Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

21–30 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#21
post #17
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

Did you not see the top post?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#22
post #17
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

If he reported it, he runs the risk of the company turning on him (as was the case in the article above). If he doesn't report it, nothing happens.

It's a choice between the certainty of no loss vs the possibility of great loss.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#23
post #16

Earlier quoted context omitted.

> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…

I'm confused by his request as well, I can't understand why he asked it. Any context?

A scene in Star Trek IV.

https://www.youtube.com/watch?v=kvkYTJYcYzY

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#24

"if you just typed in the url (shop.bkk.hu), the site just wouldn't appear. At first I thought they've taken it offline, but it turns out that they just didn't set up the http -> https redirection. And it was left like that for days. If you just heard about it, you couldn't use it. You had to click a link (normal users won't figure out to put an https in front of the host name, even I didn't think of it)." I'd really…

See https://hstspreload.org

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#25
post #17
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

You're often opening up yourself to a LOT of bad exposure, where you'll be accused of hacking the software (along with the 20+ jail term this might eventually entail) and just generally putting the spotlight on yourself as a potentially dangerous person.

Better to report anonymously, or report directly to someone who might appreciate or is responsible (and hope they appreciate responsible disclosure).

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#26
post #16

Earlier quoted context omitted.

> Adobe had him arrested on the stage as he gave his talk. I was there! The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster. During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Ru…

I'm confused by his request as well, I can't understand why he asked it. Any context?

I think it is a Star Trek reference.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#27
post #17
post #7

I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…

Why didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view

You're replying to a comment about news of someone being arrested for a similar thing.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#28
post #24

"if you just typed in the url (shop.bkk.hu), the site just wouldn't appear. At first I thought they've taken it offline, but it turns out that they just didn't set up the http -> https redirection. And it was left like that for days. If you just heard about it, you couldn't use it. You had to click a link (normal users won't figure out to put an https in front of the host name, even I didn't think of it)." I'd really…

See https://hstspreload.org

Ok, so that works for Chrome, but every other application is still going to be subject to an MITM attack if their users try to connect via http?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#29

"this outrageous move from the police brought about fierce reaction resulting in tens of thousands of 1-star reviews on the facebook pages of the companies involved" In the old days, protesters used to physically go and picket in front of company offices. These days, protesters leave one-star reviews. I wonder which is more effective.

I'm as much of a curmudgeon when it comes to slacktivism as you can get. But damaging a companies online presence with negative reviews, ratings, posts on social media, blogs, and more, will live on. It will hurt the company quite a bit. In this case I think the online element is quite effective.

Also there seems to be some irl protesting going on as well, at least in this case.

Post reply on HN