Proposed German law a 'win-win' for black hats?
Experts critical of legislation that would ban hacker tools
September 21, 2006 12:00 PM ETIDG News Service - New legislation proposed by the German government aims to make computer hacking a punishable crime.
The draft law, announced Wednesday, defines hacking as penetrating a computer security system and gaining access to secure data, without necessarily stealing data.
As part of the draft, groups that intentionally create, spread or purchase hacker tools designed for illegal purposes could be punished by law, the Federal Ministry of Justice said in a statement.
Other punishable cybercrimes include denial-of-service attacks and computer sabotage attack on individuals, which would extend the existing law that limited sabotage to businesses and public authorities. Offenders could face up to 10 years in prison for major offenses.
Although Germany already has a comprehensive penal law against attacks on IT systems, the proposed revision aims to close any remaining loopholes, the ministry said.
Some security experts warn, however, that "good" hackers, also known as "white hats" who work for security companies, could be restricted in their ability to help software makers and businesses as a result of the proposed law.
If hackers can't share their tools with the public, "white hats will not be able to get them and use them internally for testing or external security consultants won't be able to do security testing," a hacker, known by the pseudonym van Hauser, wrote in an e-mail. "It's a win-lose law in favor for the bad guys."
Van Hauser is president of The Hacker's Choice, a noncommercial group of security experts.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
white hat
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Email Archiving: A Business-Critical Application
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
IBM ISS X-Force Threat and Risk Report
Learn about all aspects of threats that affect Internet security.
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
The New World of eCrime: Targeted Brand Attacks and How to Combat Them
Download This Whitepaper Now!
The Commercialization of ITIL: Lessons Learned
Register for this event today!
