Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

131–140 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#131
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I have read some advice in the past that one should report vulnerabilties via officially known independent security related group (white hat) or via a journalist. The point is to get some legal backing just in case. Does anybody have an experience with such way?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#132

That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…

> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…

Sounds kinda mean spirited to mock of the accent of someone who is presenting in their second language.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#133

Earlier quoted context omitted.

Please don't spread fake news! The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia. Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

What do you mean eastern Europe ? This could be said for governments all over the world.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#134
post #106

Earlier quoted context omitted.

Maybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.

So you should just become a malicious actor and actually break the law? Good plan.

Becoming a malicious actor, no. Looking like one, definitely. Break the law, most probably. Also, I would rather threaten to publish if I did this for real.

It's risky and scary, but also the right thing to do in some cases.

You could also fail to report at all, and let their ship sink. Maybe they deserved it.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#135
post #65

Earlier quoted context omitted.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

Why does a group of criminals need a subway? As a local guy using the public transport on a daily basis, I highly doubt this.

Why do criminals need to be re-elected at election time ?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#136
post #92
post #47

Earlier quoted context omitted.

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

My guess would be: - BKK is the client of T-Systems. They have a contract for the development and maintenance of this system which might contain clauses about liability or indemnification in cases of hacking, security bugs, negligency, etc. - This guy reported it to BKK who obviously don't have any technical knowledge - BKK (the client) forwards the email to T-Systems (the contractor): "What's this about? Looks like…

T-Systems has a third option: blame it on russian hackers! Works all the times!

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#137
post #22
post #17

Earlier quoted context omitted.

Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

If he reported it, he runs the risk of the company turning on him (as was the case in the article above). If he doesn't report it, nothing happens. It's a choice between the certainty of no loss vs the possibility of great loss.

If he does not report it, and somebody else does, then he runs the risk of being rightfully accused of hacking, as the motivation can be understood as financially motivated.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#138
Although deeply unfair, this is not unusual, there have been many reported cases of companies shooting the messenger.

Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking.

What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has 2 options, admit it was their fault and the vulnerability exists and risk being accused of incompetence, or say that the system was hacked.

Human nature being what it is, one tends to complain of being hacked, thus snow-balling effects, which lead to the arrest of an 18 year old just trying to help.

My advice: Don't report these types of bugs at all, or if you really feel you must, report anonymously.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#139

Although deeply unfair, this is not unusual, there have been many reported cases of companies shooting the messenger. Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking. What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has…

[deleted]

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#140
We've seen two[1] cases[2] of this in Denmark in the last couple of years surrounding systems that kindergartens are using. The second one is currently (still) being investigated, but the first one was rightfully concluded earlier this year with the "hacker" being acquitted.

In both cases, it was dads of children in the institution that noticed the bugs when they were rightfully using the system and were ignored when notifying the responsible party about it until they "shouted it so loudly" that they couldn't be ignored anymore, in which case they were reported to the police for hacking.

Links below are in danish, but they can probably be translated if needed.

1: https://www.version2.dk/artikel/boernehavehackeren-frifundet...

2: https://www.version2.dk/artikel/interview-hacker-tiltalt-jeg...

Post reply on HN