18yo arrested for reporting a bug in the new Budapest e-Ticket system
blog.marai.me
blog.marai.me
Protection from this kind of blame-shifting and misdirected retaliation should be guaranteed by law. Until it is, bugs in critical and important infrastructure will go on unreported, and remain available for malicious actors to exploit.
Seems somewhat negligent - at the very least from a Good Samaritan™ point of view
It's a choice between the certainty of no loss vs the possibility of great loss.
Better to report anonymously, or report directly to someone who might appreciate or is responsible (and hope they appreciate responsible disclosure).
In hindsight it was a huge risk and I was dangerously trusting.
What they don't like is the publicity.
Edit: but maybe not in Hungary. It's the bad child in EU.
At first the bank security department said no one will find it so it's safe and later when he pressed the issue as a dangerous leak they reported him to the police for "hacking and extortion". All the computers from his company got confiscated for investigation so he had to buy new computers and software to continue running his company. In the end he was found not guilty by the police investigation of his computers so the prosecution dropped the case (it didn't even go to court) and all his stuff returned after 6 months.
Source in Polish (sorry, there is no English source): https://niebezpiecznik.pl/post/glebokie-ukrycie-danych-w-pko... http://www.tvn24.pl/wiadomosci-z-kraju,3/haker-mimo-woli,132...
Bank spokesperson later explained that the files were "deeply hidden" ("głębokie ukrycie", he said it's an IT term, it's not) and only one person found them in 4 years of their existence there so it's not a big deal.
And in general misusing, testing, etc. a website is illegal without owners permission, there is now a small exception for acting in good faith but it's narrow, a bit strangely worded and it doesn't prevent stuff like above.
The European commission is currently threatening to remove Poland's voting rights due to the changes to the juridical system, but it will not happen as Hungary will veto.
I think they are on their own cultural axis somehow.
> Edit: but maybe not in Hungary. It's the bad child in EU.
The article suggests that they reported this guy to the police only after the info leaked out (or possibly was independently discovered by others) and made it to the press.
Scapegoating of non-malicious hackers isn't really anything new or unique to Hungary. It's a common reaction of IT-illiterates to people "cheating" on their systems everywhere.
In both cases, they fixed it, thanked me, no arrests or threats were made. I think your experience is only outside the norm in the sense that you got monetary compensation out of it! Nice!
I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as soon as I realised 'my mistake' and was very surprised. Basically enough that 1) If it should go to court the situation would be in my favour as much as it can be and 2) Given they were a well know public retailer I figured this would hit social media and make an uproar about the company should they act badly.
Initially I contact several people in IT and heard nothing. Six months later when I noticed this was still open. I then contacted the CEO. Expecting nothing or canned 'thanks', we was thankful had some followup contact about the issue.
I wont say there is no risk, but I think its the right thing to do and risk seems minimal. And you can always do it anonymously.
I realize that big incidents are probably the only way to get laypeople to care about IT security in the long run, but still it may be preferable to help averting them when possible for various quite practical reasons.
Assuming you have done the hacking anonymously in the first place.
Would they also prosecute a person who told them one of their doors was left unlocked after-hours?
A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops.
EDIT: Is it suspicion? "Hmm...this person found an unlocked door, which means they were clearly trying all the doors. Don't like that. Who knows what else they found but didn't report." Which is understandable, but clearly counter-productive. If the person was a malicious actor, they obviously wouldn't go to the trouble of reporting in the first place.
Then again there is this culture of making an example to discourage others to even try, similar to prison, which we know is not that effective if at all.
I'll also add: when I was a teenager I've been in this position countless times, reporting security issues at school, etc. The reactions I received from fully grown adults was nothing short of stochastic. This fascinated me enough to minor in political science and philosophy/ethics. I draw on that for insight, but it doesn't really provide a final answer.
And multi-billion companies or governments are in the business of bending over customers and effing them. So another guy getting fked is business as usual.
- BKK is the client of T-Systems. They have a contract for the development and maintenance of this system which might contain clauses about liability or indemnification in cases of hacking, security bugs, negligency, etc.
- This guy reported it to BKK who obviously don't have any technical knowledge
- BKK (the client) forwards the email to T-Systems (the contractor): "What's this about? Looks like hacking or something."
