Elektrine lite

← Feed

@ilumium@eupolicy.social

2026-07-10 07:24 UTC

A proposed change to the German Intelligence Services Law (#BND-Gesetz) would--if enacted--require #cybersecurity authorities to notify any #0day to the German foreign and domestic intelligence service to that they can abuse it until it's fixed. This means friendly hackers that find and notify such #vulnerabilities through official channels would directly contribute to their exploitation by government spies. https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/OESI2/nachrichtendienstrecht.html Via @HonkHase@chaos.social #privacy #DigitalRights #DigitalSecurity

Replies (2)

  • @ilumium@eupolicy.social 2026-07-10 07:30

    The proposal explicitly suggests: "It takes time for a #ZeroDay #vulnerability to be remedied through patches by manufacturers following publication by the Office for Information Security (#BSI); the Intelligence Service (#BND) can use this time to carry out important work. If the BSI is asked to share findings immediately, the time between internal processing, notification to manufacturers, patch provision & installation may be long enough to exploit it for valuable work."

    Open ##3711618

  • @bdm@iceshrimp.de 2026-07-10 13:34

    @ilumium@eupolicy.social @HonkHase@chaos.social What's the idea? Push researchers into black market so that more vulns go into ransomware development? Current government is like a train-collision in slow-motion, painful to watch 🤦

    Open ##4654561