Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

161–170 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#161
post #73

Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.

By purchasing the ticket, he was confirming the vulnerability. I am sure he knew that they would cancel the ticket when he reported it. I don't find any wrong doing here.

Also, since he doesn't live in Budapest, it should be obvious he wouldn't be doing it for personal gain — he has no way to use the pass anyway, after all.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#162

Earlier quoted context omitted.

Offering your company's services could be risky. Whatever your good intentions, it could be portrayed as extortion.

That's why you speak to a lawyer first, the law is an ass, and they're the right tool for telling you how to avoid these nasty little traps.

...provided the law in your country really works.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#163

Earlier quoted context omitted.

> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…

Sounds kinda mean spirited to mock of the accent of someone who is presenting in their second language.

A lot of the amateur security scene is pretty mean-spirited, unfortunately for anyone trying to get into it.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#164
post #4

Side note: this page gives me the weirdest Firefox behaviour I've ever seen: https://gfycat.com/HandyRapidJabiru

That's probably the weirdest browser behaviour I've seen on any browser! I don't even know how I would describe that to someone :/

It looks like the scrolling in Firefox is implemented in screen-height tiles, and when he's scrolling it's picking a smaller and smaller portion of the top tile (as the top portion of the tile is scrolling out of the window) but not updating the bottom coordinate of the rectangle it's supposed to render to (so instead of moving up, instead the smaller and smaller portion gets stretched out to fill the window). Then when the top tile is supposed to be completely off-screen, it jumps to the second tile in one go.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#165
post #92

Earlier quoted context omitted.

My guess would be: - BKK is the client of T-Systems. They have a contract for the development and maintenance of this system which might contain clauses about liability or indemnification in cases of hacking, security bugs, negligency, etc. - This guy reported it to BKK who obviously don't have any technical knowledge - BKK (the client) forwards the email to T-Systems (the contractor): "What's this about? Looks like…

T-Systems has a third option: blame it on russian hackers! Works all the times!

Two wears ago it was Chinese hackers. And ten years ago it was American ones. So extrapolating, I declare the next year The Year of Indian hackers!

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#166

The price of a ticket was client-side authenticated!? I can't fathom the level of incompetence required to do something like this...

You have to wonder why they didn't hire a security tester. Just for 10 minutes or so.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#167
post #9

Earlier quoted context omitted.

Yep, a few people were frowning, especially since the democracy is in pretty bad shape in Hungary right know. However, in this case it works: it will be seen and remembered longer this way. Also, there were quite heated discussions on facebook, the case received a lot of attention even from non-tech people, the guy will be represented by the lawyers of a human rights association, etc. And actually there will be a pro…

As every other country on earth right now, Hungary is not a democracy at all. So there's that. At some point we need to understand the novlang used here, by squatting the word democracy to label the political system based on elections, people in power manage to prevent to emergence of an actual democracy. Please stop misusing this word so we have a better chance of actually having a democracy somwhere at some point i…

A practical democracy must be an abstraction of a pure, idealistic democracy. You cannot have millions of people deciding on every issue. Democratically elected representatives are one way we can do this.

There may be better ways of doing things but it doesn't make democracies not democracies.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#169

Earlier quoted context omitted.

This story takes place in Hungary.

But inspired by the DMCA, the EU has also adopted anti-circumvention legislation. Though I'm dubious either would apply here, as this would be very difficult to spin as a copyright issue.

Has it? Can you link to it?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#170
post #47

Earlier quoted context omitted.

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

I think there is a disconnect in how techies and non-techies think about web security in general. To push your analogy further, the non-tech person thinks of this type of exploit discovery as if someone has trespassed onto their private yard in the cover of darkness, trying every door and window. A tech savvy person might instead think of it as a row of doors lined up next to a busy street, in broad daylight. Knockin…

I think that the second scenario in your analogy is somewhat creepy too. Why are they trying all of the doors? A person should have a reasonable expectation of privacy in their house, to be able to walk around in their underwear or whatever without someone just opening the door on them.

Edit: Note that in this analogy the keys aren't fully visible from outside and it requires opening the door to be sure that the keys were accidentally left out

Post reply on HN