Live data from Hacker News

Inside the Transport for London cyberattack

londoncentric.media

51–60 of 89 posts

Re: Inside the Transport for London cyberattack

#51
post #31

I think lots of people who lack the experience have no idea quite how large and difficult cybersecurity is for a massive organisation whose systems span 20-30+ years or possibly even longer. There is no standardised tooling and very little that can be retrofitted to older systems. Firewalls are fine if the attack is against a port you do not need to use but otherwise you are left with a myriad of commercial offerings…

[dead]

Re: Inside the Transport for London cyberattack

#52
post #35

> Hundreds of thousands of Londoners are being overcharged for travel, while London Centric spoke to one teenager who is having to skip meals because of cashflow issues brought on by the cyberattack. This is just crazy, why not make public transport as cheap as peanuts to begin with? Why does everything have to be so damn expensive? Why the heck does a monthly transport pass have to cost, let me check, around 200 pou…

[dead]

Re: Inside the Transport for London cyberattack

#53
> Cybersecurity experts claim TfL’s software may have not been up to scratch, with some public-facing systems coded to be compatible with long-defunct browsers such as Internet Explorer 6.

This is rubbish, public-facing websites being compatible with defunct browsers is not indicative of any security issue

Re: Inside the Transport for London cyberattack

#54
post #49
post #2

Lots of people who should have been establishing effective security practices and monitoring and improving it were doing … something … but not that. Total failure of management and governance at TfL and the British Library (which even had a “private sector security leader” on its board of governors for a decade or more before their total shitshow of a breach last year) But as usual, there will be no consequences.

TFL are better than most public bodies but are likely hamstrung on being able to pay anything like market rates for competent security people.

Totally get it that budgets are tight. But making sure that stuff happens isn’t highly correlated to tech staff or manager salaries.

Unless they’re hiring inexperienced high-schoolers, it’s a failure of will and competence in management. And even that would actually be a failure of managrnent.

I’m guessing - based on historic contacts with TfL - that this failure of management is probably manifest in too many meetings and intermediate products valorised over and above culture, knowledge and tech improvements.

Avoidance of outcome-based monitoring and governance, and instead a focus on “process execution” like reorgs, agonisingly-slow checkbox actions and deckchair relocations is pretty common in low-ambition, low-performance orgs. Again, you don’t get this because you’re being cheap on security people.

Re: Inside the Transport for London cyberattack

#55
post #35

> Hundreds of thousands of Londoners are being overcharged for travel, while London Centric spoke to one teenager who is having to skip meals because of cashflow issues brought on by the cyberattack. This is just crazy, why not make public transport as cheap as peanuts to begin with? Why does everything have to be so damn expensive? Why the heck does a monthly transport pass have to cost, let me check, around 200 pou…

I don't live in London, but most people I've talked to who do don't have any monthly transport pass or anything like that. They just tap in with contactless. The transport is cheap enough that if you don't travel many times per day, there is really no need. As one example - a bus journey is 1.75 GBP regardless of the distance and number of individual buses taken, as long as all initial tap-ins are within one hour.

Looking at the TfL website, people on benefits get 50% rate discounts; students get 30% off; pensioners and children get completely free travel. It's really quite a good system actually.

Re: Inside the Transport for London cyberattack

#56
post #33

Earlier quoted context omitted.

> easier to just tax wealth a bit more and let everyone get on the bloody train I mean its not. If it was, they would have done it. Wealth taxes are really fucking hard to do equitably, at least at first. For example OAPs tend to live in very expensive hosues. take rotherhithe for example one could have bought a house in the 90s for shit all, and now its worth the best part of 1.4 million. so now you're levying a 5%…

> Well, they'll transfer all they own into a corporation. They can't tax assets like that on business because it'll crash the economy super quick Thanks for that. I've always thought that wealth isn't taxed heavily because it's the wealthy that make the laws. That still may be part of it, but this surely is too. As a side note, I'm puzzled as to where this seemingly prevalent (here, at least) sentiment of letting peo…

Wealth isn't taxed because most wealth, unlike income or other use taxes, are based on valuations that are extremely fragile.

Let's say you open a corner bakery that does very well. You are making $1m/year and paying the government $200k/yr in corporation taxes. That leaves $800k/yr in the biz. A perpetuity paying $800k/yr at 5% discount rate is worth $16m (obviously this is a bad proxy for the value of a risky business, but it's a starting point).

