Live data from Hacker News

We tried to book a train ticket and ended up with a 245k records data breach

zerforschung.org

41–50 of 83 posts

Re: We tried to book a train ticket and ended up with a 245k records data breach

#41
post #4

The sad thing is I don't see the public sector getting any better at this anytime soon.

Worse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.

I can tell you for the procurement that I had anything to do with at a UK school, though for projects above a certain cost floor three or more quotes were required, I advised NOT taking the cheapest nor most expensive bids unless there was a specific good reason...

Re: We tried to book a train ticket and ended up with a 245k records data breach

#44

Earlier quoted context omitted.

Worse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.

They don't just accept the lowest bid. It's the lowest bid that complies with the requirements . You can tighten up the requirements and conditions.

You can also consider the demonstrated qualifications/competency of the bidder. I could submit a low bid for a project and if I have no history of ever completing similar projects my bid can be rejected on that basis.

However (at least in the few governemnt bids I've been involved in) if the low bidder does not get the award, they can challenge the award and often do. Then the government has to defend their decision and give the reasons the low bid was disqualified.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#45
post #40
post #36

Earlier quoted context omitted.

Its actually probably more of a situation that a client cant discern quality. Its impossible to tell if the most expensive or least expensive if the best option. How does a non technical/semi technical actually grade this stuff appropriately?

This is a problem traditionally solved by the professional engineering licensing system. Most engineering curriculum in the USA involve an Engineering Ethics course that goes over such issues. We're quite far from implementing such a system for software "engineers".

Just hire pentesters along with the development team. Make sure they are not affiliates. You can put in contract that as long as security issues are present they need to fix them before getting paid, which seems like a reasonable expectation. Even the best make mistakes, so let's at least leave those which are not trivial.

We don't trust building ethics, independent inspector comes and checks if everything is as it should be before it can be used by the public.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#46
post #27
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

If my company is anything like the others, its very rarely the lowest bidder who wins at all.

Usually there is some sort of RFI process, where they ask a few companies 'hey can you build this for us? What are the types of services you would propose'. The list of companies here is already more or less pre-existing partnerships, or ex colleagues or...

(it mostly always contains Microsoft, and your boss is ex Accenture, so it involves Accenture, and for good measure to seem like they are open to other options they invite Deloitte and some other players as well, sometimes even IBM has joined the club again)

Then they decide who they deem thrustworthy, and you end up with Microsoft and (insert boss previous employer). So not only do you not get the lowest bidder, you can some veeerrryyy generic company that doesn't care and just sends juniors to solve it. This process is called the RFP. And it typically is far from neutral

Re: We tried to book a train ticket and ended up with a 245k records data breach

#47
post #36
post #27

Earlier quoted context omitted.

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

Its actually probably more of a situation that a client cant discern quality. Its impossible to tell if the most expensive or least expensive if the best option. How does a non technical/semi technical actually grade this stuff appropriately?

Hire independent consultants with software experience to work on an hourly basis to write portions of the RFP and evaluate the responses. There is a niche industry of experts who help buyers with this stuff. Of course, if the customer is totally ignorant about software then it can be difficult to know which consultants to trust but generally they can ask around industry circles and check references.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#48
post #30

Lots of people complaining about state-run projects or suppliers who do stuff on the cheap but I think the simple fact is that in most people's minds, buying a "IT system" is like buying a car except that the car is built from scratch each time even though the customer wants off-the-shelf prices. How many applications do we create that all do exactly the same thing? Payments, customer details, tasks, shopping baskets…

It appears as though you are merely rehashing the realm of SAAS and, to compound matters, the labyrinthine government contracting procedure.

The market already boasts software solutions that are more or less ready-made, precisely catering to your described needs, particularly concerning areas like payments.

However, governmental entities abstain from employing such software, as their provider selection process deliberately embraces a convoluted nature to sidestep any hint of impropriety.

Thus, the government contracting industry flourishes—a cohort proficient in maneuvering through the intricate channels of governmental procurement. Most private enterprises that excel in providing top-tier services opt out of engaging in this government contracting labyrinth because it's not worth the headache. It involves an assortment of antiquated procedures and certifications that the private sector seldom finds worthwhile to partake in, as they exclusively pertain to the realm of government contracting and are often accompanied by a disheartening degree of bureaucratic rigmarole.

Deciphering a pathway towards resolving this predicament would transcend the mere realm of overhauling regulations; rather, it necessitates the overhaul of modern bureaucracy and solving the arduous struggle government faces to keep pace with fast-evolving fields like technology.

Basically: Good luck with that!

Re: We tried to book a train ticket and ended up with a 245k records data breach

#49
post #27
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

Yeah, there is probably some minority/equity politics that is giving the contracts to totally incompetent people that have the right gender claims or have the right skin colour.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#50
post #39

Earlier quoted context omitted.

1 hour by plane (+ time hanging around the airport, but train/bus has the same issue there)

Train and bus normally have that “10-20 minutes ahead” planning to be at the station. Planes? At least an hour, and if you cut into that, and the queues or security theatre more mind boggling than normal, you’ve missed your flights. Eurostar is similar to airports, so I’m glowering at them too!

Even if you aren't at the airport that early, it still takes you an hour to get from the airport to the city centre in Berlin, and about half an hour to get to the airport from Cologne's city centre. That's by train, by car it takes even longer.
Post reply on HN