We tried to book a train ticket and ended up with a 245k records data breach
zerforschung.org
zerforschung.org
I suspect that this is the root cause of this and for many other systems failing. When a project is created by the lowest bidder, as a one time effort with fluffy requirements why would they invest in proper architecture, planning or testing? Why would they invest in securing resources when they are paid anyway?
There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief.
If a project is too expensive for a client to do well, they should not be doing that work in the first place.
We're quite far from implementing such a system for software "engineers".
We don't trust building ethics, independent inspector comes and checks if everything is as it should be before it can be used by the public.
Clients not being experts at the job they are getting somebody else to do is not a new pattern. So while some trust is required, it's best if you can get somebody else to verify.
I've seen a few smart clients over the years which when faced with some excuses from a software house hired another one to give them opinion about the codebase and capabilities. It seems pretty intuitive. It seems like a money well spent.
In fact, a whole lot of the time, the entire reason someone hires a professional is precisely because they themselves aren't experts.
Good narrative: but certification and guilds do not solve the problem.
For example: UK Grenfall towers. https://www.bbc.com/news/uk-61724373
It is a wrong to assume that only engineers can cause deadly mistakes. Also we have penal liabilities that don’t need licensing:
The [UK] Health and Safety at Work Act 1974 is designed to stop employers putting the public at risk, not just employees in the workplace. Individuals can be prosecuted and a serious breach could attract a two-year prison sentence.
And sometimes some pretty big exceptions: the [UK] government can't be prosecuted for corporate manslaughter
Locally to me in Christchurch, New Zealand, there have been no prosecution for the CTV tower collapse: https://www.nzherald.co.nz/nz/fatal-ctv-building-collapse-po... https://www.nzherald.co.nz/business/govt-considering-introdu... The second link is interesting because it looks at changing the law to add liability (not engineers licensing changes )In both cases, there are multiple layers of failure, and many causes could be asssigned. Especially the CTV building with inspections before collapse and warnings from people working there ignored.
You are talking Nirvana fallacy https://en.m.wikipedia.org/wiki/Nirvana_fallacy
Usually there is some sort of RFI process, where they ask a few companies 'hey can you build this for us? What are the types of services you would propose'. The list of companies here is already more or less pre-existing partnerships, or ex colleagues or...
(it mostly always contains Microsoft, and your boss is ex Accenture, so it involves Accenture, and for good measure to seem like they are open to other options they invite Deloitte and some other players as well, sometimes even IBM has joined the club again)
Then they decide who they deem thrustworthy, and you end up with Microsoft and (insert boss previous employer). So not only do you not get the lowest bidder, you can some veeerrryyy generic company that doesn't care and just sends juniors to solve it. This process is called the RFP. And it typically is far from neutral
The whole process is long and drawn out with all sorts of checks and balances built in to it, based on previous learnings from previous contracts that have failed in various ways (particularly if it has embarrassed an elected figure). No doubt on the back of this failure, there will be more conditions added to the bidding process, making it even harder to find a vendor.
Usually by the time the entire process is done, there's not many vendors left and in my experience they're usually not the ones you'd actually want to do the work if you had a choice, just often ones that'll at least get you something.
If we assume there is no corruption involved, then lack of competence from the project management side can fail such a project. For this example it could be failing to mention or think about the extra load on the first hours in the SOA
The peak of "state capacity" was undoubtedly WW2, when governments bypassed market mechanisms and became command economies. Out of necessity - war is the one venture in which failed state capacity can end the state itself, and the personal privileges of those running it and the elite around them.
It's not a coincidence that the centralized socialist institutions of the UK, the NHS and state education, date from that period. Heck, the state commissioned the invention and building of cutting-edge computer technology! But since that no longer matters, there's little to no will to build state capacity in computing.
https://www.gov.uk/government/organisations/government-digit...
As I understand it they’re effectively a central dev shop for other government agencies. It’s worth their time investing in good practises because they’re going to use them over and over again. And from the user perspective you get a very consistent, reliable set of tools for interacting with government. A win win in my book.
Sure, when they were building web sites they delivered stellar stuff. Agile, break things and all that. But when you had real complexity they just... couldn't...
The Government Gateway is a prime example - single citizen login for ALL government services. It ran well, super robust and mature enough to have ironed out virtually all issues.
Then GDS decided that because the Government Gateway was based on a Microsoft stack, it needed to be re-done. The tech lead didn't understand the concept of Identity Federation, let alone SAML tokens, and that you just! can't! do secure code using agile (2-week sprint no good for meaningful security testing...).
I spent two long years at GDS banging my head against a wall. And then I left. And unsurprisingly the Microsoft-based Government gateway was never replaced, still going strong.
