Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m not in security (thank goodness, it sounds like a legal minefield). It sounds like this system was so wildly insecure that… I actually kinda wonder what laws specifically he broke.

If you just text out passwords to anybody who asks, are they really doing unauthorized access? Lol.

I’m sure it was illegal somehow, though.



It is very likely illegal but also discouraged to be prosecuted. From the federal government's guidelines on prosecuting unauthorized computer access (https://www.justice.gov/jm/jm-9-48000-computer-fraud):

> "The attorney for the government should decline prosecution if available evidence shows the defendant’s conduct consisted of, and the defendant intended, good-faith security research."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: