678 karma · joined September 17, 2015
The reform and merge into InfraGO with government funding is supposed to help fix that, but there's a massive backlog.
Text in full:
> There have been drastic price increases in various areas in the IT branch recently. That is why, unfortunately, we must also increase the prices of our products.
> The costs to operate our infrastructure and to buy new hardware have both increased dramatically. Therefore, our price changes will affect both existing products and new orders and will take effect starting on 1 April 2026.
> We have genuinely tried hard to optimize our costs and to prevent increasing our prices for as long as possible. But we can no longer compensate for the strain that it has placed on our operations. We want to continue to deliver quality products that meet both our standards and your expectations, so we must take this step.
> The price changes take effect on 1 April 2026 and are for both new orders and existing products. There is list of affected prices on Hetzner Docs at https://docs.hetzner.com/general/infrastructure-and-availabi....
The spoofer could have just sent them fake location information drawing an image using latitude, longitude and altitude for color (in the default view flight paths have different colors based on the altitude of the plane at that point in time).
They could have built an antenna and actually broadcast this data, but that would be a lot more effort and most likely some form of crime.
Projects are planned, coordinated and funds allocated far in advance, so if the government can't agree on a budget and projects are shelved or canned, restarting the process causes a significant delay.
-the ID card which trusts the government PKI and has its own private key and certificate
- the application that does some certificate checks and facilitates communication between the card and an eID server
- an eID server which is connected to the PKI and regularly received short lived certificates to present to the card, does revocation checks, validity checks and a bunch of other stuff. Also provides a list of fingerprints of TLS certificates of eID services allowed for the session
- an eID service which opens a session with the eID server indicating requested data and ultimately receives this data from the eID server. They own the legalese certificate of which data they have access to.
- maybe another provider wrapping all this and the required certifications,. compliance and hardware into an easy to use API. But could also all be the same.
It could be argued that the government has influence on the eID server providers - which do the actual communication with the card and are the first to receive the data before passing it on - via access to the necessary PKI, but they're not directly involved in the communication.
The card communicates with an eID server via the app. This server is connected to the PKI and receives a new certificate daily-ish and also has a revocation list of blocked IDs. There's a ridiculous amount of regulation for hosting one yourself, so you get that service from one of the two or three who provide it as a service.
ID data this eID server received from the card is then sent to the eID service that initiated the session, which may either be the entity who needs it, or another service provider who wraps another set of regulation requirements and complex eID server API calls into an easy to use API for their customers.
ID data isn't actually shown to the user in the app unless it's a custom implementation that loops it all the way back from the service provider at the end.
The Deutschlandticket is only valid for up to Reginald lines and not on faster trains like IC and ICE. It's already worth it money wise for the first trip already, but only using local connections adds at least an hour per trip between those cities, plus a bunch of layovers.