319
submitted 10 months ago by L4s@lemmy.world to c/technology@lemmy.world

IT consultant in Germany fined for exposing shoddy security::Spotting a plaintext password and using it in research without authorization deemed a crime

you are viewing a single comment's thread
view the rest of the comments
[-] autotldr@lemmings.world 5 points 10 months ago

This is the best summary I could come up with:


Back in June 2021, according to our pals at Heise, an contractor identified elsewhere as Hendrik H. was troubleshooting software for a customer of IT services firm Modern Solution GmbH.

And we're told that Modern Solution's program files were available for free from the web, so truly anyone could inspect the executables in a text editor for plain-text hardcoded database passwords.

In June, 2023, a Jülich District Court in western Germany sided with the IT consultant because the Modern Solution software was insufficiently protected.

"The penalty order is all the more shocking because it is fundamentally wrong," wrote Steier, the blogger who helped bring the exposed database to light, in a post on Wednesday.

In a post to Mastodon, Wladimir Palant, a security researcher, software developer, and co-founder of Germany-based ad filtering biz eyeo, expressed frustration with the court's decision.

"But it’s exactly as people feared: no matter how flawed the supposed 'protection,' its mere existence turns security research into criminal hacking under the German law.


The original article contains 659 words, the summary contains 166 words. Saved 75%. I'm a bot and I'm open source!

this post was submitted on 22 Jan 2024
319 points (99.4% liked)

Technology

59708 readers
1473 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS