NHS gets £40M to cut login times on its IT systems
theguardian.com
theguardian.com
1. Type in user name and password onto computer
2. Logs in to windows, normally taking ~60 seconds, unless you've got the computer where the WiFi signal is poor (yes, WiFi on desktops!) and you get a 'no log in servers'
3. Windows finally loads, click the icon for the software for viewing blood test results
4. An internet explorer window opens, then closes, then after 10 seconds the software opens
5. Type in your username and password, wait 10 seconds
6. Now I want to prescribe some medications, close the first software (computer can't cope with two things open at once), click the logo for the prescribing software
7. A Google Chrome window opens, slowly loads the prescribing software website
8. Type in username and password
9. Navigate through the slow and unintuitive prescribing software
10. Oh wait, I can't prescribe this particular drug without checking a blood test result, close the prescribing software and go to step 4
11. Some alarm goes off, so I have to lock the computer and run. Return from dealing with the alarm, go back to step 1
I can think of a couple ways to make that faster for free. Many dozens more for a lot less than a million pounds, forget 40. Arguments about "but corporate / compliance / vendor contracts / red tape" be damned. (Edit: Most of the replies to this comment are exactly this sort of thinking - It's too complicated, there's too many vendors, we can't do it, it's too hard, no one will do it for free. This is the exact kind of lack of political will to get anything done that I'm talking about. It's someone's existing job to do IT, task them with making it better - plugging in the computers to the wired network is a good free first step. Cleaning up the GPOs so Windows login doesn't take 60 seconds (!) is another freebie. Yes, these systems are complicated. That's not an excuse for them to be garbage).
The decadence of IT spend is horrifying. I suspect most of it winds up lining someone's pocket.
Such as?
They've already stated but it will take a long long time.
The fact that they've already started down that path is a good sign.
The idea that anything is free is ludicrous. You are either spending time (wages) or money (buying solutions).
Why would £40 million be a lot of money for the IT systems of the entire public healthcare system in the UK? The NHS has a yearly budget of £114 billion, so this particular IT spend is only 0.03% the size of their yearly budget.
There's nothing decadent about this. It's essentially deferred maintenance that is long overdue, probably overdue because the government had to wade through people like you who can't help but complain every time a government organization wants to invest in modernizing.
You might want to double check you math.
But yes, it's such a small amount of the overall IT budget I almost wonder why it's being given separately.
I'd also like to see you walk into a situation like this, no matter how much power you had, and see how far 'Arguments about "but corporate / compliance / vendor contracts / red tape" be damned.' gets you.
Contracts might include processes that must be followed for any modification so nobody gets sued afterwards.
The developers who implemented the software might not even be with the contractor anymore. So you pay for training someone else, too.
care.data (about 10 million) https://en.wikipedia.org/wiki/Care.data
Connecting for Health: (over 10 billion!!!) https://en.wikipedia.org/wiki/NHS_Connecting_for_Health
Unfortunately it was far too ambitious and effectively killed private development of healthcare software for the U.K. market in the process, making (for an example relevant to one area of my expertise) dose-based eprescribing a pipe dream despite having produced a ton of useful standards.
That would be Simon Eccles at NHSX. https://twitter.com/NHSCCIO
NHSX is reasonably new. https://www.nhsx.nhs.uk/
They've been having some trouble recruiting and retaining staff. https://www.healthcareitnews.com/news/europe/nhsx-reviews-st...
I do feel that you haven't understood the complexity of the landscape. Not of the vendors, because in theory we could just impose standards of interoperability upon them with RFC like documents. But the complexity of NHS providers. There are thousands of GPs, hundreds of NHS trusts, and they've all got to talk to each other while providing strong access controls and audits.
EDIT: I don't normally ask about downvotes, but I'm curious about the votes in this post, and I'd be grateful for any explanation about downvoting.
And yet I didn't see any obvious job openings. I didn't see an obvious way of checking civilservicejobs.service.gov.uk as neither NHSX nor National Health… turned up any results when plugging them into the organization filter. It's an interesting mission, but if they're not hiring then I can only imagine they're starved for funding or they've successfully retained enough folks.
The overall context is a government that has been openly antagonistic to the NHS for at least a decade, pushed for disastrously expensive "privatisation by stealth" efforts [0][1][2], and is now effectively trying to outsource the digital side of NHS operations to private companies [3]. Strategically starving certain departments is par for the course.
[0] https://www.theguardian.com/society/2014/apr/04/gp-local-nhs...
[1] https://the-probe.co.uk/blog/2019/12/hancock-urged-to-halt-n...
[2] https://www.bmj.com/content/346/bmj.f1322
[3] https://en.wikipedia.org/wiki/Babylon_Health#Matthew_Hancock
(and many, many more sources if you really need them...)
They are a very large provider, and that's causing problems for their hosting CCG.
None of this detracts from your point: the NHS has been deliberately under-funded for years, and the Conservatives are pushing for non-NHS providers to provide services.
If the goal is to "starve the beast" NHSX isn't having trouble with retention then are they?
