Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

231–240 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#231
post #225
post #167

Earlier quoted context omitted.

A practical democracy must be an abstraction of a pure, idealistic democracy. You cannot have millions of people deciding on every issue. Democratically elected representatives are one way we can do this. There may be better ways of doing things but it doesn't make democracies not democracies.

> You cannot have millions of people deciding on every issue. From a technical perspective, this is clearly untrue.

> From a technical perspective, this is clearly untrue.

It's impossible if you take “every issue” literally, as you are multiplying the number of pdecisions that must be made by each participant per unit of time so much that the time to consider them is non-existent.

It's less impossible if you reduce it to the kind of decisions typically made by a legislature, which mainly just sets rules for executive and judicial officials to apply in deciding more specific issues.

But even then it's of dubious practicality; obviously not every citizen can have a full-time legislative staff, and most of other things besides legislation to devote their time to.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#232

Earlier quoted context omitted.

who is the sheriff in this case?

I'm the sheriff! But all kidding aside, It sounds like the sheriff is the hacker. Who has discovered every lock is the exact same through investigation. That said, a hacker isn't elected to protect people, they are doing it out of the "kindness" of their heart. What a lot of people get in trouble for is hacking first and asking for permission after. If you go up to a company with a statement like: "I think you may ha…

That seems unreasonable.

If I logged in to a service and saw an URL like http://example.com/1234/secret_data, calling them with a report of potential vulnerability would be a waste of their and my time 98% of the time. And there's infinite number of such "potential vulnerabilities" to report, too. Like on HN, I see I can edit my profile description over at https://news.ycombinator.com/user?id=TeMPOraL. I wonder what happens when I change the 'id' param? Better not try out, but call 'dang immediately!

Discovering an actual vulnerability in the first place requires doing something that could be considered hacking.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#233

A few years ago I also found a serious bug in a debt collection agencies web software. I ordered a phone and neglected to pay import tax and was chased by the agency. I found their website and saw that they developed their management software in-house and made it available for purchase for other agencies. They offered a demo which I used to navigate around, in the demo was a reporting tool which essentially allowed y…

Such companies are usually extremely shady and unethical, I would not consider it evil at all to delete all of their recorded debts via tor or something.

Would you gladly go to prison for it?

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#234

Earlier quoted context omitted.

I'd disagree here, how would he know there was a bug to report if he didn't do it once ? Besides this has been used for decades by corps to prosecute vulnerability reporters, see Serge Humpich who discovered a huge vulnerabilty in bank cards back in 1997. He reported to european bank card Economic Interest Group (EIG) with the support of a lawyer who said they would not believe him until he proved it practically. So…

He could have used the same value in the hacking as the original one or even adding 1 unit to the original price. This does not cause anybody any damages and it is much easier to defend it at the court while still illegal. If there is no bug bounty program and you do not have a contract to perform such activities than it is not a good idea to engage in such activities.

He didn't cause any damages. He reported the issue including the pass he purchased as evidence and it was invalidated.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#235

Earlier quoted context omitted.

That's unlikely. Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. So the "BKK obviously don't have any technical knowledge" claim is bogus. It's possible the particular BKK person d…

> Every if you don't develop the system on your own and buy it from a third party (be it T-Systems or someone else), you still need technical expertise to prepare the requirements, evaluate the proposed solution (possibly proposals from multiple vendors) and do then do acceptance testing. I don't think this is true. When you buy a house, do you have to be able to do the specification and evaluate? This is a good anal…

In my experience, clients rarely have any technical expertise at all.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#236

A few years ago I also found a serious bug in a debt collection agencies web software. I ordered a phone and neglected to pay import tax and was chased by the agency. I found their website and saw that they developed their management software in-house and made it available for purchase for other agencies. They offered a demo which I used to navigate around, in the demo was a reporting tool which essentially allowed y…

You don't erase just your debt, you open up Tor browser and drop the entire database. That'll teach them for next time.

Better to pay your debt, wait till your PII has been removed, then issue a public disclosure of the bug.

Public disclosure because everybody should know about something like this that may impact them. Not because some random vigilante will see it and drop their DB for which they probably have no backups.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#237

Earlier quoted context omitted.

Such companies are usually extremely shady and unethical, I would not consider it evil at all to delete all of their recorded debts via tor or something.

Would you gladly go to prison for it?

No, which is why I mentioned tor.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#238

Earlier quoted context omitted.

Would you gladly go to prison for it?

No, which is why I mentioned tor.

If you think you can't get caught because you use Tor, I know of a few people who can testify otherwise. See, e.g., Ross Ulbricht and Christopher Grief, to name a few.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#239

Earlier quoted context omitted.

Would you gladly go to prison for it?

No, which is why I mentioned tor.

In case anyone feels like doing something like that, this talk is worth a listen:

https://www.youtube.com/watch?v=eQ2OZKitRwc

A talk on how Tor users got caught. In a nutshell: it wasn't Tor's fault, but bad OPSEC on the part of the users.

Post reply on HN