Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Blue Footed Booby
Oct 4, 2006

got those happy feet

uninterrupted posted:

Worth noting that these laws are extremely broad because lots of companies are uniquely vulnerable to being hacked. Secure code is hard to write and often orthogonal to quickly written or performant or simple to maintain code, and especially companies that are small or don’t have a tech focus will have tons of vulnerabilities lying out in public.

Legally it shouldn’t matter, but the wide scope of laws against hacking disincentivizes a lot of attacks.

There's also the issue that security is impossible to maintain without compliance of employees, most of which are thoroughly unqualified to understand what they're complying with. Hell is in fact other people.

Adbot
ADBOT LOVES YOU

Blue Footed Booby
Oct 4, 2006

got those happy feet

Aramis posted:

That's a heck of a leap to conclusion. The hacker did a lot more than just access an unlisted URL. They wrote a script to systematically iterate through semantically empty ids in order to discover and access resources that they knew were not meant to be public.

This idea that at the end of the day "all they did was access publicly available resources" removes several layers of context, and is only true in the strictest of technical sense.

Not to mention that applying for access to the information shows he knew access was restricted, and that anything he came up with after being rejected wasn't intended.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply