• CompassRed@discuss.tchncs.de
    link
    fedilink
    arrow-up
    34
    ·
    16 hours ago

    Maybe you should just try being lucky. I found a critical security vulnerability while working on my scraping project. I told them, they paid me and gave me written permission to scrape.

    • einkorn@feddit.org
      link
      fedilink
      arrow-up
      15
      ·
      10 hours ago

      You are braver than I am because here in Germany usually people get sued for reporting security vulnerabilities.

          • Victor@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            7 hours ago

            But the technology is already there in place, and you get sued if you point out security flaws in it? Crazy.

            • einkorn@feddit.org
              link
              fedilink
              arrow-up
              2
              ·
              4 hours ago

              Yes, because any circumvention of any form of security, be it as useless as a hardcoded default password, is considered a crime in German law. So even the discovery of a security flaw puts you with one foot in jail, because technically you did something you are not supposed to.

              • Victor@lemmy.world
                link
                fedilink
                arrow-up
                2
                ·
                2 hours ago

                Time for some reform. Finding security holes is very important and benefits everyone.

                • einkorn@feddit.org
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  1 hour ago

                  Not like there have been no initiatives. But given that our biggest party also sued after someone pointed out their technical fuck-ups it is not likely to happen.