This kind of pen-testing, without previous authorization, is a very risky enterprise if you live in the UK. The Computer Misuse Act 1990 expressly forbids "unauthorised access". Sections 1-3 of the Act introduced three criminal offences:<p>- unauthorised access to computer material, punishable by 6 months' imprisonment or a fine "not exceeding level 5 on the standard scale" (currently £5000);<p>- unauthorised access with intent to commit or facilitate commission of further offences, punishable by 6 months/maximum fine on summary conviction or 5 years/fine on indictment;<p>- unauthorised modification of computer material, subject to the same sentences as section 2 offences.<p>If he had been contracted to pen-test the website by Apple then it would be a different matter.