- Now T-Systems has two options: 1. Blame it on the guy, or 2. Take the blame for overpromising and screwing it up, possibly taking a financial loss of an unkown amount (depending on the contract and how widespread exploitation was)
It's possible the particular BKK person dealing with the report does not have technical knowledge, but that's more a fail on BKK side as they let incompetent people to deal with reports of security incidents.
But I'd bet it's merely a matter of covering broken shit and shifting blame. BKK is (probably?) a public company, managing transport in the capital city. They manage a lot of money, and it's not uncommon to funnel lucrative contracts to friendly companies, even if it increases price and the quality is dubious. Whoever came up with this project / awarded the contract / accepted the solution is probably scared people might start digging into the details. Better blame the problems on a hacker!
I don't think this is true. When you buy a house, do you have to be able to do the specification and evaluate? This is a good analogy, because T-Systems have delivered similar solutions to other clients, what they needed here is a little bit of tailoring and integration (which is not the part that failed).
I think the hypothetical above is very reasonable. Lots of technical vendors will elect to shift blame. They should take responsibility for their issues, but they often don't.
Perhaps BKK operates in a different way, but well - incompetence is not an excuse. It's a management failure.
To push your analogy further, the non-tech person thinks of this type of exploit discovery as if someone has trespassed onto their private yard in the cover of darkness, trying every door and window.
A tech savvy person might instead think of it as a row of doors lined up next to a busy street, in broad daylight.
Knocking, and telling someone that they have "forgot their keys in the door" seems a bit creepy in the first scenario, but completely legitimate in the second.
Edit: Note that in this analogy the keys aren't fully visible from outside and it requires opening the door to be sure that the keys were accidentally left out
"the sheriff has told everyone that there's a bad dude wandering round town trying doors, and [responsible citizen] noticed that everyone had identical door-keys which would open every lock".
Is that still creepy?
But all kidding aside, It sounds like the sheriff is the hacker. Who has discovered every lock is the exact same through investigation.
That said, a hacker isn't elected to protect people, they are doing it out of the "kindness" of their heart. What a lot of people get in trouble for is hacking first and asking for permission after.
If you go up to a company with a statement like: "I think you may have a vulnerability in your software. I haven't tested this hypothesis (you can verify in your logs), but with your permission, I could check it, and report back to you." Most companies would probably be thankful, others might instead get mad and handle it internally. But if you DON'T hack first, you have nothing to really worry about.
If I logged in to a service and saw an URL like http://example.com/1234/secret_data, calling them with a report of potential vulnerability would be a waste of their and my time 98% of the time. And there's infinite number of such "potential vulnerabilities" to report, too. Like on HN, I see I can edit my profile description over at https://news.ycombinator.com/user?id=TeMPOraL. I wonder what happens when I change the 'id' param? Better not try out, but call 'dang immediately!
Discovering an actual vulnerability in the first place requires doing something that could be considered hacking.
If I caught someone trying their key on my door I would call the cops, even if they said they were just testing it to see if it would work.
Perhaps not, but they probably would be tempted to prosecute someone who opened the door with a toothbrush and told them about it...
The temptation is to squash anything that comes along and potentially makes you look like you weren't doing your job properly (installing a better lock in the first place) rather than thank the person and then install a better lock, or fix the design of the lock.
A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops.
Well, those aren't quite the same thing.
If someone told me I'd left my key in the lock, I'd say thanks and remove the key.
If someone told me I'd left my door unlocked after-hours, I might wonder what they were doing trying my door after-hours in the first place.
I think the line is pretty grey though.
One analogy is telling a company that their front door is unlocked.
Another analogy is going into an unlocked front door, and going deeper into the building, and then reporting to the company that you could, in fact, get to classified information from this door.
IRL Pentesters get permission before trying to sneak into buildings, so there's some argument for it being the same for these sorts of things.
EDIT: I 100% think that users that are acting in good faith shouldn't be thrown in prison. This case is a pretty good example of this
In this situation, it would have been difficult to report the parameter tampering without verifying that it actually worked (there're systems that pass params back and forth without apparent use, but they throw an error when client and server states don't match) - and, most probably, the report would have been ignored without the verification.
If that was tantamount to not-breaking & entering, it means the it is okay to legally forbid step by step debugging on your own computer. That it may not be legal to inspect code from another company, even if it runs on your computer. That whatever the code decides (here, the price of the ticket), must be observed by the rest of the system (here, the price sent in the HTTP request wasn't the price decided by the web page).
The consequences of such thinking are chilling. If this is the kind of cyberpunk we're heading to, I'll seriously consider becoming a Runner.
