Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Everything is a hacking tool. Every programming language and every pre-existing piece of software, every computer and every phone is a potential hacking tool. Thought itself is the biggest hacking tool.

How are these fucking morons going to define legally what is and isn't a "hacking tool"?



The law has no trouble at all making fuzzy distinctions. They are attempting to keep the peace, not make orthogonal cuts into reality.

We programmers need absolute clarity because our systems are executed by machines with no insight. But in other fields where humans execute rules, everyone else just shrugs and deals with little inconsistencies, or make meta-rules about judging "intent", that sort of thing.


> The law has no trouble at all making fuzzy distinctions.

Actually, in most of Europe it does.

While the US, UK and Ireland's legal system is based on "Common Law", most of Europe uses "Civil Law", where the primary source of law is the law code, which is a systematic collection of interrelated articles that explain the principles of law, rights and entitlements, and how basic legal mechanisms work.

Of course there's still a lot of room for interpretation and pragmatics, but the point is that right from the start, you try to get your definitions down as clear as possible.

It's quite interesting to see how the fundamentals of our legal systems actually differ. I decided to look this up for the first time because at some point I read some thread where some US people were actively discussing interpretation of your Constitution or the Bill of Rights, as to whether something fairly trivial to define could be ruled or not--might even have had to do with the right to bear arms, but the specifics aren't important. I was just amazed that this centuries-old document was seriously being "consulted" as if somewhere between the lines would appear some sort of hidden meaning--except it was pretty obvious that the final decision would rest with the interpretation and political ideas of whatever judge got to rule it. Which completely amazed me, it's one thing if somnewhere, in some obscure corner of fiscal tax laws some particular exception to a rule isn't defined unambiguously, but the big-to-medium picture of the law is not supposed to be up for interpretation!

Except in the US, or more precisely in Common Law legal systems, that's pretty much the idea.

I'm not saying it's bad BTW, it's just different. And I'm just commenting on how surprised I was that there's other ways (in democratic countries) than to strictly codify your laws.

[1] http://en.wikipedia.org/wiki/Common_law#2._Common_law_legal_...

[2] http://en.wikipedia.org/wiki/Civil_law_(legal_system)


> How are these fucking morons going to define legally what is and isn't a "hacking tool"?

They won't. They'll just use the broad qualifications to opress the ones they don't feel comfortable with.


Ah, of course. How stupid of me to think that they would have an empirical definition or set of legal definitions that actually was robust and made coherent sense.

Why bother with the hard stuff when opinionated prejudice gets you where you want to go?


This is 'hacking' a la the popular meaning of the term (gaining unauthorised entry to a computer system), not the definition adopted by self-described 'hackers'.

Think port scanners, password crackers, vulnerability identification and exploitation tools. Any reasonable person would consider these to be 'hacking tools', and that's all a legal system needs for a definition.


As an ex network admin, not having port scanners and vulnerability testing tools would make me feel blind. Those tools have very legitimate uses. Port scanners don't even have to be used for security purposes, sometimes you can't access a machine and want to see what services are active and open to the world etc.


There will probably be a vague exception for legitimate professional use, the way there is for burglary tools. Varies based on the jurisdiction, but whether carrying a lockpick set is illegal depends a lot on factors like whether you're a locksmith, the circumstances in which you were carrying it, etc. The crime essentially boils down to something like: carrying a lockpick set while seeming suspicious and not having a good excuse.


Indeed. I often find myself using nmap on my own network to find out which IP address was assigned to a system when .local/mDNS name resolution is down and the DHCP server doesn't provide enough info to identify a specific computer.


"Think port scanners, password crackers, vulnerability identification and exploitation tools. Any reasonable person would consider these to be 'hacking tools'"

But, once again, these are all perfectly legitimate system engineering tools and are essential for hardening commercial or government or military sites, for example. You can't make something secure unless you know how easy or hard it will be to get past that.

It is like making dynamite illegal for civil engineers or morphine forbidden to medical practitioners or hammers and chisels denied to cabinet makers because they might hurt themselves. Ridiculous!


