By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Germany drafts law to protect researchers who find security flaws
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Germany drafts law to protect researchers who find security flaws
Tech News

Germany drafts law to protect researchers who find security flaws

By admin 4 Min Read
Share
SHARE

The Federal Ministry of Justice in Germany has drafted a law to provide legal protection to security researchers who discover and responsibly report security vulnerabilities to vendors.

When security research is conducted within the specified boundaries, those responsible will be excluded from criminal liability and the risk of prosecution.

“Those who want to close IT security gaps deserve recognition—not a letter from the prosecutor,” stated Federal Minister of Justice Dr. Marco Buschmann.

“With this draft law, we will eliminate the risk of criminal liability for people who take on this important task,” mentions the Minister in the same statement.

Additionally, the proposed amendment to the criminal law introduces stricter penalties for serious cases of data spying and interception, particularly when critical infrastructure is targeted.

Protecting security researchers

The new draft law amends Section 202a of the Criminal Code (StGB) to protect IT security researchers, companies, and so-called “hackers” from punishment under computer criminal law.

This applies when their actions are carried out to detect and close a security vulnerability, as long as they are not considered “unauthorized.”

The criteria to meet for security research are the following:

  1. The action must be carried out with the aim of identifying a vulnerability or another security risk in an IT system.
  2. The researcher must intend to report the identified security vulnerability to a responsible entity capable of addressing the issue, such as the system operator, the software manufacturer, or the Federal Office for Information Security (BSI).
  3. The act of accessing the system must be necessary to identify the vulnerability. This ensures that the exemption only applies to the extent required for security testing, without unnecessary or excessive access.

The same exclusion from criminal liability is also applied to offenses pertaining to data interception (§ 202b StGB) and data modification (§ 303a StGB) as long as the related actions are deemed authorized.

At the same time, the draft fill introduces a penalty ranging from three months to five years of imprisonment for severe cases of malicious data spying and data interception (§ 202a StGB).

In terms of what constitutes a severe case, the draft bill mentions the following cases:

  • The offense results in substantial financial damage.
  • The act was driven by a profit motive, conducted on a commercial scale, or carried out as part of a criminal organization.
  • Cases that compromise critical infrastructure—like hospitals, energy suppliers, or transportation networks—or affect the security of Germany or one of its states, including attacks originating from abroad.

More details about the draft law and proposed amendments are available here.

Federal states and concerned associations have received it for review and are given until December 13, 2024, to submit their feedback before it is presented to the Bundestag for parliamentary deliberation.

The U.S. Department of Justice announced a similar revision to the Computer Fraud and Abuse Act (CFAA) in May 2022, introducing prosecution exclusions for “good-faith” security researchers.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Cybersecurity, Germany, Legal, Security, Security Researcher, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Traders dump Cardano and IOTA as they move to Vantard
Next Article How to Secure Microsoft 365 on Personal Devices 2024
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?