Live data from Hacker News

Belgium legalises ethical hacking

law.kuleuven.be

61–70 of 74 posts

Re: Belgium legalises ethical hacking

#61

Earlier quoted context omitted.

Surely the law here should be pedantic here, no? Does the location where a server is physically located or the location where a company is registered count?

Or what if a company buys a set of previously-used-in-Belgium IP addresses and now uses them in France? Something like this happened on the cloud when they were running low on IPv4 addresses.

IP addresses are assigned to organizations, not countries.

There's nothing at all preventing me from geolocating my /32 of v6 to anywhere at all I want.

Or chopping it into smaller subnets and then allocating those wherever.

Re: Belgium legalises ethical hacking

#62
post #58
post #38

Earlier quoted context omitted.

> By (b) I mean “security doesn’t matter,” in the sense that very few companies have ever died from security incidents. The cost is borne by the customers whose data is exposed, not the companies who allowed the breach. Shouldn't the companies be liable for millions of dollars on a sane justice system?

Know of any?

Technically not a case of hacking but still:

https://facebookuserprivacysettlement.com/

Re: Belgium legalises ethical hacking

#65

Earlier quoted context omitted.

Just checked: Ashley Madison is still in business and reached their highest (known) peak of users in 2019, about 4 years after the leak.

This begs the question: who's more stupid, the business that negligently screwed their customers, or the customers who came back after?

it wasn't that customers came back, aspiring women noticed the gap in the market from the data leaks and chose to be sex workers, replacing the sock puppet users with real women. the hack and leak was a blessing in disguise for ashley madison.

this is already reported but once you leave the corporate sex worker exclusionary echo chamber it becomes more obvious how efficient that market is, from the supply side

it would alter most of your assumptions and make a lot of things more obvious without needing to be “studied”

Re: Belgium legalises ethical hacking

#66

I guess the people cheering this have not lived in Europe. Typically what happens is that some of the local hackers who naively trust the state and disclose their hacks will have the book thrown at them. Either on the basis of an inconsequential technicality or because authorities arbitrarily decide the hack intended to cause harm or was not "proportionate", enabled by the vague wording of the law. Meanwhile the actu…

I once reported a leak on a government website to the National Cyber Security Centre, hoping to get a cool t-shirt out of it ("I hacked the Dutch government and all I got was this lousy t-shirt"). Turns out that system wasn't government but contracted out to the private sector. That got me into a lot of trouble since I reported a leak on a private company. Luckily I didn't get arrested or sued after explaining my int…

Ah yes, the National Cyber Security Centre is constantly in the news for arresting and suing people that report vulnerabilities to them /s

... seriously, what?

Re: Belgium legalises ethical hacking

#67

I'm divided on this one. On one hand, I can see a lot of good in this, because, well, I'm on HN. On the other hand, I think people would find it weird that anybody would be allowed to do that IRL with physical building, so why allow it on the internet? Given that the consequences of probing a website are less than cracking on an office, and the surface of attack bigger on a website, with potentially a larger cascade,…

> so why allow it on the internet?

I find this weird also. The explanation I've been able to come up with is that there isn't prosecution on the internet the way that there is IRL. You're just screwed if you got hacked by someone whose VPN provider didn't already have a tap order in place on this customer. Without deterrence, the only remaining thing you can do is make it impossible to perform in the first place.

Re: Belgium legalises ethical hacking

#68
post #66

Earlier quoted context omitted.

I once reported a leak on a government website to the National Cyber Security Centre, hoping to get a cool t-shirt out of it ("I hacked the Dutch government and all I got was this lousy t-shirt"). Turns out that system wasn't government but contracted out to the private sector. That got me into a lot of trouble since I reported a leak on a private company. Luckily I didn't get arrested or sued after explaining my int…

Ah yes, the National Cyber Security Centre is constantly in the news for arresting and suing people that report vulnerabilities to them /s ... seriously, what?

If you read my comment it will become clear to you that the National Cyber Security Centre did not have any intention of suing me, as the vulnerable system was not their responsibility.

The NCSC has not been in the news for arresting people and suing them.

Re: Belgium legalises ethical hacking

#69
post #12

Earlier quoted context omitted.

Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.

But the inverse seemingly works with regards to GDPR? If a Belgian citizen in Belgium hacks my US server they are not protected by this Belgian law. Yet if a Belgian citizen in Belgium visits my US server they are protected by GDPR? How does that work then?

> Yet if a Belgian citizen in Belgium visits my US server they are protected by GDPR?

No, not if you and your server have no EU presence. There might be other reasons to comply, though.

Post reply on HN