FCC must reveal IP addresses and user-agent headers of net neutrality commenters
arstechnica.com
arstechnica.com
Funny how a government agency considers it overly burdensome to write what is likely a 4 line script, so goes through a lawsuit that costs taxpayers likely millions of dollars to avoid it. Unless their infrastructure is well and truly F*ed, this is a 30-60 minute task for a junior server admin. Most likely they already ran it and didn't like what it revealed so it's even less effort.
Within the last couple years, I've overheard senior, so-called technical government employees 1) complain about Git and wonder aloud why we weren't using Visual Source Safe; 2) insist that rotating through a list of 12 hard-coded passwords, in code, checked into Git, was totally fine; 3) refuse to believe that automated deployments were possible (not hard, or against norms, but physically impossible); 4) try to explain to another so-called technical gov't employee the difference between CSS and JavaScript, and get it wrong; 5) stand up in the middle of a conversation and walk out the door because it's 2:30 PM and their day is over; 6) even more nonsense you wouldn't believe if I showed you a video of it.
I would hope Federal is a little better than State, but I'm not convinced.
I worked with Federal briefly. I was at a startup at the time, and we had this integration with the Dept. Homeland Security. I was young and stoked. I was the one who was going to wire everything together. It seemed really big and important. I thought it'd be a gold star on my resume.
Reality was super disappointing. So much "we're working on a document for when we can give a date for a date on another document" kind of bureaucracy. I'm sure down in the deep cores of these agencies there are super bright and talented people. The ones at the edges, though.. the problem seems to be that you have to be more of a politician than an engineer to actually get anything done.
In Red Mars, they try to colonize Mars. At first, the challenges are completely technical, and the engineers prevail. But the success is chased by increasing bureaucracy and involvement of stakeholders, and it quickly becomes all politics. c:
And then quickly becomes colonial revolution.
You practically have to assault someone in the break room to get fired from a government job.
Organizational inertia is definitely a thing, and technology trends do not move as quickly in all sectors.
My guess is, in most circumstances, probably not
"New tech" lately feels more and more like whatever the next breed of inexperienced geeks decided to reinvent
I'm told that at this point sales will quietly try to talk you out of buying it.
If you want people in a company to be able to produce good ideas, they must have reasonable leeway to disagree or be contrarian.
My dad would do the same stuff. He worked at Samsung. When he got into his 50s, it was like a switch turned on and he just wouldn't stay beyond a standard work day. Got a meeting you scheduled late in the day? Too bad, he was there at 6am and was going home. He was always home at the same time.
In comparison, during this period of time my mom would go into the office at 8am and stay as late as 1am. She would even pick up 2nd dinner for me on her way home.
When I was in training with the RCAF, I was in lecture where the Information Systems Security Officer (i.e. the senior most infosec person at this base of 6-8000 people) told us about a time where "two guys were emailing back and forth and just picked up a virus".
I made the mistake of pointing out that that's not really how computers work, i.e. an email can't just pick up a virus in transit like a dog picks up a tick.
I learned two lessons that day:
1. Militaries don't like it when people stand out
2. Governments are fundamentally incompetent
Medicare spent months just digging into the laws and talking to their lawyers just to prove they actually had the jurisdiction to change the policy. That really blew me away. One of their bigger concerns was "this might not be our job".
You make it sound like they spent months trying to finagle a way out of working.
> Don't underestimate the absolutely jaw-dropping incompetence from even senior "tech" folks employed by governments.
100% agree. Except each agency can significantly change on this. Some agencies (DEA, USCIS) can and are completely competent. I've seen then turn around on certain moderately complex tasks within hours.
Then you have the idiots at HISN and VA that takes a year for even basic one-way integration. Or, they will argue with you how SAML works (or doesnt) for weeks at a time.
> 1) complain about Git and wonder aloud why we weren't using Visual Source Safe;
Ah so you were talking with their developers. Sounds DoD'ish as that's what they use, along with Firebird.
> 2) insist that rotating through a list of 12 hard-coded passwords, in code, checked into Git, was totally fine;
Ive dealt with network infrastructure entities that did similar for the commercial side of things. I wish it were the "OMG" exception. There's more terrible out there than this, admittedly.
> 3) refuse to believe that automated deployments were possible (not hard, or against norms, but physically impossible);
Well, they ARE impossible by policy. FedRAMP and FISMA requires manual and intentional deployments. Of course we all know that this is the norm for a software SaaS company - but its not the norm when you have to go through a VPN with a CAC or PIV card, and then another VPN to either the testnet or prodnet... And the only software support for both are Windows. (And the VPNs will also kick you out if you're not running windows.)
> 4) try to explain to another so-called technical gov't employee the difference between CSS and JavaScript, and get it wrong;
I've had screaming fights break out in calls when technical issues came up like this. And usually its the single real employee screaming at the legions of 3rd party contractors. And also, Snowden was correct in that 95% of the "government employees" aren't. They are contractors working for Accenture or the host of other Gino (govt in name only) employees. They don't get govt benefits, nor do they have whistleblower protections. Snowden in Hawaii was such a 3rd party govt employee.
