this post was submitted on 22 Jan 2024
319 points (99.4% liked)

Technology

59374 readers
7409 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

IT consultant in Germany fined for exposing shoddy security::Spotting a plaintext password and using it in research without authorization deemed a crime

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 133 points 9 months ago (7 children)

I hope it gets reversed in the next instance. The judge had it absolutely wrong. And the consultant did not expose it, but told the company directly that he is able to read the admin password without an effort. They sued for telling them. That's absolutely the worst thing to do.

[–] [email protected] 37 points 9 months ago (1 children)

The people that write laws and the systems that enforce laws are inept to an unbeliavable degree when dealing with anything cyber related so I have less than zero expectations that this gets reversed and actually expect a worse outcome should there be an appeal.

Because somehow only the most incompetent morons appear to be able to make it to judge or law maker.

[–] [email protected] 13 points 9 months ago

The problem is that any judge can judge any domain they have zero knowledge about. They're just expected to understand complex systems because they're educated, and only required to know law (often not even that). The way it should be is that judges making decisions about complex domains should require a level of understanding or specialisation in that domain — judges judging cybersecurity should also have a background in some sort of computer science or engineering discipline.

Otherwise we're just allowing "the internet is a series of tubes" people to dictate human progress.

load more comments (5 replies)