I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…
18yo arrested for reporting a bug in the new Budapest e-Ticket system
131–140 of 329 posts
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#132That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…
> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#133Earlier quoted context omitted.
Please don't spread fake news! The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia. Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.
TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#134Earlier quoted context omitted.
Maybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.
So you should just become a malicious actor and actually break the law? Good plan.
It's risky and scary, but also the right thing to do in some cases.
You could also fail to report at all, and let their ship sink. Maybe they deserved it.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#135Earlier quoted context omitted.
TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.
Why does a group of criminals need a subway? As a local guy using the public transport on a daily basis, I highly doubt this.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#136Earlier quoted context omitted.
I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…
My guess would be: - BKK is the client of T-Systems. They have a contract for the development and maintenance of this system which might contain clauses about liability or indemnification in cases of hacking, security bugs, negligency, etc. - This guy reported it to BKK who obviously don't have any technical knowledge - BKK (the client) forwards the email to T-Systems (the contractor): "What's this about? Looks like…
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#137Earlier quoted context omitted.
Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view
If he reported it, he runs the risk of the company turning on him (as was the case in the article above). If he doesn't report it, nothing happens. It's a choice between the certainty of no loss vs the possibility of great loss.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#138Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking.
What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has 2 options, admit it was their fault and the vulnerability exists and risk being accused of incompetence, or say that the system was hacked.
Human nature being what it is, one tends to complain of being hacked, thus snow-balling effects, which lead to the arrest of an 18 year old just trying to help.
My advice: Don't report these types of bugs at all, or if you really feel you must, report anonymously.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#139Although deeply unfair, this is not unusual, there have been many reported cases of companies shooting the messenger. Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking. What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has…
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#140In both cases, it was dads of children in the institution that noticed the bugs when they were rightfully using the system and were ignored when notifying the responsible party about it until they "shouted it so loudly" that they couldn't be ignored anymore, in which case they were reported to the police for hacking.
Links below are in danish, but they can probably be translated if needed.
1: https://www.version2.dk/artikel/boernehavehackeren-frifundet...
2: https://www.version2.dk/artikel/interview-hacker-tiltalt-jeg...