Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

11–20 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#11

That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…

> Adobe had him arrested on the stage as he gave his talk.

I was there!

The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster.

During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Russian accent, "I do not know where the nuclear wessels are in Alameda?" The mostly American Trek-familiar audience had a good laugh, and Dmitry continued with his talk.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#12

That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…

Yep, Hungarian story. And indeed the law in this case is not that bad at all. It doesn't penalize what the guy did. The sad part is of course the corporate & governmental reaction, the frightening part is that the police was so eager to jump in and overreact.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#13
"if you just typed in the url (shop.bkk.hu), the site just wouldn't appear. At first I thought they've taken it offline, but it turns out that they just didn't set up the http -> https redirection. And it was left like that for days. If you just heard about it, you couldn't use it. You had to click a link (normal users won't figure out to put an https in front of the host name, even I didn't think of it)."

I'd really like to know which of these is the better solution.

It seems to me that if people go to the http address, they could be redirected to an attacker's address with a simple MITM attack. So there's an argument to be made for not using http at all, even for a legitimate redirect, because it can be so easily MITM'ed.

On the other hand, if the http address is left unused, then people who try it anyway and it fails will be confused. For this solution to work, it seems the users have to be educated to always and only use the https address.

For these reasons, the whole separate http/https scheme seems broken by design.

What's the consensus from the security community as to the right setup here? Am I missing something, or is there a better way?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#15
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

I'm not aware of any actual mafia. They were almost certainly metaphorical and they must have been just bashing the local government. Because what they do is really a shame. One of the lines is de facto in a life threatening condition. Trains caught fire multiple times. Instead of being replaced, the 40 year old cars are being refurbished/modernized. This has something to do with the EU (they gave money for this, but not that). There was a tender, but miraculously it was the Russians who won it, despite their offer was quite a lot more expensive than that of the Estonians. And of course, as it happens with corruption, they failed to deliver a properly working version, so after a few weeks of testing, the first few trains were sent back.

About the security (or rather the extremely low quality) of the eTicket system: that was developed by a 3rd party that belongs to the Deutsche Telekom group, and that company is indeed quite a high profile system integrator working with a lot of large companies, banks, etc. So it's a bit of surprising (even if corruption is involved) that they released it in this form. Actually I'm surprised by these bugs even for a prototype that was forcefully pushed out of the door, because you just never do these things in the first place.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#16

That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…

> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…

I'm confused by his request as well, I can't understand why he asked it. Any context?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#17
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Why didn't you report it?

Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#18
post #4

Side note: this page gives me the weirdest Firefox behaviour I've ever seen: https://gfycat.com/HandyRapidJabiru

That's probably the weirdest browser behaviour I've seen on any browser! I don't even know how I would describe that to someone :/

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#19
post #17
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

Reporting these things can get you in trouble. Once burnt twice shy.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#20
post #15
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

I'm not aware of any actual mafia. They were almost certainly metaphorical and they must have been just bashing the local government. Because what they do is really a shame. One of the lines is de facto in a life threatening condition. Trains caught fire multiple times. Instead of being replaced, the 40 year old cars are being refurbished/modernized. This has something to do with the EU (they gave money for this, but…

> Instead of being replaced, the 40 year old cars are being refurbished/modernized.

Age seems like a bit of a red herring to me. Here in San Francisco BART cars are about that old, Muni runs 90 year old Italian trams and American ones that are close to 70 years old. And, of course, the cable cars. BART bears about the worst of it because many parts are no longer available.

Post reply on HN