Use of Yammer by VA staff was a major security risk, investigation says
theguardian.com
theguardian.com
As a veteran using VA services, I beg Americans to raise their own awareness of the criminal negligence occurring at the VA. Law currently provides that the VA may not fire or reprimand VA employees based on past performance. That's right: VA employees cannot be fired for shitty performance (or "erroneous shredding").
The phrase we use to describe the VA is "delay or deny until they die" and it's absolutely the truth. A very good friend of mine was murdered by VA doctors who prescribed him drugs with deadly interaction. His family can't do anything about it, and those doctors are still working at the VA, prescribing medications to veterans.
If any government organization needs a complete overhaul, an across-the-board firing of all employees (and a permaban of all of those employees from ever working for the government ever again), it's the Department of Veteran Affairs.
Loved or hated, the VA is a large HMO set up as a benefit for veterans to help them because many of them have had to sacrifice their personal health to fulfill orders their were given.
Any healthcare system is riddle with anecdotes of failures, but if you look at it from a population health perspective, as a whole the VA has been able to care for its patients with a pretty good quality if you consider the cost constraints they are working with. I'm not aware of any private health system that's as efficient as the VA.
Also, the VA has had a fair amount of innovation that then trickles down to the rest of the healthcare systems. One example is BlueButton, a method to obtain a dump of all your healthcare records as a patient. Eventually CMS (Medicare) enhanced it and started promoting for everyone else, under the spec "BlueButton Plus".
On that topic, the US as a whole ranks 24th in the world in terms of preventable deaths[1], and we spend twice per capita as the highest-performing country on the list. Our healthcare has A LONG WAYS TO GO to improve.
Back to the original topic, I'm not speaking from the POV of someone having experienced the VA care system. I'm speaking from having worked in population health. Quality is defined by specific measures that compare in aggregate the outcomes of patients given particular co-morbidities. That doesn't make it perfect, it just means that as a whole, the VA treats people as good or better than the private system.
As for wait times to see providers, keep in mind that many people on the private system may be able to see specialists but just can't afford it, so they never get treated... until it's too late. Part of the quality-based initiatives are to nudge providers (via reimbursements/penalties) to treat things while it's early enough, both for the health of patients and cost reduction—instead of waiting for complications.
[1] http://www.oecd.org/officialdocuments/publicdisplaydocumentp...
Outcomes do take into account the starting conditions ("comorbidities") so this doesn't necessarily mean that the actual health of that population is better than average population. Because as you pointed out, service people get a pretty raw deal when it comes to occupational hazard. ;(
Additional info:
RAND analysis about VA and non-VA care -- http://www.rand.org/blog/2012/08/socialized-or-not-we-can-le...
Meta-study commissioned by the VA looking at existing studies comparing quality of care in VA and out of VA -- http://www.hsrd.research.va.gov/publications/esp/quality.pdf
As this point the US should give the veterans the same insurance place Congress gets.
Most of us use our own health insurance from our jobs because the VA is absolute garbage.
We ended up developing our own system which ended up a bit similar to Slack. Of interest to the crowd here, the server side is implemented in Common Lisp. We'll release it as open source as soon as we've cleaned it up a bit.
I have an externally available demo system, but I don't want to reveal the URL to it publicly right now since it runs on the smallest possible Google Cloud instance. If anyone is interested in testing it, send a private message to me, or wait until we release it.
a) no one actively admining the service, in particular removing accounts when people left.
b) users themselves were communicating things they were not supposed to, like instructions for circumventing other security procedures.
You can just as easily have these problems with an internal service.
Telling is that the illegal advice VA staff were giving each other had to do with circumventing other security procedures that were interfering with their ability to work effectively (like needing to be available via email but not having access to email on an available device). These are issues all big organizations face, regardless of whether they are purchasing IT services or implementing themselves.
Not for the typical definition of "internal". Typically to reach an internal service you have to be on the internal network. Removal of an ex-user's intranet credentials is usually something IT handles well.
And of course they have more features. They have hundreds of developers and we have 2, working on spare time.
What we implemented has worked well for us for a long time now, but the features that are important to us is there (free-text search, email notifications for example) , and being in control of code so that we can add features as we please is quite liberating to me. But like you said, most teams are not interested in that.
Sounds more like it wasn't made clear what was or wasn't an okay internal communication tool, which points to a lack of training and IT management.
That's a pretty scummy business model, IMO.
Basically, it seems Microsoft designed Yammer so that any employee of any organisation can start/join a Yammer network for their employer just by using their work e-mail address. If the employer then wants to actually administer the internal social network that they've unexpectedly wound up with - for example, to remove ex-employees - Microsoft charge them a substantial monthly per-user fee.
1.) Well, our employees spend a lot of time screwing around on Facebook, so let's build something that looks almost identical, but that is supposed to be used for posting status messages about work, instead of BuzzFeed listicles, baby pictures, and venting!
2.) ?????
3.) PROFIT!!!!
It seems like "social" is a buzzword that is finally starting to lose it's luster, but it was pretty ridiculous for a while - IBM changing the name of Lotusphere to IBM Connections, all of these business Facebook-clones, Microsoft spending a boat-load of money on Yammer, then letting it languish, while building more or less parallel features into SharePoint and Office365.
So much hype about "transforming the way people work" and some truly disturbing rhetoric about enabling the blurring of personal and work life. Good riddance.
People like to play around with how to arrange metawork. Mangers especially like this. A lot of it is yak shaving.