I don't know about Hungary, but in the US the DMCA has exactly these provisions.
"I have hacked your system, accessed <this information> and modified <that bit of data>, using <this procedure>. You have <this time> to send <this much> Bitcoins to <this wallet>, or I <copy or trash> your database. Thank you for your attention."
Maybe they will panic strongly enough to actually do something about the issue.
It's risky and scary, but also the right thing to do in some cases.
You could also fail to report at all, and let their ship sink. Maybe they deserved it.
From the hacker "hat classification" perspective, that's obviously black hat, nothing gray about it.
From the legal perspective it's not a debate anymore (like in the original article) if you do this, it's clearly a crime, if you get caught in whatever way (e.g. by bragging about it someplace later that leads to your person, or by testing a "discounted" pass in some place that has cameras), it's a straightforward conviction for extortion.
From the ethical perspective, that is an unethical action, doing that shows that the person is immoral.
But you are right, yes, it can be quite effective, and definitely makes it more likely that they will panic strongly enough to actually do something about the issue. It's just that if this happens, then it's not sufficient to just fix the hole, identifying and catching the perpetrator becomes a big part of what they should be doing.
That's as classic as it can be, there's nothing new or technology related about this - for example, sending an anonymous message "Send cash or I'll burn your house" is a crime (and unethical) even if you don't burn anything. It is a crime (and unethical) even if you're just making an empty threat and never intend to burn anything, it still is extortion.
Arson is one crime, and extortion is a separate crime punishable by itself. If you don't attempt to delete their data then you (obviously) don't get charged with deleting their data, but making threats like that is not acceptable in any way (legal or ethical) whatsoever. Once you press "send" on a message like that, you've crossed a very serious line.
Is there a moral imperative that they are morally required to secure their systems and that others should/could demand that they must do so? It definitely could be in certain cases (for example, a hospital storing confidential data of their customers), but in the usual situation where it's just their data and their money, isn't that their moral right to decide how high a fence (if any!) they want to build around their property?
Telling someone "hey, you forgot to lock your door" is a good thing, but ultimately IMHO it's their decision if they want to lock the door or accept those risks.
The process works reasonably well even if the vendor is not cooperative. In that case it is somewhat similar to the message proposed above, but substantially different - first, the threat is not that you'll destroy or publish their data (which is extortion) but that you'll publish your description of the vulnerability (which generally is not); second, the threat is not that you might consider damaging the data (i.e. stating that you'd be willing to do an immoral thing) instead that some other immoral people might damage the data; and third, the disclosure is not conditional on receiving money from them.
I can see that the proposed threat was meant in the same direction, and is somewhat similar to the "threat" implied in general responsible disclosure, i.e., if you don't fix it in 45 days then we'll publish info that most likely will mean that you'll get hacked. But it's substantially different, the details are quite important, and you'd need a good reason to deviate from the standard responsible disclosure guidelines.
I mean, what do you do when after sending a message "I have hacked your system, accessed <this information> and modified <that bit of data>, using <this procedure>. You have <this time> to send <this much> Bitcoins to <this wallet>, or I <copy or trash> your database. Thank you for your attention." you see that they have not fixed the issue but have transferred the requested Bitcoins? It'd be a possible direct result of your actions. Is that a desirable outcome? Is that an ethical outcome?
I do, however loup-vaillant's post also contained the following, which makes it not immoral nor unethical:
> accessed <this information> and modified <that bit of data>, using <this procedure>. You have <this time>
Also, you need to panic them, you do not necessarily need to delete or copy their data (but even if you did, I see nothing evil in it. They are the ones that refused to fix it within the time given after all).
> It's obviously a crime.
Doesn't mean that it's immoral or unethical.
Threatening to harm someone unless they do what you say is immoral even if you don't harm them; it's not ethically acceptable to threaten others.
If your leaving the door open leaves not only you, but others, vulnerable, the discoverer of the broken lock may very well have a moral obligation to protect those innocent people, by whatever means appropriate.
What is appropriate depends on the situation. I expect in most cases, just telling you the door is open may be enough. But if you are being particularly obnoxious, threats may be the only way. In some extreme cases, burning the house down to avoid the disclosure of the sensitive information that would harm countless innocents may be the best course of action.
The legal system even have analogous situations, where a judge can order the orderly destruction of some unsafe building. The only (yet crucial) difference is, judges aren't vigilantes. But this is fixable: one could have the law allow the vigilante to send a cease & desist letter saying "fix your door or I'll have a judge burn your house down".
