Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

41–50 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#41

"this outrageous move from the police brought about fierce reaction resulting in tens of thousands of 1-star reviews on the facebook pages of the companies involved" In the old days, protesters used to physically go and picket in front of company offices. These days, protesters leave one-star reviews. I wonder which is more effective.

Honestly, I wouldn't be surprised if the reviews are effective—I bet reviews are a metric that's tied a lot more directly to executive compensation/promotions than "number of people protesting outside HQ"! Both attack the company's reputation, and, unless a protest gets on a major news network, I suspect acting out on Facebook has greater reach.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#42
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I was more naive, but it worked out. Reported a vulnerability and how to fix it to a regional bank when applying for a student loan. They asked me to come in person to explain it and dropped a point off my interest rate.

In hindsight it was a huge risk and I was dangerously trusting.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#43
post #15
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

I'm not aware of any actual mafia. They were almost certainly metaphorical and they must have been just bashing the local government. Because what they do is really a shame. One of the lines is de facto in a life threatening condition. Trains caught fire multiple times. Instead of being replaced, the 40 year old cars are being refurbished/modernized. This has something to do with the EU (they gave money for this, but…

Actually yes, the EU some money for refurb, not new trains.

The Russians didn't magically win the tender, i think it was realpolitik. They manufactured them originally in the first place, they have the means to do the work, and without knowing if the proposals were technically equivalent, Hungary needs to maintain a good relation not only to its neighbors, and fellow EU members, but to Moscow.

Also the trains are not in a worse working condition than the Siemens Combino trams or the Siemens and Alstom technology at Metro 4 line, which also had integration problems during the first months of operation. The problems will be addressed by the russian firm as well as as the western firms addressed those problems.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#44
post #32

"if you just typed in the url (shop.bkk.hu), the site just wouldn't appear. At first I thought they've taken it offline, but it turns out that they just didn't set up the http -> https redirection. And it was left like that for days. If you just heard about it, you couldn't use it. You had to click a link (normal users won't figure out to put an https in front of the host name, even I didn't think of it)." I'd really…

Not having an http site doesn't help in a MITM scenario as the attacker will happily serve up an http site even if you don't.

It's true that it doesn't help once the user has been MITM'ed.

But before that happens, if the user always goes to the http address and it works for them (whether by legitimate redirect or by the legitimate site simply supporting http) it lulls them in to a false sense of security, and a belief that going to the http address is ok.

So the idea behind having the http address be broken from the start is to make the users see that the address they're trying is broken, and therefore the wrong one for them to use. Hopefully at that point they'll investigate why (perhaps complaining or talking to their sysadmin, if they have one), and be straightened out by someone providing the https link to them (or the more tech-savvy users like the OP figuring it out for themselves).

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#45
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up.

I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as soon as I realised 'my mistake' and was very surprised. Basically enough that 1) If it should go to court the situation would be in my favour as much as it can be and 2) Given they were a well know public retailer I figured this would hit social media and make an uproar about the company should they act badly.

Initially I contact several people in IT and heard nothing. Six months later when I noticed this was still open. I then contacted the CEO. Expecting nothing or canned 'thanks', we was thankful had some followup contact about the issue.

I wont say there is no risk, but I think its the right thing to do and risk seems minimal. And you can always do it anonymously.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#46
post #35

Earlier quoted context omitted.

> Instead of being replaced, the 40 year old cars are being refurbished/modernized. Age seems like a bit of a red herring to me. Here in San Francisco BART cars are about that old, Muni runs 90 year old Italian trams and American ones that are close to 70 years old. And, of course, the cable cars. BART bears about the worst of it because many parts are no longer available.

Interesting point. Don't forget that this is 40-50 year old Soviet technology :). And cars are actually in pretty bad shape, well over their planned lifetime of 30 years (AFAIK). Full of rust, sometimes catch fire. The drive system is also problematic, because it doesn't have regenerative breaking so the cars heat the tunnels quite a lot which is pretty bad during the summer. They are in such a bad shape and/or hard…

Actually the Russian company and the tender has received attacks that the cars are actually new, only some identifiers have been transferred from the old cars, as Metrowagonmash had a dozen or so surplus cars of the type the used cars were supposed to be upgraded to.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue.

Would they also prosecute a person who told them one of their doors was left unlocked after-hours?

A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops.

EDIT: Is it suspicion? "Hmm...this person found an unlocked door, which means they were clearly trying all the doors. Don't like that. Who knows what else they found but didn't report." Which is understandable, but clearly counter-productive. If the person was a malicious actor, they obviously wouldn't go to the trouble of reporting in the first place.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#48
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

Please don't spread fake news! The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia. Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#49
post #47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

This. Executives who usually have no trouble treating engineers as replaceable parts, suddenly fail to believe someone else can and possibly has found the same vulnerability. They think getting rid of the one person capable of finding it is all it takes to be safe.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#50
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as so…

Doing the right thing is admirable. Doing something that helps a little bit, when the group that you are trying to help may or may not try to destroy you, seems like its not such a great idea. If a company doesn't have a set of published procedures for reporting a bug its not worth helping them
Post reply on HN