Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

171–180 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#171
post #86
post #78

Earlier quoted context omitted.

In Poland there was a case few years back of a company (I have no idea if that means a one person company or a bigger one) owner finding out by putting a name of his client into google that it indexed documents containing private information of over a 1000 of companies that are clients of PKO BP and reported it to the bank. At first the bank security department said no one will find it so it's safe and later when he…

Ah, yes. Actually Poland is the other bad child in EU... The European commission is currently threatening to remove Poland's voting rights due to the changes to the juridical system, but it will not happen as Hungary will veto. I think they are on their own cultural axis somehow.

Poland is drifting towards Russia.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#172
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Maybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.

Better hope you've not left any evidence on their systems then, you know, like a discounted transport pass.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#173
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Had a similar issue with Wolfram Alpha some years ago. I reported a dozen different XSS vulnerabilities to them and their answer was: "We forwarded this email to our legal department.".

So even technical companies can react in really silly ways.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#174
post #121

Earlier quoted context omitted.

No I do not know.

Try harder then. And do not campaign against an innocent young boy even if you think your point of view harmonises with the outdated Hungarian law that bleeds from hundreds of wounds.

You can try harder too. Law is the law, regardless of your feelings.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#175
post #86

Earlier quoted context omitted.

Ah, yes. Actually Poland is the other bad child in EU... The European commission is currently threatening to remove Poland's voting rights due to the changes to the juridical system, but it will not happen as Hungary will veto. I think they are on their own cultural axis somehow.

Poland is drifting towards Russia.

To clarify: they're drifting towards a political system reminiscent of Russia today, but they would never ally with Russia. The Soviet regime is still fresh in the zeitgeist's memory.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#176
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Maybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.

That is quite straightforward and makes it clear from all perspectives.

From the hacker "hat classification" perspective, that's obviously black hat, nothing gray about it.

From the legal perspective it's not a debate anymore (like in the original article) if you do this, it's clearly a crime, if you get caught in whatever way (e.g. by bragging about it someplace later that leads to your person, or by testing a "discounted" pass in some place that has cameras), it's a straightforward conviction for extortion.

From the ethical perspective, that is an unethical action, doing that shows that the person is immoral.

But you are right, yes, it can be quite effective, and definitely makes it more likely that they will panic strongly enough to actually do something about the issue. It's just that if this happens, then it's not sufficient to just fix the hole, identifying and catching the perpetrator becomes a big part of what they should be doing.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#177
post #90
post #9

Earlier quoted context omitted.

Yep, a few people were frowning, especially since the democracy is in pretty bad shape in Hungary right know. However, in this case it works: it will be seen and remembered longer this way. Also, there were quite heated discussions on facebook, the case received a lot of attention even from non-tech people, the guy will be represented by the lawyers of a human rights association, etc. And actually there will be a pro…

"democracy is in pretty bad shape in Hungary right know" I thought that Hungary has a democratically elected government. Did I miss something?

There's a saying that democracy is not when a government gets installed by fair elections, democracy is when a government gets removed by fair elections.

Hitler was democratically elected as well, that is not sufficient to label his regime as democracy.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#178

Earlier quoted context omitted.

But inspired by the DMCA, the EU has also adopted anti-circumvention legislation. Though I'm dubious either would apply here, as this would be very difficult to spin as a copyright issue.

Has it? Can you link to it?

General info: https://en.wikipedia.org/wiki/Anti-circumvention#European_Un...

More about the directive: https://en.wikipedia.org/wiki/Copyright_Directive

Actual text of the directive: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:320... (see Chapter III, containing things like "Member States shall provide adequate legal protection against the circumvention of any effective technological measures" and then going on to define "effective" to mean "not necessarily effective")

Some parts have been amended (for example, copyright duration has been expanded from 50 to 70 years after death), but I believe the anti-circumvention parts to be unchanged. I'm not sure how to find up-to-date codified versions of EU laws, though.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#179

Earlier quoted context omitted.

I think there is a disconnect in how techies and non-techies think about web security in general. To push your analogy further, the non-tech person thinks of this type of exploit discovery as if someone has trespassed onto their private yard in the cover of darkness, trying every door and window. A tech savvy person might instead think of it as a row of doors lined up next to a busy street, in broad daylight. Knockin…

I think that the second scenario in your analogy is somewhat creepy too. Why are they trying all of the doors? A person should have a reasonable expectation of privacy in their house, to be able to walk around in their underwear or whatever without someone just opening the door on them. Edit: Note that in this analogy the keys aren't fully visible from outside and it requires opening the door to be sure that the keys…

If your security is "http://example.com/1234/secret_data/", but 1234 is your customer number, and changing the customer number gives you someone else's data, then the analogy is more like:

"the sheriff has told everyone that there's a bad dude wandering round town trying doors, and [responsible citizen] noticed that everyone had identical door-keys which would open every lock".

Is that still creepy?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#180
post #40

Earlier quoted context omitted.

As long as the other application is Firefox, Safari, IE11/Edge, or Opera, then it probably has a HSTS preload list that is at least in part generated from the Chrome one. Firefox have some scripts which go through and check to make sure everything still on the Chrome list is still announcing the preload headers, and will autoremove if that isn't that case, IIRC. I wouldn't be too shocked if Apple/Microsoft were doing…

"As long as the other application is Firefox, Safari, IE11/Edge, or Opera, then it probably has a HSTS preload list that is at least in part generated from the Chrome one." Is there any documentation for these browsers that officially say exactly what they're doing and how their preload lists are generated?

Here's a firefox one

https://wiki.mozilla.org/SecurityEngineering/HTTP_Strict_Tra...

Post reply on HN