Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a4336f271c4b9318

Jump to content

Lilith Wittmann

From Wikipedia, the free encyclopedia

Lilith Wittmann
Lilith Wittmann in 2021
Wittmann in 2021
Born (1995-09-26) 26 September 1995 (age 31)
CitizenshipGermany
OccupationsSoftware developer, security researcher, activist
Organizationzerforschung

Lilith Wittmann (born 26 September 1995) is a German software developer, security researcher and activist.[1] She is known for identifying security vulnerabilities in digital services, including the CDU connect campaign app, the ID Wallet digital identity app and online gambling platforms.[2][3][4]

Early life and career

[edit]

According to Wittmann, she left school at the age of 16 and subsequently completed vocational training in application development.[5] Alongside her employment, including work at an international management consultancy, she studied political science, sociology and public administration. She is based in Berlin.[1]

In 2020, Wittmann participated in the Work4Germany fellowship programme at Germany's Federal Ministry of Education and Research, where she worked on projects concerning digital education and collaboration within the federal administration.[6]

Wittmann is a member of zerforschung, a collective that investigates the security of information technology systems.[7][8]

Security research

[edit]

Luca and CDU connect

[edit]

Wittmann attracted media attention in 2021 after identifying security vulnerabilities in the Luca contact-tracing app and CDU connect, a campaign app used by the Christian Democratic Union of Germany (CDU).[9][10]

In July 2021, CDU federal managing director Stefan Hennewig filed a criminal complaint naming Wittmann. Before publishing her findings, she had notified the app developer and the relevant authorities and waited until the app had been disabled, following the principles of responsible disclosure.[11][2] In response to the complaint, the Chaos Computer Club announced that it would no longer report vulnerabilities in CDU systems, citing the risk of legal proceedings against security researchers.[2]

Following public criticism, the CDU announced that it had withdrawn the complaint against Wittmann. Hennewig said that the complaint concerned the publication of personal data by third parties and public disclosures made before the CDU was notified. He acknowledged that Wittmann had been involved in neither incident and apologised for naming her.[12]

The investigation was discontinued in August 2021. According to netzpolitik.org, the decision was based on the absence of access controls protecting the data, rather than the CDU's announced withdrawal of its complaint. The relevant provision of German criminal law concerning unauthorised access to protected data therefore did not apply.[13]

Videoconferencing and digital identity

[edit]

In July 2021, Wittmann identified a vulnerability in Visavid, a videoconferencing platform used in Bavarian schools. The vulnerability allowed users to join a conference without approval, bypassing its waiting room.[14]

In late September 2021, Wittmann and Fabian Lüpke reported vulnerabilities affecting the ID Wallet app, including the possibility of taking control of a subdomain belonging to its publisher. Wittmann warned that the vulnerabilities could enable the theft of personal data and identities. The app, which was intended to store documents including a digital version of a driving licence, was withdrawn a few days after its launch.[3][15]

Credit-reporting services

[edit]

In July 2023, Wittmann demonstrated a vulnerability in Bonify, a credit-reporting platform owned by Schufa, by generating and publishing a purported tenant credit report in the name of CDU politician Jens Spahn. Bonify temporarily disabled the affected service following the publication.[16]

In November 2024, she identified a similar vulnerability in the credit-reporting service "it's my data", again using Spahn's name to demonstrate the issue.[17]

Prison systems

[edit]

In June 2024, Wittmann reported that some telecommunications records relating to inmates in German prisons were accessible without password protection.[18] At the 38th Chaos Communication Congress in December 2024, she presented her broader investigation into the security of prison telecommunications systems and administrative software. She also described obtaining prison newspapers for her research and making them available through the website knastarchiv.de.[19]

Online gambling

[edit]

In March 2025, Wittmann published an investigation into vulnerabilities affecting online gambling services operated by the Merkur Group. Records relating to hundreds of thousands of users, including copies of identity documents and correspondence from Germany's employment agency, were accessible through a GraphQL API. The Merkur Group subsequently suspended gambling functions on three online platforms, although the vulnerabilities had reportedly already been fixed.[4]

Several days later, additional online casinos using the same software were taken offline. According to Heise Online, those platforms were suspected of operating illegally in Germany.[20] Wittmann said that she intended to use the approximately 200 GB of extracted data for research into problem gambling.

In March 2026, Wittmann claimed responsibility for gaining unauthorised access to a system operated by the Malta Gaming Authority. She alleged that the material she obtained indicated links between the regulator and organised crime; according to ISA-GUIDE, she did not initially publish evidence substantiating those allegations.[21] The authority rejected the allegations as unsubstantiated and condemned the unauthorised access and the extraction or dissemination of data obtained through it.[22]

Activism and digital policy

[edit]

Open data and government transparency

[edit]

In August 2021, Wittmann launched a website documenting publicly accessible application programming interfaces provided by government bodies.[23] She described the project as a criticism of government agencies' lack of action on open data. The project also includes publicly accessible Git repositories published under the name bundesAPI.[24]

In 2022, Wittmann highlighted privacy problems in Germany's online commercial register portal, where documents available for download included copies of identity documents and residential addresses.[25] Access to the portal had become free of charge and no longer required registration on 1 August 2022.[26]

Bundesservice Telekommunikation

[edit]

In January 2022, Wittmann published an investigation into Bundesservice Telekommunikation, an obscure entity listed in Germany's federal government directory.[27] In a subsequent report, she described sending a parcel containing an AirTag to trace its delivery and concluded that the entity was a cover organisation for the Federal Office for the Protection of the Constitution (BfV).[28]

Wittmann has stated that she opposes the BfV on political grounds and intends her exposure of its cover organisations to obstruct its activities. She has also stated that she is a member of the Association of Persecutees of the Nazi Regime – Federation of Antifascists (VVN-BdA) and the solidarity organisation Rote Hilfe.

