Earlier quoted context omitted.
The blog is under a German domain, the company is from Malta. Why would they care about a US law again?
IANAL but the law in Germany is basically the same in this case, accessing data that's meant to be protected and not intended for you is is illegal. It depends somewhat on the interpretation of what "specifically protected" ("besonders gesichert") means. https://www.gesetze-im-internet.de/stgb/__202a.html
I found a vulnerability. they found a lawyer
371–380 of 466 posts
Re: I found a vulnerability. they found a lawyer
#372Earlier quoted context omitted.
Good guideline advice but it seems you didn't read the article. Their personal data was at risk here. Leaving them alone would very likely result in a breach of this person's data. Both he and you have an ethical responsibility to at minimum notify the business of this problem and follow up with it.
That’s not how it works. You are not ethically responsible to hack every company you interact with.
https://www.giac.org/policies/ethics/
"I will protect confidential and proprietary information with which I come into contact."
Re: I found a vulnerability. they found a lawyer
#373I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…
If he wanted to solve it he would automatically sue them back for breaching his and his clients' personal data and not make any publicity blog post.
Re: I found a vulnerability. they found a lawyer
#374I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.
How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?
So far I've been happy. I hope I'll stay happy.
Re: I found a vulnerability. they found a lawyer
#375Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…
Re: I found a vulnerability. they found a lawyer
#376Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…
In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…
I think this is mostly a US thing.
Re: I found a vulnerability. they found a lawyer
#377Earlier quoted context omitted.
In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.
>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?
This isn't really that exceptional and as someone from a place where not just anyone can call themselves engineer I'm always baffled when people think that it is.
Re: I found a vulnerability. they found a lawyer
#378Earlier quoted context omitted.
That’s not how it works. You are not ethically responsible to hack every company you interact with.
No, that's exactly how it works when you're Certified. https://www.giac.org/policies/ethics/ "I will protect confidential and proprietary information with which I come into contact."
Re: I found a vulnerability. they found a lawyer
#379I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…
Re: I found a vulnerability. they found a lawyer
#380I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.
Every single time I order from KFC, I get an e-mail by a hot girl in my area. You think I can sue them for free chicken wing buckets?