Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

31–40 of 112 posts

Re: SecurityBaseline.eu

#31
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

In Germany we have the completely wrong mindset for such things. Instead of being grateful, all we care about is "whose fault is it" and CYA tactics. And no one wants to be "guilty" or have their incompetence revealed, so suits will do anything they can to avoid that. Somethings serious needs to go wrong first, so that loss of face already happens, before anyone will move. Maybe we need to get hacked by Russia a few more times.

Re: SecurityBaseline.eu

#32
post #21

There should be a metric for sites hosting malicious content! https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf

Might be worth enclosing that URL in quotes or using [dot] in the URL instead, so people don't accidentally click on that "mortal-kombat-2-cs.pdf" file that Europa.EU is hosting.

VirusTotal claims the PDF file is clean, but I don't think I'd fully trust it anyway. If you do find malicious content, could be worth submitting the URLs to VirusTotal so that the domain is flagged by browsers (eg Google SafeBrowsing) and people can't accidentally visit ec.europa.eu domains until it has been cleaned.

Re: SecurityBaseline.eu

#34
Great work. It's fun how these graphs indirectly hint at a cross-section of "e-Gov"/"tech-literacy in politics" per country with those incident-tables.

1. Countries with strong e-government and HIGH understanding of its requirements rank LOW (good!)

2. Countries with evolving e-government practices and LOW understanding of the implications rank HIGH (bad!)

3. Countries FAR BEHIND in e-government practices rank LOW (...good?)

Goes to show that globally we need more tech-literate people on the forefront of politics, so that the proper priorities are also set in execution...

Re: SecurityBaseline.eu

#35
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

In Germany we have the completely wrong mindset for such things. Instead of being grateful, all we care about is "whose fault is it" and CYA tactics. And no one wants to be "guilty" or have their incompetence revealed, so suits will do anything they can to avoid that. Somethings serious needs to go wrong first, so that loss of face already happens, before anyone will move. Maybe we need to get hacked by Russia a few…

How is the home of chaos computer club so bad at this....

Re: SecurityBaseline.eu

#36

[flagged]

Came here to say this. Absolutely insane. Why is phpMyAdmin even still needed/wanted in 2026? It's not exactly user friendly for a developer, let alone an average Gov employee...

It's what you get, when you scrape the bottom of the barrel with the salaries you are willing to pay. Are you willing to take a 1/3 pay cut for no good reason? You are welcome to work in such positions.

Re: SecurityBaseline.eu

#37
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

To be fair, most of this stuff could be found with any normal browser. You don't even need browser dev tools. But if you write a simple script to automate any of this... yeah. They can totally get you for doing that. Probably one or the best examples why politicians should not be allowed to pass technical laws they fundamentally can't grasp.

Visiting an admin page is fine, yeah, but even just trying a default password, or having specific cookies set in the browser that look like an attempt to gain access, already clearly violate § 202a and you could be prosecuted, from how I read that law's text.

And while URL obscurity alone is weak evidence of "special protection" of a resource, I'm sure some legal team would love to try to argue otherwise.

Re: SecurityBaseline.eu

#39

Earlier quoted context omitted.

In Germany we have the completely wrong mindset for such things. Instead of being grateful, all we care about is "whose fault is it" and CYA tactics. And no one wants to be "guilty" or have their incompetence revealed, so suits will do anything they can to avoid that. Somethings serious needs to go wrong first, so that loss of face already happens, before anyone will move. Maybe we need to get hacked by Russia a few…

How is the home of chaos computer club so bad at this....

It is only this degree of malice and incompetence that can give rise to something like the CCC.

Re: SecurityBaseline.eu

#40

Interesting data set. Would be interesting to repeat the same for SMEs. In my experience, Germany is pretty hopelessly behind on everything except GDPR enforcement. They are kings of that. Must have a cookie screen, apparently. That's why they score so good on that and not much else. When the GDPR became active eight or so years ago, we got a few GDPR related requests to our service. Basically strongly worded request…

> Germany is a big reason GDPR got so complicated and why, hopefully soon, it will be updated to not be fixated on just cookies so much.

In what way is GDPR focused on cookies?

In my experience, developers in online discussions make it seem all about cookies, pretending other ways of tracking don't exist, while the law does not. But it has been a while since I looked into it and I might remember that wrong.

> There usually is no cookie screen when you install one usually (unless it's a web app packaged up as an app).

A lot of games provide opt-in screens, as they heavily rely on ad networks.

> If you read the actual law, it barely mention cookies at all

Now I am confused, didn't you just say it was focused on cookies?

Post reply on HN