Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

51–60 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#51
post #40

Earlier quoted context omitted.

Ok, so that works for Chrome, but every other application is still going to be subject to an MITM attack if their users try to connect via http?

As long as the other application is Firefox, Safari, IE11/Edge, or Opera, then it probably has a HSTS preload list that is at least in part generated from the Chrome one. Firefox have some scripts which go through and check to make sure everything still on the Chrome list is still announcing the preload headers, and will autoremove if that isn't that case, IIRC. I wouldn't be too shocked if Apple/Microsoft were doing…

"As long as the other application is Firefox, Safari, IE11/Edge, or Opera, then it probably has a HSTS preload list that is at least in part generated from the Chrome one."

Is there any documentation for these browsers that officially say exactly what they're doing and how their preload lists are generated?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#53
post #47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

You fear what you don't understand

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#54
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as so…

What I would suggest is report the bug in an anonymous manner if possible. They're not going to be able to do much if you report a bug anonymously I would think? I mean in the case of people who find bugs by "accident" I mean I'm guilty of messing with a URL here or there to get the true HQ picture of a website.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#55

Earlier quoted context omitted.

Please don't spread fake news! The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia. Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

This is simple demagogue populism. This is not a critique of the problems, and does not start any fruitful discussion, and will not lead eventually to better conditions.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#56
post #47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

maybe you're projecting your own ability to them, have you considered that maybe they are highly incompetent and do sincerely believe this was a cracking attempt on their system.

Then again there is this culture of making an example to discourage others to even try, similar to prison, which we know is not that effective if at all.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#57

That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…

People from Adobe should have spent a few nights in jail for the security hell their thrust on people with flash

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#58

Earlier quoted context omitted.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

This is simple demagogue populism. This is not a critique of the problems, and does not start any fruitful discussion, and will not lead eventually to better conditions.

Oh, you seem to be using the code words of state-sponsored media pretty well. Demagogue and populism in the same sentence, nice! : )

Lets not pretend that the tenders made by the BKK is any more lawful or fair than the rest of the tenders that dominate the market around here.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#59
> We knew that they have been working on an NFC/smart card based system for around 4 years, without any visible result despite having spent over 4 million EURs.

The public procurement process for the current system called RIGO was indeed 2013 but the whole process is much, much older than that. A more than 300 page feasibility study was published in 2011 https://www.bkk.hu/apps/docs/megvalosithatosagi_vizsgalat.pd... And a completely different system, called Elektra was announced in 2004 with a 2006 deadline.

This whole clusterfuck with RIGO starting in less than a year was absolutely unnecessary since the 2011 study already suggested supporting contactless credit cards so once RIGO starts the only ones using this online ticket purchasing system will be those who have a credit card but not a contactless one. This is a (very) rapidly shrinking audience.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#60

The price of a ticket was client-side authenticated!? I can't fathom the level of incompetence required to do something like this...

"Budapest's new e-ticketing system uses state-of-the-art JavaScript to deliver a smooth user experience, combining a great React front-end with a micro-services node.js backend!" - marketing blurb I just made up, needs more buzzwords though.
Post reply on HN