Perhaps. But being a crime does not automatically mean something is immoral or unethical.
You have <this time> to fix the issue, or I <copy or trash> your database.
Asking for extortion does not push them to fix their systems, only to pay you and/or find you.
http://www.ssi.gouv.fr/en-cas-dincident/vous-souhaitez-decla...
So even technical companies can react in really silly ways.
What isn't cool is legal deciding to go after the party disclosing the vulnerability.
That's because companies routine receive unsolicited product proposals, ideas for new features or enhancements, and the like. Often these overlap with things they have been working on internally but that are not known to the public.
If they let engineers see these unsolicited mails and then later come out with an even vaguely similar feature they may find themselves in an intellectual property dispute with the emailer.
Adobe had him arrested the day after he gave his talk.
Link to a Wired article here: https://www.google.com/amp/s/www.wired.com/2001/07/russian-a...
EDIT: I have a terrible memory-- thanks to the folks who replied to my comment with corrections.
More about the directive: https://en.wikipedia.org/wiki/Copyright_Directive
Actual text of the directive: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:320... (see Chapter III, containing things like "Member States shall provide adequate legal protection against the circumvention of any effective technological measures" and then going on to define "effective" to mean "not necessarily effective")
Some parts have been amended (for example, copyright duration has been expanded from 50 to 70 years after death), but I believe the anti-circumvention parts to be unchanged. I'm not sure how to find up-to-date codified versions of EU laws, though.
I was there!
The FBI arrested him in a hallway, 1 day after his talk. Dmitry at first thought it was a joke put on by a Defcon prankster.
During his talk, the panel moderator asked Dmitry to pause for a minute... and said "Would you mind saying 'Can you tell me where are the nuclear vessels in Alameda'?" Dmitry was confused by this request and said, in his Russian accent, "I do not know where the nuclear wessels are in Alameda?" The mostly American Trek-familiar audience had a good laugh, and Dmitry continued with his talk.
They offered a demo which I used to navigate around, in the demo was a reporting tool which essentially allowed you to send raw SQL queries to an AJAX endpoint. Something along the lines of:
http://demosoftware.com/reports/ajax.php?sql=SELECT * FROM debts
I switched out the demo software domain name for the live version and it worked, not only could I query the database there was no authentication preventing me hitting this end point.
At this point I was left with a dilemma, do I "erase" my debt, do I disclose the bug and pay the debt, or simply pay the debt and move on. I chose to pay the debt and move on due to fear of any recriminations. However it has left me uneasy ever since knowing that this company have such bad security and any debtors they are chasing for payments potentially will have all of their personal data leaked.
https://www.youtube.com/watch?v=eQ2OZKitRwc
A talk on how Tor users got caught. In a nutshell: it wasn't Tor's fault, but bad OPSEC on the part of the users.
Apart from being a federal crime (CFAA), it would be rather obvious by the logs that a user was testing SQL injection on the demo system minutes before the production system was vandalised.
A better option would be to pay the debt, and then let them know you found a potential issue on their demo system. Let them connect the dots between demo system and production system. If they can't make the logical leap, then they deserve whatever someone else does.
I'm not arguing against paying the debt - I would pay it in either case. However leaving such a vulnerability exposed is so bad they deserve to get their entire database dropped (and in this case I hope they don't have backups).
I understand the feeling here, but no, they don't deserve to get their assets destroyed because of a lack of care.`
You can't just destroy someone else's property because you have some personal anarchist notion of justice.
If they are really being negligent then they should face the proper penalties.
Dropping the DB means there's no more PII to leak, makes a pretty good financial penalty for the company and doesn't make millions for useless lawyers. That sounds like an acceptable solution by my standards.
Public disclosure because everybody should know about something like this that may impact them. Not because some random vigilante will see it and drop their DB for which they probably have no backups.
I've reported several of these issues, sometimes all I get is single reply months later saying: "fixed".. mostly, nothing.