Plugging into wired ethernet is only free if you have a wired port near the computer and it connects (properly) to an available port on a network switch and you have patch cables onsite and free labor to connect them (including labor that can access the network closet if needed) and free labor to configure the computer to prefer the wired over the wireless, if necessary.
Ideally, it's not a lot of labor, and there's likely to be some switch ports available and some patch cables available, but there's also probably a reason the computers are using wifi if they are.
You can argue this is probably part of someone's job already, but if they aren't doing it because they have too much other stuff to do, you'll need to pay someone else to do it.
1) PC is desperately under-provisioned, probably several years old and upgraded to Windows 10
2) Too large roaming profile (easy situation to get into and hard to spot other than "it's slow")
3) Too slow AD profile server to get the large profile from
4) Internal websites "should" use NTLM authentication if available, which would remove the requirement to log in again, but forwarding this outside the domain properly is remarkably hard
5) Smartcard auth can offer the dropin use case with no typing, but it's a pain to provision and costs more
In many cases you'd be better off with an IBM 3270 terminal but with higher resolution text and images...
In my previous job we built a Windows CE-based system that let you log in instantly by tapping a keyfob and brought the screen you were last using up anywhere on the site, running on fifteen-year-old hardware. It was for selling beer.
...probably still running Windows 7.
Better if you can replace it with a CIFS mount
Or computer can't cope with twin birth either side of midnight on NYE: https://twitter.com/VoicesHeard3/status/1213482121513390080?...
The replies to this (labour, left wing) politician (who many HCPs will tend to support) are illustrative of some of the problems faced: https://twitter.com/AngelaRayner/status/1213469393692299264
And the replies to this post give a bit more idea about what's going on: https://twitter.com/NHSCCIO/status/1213390407784161281?s=20
We had an issue at one site where instead of taking 30 seconds to log in it took over 20 minutes. Our JDBC driver was using the default fetch size and the network latency was killing it.
As you may be able to tell, that had nothing to do with authentication - it was a thick client that downloaded a bunch of reference data at login. I left that role well over a decade ago but I've been back into a hospital in the last year or so and it was still in use, in fact, I couldn't see that it had changed at all.
Good luck to them, it's money well spent, but I doubt £40m is going to fix much.
not exactly sure what you mean, was the login sql query fetching more data than needed in that case shouldn't you tweak the query?
Fetch size is a standard JDBC parameter for tweaking the number of rows paged in a database query. The Sun/Oracle default was 10 rows and the app needed to retrieve thousands. So it would retrieve 10, process them, retrieve 10 more, etc. Which was minimal overhead on most networks, but on a network with high latency it meant there was perhaps a couple of seconds delay with each fetch.
Sun had SunRay terminals with smartcards that allowed users to seemlessly move from terminal to terminal. It was a solution that would have been revolutionary if Microsoft had implemented it in Windows. Being Solaris only means that only a few of us ever saw what could be done and how easy logins and moving from terminal to terminal could be.
It's still a joke that all systems don't hang off their AD/LDAP/jumpcloud/whatever though.
What do you mean? That some other NHS systems have their own directory of users, or there is a master user/pass shared by everyone?
Sure you’d still not have SSO, but you could just let everything running, logged in, in your session on the server.
Why any organisation would choose to deploy regular desktops if this option exists, and why wouldn’t someone like the NHS not already be using this?
We all say "The NHS", but it's made up of a bunch of different companies.
https://www.nhsconfed.org/resources/key-statistics-on-the-nh...
135 acute non-specialist trusts (including 84 foundation trusts)
17 acute specialist trusts (including 16 foundation trusts)
54 mental health trusts (including 42 foundation trusts)
35 community providers (11 NHS trusts, 6 foundation trusts, 17 social enterprises and 1 limited company)
10 ambulance trusts (including 5 foundation trusts)11
7,454 GP practices12
853 for-profit and not-for-profit independent sector organisations, providing care to NHS patients from 7,331 locations13* Nobody likes Citrix, even (or particularly) when they use it every day. The amount of compromises and hoops that app developers have to consider to deploy on it, is significant.
Entire companies run on remote desktop. It's the industry standard, at least here in Germany. I'm working with a lot of enterprise customers and I never heard about particular security concerns with RDP. If anything, the protocol has an excellent security track record.
I did some digging - there are errors in /var/log/messages and /var/log/secure (RHEL 7), and... most of this is caused by an initial hang while trying to reach an ldap server which doesn't exist - it just hangs and times out.
I pointed this out to their tech people, asking for some assistance, and had multiple back and forths where they kept saying "we're seeing you logged in". I had to keep replying "the problem is it takes 65-70 seconds to login - this surely can't be normal". No one ever said it was normal, but one guy wrote privately and said, more or less, "we deal with a lot of systems, and have standard setups. it's better to just have everyone just the standard configs for all systems, even if they're a bit buggy, but not completely broken".
I'm not even sure if I should be surprised by this, but... it was certainly disheartening.
The login thing is just obnoxious.
