• CompassRed@discuss.tchncs.de
    link
    fedilink
    arrow-up
    39
    ·
    3 days ago

    Maybe you should just try being lucky. I found a critical security vulnerability while working on my scraping project. I told them, they paid me and gave me written permission to scrape.

    • einkorn@feddit.org
      link
      fedilink
      arrow-up
      25
      ·
      2 days ago

      You are braver than I am because here in Germany usually people get sued for reporting security vulnerabilities.

      • EldenLord@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        2 days ago

        I know a guy who did exactly that and got sued. The security failure he reported even was a Straftatbestand committed by the company and so he won the process. German companies really love shooting themselves in the foot.

        • bless@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          1 day ago

          Over here, not just sued, but sued for extortion because they had the audacity to ask for bug bounty. Ok then, if I ever find a security hole that exposes sensitive data, filing a gdpr report it is

          • Victor@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            2 days ago

            But the technology is already there in place, and you get sued if you point out security flaws in it? Crazy.

            • einkorn@feddit.org
              link
              fedilink
              arrow-up
              3
              ·
              2 days ago

              Yes, because any circumvention of any form of security, be it as useless as a hardcoded default password, is considered a crime in German law. So even the discovery of a security flaw puts you with one foot in jail, because technically you did something you are not supposed to.

                • einkorn@feddit.org
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  2 days ago

                  Not like there have been no initiatives. But given that our biggest party also sued after someone pointed out their technical fuck-ups it is not likely to happen.