Live data from Hacker News

Belgium legalises ethical hacking

law.kuleuven.be

11–20 of 74 posts

Re: Belgium legalises ethical hacking

#11
post #4

Does this mean anything for the legal protections of Belgian citizens who research security vulnerabilities in foreign, rather than domestic, systems?

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?

Re: Belgium legalises ethical hacking

#12

Earlier quoted context omitted.

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?

Well, unfortunately, yes.

Belgium can’t give you a license to commit a crime in another country.

Re: Belgium legalises ethical hacking

#13

Earlier quoted context omitted.

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

Any cloud datacenters in Belgium?

Google has a large datacenter there. (europe-west1)

Re: Belgium legalises ethical hacking

#15
post #12

Earlier quoted context omitted.

So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?

Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.

Why not? The US does this regularly.

Re: Belgium legalises ethical hacking

#17

Earlier quoted context omitted.

No: > The new Belgian whistleblower law only applies in Belgium. If a cybersecurity vulnerability concerns an IT system outside of Belgium, hacking might be covered by the rules of the country where the system is located.

Any cloud datacenters in Belgium?

Interesting to point out that Euroclear and Euronext are based in Belgium.

Re: Belgium legalises ethical hacking

#18
post #12

Earlier quoted context omitted.

So if a Belgian hacker is researching a Belgian company and a single server happens to be outside of Belgium territory, they're suddenly breaking the law?

Well, unfortunately, yes. Belgium can’t give you a license to commit a crime in another country.

Surely the law here should be pedantic here, no? Does the location where a server is physically located or the location where a company is registered count?

Re: Belgium legalises ethical hacking

#19

Some progress but with some notable weaknesses (a state institution determines whether public disclosure is appropriate).

Seems more than reasonable given that the law does not appear to exclude state institutions from being the target of hacking. If that provision did not exist you can bet the law would never apply to any security sensitive sector.

Re: Belgium legalises ethical hacking

#20

> The new Belgian whistleblower law (Klokkenluiderswet) has changed the legal situation for ethical hacking in Belgium. A natural or legal person is now authorised to investigate organisations in Belgium for potential cybersecurity vulnerabilities, even if they have not consented to such investigations. Cool. Though, Belgium will soon have the most secure systems in the world, or no one dares running open computer sy…

Looks like the new legal framework puts everyone at the mercy of CCB, a government body. Hope they have enough incentives and processes to do the right thing with all those 0-days that will flow to them.

Otherwise, this could undermine the public disclosure concept itself, a mechanism to force a stubborn vendor to fix their vulnerabilities.

Post reply on HN