Once I found a SQL injection in a courier service's (very broken) web portal. This was very serious because any idiot could drop all the tables, so I sent an email to the most important worded member of their tiny, yet already bureaucratically structured team. I followed up several times because I knew someone saw my email (I embed beacons in my emails) but gave up after the sixth time. Three months later someone else replied saying "thanks Amin, we've fixed it"
On a separate occasion, a large government agency's emails routinely ended up in my spam folder. It was a huge problem, and they acknowledged it and said they couldn't figure out what was wrong. I took five minutes and found the problem to be a misconfigured server on the domain. The server sending the email thought it was `server-a.governmentdomain.com` but there were no DNS entries pointing the subdomain to the server. I reported this problem with clear instructions to test and fix the issue, but I was called despite the instructions, multiple times, to explain the issue with my words over the phone. This was 2 years ago, last I checked, the issue was still present.
That aside, Streak.com's beacons work even in Gsuite readers! They're awesome. It's essentially just a unique image included in the email body.
First, when testing whether you can change a price and have a transaction go through successfully, RAISE THE PRICE. If you lower the price the affected entity may come back and say "See??? He's STEALING from us! Lock him up!" If you've overpaid for something through their web interface that complaint and issue goes completely away.
Second, if you're going to suggest that they contact you for assistance in fixing it also suggest other options. My typical handling for this is with hacked websites, so I'll basically say "Your website has problems X, Y and Z. You should work with whoever you have working on your site to resolve these. If you don't have anyone I may be able to assist you, or I recommend talking with a firm like Sucuri.net which has dealing with and preventing issues like this as their primary business. (My only link with Sucuri is having seen some of their folks do presentations at trade shows.)"
Or it doesn't, because you have still "hacked them". Doing it in a seemingly bizarre way may only raise more suspicions; obviously you must have maliciously cheated them, since who would give them money?
Please don't put people at risk by giving such "advice".
Code:
var db = document.body;document.onscroll = function(){db.style.transform = 'scaleY(1)'; db.style.transform = 'scaleY('+db.scrollHeight / (db.scrollHeight - db.scrollTop)+')'}- Firefox 54.0.1 (64-bit)
- Arch Linux 4.11.5-1-ARCH
In both cases, it was dads of children in the institution that noticed the bugs when they were rightfully using the system and were ignored when notifying the responsible party about it until they "shouted it so loudly" that they couldn't be ignored anymore, in which case they were reported to the police for hacking.
Links below are in danish, but they can probably be translated if needed.
1: https://www.version2.dk/artikel/boernehavehackeren-frifundet...
2: https://www.version2.dk/artikel/interview-hacker-tiltalt-jeg...
In the old days, protesters used to physically go and picket in front of company offices. These days, protesters leave one-star reviews. I wonder which is more effective.
And actually there will be a protest in front of the office of the Public Transport Authority tomorrow. But I think in this case, the online petitioning worked pretty well.
I thought that Hungary has a democratically elected government. Did I miss something?
The very definition of election means aristocracy. To have a democracy it requires sortition instead.
Much of it focuses on the treatment of refugees, but you'll also find information about the suppression of free speech and the like. A "democratically elected government" in a country where the opposition is suppressed is not that democratically elected after all.
<tinfoil>Financier and philanthropist George Soros of the Open Society Foundation announced in 2010 his intention to grant US $100 million to HRW over a period of ten years to help it expand its efforts internationally.</tinfoil>
Ah, I see. Presumably he also finances...
Freedom House: https://freedomhouse.org/report/freedom-press/2015/hungary
The International Press Institute: https://ipi.media/civil-defamation-and-media-freedom-in-hung...
The New York Times: https://www.nytimes.com/2014/09/09/opinion/hungarys-crackdow...
The US government: https://hu.usembassy.gov/hungary-media-freedom-press-stateme...
The LA Times: http://www.latimes.com/world/europe/la-fg-hungary-media-free...
Hitler was democratically elected as well, that is not sufficient to label his regime as democracy.
No he wasn't, it is not that simple. His party at that time had no majority despite being the largest one. He got appointed chancellor not by democratic vote but by backroom negotiations - mostly because he was expected to be easy to control.
From this state he went for the dictatorship but again not by democratic election but rather by scaring the other parties into voting him the Enabling Act in 1933 after the supposedly communist-inspired Reichstag Fire.
But if you don't like that, here's a short excerpt from Wikipedia: "No consensus exists on how to define democracy, but legal equality, political freedom and rule of law have been identified as important characteristics."[1]
We don't have any of these. Or, to put it in an easier to digest way: all of these have been regularly (and increasingly) violated by the govt.
As probably a fellow Hungarian who likes (is emotionally attached to) this government, I understand you are OK with it, but it doesn't make the current system any more democratic. Fun fact: the Kadar system called itself democratic too. But it's judged from the outside, for obvious reasons.
