Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.
I'd disagree here, how would he know there was a bug to report if he didn't do it once ? Besides this has been used for decades by corps to prosecute vulnerability reporters, see Serge Humpich who discovered a huge vulnerabilty in bank cards back in 1997. He reported to european bank card Economic Interest Group (EIG) with the support of a lawyer who said they would not believe him until he proved it practically. So…
18yo arrested for reporting a bug in the new Budapest e-Ticket system
191–200 of 329 posts
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#192My parents went to buy a ticket at the counter. The lady behind the counter didn't speak English (which is totally OK). Her only communication was a 'go away' movement with her hand, after which she ignore us and signaled for the next customer in line to come to her.
Luckily a colleague of her helped us and gave us careful instruction on the time and platform of the train. After we took the train and sat for a few hours, the conductor of the train came and notified that our tickets were invalid. We argued for some time since the lady behind the counter told us this was the right train. The conductor became mad and told us that we had to pay him 50 euros in cash for some unknown reason (presumably to buy a ticket for the train we were on, but his English was very limited). Note that this was a normal train and there was no shortage of seats. In the end, we chose to get out at the next stop, and take the next train, which was about 3 hours later.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#193Earlier quoted context omitted.
Please don't spread fake news! The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia. Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.
TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#194Although deeply unfair, this is not unusual, there have been many reported cases of companies shooting the messenger. Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking. What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has…
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#195Wtf ,I thought I was bad at my job.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#196I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…
Had a similar issue with Wolfram Alpha some years ago. I reported a dozen different XSS vulnerabilities to them and their answer was: "We forwarded this email to our legal department.". So even technical companies can react in really silly ways.
What isn't cool is legal deciding to go after the party disclosing the vulnerability.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#197Earlier quoted context omitted.
I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as so…
> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#198Earlier quoted context omitted.
...stateless cloud interactive real-time connection through highly sophisticated authentication featuring dual way private/public key encryption services with single use time-limited tokens ...
Don't forget the blockchain! It needs more blockchain! ;-)
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#199Earlier quoted context omitted.
That is quite straightforward and makes it clear from all perspectives. From the hacker "hat classification" perspective, that's obviously black hat, nothing gray about it. From the legal perspective it's not a debate anymore (like in the original article) if you do this, it's clearly a crime, if you get caught in whatever way (e.g. by bragging about it someplace later that leads to your person, or by testing a "disc…
My understand was that you just threaten to do those things but don't actually follow through on those threats. Then it's grey hat and ethical but still not legal. If they actually pay the bitcoins and don't fix the issue then you despair and go on with your life. It's hard to spend the bitcoins without deanonymising yourself, but you can try to give them to charity or something.
That's as classic as it can be, there's nothing new or technology related about this - for example, sending an anonymous message "Send cash or I'll burn your house" is a crime (and unethical) even if you don't burn anything. It is a crime (and unethical) even if you're just making an empty threat and never intend to burn anything, it still is extortion.
Arson is one crime, and extortion is a separate crime punishable by itself. If you don't attempt to delete their data then you (obviously) don't get charged with deleting their data, but making threats like that is not acceptable in any way (legal or ethical) whatsoever. Once you press "send" on a message like that, you've crossed a very serious line.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#200Earlier quoted context omitted.
I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as so…
> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.