Live data from Hacker News

We tried to book a train ticket and ended up with a 245k records data breach

zerforschung.org

31–40 of 83 posts

Re: We tried to book a train ticket and ended up with a 245k records data breach

#31
post #20
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It's a shame that (from my perspective anyway) a lot of that state capacity seems to have degassed for the NHS. Right now it's impossible to get a doctor's appointment where I live. If you call any local surgery within a split second of 8:00am then you have a very low chance of getting an appointment, every time I've tried the line's busy or I'm number 60 in the queue and after a 40 minute wait all the appointments are gone. They are also fully booked for advance appointments every day (they limit the time in advance you can book, probably to prevent having e.g. a 2 year wait time on appointments, because it 'looks better' if nobody can go than if there's literally a 2 year advance appointment wait).

The only way to see a doctor is to go to A&E, or convince NHS 111 to give you an "emergency appointment" of some kind. All of this drains emergency resources and are not an option due to the time investment for average people with precarious employment.

Unfortunately many people won't believe these facts, because depending on which area you live in there's always plentiful appointments, in advance or on the day! Where I last lived, getting an appointment was easy, the difference in outcomes based on how wealthy or urban your area is leaves a bad taste in my mouth.

Briefly, we had a new surgery open that offered more appointments, at more convenient times of day, and we could actually see the doctor. All the other GP's started losing their patients to them. Then within a few months they were shut down by the local NHS trust, under multiple investigations (one of these investigations was regarding an offensive Facebook post by the surgery's chief, I kid you not). They then later reopened with normal appointment times and no free spaces, like all the other surgeries.

I agree with what you say re the command economy of WW2 allowing the creation of the NHS. But it was not this country that founded the NHS: it is some ancient, lost nation that seems utterly alien to me today. I don't believe we could achieve even a small version of what WW2 Britain did anymore, if our survival depended on it. I cite the UK's response to COVID19 as evidence.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#32
post #30

Lots of people complaining about state-run projects or suppliers who do stuff on the cheap but I think the simple fact is that in most people's minds, buying a "IT system" is like buying a car except that the car is built from scratch each time even though the customer wants off-the-shelf prices. How many applications do we create that all do exactly the same thing? Payments, customer details, tasks, shopping baskets…

It's a lot like building houses. Lots of manual processing and making the standard formula fit the specific application.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#33
post #4

The sad thing is I don't see the public sector getting any better at this anytime soon.

Worse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.

They don't just accept the lowest bid. It's the lowest bid that complies with the requirements. You can tighten up the requirements and conditions.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#34
post #17

Stuff like this is why I prefer to take a bus in Germany. Trains are overbooked with free tickets and promotions (free pass for entire summer for 50 euro). While underlying infrastructure is not ready for such load. It leads to delays and mistakes. Plus railway stations in Germany look like homeless shelters! On other side Germany has excellent motorway network. Flixbus is very cheap, quite comfortable, goes all the…

Let's see. Cologne to Berlin takes ~4:40 hours by train. Flixbus takes 9-10 hours, not counting the time it takes to get to their departure station which would involve a train journey as it's not actually in the city centre. Flixbus is 50€ cheaper when traveling that route tomorrow but that's about all it has going for it.

1 hour by plane (+ time hanging around the airport, but train/bus has the same issue there)

Re: We tried to book a train ticket and ended up with a 245k records data breach

#35
post #31
post #20

Earlier quoted context omitted.

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It's a shame that (from my perspective anyway) a lot of that state capacity seems to have degassed for the NHS. Right now it's impossible to get a doctor's appointment where I live. If you call any local surgery within a split second of 8:00am then you have a very low chance of getting an appointment, every time I've tried the line's busy or I'm number 60 in the queue and after a 40 minute wait all the appointments a…

Same as in the US -- right wing politicians who believe the state is bad at doing things remove the funding that allowed the state to do it. Then when that means those government provided services become worse, they use that to show that the state is bad at doing those things, and therefore even less funding should go there, et cetera.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#36
post #27
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

Its actually probably more of a situation that a client cant discern quality. Its impossible to tell if the most expensive or least expensive if the best option. How does a non technical/semi technical actually grade this stuff appropriately?

Re: We tried to book a train ticket and ended up with a 245k records data breach

#37
post #31
post #20

Earlier quoted context omitted.

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It's a shame that (from my perspective anyway) a lot of that state capacity seems to have degassed for the NHS. Right now it's impossible to get a doctor's appointment where I live. If you call any local surgery within a split second of 8:00am then you have a very low chance of getting an appointment, every time I've tried the line's busy or I'm number 60 in the queue and after a 40 minute wait all the appointments a…

This mirrors my exact experience with the NHS – the futile 8am phone calls, to relying on NHS 111 for any hope at getting medical attention.

Coming from Australia and previously NZ, the healthcare system here seems barbaric.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#38
post #27
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

You are right of course, I was just theatrically Exaggerating.

If we assume there is no corruption involved, then lack of competence from the project management side can fail such a project. For this example it could be failing to mention or think about the extra load on the first hours in the SOA

Re: We tried to book a train ticket and ended up with a 245k records data breach

#39
post #17

Earlier quoted context omitted.

Let's see. Cologne to Berlin takes ~4:40 hours by train. Flixbus takes 9-10 hours, not counting the time it takes to get to their departure station which would involve a train journey as it's not actually in the city centre. Flixbus is 50€ cheaper when traveling that route tomorrow but that's about all it has going for it.

1 hour by plane (+ time hanging around the airport, but train/bus has the same issue there)

Train and bus normally have that “10-20 minutes ahead” planning to be at the station.

Planes? At least an hour, and if you cut into that, and the queues or security theatre more mind boggling than normal, you’ve missed your flights.

Eurostar is similar to airports, so I’m glowering at them too!

Re: We tried to book a train ticket and ended up with a 245k records data breach

#40
post #36
post #27

Earlier quoted context omitted.

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

Its actually probably more of a situation that a client cant discern quality. Its impossible to tell if the most expensive or least expensive if the best option. How does a non technical/semi technical actually grade this stuff appropriately?

This is a problem traditionally solved by the professional engineering licensing system. Most engineering curriculum in the USA involve an Engineering Ethics course that goes over such issues.

We're quite far from implementing such a system for software "engineers".

Post reply on HN