Elektrine lite

← Feed

@WPalant@infosec.exchange

Post #3134777

2024-01-18 12:55 UTC

@thisismissem@hachyderm.io Difficult. If we spin this analogy further: you gave me your key for a specific purpose (e.g. pizza delivery while you were out), after which I returned it to you. You didn’t allow me to make a copy of this key and use it later to rearrange the furniture for example. Abusing hardcoded credentials can definitely constitute hacking and cause perfectly justified criminal charges. But intention and damage caused definitely need to go into the equation, not merely “circumvention of protection mechanisms.”

Replies (3)

  • @thisismissem@hachyderm.io 2024-01-18 12:58

    @WPalant@infosec.exchange in this case it just sounds like he used the key to open the front door, saw an absolute mess & notified the company of the issue

    Open ##3134778

  • @tklengyel@discuss.systems 2024-01-18 13:22

    @WPalant@infosec.exchange @thisismissem@hachyderm.io Intent and damages should absolutely matter. But it's also common sense not to use the hardcoded credentials to login and dump the database. Or if you do, why report that you did? Perfectly sufficient to just say you found the hardcoded credentials and stop there.. Bad practice on both sides.

    Open ##3134784

  • @pierstoval@mastodon.social 2024-01-18 14:46

    @WPalant@infosec.exchange @thisismissem@hachyderm.io Many judges in court don't know jack shit about programming, and "compiling" is the same as "encrypting" for them. As many analogies said: if you give someone the key to your house, whether it's wrapped in tons of cardboard and tape, they still have the key. The software provider must be condemned as a security flaw, endangering all users.

    Open ##3134790