Live data from Hacker News

18yo arrested for reporting a bug in the new Budapest e-Ticket system

blog.marai.me

311–320 of 329 posts

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#311
post #220

Earlier quoted context omitted.

It's 20 freaking 17. How can people release software with these totally elementary mistakes? Just one is bad enough, but... admin/admin?? This is easily worthy of a Daily WTF article to itself. And this software was written by a professional contractor - pretty sure you'd get better quality from a kid fresh out of university, because on my course, it was drilled into me - NEVER TRUST THE CLIENT BROWSER! Companies nee…

"NEVER TRUST THE CLIENT BROWSER!" Isn't it mostly in multiplayer game programming where this gets said over and over "Never trust the game client" even though it should be said in all aspects of programming really

[deleted]

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#312

Earlier quoted context omitted.

Why not? Destroying the company means they won't be there anymore to put everyone's PII at risk.

Because private property is a cornerstone of a free society? You can't just destroy someone else's property because you have some personal anarchist notion of justice. If they are really being negligent then they should face the proper penalties.

Well the issue is that there are no penalties. Only free money for lawyers and nothing for the people who got their PII stolen.

Dropping the DB means there's no more PII to leak, makes a pretty good financial penalty for the company and doesn't make millions for useless lawyers. That sounds like an acceptable solution by my standards.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#313
post #10

When I was in Budapest a few weeks ago, I heard from multiple locals that the metro system was owned by some sort of mafia. I wonder if that explains the subpar security and overreaction to the bug report. edit: a few weeks ago, not this past summer that is still occurring

Since I can't edit the post, apologies to any offense I may have caused. Although I did hear this from locals, it was likely a communications breakdown.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#314
post #193

Earlier quoted context omitted.

No, it isn't. Sorry but this is exactly the kind of "there must be a hidden agenda to this" thinking which skews your reality. Our governments are simply highly incompetent and terribly mismanaged, but not in the hands of organised crime. You can still draw parallels between ANY government and mafia.

Depends on the country, I guess. Come visit Ukraine - there is almost nothing hidden regarding those agendas here. One question, tho - if they are so incompetent and mismanaged, how come they're your government?

Ah, you are from Ukraine. This explains your bitterness. There are differences between Eastern-Europe and Eastern-Europe. Ukraine is in a whole different dimension regarding corruption, than Hungary.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#315

Earlier quoted context omitted.

> You don't see anything unethical or immoral about telling a company "I hacked your systems, send me money or I'll delete all your data"? I do, however loup-vaillant's post also contained the following, which makes it not immoral nor unethical: > accessed and modified , using . You have Also, you need to panic them, you do not necessarily need to delete or copy their data (but even if you did, I see nothing evil in…

If you point out that my front door is unlocked, and I decide to keep it unlocked forever (i.e. refuse to fix it), then it doesn't mean that it somehow becomes ethical to enter my house and take my stuff. It might be stupid on my part to keep it unlocked, but a thief is still ethically a thief even if I carelessly kept it unlocked forever. My "door" might as well be a line in sand or a sign "don't enter" on a pathway…

If you had classified information behind your open door, you could be sued if anyone stole it (or worse, depending on the level of classification). Sometimes, one is legally required to take appropriate steps not to unwillingly disclose information. I believe users' personal information should fall under this category. (I believe it does in some cases.)

If your leaving the door open leaves not only you, but others, vulnerable, the discoverer of the broken lock may very well have a moral obligation to protect those innocent people, by whatever means appropriate.

What is appropriate depends on the situation. I expect in most cases, just telling you the door is open may be enough. But if you are being particularly obnoxious, threats may be the only way. In some extreme cases, burning the house down to avoid the disclosure of the sensitive information that would harm countless innocents may be the best course of action.

The legal system even have analogous situations, where a judge can order the orderly destruction of some unsafe building. The only (yet crucial) difference is, judges aren't vigilantes. But this is fixable: one could have the law allow the vigilante to send a cease & desist letter saying "fix your door or I'll have a judge burn your house down".

