TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Did you test for the heartbleed vulnerability without permission?

5 pointsby comiceabout 11 years ago
Checking services for vulnerabilities without permission is quite likely illegal in many countries (UK in particular). Did you knowingly break the law yesterday testing for it?<p>Do you think it should be legal to do vulnerability checks like this?

2 comments

comiceabout 11 years ago
Instead of just testing one supplier, I tried to ask them about their own assessment. It was a very frustrating experience and took 30mins of faffing around and the only answer I got was they hadn&#x27;t heard about it and were going to look into it (they were a large company btw, other departments of which had issued statements).<p>Compared to just checking it with a script that takes several seconds to run, this was pretty ridiculous.
mchermabout 11 years ago
Yes, yes I did knowingly break the law in doing that test.<p>I rely on the good grace of my employers and my banks not to press charges for this. Of course I commit many other felonies regularly also.[1]<p>Yes, I think it should be legal to do this sort of vulnerability test, but I doubt that the legislature (or even myself, if I were made dictator) has the ability to write a law that criminalizes &quot;bad&quot; exploit abuse while allowing &quot;good&quot; exploit abuse.<p>[1] - <a href="http://www.threefeloniesaday.com/Youtoo/tabid/86/Default.aspx" rel="nofollow">http:&#x2F;&#x2F;www.threefeloniesaday.com&#x2F;Youtoo&#x2F;tabid&#x2F;86&#x2F;Default.asp...</a>