1: https://de.wikipedia.org/wiki/Vorbereiten_des_Aussp%C3%A4hen... [de]
I'm not sure white-hat hacking is broadly compatible with German culture. Keep in mind that going bankrupt in Germany permanently closes off lots of avenues, from future lending to whether you can be in senior management at a public company.
They really couldn't. BVerfG (Germany's constitutional court) has clearly said that dual use tools have a presumption of not being tools to break the law. It's been very clear that mens rea matters. And that a narrow reading of the law is the only constitutional reading.
The problem here is taking "word for word" as "by dictionary meaning", which is never how laws are read.
It's still a problematic law (together with §202a/b) because it doesn't clearly carve out space for grey-hat activities (white-hat attacks with authorization really don't fall under it even with creative reading).
On the upside, Germany is considering fixing that. On the downside, it moves with the speed of classic German bureaucracy and is being "discussed" since 2024.
Back in the days of "smart contracts" and "DAOS" this was something many well-meaning technical people struggeled with. Humans and their societies are flexible and therefore laws must be flexible as well (to a certain degree before it becomes damaging).
It's also why a lawyer/expert is usually recommended when engaged with legal matters: We as layman lack all the context around seemingly "simple" concepts, procedures and definitions. You can learn all of that or hire a professional.
In that way, I don't really think the government need to design laws to have loop holes in them. With enough political pressure they can get the judges to make any decision they like.
Fun fact: In the 1990s, the CCC e.V. was declared a terrorist organization by the BND. Also, a lot of members have been sued for Landesverrat (high treason) for disclosing found vulnerabilities and/or doing journalistic work.
For example, the netzpolitik guys have been sued for high treason twice.
Just as a side note on how competent the German state is to use their existing talent to work on issues in cyber security.
> If a hacker collaborates with the BND they do run a risk of many of their peers not wanting to collaborate with them anymore.
Another fun fact: There is no effective witness protection program in Germany. You have to have been attacked almost murdered twice (with legal cases leading to prosecution) before you can apply for the witness protection program.
And they're asking themselves why all the witnesses in high profile cases from Europol/Interpol keep disappearing ...
nor should there be.
Similar to how us American hackers have a huge dislike and distrust of the FBI.
Your own law enforcement agency will lie to you, manipulate you, raid you, extort you, and imprison you over bullshit.
But this is not, how it should be. And not all law enforcement agencies are like this.
80th, 90th were the last time were hacking was a means to an end. C64 and Amiga scene had skindheads showing up at copy parties but no one cared really.
Some were a bit unsure but the moment they talked about their craft there was no divide but hacker spirit.
In recent years this would be unimaginable. And guess what? Talking to each other made the skins disappear.
It was more of a niche expression without doing harm. Popper, Goths, Ted’s, Rockers - in comparison to today there was more unity than today.
Hooligans were the same. Many local groups that fought each other due to political stances befriended each other later because it was more of a ritual than ideology.
It is a bit sad because politics doesn’t belong to hacking, and never did.
Hacking is Boolean only in the sense of it either works or it doesn’t. Or does a computer care about left or right?
And BtW that’s why I find local attempts in Europe for “Go EU” pathetic. It is about ideology, not improvement.