Help Reform Computer Crime Laws
hackerone.com
hackerone.com
I know this is an unpopular opinion here, but I personally think that you shouldn't mess with people's shit unless they invite you to (e.g. by having a bounty, research partnership program, etc.). Yes, some organizations will be less secure because of it. Similarly, some houses are less secure because the locks are low quality. It isn't up to you to decide how thoroughly said locks should be checked.
Is the key term here. What counts as people's shit? If I, as a customer of a company, find out my shit (lets say personal information) is insecure because a security researcher investigated a security flaw in a company's API: Is that ok?
This gets even more blurred when lets say my shit (house) is in imminent threat of destruction because the chemical plant 1 mile away can easily be explosively sabotaged remotely, releasing toxic chemicals, due to shoddy SCADA security. Don't I and my shit deserve to be protected?
We are getting into the whole "Greater good / public interest" here where such a simple definition as you specified is no longer applicable I think.
The idea that government regulations could cover digital security is something that I do not believe possible. The whole history of SCADA is a pretty good example.
It is even further harmful when the laws are aggressively applied to prevent research into personal property, especially when your personal safety may depend upon it. For example, your car: https://twitter.com/0xcharlie/status/600729130355666944
Do you make a habit of visiting banks uninvited to test their vaults?
The analogy doesn't hold when applied to the digital services we all depend upon as such assurances are impossible.
Rather than allowing anyone to try to crack a server as long as they claim to be a white hat, I'd much rather require corporations to go through a standard, "extensive third-party verification of security practices that may be publicly audited upon request" and default cracking attempts to "illegal."
I may be misunderstanding something in what you're saying, though -- if I am, could you clarify that for me?
Here's the problem: Last job I had, I was told I had to open a google account, because the company used google docs.
Mandatory, I was told. Company policy. I passive-aggressively opened one called <company name>_temp, and deleted it when I finished the job, but I wasn't going to risk the job itself by flat out refusing.
Does a company have the legal authority to compel it's employees to open accounts that require third party agreements? Don't know, not a lawyer, probably country specific, but it's not relevant because even if the legal answer is no, you can't start a lawsuit against your own employer.
Now, Google does have a bounty program, but we used dozens of pieces of software at that company from small providers who did not. As luck would have it, none of them were account based information vacuums, but they could have been, and if they had been, I'd have been at their mercy when it came to security. It would have been that or my job.
My unpopular opinion is that the software industry needs way more regulation. We crash-test cars, we should crash-test software. I definitely support impromptu third party pentesting, because it's currently the only way I find out about lazy companies who don't take my security seriously, particularly ones that I am compelled to use.
They sure as hell never call themselves out on it.
Security researchers try to call attention to security and privacy risks early. They aren't always right, but even when they're wrong, it's still beneficial for the rest of us to have them sounding their warning calls.
One kind of security researcher we would want to protect is the one who finds out they can get information, but doesn't get everything, or doesn't keep what they get, or doesn't get anything really sensitive. Or who establishes that they can modify a system, but doesn't change anything important.
If someone gets my credit card number, and doesn't use it, and points out the problem, I want to thank them.
We make the analogy of breaking into houses, but bad information security is more like someone putting up a post-it note that says "This is a lock."
Sometimes just looking past the lock violates the letter of the law.