Hacker News new | ask | show | jobs
by junto 4720 days ago
This kind of pen-testing, without previous authorization, is a very risky enterprise if you live in the UK. The Computer Misuse Act 1990 expressly forbids "unauthorised access". Sections 1-3 of the Act introduced three criminal offences:

- unauthorised access to computer material, punishable by 6 months' imprisonment or a fine "not exceeding level 5 on the standard scale" (currently £5000);

- unauthorised access with intent to commit or facilitate commission of further offences, punishable by 6 months/maximum fine on summary conviction or 5 years/fine on indictment;

- unauthorised modification of computer material, subject to the same sentences as section 2 offences.

If he had been contracted to pen-test the website by Apple then it would be a different matter.

2 comments

Those laws are retarded and it's sad to see them defended in HN.

Always try to do a parallel without computers to see if a computer law pass the retarded test.

In this case "it's illegal to enter a door left wide open for months, pick up a wallet full of money from a desk visible inside thru said open door, and return it to the home owner with all the money and a note about closing the door because it's not a safe neighborhood"

He cannot return the data per se, so there is a difference. Once it leaves Apple's servers it could be less secure and he's not registered as a data controller I'm sure.

In your example above, why could the person not just point out that the money was not safe? It's no loss to them if the person does not act on the information.

I don't believe I defended those laws, nor critised them. I merely stated the facts.
Agreed. I would think cases like the Andrew Auernheimer (who was convicted and sentenced to three years in jail) would be a wake up call for pen testing sites without prior authorization.

Taking the 73 accounts is arguable in court.

Once you cross the line and scrap another 100K users in order to get their attention and shut the developer site down - you've just boxed yourself. There is no really no defense for doing something like this, regardless of your motives.