Live data from Hacker News

We tried to book a train ticket and ended up with a 245k records data breach

zerforschung.org

21–30 of 83 posts

Re: We tried to book a train ticket and ended up with a 245k records data breach

#21
post #16
post #6

Earlier quoted context omitted.

[flagged]

Because private companies like Microsoft, British Airways, T-Mobile, Equifax never make amateur mistakes in cyber security.

Hey, only one of those is a true tech company. The others are failing legacy comoanies, former government owned ones, that just don't get tech / software. And Ms is, well, MS. /s

Re: We tried to book a train ticket and ended up with a 245k records data breach

#22
post #20
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It’s not WW2 mobilisation but I’ve always thought the UK’s Government Digital Service is a wonderful example of what government can achieve in tech:

https://www.gov.uk/government/organisations/government-digit...

As I understand it they’re effectively a central dev shop for other government agencies. It’s worth their time investing in good practises because they’re going to use them over and over again. And from the user perspective you get a very consistent, reliable set of tools for interacting with government. A win win in my book.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#23
post #15
post #2

Completely shambolic schoolboy errors!

Large, state-backed, entities that predate the internet seem to get away with stuff of this kind all the time. The other day my mother tried to buy a train ticket. The payment went through, but something went wrong on the site and the ticket was not issued. If this were just some e-commerce site, the payment provider would have had their head on a spike. In this case she had to go through the usual return process.

In this case, it looks like the private company which did the work is also getting away with it...

https://www.caracal.agency/en/projects/discover-eu

Re: We tried to book a train ticket and ended up with a 245k records data breach

#24
post #4

The sad thing is I don't see the public sector getting any better at this anytime soon.

Worse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#25
post #6
post #2

Completely shambolic schoolboy errors!

[flagged]

I thought the project was implemented by private agencies? Article says MCI and Caracal.

Isn't that supposed to be how the government gets the best results with the greatest efficiency under neoliberal capitalism? Subcontract the private sector to do it. They have the expertise to know what they're doing and avoid obvious errors, which would not be the case if the government did it themselves?

Re: We tried to book a train ticket and ended up with a 245k records data breach

#26

Stuff like this is why I prefer to take a bus in Germany. Trains are overbooked with free tickets and promotions (free pass for entire summer for 50 euro). While underlying infrastructure is not ready for such load. It leads to delays and mistakes. Plus railway stations in Germany look like homeless shelters! On other side Germany has excellent motorway network. Flixbus is very cheap, quite comfortable, goes all the…

The 50eur pass doesn't include the trains you'd use for the trips you'd use Flixbus for.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#27
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

It's a fallacy to believe that all projects are just sold to the lowest bidder.

There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief.

If a project is too expensive for a client to do well, they should not be doing that work in the first place.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#28
Made me think about this podcast I listened to the other day: https://www.nytimes.com/2023/06/06/opinion/ezra-klein-podcas...

In it Jennifer Pahlka, a high ranking US government official who worked on heathcare.gov and other digital government projects, talks about her book that is about why most of these projects go as poorly as they do. Quite illuminating...

Re: We tried to book a train ticket and ended up with a 245k records data breach

#29
post #22
post #20

Earlier quoted context omitted.

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It’s not WW2 mobilisation but I’ve always thought the UK’s Government Digital Service is a wonderful example of what government can achieve in tech: https://www.gov.uk/government/organisations/government-digit... As I understand it they’re effectively a central dev shop for other government agencies. It’s worth their time investing in good practises because they’re going to use them over and over again. And from the…

This is something we desperately need more of in other countries. We've found something like a dozen breaches of similar severity in the last 6 years and they all came from systems developed through public tenders by companies that either aggressively under-priced or used other (legal or illegal) dirty tactics to win them. The very few things that were developed in-house have proven to be far more reliable and secure, not to mention developing them was far cheaper and the UX is better and more consistent between them.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#30
Lots of people complaining about state-run projects or suppliers who do stuff on the cheap but I think the simple fact is that in most people's minds, buying a "IT system" is like buying a car except that the car is built from scratch each time even though the customer wants off-the-shelf prices.

How many applications do we create that all do exactly the same thing? Payments, customer details, tasks, shopping baskets, items for sale etc. and how many times have we rebuilt all of that from the ground up with all the risks? Even if we know what we are doing, it is easy enough to forget something, for someone who didn't know what they were doing to build part of it, to cost enormous money to plumb together a tonne of bespoke parts.

I think the solution is 1) We need much better regulation of who has the relevant skills to do work to the required standard, we still allow untrained and unqualified people to build banking apps etc. 2) We need to create something that allows us to possibly certify implementations of standard functionality so they can be used to create standard applications, just like Peugeot might buy engines from Toyota that they know already work.

We talk about freedom of thought and creativity but the price of reliable and trustworthy software is probably only going to come by establishing a much higher level of quality - hopefully minus some of the BS you get with some accreditations.

Post reply on HN