‘We feel really terrible,’ says chief executive whose app roiled the Iowa caucus
latimes.com
latimes.com
Couldn't they just create a Google Forms link share it to the field people sending the results back? It would be only 1765 lines in a Google Sheets doc, and would be practically free. (Not to mention more secure than a custom implementation by semi-incapable development contractors like in this case.)
Had they done any of that, it might even have worked. I don't think their stack is as exciting as that.
- Only allow one entry per GSuite ID in Google Forms
- Enforce yubikey 2FA on GSuite.
- Issue each captain a Pixel 1 with Google MDM for remote wiping and app deployment.
- Turn off all other apps (Docs, Fi, Photos, etc...) in GSuite.
https://thehill.com/policy/technology/267302-sanders-campaig...
Now, this necessitated a new app, since the Microsoft one provided previously didn't address the new reporting requirements. But it was the reporting requirements, not moving from MS to a firm that had even clearer reason to suspect anti-Sanders bias, that was intended to negate the complaints of Sanders and other candidates about the 2016 cycle.
1. Ignoring like... stupid high information transmission systems where clever solutions may be required to concurrently stream data to even dozens of customers - the data here was measurable in bytes, _maybe_ kilobytes.
P.S. I work at Google and internally sheets is used thoroughly to survey large numbers of employees and it can view large sheets for a lot of people in "read-only" mode pretty well.
I eventually found that if I changed how the spreadsheet was structured, a lot of problems were drastically reduced. I forget the details, but I think I switched to having one sheet that just collects form submissions and does nothing else, then another sheet that uses Javascript to pull data off the first and do the computations. That way processing was moved offline from form submission.
But the general point is, you can't just write a spreadsheet, collect thousands of form submissions, and have no issues. You can't just assume "Google scales everything". N people interacting with N (or 2N or 3N if you share with a few) spreadsheets is an embarrassingly parallel problem. N people interacting with 1 spreadsheet is not.
Deputize 40 administrators, give them each the 45 phone numbers for their districts. At the appointed time, have the administrators direct-dial each of the 45 numbers and quickly note the results. Combine the results from the 40 as they come in.
Secure and effective. It'd probably take 3 hours to wrap it all up.
(Presume $100,000 base salary, 1.4x overhead for a salaried employee, $0 profit, all employees working on the project are developers, and no code reuse with any other project. Some of these assumptions are clearly false, but I think it gives a reasonable guess at an upper bound).
However, seeing as the developers they hired didn't bother changing the default manifest and forgot to prefix a URL with HTTPS, I hope they Shadow at least wasn't paying them that much?
So much for "improved security"
[1] https://www.propublica.org/article/the-iowa-caucuses-app-had...
Other way to say it, if you don't count the mistakes - then the app is excellent.
The more this saga continues the more the democrat gang seems like a troop of out of touch hippie professors recruiting freshman to do their “technology” work.
Shadow Inc. — the tech company behind the app — launched in 2019 with backing from political nonprofit ACRONYM, according to a statement from the nonprofit.
ACRONYM founder and CEO Tara McGowan, a Newport, R.I., native, said on Twitter that Shadow is “an independent company ACRONYM invested in.
McGowan, who lists herself as a former journalist, married then-Hillary Clinton campaign staffer and current Buttigeig strategist Michael Halle in 2015, according to a Providence Journal marriage announcement and Halle’s Twitter account.
Not at all suspicious !
I'm not a developer at all, but even I recognize that the world is full of crappy products that no one needs or that dont actually solve a problem but nonetheless were engineered and built exactly as the original scope dictated. Doing good work doesnt always mean that the work is any good.
To those devs, jr or otherwise - every step that was supposed to protect against a failure in the app seems to have failed here, and you should not feel bad. Mistakes happen and should be expected, but the damage that they are allowed to wreck is the blame of poor management, not you.
Not to mention, political parties aren't transparently run in many cases like we've seen in 2016 Democratic National Committee email leak. Most likely, these people are feeding off of their political connections and harvesting donation money from not just the party, but also the candidates [2].
This is also why I'm no longer donating to a political party directly, or a candidate who would in turn would do the same. It seems like the only independent candidate running under democratic party is keeping his campaign money in-house.
[1] https://www.crn.com/slide-shows/applications-os/who-is-shado...
[2] https://twitter.com/BustinTrudeau/status/1224697566182498306
Why isn't the DNC harder on crap like this?
Well, for starters, because the DNC doesn't run the Iowa caucus.
Additionally, the Iowa dem caucus (and primaries) aren't a governmental thing, the political parties aren't government organizations - they're private organizations that are just _all about the government and politics_ as such the Iowa caucus is really weirdly in a grey zone where there is even less necessary oversight than the administration of the general election in Iowa will have - but sort of more oversight since the DNC could just reject the results outright... Buuuut things like the voting rights act have forced some regulations into primary operation - it's all quite confusing...