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#316

Two takeaways, one from this and one from my other past experience. First, when testing whether you can change a price and have a transaction go through successfully, RAISE THE PRICE. If you lower the price the affected entity may come back and say "See??? He's STEALING from us! Lock him up!" If you've overpaid for something through their web interface that complaint and issue goes completely away. Second, if you're…

> If you've overpaid for something through their web interface that complaint and issue goes completely away. Or it doesn't, because you have still "hacked them". Doing it in a seemingly bizarre way may only raise more suspicions; obviously you must have maliciously cheated them, since who would give them money? Please don't put people at risk by giving such "advice".

What I was talking about was the question of being accused of theft (by having completed an order/purchase after lowering the price). This was also in the context of someone already intending to push a transaction with an attempted price change. At that point nothing you do with the price is going to prevent a "hacking" charge if there's going to be one, but you may be able to prevent a corresponding "stole from us" charge.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#317
post #193

Earlier quoted context omitted.

No, it isn't. Sorry but this is exactly the kind of "there must be a hidden agenda to this" thinking which skews your reality. Our governments are simply highly incompetent and terribly mismanaged, but not in the hands of organised crime. You can still draw parallels between ANY government and mafia.

Depends on the country, I guess. Come visit Ukraine - there is almost nothing hidden regarding those agendas here. One question, tho - if they are so incompetent and mismanaged, how come they're your government?

> if they are so incompetent and mismanaged, how come they're your government?

Because we elected them based on their skills in lying rather than governance. And also because government jobs naturally attract and promote incompetence.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#318
post #305
post #303

Earlier quoted context omitted.

> Poland is very much its own cultural axis since last election Election results are largely a reaction to existing "cultural" state. I don't think it's accurate to consider them to be changing it (think "effect does not imply cause").

[deleted]

> The thing is that PiS, Kukiz and TVP have normalized and brought into daily life in Poland extremely aggressive language and rhetoric.

Same thing as with Trump. It's because literally nothing else works today against self-righteous leftists.

You said in another comment that majority of Poles would rather leave EU than deal with the Islamic mess. AFAIK the most credible opposition to the current government is still PO, who were the ruling party before and literally in the last days of their term they signed an extremely unpopular obligation to accept forced resettlement of German Muslims, which the current government had to backpedal from, damaging the country's international credibility.

The Polish government doesn't really have to do anything to stay in power indefinitely now. Until something changes on the political scene and a credible opposition arrives which isn't a puppet of Brussels, it's enough that they shake their fist at Merkel's social policies every now and then and they are literally guaranteed to win every election forever.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#319
post #284

Earlier quoted context omitted.

It's 20 freaking 17. How can people release software with these totally elementary mistakes? Just one is bad enough, but... admin/admin?? This is easily worthy of a Daily WTF article to itself. And this software was written by a professional contractor - pretty sure you'd get better quality from a kid fresh out of university, because on my course, it was drilled into me - NEVER TRUST THE CLIENT BROWSER! Companies nee…

I find one of the worst arguments I come across is "it is " because it doesn't actually mean anything.

Correct, but in exasperation it's often the only thing to reach for, because programming is not a new thing, even web programming, and these are such elemental flaws that should have long been eliminated. It's just cringe-worthy they are still causing problems.

Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system

#320
post #220

Earlier quoted context omitted.

It's 20 freaking 17. How can people release software with these totally elementary mistakes? Just one is bad enough, but... admin/admin?? This is easily worthy of a Daily WTF article to itself. And this software was written by a professional contractor - pretty sure you'd get better quality from a kid fresh out of university, because on my course, it was drilled into me - NEVER TRUST THE CLIENT BROWSER! Companies nee…

"NEVER TRUST THE CLIENT BROWSER!" Isn't it mostly in multiplayer game programming where this gets said over and over "Never trust the game client" even though it should be said in all aspects of programming really

I would have ended at 'client' but figured it could extend to the human (although that's true too). But yes, there is still so much naivety in implementing distributed or client-server systems that they should trust input from remote sources.
Post reply on HN