16 ms·
We tried to book a train ticket and ended up with a 245k records data breach
- DamonHD 3y agoCompletely shambolic schoolboy errors!
- db48x 3y ago[flagged]
- fifafifi 3y agoCompetence and professionalism.
- bell-cot 3y agoIf not '/s'...might we ask what country you live in, and how much experience you have with government?
- benburleson 3y agoIn America you get accused of crime for this type of activity. Seriously: https://www.malwarebytes.com/blog/news/2022/02/journalist-wont-be-indicted-for-hacking-for-viewing-a-state-websites-html/amp https://www.malwarebytes.com/blog/news/2022/02/journalist-wo...
- quickthrower2 3y agoExpect has 2 meanings: A standard —-or—- a prediction. I expect my child to behave well at school but I expect my child will not.
- DamonHD 3y agoNothing much to do with government: organisations of all types regularly screw up in similar ways. Probably some over-promoted growling manager insisting "Do it now!" without listening to the "but ... but ... but" caveats. But maybe also an undereducated and oblivious techie.
- sofixa 3y agoBecause private companies like Microsoft, British Airways, T-Mobile, Equifax never make amateur mistakes in cyber security.
- hef19898 3y agoHey, only one of those is a true tech company. The others are failing legacy comoanies, former government owned ones, that just don't get tech / software. And Ms is, well, MS. /s
- Karellen 3y agoI thought the project was implemented by private agencies? Article says MCI and Caracal. Isn't that supposed to be how the government gets the best results with the greatest efficiency under neoliberal capitalism? Subcontract the private sector to do it. They have the expertise to know what they're doing and avoid obvious errors, which would not be the case if the government did it themselves?
- db48x 3y agoEven the best way of doing something is not a guarantee that it will always go perfectly. Usually the government mismanages a project like this and the contractor can do little aside from implement whatever the client asks for. Maybe it would have gone better if the government had built performance standards into the contract so that the contractor would have to pay a penalty if the site wasn’t reliable or available to the public, or if the entrant’s personal information was leaked.
- Tade0 3y agoLarge, state-backed, entities that predate the internet seem to get away with stuff of this kind all the time. The other day my mother tried to buy a train ticket. The payment went through, but something went wrong on the site and the ticket was not issued. If this were just some e-commerce site, the payment provider would have had their head on a spike. In this case she had to go through the usual return process.
- DougBTX 3y agoIn this case, it looks like the private company which did the work is also getting away with it... https://www.caracal.agency/en/projects/discover-eu https://www.caracal.agency/en/projects/discover-eu
- TazeTSchnitzel 3y agoZerforschung (research to the point of destruction) is a perfect name for a site with this post.
- luplex 3y agoThe sad thing is I don't see the public sector getting any better at this anytime soon.
- throwaway049 3y agoDon't see the private sector doing so either. It's a scramble every year for Glastonbury festival tickets.
- skeeter2020 3y agoAlso sad: the (terrible) response times and efforts detailed here exceed what many organizations, private and public, have shown in their situations.
- mysterydip 3y agoWorse, there's laws in place (in the name of "cost savings") that need changed before any policy improvement could be made. A group can't just decide "it would be better if we didn't use the lowest bidder." There's legal repercussions and losers can sue (leading to more expense than if they just went with them in the first place). It's truly terrible.
- HPsquared 3y agoThey don't just accept the lowest bid. It's the lowest bid that complies with the requirements. You can tighten up the requirements and conditions.
- deleted 3y ago[deleted]
- SoftTalker 3y agoYou can also consider the demonstrated qualifications/competency of the bidder. I could submit a low bid for a project and if I have no history of ever completing similar projects my bid can be rejected on that basis. However (at least in the few governemnt bids I've been involved in) if the low bidder does not get the award, they can challenge the award and often do. Then the government has to defend their decision and give the reasons the low bid was disqualified.
- nelox 3y agoYou scored the mystery ride
- pixel3234 3y agoStuff like this is why I prefer to take a bus in Germany. Trains are overbooked with free tickets and promotions (free pass for entire summer for 50 euro). While underlying infrastructure is not ready for such load. It leads to delays and mistakes. Plus railway stations in Germany look like homeless shelters! On other side Germany has excellent motorway network. Flixbus is very cheap, quite comfortable, goes all the way to airport, and always on time!
- sc11 3y agoLet's see. Cologne to Berlin takes ~4:40 hours by train. Flixbus takes 9-10 hours, not counting the time it takes to get to their departure station which would involve a train journey as it's not actually in the city centre. Flixbus is 50€ cheaper when traveling that route tomorrow but that's about all it has going for it.
- HPsquared 3y ago1 hour by plane (+ time hanging around the airport, but train/bus has the same issue there)
- com 3y agoTrain and bus normally have that “10-20 minutes ahead” planning to be at the station. Planes? At least an hour, and if you cut into that, and the queues or security theatre more mind boggling than normal, you’ve missed your flights. Eurostar is similar to airports, so I’m glowering at them too!
- sc11 3y agoEven if you aren't at the airport that early, it still takes you an hour to get from the airport to the city centre in Berlin, and about half an hour to get to the airport from Cologne's city centre. That's by train, by car it takes even longer.
- 3y ago
- Springtime 3y agoJust wanted to mention the photos of the model trains used to show the progression of events was charming.
