I think that covers police databases, social security and also customer details on a website amongst others. It would not necessarily cover accidentally accessing customer data on a system (that happens) but if you started wilfully sharing that data or details about how to access it with persons other than the owners of the system then you could start to get into the problematic zone. To prevent the scenario where the owners just do nothing and then when the 'hacker' tells somebody else they call the cops and accuse, it should probably be a crime, after being notified that your system is leaking private data, that you didn't take any action to plug that hole.
Here I disagree, assuming we are still talking about the USA. There are strong freedom of speech implications when you make sharing the fact that some company left their S3 bucket world-readable a criminal offense. Would the New York Times be open to criminal prosecution for publishing such information on their front page?
Very tightly-defined, personally-identifiable data I can see being protected. Things like financial and medical records, sensitive search queries etc. but general disclosure of security issues should not be something that is criminal.
So you find a company leaves their S3 bucket world-readable by accident and it contains personal information that the persons concerned would reasonably consider private (from medical records all the way to my real identity on a forum). The correct course of action is not to exercise your free speech by going first to the New York Times so they can publish a story about it allowing all and sundry to access that information, but to go to the company and tell them that this is open and that information they are responsible for is leaking. This is your responsibility to your fellow citizens whose data is leaking! However, if the company do not fix it in a reasonable time then you can report them to the relevant authorities who can decide what action to take and now the criminal aspect of this data leakage will now be attached to the owners of the company which has not fixed the problem and you are free to exercise your free speech rights.
If I sell (for money, fame, fake internet points or smug satisfaction) access to your personal data without your consent how can I claim that is my free speech? I think the USA has the concept of limits to freedom, ably illustrated by the phrase "Your Freedom To Swing Your Fist Ends Where My Nose Begins"
Why wouldn't that apply to some website that's using some cache exploit to probe users' browsing histories?
I mean, a computer is a computer, and unauthorized access is unauthorized access. No matter who's involved.
My proposal would require companies to actually take security very seriously.
https://www.troyhunt.com/we-take-security-seriously-otherwis...
Are they discussing national secrets over Zoom? Without end-to-end encryption?! That's some form of criminal negligence and/or mishandling of classified information in every jurisdiction I know.
If not, it's little more than a nuisance and a reminder that Zoom should not be relied on for important communications.