It may be ILLEGAL to run Heartbleed health checks – IT lawyer

  • 11 April 2014
  • 6 replies
  • 2282 views

Userlevel 7
Badge +54
Websites and tools that have sprung up to check whether servers are vulnerable to OpenSSL's mega-vulnerability Heartbleed have thrown up anomalies in computer crime law on both sides of the Atlantic.
Both the US Computer Fraud and Abuse Act and its UK equivalent the Computer Misuse Act make it an offence to test the security of third-party websites without permission.
 
Full Article
 
Interesting but I cannot somehow see vast amounts of people dragged before the courts.

6 replies

Userlevel 7
While that is a concern.... I think in this case it will be forgiven when used for the purpose of determining if safe to change password information.
 
Also... I am pretty sure that any company that chooses to press criminal charges against its users who are attempting to make sure that their login and other data is now secure is likely to end up with no customers.  I certainly will cease dealing with any website that does that.
 
🙂
Userlevel 7
Badge +54
That is it really. For a company to press charges could well end up being a huge own goal for them.
Userlevel 7
Badge +56
Yeah, they'd get hit by the Streisand Effect for sure.
Userlevel 7
Badge +54
And here we have browser plug-ins arriving to scan for vulnerable sites Free Heartbleed-Checker Released for Firefox Browser
So there could in theory be millions brought before the courts.
 
 :@
Userlevel 7
Have always be a fan of Babs...:D
Userlevel 7
Whether it is illegals or not this site may be of interest for those that do want to test out URLs:
 
http://filippo.io/Heartbleed/
 
Give it a try...you may find it useful.
 
REgards
 
 
Baldrick

Reply