Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

181–190 of 466 posts

Re: I found a vulnerability. they found a lawyer

#181

Maintaining Cybersecurity Insurance is a big deal in the US, I don't know about Europe. So vulnerability disclosure is problematic for data controllers because it threatens their insurance and premiums. Today much of enterprise security is attestation based and vulnerability disclosure potentially exposes companies to insurance fraud. If they stated that they maintained certain levels of security, and a disclosure de…

It's not generally good financial advice to pay the overhead of an insurance company for costs you can easily pay yourself (also things like phone insurance, appliance warranty extensions, etc. won't make your device last longer and the insurer knows better than you what premium covers the average repair costs plus a profit margin). If you have a decent understanding of where the line is between vulnerability disclosure and criminal activities, fronting any court fees and a little bit of lawyer time (iff you can afford these out of pocket) until you're acquitted should be the better route, assuming anyone even ever takes you to court

Re: I found a vulnerability. they found a lawyer

#182
post #42

Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.

Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".

[flagged]

Re: I found a vulnerability. they found a lawyer

#183

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

Maybe the law should be changed then. The companies that have this level of disregard for security in 2026 are not going to change without either a good samaritan or a data breach.

Re: I found a vulnerability. they found a lawyer

#184

Earlier quoted context omitted.

I'm wary of centralizing the powers of the web like that.

Web is already mostly centralized, and corporations which should be scrutinized in way they handle security, PII and overall software issues are without oversight. It is also a matter of respect towards professionals. If civil engineer says that something is illegal/dangerous/unfeasible their word is taken into the account and not dismissed - unlike in, broadly speaking, IT.

I just don't feel we want the overhead on software. I'm in an industry with PEs and I have beef with the way it works for physical things.

PII isn't nearly as big a deal as a life tbh. I'd rather not gatekeep PII handling behind degrees. I want more accoubtability, but PEs for software seems like it's ill-suited for the problem. Principally, software is ever evolving and distributed. A building or bridge is mostly done.

A PR is not evaluated in a vacuum

Re: I found a vulnerability. they found a lawyer

#185

Contacting the authorities led the company to hire lawyers— for communication with the data protection authority. The lever lawyers have to “make it go away” is “law says so.” They’re not going to beg for mercy, they’re not going to invite you to coffee, no “bug bounty.” From their perspective if they arm-wrestle the researcher into an NDA, they patched the only known breach, retrospectively. Perhaps it’s not prosoci…

I think we should stop making excuses for shitty practices. I can understand why they might do it, i can also see there are much better ways to deal with this situation.

Re: I found a vulnerability. they found a lawyer

#186

Malta has been mentioned? As a person living here I could say that workflow of the government here is bad. Same as in every other place I guess. By the way, I had a story when I accidentally hacked an online portal in our school. It didn't go much and I was "caught" but anyways. This is how we learn to be more careful. I believe in every single system like that it's fairly possible to find a vulnerability. Nobody car…

Being more careful is an option, or owning up to it and saying "hey I just did this and noticed this thing unexpectedly happened, apparently you have an XSS here" (or whatever it was). In most cases, the organization you're reporting to is happy about this up-front information, and in the exceptional situation where someone decides to take it to court, there's a clear paper trail (backed up by access and email logs) of what actions were taken and why, making it obvious you did nothing wrong

Re: I found a vulnerability. they found a lawyer

#187
post #162

I suspect that the direction of these situations often depends on how your initial email is routed internally in these organizations. If they go to a lawyer first, you will get someone who tries to fix things with the application of the law. If it goes to an engineer first, you will get someone who tries to fix it with an application of engineering. If it were me, I would have avoided involving third party regulators…

Yes, this routing is common. German energy company recommended by a climate organization had a somewhat similar vulnerability and no security contact, so I call them up and.. mhm, yes, okay, is that l-e-g-a-l-@-company-dot-de? You don't want me to just send it to the IT department that can fix it? Okay I see, they will put it through, yes, thank you, bye for now! Was a bit of a "oh god what am I getting into again" m…

In the early internet days, you could email root@company.com about a website bug, and somebody might reply.

Re: I found a vulnerability. they found a lawyer

#188
post #139
post #108

Earlier quoted context omitted.

There is a term for this but I can't remember what it's called. Effectively you put in on purpose bugs for an inspector to find so they don't dig too deep for difficult to solve problems.

'canary', 'review canary' or something.

There's a related (apocryphal?) story from Interplay about adding a duck to animations so that the producer would ask for it to be removed, to make him happy, while leaving the rest alone.

https://bwiggs.com/notebook/queens-duck/

Re: I found a vulnerability. they found a lawyer

#189

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

I agree. You have to know when to stop.

No expert but I assume anything you do that is good faith usage of the site is OK. And take screenshots and report the potential problem. But making a python script to pull down data once you know? That is like getting in that car.

Real life example of fine would be you walk past a bank at midnight when it is unstaffed and the doors open so you have access to lobby (and it isnt just the night atm area). You call police on non emergency no and let them know.

Re: I found a vulnerability. they found a lawyer

#190

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

Maybe the law should be changed then. The companies that have this level of disregard for security in 2026 are not going to change without either a good samaritan or a data breach.

He didn't have to crack the site. He could have reported up to that point.

We need a change in law but more to do with fining security breaches or requiring certification to run a site above X number of users.

Post reply on HN