Live data from Hacker News

Belgium legalises ethical hacking

law.kuleuven.be

31–40 of 74 posts

Re: Belgium legalises ethical hacking

#31

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

Vulnerabilities are by definition dangerous. In some cases critically dangerous.

It is reasonable, common sense even, that vulnerabilities should not be publicised without a vetting process.

Re: Belgium legalises ethical hacking

#32
post #8

Earlier quoted context omitted.

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

That part is obvious, if you commit a crime somewhere else, then you commit it somewhere else. The question is whether Belgium protects you as their citizen, or doesn't.

Typically extradition requires dual criminality.

i.e. you can’t be extradited for something that is a crime in a foreign country but isn’t in yours.

Re: Belgium legalises ethical hacking

#33
I guess the people cheering this have not lived in Europe. Typically what happens is that some of the local hackers who naively trust the state and disclose their hacks will have the book thrown at them. Either on the basis of an inconsequential technicality or because authorities arbitrarily decide the hack intended to cause harm or was not "proportionate", enabled by the vague wording of the law. Meanwhile the actual criminals who mostly aren't located in the EU to begin with get off scot-free, even if they can be tracked back to Russia or somewhere local law enforcement can do nothing about it in the majority of cases.

Re: Belgium legalises ethical hacking

#34

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

Ah, a crowd sourced NSA. Very clever.

Yes, a very cheap solution. Very typical, as security always ends up at the bottom of the budget plan.

Re: Belgium legalises ethical hacking

#35
I'm divided on this one. On one hand, I can see a lot of good in this, because, well, I'm on HN.

On the other hand, I think people would find it weird that anybody would be allowed to do that IRL with physical building, so why allow it on the internet?

Given that the consequences of probing a website are less than cracking on an office, and the surface of attack bigger on a website, with potentially a larger cascade, I think I can find more arguments for than against.

But it's not so easy to answer.

Re: Belgium legalises ethical hacking

#37

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

Compare and contrast Google's Project Zero's disclosure policy: https://googleprojectzero.blogspot.com/p/vulnerability-discl...

They don't wait for your permission to publish - they give you 90 days to fix and 30 days from when the fix is ready, but if you don't cooperate, they're posting it anyway.

As I understand it they don't hack into someone else's system, but they might disclose a vulnerability in your software running on my device.

Re: Belgium legalises ethical hacking

#38

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

Good. Make it law in every other country too. You would not believe the amount of duct tape holding systems together; crowd sourcing the inspections would at least get eyeballs on the problems, even if it caused an uptick in security incidents. (Former pentester @matasano, though only for a little over a year.) After witnessing the results of over 50 pentests, you’re dragged to the conclusion that (a) companies usual…

> By (b) I mean “security doesn’t matter,” in the sense that very few companies have ever died from security incidents. The cost is borne by the customers whose data is exposed, not the companies who allowed the breach.

Shouldn't the companies be liable for millions of dollars on a sane justice system?

Re: Belgium legalises ethical hacking

#39

I'm divided on this one. On one hand, I can see a lot of good in this, because, well, I'm on HN. On the other hand, I think people would find it weird that anybody would be allowed to do that IRL with physical building, so why allow it on the internet? Given that the consequences of probing a website are less than cracking on an office, and the surface of attack bigger on a website, with potentially a larger cascade,…

Like with physical business, if you can't guarantee proper security - you should not be in this business.

Companies cut costs on cyber security whenever they can. And if you try to expose it you can get sued. It's about time this ends. Hopefully everywhere soon.

Re: Belgium legalises ethical hacking

#40

I guess the people cheering this have not lived in Europe. Typically what happens is that some of the local hackers who naively trust the state and disclose their hacks will have the book thrown at them. Either on the basis of an inconsequential technicality or because authorities arbitrarily decide the hack intended to cause harm or was not "proportionate", enabled by the vague wording of the law. Meanwhile the actu…

I live in Europe and I don't know many if any story of ethical hackers getting incarcerated.

In my youth in Italy, when I dabbled in "hacking", the stories going around at the time on IRC were that if you were ever nabbed hacking a server, you would get recruited by the local cyber police force (Polizia Postale)

Post reply on HN