logoalt Hacker News

tptacektoday at 3:34 AM1 replyview on HN

Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this.

I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.

https://news.ycombinator.com/item?id=16642155

What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.


Replies

doc_icktoday at 5:05 AM

Doubt, I’d argue it’s the opposite given the term “vulnerability research” is being overloaded to include things such as F12 on a school website.