Data cleanser did its job, but – oopsie! – also doubled customers' bills
- Reference: 1687159753
- News link: https://www.theregister.co.uk/2023/06/19/who_me/
- Source link:
This week we are once again joined by semi-regular raconteur "Bernard", who told us a while ago about a [1]prank that he had played on the auditors at his place of work. The Reg does not recommend playing jokes on auditors any more than we recommend annoying spiders or giving your bank details to anyone selling NFTs. It might be fun for a while, but eventually the consequences will become unpleasant.
Anyway, at the end of Bernard's story, we wondered wistfully what might have happened the next time Bernard came under the withering gaze of the auditors. This is that story.
[2]
It happened about a year after the jolly jape with the wet PCs, and Bernard had been tasked with modernizing the banking system for the local government authority. You see, banking data was all couriered about by people on motorcycles with sacks full of magnetic tapes. Much could go wrong.
[3]
[4]
Bernard set up a PC with a dial-up modem and a four-step validation procedure – this is banking you know, and things have to be secure.
Some test data was obtained from the old system and run through the new system. Unfortunately there were some errors, but nothing a whizz like Bernard couldn't overcome with a filter program to ensure that data passed to the system was clean and could be validated.
[5]A toast to being in the right place at the right time
[6]Fed up with slammed servers, IT replaced iTunes backups with a cow of a file
[7]Seriously, boss? You want that stupid password? OK, you get that stupid password
[8]Rigorous dev courageously lied about exec's NSFW printouts – and survived long enough to quit with dignity
So data came in, went through Bernard's filter into an "interface file" which was then passed on to the PC which directed it to where it needed to go. It either went to the "Creditor" account (for stuff the Council had to pay) or the "Debtor" account (for stuff people needed to pay Council).
Trust us, this excruciating level of detail is necessary.
[9]
The first month's banking went through, and all appeared to be well. Everyone was paid, everyone was happy.
In the second month, chaos reigned. While the outgoings were fine, the incomings were causing problems. Residents' payments were effectively double what they should have been and, understandably, this did not make them happy and some were not afraid to say it.
As the torches and pitchforks appeared around the local government authority at which Bernard toiled, auditors asked if he could possibly explain what had gone wrong.
[10]
Well, it seemed, his clever filter was catching all of the mistaken data and cleaning it up before passing on to the interface file. But it didn't actually have a procedure to clear itself.
That would obviously have to be fixed, but in the meantime there was an angry mob approaching and Bernard had to convince the banking team (who had only recently been convinced that doing all of this over a modem would be better than doing it with mag tape) to reverse a whole bunch of transactions and pay money out of the Debtor account, which was only supposed to have money going in.
Once the smoke had cleared, a tense meeting with the auditors took place. Bernard argued that his task was to ensure the data in the interface file was valid – not that it was correct. The mainframe team argued that their job was to ensure that the interface file was full – not that it got cleared afterwards.
So whose job was it to ensure that the filter was actually cleared between uses? Everyone's answer seemed to be the same: Who, me?
Eventually Bernard "added a hash-total function to the interface filter and exceeded his authority by instituting a security check procedure to match the sender's hash-total to what was about to be transmitted" which, apparently, fixed things?
OK then.
Have you ever found yourself creating a problem by fixing a problem and then having to fix more problems ad infinitum? We'd love to hear about it in [11]an email to Who, Me? Tell us and we'll tell the world. ®
Get our [12]Tech Resources
[1] https://www.theregister.com/2023/04/24/who_me/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJAnQYo5-qOqWS2IkcX2LAAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJAnQYo5-qOqWS2IkcX2LAAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJAnQYo5-qOqWS2IkcX2LAAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/06/12/who_me/
[6] https://www.theregister.com/2023/06/05/who_me/
[7] https://www.theregister.com/2023/05/29/who_me/
[8] https://www.theregister.com/2023/05/22/who_me/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJAnQYo5-qOqWS2IkcX2LAAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJAnQYo5-qOqWS2IkcX2LAAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] mailto:whome@theregister.com
[12] https://whitepapers.theregister.com/
The money was just resting in his account.
That would be an ecumenical matter!
Card Payments
When the developers implemented a payment processor into the EPOS - what they didn't do is implement the refund correctly and basically whenever the system did a refund it sent a payment request instead - hence customer got billed twice, but as this was well before Online Banking it left a lot of unhappy customers come statement day. (Glad to say this isn't a who me as I was told when fixing the unreliable mess they left)
Oh, I remember PC front ends to Mainframes
Back in the early 1992 the UK Pharmaceutical Wholesalers each had a separate order entry terminal that was supplied to Pharmacies wanting to buy from them. As was the fragmented supply chain at the time, I personally saw a Pharmacy with 5 order entry terminals to order the various drugs from the different wholesalers. (4 of the 5 were Epson PX-4 laptops and so they were stacked in a pile next to the PC used for the other wholesaler, in a very small office.)
I decided with one of the wholesalers to try and tidy this up a little and also deal with a mainframe that needed Viagra it was having so much problem with up time!
Cue a single program on the PX-4 to talk to all wholesalers and a PC front end to the mainframe to accept all the wholesaler's protocols. (Yes, it was hacking the protocols used over the modems, including different number of bits and parities (or none). Nobody minded a White Hat then.)
The solution had 48 serial ports on the 486SX to talk to the modems and buffer these (with stale stock status replies to the Pharmacies) when the mainframe took its regular excursions from working. The commissioning wholesaler also wanted the receiver software to run as a TSR (he'd seen the description of a TSR in a PC magazine and would not be persuaded), as he also wanted to use the PC as (effectively) a print server, (but with document transfer by floppy disk.)
Ahhh... the simpler times.
One can only wonder... which pocket that money really has flown into before the "fix" and how much of it actually found its way back?
You know, skimmer by accident, the best possible accident accounting for future Friday beers ;-)