Live data from Hacker News

Luca App: CCC calls for a moratorium

ccc.de

131–140 of 169 posts

Re: Luca App: CCC calls for a moratorium

#131

Earlier quoted context omitted.

It's actually "accountability" that's a big part of the problem. Government procurement is so focused on the appearance of fairness and money saving that all other goals, like actually getting something that works, take a back seat. You end up with over-specified requirements that remove the possibility of innovative or creative solutions. Providers are treated like a commodity, where it is assumed that all will do t…

This is exactly it. And to be clear, there's a good reason for it: it's to prevent corruption. If things aren't overspecified and providers aren't treated like a commodity, then it's incredibly hard to prove that a government official actually awarded a contract in a fair process, rather than just sending it over to their best friend's business. Unfortunately, nobody's really come up with any reliable process for hav…

> Unfortunately, nobody's really come up with any reliable process for having the flexibility to get good products for good value, while reliably preventing corruption.

I've seen one approach work, but it struggles to scale, as it needs technical people on the client side.

Buying "outcomes" rather than services can work well - rather than procuring a specific "specification", you buy a solution. The standard contractual framework means you are paid for delivery to tangible milestones (demonstrable value), with engineering/technical background project management team overseeing the work. You work at risk, as you only get paid for delivery. That keeps many of the charlatans away, since it's very clear you're paid for delivery, not effort. That means the headline rate is higher, of course.

Focusing aggressively on actual delivery, but also not dictating the solution means you can see suppliers compete not only on price, but also on how they'll solve the problem. This means the government client needs to understand their problem well enough to articulate it (with some of that support from a technical project manager), but they then evaluate proposals for solving their problem. This moves away from the incentives to "body-shop" low-pay graduates onto a project that a partner pitched for, as it has to actually deliver.

I tend to see the "worst" projects (in terms of non-delivery, large bills incurred, poor value, and the only output being a report recommending more work) come about when the government client doesn't understand their own problem or goal though, so perhaps this approach self-selects problems where the customer can actually articulate their need.

Re: Luca App: CCC calls for a moratorium

#132
post #89

Earlier quoted context omitted.

I've seen authorities like this "not consulted" deliberately, on the basis that there's a more expedient need for the product, than for the product to be secure. If the experience of the procuring department is that "BSI finds everything is insecure", then you procure without letting BSI know or have a say in it, and then you look good for getting the procurement completed. Getting cross-department cooperation on any…

> If the experience of the procuring department is that "BSI finds everything is insecure", then you procure without letting BSI know or have a say in it, and then you look good for getting the procurement completed. Sounds plausible. Especially looking at years of (German) data protection officials recommending against using Windows 10/Office 365 in government agencies, followed by officials explaining that only Mic…

Of course it doesn't! I've yet to meet a procurement team that actually understands what they are buying. Companies like Microsoft focus heavily on "training" and "awareness" of their products and solutions - pure slideware, but speaking the right language.

At enterprise-scale, I must concede that Microsoft have a really sleek sales pitch. Group Policy in AD offers a level of "managed desktop" that a low-pay, mid-skill sysadmin can operate. That lets you set and enforce "policies", and they get enforced on the computers, and this is something that entirely non-technical senior managers can understand and feel confident in.

Any OS could be used to register a vehicle title, but MS' option gives you a fleet of relatively cheap and accessible talent with an "official certification" (MCSP or whatever it has become) - governments love certifications, as it helps them de-risk things they don't understand. The clever enterprise vendors understand this, and try to ensure the market is awash with "their people". It's probably controversial to say, but governments love technology that is able to be run (by-design) by hiring mediocre people to run it. Windows Server with a shiny GUI to edit group policies and apply updates hits that spot for many organisations.

I wouldn't be surprised to find the "extremely complicated requirements" for the vehicle registration government agency are the ability to run some (procured) proprietary endpoint protection client (which probably runs everything it sees unsandboxed, as NT AUTHORITY\SYSTEM [1]), and enforce a whole host of client-side restrictions (which could easily be network-layer) to prevent people using personal email on managed devices.

