Maybe fixing the child is easier than fixing the software.
Maybe fixing the child is easier than fixing the software.
Of course they were furious at your hacking. And of course you should have not done that regardless of what fault the system had. (They would be in the wrong of they tried to impose serious consequences on 10 years old, which I hope did not happened.)
If you have an isolated network that is truly airgapped from any other network then and only then is it remotely acceptable to “leave your doors unlocked”. This doesn’t absolve the criminals who deface/destroy/steal your PII/data but rather you’ve got to adapt to the times.
But in situation described above, it sounds like it was not fuzzy at all.
The infrastructure can be a danger to others, to employees, etc.
So yes, it's a mandatory duty for organization owners to secure their infrastructure.
There's a problem with the reaction to security issues in most of the countries.
"Hacking" isn't the same as "breaking in". Breaking into somewhere is usually destructive, dangerous, can be done b anyone and reveals no poor security (how did they forget to protect their vault door from a drill and plastic explosives??). A DDoS attack falls into this same category - a boring zero-skill brute force attack that can only be interpreted as malicious.
"Real hacking", however, isn't any of those things. If I put on an orange jumper and walk right into the back of my local bank and straight down to the vault without so much as a confused glance from a guard, they will, as they should, be more concerned with firing their guards for dangerous incompetence than prosecuting me for walking past an "employees only" sign. Especially if I, after arriving at the vault, called the bank manager and explained how bad their security is.