Maintaining Cybersecurity Insurance is a big deal in the US, I don't know about Europe. So vulnerability disclosure is problematic for data controllers because it threatens their insurance and premiums. Today much of enterprise security is attestation based and vulnerability disclosure potentially exposes companies to insurance fraud. If they stated that they maintained certain levels of security, and a disclosure de…
I found a vulnerability. they found a lawyer
181–190 of 466 posts
Re: I found a vulnerability. they found a lawyer
#182Re: I found a vulnerability. they found a lawyer
#183AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…
Re: I found a vulnerability. they found a lawyer
#184Earlier quoted context omitted.
I'm wary of centralizing the powers of the web like that.
Web is already mostly centralized, and corporations which should be scrutinized in way they handle security, PII and overall software issues are without oversight. It is also a matter of respect towards professionals. If civil engineer says that something is illegal/dangerous/unfeasible their word is taken into the account and not dismissed - unlike in, broadly speaking, IT.
PII isn't nearly as big a deal as a life tbh. I'd rather not gatekeep PII handling behind degrees. I want more accoubtability, but PEs for software seems like it's ill-suited for the problem. Principally, software is ever evolving and distributed. A building or bridge is mostly done.
A PR is not evaluated in a vacuum
Re: I found a vulnerability. they found a lawyer
#185Contacting the authorities led the company to hire lawyers— for communication with the data protection authority. The lever lawyers have to “make it go away” is “law says so.” They’re not going to beg for mercy, they’re not going to invite you to coffee, no “bug bounty.” From their perspective if they arm-wrestle the researcher into an NDA, they patched the only known breach, retrospectively. Perhaps it’s not prosoci…
Re: I found a vulnerability. they found a lawyer
#186Malta has been mentioned? As a person living here I could say that workflow of the government here is bad. Same as in every other place I guess. By the way, I had a story when I accidentally hacked an online portal in our school. It didn't go much and I was "caught" but anyways. This is how we learn to be more careful. I believe in every single system like that it's fairly possible to find a vulnerability. Nobody car…
Re: I found a vulnerability. they found a lawyer
#187I suspect that the direction of these situations often depends on how your initial email is routed internally in these organizations. If they go to a lawyer first, you will get someone who tries to fix things with the application of the law. If it goes to an engineer first, you will get someone who tries to fix it with an application of engineering. If it were me, I would have avoided involving third party regulators…
Yes, this routing is common. German energy company recommended by a climate organization had a somewhat similar vulnerability and no security contact, so I call them up and.. mhm, yes, okay, is that l-e-g-a-l-@-company-dot-de? You don't want me to just send it to the IT department that can fix it? Okay I see, they will put it through, yes, thank you, bye for now! Was a bit of a "oh god what am I getting into again" m…
Re: I found a vulnerability. they found a lawyer
#188Earlier quoted context omitted.
There is a term for this but I can't remember what it's called. Effectively you put in on purpose bugs for an inspector to find so they don't dig too deep for difficult to solve problems.
'canary', 'review canary' or something.
Re: I found a vulnerability. they found a lawyer
#189AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…
No expert but I assume anything you do that is good faith usage of the site is OK. And take screenshots and report the potential problem. But making a python script to pull down data once you know? That is like getting in that car.
Real life example of fine would be you walk past a bank at midnight when it is unstaffed and the doors open so you have access to lobby (and it isnt just the night atm area). You call police on non emergency no and let them know.
Re: I found a vulnerability. they found a lawyer
#190AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…
Maybe the law should be changed then. The companies that have this level of disregard for security in 2026 are not going to change without either a good samaritan or a data breach.
We need a change in law but more to do with fining security breaches or requiring certification to run a site above X number of users.