Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

301–310 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#301

Earlier quoted context omitted.

That's unlikely. Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. So the "BKK obviously don't have any technical knowledge" claim is bogus. It's possible the particular BKK person d…

> Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. I don't think this is true. When you buy a house, do you have to be able to do the specification and evaluate? This is a good anal…

It is common for a typical western government to have domain specialists, working directly for them, to help write the contracts and requirements for their external contractors and vendors.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#302

Earlier quoted context omitted.

Do you believe that you have a moral right to force them to do anything? Is there a moral imperative that they are morally required to secure their systems and that others should/could demand that they must do so? It definitely could be in certain cases (for example, a hospital storing confidential data of their customers), but in the usual situation where it's just their data and their money, isn't that their moral…

Yeah, I agree 100%. But in a lot of the cases mentioned in this thread the private data of the company's customers was at risk. For example system in the original article allowed you to access other people's name, address and national ID number. I was thinking only of situations like these, there's no reason to threaten a company if they're the only ones at risk.

Okay, if private data of the company's customers is at risk, then it is a reason to push for some action, but it matters how you do it. In this case I don't see a big need for reinventing the wheel - this is a common issue for which all the options, pros, cons and risks have already been discussed and there is a somewhat clear consensus (with some debate about nuances) on the expected ethical action, and that is https://en.wikipedia.org/wiki/Responsible_disclosure or http://www.cert.org/vulnerability-analysis/vul-disclosure.cf...? . Many nations have some more specific guidelines issued by e.g. their local CERT that are adapted to their local legal situation.

The process works reasonably well even if the vendor is not cooperative. In that case it is somewhat similar to the message proposed above, but substantially different - first, the threat is not that you'll destroy or publish their data (which is extortion) but that you'll publish your description of the vulnerability (which generally is not); second, the threat is not that you might consider damaging the data (i.e. stating that you'd be willing to do an immoral thing) instead that some other immoral people might damage the data; and third, the disclosure is not conditional on receiving money from them.

I can see that the proposed threat was meant in the same direction, and is somewhat similar to the "threat" implied in general responsible disclosure, i.e., if you don't fix it in 45 days then we'll publish info that most likely will mean that you'll get hacked. But it's substantially different, the details are quite important, and you'd need a good reason to deviate from the standard responsible disclosure guidelines.

I mean, what do you do when after sending a message "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." you see that they have not fixed the issue but have transferred the requested Bitcoins? It'd be a possible direct result of your actions. Is that a desirable outcome? Is that an ethical outcome?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#303
post #276
post #86

Earlier quoted context omitted.

Ah, yes. Actually Poland is the other bad child in EU... The European commission is currently threatening to remove Poland's voting rights due to the changes to the juridical system, but it will not happen as Hungary will veto. I think they are on their own cultural axis somehow.

[deleted]

> Poland is very much its own cultural axis since last election

Election results are largely a reaction to existing "cultural" state. I don't think it's accurate to consider them to be changing it (think "effect does not imply cause").

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#304
post #282

Earlier quoted context omitted.

If you think you can't get caught because you use Tor, I know of a few people who can testify otherwise. See, e.g., Ross Ulbricht and Christopher Grief, to name a few.

Go to the public library and use a pc there? Or a free wifi in a mall?

See the previous point about Ross Ulbricht (arrested in a public library)

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#305
post #303
post #276

Earlier quoted context omitted.

[deleted]

> Poland is very much its own cultural axis since last election Election results are largely a reaction to existing "cultural" state. I don't think it's accurate to consider them to be changing it (think "effect does not imply cause").

[deleted]

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#306

Earlier quoted context omitted.

That seems unreasonable. If I logged in to a service and saw an URL like http://example.com/1234/secret_data , calling them with a report of potential vulnerability would be a waste of their and my time 98% of the time. And there's infinite number of such "potential vulnerabilities" to report, too. Like on HN, I see I can edit my profile description over at https://news.ycombinator.com/user?id=TeMPOraL . I wonder wha…

You consider it "hacking" to change a url from example.com/1234 to example.com/1235?

Ask Weev, while being a troll... Apparently he gets to go to jail for using numbers at the end of a url... ICC ID... So you try one number than another, then disclose it, and yeah... Go to prison. Welcome to America.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#307
post #4

Side note: this page gives me the weirdest Firefox behaviour I've ever seen: https://gfycat.com/HandyRapidJabiru

I am having this exact issue. - Firefox 54.0.1 (64-bit) - Arch Linux 4.11.5-1-ARCH

I'm on the 4.11.9-1-ARCH kernel, but same Firefox version. I'm only able to reproduce with the Zotero addon enabled, are you using it too?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#308

Earlier quoted context omitted.

> However leaving such a vulnerability exposed is so bad they deserve to get their entire database dropped (and in this case I hope they don't have backups). I understand the feeling here, but no, they don't deserve to get their assets destroyed because of a lack of care.`

Why not? Destroying the company means they won't be there anymore to put everyone's PII at risk.

Because private property is a cornerstone of a free society?

You can't just destroy someone else's property because you have some personal anarchist notion of justice.

If they are really being negligent then they should face the proper penalties.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#309
post #283

In my country, the laws are draconian and totally against this kind of responsible disclosure. But being a good guy, whenever I find something I write a strongly worded email explaining why the company's IT department messed up, how to test said mess-up, and how they can hire my company to ensure these kinds of stupid things don't happen again. I've reported several of these issues, sometimes all I get is single repl…

How do you embed beacons into your emails?

Streak.com does it for you, it's awesome

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#310
post #154

Earlier quoted context omitted.

> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.

That's yet another reason to run something like Qubes OS, split up your online presence into distinct "domains" and heavily firewall each domain, only connecting it through VPNs and/or Tor in most cases.

Because TOR is safe...
Post reply on HN