back
1 comments
AFAIK felonies in Germany require "intent", not "criminal intent". The guy could have stopped earlier, right after testing the password. But he decided to use it to view data which didn't belong to him. I realize I'm going against the general public opinion, but he didn't have to do that, and I can see why the court didn't accept "but I only did it to take screenshots" as a valid defense, because that's clearly intent.
Modern Solution would have claimed that the password wouldn‘t have allowed access to important data.
So be it. Publicly disclose the vulnerability and stop doing business with them.
He didn’t do business with them, his customer did.
And publicly disclose that the publicly available software contains the password in plain text could have been construed as aiding a criminal offense.
He was ordered by his customer to look into logging problems.
He found the password in plain text, looked into a database he thought contains only data of his customer and found it‘s data of other customers too.