[1]: https://en.wikipedia.org/wiki/Democracy#Characteristics
At some point we need to understand the novlang used here, by squatting the word democracy to label the political system based on elections, people in power manage to prevent to emergence of an actual democracy.
Please stop misusing this word so we have a better chance of actually having a democracy somwhere at some point in the future.
There may be better ways of doing things but it doesn't make democracies not democracies.
From a technical perspective, this is clearly untrue.
It's impossible if you take “every issue” literally, as you are multiplying the number of pdecisions that must be made by each participant per unit of time so much that the time to consider them is non-existent.
It's less impossible if you reduce it to the kind of decisions typically made by a legislature, which mainly just sets rules for executive and judicial officials to apply in deciding more specific issues.
But even then it's of dubious practicality; obviously not every citizen can have a full-time legislative staff, and most of other things besides legislation to devote their time to.
Please stop promoting democracy as the be-all end-all of systems for organizing human society. As the old saw goes "Democracy is two wolves and a lamb voting on what to have for dinner. Liberty is a well armed sheep contesting the outcome".
Also there seems to be some irl protesting going on as well, at least in this case.
When the story made it to Slashdot's front page, it had ~46k 1-start reviews and a few hundred ratings in the 2-5 stars range.
Methinks whoever is in charge of company reviews at BKK is despairing right now. Unless they somehow convince FB to drop the recent cohort of 1-star ratings (which will almost certainly yield a Streisand effect) and keep a low profile for a very long time before allowing star ratings again, there's simply no way the BKK will rescue the rating.
It's unfortunate for the BKK and its staff. The quality of their service and vehicles is good overall and the staff is friendly. It's admittedly not 5-star grade, but it's certainly not 1-star material either. Yet this sequence of event might haunt them for years.
Unless the company concerned has a well documented and trusted bug bounty procedure, it can be very risky to report a bug in a system, if it involves any kind of hacking.
What happens is once the "bug" is reported, someone inside the company asks "How did this happen?". Now the person responsible has 2 options, admit it was their fault and the vulnerability exists and risk being accused of incompetence, or say that the system was hacked.
Human nature being what it is, one tends to complain of being hacked, thus snow-balling effects, which lead to the arrest of an 18 year old just trying to help.
My advice: Don't report these types of bugs at all, or if you really feel you must, report anonymously.
"There was nothing I could do boss! He's a hacker!"
s/stupid/trusting/. There's no reason to think this guy isn't bright, and he's faced enough trouble without piling on.
Also, if such behaviour is systemic, how should we bring about the paradigm shift in handling such events? Such incidents will happen more often across the world as e-governance becomes more predominant.
1 - https://thewire.in/119578/aadhaar-sting-uidai-files-fir-jour...
The public procurement process for the current system called RIGO was indeed 2013 but the whole process is much, much older than that. A more than 300 page feasibility study was published in 2011 https://www.bkk.hu/apps/docs/megvalosithatosagi_vizsgalat.pd... And a completely different system, called Elektra was announced in 2004 with a 2006 deadline.
This whole clusterfuck with RIGO starting in less than a year was absolutely unnecessary since the 2011 study already suggested supporting contactless credit cards so once RIGO starts the only ones using this online ticket purchasing system will be those who have a credit card but not a contactless one. This is a (very) rapidly shrinking audience.
And this software was written by a professional contractor - pretty sure you'd get better quality from a kid fresh out of university, because on my course, it was drilled into me - NEVER TRUST THE CLIENT BROWSER!
Companies need to understand, if they want an internet presence, no matter how strong the laws are in their own country, laws don't stop a crime in progress, especially when all they need to do is send a fairly simple message to the website. Computers are dumb, they do what they're told. Giving anyone the loophole to tell them to do something you didn't intend is asking to have it exploited.
Going after the messenger will solve nothing. The guy who discovered the payment flaw could easily have kept quiet, letting others discover it, or quietly told his friends, who tell their friends, ad infinitum, and suddenly the whole country is buying valid passes for a penny, costing the company a hideous amount of money. Prosecuting the whistleblower will actually hurt their bottom line.
Isn't it mostly in multiplayer game programming where this gets said over and over "Never trust the game client" even though it should be said in all aspects of programming really
Also, a question: does the EU have the legal concept of "fair use" ? I would have thought that messing around with a web application would fall under fair use, given that the web application can, and probably will, be stored on a person's computer. A computer that they (also probably) personally own, I might add...
