Live data from Hacker News

Belgium legalises ethical hacking

law.kuleuven.be

41–50 of 74 posts

Re: Belgium legalises ethical hacking

#41
"""The new Belgian whistleblower law only applies in Belgium."""

I haven't read the PDF of the law but from the article it doesn't sound like it is limited to Belgian citizen but only to the location. I hope there will be some pressure on the government organization to basically rubber stamp the "disclosure allowed" authorization in a reasonable time if everything was reported to them but remain a bit sceptical.

Quite curious on the implications for the announced eu-west-3-bru-1a (AWS Brussels). I hope Amazon won't cancel it :)

Re: Belgium legalises ethical hacking

#42

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

> Why not let the organization self decide this? Or one-out-of-two?

I think there could be two different situations. In the first one, the company doesn't want to let the pubilc know about a vulnerability they had to not damage their image. But the CCB gives permission after the vulnerability has been patched.

The second one is that the company gives permission, but the CCB wants to wait to first evaluate how many companies could have the same problem and get in touch with them. Think e.g. a vulnerability that can be potentially widespread like log4j.

Re: Belgium legalises ethical hacking

#44

I'm divided on this one. On one hand, I can see a lot of good in this, because, well, I'm on HN. On the other hand, I think people would find it weird that anybody would be allowed to do that IRL with physical building, so why allow it on the internet? Given that the consequences of probing a website are less than cracking on an office, and the surface of attack bigger on a website, with potentially a larger cascade,…

Like with physical business, if you can't guarantee proper security - you should not be in this business. Companies cut costs on cyber security whenever they can. And if you try to expose it you can get sued. It's about time this ends. Hopefully everywhere soon.

There are millions of small businesses that have an online presence and no way to protect themselves against a physical building penetration.

Heck, most administrations can't. A small town city council cannot be expected to have the budget or expertise to deal with someone trying to break in.

Re: Belgium legalises ethical hacking

#45

I guess the people cheering this have not lived in Europe. Typically what happens is that some of the local hackers who naively trust the state and disclose their hacks will have the book thrown at them. Either on the basis of an inconsequential technicality or because authorities arbitrarily decide the hack intended to cause harm or was not "proportionate", enabled by the vague wording of the law. Meanwhile the actu…

I once reported a leak on a government website to the National Cyber Security Centre, hoping to get a cool t-shirt out of it ("I hacked the Dutch government and all I got was this lousy t-shirt").

Turns out that system wasn't government but contracted out to the private sector. That got me into a lot of trouble since I reported a leak on a private company. Luckily I didn't get arrested or sued after explaining my intentions.

I have since not disclosed anything I find. Too much of a risk.

Re: Belgium legalises ethical hacking

#46
I've wanted this for the longest time. It makes a lot of sense because any existing vulnerabilities are ALREADY vulnerabilities. If exploited they're only going to go to whatever bad actors are trying to be secretive.

If you incentivize people [and young kids] to try hacking into their local government/company infrastructure by offering a reward in exchange or an explanation, you're basically making a cybersecurity immune system for your entire country.

When chinese/north korean/russian hackers are savagely going after hospital infrastructure and trade secrets in western countries, this is the best step forward towards improving the upstream and training your own hackers in response to these kind of events.

Re: Belgium legalises ethical hacking

#47
post #13

Earlier quoted context omitted.

Any cloud datacenters in Belgium?

Google has a large datacenter there. (europe-west1)

eu-west-1 is in Ireland. There are no currently open availability zone in Belgium.

Source: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-re...

Re: Belgium legalises ethical hacking

#48
post #40

I guess the people cheering this have not lived in Europe. Typically what happens is that some of the local hackers who naively trust the state and disclose their hacks will have the book thrown at them. Either on the basis of an inconsequential technicality or because authorities arbitrarily decide the hack intended to cause harm or was not "proportionate", enabled by the vague wording of the law. Meanwhile the actu…

I live in Europe and I don't know many if any story of ethical hackers getting incarcerated. In my youth in Italy, when I dabbled in "hacking", the stories going around at the time on IRC were that if you were ever nabbed hacking a server, you would get recruited by the local cyber police force (Polizia Postale)

French hacktivist bluetouff was condemned for finding and reporting that government files were left unprotected on the internet:

https://www.silicon.fr/bluetouff-blogueur-condamne-recherche...

30 hours locked up in the police station, all equipment confiscated.

Re: Belgium legalises ethical hacking

#49

Earlier quoted context omitted.

Good. Make it law in every other country too. You would not believe the amount of duct tape holding systems together; crowd sourcing the inspections would at least get eyeballs on the problems, even if it caused an uptick in security incidents. (Former pentester @matasano, though only for a little over a year.) After witnessing the results of over 50 pentests, you’re dragged to the conclusion that (a) companies usual…

> By (b) I mean “security doesn’t matter,” in the sense that very few companies have ever died from security incidents. Ashley Madison, and Mt Gox come to mind. I suspect Lastpass will be added to that list soon.

Just checked: Ashley Madison is still in business and reached their highest (known) peak of users in 2019, about 4 years after the leak.

Re: Belgium legalises ethical hacking

#50
post #12

Earlier quoted context omitted.

Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.

Surely the law here should be pedantic here, no? Does the location where a server is physically located or the location where a company is registered count?

Or what if a company buys a set of previously-used-in-Belgium IP addresses and now uses them in France?

Something like this happened on the cloud when they were running low on IPv4 addresses.

Post reply on HN