This one of the reasons I tend to flip completely whenever I see healthcare providers and their suppliers run google analytics tags inside their logged in areas (yes, this really happens). Besides the questionable value of having such tracking inside the logged in areas (it's healthcare, they are not going to worry about their conversion rates) such information should simply never leave the premises. Better still if…
Firefox 59 to strip path information from referrer values for 3rd parties
231–236 of 236 posts
Re: Firefox 59 to strip path information from referrer values for 3rd parties
#232This one of the reasons I tend to flip completely whenever I see healthcare providers and their suppliers run google analytics tags inside their logged in areas (yes, this really happens). Besides the questionable value of having such tracking inside the logged in areas (it's healthcare, they are not going to worry about their conversion rates) such information should simply never leave the premises. Better still if…
Often they even load the script from Google, giving Google full code execution control in the web app context.
Re: Firefox 59 to strip path information from referrer values for 3rd parties
#233Earlier quoted context omitted.
Preventing CSRF attacks: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(...
This. For this you just need the origin though. There's an origin header for 10 years which makes CSRF protection so trivial yet its still not available in all browsers. Firefox can leak referer in regular mode but can't send origin? Not sure. Anyone knows a good document on when/which browser actually sends referer header?
0: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Or...
1: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re...
Re: Firefox 59 to strip path information from referrer values for 3rd parties
#234Earlier quoted context omitted.
This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…
You're not wrong - there are a lot of crappy contractor teams out there working for the government... just like in the private sector. But I've never seen a gov. contractor purposefully add analytics code. It's far more likely that one of those free frameworks, ui-kits, or fonts, benevolently provided by one of the privacy-invading Silicon Valley behemoths, ended up in the code base. Anyway, there's a good reason tha…
Federal benefits are not that lavish on an international scale. You get things that are considered human rights in other countries and a good pension.
And while the benefits may cost the government more in the long wrong, the subcontractor is still taking a profit off what they're paying developers. I'd rather tax dollars go to the actual worker than some corporation.
>Furthermore, most government projects are only a few years long. The government uses contractors because they can get rid of the dev teams when they're finished with the project. Can't do that with gov workers.
That's part of the problem though. If you're on a contract, you know you're expendable. You have no skin in the game other than doing the bare minimum to not get fired because the actual client (the government) is several layers removed from you.
And getting rid of contractors after you're done with them doesn't really add up to software. For one, many contractors work as contractors for years, moving from project to project. You can do the exact same thing in-house. Groups like 18F and USDS mean that you can move employees around as necessary.
Re: Firefox 59 to strip path information from referrer values for 3rd parties
#235Earlier quoted context omitted.
This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…
TL DR of what you wrote is basically Government doesn't know what it is doing and can't be bothered to change. If that is the case I doubt if there is anything you do can change that unless you held Government accountable for it.
When there's a subcontractor involved though, there's an additional profit motive involved as well as requirements legislators set up to maximize the profit for the subcontractor.
It also means requirements need to be written out in advance and in a way that may not be optimal. When you're working between employees of the same organization, that's a lot less of a problem, at least as long as legislators don't put plenty of hurdles up.
Re: Firefox 59 to strip path information from referrer values for 3rd parties
#236Earlier quoted context omitted.
This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…
> (as no one needs to run their own data center). That can be extraordinarily expensive once it leaks out that classified government data is in the hand of uncertified third-party cloud in some other nation, and you have to rush and pay twice or three times more in order for the contract to be changed and now have local certified supplier. This is what happened here in Sweden in equivalent departments for the DMV, wh…
>IBM took over the agency's IT operations, and "IBM used subcontractors abroad, making sensitive information and an entire database of Swedish drivers’ licences accessible by foreign technicians who did not have the usual security clearance".
IBM used subcontractors, which is the profit maximizing stuff I'm talking about. When you pass stuff off to a for-profit corporation, they're going to do what they can to maximize profit, even if it screws the government over, because people will blame the government, not them.
>When the cost go up by 200%-300%, suddenly the idea of running your own data center sounds much cheaper. It ended up being the highest single cost the departments had, excluding salaries and rent. you can get quite a nice data center for those billions.
The costs never were lower though. They just looked lower on paper because the bill was less. But they weren't actually getting what they paid for.
There are already cloud providers certified for government use (at least in the US). But you don't need to pay a company to pay some other company. Government employees can do that fine.