5 ms·
> Comparitech conducts security research that entails scanning the web for exposed databases. When we uncover a database that hasn’t been properly secured and a
by anon1m0us 7y ago
> Comparitech conducts security research that entails scanning the web for exposed databases. When we uncover a database that hasn’t been properly secured and allows unauthorized access, we immediately notify the owner.
Germany, the government, does this. They routinely scan systems in Germany and alert the owners to security issues.
I wonder if this is something all governments should do. I'm not convinced yet, but heavily leaning toward that it is something governments should do.
Exposed servers are a national security risk. They are a risk to public safety. Governments are there to protect their citizens.
- colejohnson66 7y agoAre we sure the governments don’t already do this? The difference between the US and Germany is that the NSA doesn’t alert the company there’s a security hole. The NSA has been found multiple times to be exploiting exploits under the pretenses of catching terrorists. Arguably, by not telling companies about holes in their systems, they are doing the exact opposite of what they were founded to do: secure the US.
- sargun 7y agoThe FBI does this in the US.
- deleted 7y ago[deleted]
- K0SM0S 7y agoIt's generally the thing to do, whether governement or lone programmer —security is a collective matter, bigger than us. Just like we notify people when there's a fire hazard, we don't just stand idle when many people are at risk of something.
- colejohnson66 7y agoA problem arises when you notify them they have a security hazard: they either ignore it, or threaten a lawsuit if you don’t shut up.
- AnthonyMouse 7y agoSome government -- anywhere in the world -- should offer a responsible disclosure service. You disclose to them a vulnerability, anonymously (e.g. via Tor) if you prefer, then they notify the target and impose a reasonable remediation deadline before publication. And then they would all do it because everyone would prefer that they rather than a foreign government are the ones holding 0-days during the remediation period.
- ipsa 7y agoIn the Netherlands there is the NCSC (National Cyber Security Centre). They also scan the internet: It continuously monitors all (potentially) suspect sources on the internet. When it identifies a threat (such as a virus or an attack on a website), it alerts public authorities and organisations. and can act as a mediator: If you discover a security flaw in another government body (such as a municipality or province) or in an organisation with a vital function (such as an energy or telecoms company), please contact the body or organisation first. If you receive no response, please notify the National Cyber Security Centre, which will mediate between you and the body or organisation concerned. with anonimity garantuee: The government treats the notifications it receives confidentially. It will not share your personal details with third parties without your permission unless required to do so by law or a court order. while avoiding court cases for doing your civic duty: When you report the security flaw, check that you comply with the conditions described above. If you do so, the government will not attach any legal consequences to your notification.
- aagd 7y agoBeing from Germany I never heard about government based security checks. IT-wise our government doesn't make a very competent impression. Do you have any background info on this?
- phit_ 7y agohttps://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/CERT-Bund/CERT-Reports/reports_node.html https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/CERT-... https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/IT-Situation-Centre/itsituationcentre_node.html https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/IT-Si... https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/IT-Crisis-Reaction-Centre/itcrisisreactioncentre_node.html https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/IT-Cr...
- aurelian15 7y agoI remember receiving an email from the BSI ("Bundesamt für Sicherheit in der Informationstechnik"; engl. "Federal Office for Security of Information Technology") regarding a misconfigured NTP server that could be abused for NTP reflection attacks. The functions of the BSI are explained in English here [1] based on the following law [2]. I guess initiatives such as informing about the NTP problem fall into what is listed under §3.2. [1] https://www.bsi.bund.de/EN/TheBSI/Functions/functions_node.html https://www.bsi.bund.de/EN/TheBSI/Functions/functions_node.h... [2] https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/BSI/bsiges2009_pdf.pdf?__blob=publicationFile&v=1 https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/BSI/bsig...
- KenanSulayman 7y agoThey pretty quickly send you emails once your email comes up in the whois of a domain that’s pointing to an IP in the allocation space of German companies. Example: hetzner.
- StudentStuff 7y agoThe German government has contributed the base layer to OpenStreetMaps, and uses it for their official parcel/lot line maps. It is much better than the janky pile of crap Esri dumps on most counties in the USA.
- tyingq 7y agoI imagine the NSA routinely keeps vulnerabilities to themselves, for their own use.