Live data from Hacker News

We tried to book a train ticket and ended up with a 245k records data breach

zerforschung.org

51–60 of 83 posts

Re: We tried to book a train ticket and ended up with a 245k records data breach

#52
post #39

Earlier quoted context omitted.

1 hour by plane (+ time hanging around the airport, but train/bus has the same issue there)

Train and bus normally have that “10-20 minutes ahead” planning to be at the station. Planes? At least an hour, and if you cut into that, and the queues or security theatre more mind boggling than normal, you’ve missed your flights. Eurostar is similar to airports, so I’m glowering at them too!

Also no time at all when arriving. Getting out of a train and the station rarely takes more than five minutes; usually less.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#53
post #28

Made me think about this podcast I listened to the other day: https://www.nytimes.com/2023/06/06/opinion/ezra-klein-podcas... In it Jennifer Pahlka, a high ranking US government official who worked on heathcare.gov and other digital government projects, talks about her book that is about why most of these projects go as poorly as they do. Quite illuminating...

Came here to mention that episode. Agree that it was very insightful. Transcript:

https://pastebin.com/Lg7zfHd9

Re: We tried to book a train ticket and ended up with a 245k records data breach

#54
post #4

The sad thing is I don't see the public sector getting any better at this anytime soon.

Worse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.

It's supposed to limit corruption by making it harder to give contracts as political favors

Re: We tried to book a train ticket and ended up with a 245k records data breach

#55
post #50
post #39

Earlier quoted context omitted.

Train and bus normally have that “10-20 minutes ahead” planning to be at the station. Planes? At least an hour, and if you cut into that, and the queues or security theatre more mind boggling than normal, you’ve missed your flights. Eurostar is similar to airports, so I’m glowering at them too!

Even if you aren't at the airport that early, it still takes you an hour to get from the airport to the city centre in Berlin, and about half an hour to get to the airport from Cologne's city centre. That's by train, by car it takes even longer.

It depends if you're going from "centre to centre" or "somewhere near Cologne to somewhere near Berlin".

Re: We tried to book a train ticket and ended up with a 245k records data breach

#57
post #27
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

The way that government procurement often works, it isn't the cheap contractors you end up with, either. Not many companies have the resources or willingness to stick through the long time it often takes to go through the bidding process, nor all of the pre-qualification requirements.

The whole process is long and drawn out with all sorts of checks and balances built in to it, based on previous learnings from previous contracts that have failed in various ways (particularly if it has embarrassed an elected figure). No doubt on the back of this failure, there will be more conditions added to the bidding process, making it even harder to find a vendor.

Usually by the time the entire process is done, there's not many vendors left and in my experience they're usually not the ones you'd actually want to do the work if you had a choice, just often ones that'll at least get you something.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#58
post #20
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

Governments do in-house development just as well as any company with a large development department.

Governments also do development off-shoring just as well as any company with a large off-shored project.

The kind of project people are talking about here never works. It doesn't matter who is doing it.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#59
post #31
post #20

Earlier quoted context omitted.

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It's a shame that (from my perspective anyway) a lot of that state capacity seems to have degassed for the NHS. Right now it's impossible to get a doctor's appointment where I live. If you call any local surgery within a split second of 8:00am then you have a very low chance of getting an appointment, every time I've tried the line's busy or I'm number 60 in the queue and after a 40 minute wait all the appointments a…

> "I cite the UK's response to COVID19 as evidence."

Here's some things I would love to see an alternate-history version of:

1) Vitamin D has some involvement in the immune system. The US Department of Health[1] says "Your immune system needs vitamin D to fight off invading bacteria and viruses.". Harvard School of Publich Health says[2] "laboratory studies show that vitamin D can reduce cancer cell growth, help control infections and reduce inflammation", "a large meta-analysis of individual participant data indicated that daily or weekly vitamin D supplementation lowers risk of acute respiratory infections"

2) The UK NHS page on Vitamin D does not mention immune function at all[3] but does strongly imply that everyone in the UK is deficient during winter when it recommends "since it's difficult for people to get enough vitamin D from food alone, everyone (including pregnant and breastfeeding women) should consider taking a daily supplement containing 10 micrograms of vitamin D during the autumn and winter."

3) The Harvard page linked earlier says a randomized controlled trial with 340 Japanese school children given either Vitamin D or a placebo, the Vitamin D group had 40% fewer flu infections in winter.

What do we know about COVID? It's an infection, it's expected to be more prominent in winter, some of the knock-on effects are to do with inflammation of tissues all around the body - lung, heart, brain, nerves.

So, would anything have played out differently if during the early days of no vaccines and no effective treatment, the NHS had leaned hard into Vitamin D testing and supplementation? Anyone presenting to a doctor or hospital or care home of any kind for any medical problem gets a routine blood test for VitD levels as well, any blood tests happening for anything also test for VitD levels, high risk people picked out specifically and called for testing, generic supplments freely available from GPs and pharmacies even without prescription using the NHS's large scale buying and negotiating power, anyone found deficient given a strong dose or large injection to start with, public relations push for the public to supplement or get checked, kept up all through the year leading into the first winter. Would it have made a difference to the ease of it spreading, to the amount of dead people, to the amount of hospitalized people, to the amount of long-term complications, would it have flattened the curve, helped the NHS, reduced or eliminated the lockdowns?

I am indoors most of the time, but I eat a lot of the recommended vitamin D foods - dairy, eggs, red meat, sardine, mackerel - and still had 'severely deficient' levels the first time I paid for my own test out of my own curiosity[4], and then 'insufficient' the next time.

That seems like the kind of thing a "national health service" would be well placed and incentivised to do, whereas a for-profit expensive-pills-and-surgery-and-insurance-profit "service" isn't.

[1] https://ods.od.nih.gov/factsheets/VitaminD-Consumer/

[2] https://www.hsph.harvard.edu/nutritionsource/vitamin-d/ (click to expand the 'immune function' section)

[3] https://www.nhs.uk/conditions/vitamins-and-minerals/vitamin-...

[4] (by a UK NHS lab, one which doesn't sell supplements so it's not incentivised to report misleadingly low figures)

Re: We tried to book a train ticket and ended up with a 245k records data breach

#60
post #22
post #20

Earlier quoted context omitted.

This is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state ca…

It’s not WW2 mobilisation but I’ve always thought the UK’s Government Digital Service is a wonderful example of what government can achieve in tech: https://www.gov.uk/government/organisations/government-digit... As I understand it they’re effectively a central dev shop for other government agencies. It’s worth their time investing in good practises because they’re going to use them over and over again. And from the…

GDS did a great job building gov.uk, but everythig else they touched was an abject disaster. From the Diabetes project at the NHS, the fiasco that was the Office of the Public Guardian, the even bigger fiasco that happened at Border Force, the NHS, DWP...

Sure, when they were building web sites they delivered stellar stuff. Agile, break things and all that. But when you had real complexity they just... couldn't...

The Government Gateway is a prime example - single citizen login for ALL government services. It ran well, super robust and mature enough to have ironed out virtually all issues.

Then GDS decided that because the Government Gateway was based on a Microsoft stack, it needed to be re-done. The tech lead didn't understand the concept of Identity Federation, let alone SAML tokens, and that you just! can't! do secure code using agile (2-week sprint no good for meaningful security testing...).

I spent two long years at GDS banging my head against a wall. And then I left. And unsurprisingly the Microsoft-based Government gateway was never replaced, still going strong.

Post reply on HN