Chaos Computer Club saves the German healthcare system 400M Euros
ccc.de
ccc.de
What's worse about this story is that the company apparently planned the hardware replacement in a way that it would have to be replaced again in 2027, and they still were awarded the contracts for this multi-million dollar project.
The German government has been lauded as this great bastion, "Look, their economy is still running!", but it's also has its corrupt elements. Besides, the whole roaring economy thing is related to making the rest of Europe peg its currency to the German one by way of the Euro, making the rest of the continent suffer...
>President François Mitterrand argued for the single currency because he hoped to bolster French influence in an EU that would otherwise fall under the sway of a unified Germany
However, you can argue that the continent suffers because Germany had reduced its labor costs [2], which unnecessarily moved production processes.
[1] https://www.economist.com/leaders/2012/11/17/the-time-bomb-a...
In this case, they're implying lobbying and corruption are one and the same, as far as I can tell.
The Gematik GmbH is in part managed (owned?) by the German ministry of health [0] and some health organizations like the Association of Statutory Health Insurance Agencies.
That says something about the 'risks' the Gematik takes (Hint: none).
Similar story: Earlier this year some health card readers, certified by the Gematik had a bug. They wouldn't read certain cards that supposedly were electrostatically charged. The solution was a grounding device connected to the USB port of the card reader. [1] This thingy cost the doctor's practices another 100 bucks even though this clearly is a design flaw by the manufacturer.
They can do pretty much what they want at this point and the physicians and hospitals just have to cough up the dough.
[0] https://de.m.wikipedia.org/wiki/Gematik
[1] https://www.borncity.com/blog/2022/01/16/problem-mit-statisc...
This is fucking brilliant XD
It's hilarious when you look at the web pages of such companies and see that their only customers in the last decades are various government agencies and state enterprises which are their bread an butter as they would never be competitive on the free market. Working at such companies is even more toxic. Extremely outdated tech, poorly qualified staff, huge bureaucracy yet poor management and poor understanding of the work going on, and so many people doing nothing all day than keeping seats warm and answering a couple of emails per week.
This is especially true in Germany. I remember the story from a former colleague who worked at the German information security government office (BSI) which had a cipher calculator on their website and it turned out to have a flaw in the calculation, and since the guy who implemented it didn't work there anymore and nobody on the staff knew where the code was, so instead of fixing the calculator or removing it from the website, they instead put a warning on the webpage that this calculator is wrong and shouldn't be used and called it a day lol. Hilarious but also sad for the German taxpayer.
You get exactly what you pay for.
This is true for most government contracts in most countries.
It gets worse with government contracts involving tech products and services as most governments don't have any skilled and knowledgeable tech people working for them, even in Germany, because why would they work for the toxic and underpaying public sector when they could earn more and get more respect in the private sector. This way, you only retain clueless people who only heard about the internet from a book, don't care about learning or improving things and are just there for a cushy job, ticking boxes and filing paperwork till retirement. If you want to hire skilled tech workers you gotta pay them well and give them freedom, which is not usually what government jobs are all about.
From what I've heard, Denmark is a great example of a well run, transparent government, which also employs skilled tech workers to develop high quality government software in house, instead of farming it all off to slimy companies who are gonna ship low quality trash at insane markups.
They end up cornered in markets where the expertise needed and moats are high and where they are slightly not too behind or ahead of the competition.
But anyway, the way to procure such "routers for secure networks" would be to add a contractual requirement of support for 20+ yrs.
It’s virtually impossible to overstate how bad the situation in this area truly is in Germany.
Can public organizations be made more efficient? Of course, as any organization can.
Finally, in this case is it not a private firm that is promoting inefficiency via dishonest market practices?
The real issue here is that the public agency has to buy services and products from private firms. Why can't the German state produce cost efficient routers on its own?
On average, this means they’re more rigorous in their vendor selection processes.
Therefore private entities are less likely to make bad purchases.
This claim gets thrown around so much, I can't stand it. The bigger a company gets, the more bureaucracy you have to deal it. Many big companies/market leaders are basically no better than government agencies when it comes to efficiency.
Also, I hate this idea of privatization for the sake of "efficiency". Imho some things (like healthcare) have so positive external effects on the whole economy, the should not be trimmed for profit, but for the best results instead. And, as it turns out, letting companies compete for this kinds of public infrastructure with a "winner takes it all" principle often does not quite turn out to be the most efficient choice
As far as I’ve seen, the general dynamic of having to spend the budget you’ve been given, even in the most wasteful way possible, or facing a budget reduction next term is universal whether you’re a bureaucrat in a socialist government, a bureaucrat in a large department of a democratic government, or a manager in a large company like IBM or Oracle.
