Live data from Hacker News

Inside the Obama Tech Surge as It Hacks the Pentagon and VA

backchannel.com

81–90 of 148 posts

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#81

Earlier quoted context omitted.

Disclosure: I'm an engineer at USDS and these are my own opinions. So in my admittedly short time in the government [0], I've witnessed how all of these problems are due to good intentions. That's what makes this all really tough because everything you think is bonkers actually has a reason. The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rul…

> every single issue that comes up results in a new rule. This sentence is the simplest explanation for government (and bureaucratic) incompetence. Think about writing software. Is the optimal solution to every single bug to write more code to deal with that specific situation? Of course not. In many cases, sorting out the underlying cause and fixing that (which may involve new code, rewriting old code, or even delet…

Funnily enough, it turns out that collections of humans interacting isn't like software.

Go figure.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#82

Earlier quoted context omitted.

People are pretty sensitive about government financial workers committing fraud, similar to how they are rather sensitive to government police committing murder.

Sadly, in neither case will you ever have 100% compliance. Pretending it's achievable, and trying to achieve it, is IMHO, silly. Remember the regulations do not prevent fraud, enforcement prevents fraud. There already exist plenty of things saying it's not okay, etc. Saying "and also, don't do that" is probably not actually necessary most of the time, in the same way saying "don't shoot people" is sufficient. Saying…

I don't think we can take this much further without knowing what's actually in the regulations, but I imagine they consist more of "officer's dash cam will be run 24/7 and backed up in triplicate", "officer will learn proper gun handling techniques X, Y, & Z", etc rather than "don't shoot people", "don't shoot handcuffed people", "don't shoot clowns", "don't shoot children".

Or, in the fraud case, "books will be audited at frequency X", "Y behavior makes it too easy to hide fraud and is not allowed". Rather than "fraud is illegal on Monday", "fraud is also illegal on Tuesday", "fraud is even illegal on holidays"...

Of course we can never achieve 100% with more regulation, but we make it more of a priority to make abuse harder to get away with than elsewhere, presumably increasing overhead in exchange for lowering abuse (yes, this is probably not a strictly linear curve)

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#83
post #76

Earlier quoted context omitted.

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

This is analogous to adding code to cover security issues. 99.9% isn't good enough when people are actively looking to exploit the 0.1%.

But unlike security issues a single failure doesn't compromise 100% of the rest of the system. This is also why analogies between software/security/cryptography/privacy and the tangible world are so awkward.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#84

Earlier quoted context omitted.

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

People are pretty sensitive about government financial workers committing fraud, similar to how they are rather sensitive to government police committing murder.

I don't think that necessarily has to be the case. The public conversation could conceivably shift to a cost/benefit analysis of varying levels of enforcement vs. fraud, if only the media would cooperate.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#85
post #76

Earlier quoted context omitted.

This is analogous to adding code to cover security issues. 99.9% isn't good enough when people are actively looking to exploit the 0.1%.

But unlike security issues a single failure doesn't compromise 100% of the rest of the system. This is also why analogies between software/security/cryptography/privacy and the tangible world are so awkward.

Fraud prevention actually is a security issue. Not an Internet security issue, so mistakes aren't punished that quickly, but the analogy is still sound.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#86
Unfortunately, there's quite a bit of misinformation in this article.

The author makes it sound as simple as hiring fresh hackers from Silicon Valley to take over failed projects from stodgy software developers from the large D.C. contracting firms.

Having worked on government projects like those cited in this article for several years, I can tell you that it is the government agencies themselves, and not so much the developers who are to blame. To build a cool iPhone app for a private service, you can pretty much use whatever tools and timetables you want.

Not so with government tech. With even small projects, you are beholden to policies that were written several levels up. Things like no cloud-based hosting, no sites that don't use government-written style guidelines, and in many cases, no development that occurs outside the government facility. If you hamstrung pretty much any private tech company with the same restrictions government contractors have to deal with, I can guarantee you they would look a lot different.

That's not to say that change can't occur, but to attack the contractors is to misunderstand the root cause of why government software is historically so bad. There are actually many, many very talented developers and software engineers steeped in the latest lean startup theories inside the beltway, but they can seldom use any of that because government policies stand in their way. For most projects, you are dealing with literally thousands of regulations throughout the development process, and most software apps have to account for ever-changing laws and policies that are specific to each application.

However I have already seen a great deal of positive change, with many agencies opening their minds to newer, faster methods of development and allowing better tools to be used.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#87
post #37

Earlier quoted context omitted.

Mmmm, I've been through the process and gotten an offer, and it wasn't that far off what the industry standard is (and honestly beats regular DC rates). They're really solid overall. Granted everyone's got their own experiences, so YMMV I guess. Just curious where your data comes from?

I read (sorry I don't recall where) a comment on GS levels for USDS. It was like half my current income. Perhaps I should just apply and find out for sure though.

https://www.usds.gov/join#compensation

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#88
post #85

Earlier quoted context omitted.

But unlike security issues a single failure doesn't compromise 100% of the rest of the system. This is also why analogies between software/security/cryptography/privacy and the tangible world are so awkward.

Fraud prevention actually is a security issue. Not an Internet security issue, so mistakes aren't punished that quickly, but the analogy is still sound.

Someone buying a new watch with their expense account doesn't suddenly give them access to the whole treasury -- that's the difference between physical and digital realms I am trying to emphasize.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#89
post #54
post #7

The federal government hires a team of young, talented, motivated engineers and managers, puts them in charge of failed software projects, gives them the resources and authority they require to turns things around, and -- surprise! -- it turns out they do a GREAT job. In hindsight, this shouldn't be too surprising. What might be surprising is that the same logic should apply to ALL government functions, not just soft…

> Who says government projects and agencies have to be poorly run? I'm not sure how to test this empirically, but it's always seemed to me that these are the inefficiencies that emerge with scale and incredibly broad objectives—and that the federal gov't actually does a decent job considering. Remind which company has 320m consumers, annual revenue of 6.7 trillion, and 2.8m (non-uniformed) employees? The federal gove…

This is an argument for refactoring into smaller modules. Decentralization. Local and state government taking on more responsibilities, with the added benefit of forcing competition and choice among citizens vs. one-size-fits-all policy.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#90

What I would love to see is an 18F-like organization that creates open source software that helps user-facing government organizations at the state and local level. All of these things should be simple but (typically) are not: * Paying a utility bill online * Registering to vote * Finding out how to get from place to place using public transportation * Paying for public transportation passes * Signing up for unemploy…

I'm an engineer at Code for America - https://www.codeforamerica.org/ - a non-profit that does this kind of work with cities, counties, and states.

Its still pretty early days for civic technology. I think we'll see tech provide all the services you listed, eventually. It'll probably be a mix of outside vendors and local governments running their own engineering teams. There are still some legal barriers in the way, procurement for example.

Its happening, just slowly.

If you are interested in speeding up the progress of your city, I'd recommend checking out if there are any civic tech volunteer groups near you. https://www.codeforamerica.org/brigade/

Post reply on HN