Remix.run Logo
ofjcihen 2 hours ago

So this wording is really interesting in the bug bounty sense and I’m curious if you know how it would be handled.

If someone hits an unsecured API, receives information, and notifies the company of this while also requesting a bounty, would that satisfy all of the requirements of prosecution?

The unlawful gain is the sticking point in my mind.

kenniskrag an hour ago | parent | next [-]

If you publish the bug then it could be unfair competition in my opinion. There was a product test where the mentioned some flaws of a medicine but didnt mention other producers of same drug. They broke the UC rules and paid some money: https://politchronik.swiss/de/prozesse/57953-das-kassensturz...

kenniskrag an hour ago | parent | prev [-]

If you access "private" data it's also unlawful acording to 143. Pentesting is a hot topic but there are comapnys acusing you of hacking if you send them a security report (hacking). If they mention a bug bounty program then you are allowed to test their security as described in this program but not more.