HACKER Q&A
📣 jjgreen

Cause of UK e-gates outage?


A Bank-holiday weekend in the UK, the passport-control system (e-gates) goes down and all passports have to be checked manually, so huge queues etc. I'd assumed an unwise Friday deploy, but the press says the issue is "too sensitive to discuss", eg: https://www.bbc.co.uk/news/uk-65731795

Anyone with inside information they'd like to share?


  👤 btc-ln-ftw Accepted Answer ✓
Re: e-gates shambles

Fujitsu's contract runs from 4 September 2021 to 2024 https://www.theregister.com/2021/09/09/fujitsu_border_crossi... https://www.theregister.com/2022/01/14/uk_border_upgrade_con...

Re: Horizon disgrace

Fujitsu has also, so far, escaped financial penalties, whereas the government has been forced to set aside £1bn to cover the costs of compensating victims of the scandal. Meanwhile, Fujitsu is continuing to win significant IT projects with the UK government. https://www.computerweekly.com/news/252526102/Fujitsu-to-fin...

UK Gov & Fujitsu smells bad


👤 Nextgrid
Underpaid third-world slave working for whatever shitty consultancy got the contract pushed the wrong button.

It's "too sensitive to discuss" because it would be inconvenient to admit that the people who have privileged access to this system aren't paid enough to give a shit and are very vulnerable to bribery.


👤 yellow_lead
Too sensitive to discuss can also mean too embarrassing to discuss

👤 the-golden-one
No idea but I’m gonna go for expired TLS cert, and Finance won’t let you have the corporate card to renew it until Monday when the approver is back from holiday.

👤 danpalmer
No insight here, but I've always wondered if the e-gates are doing anything "clever" with the camera, or if they're just connecting you to some call-centre in Swindon where your face and passport details pop up in front of someone with a lot less training than traditional border security.

It might be doing facial recognition, but it feels too reliable for the level of facial recognition I expect a consultancy could pull off in a government contract.


👤 PaulAJ
Nothing specific, but I've seen some big systems from the inside, and I know the kind of thing that leads to failures:

* Back in the 60s they got a big IBM computer to do some stuff. Then later on they needed to do other stuff. The old computer was too expensive and difficult to replace, so they got a new VAX or something to do the new stuff and talk to the old mainframe. Then some PCs got added to do more stuff, and so on. Today the back end consists of many different systems of different ages all talking to each other using different protocols that were designed against different requirements. Newer systems are forever being patched and updated to cope with new requirements, while the code for old requirements lurks waiting to be accidentally reactivated. Each of these systems has its own specialists for care and feeding, but nobody fully understands the whole thing. When something goes down there are not many people who can diagnose the fault and get it back up.

* Government contracts have lots of rules around them to ensure value for money and prevent corruption (see the UK COVID PPE fiasco for what happens when you try to cut these rules out). But the size and complexity make even bidding for a big contract very expensive and complicated, so it tends to be the preserve of a few big companies who chose to specialise in it. Their core competence is winning these contracts, not delivering on them later.

* These rules mean that everything has to be specified in detail up front, so that everybody knows what is supposed to happen. But this makes the whole thing horribly inflexible. As new requirements emerge from the woodwork there is a continuous process of renegotiation.

* The UK civil service is based around the "cult of the gifted amateur". Senior managers are rotated around departments every few years. So the person who kicks off a project is rarely the person who sees it through. Everybody gets to blame someone else for failure.

* When one of these big contractors fails to deliver, the Government has to chose between suing to get their money back (or some of it) in a few years, or getting the at least part of the system they actually need at a higher price. The government doesn't need the money, it needs the system. So the contractor gets to carry on regardless of failure.

* Humans are very bad at managing small risks with large consequences. Many big disaster stories have at their heart someone who decided that the risk was too small to be bothered with.


👤 noodlesUK
I’m not sure if all the gates are by the same vendor, but at least one of them is vision-box[1]. My suspicion is there’s a backend system on the Home Office’s side that went down. The ICIBI did an assessment of the epassport gate system recently, detailed here [2].

[2] https://assets.publishing.service.gov.uk/government/uploads/...

[1] https://www.vision-box.com/


👤 c7DJTLrn
Some pod in CrashLoopBackOff somewhere.

Nah, just kidding, but the fact that it's country-wide indicates it's probably a server issue.


👤 switch007
There was an issue with France’s system too at Dover. It wouldn’t be tin foil hat territory to suggest a coordinated cyber attack.

I wonder who has snuck through the chaos. UK border control regularly fails when the systems up, god knows what about when they’re down


👤 etothepii
Probably the Lazarus group.

👤 raverbashing
I'm not sure why this should affect holidaymakers, if I remember correctly passports are checked on the way in, but not when going out of the UK correct?

👤 hankchinaski
“Too sensitive to discuss” very likely mean cyber attack

👤 jonathantf2
These things have never worked for me, the camera goes up and down like mad for a minute then I have to go and see a person. What a waste of time

👤 IshKebab
They probably found a stupid bug. Like it doesn't check expiry dates on passports.

👤 jimbobthemighty
Maybe they bought an upgrade from someone who donated to the CONservatives?