10/21/2008

De Standaard did illegal hacking ?

One of the main serious newspapers of Belgium De standaard had a catchy frontpage article 'everybody can be a cyberhacker'. So what was it all about ? Would we all steal and trade credit and personal data ? Would we be hacking into critical infrastructure ? No, we could download lists of emaillistings of a small newsletterprovider and change the contents of a website.

This is an enormous title for a small story. THere is a lot more going on and there is a lot more than that that is possible - even if we can't publish that kind of information and we wouldn't say it behind closed doors in parliament either because someone would talk to the press like they already do with the closed commissions about the intelligence institutions. If they already leak information about our intelligence institutions why should we be confident that they wouldn't leak other information ?

THere is some good points that are being made by our 'comrade in arms' Luc Beirens of the FCCU  but we would like to say also that we need in Belgium a CERT and responsable disclosure.

Because with the strict interpretation of the cybercriminality law in Belgium De Standaard can be prosecuted. The fact that they contacted the firms they had 'penetrated' changes nothing at that fact. They had no approval to do this 'penetration testing' so they were doing an illegal act according to our law. We don't like that law for this reason. It only installs the omerta and so nobody knows how to contact someone when they by accident find or know about vulnerabilities and illegal data on the Belgian web. Each time you can be prosecuted instead of the incompetent programmer or hoster or the hacker himself.

10:11 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment