Live data from Hacker News

We tried to book a train ticket and ended up with a 245k records data breach

zerforschung.org

61–70 of 83 posts

Re: We tried to book a train ticket and ended up with a 245k records data breach

#61
post #6

Earlier quoted context omitted.

[flagged]

I thought the project was implemented by private agencies? Article says MCI and Caracal. Isn't that supposed to be how the government gets the best results with the greatest efficiency under neoliberal capitalism? Subcontract the private sector to do it. They have the expertise to know what they're doing and avoid obvious errors, which would not be the case if the government did it themselves?

Even the best way of doing something is not a guarantee that it will always go perfectly. Usually the government mismanages a project like this and the contractor can do little aside from implement whatever the client asks for. Maybe it would have gone better if the government had built performance standards into the contract so that the contractor would have to pay a penalty if the site wasn’t reliable or available to the public, or if the entrant’s personal information was leaked.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#62
post #18

> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?

As this is a government contract, and there are strict public transparency rules on government contracts, I went digging.

Here's the call for tenders: https://etendering.ted.europa.eu/cft/cft-display.html?cftId=...

And here's the award: https://ted.europa.eu/udl?uri=TED:NOTICE:120998-2022:TEXT:EN...

Some interesting things:

1. This is a broad framework contract for marketing, for the eye-watering amount of 300 million euro. The title is "Belgium-Brussels: Framework Service Contract for the Organisation of Large-scale Travels of Participants in the Context of Erasmus+/DiscoverEU"

The reason they do these kinds of framework contracts is because the legally required tendering procedures surrounding government contracts are so onerous that it's better to do a broad contract once and bundle a lot of projects inside of them, than to have one contract per project.

2. The executing party (Caracal) is nowhere to be seen, instead the contract is awarded to EURail and MCI.

EURail is the intermediary I suspect, responsible for navigating the wild world of government contracting, and MCI is a marketing agency. They have no doubt built up years of expertise in how to successfully navigate these kinds of tendering procedures, and they probably are not the lowest bidder. Caracal is no doubt subcontracted by MCI, but as MCI is a private company we cannot see how much they were paid or how they were selected. So much for transparency.

In my own experience in government contracting, price is a factor but usually not the largest factor. There's a large set of requirements (which you can read through if you follow the first link), and the ability to prove that you will be able to meet them is mostly what determines who wins the contract. However, because it is so difficult to know how to do that, only a few parties will have submitted a tender, and the best of a poor batch may still not be very good.

Personally I think this kind of public procurement legislation is well intended but ultimately flawed. It does not result in lower costs, faster turnaround, better transparency, or overall better government. I'm in favor of transparency rules, but they need to be a lot more thorough and they need to cover subcontracting as well. I'm against public tendering legislation, as I think it prevents the government from being efficient.

(By the way, how awful is that public tendering website? It's like a flashback to 2003. No doubt built under one of those big framework contracts.)

Re: We tried to book a train ticket and ended up with a 245k records data breach

#63
post #50

Earlier quoted context omitted.

Even if you aren't at the airport that early, it still takes you an hour to get from the airport to the city centre in Berlin, and about half an hour to get to the airport from Cologne's city centre. That's by train, by car it takes even longer.

It depends if you're going from "centre to centre" or "somewhere near Cologne to somewhere near Berlin".

Sure but assuming you're traveling from centre to centre, which is where population densities are highest, is a sound assumption. Otherwise you can always find spots where getting to the airport, train station, flixbus stop or whatever takes extremely long with one mode of transport over the other.

Doesn't distract from the point that long distances busses are very much not an alternative to rail (or planes for that matter) unless price is the deciding factor. And even the latter is questionable in many cases thanks to the 49€ ticket.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#65
post #45
post #40

Earlier quoted context omitted.

This is a problem traditionally solved by the professional engineering licensing system. Most engineering curriculum in the USA involve an Engineering Ethics course that goes over such issues. We're quite far from implementing such a system for software "engineers".

Just hire pentesters along with the development team. Make sure they are not affiliates. You can put in contract that as long as security issues are present they need to fix them before getting paid, which seems like a reasonable expectation. Even the best make mistakes, so let's at least leave those which are not trivial. We don't trust building ethics, independent inspector comes and checks if everything is as it s…

This can't happen more often than not, because the client has no idea what a pentest is. They don't even know what a is XSS means, or even API. These things are negotiated by people that only can see the frontend, and if it looks great, _snappy_, _flashy_, with random animations and following current trends it's OK. The contractors know and can easily detect this, so they focus on frontend and don't waste their time in behind-the-scenes polish. You don't polish the security or find a costly query that could bring the site to their knees, but you add a scroll-spy that brings some images from nowhere.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#66
post #45

Earlier quoted context omitted.

Just hire pentesters along with the development team. Make sure they are not affiliates. You can put in contract that as long as security issues are present they need to fix them before getting paid, which seems like a reasonable expectation. Even the best make mistakes, so let's at least leave those which are not trivial. We don't trust building ethics, independent inspector comes and checks if everything is as it s…

This can't happen more often than not, because the client has no idea what a pentest is. They don't even know what a is XSS means, or even API. These things are negotiated by people that only can see the frontend, and if it looks great, _snappy_, _flashy_, with random animations and following current trends it's OK. The contractors know and can easily detect this, so they focus on frontend and don't waste their time…

Investors have no idea what thickness the wall should be in their building either.

Clients not being experts at the job they are getting somebody else to do is not a new pattern. So while some trust is required, it's best if you can get somebody else to verify.

I've seen a few smart clients over the years which when faced with some excuses from a software house hired another one to give them opinion about the codebase and capabilities. It seems pretty intuitive. It seems like a money well spent.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#67
post #46
post #27

Earlier quoted context omitted.

It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief. If a project is too expensive for a client to do well, they should not be doing that wo…

If my company is anything like the others, its very rarely the lowest bidder who wins at all. Usually there is some sort of RFI process, where they ask a few companies 'hey can you build this for us? What are the types of services you would propose'. The list of companies here is already more or less pre-existing partnerships, or ex colleagues or... (it mostly always contains Microsoft, and your boss is ex Accenture,…

Sounds spot on to me. Just let a bunch of unsupervised kids loose to screw shit up as much as they like, then after they've done that for a couple years you call them seniors and charge double for their time.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#68

How were they able to generate / obtain the `apiKey` shown in the technical details in part 6?

Without looking closer I just assumed it was trivially extracted from the frontend.

You're right, it's the Supabase's anonymous API key they send with each anonymous request.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#69
You're lucky that you got in touch with someone who understood the report and didn't refer you to the polizei, like happened in Hungary a few years ago when a 17 year old kid figured out he could change the price of a ticket in his browser dev tools.

Re: We tried to book a train ticket and ended up with a 245k records data breach

#70

Earlier quoted context omitted.

Worse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.

They don't just accept the lowest bid. It's the lowest bid that complies with the requirements . You can tighten up the requirements and conditions.

[deleted]
Post reply on HN