Live data from Hacker News

USDS Digital Services Playbook

playbook.cio.gov

101–103 of 103 posts

Re: USDS Digital Services Playbook

#101
post #73

The first point would be gamechanging. Also used to do govt work. I'm sure everyone has stories. My takeaways. 1) Understand what people need -> AND LET THEM DO IT. 2) DO NOT ADD A SINGLE NEW THING with the IT / automation. If the old system doesn't have it DO NOT ADD IT. No 20 extra fields for demographics if you didn't track that before. That can be added later IF it's a MUST. If they would take away all various fi…

> The IT folks say that passwords have to change every 90 days This is explicitly not the NIST recommendation (the group in gov that sets some security standards), but the word is not getting out quickly.

For a long time this must have been on the recommendation list - because password forms with insane complexity (12 charachters, upper, lower etc), but then non copy pastable forms and 60 day change requirements remained very common.

The current IRS requirements are 90 day password changes. Ergo - many people write their passwords down in a text document next to the software launch icon.

What I don't get - if your computer is hacked, and you force people to write down their passwords on the computer being hacked, they will even more easily be able to access the systems you have access to.

Google seems to get this right. I have had same password for 20 years, if I login with a new device I use my MFA (no SMS). If I do a security sensitive op I need to login and do an MFA again (password reset etc). I imagine they actually monitor and rate limit bad login attempts etc. A 10 character password is really fine then in my view as an example.

Re: USDS Digital Services Playbook

#102
post #97

Earlier quoted context omitted.

What would be nice is if these government jobs had training. The military can take someone from the street and make them a specialist in something. If USDS could take someone and make them into what they needed, the lower salary might be better justified.

I could not agree more. If the USG wants to provide competent digital services to it's customer/shareholder then it might make more sense to get rid of the Digital Service in the WH and rather expand and go all in on 18F, where it provides a whole career progression from basic training on up through SES. I feel the absence of job training upon hiring is also why there is no concept of "company men" after the Boomer G…

Are you sure 18F offers whole career progression? I looked at their website and they only seem to be hiring GS15. I don’t see any mention about training.

https://join.tts.gsa.gov/

Re: USDS Digital Services Playbook

#103
post #97

Earlier quoted context omitted.

I could not agree more. If the USG wants to provide competent digital services to it's customer/shareholder then it might make more sense to get rid of the Digital Service in the WH and rather expand and go all in on 18F, where it provides a whole career progression from basic training on up through SES. I feel the absence of job training upon hiring is also why there is no concept of "company men" after the Boomer G…

Are you sure 18F offers whole career progression? I looked at their website and they only seem to be hiring GS15. I don’t see any mention about training. https://join.tts.gsa.gov/

I'm sorry, the wording of my comment might be confusing.

> go all in on 18F, where it provides a whole career progression from basic training on up through SES.

should read

"go all in on 18F so that it can provide a whole career progression from basic training on up through SES."

You're correct, as far as I'm aware 18F, or any other government org that isn't the US military, does not offer actual training.

Post reply on HN