Someone's going to probe your system; you should be glad to hear about it in email rather than in the news or your accountants or from angry customers.
Wtf ,I thought I was bad at my job.
I'd really like to know which of these is the better solution.
It seems to me that if people go to the http address, they could be redirected to an attacker's address with a simple MITM attack. So there's an argument to be made for not using http at all, even for a legitimate redirect, because it can be so easily MITM'ed.
On the other hand, if the http address is left unused, then people who try it anyway and it fails will be confused. For this solution to work, it seems the users have to be educated to always and only use the https address.
For these reasons, the whole separate http/https scheme seems broken by design.
What's the consensus from the security community as to the right setup here? Am I missing something, or is there a better way?
Firefox have some scripts which go through and check to make sure everything still on the Chrome list is still announcing the preload headers, and will autoremove if that isn't that case, IIRC. I wouldn't be too shocked if Apple/Microsoft were doing something similar.
Is there any documentation for these browsers that officially say exactly what they're doing and how their preload lists are generated?
https://wiki.mozilla.org/SecurityEngineering/HTTP_Strict_Tra...
But before that happens, if the user always goes to the http address and it works for them (whether by legitimate redirect or by the legitimate site simply supporting http) it lulls them in to a false sense of security, and a belief that going to the http address is ok.
So the idea behind having the http address be broken from the start is to make the users see that the address they're trying is broken, and therefore the wrong one for them to use. Hopefully at that point they'll investigate why (perhaps complaining or talking to their sysadmin, if they have one), and be straightened out by someone providing the https link to them (or the more tech-savvy users like the OP figuring it out for themselves).
edit: a few weeks ago, not this past summer that is still occurring
About the security (or rather the extremely low quality) of the eTicket system: that was developed by a 3rd party that belongs to the Deutsche Telekom group, and that company is indeed quite a high profile system integrator working with a lot of large companies, banks, etc. So it's a bit of surprising (even if corruption is involved) that they released it in this form. Actually I'm surprised by these bugs even for a prototype that was forcefully pushed out of the door, because you just never do these things in the first place.
Age seems like a bit of a red herring to me. Here in San Francisco BART cars are about that old, Muni runs 90 year old Italian trams and American ones that are close to 70 years old. And, of course, the cable cars. BART bears about the worst of it because many parts are no longer available.
They are in such a bad shape and/or hard to rebuild that not much remains of the original during the refurbishment.
The Russians didn't magically win the tender, i think it was realpolitik. They manufactured them originally in the first place, they have the means to do the work, and without knowing if the proposals were technically equivalent, Hungary needs to maintain a good relation not only to its neighbors, and fellow EU members, but to Moscow.
Also the trains are not in a worse working condition than the Siemens Combino trams or the Siemens and Alstom technology at Metro 4 line, which also had integration problems during the first months of operation. The problems will be addressed by the russian firm as well as as the western firms addressed those problems.
Maintaining good relationships with the Russians wasn't part of it, of course. We'll pay them enough for Pask2 (awarded without tendering). But even if not, because enough does not exist, more is always better, if this is the price of a 'good relationship' then we already have a bad relationship with them. I.e. they are blackmailing us. (Of course, it's not the case, but they are probably more willing to pay back than the Estonians...)
No, these problems are not like other problems, though Siemens and Alstrom were also both involved in corruption cases (I mean outside of Hungary), these are more serious and didn't happen with the others. It's not simply only integration problems.
The metro system is owned by the city, and ultimately the government. With all its problems, it is still not a mafia.
Although you are in a different part of the world, but when visiting the poor and backwards Eastern Europe, please use your common sense, or at least do some fact check.
Lets not pretend that the tenders made by the BKK is any more lawful or fair than the rest of the tenders that dominate the market around here.
https://www.cambridge.org/core/journals/perspectives-on-poli...
That is what I've meant by saying "basically own" - you can do whatever you want with company and you can't be held responsible for any of your actions.
And that's not just some imaginary scheme - that shit happens on daily basis in most of Eastern Europe countries. I'm from Ukraine and we're trying to fight that shit for several years now.
Turns out there are just a lot of incompetent people.
Because we elected them based on their skills in lying rather than governance. And also because government jobs naturally attract and promote incompetence.
Or, the managers knew full well the system was shit and they had no time to fix it, but 80k/month is 80k/month.
>BKK pays T-Systems 80kEUR/month to operate this system.