Parliamentary hearing

[edit]

On 14 December 2022, Wittmann appeared as an expert at a public hearing of the Bundestag's Committee on Digital Affairs concerning Web 3.0 and the metaverse. She discussed privacy and security concerns associated with blockchain-based systems, including their use for digital identity documents.[29]

References

[edit]
  1. 1 2 Drosdowski, Johannes (25 September 2021). "Lilith Wittmann über Wahlkampf-Apps: „Manche spielen Sudoku. Ich hacke"". Die Tageszeitung (in German). ISSN 0931-9085.
  2. 1 2 3 Hurtz, Simon. "CDU Connect: Erst die Anzeige, dann die Blamage". Süddeutsche Zeitung (in German).
  3. 1 2 Beuth, Patrick (12 October 2021). "Verantwortungslos und gefährlich". Der Spiegel (in German).
  4. 1 2 "Online-Casinos wie "Slotmagie" nach Datenverlust offline". Heise Online (in German). 15 March 2025.
  5. ↑ "#30 Wahl, Hack und Krawall mit Lilith Wittman". ARD Audiothek (in German). NDR Info. 28 September 2021. Archived from the original on 17 October 2021.
  6. ↑ "Unterstützung bei Projekten im Bereich Grundsatzfragen der Digitalisierung" (in German). DigitalService.
  7. ↑ "Forscher*innen". zerforschung (in German).
  8. ↑ von Lindern, Jakob (28 September 2021). "Hacken für das Gute". Zeit Campus (in German). No. 5/2021.
  9. ↑ "CDU, CSU und Volkspartei: Wahlkampf-Apps gaben persönliche Daten preis". Heise Online (in German).
  10. ↑ "Je mehr Digital, desto weniger Lockdown?". Digitalistan (in German). Westdeutscher Rundfunk. 17 March 2021.
  11. ↑ Wolfangel, Eva (5 August 2021). "Danke für den Hinweis, Anzeige ist raus". Die Zeit (in German).
  12. ↑ "CDU zieht Anzeige gegen IT-Sicherheitsforscherin zurück" (in German). Bayerischer Rundfunk. 4 August 2021.
  13. ↑ Reuter, Markus. "CDU Connect: Ermittlungsverfahren gegen Sicherheitsforscherin Lilith Wittmann eingestellt". netzpolitik.org (in German).
  14. ↑ "Unsichere Corona-Software: Start-ups haben andere Ziele als das Gemeinwohl". Der Spiegel (in German).
  15. ↑ "Führerschein am Smartphone gefloppt: Digitale Kopie bereits wieder eingestellt". Chip (in German).
  16. ↑ "Unsichere Schufa-App: So fälschte eine Hackerin Jens Spahns Mietauskunft". Golem.de (in German).
  17. ↑ "Datenleck bei Online-Auskunftei: Hackerin kann beliebige Bonitätsdaten einsehen". Heise Online (in German). 14 November 2024.
  18. ↑ Wittmann, Lilith (26 June 2024). "Datenabfluss aus dem Knast". Medium (in German).
  19. ↑ Wittmann, Lilith (30 December 2024). Knäste hacken (Conference presentation) (in German). Chaos Computer Club.
  20. ↑ "Nach Merkur-Datengau: Weitere Online-Casinos mit "The Mill"-Software offline". Heise Online (in German). 23 March 2025.
  21. ↑ "Deutsche IT-Sicherheitsexpertin bekennt sich zu Angriff auf die Malta Gaming Authority". ISA-GUIDE (in German). 24 March 2026.
  22. ↑ "Statement on unauthorised access and related claims". Malta Gaming Authority. 20 March 2026.
  23. ↑ Grüner, Sebastian (9 August 2021). "Aktivistin gründet fingierte Bundesstelle für Open Data". Golem.de (in German).
  24. ↑ "Bundesstelle für Open Data". GitHub.
  25. ↑ "Schufa und Bonify – Kritik an Datenschutz und Transparenz". ARD Audiothek (in German). Deutschlandfunk Kultur. 29 July 2023.
  26. ↑ Tönnesmann, Jens (16 September 2022). "Lilith hackt den Staat". Die Zeit (in German). No. 38/2022.
  27. ↑ Hensen, Christian (13 January 2022). "Karteileiche? Geheimdienst? Hackerin entdeckt zufällig eine mysteriöse Behörde – und niemand will sich dazu äußern". Stern (in German).
  28. ↑ Wittmann, Lilith (24 January 2022). "Bundesservice Telekommunikation — enttarnt: Dieser Geheimdienst steckt dahinter". Lilith Wittmann (in German).
  29. ↑ Wortprotokoll der 24. Sitzung: Web 3.0 und Metaverse (PDF) (Report) (in German). Deutscher Bundestag, Ausschuss für Digitales. 14 December 2022. pp. 16–17.
[edit]