> It is like making dynamite illegal for civil engineers or morphine forbidden to medical practitioners or hammers and chisels denied to cabinet makers because they might hurt themselves. Ridiculous!

Described in those terms, what would you say to an exception that permitted possession by authorised information security personnel?

That's akin to the legislation we have in the UK with regards to explosives and controlled substances.


The problem with regulating possession of specific kinds of software is that they are entirely a product of the mind. You need specific precursor materials to create explosives and controlled substances, but anybody can imagine and create a good system administration tool.

There should never be a legal concept of an "authorized" information security person. It's about like defining a concept of an "authorized" painter or musician, since all are talents that can be developed in isolation.


There are no legal definitions for being a programmer. There are for being a medical practitioner or a civil engineer. Only practising doctors who are certified to practice may prescribe. Only legally certified civil engineers who after prerequisite training and certification are permitted to handle high explosives and blow things up. Having a degree alone in either of those two professions does most certainly NOT on its own qualify you to do either. Or anything much. So maybe a bad example.

But that's a whole different argument. At present it is "programmers" (self-taught or academic or industrially trained) who make things and routinely test them for hardness. You can't suddenly invent rules that say only certain types of programmer may use and deploy "hacking" tools. That won't work because there is no defined path to test suitability or career fitness in the majority of people who define themselves as "programmers". Too broad a church. Too many disciplines and areas of specialisation. And too few people qualified to legitimately or meaningfully assess that either way. Or are we going to say, for example, only Microsoft Certified Pros are allowed to test? God in heaven forbid!

Reputation (from both peers and clients) and demonstrated output that works is the only test for whether someone is a good or bad (read, fit or unfit) programmer.

And no, in answer to your question, we don't allow only certain government regulated individuals to have legal access to perfectly ordinary systems analysis tools. They are probably the last people you want doing it.


that's probably what they want


port scanners, password crackers, vulnerability identification tools, all have legitimate system engineering uses.

consider the black hole exploit kit, or the poison ivy RAT, or zeus. these are tools that have one purpose: exploit specific vulnerabilities, some of them unreported, and install monitoring software that allows a third party to take control of a system without that systems user or owners knowledge or consent.

surely the number of times that activity is going to be part of perfectly legitimate system engineering would be vanishingly small? when would you need to exploit a 0day vulnerability as part of legitimate system engineering?


"when would you need to exploit a 0day vulnerability as part of legitimate system engineering?"

When you think you have just found a 0-day in your systems and want to check if you are right or not.


okay, when would you need to purchase a 0day vulnerability from someone else to exploit thousands of other systems as part of legitimate system engineering?


Well, if they'd be considering to outlaw selling 0days on the black market, that'd be a whole different discussion.

My first intuition would be all for it, actually. Though there might be some consequences I haven't considered.

For all I know that could already be illegal? Anyone?


The problem is defining the black market.

Anyone with software affected by a 0-day is effectively a legitimate buyer of that bug.


Well, if working for a company where you are in charge of the security of thousands of systems, you might be asked to do exactly this.

If I was running a massive company, I would want my network security team to be buying up the latest cracking tech and checking it against as much of the corporate systems as possible.

Any corporation with any sense and lots of stuff they need to secure pays people to attack their corporate networks with anything and everything available, and then report back.


> When you think you have just found a 0-day in your systems and want to check if you are right or not.

That's like shooting yourself in the foot to see if the bullet hole is the same.


More like shooting a dummy in the foot? How is this even a valid comparison?


Huh? Same as what? We are talking about 0-day vulns. By definition if you think you have found a 0-day, you have little to compare it to.

Exploiting a bug on your system to verify that it is a bug that can be exploited would seem to be one of the very first things to do after verifying your backups, if you think you have found a 0-day vuln.

Otherwise, how would you know that it is what you think it is?

There is no general procedure you can run on code to check this for you other than actually checking it and seeing what it does.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: