logo

German security researchers at risk of prosecution for “hacking” because of a plain text hardcoded password?

ID: 74458ce6-3096-5e0f-96ca-3e3bec55a011

STIX ID: report--74458ce6-3096-5e0f-96ca-3e3bec55a011

Feed Name: DataBreaches.Net

Date Published: 2024-01-19

Date Updated: 2026-04-19

Author: Dissent

...
...

A report highlights a case in Germany where a developer was convicted of hacking after discovering hardcoded MySQL credentials in an application and responsibly disclosing that the vendor’s database exposed multiple customers’ data. The vendor fixed the issue but pursued charges, and the court ruled that the mere presence of a password constituted a protection mechanism that was circumvented. This outcome raises concerns about chilling effects on legitimate security research under German law.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.