Earlier quoted context omitted.
That's unlikely. Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. So the "BKK obviously don't have any technical knowledge" claim is bogus. It's possible the particular BKK person d…
> Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. I don't think this is true. When you buy a house, do you have to be able to do the specification and evaluate? This is a good anal…
18yo arrested for reporting a bug in the new Budapest e-Ticket system
301–310 of 329 posts
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#302Earlier quoted context omitted.
Do you believe that you have a moral right to force them to do anything? Is there a moral imperative that they are morally required to secure their systems and that others should/could demand that they must do so? It definitely could be in certain cases (for example, a hospital storing confidential data of their customers), but in the usual situation where it's just their data and their money, isn't that their moral…
Yeah, I agree 100%. But in a lot of the cases mentioned in this thread the private data of the company's customers was at risk. For example system in the original article allowed you to access other people's name, address and national ID number. I was thinking only of situations like these, there's no reason to threaten a company if they're the only ones at risk.
The process works reasonably well even if the vendor is not cooperative. In that case it is somewhat similar to the message proposed above, but substantially different - first, the threat is not that you'll destroy or publish their data (which is extortion) but that you'll publish your description of the vulnerability (which generally is not); second, the threat is not that you might consider damaging the data (i.e. stating that you'd be willing to do an immoral thing) instead that some other immoral people might damage the data; and third, the disclosure is not conditional on receiving money from them.
I can see that the proposed threat was meant in the same direction, and is somewhat similar to the "threat" implied in general responsible disclosure, i.e., if you don't fix it in 45 days then we'll publish info that most likely will mean that you'll get hacked. But it's substantially different, the details are quite important, and you'd need a good reason to deviate from the standard responsible disclosure guidelines.
I mean, what do you do when after sending a message "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." you see that they have not fixed the issue but have transferred the requested Bitcoins? It'd be a possible direct result of your actions. Is that a desirable outcome? Is that an ethical outcome?
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#303Earlier quoted context omitted.
Ah, yes. Actually Poland is the other bad child in EU... The European commission is currently threatening to remove Poland's voting rights due to the changes to the juridical system, but it will not happen as Hungary will veto. I think they are on their own cultural axis somehow.
[deleted]
Election results are largely a reaction to existing "cultural" state. I don't think it's accurate to consider them to be changing it (think "effect does not imply cause").
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#304Earlier quoted context omitted.
If you think you can't get caught because you use Tor, I know of a few people who can testify otherwise. See, e.g., Ross Ulbricht and Christopher Grief, to name a few.
Go to the public library and use a pc there? Or a free wifi in a mall?
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#305Earlier quoted context omitted.
[deleted]
> Poland is very much its own cultural axis since last election Election results are largely a reaction to existing "cultural" state. I don't think it's accurate to consider them to be changing it (think "effect does not imply cause").
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#306Earlier quoted context omitted.
That seems unreasonable. If I logged in to a service and saw an URL like http://example.com/1234/secret_data , calling them with a report of potential vulnerability would be a waste of their and my time 98% of the time. And there's infinite number of such "potential vulnerabilities" to report, too. Like on HN, I see I can edit my profile description over at https://news.ycombinator.com/user?id=TeMPOraL . I wonder wha…
You consider it "hacking" to change a url from example.com/1234 to example.com/1235?
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#307Side note: this page gives me the weirdest Firefox behaviour I've ever seen: https://gfycat.com/HandyRapidJabiru
I am having this exact issue. - Firefox 54.0.1 (64-bit) - Arch Linux 4.11.5-1-ARCH
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#308Earlier quoted context omitted.
> However leaving such a vulnerability exposed is so bad they deserve to get their entire database dropped (and in this case I hope they don't have backups). I understand the feeling here, but no, they don't deserve to get their assets destroyed because of a lack of care.`
Why not? Destroying the company means they won't be there anymore to put everyone's PII at risk.
You can't just destroy someone else's property because you have some personal anarchist notion of justice.
If they are really being negligent then they should face the proper penalties.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#309In my country, the laws are draconian and totally against this kind of responsible disclosure. But being a good guy, whenever I find something I write a strongly worded email explaining why the company's IT department messed up, how to test said mess-up, and how they can hire my company to ensure these kinds of stupid things don't happen again. I've reported several of these issues, sometimes all I get is single repl…
How do you embed beacons into your emails?
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#310Earlier quoted context omitted.
> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.
That's yet another reason to run something like Qubes OS, split up your online presence into distinct "domains" and heavily firewall each domain, only connecting it through VPNs and/or Tor in most cases.