Live data from Hacker News

The People's Code

code.gov

181–190 of 203 posts

Re: The People's Code

#181

Earlier quoted context omitted.

No effort towards innovation would then go into that sector. Ever again.

I, as a taxpayer/legislator, can't contract a private company to (for a token fee) write and support a codebase that they will (as part of the contract) open source? The people win, as we get open source and hopefully transparent code. The company wins, as they're paid for their work (as they should be). I fully expect that this would be more expensive than closed source. (I'm not convinced that we should be using el…

Well, ostensibly, given enough time, we'd end up with a single code base, where the modular add-ons are really just about user interface, similar to how every county in the U.S. does their own ballot layout. In the old days, pen and paper could be considered to be a single code base. If you get the basic thing to do right, it's a choice, not a necessity, to have different code bases that do the same damn thing.

So eventually it would be less expensive than closed source, to implement and maintain. Basically wealthier and more ideologically committed states would subsidize that reference implementation, and the rest of the country, should they adopt that open source reference, would get to use the code more cheaply.

From a global perspective, there's a pretty decent chance a huge chunk of the code is already done - i.e. it could use the Linux kernel with a bunch of its more extraneous modules disabled. A handful of math libraries. A handful of UI libraries. And then a code signing mechanism from stem to stern. There's a lot more to it than that, but code wise, a bunch of it might already be written, the work is not innovating ducks but getting them in rows, and documenting it in a way that it's reproducible and ideally only boots up when it's exactly conforming to the spec.

Closed source with multiple competing companies nationally by definition means many different code bases all in different maintenance states. It really is wheel reinvention over and over again.

Re: The People's Code

#182
post #154

Earlier quoted context omitted.

Whether it's relevant or not is up for the project maintainer to decide. All anyone can do is point out what they perceive as a potential problem, and then let the others take it from there. CiPHPerCoder didn't exactly do that. He came out guns ablaze from the start, using bolded text, italics and inflammatory phrasing - basically just stopping short of calling the project maintainer a complete idiot. It's not surpri…

> It's almost like CiPHPerCoder is personally offended that some joe random developer hasn't heard about some obscure CVE CiPHPerCoder was involved with, or that they didn't handle it like he would like. "Do you know who I am!?" Except this isn't "some joe random developer", this is software created by and for the US government, which is featured on code.gov. I'd expect them to take security seriously and apply all u…

Perhaps if you didn't act like a jackass when reporting bugs, you'd have better interactions, and get less of the "burn out" feeling you're describing.

And next time you decide to put on a show, consider not doing it under your company name.

You're forgetting this arrogant display is here for all to witness, including folks who may (or may not, now) want to contract your company in the future. You also seem to forget the very folks behind code.gov are the same ones that influence who gets contracted with the government...

The people working on code.gov and all of the repositories are truly doing something great. Code has been in the federal government for at least 60 years, probably longer - and this is the first time something like code.gov has been produced. It's an amazing effort, and it's surely not easy to effect change like this at the federal level.

The open source initiative will help increase code quality at the federal level, as well as encourage less duplication of efforts (different agencies likely solve similar or the same problems very often). It also encourages a baseline standard of code and organization. This is a fantastic beginning!

Next time, a simple "Hey, did you guys know about CVE-2015-2171? You may have some vulnerabilities." is all that's needed. Instead, you let everyone know you were in a fit of rage - how dare someone suggest you comment on an issue you brought up!

We need to encourage and support these efforts, not shit all over them.

In short, don't be an ass... please.

Re: The People's Code

#183

Earlier quoted context omitted.

Oh yes, I don't discourage it. I just think that you can't be satisfy with it. Open source voting machine are still an abomination for the democratic process.

remind me again how the open-source part makes anything worse than a standard voting machine?

I think it's an electronic voting machine in general. There must be a paper ballot trail. The absolute best setup for voting is the scan-tron style paper ballot. Immediate confirmation, quick and continuous vote tallies, errors are very rare and it includes a paper trail.

Re: The People's Code

#184
post #182

Earlier quoted context omitted.

> It's almost like CiPHPerCoder is personally offended that some joe random developer hasn't heard about some obscure CVE CiPHPerCoder was involved with, or that they didn't handle it like he would like. "Do you know who I am!?" Except this isn't "some joe random developer", this is software created by and for the US government, which is featured on code.gov. I'd expect them to take security seriously and apply all u…

Perhaps if you didn't act like a jackass when reporting bugs, you'd have better interactions, and get less of the "burn out" feeling you're describing. And next time you decide to put on a show, consider not doing it under your company name. You're forgetting this arrogant display is here for all to witness, including folks who may (or may not, now) want to contract your company in the future. You also seem to forget…

> You're forgetting this arrogant display is here for all to witness, including folks who may (or may not, now) want to contract your company in the future. You also seem to forget the very folks behind code.gov are the same ones that influence who gets contracted with the government...

