Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

281–290 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#281

> the poor 18 year old 'hacker' who was stupid enough to email them s/stupid/trusting/. There's no reason to think this guy isn't bright, and he's faced enough trouble without piling on.

I believe the author meant it to sound sarcastic

It's definitely a jab at the company, but seems to cast a little shade too on the bug-finder. Cf the lede "The amount of stupidity in this story warrants that this is going to be somewhat long". That might not be the author's intent! I hope they'll see this as helpful.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#282

Earlier quoted context omitted.

No, which is why I mentioned tor.

If you think you can't get caught because you use Tor, I know of a few people who can testify otherwise. See, e.g., Ross Ulbricht and Christopher Grief, to name a few.

Go to the public library and use a pc there? Or a free wifi in a mall?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#283

In my country, the laws are draconian and totally against this kind of responsible disclosure. But being a good guy, whenever I find something I write a strongly worded email explaining why the company's IT department messed up, how to test said mess-up, and how they can hire my company to ensure these kinds of stupid things don't happen again. I've reported several of these issues, sometimes all I get is single repl…

How do you embed beacons into your emails?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#284

The list of bullet points of the egregious flaws in the software just get worse and worse. It's crazy how I thought the first one or two would be the worst since, but it just got worse.

It's 20 freaking 17. How can people release software with these totally elementary mistakes? Just one is bad enough, but... admin/admin?? This is easily worthy of a Daily WTF article to itself. And this software was written by a professional contractor - pretty sure you'd get better quality from a kid fresh out of university, because on my course, it was drilled into me - NEVER TRUST THE CLIENT BROWSER! Companies nee…

I find one of the worst arguments I come across is "it is " because it doesn't actually mean anything.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#285
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

Someone probably misunderstood something. Our government is usually referred to as a mafia government because of their tactics and modus operandi. The Metro is state owned and with a bit of a stretch I can understand where this is coming from.

You remind me of the Dutch railroad system. It has a monopoly despite having been privatized, and the majority stockholder is.... the Dutch government.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#286
post #93

Earlier quoted context omitted.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

It's just the old commie era thinking. Some people think of the government as a hostile entity. Strangely the same people believe in a strong state acting as a nanny, so they don't have to solve their problems themselves. Hopefully this will heal with time and people start to take responsibility in both their private life and politically.

Wow, there is some really funny shit going on in your head behind that pink goggles of yours? We are trying to deal with that for several years now, still a lot of work to be done. And no - that's not just thinking. Some of those government guys became so insolent that their shady schemes are basically open to public.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#287
post #193

Earlier quoted context omitted.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

No, it isn't. Sorry but this is exactly the kind of "there must be a hidden agenda to this" thinking which skews your reality. Our governments are simply highly incompetent and terribly mismanaged, but not in the hands of organised crime. You can still draw parallels between ANY government and mafia.

Depends on the country, I guess. Come visit Ukraine - there is almost nothing hidden regarding those agendas here. One question, tho - if they are so incompetent and mismanaged, how come they're your government?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#288

Two takeaways, one from this and one from my other past experience. First, when testing whether you can change a price and have a transaction go through successfully, RAISE THE PRICE. If you lower the price the affected entity may come back and say "See??? He's STEALING from us! Lock him up!" If you've overpaid for something through their web interface that complaint and issue goes completely away. Second, if you're…

3rd takeaway - don't do this in turkey unless you want to end up in a literal Turkish prison.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#289
post #272

Earlier quoted context omitted.

Make a backup for them first too, just in case they don't have one..

This is very evil...

In most of my D&D games it might be considered chaotic good depending on the debt collector.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#290
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

I was more naive, but it worked out. Reported a vulnerability and how to fix it to a regional bank when applying for a student loan. They asked me to come in person to explain it and dropped a point off my interest rate. In hindsight it was a huge risk and I was dangerously trusting.

I've reported two vulnerabilities. One to a fairly large web hosting provider that allowed me to access the databases of anyone else on the shared server my website was on. Another to a major credit card company -- Given a person's first and last name I was able to see what kind of credit cards they had.

In both cases, they fixed it, thanked me, no arrests or threats were made. I think your experience is only outside the norm in the sense that you got monetary compensation out of it! Nice!

Post reply on HN