| ▲ | croes 2 hours ago |
| If you ask a software developer: no If you ask a judge: probably yes |
|
| ▲ | kenniskrag 2 hours ago | parent | next [-] |
| In switzerland it depends 143bis StGB: Any person who, with the intention of securing an unlawful gain for themselves or another obtains for themselves or another data that are stored or transmitted electronically or in some similar manner and which are not intended for them and have been specially secured to prevent their access shall be liable to a custodial sentence not exceeding five years or to a monetary penalty. |
| |
| ▲ | ofjcihen 2 hours ago | parent [-] | | So this wording is really interesting in the bug bounty sense and I’m curious if you know how it would be handled. If someone hits an unsecured API, receives information, and notifies the company of this while also requesting a bounty, would that satisfy all of the requirements of prosecution? The unlawful gain is the sticking point in my mind. | | |
| ▲ | kenniskrag an hour ago | parent | next [-] | | If you publish the bug then it could be unfair competition in my opinion. There was a product test where the mentioned some flaws of a medicine but didnt mention other producers of same drug. They broke the UC rules and paid some money: https://politchronik.swiss/de/prozesse/57953-das-kassensturz... | |
| ▲ | kenniskrag an hour ago | parent | prev [-] | | If you access "private" data it's also unlawful acording to 143. Pentesting is a hot topic but there are comapnys acusing you of hacking if you send them a security report (hacking). If they mention a bug bounty program then you are allowed to test their security as described in this program but not more. |
|
|
|
| ▲ | Foskya 2 hours ago | parent | prev | next [-] |
| I guess it falls in the same category of burglars that enter from the unlocked main door.
It is still illegal even if there were no security measures to overcome by the attacker. That being said using an API does require a minimum of computer knowledge |
|
| ▲ | CJefferson 2 hours ago | parent | prev | next [-] |
| I'm a software developer. This is clearly bad, and we can decide what it should be called. It might not be 'hacking', but you are clearly abusing the computer to steal a space in a class you shouldn't have. |
|
| ▲ | nicman23 2 hours ago | parent | prev [-] |
| not really, it needs criminal intent. |
| |
| ▲ | croes 2 hours ago | parent [-] | | Nope https://www.heise.de/en/news/Modern-Solution-Court-of-Appeal... | | |
| ▲ | mr_mitm an hour ago | parent [-] | | AFAIK felonies in Germany require "intent", not "criminal intent". The guy could have stopped earlier, right after testing the password. But he decided to use it to view data which didn't belong to him. I realize I'm going against the general public opinion, but he didn't have to do that, and I can see why the court didn't accept "but I only did it to take screenshots" as a valid defense, because that's clearly intent. | | |
| ▲ | croes an hour ago | parent [-] | | Modern Solution would have claimed that the password wouldn‘t have allowed access to important data. | | |
| ▲ | mr_mitm 26 minutes ago | parent [-] | | So be it. Publicly disclose the vulnerability and stop doing business with them. | | |
| ▲ | croes 9 minutes ago | parent [-] | | He didn’t do business with them, his customer did. And publicly disclose that the publicly available software contains the password in plain text could have been construed as aiding a criminal offense. He was ordered by his customer to look into logging problems. He found the password in plain text, looked into a database he thought contains only data of his customer and found it‘s data of other customers too. |
|
|
|
|
|