| ▲ | kenniskrag 2 hours ago | |||||||||||||
In switzerland it depends 143bis StGB: Any person who, with the intention of securing an unlawful gain for themselves or another obtains for themselves or another data that are stored or transmitted electronically or in some similar manner and which are not intended for them and have been specially secured to prevent their access shall be liable to a custodial sentence not exceeding five years or to a monetary penalty. | ||||||||||||||
| ▲ | ofjcihen 2 hours ago | parent [-] | |||||||||||||
So this wording is really interesting in the bug bounty sense and I’m curious if you know how it would be handled. If someone hits an unsecured API, receives information, and notifies the company of this while also requesting a bounty, would that satisfy all of the requirements of prosecution? The unlawful gain is the sticking point in my mind. | ||||||||||||||
| ||||||||||||||