• CompassRed@discuss.tchncs.de
    link
    fedilink
    arrow-up
    34
    ·
    21 hours ago

    Maybe you should just try being lucky. I found a critical security vulnerability while working on my scraping project. I told them, they paid me and gave me written permission to scrape.

    • einkorn@feddit.org
      link
      fedilink
      arrow-up
      18
      ·
      15 hours ago

      You are braver than I am because here in Germany usually people get sued for reporting security vulnerabilities.

      • EldenLord@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        5 hours ago

        I know a guy who did exactly that and got sued. The security failure he reported even was a Straftatbestand committed by the company and so he won the process. German companies really love shooting themselves in the foot.

          • Victor@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            12 hours ago

            But the technology is already there in place, and you get sued if you point out security flaws in it? Crazy.

            • einkorn@feddit.org
              link
              fedilink
              arrow-up
              2
              ·
              9 hours ago

              Yes, because any circumvention of any form of security, be it as useless as a hardcoded default password, is considered a crime in German law. So even the discovery of a security flaw puts you with one foot in jail, because technically you did something you are not supposed to.

              • Victor@lemmy.world
                link
                fedilink
                arrow-up
                2
                ·
                6 hours ago

                Time for some reform. Finding security holes is very important and benefits everyone.

                • einkorn@feddit.org
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  6 hours ago

                  Not like there have been no initiatives. But given that our biggest party also sued after someone pointed out their technical fuck-ups it is not likely to happen.