• einkorn@feddit.org
    link
    fedilink
    arrow-up
    60
    ·
    edit-2
    19 hours ago

    Guess who recently asked a company if he could get access to the API they use to load stuff in their frontend from their backend and got told “Nope and btw scraping is against our TOS”?

    Well, if you won’t give it to me the info that you provide anyway the easy way, I can still take it the hard way. 🤷‍♂️

    • CompassRed@discuss.tchncs.de
      link
      fedilink
      arrow-up
      34
      ·
      16 hours ago

      Maybe you should just try being lucky. I found a critical security vulnerability while working on my scraping project. I told them, they paid me and gave me written permission to scrape.

      • einkorn@feddit.org
        link
        fedilink
        arrow-up
        15
        ·
        10 hours ago

        You are braver than I am because here in Germany usually people get sued for reporting security vulnerabilities.

            • Victor@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              7 hours ago

              But the technology is already there in place, and you get sued if you point out security flaws in it? Crazy.

              • einkorn@feddit.org
                link
                fedilink
                arrow-up
                2
                ·
                4 hours ago

                Yes, because any circumvention of any form of security, be it as useless as a hardcoded default password, is considered a crime in German law. So even the discovery of a security flaw puts you with one foot in jail, because technically you did something you are not supposed to.

                • Victor@lemmy.world
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  2 hours ago

                  Time for some reform. Finding security holes is very important and benefits everyone.

                  • einkorn@feddit.org
                    link
                    fedilink
                    arrow-up
                    1
                    ·
                    1 hour ago

                    Not like there have been no initiatives. But given that our biggest party also sued after someone pointed out their technical fuck-ups it is not likely to happen.