How are these fucking morons going to define legally what is and isn't a "hacking tool"?
How are these fucking morons going to define legally what is and isn't a "hacking tool"?
We programmers need absolute clarity because our systems are executed by machines with no insight. But in other fields where humans execute rules, everyone else just shrugs and deals with little inconsistencies, or make meta-rules about judging "intent", that sort of thing.
Actually, in most of Europe it does.
While the US, UK and Ireland's legal system is based on "Common Law", most of Europe uses "Civil Law", where the primary source of law is the law code, which is a systematic collection of interrelated articles that explain the principles of law, rights and entitlements, and how basic legal mechanisms work.
Of course there's still a lot of room for interpretation and pragmatics, but the point is that right from the start, you try to get your definitions down as clear as possible.
It's quite interesting to see how the fundamentals of our legal systems actually differ. I decided to look this up for the first time because at some point I read some thread where some US people were actively discussing interpretation of your Constitution or the Bill of Rights, as to whether something fairly trivial to define could be ruled or not--might even have had to do with the right to bear arms, but the specifics aren't important. I was just amazed that this centuries-old document was seriously being "consulted" as if somewhere between the lines would appear some sort of hidden meaning--except it was pretty obvious that the final decision would rest with the interpretation and political ideas of whatever judge got to rule it. Which completely amazed me, it's one thing if somnewhere, in some obscure corner of fiscal tax laws some particular exception to a rule isn't defined unambiguously, but the big-to-medium picture of the law is not supposed to be up for interpretation!
Except in the US, or more precisely in Common Law legal systems, that's pretty much the idea.
I'm not saying it's bad BTW, it's just different. And I'm just commenting on how surprised I was that there's other ways (in democratic countries) than to strictly codify your laws.
[1] http://en.wikipedia.org/wiki/Common_law#2._Common_law_legal_...
They won't. They'll just use the broad qualifications to opress the ones they don't feel comfortable with.
Why bother with the hard stuff when opinionated prejudice gets you where you want to go?
Think port scanners, password crackers, vulnerability identification and exploitation tools. Any reasonable person would consider these to be 'hacking tools', and that's all a legal system needs for a definition.
But, once again, these are all perfectly legitimate system engineering tools and are essential for hardening commercial or government or military sites, for example. You can't make something secure unless you know how easy or hard it will be to get past that.
It is like making dynamite illegal for civil engineers or morphine forbidden to medical practitioners or hammers and chisels denied to cabinet makers because they might hurt themselves. Ridiculous!
Described in those terms, what would you say to an exception that permitted possession by authorised information security personnel?
That's akin to the legislation we have in the UK with regards to explosives and controlled substances.
But that's a whole different argument. At present it is "programmers" (self-taught or academic or industrially trained) who make things and routinely test them for hardness. You can't suddenly invent rules that say only certain types of programmer may use and deploy "hacking" tools. That won't work because there is no defined path to test suitability or career fitness in the majority of people who define themselves as "programmers". Too broad a church. Too many disciplines and areas of specialisation. And too few people qualified to legitimately or meaningfully assess that either way. Or are we going to say, for example, only Microsoft Certified Pros are allowed to test? God in heaven forbid!
Reputation (from both peers and clients) and demonstrated output that works is the only test for whether someone is a good or bad (read, fit or unfit) programmer.
And no, in answer to your question, we don't allow only certain government regulated individuals to have legal access to perfectly ordinary systems analysis tools. They are probably the last people you want doing it.
There should never be a legal concept of an "authorized" information security person. It's about like defining a concept of an "authorized" painter or musician, since all are talents that can be developed in isolation.
consider the black hole exploit kit, or the poison ivy RAT, or zeus. these are tools that have one purpose: exploit specific vulnerabilities, some of them unreported, and install monitoring software that allows a third party to take control of a system without that systems user or owners knowledge or consent.
surely the number of times that activity is going to be part of perfectly legitimate system engineering would be vanishingly small? when would you need to exploit a 0day vulnerability as part of legitimate system engineering?
When you think you have just found a 0-day in your systems and want to check if you are right or not.
That's like shooting yourself in the foot to see if the bullet hole is the same.
Exploiting a bug on your system to verify that it is a bug that can be exploited would seem to be one of the very first things to do after verifying your backups, if you think you have found a 0-day vuln.
Otherwise, how would you know that it is what you think it is?
There is no general procedure you can run on code to check this for you other than actually checking it and seeing what it does.
If I was running a massive company, I would want my network security team to be buying up the latest cracking tech and checking it against as much of the corporate systems as possible.
Any corporation with any sense and lots of stuff they need to secure pays people to attack their corporate networks with anything and everything available, and then report back.
My first intuition would be all for it, actually. Though there might be some consequences I haven't considered.
For all I know that could already be illegal? Anyone?
Anyone with software affected by a 0-day is effectively a legitimate buyer of that bug.