Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

191–200 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#191

Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.

I'd disagree here, how would he know there was a bug to report if he didn't do it once ? Besides this has been used for decades by corps to prosecute vulnerability reporters, see Serge Humpich who discovered a huge vulnerabilty in bank cards back in 1997. He reported to european bank card Economic Interest Group (EIG) with the support of a lawyer who said they would not believe him until he proved it practically. So…

He could have used the same value in the hacking as the original one or even adding 1 unit to the original price. This does not cause anybody any damages and it is much easier to defend it at the court while still illegal. If there is no bug bounty program and you do not have a contract to perform such activities than it is not a good idea to engage in such activities.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#192
Not really related to the technological side of the story, but I had a horrible experience with the international trains from Budapest. So they don't need a broken electronic system to provide a horrible service ;)

My parents went to buy a ticket at the counter. The lady behind the counter didn't speak English (which is totally OK). Her only communication was a 'go away' movement with her hand, after which she ignore us and signaled for the next customer in line to come to her.

Luckily a colleague of her helped us and gave us careful instruction on the time and platform of the train. After we took the train and sat for a few hours, the conductor of the train came and notified that our tickets were invalid. We argued for some time since the lady behind the counter told us this was the right train. The conductor became mad and told us that we had to pay him 50 euros in cash for some unknown reason (presumably to buy a ticket for the train we were on, but his English was very limited). Note that this was a normal train and there was no shortage of seats. In the end, we chose to get out at the next stop, and take the next train, which was about 3 hours later.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#193

Earlier quoted context omitted.

Please don't spread fake news! The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia. Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.

TBH in Eastern Europe something being owned by government usually means that it's being ran (basically owned) by mafia.

No, it isn't. Sorry but this is exactly the kind of "there must be a hidden agenda to this" thinking which skews your reality. Our governments are simply highly incompetent and terribly mismanaged, but not in the hands of organised crime. You can still draw parallels between ANY government and mafia.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#194

Although deeply unfair, this is not unusual, there have been many reported cases of companies shooting the messenger. Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking. What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has…

One thing that solves this is stating the obvious, something getting hacked means someone was incompetent.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#196
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Had a similar issue with Wolfram Alpha some years ago. I reported a dozen different XSS vulnerabilities to them and their answer was: "We forwarded this email to our legal department.". So even technical companies can react in really silly ways.

I think legal's involvement is perfectly normal. Part of damage control consists of figuring out the legal ramifications of the product/service having technical vulnerabilities. Especially if those vulnerabilities leak customer data.

What isn't cool is legal deciding to go after the party disclosing the vulnerability.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#197
post #154

Earlier quoted context omitted.

I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as so…

> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.

That's yet another reason to run something like Qubes OS, split up your online presence into distinct "domains" and heavily firewall each domain, only connecting it through VPNs and/or Tor in most cases.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#198
post #182
post #150

Earlier quoted context omitted.

...stateless cloud interactive real-time connection through highly sophisticated authentication featuring dual way private/public key encryption services with single use time-limited tokens ...

Don't forget the blockchain! It needs more blockchain! ;-)

Also wouldn't mind some "cyber" in there :D

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#199

Earlier quoted context omitted.

That is quite straightforward and makes it clear from all perspectives. From the hacker "hat classification" perspective, that's obviously black hat, nothing gray about it. From the legal perspective it's not a debate anymore (like in the original article) if you do this, it's clearly a crime, if you get caught in whatever way (e.g. by bragging about it someplace later that leads to your person, or by testing a "disc…

My understand was that you just threaten to do those things but don't actually follow through on those threats. Then it's grey hat and ethical but still not legal. If they actually pay the bitcoins and don't fix the issue then you despair and go on with your life. It's hard to spend the bitcoins without deanonymising yourself, but you can try to give them to charity or something.

No, simply making that threat ("send Bitcoins to , or I your database") is very definitely a crime (and black hat, and unethical) even without any followup.

That's as classic as it can be, there's nothing new or technology related about this - for example, sending an anonymous message "Send cash or I'll burn your house" is a crime (and unethical) even if you don't burn anything. It is a crime (and unethical) even if you're just making an empty threat and never intend to burn anything, it still is extortion.

Arson is one crime, and extortion is a separate crime punishable by itself. If you don't attempt to delete their data then you (obviously) don't get charged with deleting their data, but making threats like that is not acceptable in any way (legal or ethical) whatsoever. Once you press "send" on a message like that, you've crossed a very serious line.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#200
post #154

Earlier quoted context omitted.

I get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as so…

> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.

Yeah, you have to consider if there might be logs likely showing you to be the only person to have used the system in the manner you described.
Post reply on HN