7
5 Comments

Good-faith hackers no longer prosecuted

https://techcrunch.com/2022/05/19/justice-department-good-fatih-hackers-cfaa/

Interesting turn of events. "Good-faith security research" and good-faith hacking will no longer be charged by the DOJ. That means doing it "in a manner designed to avoid any harm to individuals or the public" and that is "used primarily to promote the security or safety..."

submitted this linkon May 19, 2022
  1. 1

    I wonder where they’ll draw the line of good and bad faith.

  2. 1

    So will this mean more hackers trying to find weakness to exploit, and then selling that information back to the companies? Would be a cool gig!

    1. 1

      So will this mean more hackers trying to find weakness to exploit

      Probably 🙂

  3. 1

    I didn't realize it was illegal in the first place. Why would you make white hats illegal?

    1. 1

      Some of the testing activity can be disruptive, trigger responses and waste resources.

      There are bug bounty platforms where orgs can specify the rules for when and where they want you to test and the amounts they’re willing to pay for certain types of bug.
      Outside of this you’re basically considered hostile by default.