4 ms·
If a security researcher finds and reports a flaw in a system, they can get in trouble for unauthorized access. This is dumb, since we want flaws to be disclose
by s_tec 10y ago
If a security researcher finds and reports a flaw in a system, they can get in trouble for unauthorized access. This is dumb, since we want flaws to be disclosed so they can be fixed. In a certain sense, systems that can be accessed, should be accessed.
The real problem isn't unauthorized access; it's what someone does with that access. Someone who gains access to information but does nothing with it hasn't really done anything wrong. The law should apply only when that access is used for harm (vandalism, corporate espionage, fraud, or whatever is relevant). Right now, the law penalizes the access itself, which is backwards.
If we apply this logic to the FBI, then sure, let them hack away. Without the due process of a warrant, however, none of the stolen information should be admissible in court. The problem isn't the hacking; it's making inappropriate use of stolen information.
- aggie 10y agoUnfortunately, the inadmissibility of evidence due to being obtained without warrant seems to be eroding: http://www.nytimes.com/2016/06/21/us/supreme-court-says-police-may-use-evidence-found-after-illegal-stops.html http://www.nytimes.com/2016/06/21/us/supreme-court-says-poli...