Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

141–150 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#141
post #96
post #94

Earlier quoted context omitted.

This is Hungary we're talking about, more likely it was 24k or less.

The article says >BKK pays T-Systems 80kEUR/month to operate this system. If you were offered that, would you turn it down because you can't actually deliver a secure system in time?

Oh, I missed that part, I thought you were talking about programmer salaries :)

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#144
post #47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

> "Would they also prosecute a person who told them one of their doors was left unlocked after-hours?"

Perhaps not, but they probably would be tempted to prosecute someone who opened the door with a toothbrush and told them about it...

The temptation is to squash anything that comes along and potentially makes you look like you weren't doing your job properly (installing a better lock in the first place) rather than thank the person and then install a better lock, or fix the design of the lock.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#145

In my country, the laws are draconian and totally against this kind of responsible disclosure. But being a good guy, whenever I find something I write a strongly worded email explaining why the company's IT department messed up, how to test said mess-up, and how they can hire my company to ensure these kinds of stupid things don't happen again. I've reported several of these issues, sometimes all I get is single repl…

Offering your company's services could be risky. Whatever your good intentions, it could be portrayed as extortion.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#146
post #68

Earlier quoted context omitted.

They took him as a criminal, got his fingerprints, took a photo of him. I do not think they proceeded this in the right way. They should have fixed the bugs, protect our personal data and say sorry for this.

No, they brought him in as a person of interest following Hungarian law. If you do not like the law please vote the next election a party that changes that or move to a country that does not require police to follow the law. Determining if he is going to be charged with a crime is at later stage in the investigation anyways. There is no such a thing as "They took him as a criminal". Moreover, it is not only Hungarian…

The article states that what happened to him was illegal.

> In Hungary, according to the law, this was pretty much illegal.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#147
post #106

Earlier quoted context omitted.

So you should just become a malicious actor and actually break the law? Good plan.

What difference does it make if the outcome is the same?

Not the outcome for the informer in case one gets caught and accused of threatening for ransom.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#148

That's how the DMCA works. Remember the guy who gave a talk about Adobe's PDF creator which purported to produce "secure" documents (required a password) but the feature was easily bypassed. Adobe had him arrested the day after he gave his talk. Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a... EDIT: I have a terrible memory-- thanks to the folks who replied to my comment w…

This story takes place in Hungary.

But inspired by the DMCA, the EU has also adopted anti-circumvention legislation. Though I'm dubious either would apply here, as this would be very difficult to spin as a copyright issue.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#149
post #90
post #9

Earlier quoted context omitted.

Yep, a few people were frowning, especially since the democracy is in pretty bad shape in Hungary right know. However, in this case it works: it will be seen and remembered longer this way. Also, there were quite heated discussions on facebook, the case received a lot of attention even from non-tech people, the guy will be represented by the lawyers of a human rights association, etc. And actually there will be a pro…

"democracy is in pretty bad shape in Hungary right know" I thought that Hungary has a democratically elected government. Did I miss something?

Here's Human Rights Watch on Hungary: https://www.hrw.org/europe/central-asia/hungary

Much of it focuses on the treatment of refugees, but you'll also find information about the suppression of free speech and the like. A "democratically elected government" in a country where the opposition is suppressed is not that democratically elected after all.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#150

The price of a ticket was client-side authenticated!? I can't fathom the level of incompetence required to do something like this...

"Budapest's new e-ticketing system uses state-of-the-art JavaScript to deliver a smooth user experience, combining a great React front-end with a micro-services node.js backend!" - marketing blurb I just made up, needs more buzzwords though.

...stateless cloud interactive real-time connection through highly sophisticated authentication featuring dual way private/public key encryption services with single use time-limited tokens ...
Post reply on HN