Help Reform Computer Crime Laws
hackerone.com
Help Reform Computer Crime Laws
1–10 of 17 posts
Re: Help Reform Computer Crime Laws
#2Re: Help Reform Computer Crime Laws
#3I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, etc.). Yes, some organizations will be less secure because of it. Similarly, some houses are less secure because the locks are low quality. It isn't up to you to decide how thoroughly said locks should be checked.
Re: Help Reform Computer Crime Laws
#4> The hackers with the skills to break into software and networks, who choose to come forward with their knowledge and share their findings, should be legally exempt from criminal prosecution under laws designed to punish crime. I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, e…
Is the key term here. What counts as people's shit? If I, as a customer of a company, find out my shit (lets say personal information) is insecure because a security researcher investigated a security flaw in a company's API: Is that ok?
This gets even more blurred when lets say my shit (house) is in imminent threat of destruction because the chemical plant 1 mile away can easily be explosively sabotaged remotely, releasing toxic chemicals, due to shoddy SCADA security. Don't I and my shit deserve to be protected?
We are getting into the whole "Greater good / public interest" here where such a simple definition as you specified is no longer applicable I think.
Re: Help Reform Computer Crime Laws
#5> The hackers with the skills to break into software and networks, who choose to come forward with their knowledge and share their findings, should be legally exempt from criminal prosecution under laws designed to punish crime. I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, e…
Re: Help Reform Computer Crime Laws
#6> The hackers with the skills to break into software and networks, who choose to come forward with their knowledge and share their findings, should be legally exempt from criminal prosecution under laws designed to punish crime. I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, e…
> people's shit Is the key term here. What counts as people's shit? If I, as a customer of a company, find out my shit (lets say personal information) is insecure because a security researcher investigated a security flaw in a company's API: Is that ok? This gets even more blurred when lets say my shit (house) is in imminent threat of destruction because the chemical plant 1 mile away can easily be explosively sabota…
Re: Help Reform Computer Crime Laws
#7> The hackers with the skills to break into software and networks, who choose to come forward with their knowledge and share their findings, should be legally exempt from criminal prosecution under laws designed to punish crime. I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, e…
It is even further harmful when the laws are aggressively applied to prevent research into personal property, especially when your personal safety may depend upon it. For example, your car: https://twitter.com/0xcharlie/status/600729130355666944
Re: Help Reform Computer Crime Laws
#8Re: Help Reform Computer Crime Laws
#9> The hackers with the skills to break into software and networks, who choose to come forward with their knowledge and share their findings, should be legally exempt from criminal prosecution under laws designed to punish crime. I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, e…
The stance you take is harmful when said organizations are responsible for the stewardship of the data of others, and being "less secure" places the general public at risk. The true impact of a breach is rarely limited to a single organization. It is even further harmful when the laws are aggressively applied to prevent research into personal property, especially when your personal safety may depend upon it. For exam…
Do you make a habit of visiting banks uninvited to test their vaults?
Re: Help Reform Computer Crime Laws
#10Not so easy to do. As usual, there is a risk that such legislation will be abused to let people who are trying to break in to a system for malicious reasons, claim later it was research. A decent law would require researchers to register with police/whatever before they start researching. Which then excludes researching government/police systems (because they would know up front). etc. Not so easy!
One kind of security researcher we would want to protect is the one who finds out they can get information, but doesn't get everything, or doesn't keep what they get, or doesn't get anything really sensitive. Or who establishes that they can modify a system, but doesn't change anything important.
If someone gets my credit card number, and doesn't use it, and points out the problem, I want to thank them.
We make the analogy of breaking into houses, but bad information security is more like someone putting up a post-it note that says "This is a lock."
Sometimes just looking past the lock violates the letter of the law.