Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

91–100 of 112 posts

Re: SecurityBaseline.eu

#91
post #40

Interesting data set. Would be interesting to repeat the same for SMEs. In my experience, Germany is pretty hopelessly behind on everything except GDPR enforcement. They are kings of that. Must have a cookie screen, apparently. That's why they score so good on that and not much else. When the GDPR became active eight or so years ago, we got a few GDPR related requests to our service. Basically strongly worded request…

> Germany is a big reason GDPR got so complicated and why, hopefully soon, it will be updated to not be fixated on just cookies so much. In what way is GDPR focused on cookies? In my experience, developers in online discussions make it seem all about cookies, pretending other ways of tracking don't exist, while the law does not. But it has been a while since I looked into it and I might remember that wrong. > There u…

No, I said a lot of people are mistakenly focusing on cookies when it comes to GDPR. Including the linked site which checks mainly cookie consent issues with a few websites under the GDPR topic.

Re: SecurityBaseline.eu

#92
post #67

Earlier quoted context omitted.

Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

"Important" according to whom? A tracking cookie is trivial to fix (or to automagically disable for the more tech savvy citizens). Email being hosted by an untrusted foreign corporation is way harder to fix and impossible to bypass as a citizen trying to contact their government.

The effort required to fix tracking cookies is sometimes astounding, while migrating to another email provider is trivial.

This depends on how well the organization handles change and various complexities. Having great technical staff makes things easier, and throwing money at the problem can also help.

Just to give an anecdote: I've had people crying on the phone because their "solutions provider" could not get TLS to work on their www domain despite spending 5.000 euros or so.

Re: SecurityBaseline.eu

#93

Interesting data set. Would be interesting to repeat the same for SMEs. In my experience, Germany is pretty hopelessly behind on everything except GDPR enforcement. They are kings of that. Must have a cookie screen, apparently. That's why they score so good on that and not much else. When the GDPR became active eight or so years ago, we got a few GDPR related requests to our service. Basically strongly worded request…

> Germany is pretty hopelessly behind on everything except GDPR enforcement. Are you sure? I see major outlets in Germany blatantly violating the GDPR by forcing visitors to pay with their privacy or pay with their money. That is not allowed. It is perfectly fine to have a paywall, but you can never have people pay with their privacy.

Are you sure they are in violation? Because it only takes one customer to trigger expensive lawsuits. And there are a lot of very eager and trigger happy lawyers in Germany specializing in that sort of thing. A lot of people make bad assumptions about what is and isn't legal/allowed and a lot of companies have gotten good at finding the grey area of stuff that probably won't get them into trouble.

Re: SecurityBaseline.eu

#94
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

Word.....

This laws, while i wanne say have a good intention, just do the opposite...

I myself, residing in germany, developed a recon/vuln/scanning tool that im legally forbidden to publish cuz of the laws you just mentioned.

Re: SecurityBaseline.eu

#95
post #48
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

Yeah. And I do think that security research should have some regulation about it, but it should be more about responsible handling of the privileged access you gained, or a responsibility to disclose found vulnerabilities in private and/or to a government entity. You know, "If you have gained access to a system, and you saw a button and you pressed it, you are on the hook for the damages". That is common practice wit…

The mere act of scanning for vulnerability often causes outages.

I once ran a vulnerability scan at an industrial company that completely disabled their employees ability to clock in and out. I didnt believe it had anything to do with my scanner at first, but it ran on a schedule and the scanners schedule matched their outages eaxctly.

Eventually it turned out the timecard system had these IOT badge readers with a poorly written tcp stack. It would ACK every SYN, and worse the half open connections never closed, so during a port scan every port was left open until it exhausted the memory on the little buggers.

My point is... you cant know in advance what damage you'll do with this sort of testing. That's kind of the entire reason we have to actually perform the real world tests instead of assuming or emulating them.

It's also the reason that real world scanning without authorization is probably already a crime in most jurisdictions, whether it's enforced or not.

Re: SecurityBaseline.eu

#96
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

Word..... This laws, while i wanne say have a good intention, just do the opposite... I myself, residing in germany, developed a recon/vuln/scanning tool that im legally forbidden to publish cuz of the laws you just mentioned.

I heard from a friend that you can rent VPSs in pretty much any non-western country with some bitcoin (as long as you do nothing illegal, they don't care). I wouldn't suggest using it to circumvent any laws, but my friend used it for enhanced privacy

Re: SecurityBaseline.eu

#97
post #74

Earlier quoted context omitted.

As a German I fear the only way I can see one of our government agencies to react upon an external pentesting report is if you threatened to release data from it, anyway (this is not a recommendation, please don't raid my home). I just do not see them fixing even a dangerous bug if a stranger came along and told them to.

Thats far from reality. Just use the online form of BSI for disclosure. They contact the affected party for you. This way you optionally can stay anonymous and the vulnerabilities get fixed because BSI appears as the messenger.

Thats great to know, thank you!

Re: SecurityBaseline.eu

#98
post #96

Earlier quoted context omitted.

Word..... This laws, while i wanne say have a good intention, just do the opposite... I myself, residing in germany, developed a recon/vuln/scanning tool that im legally forbidden to publish cuz of the laws you just mentioned.

I heard from a friend that you can rent VPSs in pretty much any non-western country with some bitcoin (as long as you do nothing illegal, they don't care). I wouldn't suggest using it to circumvent any laws, but my friend used it for enhanced privacy

Well i wouldnt recommend to use btc for the payment to be honest. But ye offshore servers have been a thing for a long time.

Tho i wanted to open source the tool (spend ~10 years developing it) and thats just not an option.

Don't wanne self advertise here , but for the sake of better understanding if you want to know the details you can read them here: https://blog.laughingman.dev/article/Ishikawa_10_years_of_bu...

Re: SecurityBaseline.eu

#99

Earlier quoted context omitted.

In Germany we have the completely wrong mindset for such things. Instead of being grateful, all we care about is "whose fault is it" and CYA tactics. And no one wants to be "guilty" or have their incompetence revealed, so suits will do anything they can to avoid that. Somethings serious needs to go wrong first, so that loss of face already happens, before anyone will move. Maybe we need to get hacked by Russia a few…

How is the home of chaos computer club so bad at this....

There is a kind of naiveté, also at EU level, where people think that once it's a law, bad actors will just fold.

They minds are somehow unable to comprehend that only the good actors will fold and only bad actors will be left.

Other examples are: Firearms possession, supply chain law regarding human rights and child labor.

Re: SecurityBaseline.eu

#100
post #48

Earlier quoted context omitted.

Yeah. And I do think that security research should have some regulation about it, but it should be more about responsible handling of the privileged access you gained, or a responsibility to disclose found vulnerabilities in private and/or to a government entity. You know, "If you have gained access to a system, and you saw a button and you pressed it, you are on the hook for the damages". That is common practice wit…

The mere act of scanning for vulnerability often causes outages. I once ran a vulnerability scan at an industrial company that completely disabled their employees ability to clock in and out. I didnt believe it had anything to do with my scanner at first, but it ran on a schedule and the scanners schedule matched their outages eaxctly. Eventually it turned out the timecard system had these IOT badge readers with a po…

But in a perfect world, the question would be: Is it reasonable to expect an outage by sending a few single TCP packet to a system? Or, were you flooding the system unreasonably?

It is a huge security risk to treat systems as ancient eggshells you must not touch ever. A certain amount of touching has to be reasonable, because that is what foreign actors will do if they need to cause trouble. Apparently you could cause this company major operational harm with a pi zero. Why is that protected by professional ruin and jail time?

Post reply on HN