of over 50 pentests, you’re dragged to the conclusion that (a) companies usual…
Ashley Madison, and Mt Gox come to mind. I suspect Lastpass will be added to that list soon.
Re: Belgium legalises ethical hacking
#26> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
There are three groups of people:
* People who hack for profit and want to exploit you.
* People who hack for fun and don't care about telling you.
* People who hack for fun and are polite enough to tell you about it afterwards.
#1 isn't going to be deterred by law, as hacking is illegal already. #2 might do it anyway, since the risk of getting caught is low, you just won't hear about it. #3 is the only group that this new law will affect, and the way it will affect them is that now they can tell you about it without fearing repercussions.
I don't see this making people more afraid to run open computer systems. The bad guys were always going to get to them anyway.
Re: Belgium legalises ethical hacking
#27Earlier quoted context omitted.
Unicorn world. How lovely: "hackers" will start to give "vulnerabilities" for "free" to some "agencies"... I wonder how many will stay secret for those "agencies" own agenda. How can you expect any trust in the shady world of "vulnerabilities"? Are you serious?
It is about deterrence. I had more than one instance where I did not tell a government agency or an airport or whatever about a flaw in theie system, because I did not want to deal with them potentially "shooting" the messenger. Makeing certain things legal explicitly has it's merits.
There is only one way to do that safely: immediat full public disclosure. Corps and govs have to be ready for that all the time, this is a significant part of their job. The real issue is the trust about the source of "vulnerabilities", because upon publication, it must be validaded by competent ppl, and here we go again in the shadows where things could become "delayed" indefinitely (I guess as long as possible).
Re: Belgium legalises ethical hacking
#28> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
Re: Belgium legalises ethical hacking
#29> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…
The context here is "without authorisation of the owner of the system"; if they agree to publication then the additional protections [need to] don't apply
Re: Belgium legalises ethical hacking
#30Earlier quoted context omitted.
Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.
Why not? The US does this regularly.
(and whether secret services are "allowed" to do so, is a seperate question)