Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

181–190 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#181

Earlier quoted context omitted.

This is simple demagogue populism. This is not a critique of the problems, and does not start any fruitful discussion, and will not lead eventually to better conditions.

Actually that is a critique of a problem. Because one of the biggest problem of Eastern Europe is corruption which leads to many different problems, that eventually result in such stories.

The biggest problem in Eastern Europe is corruption? Citation needed. In the USA you can influence politicians, even elections and it is called lobbying. The result is that roughly 70% of the legislation passed for companies. In Eastern Europe people keep re-electing politicians who are corrupt than it is on the voters not on the corrupt politicians. I think the real issue is exactly that, people cannot use their power (voting) too well and have limited knowledge about the economy so they are easy to fool.

https://www.cambridge.org/core/journals/perspectives-on-poli...

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#182
post #150

Earlier quoted context omitted.

"Budapest's new e-ticketing system uses state-of-the-art JavaScript to deliver a smooth user experience, combining a great React front-end with a micro-services node.js backend!" - marketing blurb I just made up, needs more buzzwords though.

...stateless cloud interactive real-time connection through highly sophisticated authentication featuring dual way private/public key encryption services with single use time-limited tokens ...

Don't forget the blockchain! It needs more blockchain! ;-)

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#183
post #179

Earlier quoted context omitted.

I think that the second scenario in your analogy is somewhat creepy too. Why are they trying all of the doors? A person should have a reasonable expectation of privacy in their house, to be able to walk around in their underwear or whatever without someone just opening the door on them. Edit: Note that in this analogy the keys aren't fully visible from outside and it requires opening the door to be sure that the keys…

If your security is " http://example.com/1234/secret_data/" , but 1234 is your customer number, and changing the customer number gives you someone else's data, then the analogy is more like: "the sheriff has told everyone that there's a bad dude wandering round town trying doors, and [responsible citizen] noticed that everyone had identical door-keys which would open every lock". Is that still creepy?

who is the sheriff in this case?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#184

"this outrageous move from the police brought about fierce reaction resulting in tens of thousands of 1-star reviews on the facebook pages of the companies involved" In the old days, protesters used to physically go and picket in front of company offices. These days, protesters leave one-star reviews. I wonder which is more effective.

Having 1.1 avg review on the T-Systems International's official FB and Google page can affect the sentiment of their investors.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#185

The list of bullet points of the egregious flaws in the software just get worse and worse. It's crazy how I thought the first one or two would be the worst since, but it just got worse.

It's 20 freaking 17. How can people release software with these totally elementary mistakes? Just one is bad enough, but... admin/admin?? This is easily worthy of a Daily WTF article to itself.

And this software was written by a professional contractor - pretty sure you'd get better quality from a kid fresh out of university, because on my course, it was drilled into me - NEVER TRUST THE CLIENT BROWSER!

Companies need to understand, if they want an internet presence, no matter how strong the laws are in their own country, laws don't stop a crime in progress, especially when all they need to do is send a fairly simple message to the website. Computers are dumb, they do what they're told. Giving anyone the loophole to tell them to do something you didn't intend is asking to have it exploited.

Going after the messenger will solve nothing. The guy who discovered the payment flaw could easily have kept quiet, letting others discover it, or quietly told his friends, who tell their friends, ad infinitum, and suddenly the whole country is buying valid passes for a penny, costing the company a hideous amount of money. Prosecuting the whistleblower will actually hurt their bottom line.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#186
post #47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

Would they also prosecute a person who told them one of their doors was left unlocked after-hours?

A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops.

Well, those aren't quite the same thing.

If someone told me I'd left my key in the lock, I'd say thanks and remove the key.

If someone told me I'd left my door unlocked after-hours, I might wonder what they were doing trying my door after-hours in the first place.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#187
post #90

Earlier quoted context omitted.

"democracy is in pretty bad shape in Hungary right know" I thought that Hungary has a democratically elected government. Did I miss something?

Here's Human Rights Watch on Hungary: https://www.hrw.org/europe/central-asia/hungary Much of it focuses on the treatment of refugees, but you'll also find information about the suppression of free speech and the like. A "democratically elected government" in a country where the opposition is suppressed is not that democratically elected after all.

Only the sentence about refugees is true, but that has nothing to do with democracy.

Financier and philanthropist George Soros of the Open Society Foundation announced in 2010 his intention to grant US $100 million to HRW over a period of ten years to help it expand its efforts internationally.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#188

Earlier quoted context omitted.

Maybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.

That is quite straightforward and makes it clear from all perspectives. From the hacker "hat classification" perspective, that's obviously black hat, nothing gray about it. From the legal perspective it's not a debate anymore (like in the original article) if you do this, it's clearly a crime, if you get caught in whatever way (e.g. by bragging about it someplace later that leads to your person, or by testing a "disc…

My understand was that you just threaten to do those things but don't actually follow through on those threats. Then it's grey hat and ethical but still not legal. If they actually pay the bitcoins and don't fix the issue then you despair and go on with your life. It's hard to spend the bitcoins without deanonymising yourself, but you can try to give them to charity or something.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#189
A few years ago I also found a serious bug in a debt collection agencies web software. I ordered a phone and neglected to pay import tax and was chased by the agency. I found their website and saw that they developed their management software in-house and made it available for purchase for other agencies.

They offered a demo which I used to navigate around, in the demo was a reporting tool which essentially allowed you to send raw SQL queries to an AJAX endpoint. Something along the lines of:

http://demosoftware.com/reports/ajax.php?sql=SELECT * FROM debts

I switched out the demo software domain name for the live version and it worked, not only could I query the database there was no authentication preventing me hitting this end point.

At this point I was left with a dilemma, do I "erase" my debt, do I disclose the bug and pay the debt, or simply pay the debt and move on. I chose to pay the debt and move on due to fear of any recriminations. However it has left me uneasy ever since knowing that this company have such bad security and any debtors they are chasing for payments potentially will have all of their personal data leaked.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#190
post #92
post #47

Earlier quoted context omitted.

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

My guess would be: - BKK is the client of T-Systems. They have a contract for the development and maintenance of this system which might contain clauses about liability or indemnification in cases of hacking, security bugs, negligency, etc. - This guy reported it to BKK who obviously don't have any technical knowledge - BKK (the client) forwards the email to T-Systems (the contractor): "What's this about? Looks like…

That's unlikely. Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. So the "BKK obviously don't have any technical knowledge" claim is bogus.

It's possible the particular BKK person dealing with the report does not have technical knowledge, but that's more a fail on BKK side as they let incompetent people to deal with reports of security incidents.

But I'd bet it's merely a matter of covering broken shit and shifting blame. BKK is (probably?) a public company, managing transport in the capital city. They manage a lot of money, and it's not uncommon to funnel lucrative contracts to friendly companies, even if it increases price and the quality is dubious. Whoever came up with this project / awarded the contract / accepted the solution is probably scared people might start digging into the details. Better blame the problems on a hacker!

Post reply on HN