The only way to see a doctor is to go to A&E, or convince NHS 111 to give you an "emergency appointment" of some kind. All of this drains emergency resources and are not an option due to the time investment for average people with precarious employment.
Unfortunately many people won't believe these facts, because depending on which area you live in there's always plentiful appointments, in advance or on the day! Where I last lived, getting an appointment was easy, the difference in outcomes based on how wealthy or urban your area is leaves a bad taste in my mouth.
Briefly, we had a new surgery open that offered more appointments, at more convenient times of day, and we could actually see the doctor. All the other GP's started losing their patients to them. Then within a few months they were shut down by the local NHS trust, under multiple investigations (one of these investigations was regarding an offensive Facebook post by the surgery's chief, I kid you not). They then later reopened with normal appointment times and no free spaces, like all the other surgeries.
I agree with what you say re the command economy of WW2 allowing the creation of the NHS. But it was not this country that founded the NHS: it is some ancient, lost nation that seems utterly alien to me today. I don't believe we could achieve even a small version of what WW2 Britain did anymore, if our survival depended on it. I cite the UK's response to COVID19 as evidence.
Coming from Australia and previously NZ, the healthcare system here seems barbaric.
Meanwhile, if you actually need to go to the doctor for anything urgent, it is often best to go direct to A&E.
Here's some things I would love to see an alternate-history version of:
1) Vitamin D has some involvement in the immune system. The US Department of Health[1] says "Your immune system needs vitamin D to fight off invading bacteria and viruses.". Harvard School of Publich Health says[2] "laboratory studies show that vitamin D can reduce cancer cell growth, help control infections and reduce inflammation", "a large meta-analysis of individual participant data indicated that daily or weekly vitamin D supplementation lowers risk of acute respiratory infections"
2) The UK NHS page on Vitamin D does not mention immune function at all[3] but does strongly imply that everyone in the UK is deficient during winter when it recommends "since it's difficult for people to get enough vitamin D from food alone, everyone (including pregnant and breastfeeding women) should consider taking a daily supplement containing 10 micrograms of vitamin D during the autumn and winter."
3) The Harvard page linked earlier says a randomized controlled trial with 340 Japanese school children given either Vitamin D or a placebo, the Vitamin D group had 40% fewer flu infections in winter.
What do we know about COVID? It's an infection, it's expected to be more prominent in winter, some of the knock-on effects are to do with inflammation of tissues all around the body - lung, heart, brain, nerves.
So, would anything have played out differently if during the early days of no vaccines and no effective treatment, the NHS had leaned hard into Vitamin D testing and supplementation? Anyone presenting to a doctor or hospital or care home of any kind for any medical problem gets a routine blood test for VitD levels as well, any blood tests happening for anything also test for VitD levels, high risk people picked out specifically and called for testing, generic supplments freely available from GPs and pharmacies even without prescription using the NHS's large scale buying and negotiating power, anyone found deficient given a strong dose or large injection to start with, public relations push for the public to supplement or get checked, kept up all through the year leading into the first winter. Would it have made a difference to the ease of it spreading, to the amount of dead people, to the amount of hospitalized people, to the amount of long-term complications, would it have flattened the curve, helped the NHS, reduced or eliminated the lockdowns?
I am indoors most of the time, but I eat a lot of the recommended vitamin D foods - dairy, eggs, red meat, sardine, mackerel - and still had 'severely deficient' levels the first time I paid for my own test out of my own curiosity[4], and then 'insufficient' the next time.
That seems like the kind of thing a "national health service" would be well placed and incentivised to do, whereas a for-profit expensive-pills-and-surgery-and-insurance-profit "service" isn't.
[1] https://ods.od.nih.gov/factsheets/VitaminD-Consumer/
[2] https://www.hsph.harvard.edu/nutritionsource/vitamin-d/ (click to expand the 'immune function' section)
[3] https://www.nhs.uk/conditions/vitamins-and-minerals/vitamin-...
[4] (by a UK NHS lab, one which doesn't sell supplements so it's not incentivised to report misleadingly low figures)
Governments also do development off-shoring just as well as any company with a large off-shored project.
The kind of project people are talking about here never works. It doesn't matter who is doing it.
Here's the call for tenders: https://etendering.ted.europa.eu/cft/cft-display.html?cftId=...
And here's the award: https://ted.europa.eu/udl?uri=TED:NOTICE:120998-2022:TEXT:EN...
Some interesting things:
1. This is a broad framework contract for marketing, for the eye-watering amount of 300 million euro. The title is "Belgium-Brussels: Framework Service Contract for the Organisation of Large-scale Travels of Participants in the Context of Erasmus+/DiscoverEU"
The reason they do these kinds of framework contracts is because the legally required tendering procedures surrounding government contracts are so onerous that it's better to do a broad contract once and bundle a lot of projects inside of them, than to have one contract per project.
