Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Writing even this software wouldn’t have been illegal. It’s mentioned in the indictment as a concrete act in furtherance of a conspiracy, part of the technical abstraction of prosecuting a conspiracy in US law.

What is illegal is stealing from banks, and conspiring to steal from banks—and so they’ll show communication, an illegal agreement, and concrete acts in support of the conspiracy. If they weren’t pretty sure they could persuade a jury of those, they wouldn’t have gotten this far.

There are also some devices it’s illegal to build—bombs, for example, and other devices whose only or nearly-only purpose is illegal. Some software is included there, including software whose only purpose is illegal wiretapping.

That makes it legal to write and exchange proofs of concept for vulnerabilities, but you have to be really careful not to make the PoC too pointy.



In Germany, even the act of writing[1] software whose purpose is to access data without authorization[2] or intercept data transmissions intended for someone else[3] is a felony.

[1] https://dejure.org/gesetze/StGB/202c.html

[2] https://dejure.org/gesetze/StGB/202a.html

[3] https://dejure.org/gesetze/StGB/202b.html


Where do you draw a line between a "remote file manager" and "software whose purpose is to access data without authorization"?


The "without authorization" bit?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: