If you’re reporting to a nontechnical team…which sometimes you are…sometimes you do?
If you’re reporting to a nontechnical team…which sometimes you are…sometimes you do?
In jurisdictions like the one I'm most familiar with, it's official national policy not to prosecute when you did the minimum necessary. In a case where you're otherwise stuck, it's entirely reasonable to retrieve 1 record for the sake of a screenshot and preventing a bigger data leak. You could also consider doctoring a screenshot based on your own data. By the time they figured out the screenshot was fake, it landed on a technical person's desk who saw that the vulnerability is real
Lots of steps to go until it's necessary to dump the database as OP did, but I'll agree it can sometimes (never happened to me) be necessary to access at least one other person's data, and more frequently that it will happen by accident
They're perfectly capable of hiring incident response experts, and companies commonly have cyber insurance that'll pay for it.
"Demonstrating" is dumb and means you turn an ordinary disclosure into personal liability for you.
Blabbing about it on the internet is just the idiot cherry on the stupid cake.
Agree otherwise.
In the stories I’ve carefully read, no proof means being ignored by frontline people who are all you can reach,
turning an ordinary disclosure into no disclosure at all.
Whether or not you feel it’s your concern (or “problem”) depends on your thoughts on moral responsibility to others in your society.
If you act in certain ways, you will probably not get in trouble but I have a lawyer on retainer for a reason lol
The harsh truth is you aren't protecting anything by doing this, because you can't control how (or if!) they fix the problem. All you're doing by accessing the data is for-real committing a felony, and that is an incredibly stupid thing to do.
You take steps that match the threat model - if it’s important enough to you.
Not everything found is.
Some things are.
You don’t have to be Batman to want your data secure.
Are we and the Maltese government just going to trust this guy and assume he has actually deleted everything, with no investigation?
What a weird way to think about this.
and your societal goals for ensuring the next exploit is reported, not ignored or shared online.