Live data from Hacker News

EU: "Making hacking tools should be illegal"

theregister.co.uk

51–60 of 65 posts

Re: EU: "Making hacking tools should be illegal"

#51
post #16

If hacking tools are outlawed, then only outlaws will have hacking tools. Meaning if you're a software developer or system admin in the EU, you better be on standby 24/7 to combat 0-day exploits.

I find myself quite torn by this statement, because while I dont think hacking tools should be illegal, this is the exact same argument pro-gun people make, and i'm quite anti-gun (I'm from UK). Then again, in America drug paraphernalia is illegal but in the UK its not and i personally dont think you should be locked up for having a bong because theoretically you might only use it for tobacco. Anyway, personally i'm…

You are absolutely right it is the same argument for guns and it is correct for both.

Laws aren't going to affect hackers off in Romania and Russia and China and the NSA/CIA.

But studying the code and testing it is overwhelmingly the best, and likely essential way to understand how to protect against security threats.

Re: EU: "Making hacking tools should be illegal"

#52
post #14

Earlier quoted context omitted.

I do believe my point was that no law is free of unintended consequences, particularly not your law that outlaws laws with unintended consequences, thus your law outlaws itself. The outlawing of the law against laws with unintended consequences by the law against laws with unintended consequences would undoubtedly be considered yet another unintended consequence of the law against laws with unintended consequences.

Just make the law "any law with unintended consequences is illegal" , then embrace any possible "consequence" of this law (such as perhaps laws you otherwise like being declared illegal), then the law should fail to outlaw itself. Any consequences would be by definition intended. Anyway, I don't buy the suggestion that no law can be free of unintended consequences. If you construct a sufficiently formal definition of…

Until you find laws that can be formulated in your formal system, but cannot be proven - say hello to Gödel incompleteness theorems :).

(also, I love when discussions go meta :))

Re: EU: "Making hacking tools should be illegal"

#53
post #43

Earlier quoted context omitted.

I find myself quite torn by this statement, because while I dont think hacking tools should be illegal, this is the exact same argument pro-gun people make, and i'm quite anti-gun (I'm from UK). Then again, in America drug paraphernalia is illegal but in the UK its not and i personally dont think you should be locked up for having a bong because theoretically you might only use it for tobacco. Anyway, personally i'm…

You're not anti-gun. You're anti-'private gun ownership'. You're fine with the state employing guns. It's an important difference. Bongs are legal in the US. You just can't advertise them for use with pot. They are sold as water pipes.

I am anti-gun, so while you may be right, you shouldn't presume you are about the person you're replying to.

I'm not a moron, I don't know if we could ever learn to live without armies/armed police, and I'm not calling for a drastic change such as "the UK should give up all armed forces", obviously it doesn't work that way.

But you have the same problems for private gun ownership - for example, how would you set about making it illegal in the US given how many people already own guns, it would be a crazily difficult task. However that doesn't stop people from being in favour of finding a way to do it.

Re: EU: "Making hacking tools should be illegal"

#54
post #30
post #24

Earlier quoted context omitted.

There seems to be a big difference between that law and this one in that this would outlaw all posessions of "Hacking tools".

Lockpicks in my state in the US are permitted, except for having them with burglorious intent. Same thing IMO.

That just isn't at all the same thing... this suggested law is the equivilent of making it illegal to create lockpicks at all. Regardless of intent.

Re: EU: "Making hacking tools should be illegal"

#56
post #20

Wouldn't it be simpler and more efficacious to simply ban sales of Windows in the EU, or mandate that they fix the security issues? Not that I favor ludicrous bans of this sort, or that I think they will work. Because I manifestly don't. But geez, if you're going to be over-the-top Orwellian, at least do something that has a chance of achieving your stated goals.

It seems naive that you assume that banning Windows would decrease the rate of successful malicious attacks on machines. Every piece of software has holes - the largest of which is the user. If everyone in the EU switched off of Windows, you'd just have a large percentage of the population using linux or OSX without understanding how security works on those systems (many of whom would gladly enter their root password to install a spyware program, so long as they can keep playing farmville or whatever it promises to do).

Re: EU: "Making hacking tools should be illegal"

#57
Yes, it is illegal to financially damage a company, and many crackers do exactly that. This article and most of the comments here argue about the tools. As hackers we find it hard to understand why a hammer could be outlawed because it is good at breaking through the windows of houses.

Why does no one talk about the network that was broken into? Why does the general public believe that crackers are so good at their job it is impossible to secure a computer system? There are two possibilities that I can see here.

1. Most cracks happen because of a less-than-perfect system administrator. Either some subtle problem with a configuration file opened up a hole for the cracker or nobody bothered securing the network to begin with.

2. Most cracks happen because crackers have found a reliable method of discovering 0day exploits or our current computing model is fundamentally insecure.

In either case, I find it unjustifiable to declare cracking an act of terrorism without spending ANY effort reflecting back on our own security. If millions of us routinely use the same password (or a easy-to-guess pattern) for all of our accounts who is the terrorist? The people who take advantage of an easy opportunity, or the people who created that opportunity in the first place?

It is well known that users are stupid, and that two-factor authentication is much harder to break than static passwords. Bruce Schneider has been saying so for at least a decade. Why have we not moved on? As a system administrator, it should be an act of terrorism to NOT make two-factor authentication the DEFAULT way of using your service.

Re: EU: "Making hacking tools should be illegal"

#58
If you leave your wallet on the street in a bad neighborhood and come back, you'll probably never see it again.

The problem with such protection laws is that it doesn't take into account the ignorance or incompetence of service providers. It also holds back innovation and we end up with less security. Even if these vulnerable companies don't have the expertise they can hire a reputable security company to audit their system to plug the gaping holes.

Do we need to pass laws for companies to do security audits? Maybe for listed companies or companies that have services of a certain size, since they'll try to skimp on costs or executives don't understand IT needs.

Trying to criminalize the intent of developers even if they create tools solely for cracking is a slippery slope. While we're at it we should make defense contractors liable for war damages and execute the engineers responsible for creating weapons.

In Japan a closed source p2p software called Winny caused a lot of disorder with viruses and lots of government information and embarrassing private pictures leaked onto the net due to security issues. Unfortunately, the developer was busy fighting a trial based on whether he had intentions of violating copyright with his software (he was finally acquitted on appeal to a higher district court). If he at any point publicly endorsed copyright violations, he'd probably be locked up for a long time even if he didn't violent a single bit of copyrighted content. Needless to say the project is abandoned and full of holes. Good for the anti-virus industry though.

http://en.wikipedia.org/wiki/Winny

Re: EU: "Making hacking tools should be illegal"

#60
There's a sensible reason for implementing a law of this kind - if they catch the guy that wrote Zeus, I'd like them to be able to prosecute him (not that they could, as he's probably not in the EU, but you get the idea). Of course, it does need to be carefully written to avoid collateral damage.
Post reply on HN