3 ms·
I think the argument would go something like "just because there was a flaw in the security doesn't mitigate malicious exploitation of that flaw." To take an an
by thinkharderdev 5y ago
I think the argument would go something like "just because there was a flaw in the security doesn't mitigate malicious exploitation of that flaw." To take an analogy, if a bug in a banks website allowed you to make negative transfers (i.e. "pay" someone a negative sum and move money from their account to yours) then you would almost certainly be prosecuted for exploiting that bug. Even exploiting it as a proof of concept so you could report the vulnerability to the bank would probably be dicey territory.
Ultimately there has to be a judgement of intent which at some level requires subjective assessment. In this case it is blindingly obvious that the reporter was acting in good faith so ti seems unlikely any reasonable prosecutor would pursue this case, or if they did any reasonable juror would convict.