Post #3711619
2026-07-10 07:24 UTC
A proposed change to the German Intelligence Services Law (#BND-Gesetz) would--if enacted--require #cybersecurity authorities to notify any #0day to the German foreign and domestic intelligence service to that they can abuse it until it's fixed.
This means friendly hackers that find and notify such #vulnerabilities through official channels would directly contribute to their exploitation by government spies.
https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/OESI2/nachrichtendienstrecht.html
Via @HonkHase@chaos.social
#privacy #DigitalRights #DigitalSecurity
Replies (1)
-
@ilumium@eupolicy.social 2026-07-10 07:30
The proposal explicitly suggests: "It takes time for a #ZeroDay #vulnerability to be remedied through patches by manufacturers following publication by the Office for Information Security (#BSI); the Intelligence Service (#BND) can use this time to carry out important work. If the BSI is asked to share findings immediately, the time between internal processing, notification to manufacturers, patch provision & installation may be long enough to exploit it for valuable work."