In Germany you you cannot inform a website that it has a vulnerability, because in their eyes, vulnerabilities can only be found if you’re intentionally looking for it. Therefore you must be a criminal.
Yep. In germany you might get sued for telling a company “hey your security might endanger peoples data”.
Then again, you might get lawyers sent after you for daring to rate a restaurant low here. We take our ability to perform badly but still feel very proud very seriously here.
Was any of this right here correct ? Oh I dunno.
What a stupid law. I can’t actually understand why they would do this because their government helps Interpol all the time so the government is very technologically capable surely they understand the implications of not getting vulnerabilities disclosed like this…
Is it illegal even if the company holds like a contest or something like that?
Wow. Are German websites just full of CVEs all the time?
That’s the beauty of the law - no one knows (except everyone with any expertise, who just won’t admit they know.)
is this in reference to something Im not aware of?
It’s just the German law.
Like… that’s how it is. In Germany.
Magazine of the German association of computer scientists recently did an article on it and we provided this… commentary.
What is the law? That you can’t prepare against cyber attacks?
You need to know how to carry out a cyberattack before you can devise a way to stop it, so CS students need to be taught how to do cyberattacks to learn about cybersecurity.
My CS security class had a virtual machine set up with vulnerabilities, such that each vulnerability you exploited would let you log in as a different user. It was quite fun!
Which is why the so called hacker paragraph is so very controversial.
I hate proto-fascists so fucking much.
deleted by creator
Liberals, larval fascists, the shield arm of fascism.
That you can’t get or distribute or enable people to get applications that could enable people to commit cyber attacks.
Just sent the paragraph through deepl:
Any person who prepares to commit a criminal offense under § 202a or § 202b by
- producing, obtaining for oneself or another, selling, transferring to another, distributing, or otherwise making available passwords or other security codes that enable access to data (§ 202a(2)), or
- computer programs intended for the commission of such an offense,
shall be punished by imprisonment for up to two years or by a fine.
Emphasis mine.
Glad we don’t have such a rule in the Netherlands. My school has “hack friday” every friday, where we come together with a few students and a teacher to do a HackTheBox challenge.
So it’s only illegal if you intend to commit a criminal offense.
This seems like a pretty standard law regarding tools which can be used to commit crimes.
So it’s only illegal if you intend to commit a criminal offense.
IANAL, but the German wording is ambiguous enough for this to not be clear.
Really? Is this ambiguous?
Citation from German law
§ 202c Vorbereiten des Ausspähens und Abfangens von Daten
(1) Wer eine Straftat nach § 202a oder § 202b vorbereitet, indem er
-
Passwörter oder sonstige Sicherungscodes, die den Zugang zu Daten (§ 202a Abs. 2) ermöglichen, oder
-
Computerprogramme, deren Zweck die Begehung einer solchen Tat ist,
herstellt, sich oder einem anderen verschafft, verkauft, einem anderen überlässt, verbreitet oder sonst zugänglich macht, wird mit Freiheitsstrafe bis zu zwei Jahren oder mit Geldstrafe bestraft.
(2) § 149 Abs. 2 und 3 gilt entsprechend.
Emphasis mine.
Edit: Lawyers’ opinion
The issue remains that according to 202a ff, basically any hacking is a crime. If you don’t differentiate there, you don’t differentiate in the 202c either.
Part of the article in the German comp sci assc magazine:
In Germany, all forms of hacking are officially prohibited: Sections 202a–c of the Criminal Code (StGB) criminalize the spying on and interception of data, as well as the preparation thereof and the possession of so-called hacking tools. Ethical hacking is thus prohibited.
-
So it’s only illegal if you intend to commit a criminal offense.
That’s how I read it too but it does depend upon the wording of 202a and 202b that define what a criminal offence is in this context.
Those basically say that unauthorized access to confidential/protected data is illegal. (I’m not a lawyer but check out this article presumably by lawyers)
How is that different from it being illegal to possess the key to someone’s house unknowingly, and to use it for criminal purposes?
So having a password is illegal in Germany??
If you’re not authorized.
Fortunately only if it “enables access to data”.
It’s safer if you stop talking about it, or we’re going to have to report you to the authorities.
At first I thought this comic was about sex education in the US.
Ski masks instead of Guy Fawkes masks and hoodies? Smh probably won’t learn much from this cyber security course
I know, but those are harder to draw! Guess those participants just have become the victims of my artistic laziness.
and tbh I need the refresher 😭