If you were offered that, would you turn it down because you can't actually deliver a secure system in time?
a rabbit was detained by the secret police. the interrogator asks him, "what are you?" the rabbit says, "rabbit"
They torture, beat, and electrocute him for days.
Then, the interrogator asks him, "who told you you're a rabbit?"
They had a form you could try the demo where it sent an SMS to verify and only allowed one query.
If you looked at the source of the page it had hidden fields to override the SMS verification and allow multiple queries.
I freaked out some friends for the day and nearly contacted a journalist but lost interest after some weeks.
I could have had my 15 minutes of fame or be on some list, or both.
It's alright, had some fun.
Moreover, it is not only Hungarian but also European law to report incidents involving personally identifiable information leaks and there are authorities that investigate and fine companies failing to comply with the law. Any person (including you) can report such companies to authorities.
But ofc I got your point.
I understand that you are experienced in law, I understand what you wrote. Although, I do not think that it was the right thing to do. And maybe because of the reactions and the scandal, it will change in the future.
Would not have happened anything if we had just ignored this. We did the right thing.
Sorry but how exactly electing a different party is supposed to change anything ? Moving to another country will not help either as most other countries are the same or worse.
> In Hungary, according to the law, this was pretty much illegal.
Ho-humm. Care to point where the Hungarian law mandates this? The old BTK was simpler but even the new is pretty clear in that only a very few serious acts are mandatory to report (meaning not reporting is a felony in itself). 145. and 159 § details how military and civil superiors must report the crimes of those under them, obviously does not apply. 191. § makes reporting attempted or committed kidnapping mandatory. 263. § are crimes against the state, treason, spying and shit. 300. § makes it a crime not to report corruption but only for officials. 317. § makes terrorism mandatory to report. 328. § is about violating international sanctions. Finally 404. § makes reporting of certain financial trickery but only for the actual executor of the bankruptcy.
Which one was this one? Or did I miss something? Was he trying to sell stuff to Russia violating the sanctions? Did he make an attempt to overthrow the government? Or what?
and Hungarian law -> this is how they did it
European law about data protection and breaches, not sure if it is in effect yet and not sure if it applies to this exact case:
http://www.lexology.com/library/detail.aspx?g=8185429b-c98d-...
Have a look at this list, many of them thought they are not doing anything wrong:
https://en.wikipedia.org/wiki/List_of_computer_criminals
The point is that we live by the law, not how you feel about a certain action. I agree that the law is a bit problematic but regardless we cannot cherrypick which law to follow and which not.
Besides this has been used for decades by corps to prosecute vulnerability reporters, see Serge Humpich who discovered a huge vulnerabilty in bank cards back in 1997. He reported to european bank card Economic Interest Group (EIG) with the support of a lawyer who said they would not believe him until he proved it practically. So he went an bought metro tickets that he did not use but sent them with every details of the transaction. The EIG then got him arrested, prosecuted and sentenced for bank fraud and falsifying a bank card. The fun part is that this got publicized and it was not long before bad guys found the vulnerability too and started issuing yescards (bank card that say yes to any withdrawal from an ATM) and it cost them many tens of billions of euros over a few years due to fraud and upgrading their security and hardware in a hurry.
ahh Budapest.
:-)
Better late than never...
(I had completely forgotten IoT)
What should have been done was the second he had the thought that such a vulnerability could exist, he should have notified them that he believes that there is a possibility for one to alter the site code locally to gain unfair pricing, and to ask them if either he could check for them or if they could check using his proposed method.
The second you actually test without permission, you've committed a crime. Jury/court might look at intent later on, but for now, you've committed a crime and are thus subject to arrest.
Do you report every site that uses HTML forms for being insecure?
My parents went to buy a ticket at the counter. The lady behind the counter didn't speak English (which is totally OK). Her only communication was a 'go away' movement with her hand, after which she ignore us and signaled for the next customer in line to come to her.
Luckily a colleague of her helped us and gave us careful instruction on the time and platform of the train. After we took the train and sat for a few hours, the conductor of the train came and notified that our tickets were invalid. We argued for some time since the lady behind the counter told us this was the right train. The conductor became mad and told us that we had to pay him 50 euros in cash for some unknown reason (presumably to buy a ticket for the train we were on, but his English was very limited). Note that this was a normal train and there was no shortage of seats. In the end, we chose to get out at the next stop, and take the next train, which was about 3 hours later.