2. The executing party (Caracal) is nowhere to be seen, instead the contract is awarded to EURail and MCI.
EURail is the intermediary I suspect, responsible for navigating the wild world of government contracting, and MCI is a marketing agency. They have no doubt built up years of expertise in how to successfully navigate these kinds of tendering procedures, and they probably are not the lowest bidder. Caracal is no doubt subcontracted by MCI, but as MCI is a private company we cannot see how much they were paid or how they were selected. So much for transparency.
In my own experience in government contracting, price is a factor but usually not the largest factor. There's a large set of requirements (which you can read through if you follow the first link), and the ability to prove that you will be able to meet them is mostly what determines who wins the contract. However, because it is so difficult to know how to do that, only a few parties will have submitted a tender, and the best of a poor batch may still not be very good.
Personally I think this kind of public procurement legislation is well intended but ultimately flawed. It does not result in lower costs, faster turnaround, better transparency, or overall better government. I'm in favor of transparency rules, but they need to be a lot more thorough and they need to cover subcontracting as well. I'm against public tendering legislation, as I think it prevents the government from being efficient.
(By the way, how awful is that public tendering website? It's like a flashback to 2003. No doubt built under one of those big framework contracts.)
How many applications do we create that all do exactly the same thing? Payments, customer details, tasks, shopping baskets, items for sale etc. and how many times have we rebuilt all of that from the ground up with all the risks? Even if we know what we are doing, it is easy enough to forget something, for someone who didn't know what they were doing to build part of it, to cost enormous money to plumb together a tonne of bespoke parts.
I think the solution is 1) We need much better regulation of who has the relevant skills to do work to the required standard, we still allow untrained and unqualified people to build banking apps etc. 2) We need to create something that allows us to possibly certify implementations of standard functionality so they can be used to create standard applications, just like Peugeot might buy engines from Toyota that they know already work.
We talk about freedom of thought and creativity but the price of reliable and trustworthy software is probably only going to come by establishing a much higher level of quality - hopefully minus some of the BS you get with some accreditations.
The market already boasts software solutions that are more or less ready-made, precisely catering to your described needs, particularly concerning areas like payments.
However, governmental entities abstain from employing such software, as their provider selection process deliberately embraces a convoluted nature to sidestep any hint of impropriety.
Thus, the government contracting industry flourishes—a cohort proficient in maneuvering through the intricate channels of governmental procurement. Most private enterprises that excel in providing top-tier services opt out of engaging in this government contracting labyrinth because it's not worth the headache. It involves an assortment of antiquated procedures and certifications that the private sector seldom finds worthwhile to partake in, as they exclusively pertain to the realm of government contracting and are often accompanied by a disheartening degree of bureaucratic rigmarole.
Deciphering a pathway towards resolving this predicament would transcend the mere realm of overhauling regulations; rather, it necessitates the overhaul of modern bureaucracy and solving the arduous struggle government faces to keep pace with fast-evolving fields like technology.
Basically: Good luck with that!
However (at least in the few governemnt bids I've been involved in) if the low bidder does not get the award, they can challenge the award and often do. Then the government has to defend their decision and give the reasons the low bid was disqualified.
Good luck with that. It is prejudiced discrimination because you assume that if the bidder never did a contract like what you're looking for, they will not be able to do it.
It would be just like you don't want to hire a junior because they never worked before :)
In it Jennifer Pahlka, a high ranking US government official who worked on heathcare.gov and other digital government projects, talks about her book that is about why most of these projects go as poorly as they do. Quite illuminating...
Trains are overbooked with free tickets and promotions (free pass for entire summer for 50 euro). While underlying infrastructure is not ready for such load. It leads to delays and mistakes. Plus railway stations in Germany look like homeless shelters!
On other side Germany has excellent motorway network. Flixbus is very cheap, quite comfortable, goes all the way to airport, and always on time!
Flixbus is 50€ cheaper when traveling that route tomorrow but that's about all it has going for it.
Planes? At least an hour, and if you cut into that, and the queues or security theatre more mind boggling than normal, you’ve missed your flights.
Eurostar is similar to airports, so I’m glowering at them too!
Doesn't distract from the point that long distances busses are very much not an alternative to rail (or planes for that matter) unless price is the deciding factor. And even the latter is questionable in many cases thanks to the 49€ ticket.
The other day my mother tried to buy a train ticket. The payment went through, but something went wrong on the site and the ticket was not issued.
If this were just some e-commerce site, the payment provider would have had their head on a spike.
In this case she had to go through the usual return process.