>>difficult to imagine ways to end up more incompetent than literally all German public
I think that pretty much sums it up perfectly.
This has become a repeating pattern to such a degree that claiming plain incompetence cannot plausibly explain it any more. Maybe it’s not outright malice but corruption and fraud indeed.
> Special routers are required in German doctors' offices to connect to the "telematics" health data network. After only five years of operation, there is no alternative to replacing the devices - at least according to the manufacturers. This exchange is expected to burden the already struggling healthcare system with additional costs of around 400 million euros. The Chaos Computer Club (CCC) shows that the expensive hardware exchange is anything but necessary, and donates a solution to the problem free of charge.
I'm always amazed at the gross inefficiencies of the German bureaucratic machine (including most public and government institutions), despite the traditional world renowned stereotype of "German efficiency", even though at this point I know I shouldn't be surprised anymore.
The CCC is a national treasure.
Tip for anyone living or wanting to move there: keep digital copies of all important letters, bills, documents, contracts and paperwork you get. It's not unheard of for a company or government institution to make mistakes and you ending up on the hook with huge fines or bills to pay, so having copies of all possible paperwork from the beginning of time could save your ass one day.
Also expect close to no media coverage about that, or any political consequences. Heck, it took a thorough, highly public late night show investigation into the head of a government agency for cyber security and his close, and private links to former KGB agents and owners of cyber security firms, shady lobbying associations and whatnot for to be soon replaced. As if his known close ties to the private sector, and specific companies that ended up in the concil advising the government on cyber security, wasn't enough. One has to wonder so, how such a position doesn't require a security clearance. If I had close private contacts to known former KGB guys (known because the guy in question got an award in public for long service for the KGB and the state) I wouod have never passed these checks. Or if I had not mentioned them I would have lost my job immediately. Fun fact, it was the former conservative led government, and more specifically conservative politicians in cjarge of the ministry of interior, that put the guy in his position. And politians from the same party maintained the contact with Russian authorities.
€400M sounds a lot but how many of these devices are there? If there's one in every medical practice that could be 100-200,000. [EDIT: this article https://www.healthcareitnews.com/news/emea/error-which-cause... suggests there are 130,000 clinics, that would be €3K per clinic]
Having a technician visit each and do a firmware update - could well cost over $5K or more, as long as introducing downtime at the surgery, the changes would need to be done by people who are trained and this is a device that is involved in personal medical data - they need to be managed and monitored.
Delivering a new piece of hardware with the new certificates that could be dropped in could well be cheaper (how ever bad for the environment) than updating them within the legal requirements that may be in place for tech that handles medical data.
There may be good technical and legal reasons why the certificates can't be updated remotely or are set to expire, but if I were the companies involved I would take in some devices, 'refurbish' them with new certificates and send them out to medical practices for drop in replacement, rather than sending out new devices.
It's about that the Devices DON'T accept new certificates over a certain date, like when your iphone just accept certificates who are valid up to 2022, then you need a new iphone, that should be illegal, and the firm should have to pay the technician/fw-update.
No you get updated certs from cert-authorities (the one's trusted by apple/google/mozilla etc), the ones who "signed" the received certs from website X. Otherwise you would have to download gigabytes of certificates.
https://www.youtube.com/watch?v=86cQJ0MMses
>>TLS Handshake Explained - Computerphile
You forgot the mask-scandal ;)
Since a reasonable person buys a car as a long-lasting mode of transport, the sealed fuel tank would probably not meet expectations.
However, if the propulsion system were, say, nuclear fission, and the system lasted 5-10 years and then needed to be replaced, that might be a satisfactory product from this legal viewpoint. The NTSB and Department of Energy would have some things to say about it, though.
https://logbuch-netzpolitik.de/lnp433-auf-yolo-konfigurieren
(In German)
Remember, kids, don't buy non-rootable devices of which you have no control! )
To transfer patient data between doctors and (state) insurance companies, doctor‘s offices need to have a hardware VPN device. The system was implemented by the company „gematic“. A small number of companies produce these devices.
The certificates on these devices expire after five years. Now, instead of simply updating the certificates, the companies want the state and the doctors to buy new devices which costs around 400 million.
The CCC firstly explained that this is bullshit and a total waste of money and secondly showed that it is easy to update the devices. They could do it themselves but only need the private key from gematic.