If you base your "security talent" hiring decisions the same way you approach "contract customer service representative decisions, you'll end up with very pleasant people who don't know jack shit about security. Which would explain a lot of the results we're seeing. So you might be right.

If anyone is reading this thread and wants their software to be actually secure-- no sugar-coating or letting bad decisions happen-- get in touch. :)

> The people working on code.gov and all of the repositories are truly doing something great. Code has been in the federal government for at least 60 years, probably longer - and this is the first time something like code.gov has been produced. It's an amazing effort, and it's surely not easy to effect change like this at the federal level.

For once, we are in agreement.

> Next time, a simple "Hey, did you guys know about CVE-2015-2171? You may have some vulnerabilities." is all that's needed.

OK, why didn't you do that then?

It's so easy to tell others what to do, when you have no skin in the game. What will you do next time?

  - Tell the other person what to do.
  - Do it yourself, because it clearly matters to you.
> We need to encourage and support these efforts, not shit all over them.

> In short, don't be an ass... please.

I won't be an ass if and only if folks aren't making demands of how I spend my leisure time.

Re: The People's Code

#185

Earlier quoted context omitted.

Actually, with monopsony it's rather simple: "If you don't publish the code, then we will have to use paper ballots."

No effort towards innovation would then go into that sector. Ever again.

Linux seems to be doing fine.

Re: The People's Code

#186
post #166

Earlier quoted context omitted.

Looks like the US government makes widescale use of Google analytics, so it's hardly inappropriate: https://analytics.usa.gov/

Pointing out more instances of a problem doesn't make the problem "hardly inappropriate"; it indicates the problem is more widespread.

I hear they use Ford vehicles and Boeing airplanes as well. Highly inappropriate for the US Government to use products from some of the US's biggest companies!

/s

Re: The People's Code

#187

How about open source code for some makes and models of voting machine? The US Veterans' Administration health records software system is in the public domain. https://en.wikipedia.org/wiki/VistA#Licensing_and_disseminat... But it's not listed here. (It's also kind of complex. "wget; tar x; ./configure ; make" probably won't get you a running instance. Still.

> The US Veterans' Administration health records software system is in the public domain

This was programmed by humans?

http://code.osehra.org/gitweb/?p=VistA-M.git;a=blob_plain;f=...

http://code.osehra.org/gitweb/?p=VistA-M.git;a=tree;f=Packag...

Was released after obfuscating?

Re: The People's Code

#188

Earlier quoted context omitted.

Most people can't understand the code in openssl. So we shouldn't use it? Let's just make all cryptography closed source then. The average person doesn't even know what an elliptic function is. The point is that there is a large amount of people that do. They check. Not every citizen needs to check, but it is harder for there to be an error or to hoodwink someone if there are more eyes on the code. Essentially why op…

Crypto and democracy can't be compared. You can delegate advanced science, you should not delegate democracy, because it's the root of all the rest.

Isn't delegating democracy what we do when we elect someone to congress (or parliament) to draft, debate, and enact the law?

Re: The People's Code

#189
post #168
post #66

Earlier quoted context omitted.

Smoking weed is not going to get you fired anywhere , except for the worst jobs in the worst places. Any place that does regular drug testing and/or cares one teeny tiny itsy bitsy bit about employees smoking weed when they're not working is guaranteed to be a terrible place to work at, for that and any number of other reasons. There is not a single reputable company in the entire tech industry that does this.

That is definitely not true: http://money.cnn.com/2015/06/15/news/companies/dish-employee...

I think you just proved his point.

http://cable.tmcnet.com/topics/cable/articles/2013/01/07/321...

"Out of 617 ratings on glassdoor.com, fully 246 called themselves “very dissatisfied.” The number of employees considering themselves “very satisfied” was just 48. Some comments even suggest that executive meddling may be involved in the “very satisfied” scores, with one commenter saying “Joe Clayton (CEO) put us up to upgrading our score.” Another commenter called their time with Dish “...like a prison sentence.”

Re: The People's Code

#190
post #66

Earlier quoted context omitted.

Smoking weed is not going to get you fired anywhere , except for the worst jobs in the worst places. Any place that does regular drug testing and/or cares one teeny tiny itsy bitsy bit about employees smoking weed when they're not working is guaranteed to be a terrible place to work at, for that and any number of other reasons. There is not a single reputable company in the entire tech industry that does this.

> Smoking weed is not going to get you fired anywhere, except for the worst jobs in the worst places. Do you have numbers to back this up? Because almost every place I've worked at has had this policy. I think it's a terrible policy and should be illegal, but it's been pretty standard everywhere. Maybe it's not common in SV, but everywhere else it seems to be the norm, IME.

It has never been an issue for me as I don't partake, but anecdotally, I've worked at 5-10 mid range (100-200) firms in Virginia and Illinois and while I have been provided many free beers at work, if anyone suggested a drug testing program they would have been laughed out of the building.

I even worked for a company that ran drug testing programs for the government and they did not drug test.

Post reply on HN