3 ms·
If this (not infosec) person was doing this type of security probing during work hours using work equipment, I could see them being fired even if they are hacki
by Benjammer 5y ago
If this (not infosec) person was doing this type of security probing during work hours using work equipment, I could see them being fired even if they are hacking on the company’s own product.
You’re not paid as a competitive intelligence analyst and security researcher, regardless of your “personal interests,” you’re paid to work on a product to make the company more money.
Furthermore, if you start unpacking the mobile app of a bank and doing actual pen testing analysis in the wild hitting their prod servers, even accidentally, you seriously need to understand the situation you are putting yourself in, regardless of where you work.
- aldebran 5y agoThis is the part I’m stunned about. So many in this thread don’t see the liability of unpacking a competitors app and poking around their APIs. Forget CC fraud. This opens up liability for IP theft. Even if the other company doesn’t win the case it is going to create a shitstorm that might potentially give them free PR. “Look our new product is so good their devs are reverse engineering our innovation to copy us” Forget what this person found out. Going and unpacking the app and using private APIs itself was a dumb move regardless of what happened after. People can be idealistic and talk about intent but it really is a bad move that opens all kinds of liabilities.
- ratg13 5y agoPersonally I don't think what he did was wrong. I think the moral of the story is don't do non-work related things on your work computer. It shifts the liability from the individual to the company.
- meetups323 5y agoBut also don't do work related things on your non-work computer. Investigating the source code of your company's competitor's products is absolutely work related.
- Benjammer 5y agoThe thing that is kind of baffling to me about so many people in this comment section is that they think their personal opinion about the ethics of what he did has any bearing on anything. That's not how the legal system works at all. To quote Tom Scott, a youtuber, "I'm not telling you how it should be, I'm just telling you how it is."
- aldebran 5y agoPrecisely. Any corporate lawyer reading this thread is probably hoping none of the engineers in their company think this way. In my old company we were told to perform competitor analysis only through publicly available information - blogs, marketing announcements, videos, ads, etc. No creating a free account to poke around. I often wondered what happened in the past to have this rule.
- ratg13 5y agoAll the actions here were decisions made by a private company. At the present time the legal system is not involved beyond anything other than the terms of employment in the employee's contract. Just because a company may have the right to fire a person at will does not prove that the employee did anything wrong. (morally or legally)
- paganel 5y ago> if you start unpacking the mobile app of a bank and doing actual pen testing analysis in the wild hitting their prod servers, even accidentally That sounds pretty damn incriminating, not sure how the OP thought he could get away with it. The article is not available anymore but at first I had thought that he might have poked around with the help of Chrome inspect tools on their competitors' web app, saw a call or two being made to their backend API and then randomly changed the ID in the query being made or something like that and see what the response would be. But unpacking the mobile app to see what API backend calls are being made is on a whole another level. To be fair, nowadays I would not even choose to do the first thing, i.e. playing around with making backend API calls based on what I can see through Chrome inspect tools, I've read about too many cases of people getting in legal trouble about it to now know better. I might have done it 5 or 7 years ago, but definitely not now.