Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

71–80 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#71
post #68

Earlier quoted context omitted.

They took him as a criminal, got his fingerprints, took a photo of him. I do not think they proceeded this in the right way. They should have fixed the bugs, protect our personal data and say sorry for this.

No, they brought him in as a person of interest following Hungarian law. If you do not like the law please vote the next election a party that changes that or move to a country that does not require police to follow the law. Determining if he is going to be charged with a crime is at later stage in the investigation anyways. There is no such a thing as "They took him as a criminal". Moreover, it is not only Hungarian…

Corruption is also a crime, I do not see the police visiting Mészáros or other entities involving corruption skandals.

But ofc I got your point.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#72

Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.

> followed its internal policy and Hungarian law and reported the incident to authorities

Ho-humm. Care to point where the Hungarian law mandates this? The old BTK was simpler but even the new is pretty clear in that only a very few serious acts are mandatory to report (meaning not reporting is a felony in itself). 145. and 159 § details how military and civil superiors must report the crimes of those under them, obviously does not apply. 191. § makes reporting attempted or committed kidnapping mandatory. 263. § are crimes against the state, treason, spying and shit. 300. § makes it a crime not to report corruption but only for officials. 317. § makes terrorism mandatory to report. 328. § is about violating international sanctions. Finally 404. § makes reporting of certain financial trickery but only for the actual executor of the bankruptcy.

Which one was this one? Or did I miss something? Was he trying to sell stuff to Russia violating the sanctions? Did he make an attempt to overthrow the government? Or what?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#73

Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.

By purchasing the ticket, he was confirming the vulnerability. I am sure he knew that they would cancel the ticket when he reported it. I don't find any wrong doing here.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#74
Sounds a lot like what happens here in India [1].

Also, if such behaviour is systemic, how should we bring about the paradigm shift in handling such events? Such incidents will happen more often across the world as e-governance becomes more predominant.

1 - https://thewire.in/119578/aadhaar-sting-uidai-files-fir-jour...

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#75
post #41

"this outrageous move from the police brought about fierce reaction resulting in tens of thousands of 1-star reviews on the facebook pages of the companies involved" In the old days, protesters used to physically go and picket in front of company offices. These days, protesters leave one-star reviews. I wonder which is more effective.

Honestly, I wouldn't be surprised if the reviews are effective—I bet reviews are a metric that's tied a lot more directly to executive compensation/promotions than "number of people protesting outside HQ"! Both attack the company's reputation, and, unless a protest gets on a major news network, I suspect acting out on Facebook has greater reach.

Furthermore the 4500 1* review is there to stay and a single protest fades away :)

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#76
post #65

Earlier quoted context omitted.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

Why does a group of criminals need a subway? As a local guy using the public transport on a daily basis, I highly doubt this.

To take EU funding, obviously :)

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#77
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

Someone probably misunderstood something. Our government is usually referred to as a mafia government because of their tactics and modus operandi. The Metro is state owned and with a bit of a stretch I can understand where this is coming from.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#78
post #63

Earlier quoted context omitted.

I was more naive, but it worked out. Reported a vulnerability and how to fix it to a regional bank when applying for a student loan. They asked me to come in person to explain it and dropped a point off my interest rate. In hindsight it was a huge risk and I was dangerously trusting.

If you are nice and don't threaten to publish, at least without giving them any time to fix it - which for a large back is a couple of months - then I don't think it's a risk at all. What they don't like is the publicity. Edit: but maybe not in Hungary. It's the bad child in EU.

In Poland there was a case few years back of a company (I have no idea if that means a one person company or a bigger one) owner finding out by putting a name of his client into google that it indexed documents containing private information of over a 1000 of companies that are clients of PKO BP and reported it to the bank.

At first the bank security department said no one will find it so it's safe and later when he pressed the issue as a dangerous leak they reported him to the police for "hacking and extortion". All the computers from his company got confiscated for investigation so he had to buy new computers and software to continue running his company. In the end he was found not guilty by the police investigation of his computers so the prosecution dropped the case (it didn't even go to court) and all his stuff returned after 6 months.

Source in Polish (sorry, there is no English source): https://niebezpiecznik.pl/post/glebokie-ukrycie-danych-w-pko... http://www.tvn24.pl/wiadomosci-z-kraju,3/haker-mimo-woli,132...

Bank spokesperson later explained that the files were "deeply hidden" ("głębokie ukrycie", he said it's an IT term, it's not) and only one person found them in 4 years of their existence there so it's not a big deal.

And in general misusing, testing, etc. a website is illegal without owners permission, there is now a small exception for acting in good faith but it's narrow, a bit strangely worded and it doesn't prevent stuff like above.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#79
post #72

Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.

> followed its internal policy and Hungarian law and reported the incident to authorities Ho-humm. Care to point where the Hungarian law mandates this? The old BTK was simpler but even the new is pretty clear in that only a very few serious acts are mandatory to report (meaning not reporting is a felony in itself). 145. and 159 § details how military and civil superiors must report the crimes of those under them, obv…

Followed its internal policy -> this is why they did it

and Hungarian law -> this is how they did it

European law about data protection and breaches, not sure if it is in effect yet and not sure if it applies to this exact case:

http://www.lexology.com/library/detail.aspx?g=8185429b-c98d-...

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#80
post #73

Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.

By purchasing the ticket, he was confirming the vulnerability. I am sure he knew that they would cancel the ticket when he reported it. I don't find any wrong doing here.

And you think that this is going to be enough at the court?

Have a look at this list, many of them thought they are not doing anything wrong:

https://en.wikipedia.org/wiki/List_of_computer_criminals

The point is that we live by the law, not how you feel about a certain action. I agree that the law is a bit problematic but regardless we cannot cherrypick which law to follow and which not.

Post reply on HN