So the government comes along and says "ok you owe us X% of this business per year". Where do you get the money for this? You can't just give the government shares. But it's a corner bakery...nobody wants to go through the headache of buying 1% in a local business. And what happens next year when business drops, and the value drops, how do you prove to the govt what it's worth? It's a minefield, and probably not legal.

I get it. People want to eat the rich. It's easier to point to other people as the problem (even if they pay 40x more proportionately in tax than someone else) instead of saying "Christ, maybe we spend too much". But the ideas to kick the can are really getting silly.

Re: Inside the Transport for London cyberattack

#57
post #42

Earlier quoted context omitted.

> easier to just tax wealth a bit more and let everyone get on the bloody train I mean its not. If it was, they would have done it. Wealth taxes are really fucking hard to do equitably, at least at first. For example OAPs tend to live in very expensive hosues. take rotherhithe for example one could have bought a house in the 90s for shit all, and now its worth the best part of 1.4 million. so now you're levying a 5%…

What do you mean "can't", this is exactly what already happens in countries that already implement a wealth tax (eg, Switzerland). If you own a corporation that has assets worth millions, then the corporation is the asset that you're paying wealth taxes on (as part of your personal tax return). Doesn't matter if the company is based abroad either, you'll still need to supply the companies balance sheet as part of you…

Tax dodging is the national sport of the Swiss. This is a horrendous example.

Re: Inside the Transport for London cyberattack

#58

It's amazing how much bureaucracy they're willing to spend money on to means-test a fundamental service. If you just made transit free at the point of service you wouldn't have free cards for all under 16, and some over 16, and all over 60, and discount fares for people in poverty. Cities spend so much money outsourcing the IT for fare collection, and the administration of budget programs, and ultimately the experien…

> In Gavin Newsom’s book Citizenville he talked about how, after becoming [San Francisco] mayor, he discovered that fare collection cost as much as the revenue generated from fares. He started the process of making the bus free but was told by so many advisors that the busses would become “dumpsters on wheels,” from a combination of homeless people using them for shelter and people not respecting services that are fr…

I would guess that technology has already caught up with that. Tie it all to a phone app to track abuse and give a city services only data plan to anyone who asks. Give it a basic three strikes where the driver logs complaints or you need a remedial how to properly use city services class.

Given the license tracking already going on for bridge tolls the infrastructure may already be there.

Re: Inside the Transport for London cyberattack

#59
post #33

Earlier quoted context omitted.

> easier to just tax wealth a bit more and let everyone get on the bloody train I mean its not. If it was, they would have done it. Wealth taxes are really fucking hard to do equitably, at least at first. For example OAPs tend to live in very expensive hosues. take rotherhithe for example one could have bought a house in the 90s for shit all, and now its worth the best part of 1.4 million. so now you're levying a 5%…

> Well, they'll transfer all they own into a corporation. They can't tax assets like that on business because it'll crash the economy super quick Thanks for that. I've always thought that wealth isn't taxed heavily because it's the wealthy that make the laws. That still may be part of it, but this surely is too. As a side note, I'm puzzled as to where this seemingly prevalent (here, at least) sentiment of letting peo…

> where this [...] sentiment of letting people ride public transport for free has suddenly come from?

It has been there since public transport has been a thing. Its popularity ebbs and flows with the years, because it's fundamentally very appealing: dealing with tickets and tariffs is a huge annoyance, and everyone resents it for one reason or another. "Surely there is a simpler way!"

Alas, ticketing systems seem to be the less-worst thing, a bit like representative democracy as a system of government. Free-for-all attempts never survive an economic or budgetary crisis, and tickets are the closest thing to an objective method to raise funds for a service. Maybe technology (and politics) will eventually evolve enough to develop fairer means-tested systems.

Re: Inside the Transport for London cyberattack

#60

> Cybersecurity experts claim TfL’s software may have not been up to scratch, with some public-facing systems coded to be compatible with long-defunct browsers such as Internet Explorer 6. This is rubbish, public-facing websites being compatible with defunct browsers is not indicative of any security issue

No but also … https://www.newscientist.com/article/2197453-exclusive-thous...
Post reply on HN