3 ms·
I wouldn't say it's so clear, if you read the article it seems like the developer was investigating an issue and found the database credentials, assumed the dat
by mpeg 3y ago
I wouldn't say it's so clear, if you read the article it seems like the developer was investigating an issue and found the database credentials, assumed the database connection was single-tenant (or that the user would be limited by permissions) as the software was connecting directly to it, and used them. When they realised they had access to more data than intended, they disconnected from it.
I have done exactly the same thing in similar circumstances – I had a desktop software vendor that we had issues with, saw the config files stored database credentials in plaintext and connected to it. In my case, the database was single tenant for our company so I managed to get what I wanted done.
Surely intent must come into play when it comes to applying the law in cases like this? It doesn't seem like the developer had any intent to access a restricted system.