The TL;DR though is that the DNC doesn't technically run the Iowa caucus but is more than capable of making the Iowa dem caucus committee feel a whole lot of pain and hold them accountable.
It looks like multiple campaigns (including the one the most to lose and the one with most to gain from a confusing Iowa) paid Shadow for services - Buttigieg’s campaign was not an investor, and does not appear to have anything to do with the development of the app. Do you have any sources for your claim?
> Some claims, such as that the Iowa caucus app was funded by Buttigieg, mischaracterize what we know.
> Buttigieg’s campaign wasn’t involved in the app’s development.
This was not my claim at all
"No" - Manager
"But it could..." - Dev
"I don't care." - Manager
"Okay :(" - Dev
The app itself doesn’t sound like it needed to be that complex, and by all accounts, it wasn’t. But it feels like the company believed that the secret to a successful rollout was to ask the developer beforehand “are you sure there won’t be any problems?”
Every time I’ve been involved in releasing a web service, the step before “tell the world that the software is live” has been “make one or more complete end-to-end requests to make sure everything is running correctly.” The company clearly skipped that step: they announced the project was live without first making a single end-to-end request. We know that because the problems people reported and the problems that the company has described would have made it impossible for any upload to succeed.
Hey guys, you done messed up - no more lack of disclosure. Your company will probably be dissolved due to this hilariously well publicized failure.
> The company’s mission is to help advance Democratic causes and candidates, and its employees were excited to have an important role in Iowa’s historic presidential caucus.
That sounds noble and all, but also pretty silly - how was your solution ever going to help "advance Democratic causes and candidates" purely by serving as a drop-box for everyone to upload voter tallies to. The employees at your company can feel excited to be working to support the DNC - but it's really a stretch to claim that your vote tallying solution was advancing Democratic causes. It's like claiming, as a car manufacturer, that you're excited to help advance the cause of addressing back problems because some of the people who might buy your car end up driving to staples and buying a new office chair.
“I’m really disappointed that some of our technology created an issue that made the caucus difficult,” said Gerard Niemira, chief executive of political technology company Shadow Inc., in his first interview after the caucus. “We feel really terrible about that.”
Wonder how much tech this person understands
That’s how you end up getting sued.
The amount of data we're talking about here would fit comfortably in an Excel spreadsheet. Why on Earth was there a data warehouse involved at all?
They were deploying an app to a very inexperienced user group, via developer certificate enterprise sandbox because they couldn't get the app done in time for App Store review and approval. They didn't do the requisite amount of live user testing and were sending out instructions up to 3pm on the day of voting.
They had a chance to evaluate whether they should take on this job and do it right or not. They could've advised and warned the IDP that they were going to get in trouble.
But they thought they could handle it based on their past inconsequential apps. And they wanted the business and publicity of doing this job. They were wrong, and now playing it off like it was some minor mistake.
It wasn't. Just a typical story of overly confident people getting in over their heads, and now passing it off as no big deal when in fact it is a big deal. Maybe if such behavior was fined or penalized there would be a lesson learned...
"Shadow is a technology company dedicated to building power within the progressive movement."
Can some things remain non political these days? What a weird sentiment.
Are we moving to a future where I need to check the political leanings of software providers before they can agree to do business with me? I'm looking for a professional to do a job, you can keep your politics at home...
Is the CMM still a thing?
https://en.wikipedia.org/wiki/Capability_Maturity_Model
"The CMM was originally intended as a tool to evaluate the ability of government contractors to perform a contracted software project."
For something as important as elections, developers (organizations) should be required to adhere to CMM 5 and use a very tight waterfall + TDD practices. Further, the product and testing requirements should be public. Not this shadow development crap.
for that matter there is no (federal level) law or regulation requiring a public vote for the president at all. the constitution establishes the electoral college but the methods by which electors are chosen and vote are left to the state themselves.
They did this with a minimal viable product approach for what should have been a critical production ready/tested app.
One news story I read quoted an error message about a “missing protocol.” I believe that the “coding error” was really a configuration error: somebody forgot to include https:// in the web service URL. The app recorded the data, but couldn’t upload it.
Load testing would have found this, but so would a single integration test/smoke test.
https://www.vice.com/en_ca/article/y3m33x/heres-the-shadow-i...
It (seems to) occur while trying to access a "2nd Factor Authentication" page at auth0.com, and there's a cross through the padlock icon at the bottom of the window.
This guy doesn’t know what he’s talking about is he? Is this same person who wondered why he could copy the google frontend and it would look literally the same? What use is a browser with faulty internet ‘transmission code’
We still need the index.android.bundle.map to faithfully deminify and audit.
The problems come about when there are _nothing but_ inexperienced devs on the team.