Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

221–230 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#221

Earlier quoted context omitted.

I really can't see how this is unethical or immoral in any way.

You don't see anything unethical or immoral about telling a company "I hacked your systems, send me money or I'll delete all your data"? It's obviously a crime.

> You don't see anything unethical or immoral about telling a company "I hacked your systems, send me money or I'll delete all your data"?

I do, however loup-vaillant's post also contained the following, which makes it not immoral nor unethical:

> accessed and modified , using . You have

Also, you need to panic them, you do not necessarily need to delete or copy their data (but even if you did, I see nothing evil in it. They are the ones that refused to fix it within the time given after all).

> It's obviously a crime.

Doesn't mean that it's immoral or unethical.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#222

Earlier quoted context omitted.

> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…

Sounds kinda mean spirited to mock of the accent of someone who is presenting in their second language.

I believe it isn't about mocking but making the point about US / Russia and nuclear weapons

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#223

Earlier quoted context omitted.

Had a similar issue with Wolfram Alpha some years ago. I reported a dozen different XSS vulnerabilities to them and their answer was: "We forwarded this email to our legal department.". So even technical companies can react in really silly ways.

I think legal's involvement is perfectly normal. Part of damage control consists of figuring out the legal ramifications of the product/service having technical vulnerabilities. Especially if those vulnerabilities leak customer data. What isn't cool is legal deciding to go after the party disclosing the vulnerability.

Not having much experience on this subject, I have to ask: would you not get your developers to verify that the vulnerability is there and fix it while the legal department is doing its thing? The vulnerability is already out there, and the sooner it's fixed the better. While would they forward everything to their lawyers first thing?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#224
post #179

Earlier quoted context omitted.

I think that the second scenario in your analogy is somewhat creepy too. Why are they trying all of the doors? A person should have a reasonable expectation of privacy in their house, to be able to walk around in their underwear or whatever without someone just opening the door on them. Edit: Note that in this analogy the keys aren't fully visible from outside and it requires opening the door to be sure that the keys…

If your security is " http://example.com/1234/secret_data/" , but 1234 is your customer number, and changing the customer number gives you someone else's data, then the analogy is more like: "the sheriff has told everyone that there's a bad dude wandering round town trying doors, and [responsible citizen] noticed that everyone had identical door-keys which would open every lock". Is that still creepy?

I would find it creepy that someone was testing their key on other people's doors.

If I caught someone trying their key on my door I would call the cops, even if they said they were just testing it to see if it would work.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#225
post #167

Earlier quoted context omitted.

As every other country on earth right now, Hungary is not a democracy at all. So there's that. At some point we need to understand the novlang used here, by squatting the word democracy to label the political system based on elections, people in power manage to prevent to emergence of an actual democracy. Please stop misusing this word so we have a better chance of actually having a democracy somwhere at some point i…

A practical democracy must be an abstraction of a pure, idealistic democracy. You cannot have millions of people deciding on every issue. Democratically elected representatives are one way we can do this. There may be better ways of doing things but it doesn't make democracies not democracies.

> You cannot have millions of people deciding on every issue.

From a technical perspective, this is clearly untrue.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#226
post #179

Earlier quoted context omitted.

If your security is " http://example.com/1234/secret_data/" , but 1234 is your customer number, and changing the customer number gives you someone else's data, then the analogy is more like: "the sheriff has told everyone that there's a bad dude wandering round town trying doors, and [responsible citizen] noticed that everyone had identical door-keys which would open every lock". Is that still creepy?

who is the sheriff in this case?

I'm the sheriff!

But all kidding aside, It sounds like the sheriff is the hacker. Who has discovered every lock is the exact same through investigation.

That said, a hacker isn't elected to protect people, they are doing it out of the "kindness" of their heart. What a lot of people get in trouble for is hacking first and asking for permission after.

If you go up to a company with a statement like: "I think you may have a vulnerability in your software. I haven't tested this hypothesis (you can verify in your logs), but with your permission, I could check it, and report back to you." Most companies would probably be thankful, others might instead get mad and handle it internally. But if you DON'T hack first, you have nothing to really worry about.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#227
post #65

Earlier quoted context omitted.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

Why does a group of criminals need a subway? As a local guy using the public transport on a daily basis, I highly doubt this.

Hm.. money laundering?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#228
post #47
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…

They paid a lot of money for a system they were told was totally secure, so damnit they're going to believe that despite any evidence to the contrary. Thus any bugs reported to them are not bugs but malicious attacks on their innocent system.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#229
We had a similar case - National security authority(NBU SR) of a neighboring country got their public web infrastructure hacked after guessing credentials (nbusr:nbusr123). In the end, guys got free after trial because police were unable to unambiguously identify them.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#230

Earlier quoted context omitted.

You don't see anything unethical or immoral about telling a company "I hacked your systems, send me money or I'll delete all your data"? It's obviously a crime.

> You don't see anything unethical or immoral about telling a company "I hacked your systems, send me money or I'll delete all your data"? I do, however loup-vaillant's post also contained the following, which makes it not immoral nor unethical: > accessed and modified , using . You have Also, you need to panic them, you do not necessarily need to delete or copy their data (but even if you did, I see nothing evil in…

If you point out that my front door is unlocked, and I decide to keep it unlocked forever (i.e. refuse to fix it), then it doesn't mean that it somehow becomes ethical to enter my house and take my stuff. It might be stupid on my part to keep it unlocked, but a thief is still ethically a thief even if I carelessly kept it unlocked forever. My "door" might as well be a line in sand or a sign "don't enter" on a pathway - not a security measure at all, just an indication where the boundary is, but still unethical to cross it. Much more so would be sending a note "lock your door, send me money or I'll take or damage your stuff", as in the original example.

Threatening to harm someone unless they do what you say is immoral even if you don't harm them; it's not ethically acceptable to threaten others.

Post reply on HN