- 2rsf 3y ago> This project was implemented by the same agencies - MCI together with Caracal. I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?
- pjc50 3y agoThis is where quite a lot of people would insert a rant about "state capacity": the ability of the state to actually do things it wants and intends to do. Which requires people to do those things, trained with appropriate skills. The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state capacity can end the state itself, and the personal privileges of those running it and the elite around them. It's not a coincidence that the centralized socialist institutions of the UK, the NHS and state education, date from that period. Heck, the state commissioned the invention and building of cutting-edge computer technology! But since that no longer matters, there's little to no will to build state capacity in computing.
- afavour 3y agoIt’s not WW2 mobilisation but I’ve always thought the UK’s Government Digital Service is a wonderful example of what government can achieve in tech: https://www.gov.uk/government/organisations/government-digital-service https://www.gov.uk/government/organisations/government-digit... As I understand it they’re effectively a central dev shop for other government agencies. It’s worth their time investing in good practises because they’re going to use them over and over again. And from the user perspective you get a very consistent, reliable set of tools for interacting with government. A win win in my book.
- franga2000 3y agoThis is something we desperately need more of in other countries. We've found something like a dozen breaches of similar severity in the last 6 years and they all came from systems developed through public tenders by companies that either aggressively under-priced or used other (legal or illegal) dirty tactics to win them. The very few things that were developed in-house have proven to be far more reliable and secure, not to mention developing them was far cheaper and the UX is better and more consistent between them.
- pedybr2 3y agoMade me think about this podcast I listened to the other day: https://www.nytimes.com/2023/06/06/opinion/ezra-klein-podcast-jennifer-pahlka.html https://www.nytimes.com/2023/06/06/opinion/ezra-klein-podcas... In it Jennifer Pahlka, a high ranking US government official who worked on heathcare.gov and other digital government projects, talks about her book that is about why most of these projects go as poorly as they do. Quite illuminating...
- js2 3y agoCame here to mention that episode. Agree that it was very insightful. Transcript: https://pastebin.com/Lg7zfHd9 https://pastebin.com/Lg7zfHd9
- theironhammer 3y agoThank you!
- lbriner 3y agoLots of people complaining about state-run projects or suppliers who do stuff on the cheap but I think the simple fact is that in most people's minds, buying a "IT system" is like buying a car except that the car is built from scratch each time even though the customer wants off-the-shelf prices. How many applications do we create that all do exactly the same thing? Payments, customer details, tasks, shopping baskets, items for sale etc. and how many times have we rebuilt all of that from the ground up with all the risks? Even if we know what we are doing, it is easy enough to forget something, for someone who didn't know what they were doing to build part of it, to cost enormous money to plumb together a tonne of bespoke parts. I think the solution is 1) We need much better regulation of who has the relevant skills to do work to the required standard, we still allow untrained and unqualified people to build banking apps etc. 2) We need to create something that allows us to possibly certify implementations of standard functionality so they can be used to create standard applications, just like Peugeot might buy engines from Toyota that they know already work. We talk about freedom of thought and creativity but the price of reliable and trustworthy software is probably only going to come by establishing a much higher level of quality - hopefully minus some of the BS you get with some accreditations.
- HPsquared 3y agoIt's a lot like building houses. Lots of manual processing and making the standard formula fit the specific application.
- BoxFour 3y agoIt appears as though you are merely rehashing the realm of SAAS and, to compound matters, the labyrinthine government contracting procedure. The market already boasts software solutions that are more or less ready-made, precisely catering to your described needs, particularly concerning areas like payments. However, governmental entities abstain from employing such software, as their provider selection process deliberately embraces a convoluted nature to sidestep any hint of impropriety. Thus, the government contracting industry flourishes—a cohort proficient in maneuvering through the intricate channels of governmental procurement. Most private enterprises that excel in providing top-tier services opt out of engaging in this government contracting labyrinth because it's not worth the headache. It involves an assortment of antiquated procedures and certifications that the private sector seldom finds worthwhile to partake in, as they exclusively pertain to the realm of government contracting and are often accompanied by a disheartening degree of bureaucratic rigmarole. Deciphering a pathway towards resolving this predicament would transcend the mere realm of overhauling regulations; rather, it necessitates the overhaul of modern bureaucracy and solving the arduous struggle government faces to keep pace with fast-evolving fields like technology. Basically: Good luck with that!
- red_admiral 3y agoIt's a good thing the people writing software for the railway interlockings, unlike these guys, are held to SIL4 standards.
- banDeveloper 3y agoHow were they able to generate / obtain the `apiKey` shown in the technical details in part 6?
- Legogris 3y agoWithout looking closer I just assumed it was trivially extracted from the frontend.
- banDeveloper 3y agoYou're right, it's the Supabase's anonymous API key they send with each anonymous request.
- batch12 3y agoThe age limits on the free tickets stand out to me. I guess it's all ROI forecasting. Either older folks are assumed to have exposure to the target country already, can afford the travel, or aren't worth it?
- petrut_m 3y agoAlthough the faults are massive, the time to fix was relatively short, scroll to the bottom and look at the timeline... this is not a fault sitting in the open for months after reporting.
- _-____-_ 3y agoYou're lucky that you got in touch with someone who understood the report and didn't refer you to the polizei, like happened in Hungary a few years ago when a 17 year old kid figured out he could change the price of a ticket in his browser dev tools.