Live data from Hacker News

Inside the Obama Tech Surge as It Hacks the Pentagon and VA

backchannel.com

71–80 of 148 posts

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#71

Earlier quoted context omitted.

Disclosure: I'm an engineer at USDS and these are my own opinions. So in my admittedly short time in the government [0], I've witnessed how all of these problems are due to good intentions. That's what makes this all really tough because everything you think is bonkers actually has a reason. The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rul…

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

The problem is, once the government chooses to not close a known loophole, the number of people who exploit it may increase by orders of magnitude. Without a willingness to add the other 1350 pages, you may end up with something like 70% fraud prevention, not 99.9%.

What's needed is more refactoring. This would benefit from more capacity to try different sets of regulations in parallel.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#72

Earlier quoted context omitted.

Disclosure: I'm an engineer at USDS and these are my own opinions. So in my admittedly short time in the government [0], I've witnessed how all of these problems are due to good intentions. That's what makes this all really tough because everything you think is bonkers actually has a reason. The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rul…

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

A common approach is to set a fixed amount per day for expenses based on cost levels in the country in question, and be extremely strict with extras, coupled with approved supplier lists and price ranges for the actual travel.

It "rewards" those who are prudent with extra cash, and so it certainly won't be perfectly efficient, but in return it makes it harder for those who would otherwise try to abuse the system who often will go far overboard, because any extra expensive claims can be given a lot more attention (and often will require advance approval), and it drastically cuts down on paperwork.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#73

I'm curious if anyone here from USDS or 18F has deployed Postgres in a FIPS 140-2 environment, and if so what challenges they had. The VA seems to be saying that Postgres should not be used: http://www.va.gov/TRM/ToolPage.asp?tid=5692&tab=2 contrast that with Oracle: http://www.va.gov/TRM/ToolPage.asp?tid=9&tab=2 (Don't miss the difference in tone on the "Analysis" tabs.) I'm sure some of that is due to lobbyists, bu…

Well, you can use SQLite instead :-)

http://www.va.gov/TRM/SearchPage.asp?catid=83&catName=Inform...

But it doesn't look good in general... :-( http://imgur.com/a/1ALQV

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#74

Earlier quoted context omitted.

Disclosure: I'm an engineer at USDS and these are my own opinions. So in my admittedly short time in the government [0], I've witnessed how all of these problems are due to good intentions. That's what makes this all really tough because everything you think is bonkers actually has a reason. The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rul…

> every single issue that comes up results in a new rule. This sentence is the simplest explanation for government (and bureaucratic) incompetence. Think about writing software. Is the optimal solution to every single bug to write more code to deal with that specific situation? Of course not. In many cases, sorting out the underlying cause and fixing that (which may involve new code, rewriting old code, or even delet…

That's fine in writing software - now try that in an adversarial environment.

With special interests (some of whom may be insiders working to undermine the exact fix that's needed), and you start to get the picture.

To add a bit of spice, address some things like time pressure related to elected administration-specific goals and/or election timeframes.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#75
post #69
post #7

The federal government hires a team of young, talented, motivated engineers and managers, puts them in charge of failed software projects, gives them the resources and authority they require to turns things around, and -- surprise! -- it turns out they do a GREAT job. In hindsight, this shouldn't be too surprising. What might be surprising is that the same logic should apply to ALL government functions, not just soft…

"gives them the resources and authority they require to turns things around" They probably could have given the same resources and authority to the existing staff and they might have turned things around too. It really annoys me that in so many cases the existing guys know what's wrong but are not allowed by management to do anything about it. Then management hires new people, gives them authority, and suddenly these…

Disclosure: I'm an engineer at USDS and these are my own opinions.

We are very proud to be working along side the existing agency and contracting staff. You are right that many times, they do know how to fix it and need some help from us getting management to let them do it. Some times they are skeptical, sometimes there is friction - that's all completely understandable.

Ultimately, my time in government has opened my eyes to the talented folks inside government right now and I'm proud to be working along side them. I hope you didn't get a poor impression of us and the work that is happening.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#76

Earlier quoted context omitted.

Disclosure: I'm an engineer at USDS and these are my own opinions. So in my admittedly short time in the government [0], I've witnessed how all of these problems are due to good intentions. That's what makes this all really tough because everything you think is bonkers actually has a reason. The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rul…

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

This is analogous to adding code to cover security issues. 99.9% isn't good enough when people are actively looking to exploit the 0.1%.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#77

Earlier quoted context omitted.

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

People are pretty sensitive about government financial workers committing fraud, similar to how they are rather sensitive to government police committing murder.

Sadly, in neither case will you ever have 100% compliance. Pretending it's achievable, and trying to achieve it, is IMHO, silly.

Remember the regulations do not prevent fraud, enforcement prevents fraud. There already exist plenty of things saying it's not okay, etc. Saying "and also, don't do that" is probably not actually necessary most of the time, in the same way saying "don't shoot people" is sufficient. Saying "and also don't shoot them while they are handcuffed" isn't necessary. Crappy post-justification does mean the regulation was written wrong, and changing the regulation to account for the post-justification will not actually improve the process most of the time.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#78
post #71

Earlier quoted context omitted.

"The 1400 page travel regulations is a result of trying to prevent fraud - every single issue that comes up results in a new rule." This seems like a serious inability to understand that no process designed to prevent future things you can't forsee is 100% effective (by definition). At some point, you have to declare "good enough", and live with it until the error rate becomes unacceptable overall again, then modify…

The problem is, once the government chooses to not close a known loophole, the number of people who exploit it may increase by orders of magnitude. Without a willingness to add the other 1350 pages, you may end up with something like 70% fraud prevention, not 99.9%. What's needed is more refactoring. This would benefit from more capacity to try different sets of regulations in parallel.

This is a generally true statement about any process. The solution to that is to enforce well enough that people don't think that's a good idea. I also did say you do have to refactor over time as compliance rate decreases. Past that, i don't think we actually disagree :)

If you have a speed limit sign, and it says "speed limit, 50 mph, enforced by satellite observation", most people will probably ignore it. Those that don't and get caught, yeah, they go looking for excuses for why they ignored it to post-justify it. Changing the regulation wording will not change this. You can make the sign much larger and say "speed limit 50 mph, even if you are really late for an appointment, etc" but honestly, it still will not help that. People ignore it because the enforcement mechanism makes them feel like it won't happen to them (and because it's not socially abhorrent, etc), not because of ignorance of the law

On the other hand, if you have a sign that says "speed limit 50mph, enforced by this guy, right here", and there is a smiling cop with a radar gun sitting next to the sign, enforcing it, most people will not ignore it. In fact, i'd bet you could write everything before "enforced by this guy" in small print people had to slow down to read, and most people would slow down and read it, because they believe the risk of enforcement is greater to them.

Will you get everyone to stop speeding there? Nope.

Even if you add spike strips, laser beams, whatever, someone is going to do it, and in fact, enforcing harder sometimes increases the rate (depending how low the rate is) based on the thrill some people get. 100% compliance is just pretty much impossible, no matter what words you use.

Re: Inside the Obama Tech Surge as It Hacks the Pentagon and VA

#80
post #7

The federal government hires a team of young, talented, motivated engineers and managers, puts them in charge of failed software projects, gives them the resources and authority they require to turns things around, and -- surprise! -- it turns out they do a GREAT job. In hindsight, this shouldn't be too surprising. What might be surprising is that the same logic should apply to ALL government functions, not just soft…

> Who says government projects and agencies have to be poorly run?

They don't have to, and some are run quite well.

The actual problem is that they don't have to be well run to thrive, since they operate in a monopoly environment.

Post reply on HN