[1] https://www.recon.cx/2018/brussels/resources/slides/RECON-BR... like Windows Defender did (!)

Re: Luca App: CCC calls for a moratorium

#133

Earlier quoted context omitted.

This is exactly it. And to be clear, there's a good reason for it: it's to prevent corruption. If things aren't overspecified and providers aren't treated like a commodity, then it's incredibly hard to prove that a government official actually awarded a contract in a fair process, rather than just sending it over to their best friend's business. Unfortunately, nobody's really come up with any reliable process for hav…

I'm skeptical it's even good at that intended purpose. Perhaps one could argue it prevents blatant, direct corruption, but it does little to control for large company influence and other forms of soft power. The biggest companies in this space maintain an active revolving door, which ensures that procurement policy is moulded (either consciously or unconsciously) to their process and needs over time. Even more insidi…

Yeah, I'm not sure if it prevents corruption at all. In my country public tenders are just another word for corruption.

A real example: police force wanted to get say 1000 new squad cars. One of the points in the tender was that the car's trunk has to be exactly that many litres (say 307L, don't remember the exact number). So of course, only one model of all the cars from all manufacturers had that value, and of course the only dealer who submitted for that tender won it. So it was blatantly obvious that the process was rotten from the start. But it was legal. And they (government)did it many times. And pretty much they are doing it for the last 20 years or so. So corruption is not something which you can solve easily, you need a lot of checks and balances to make it work.

Re: Luca App: CCC calls for a moratorium

#134
post #132

Earlier quoted context omitted.

> If the experience of the procuring department is that "BSI finds everything is insecure", then you procure without letting BSI know or have a say in it, and then you look good for getting the procurement completed. Sounds plausible. Especially looking at years of (German) data protection officials recommending against using Windows 10/Office 365 in government agencies, followed by officials explaining that only Mic…

Of course it doesn't! I've yet to meet a procurement team that actually understands what they are buying. Companies like Microsoft focus heavily on "training" and "awareness" of their products and solutions - pure slideware, but speaking the right language. At enterprise-scale, I must concede that Microsoft have a really sleek sales pitch. Group Policy in AD offers a level of "managed desktop" that a low-pay, mid-ski…

Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction!

Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance. Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether an employee is playing browser games all day (instead of, you know, noticing the employee's productivity dropping)?

My primary concern that those enterprise firewalls intercepting all traffic (including MitM-ing TLS traffic) regularly prevent adoption of new Internet standards. At the same time, the idea of total communication surveillance seems surreal. Image the equivalent situation 20-30 years ago: What would you have said if your employer hired a team in order to eavesdrop on every single telephone call and open every single letter entering or leaving the office?

Re: Luca App: CCC calls for a moratorium

#135

Earlier quoted context omitted.

It's actually "accountability" that's a big part of the problem. Government procurement is so focused on the appearance of fairness and money saving that all other goals, like actually getting something that works, take a back seat. You end up with over-specified requirements that remove the possibility of innovative or creative solutions. Providers are treated like a commodity, where it is assumed that all will do t…

This is exactly it. And to be clear, there's a good reason for it: it's to prevent corruption. If things aren't overspecified and providers aren't treated like a commodity, then it's incredibly hard to prove that a government official actually awarded a contract in a fair process, rather than just sending it over to their best friend's business. Unfortunately, nobody's really come up with any reliable process for hav…

> The reason it doesn't exist in the private sector

The same problem absolutely does exist in the private sector. Many of the same big government contractors are running almost the same scam on big companies.

I think this problem is more a function of the size of the organization than public vs. private.

Re: Luca App: CCC calls for a moratorium

#136
post #59

Earlier quoted context omitted.

