Hacker News new | ask | show | jobs
by ya30a 2682 days ago
What would happen if a plebeian performed this free pen testing? I think we have several examples.

In several countries pen testing tools for plebeians are even illegal.

3 comments

Sure, it's one rule for them, and another for everyone else.

But, lets be reasonable for a second, Japan is concerned that if people's networks aren't secured before the Olympic games, these vulnerable devices will be used to disrupt systems by outside attackers and potentially costing the country significantly.

It's well known that IoT devices on the market are poorly implemented and poorly secured and rarely-to-never updated by the manufacturer.

People run pen testings every day. You might know https://www.shodan.io/ ?
Note that Shodan doesn't try to authenticate with the devices - not even using default credentials. This is different than what Japan is proposing; they want to try various default credentials to identify devices that could be used for various attacks (ex. Mirai).
So is arresting someone unless your a police officer...