So they are spending 40 million to consolidate AD. Translation: they are Probably hiring a dozen consultants, buying Quest and Imprivata and moving one department of a hospital in 4 years. They may do a demo of Azure AD to check the AI box.
With all the disparate systems an NHS member of staff needs to use, they really need a robust SSO and Context Management solution. Even with a wall-to-wall EPR like EPIC there are some huge gaps that other systems need to plug, hence multiple logins and extended waits before a user is productive.
Except apps that have nothing to do with patients... eg HR.
If this next one is going to work, they need to consider the developer experience as well as the end users.
[1] https://digital.nhs.uk/services/nhs-login/nhs-login-for-part...
Even an empty profile on a relatively new computer, recently wiped computer was painful.
And people who try to fix it so often make things worse. I was very excited about notion.so until I learned I will have to keep clicking magic links for eternity. (Yeah, I know, they support logging in via Google which reinforces my point.)
There’s also the fact that google recently forced Javascript and specific browsers to be used in order to be able to login. So I was locked out of my account for a while until someone discovered that the “rules” are a little more lax for Firefox useragents.
To add to this: I’m certainly no Microsoft fanboy but the best login I have experienced (in my life I think) is AzureAD with SAML. It seems to use Kerberos silently in the background to do saml handshaking. It’s truly seamless and very fast.
Even if I’m logged in to outlook from office365 (from a non-enrolled computer) I won’t even be presented with another login screen. I’ll just be logged in like “magic”.
You don't mention your use case but it's almost always a bad idea to be logging in as someone else, not just at Google but everywhere. Some sort of access delegation would probably be much better.
As for a work account, I keep it in a separate Chrome profile. Not because of logging in but because you can sync everything without risking spillage.
I can see 11 cookies on the Youtube.com domain in my browser. Some of those seem to be purely for authentication reasons. I'm pretty sure that's why Google flows through Youtube when you log in.
As for why they always try to set Youtube cookies: I don't know, but it's probably because they don't feel like splitting up their authentication flow. Doing the redirect for accounts even when they don't have any Youtube-related is probably a no-op; leaving it like that doesn't cost anything close to the time and resources it would take to segregate their entire workflow + verify that the security is still sound.
There's a ton of threat mitigation and detection of unusual activities going on behind the scenes. This is a big reason why my company uses GSuite SSO - it's basically impossible to achieve a similar level of security with a DIY SSO setup. Auth is very hard to get right with all corner cases considered.
JS trickery is key to detecting bots, and blocking super-outdated browsers like Konqueror that basically lack all modern security mitigations is a reasonable thing to do (and probably allows them to remove less strict fallbacks for those browsers that were previously abused by bad actors).
What's wrong with an x509 client certificate?
Except they still allow browsers far more insecure, like IE. And they could do feature detection to see if the security features are implemented or not.
Blocking user-agents does nothing good for anyone.
For example, to log into my college gmail account, I type my email, get redirected to the schools sso page (retype my username and password), then get redirected to gmail.
That's even worse than the non-sso sign in flow. It definitely doesn't have to be that bad.
At the place I work we use office 365. Their sso path is so much better. I never need to re-enter my username.
Plus if you have a bunch of tabs open (G Suite), it will log you in all of them once you log in on one.
Oh god... How a human being can stand this humiliation? I image this inflating to eight steps in 2030: login, password, 2FA key, face scan, reCAPTCHA, ID scan, phone call, click checkbox in AI TOS no one reads, final click on “We’re done!”
The alternative is to let the user choose the authentication method right on the first screen, but that would mean showing all possible methods (some of which may be limited to certain groups of accounts) and getting a lot of users stuck because they chose the wrong method.
One app I use every day at work, I have to provide my email address ever day, then log in. Then the app passes authentication for some unknown reason to Microsoft's federation service of some kind, using my email address which it asks for again + password.
Prior to their recent 'redesign' it was perfectly streamlined before they "refreshed" the app with a brand new bullshit UI that just made everything worse. I literally can't think of a positive that came out with the new version, it's worse in every conceivable way.
Personally I think someone scammed the company into redesigning something that didn't need it, subcontracted it out to the lowest bidder and pocketed a nice stack of cash for themselves.
It would be good to see the actual breakdown of the spending as it probably includes other spending as well. If not, then it is questionable spending.
Think of it in terms of SSO for an organization the size of the entire US Armed Forces and you'll begin to grasp the scale of the problem.
US DOD has well over 4 million Active Duty, Civilian Employees, Contractors, etc. Though numbers are hard to pin down, since the number of contractors is in many cases not what is being paid for by the contract (e.g. firm-fixed price, and service based contracts like IDIQ which the contract holder dedicates cleared staff, but otherwise it's hard to know; compared to time-and-material/"butts-in-seats" where numbers are know by the Government per contract).
The US DOD attempted to move everything to MS AD at one point but hit a limitation in the number of objects AD let's you create (~2bn).
If they don't show they have the basic know-how on how to set up a ssl cert, I don't want them touching auth.