It's actually "accountability" that's a big part of the problem. Government procurement is so focused on the appearance of fairness and money saving that all other goals, like actually getting something that works, take a back seat. You end up with over-specified requirements that remove the possibility of innovative or creative solutions. Providers are treated like a commodity, where it is assumed that all will do t…

> Government procurement is so focused on the appearance of fairness and money saving that all other goals, like actually getting something that works, take a back seat. I worked at a small 2 year college for many years. One time, my Dean I reported to was on vacation, so I had to go talk to the college president, and get him to sign a form for a $7 petty cash reimbursement for some zip ties I had bought to clean up…

A house? A modest apartment I can see, but a house seems a bit much

Re: Luca App: CCC calls for a moratorium

#137
post #31
post #29

There is so much incompetency in governmental IT/software decisions and software it's actually sad. Is it a product of smart people simply not working in this sector or corruption?. It seems from the outside to be filled with imbeciles masquerading as administrators. We need to somehow make the government way more accountable, if only there was an organization that could do that, we could call it the media.

Government IT: pays government salaries Private sector: pays more than lawyers and surgeons even if yiu never graduated college Gee I wonder where smart ambitious people will go

So this might be an element of the problem, but having been in government for 17 years (and last 5 dealing with IT), I'm not even sure this is a top 3 problem.

Against all odds, the government manages to recruit and retain people who can do good work.

The larger problem is that government seems designed to make it impossible for IT talent to actually apply their talent. Now I understand why one of Grace Hopper's most famous quotes in the Navy was "it is better to beg forgiveness, than to ask permission".

Re: Luca App: CCC calls for a moratorium

#138
post #59

Earlier quoted context omitted.

> Government procurement is so focused on the appearance of fairness and money saving that all other goals, like actually getting something that works, take a back seat. I worked at a small 2 year college for many years. One time, my Dean I reported to was on vacation, so I had to go talk to the college president, and get him to sign a form for a $7 petty cash reimbursement for some zip ties I had bought to clean up…

A house? A modest apartment I can see, but a house seems a bit much

Renting a furnished apartment can sometimes be almost as much as a renting a furnished house depending upon the area.

Re: Luca App: CCC calls for a moratorium

#139
post #133

Earlier quoted context omitted.

I'm skeptical it's even good at that intended purpose. Perhaps one could argue it prevents blatant, direct corruption, but it does little to control for large company influence and other forms of soft power. The biggest companies in this space maintain an active revolving door, which ensures that procurement policy is moulded (either consciously or unconsciously) to their process and needs over time. Even more insidi…

Yeah, I'm not sure if it prevents corruption at all. In my country public tenders are just another word for corruption. A real example: police force wanted to get say 1000 new squad cars. One of the points in the tender was that the car's trunk has to be exactly that many litres (say 307L, don't remember the exact number). So of course, only one model of all the cars from all manufacturers had that value, and of cour…

You're right in that it absolutely requires either a watchdog agency to ensure tenders are written in a neutral way before being issued, and/or a court system where losing bidders are able to successfully sue as soon as they're issued, on the grounds of the tender not being neutral.

In one country where I previously lived, there was also an "escape clause" where if there was emergency time pressure, you could circumvent the process -- so guess what? The government would "invent delays" in writing up the specifications until the last possible minute, then award the contract without a public tender because there was no time left for the tender process!

So yes, the process absolutely has to be designed with some form of oversight and without loopholes, in order to achieve the aim of preventing corruption.

Re: Luca App: CCC calls for a moratorium

#140
post #131

Earlier quoted context omitted.

This is exactly it. And to be clear, there's a good reason for it: it's to prevent corruption. If things aren't overspecified and providers aren't treated like a commodity, then it's incredibly hard to prove that a government official actually awarded a contract in a fair process, rather than just sending it over to their best friend's business. Unfortunately, nobody's really come up with any reliable process for hav…

> Unfortunately, nobody's really come up with any reliable process for having the flexibility to get good products for good value, while reliably preventing corruption. I've seen one approach work, but it struggles to scale, as it needs technical people on the client side. Buying "outcomes" rather than services can work well - rather than procuring a specific "specification", you buy a solution. The standard contract…

Problem with that is government is worst customer: don't know what they want, what they have and how to get anything done. It is very hard for companies to commit to deliverables, when incompetent department they need to integrate with doesn't play the ball.
Post reply on HN