Hacker News new | ask | show | jobs
by wslack 1575 days ago
It's still a breach if an org misconfigures an API, allowing more records to be available than was indended.
1 comments

Mens rea is honestly a mistake.

I don't care what the org "intended" to do. The org assumed the responsibility of providing an API and with it the responsibility of securing private data. They failed and should be held culpable.

Boeing doesn't call it a "cyberattack" when their altitude control systems fail because of poor design.