TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

We tried to book a train ticket and ended up with a 245k records data breach

300 pointsby mrzoolalmost 2 years ago

14 comments

2rsfalmost 2 years ago
&gt; This project was implemented by the same agencies - MCI together with Caracal.<p>I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?
评论 #36390659 未加载
评论 #36390433 未加载
评论 #36391567 未加载
Springtimealmost 2 years ago
Just wanted to mention the photos of the model trains used to show the progression of events was charming.
TazeTSchnitzelalmost 2 years ago
<i>Zerforschung</i> (research to the point of destruction) is a perfect name for a site with this post.
lbrineralmost 2 years ago
Lots of people complaining about state-run projects or suppliers who do stuff on the cheap but I think the simple fact is that in most people&#x27;s minds, buying a &quot;IT system&quot; is like buying a car except that the car is built from scratch each time even though the customer wants off-the-shelf prices.<p>How many applications do we create that all do exactly the same thing? Payments, customer details, tasks, shopping baskets, items for sale etc. and how many times have we rebuilt all of that from the ground up with all the risks? Even if we know what we are doing, it is easy enough to forget something, for someone who didn&#x27;t know what they were doing to build part of it, to cost enormous money to plumb together a tonne of bespoke parts.<p>I think the solution is 1) We need much better regulation of who has the relevant skills to do work to the required standard, we still allow untrained and unqualified people to build banking apps etc. 2) We need to create something that allows us to possibly certify implementations of standard functionality so they can be used to create standard applications, just like Peugeot might buy engines from Toyota that they know already work.<p>We talk about freedom of thought and creativity but the price of reliable and trustworthy software is probably only going to come by establishing a much higher level of quality - hopefully minus some of the BS you get with some accreditations.
评论 #36391271 未加载
评论 #36390921 未加载
luplexalmost 2 years ago
The sad thing is I don&#x27;t see the public sector getting any better at this anytime soon.
评论 #36390567 未加载
评论 #36390179 未加载
评论 #36390263 未加载
pedybr2almost 2 years ago
Made me think about this podcast I listened to the other day: <a href="https:&#x2F;&#x2F;www.nytimes.com&#x2F;2023&#x2F;06&#x2F;06&#x2F;opinion&#x2F;ezra-klein-podcast-jennifer-pahlka.html" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.nytimes.com&#x2F;2023&#x2F;06&#x2F;06&#x2F;opinion&#x2F;ezra-klein-podcas...</a><p>In it Jennifer Pahlka, a high ranking US government official who worked on heathcare.gov and other digital government projects, talks about her book that is about why most of these projects go as poorly as they do. Quite illuminating...
评论 #36391388 未加载
_-____-_almost 2 years ago
You&#x27;re lucky that you got in touch with someone who understood the report and didn&#x27;t refer you to the polizei, like happened in Hungary a few years ago when a 17 year old kid figured out he could change the price of a ticket in his browser dev tools.
banDeveloperalmost 2 years ago
How were they able to generate &#x2F; obtain the `apiKey` shown in the technical details in part 6?
评论 #36391336 未加载
red_admiralalmost 2 years ago
It&#x27;s a good thing the people writing software for the railway interlockings, unlike these guys, are held to SIL4 standards.
petrut_malmost 2 years ago
Although the faults are massive, the time to fix was relatively short, scroll to the bottom and look at the timeline... this is not a fault sitting in the open for months after reporting.
pixel3234almost 2 years ago
Stuff like this is why I prefer to take a bus in Germany.<p>Trains are overbooked with free tickets and promotions (free pass for entire summer for 50 euro). While underlying infrastructure is not ready for such load. It leads to delays and mistakes. Plus railway stations in Germany look like homeless shelters!<p>On other side Germany has excellent motorway network. Flixbus is very cheap, quite comfortable, goes all the way to airport, and always on time!
评论 #36390313 未加载
评论 #36390598 未加载
neloxalmost 2 years ago
You scored the mystery ride
batch12almost 2 years ago
The age limits on the free tickets stand out to me. I guess it&#x27;s all ROI forecasting. Either older folks are assumed to have exposure to the target country already, can afford the travel, or aren&#x27;t worth it?
DamonHDalmost 2 years ago
Completely shambolic schoolboy errors!
评论 #36390283 未加载
评论 #36389948 未加载