Enabling users to get something done while adhering to corporate policies effectively is a problem I don't believe anyone has solved for the Fortune 500 as a whole. If they did, I assure you that several billion of a market cap would be a small fraction of their likely valuation. Slack isn't allowed in most places in the F500 as shadow IT goes, for example, but they hit the billion dollar club within months practically because they approached chat in a small manner that Salesforce did. Even a small, tiny win is a billion dollars across these kinds of companies.
Well, they must have figured out how to get something done, to have survived long enough to get into the Fortune 500. :)
It's why big companies are more concerned about losing revenue than growing it - this is the opposite with start-ups. It's what seems obvious when you're near your market cap.
Of course it does. But does it get done as well, or as effectively, or as efficiently without a certain level of technological support? Would you want to work in a company that didn't use any technological capabilities for collaboration? No email, no IM, no document sharing of any sort, etc? I mean, printing out documents and sending them via one of those old-style interoffice memo envelopes ought to be enough for anybody, right?
The thing is, not every company needs the same kind of technological capabilities, because they don't all have the same issues. If you're in a 10 person startup where everybody sits in one room, a lot of knowledge sharing is done by just speaking out loud and everybody hears you. If you're in a 32,000 person company with offices spread around 80 countries, it's a lot harder to make sure that everybody knows everything they need to know, and knows it in a timely manner. And there are "serendipitous communications" that will never happen without some technological help, as you have employees who will almost certainly never meet in person. Or if they do, it'll be once every couple of years.
Tooling can be beneficial, it's just important to understand that no tool is a panacea. Also, no tool(s) can fix a toxic company culture, or broken processes. These are reasons some companies deploy technological tools to enhance collaboration and knowledge sharing, and don't see the expected benefits.
(Disclaimer: I'm totally biased, as my company makes "enterprise social software". Take everything I say with a grain of salt as you see fit.)
My feeling is that a lot of this is because people thought "Hey, we can make a private Facebook clone and drop it inside our organization and people will use it to be more productive". I think that's a mistaken approach. "Social" tools certainly can have value in an organisation, but there's nothing magic about a Facebook clone (or web-based IRC for that matter).
Our position at Fogbeam is that ESN's (Enterprise Social Network), in order to provide real value, have to do more. That is, they have to connect with the things and ways that people actually get work done, and make it easier to find (information|people|documents|whatever) that you need to do something... in addition to the fluffier "idle chit chat" aspects. If an ESN can do that, then it can provide value.
Of course, I'm biased, as that's one of the ways in which our ESN approach differs from some of the others. We have a tremendous focus on integration with other enterprise applications. And we use semantic web technology to do automatic semantic entity extraction from the text flowing around the system, so we can build a knowledge-base that helps people find related information.
I'll be the first to say that a lot of companies have not received as much value from deploying internal social software as they might have expected. We just think it's (in part) because they used first generation social software that doesn't provided the needed capabilities.
Another reason that companies fail to get a lot of value from this stuff is much harder to resolve: company culture and values. Simply put, some organisations will NEVER get much value from social software because the internal culture discourages collaboration, and encourages knowledge-hoarding, competition, backstabbing, secrecy and what-not. If Joe Manager at one of those firms puts in Yammer, or Jive, or Lotus Connections, or Fogcutter, or anything else, it's going to fail. In those cases, it has little or nothing to do with the technology.
(Disclaimer: I'm totally biased, as my company makes "enterprise social software". Take everything I say with a grain of salt as you see fit.)
Employee engagement is a key metric for a productive workforce but the studies that I saw all showed it declining over the past decade. Along come the 'social platform' salesmen and cleverly pitch at Business clients, who then tell Technology that they've found a solution to engagement if we'd just hurry-up and deploy $PLATFORM.
The enthusiasm usually lasts until the end of the initial support period, three years say, and then another $PLATFORM arrives which will definitely solve the problem.
Providing a social platform is fine but the employees need to have meaningful, empowered work before they'll even be motivated to look at it. In the absence of that, coercion reached the stage where employees were being forced to create their profiles on the new platform as part of annual goals.
So many profiles created and avatars loaded, never to be used...
The article talks about the guy that posted the fix to reading old email by copying an encryption key. It's discussed in a light as if he were doing something wrong but in reality he was probably solving an actual problem people have. In the process, it sounds like he also exposed the fact that you can copy keys our of what sounds like should have been a read only smart card but that points to the VA IT department being inept not that guy doing anything wrong. The fact that employees use yammer to begin with probably is because the IT department is inept and doesn't provide a good sanctioned forum for communication.
How else would you expect it to work? Email doesn't cut it (point to point, not searchable, low signal:noise) and I haven't seen a high functioning wiki, which seems like the closest alternative.
For sales in particular, though, I think the integration with SFDC (in Chatter's case) is pretty key. They live on Salesforce, so the messages & communication is right there and can easily be linked back to specific accounts as necessary.
Working in a large, dated codebase, I would love to be able to see previous discussions about features, pieces of code, code reviews, etc. But because they occurred over email, they undiscoverable to me.
Chatter was free, standalone, came actually close to what Slack does. But it wasn't hip enough to start in the early adopter circles, they went straight into enterprise with it, which is how you kill anything innovative. fist you get the hipsters, THEN you go after the suits. other way round kills your product due to wrong feedback.
IT administrators can secure everything under their control really well, but if a third-party web application used by employees is successfully penetrated, poof! IT infrastructure is now exposed to threats from the inside. Meanwhile, the only people who can evaluate and improve the security of that web application are the people selling the application.
Whether this improves anything in terms of data breaches I don't know. But as far as I can see "security" is the literal opposite of freedom and openness.
So their security policy was to not have a security policy, essentially.