I have only ran across 1 fed employee (contractor or real) that was in any way and shape competent.
> 5) stand up in the middle of a conversation and walk out the door because it's 2:30 PM and their day is over;
I get your point. But it's usually 4p. Ive also seen government employees (employed by the local/state/fed) get in trouble for working non-critical issues outside their hours.
> 6) even more nonsense you wouldn't believe if I showed you a video of it.
One thing I've learned is that there is almost always a reason (and a decent one too) of why there is a rule. It's because someone previously abused something, or did something that broke stuff, and the new rule is the usual overcompensation so that anybody in power can claim "They didnt follow our rules, which protect against that." And remember, it's not far up the foodchain to an elected official.
But yeah, there's absolutely crazy shit out there, especially in the fed side of things. And much of it is for complete show. One such tempest in a teacup issue is the new (as of 2017) NIST password guidelines: not a single fed has implemented them. They still enforce the old and terrible ruleset.
It probably happened like this: In 1995 people started planning for this Y2K bug. Some developer said "Nah it's not an issue I'll just change this field" so they changed it like they change everything else, and then 6 months later people got paid the wrong amount because a date calculation was wrong.
So they went looking for someone to blame. They fire the developer of course, but they want someone responsible, who signed off on the release. There was no one, so and with the biggest software fixing exercise in their history coming up they figured they should make sure this problem didn't happen again.
So they introduced sign-off procedures, where someone above a certain level had to sign off on things.
And that is how manual deployments are "banned". They probably aren't exactly, but some poor person will have to put their job on the line to sign off on automating them.
Nobody who gives a shit about their product/service is deploying from a developer directly into production without any kind of, you know, code review, pipeline testing, etc.
It's 'automated' in that you git push. The pipeline handles code reviews, sign-offs, etc., and then automatically deploys the approved code change.
This isn't banned at all.
Just randomly pushing shit to production is banned (separation of concerns, amongst other controls). You can still have everything be fully automated, just not fully autonomous. Someone reviewing a change and then clicking 'LGTM' is still an automated, continuously integrated and deployed system.
I know 'why' people might think that, and make assumptions. The actual controls are pretty level headed though.
How do we replace them with folks that know what they're doing? It almost sounds like it would be better for the government to outsource to a tech firm.
These people have huge salaries and pensions, too, right?
Huge salaries? No. The agencies I contracted for topped out for senior folks in the $85-90k range while the same title in the private sector is going to be about 40-50% higher than that. They have pensions but unless you're already 15 years in you really need to work the system to get anything out of it. New hires (rightly) have to put a lot of money into the system so it's not much better than a private retirement plan in terms of returns, however it is guaranteed by the taxpayers.
There are exceptions, though. If you're retiring from any of the agencies I contracted for, and you worked there your entire career, you're probably getting a lump sum $80-100k vacation time payout and anywhere from $60-100k/yr for the rest of your life depending on your exact job. This is in addition to whatever personal retirement accounts you might have. Obviously no 401(k) with the pension in place, but it was not unheard to have some of the higher ups cashing in just enough vacation every year to fully fund their Roth.
So yeah you can set up a nice retirement nest egg if you're willing to commit to the state (at least where I live). But for short term stuff it's terrible. You don't even vest any pension benefits until I think 5 years now, and then you're getting something like 5-10% from age 70 on or something.
State employees with 25 years get 54 days of leave a year[1] and 10 federal holidays. Additionally many agencies work 9 hour days, adding every other friday off, for an extra 26 days. All told, that is 90 days off a year, or more than 1 in 3 work days.
https://www.calhr.ca.gov/employees/Pages/vacation-vs-annual-...
$80k/yr with pension benefits and a third of your work days off is better than a lot of private sector comp. I'd happily take that last benefit.
The agencies I worked at routinely had employees' shifts ending at various times, anywhere from 2:30 until 5.
Here's an example from my own experience:
I can recall a FOIA request I made for the results of searches in an internal government database in spreadsheet format. To my knowledge this can be exported using existing functionality in the web interface for the internal database. The request was denied, and I appealed. They claimed that the information was publicly available, which is absurd. In the appeal I showed that actually almost none of what I wanted was publicly available and the independent appeals office agreed (after a long delay). Then it became clear that the FOIA office thought the request would be burdensome and they tried to deny it on those grounds. I insisted that no, it wouldn't be burdensome.
When it finally went to the person who would actually do the work, apparently it took only a few hours to do, and they declined to charge me anything for it. I assume the majority of that time was writing some useful comments in the headers of the spreadsheets. They didn't need to write the comments, so clearly they weren't pressed for time.
In the end, the FOIA office spent far more time trying to deny this request than it would have taken to fulfill it.
That's exactly what I was hinting at here. The agency has no interest in the public finding out how much of that feedback was bullshit.
> In my experience it's likely that no technical people were consulted on it.
From the sounds of it, they did at some point consult someone technical and tried to parse their answer as part of their justification for not executing the FOIA request. The fact that they knew it would take a script to extract the data as opposed to just dropping it into a search tool suggests as much anyhow. Though more likely it would just be a couple `sed` commands, a perl/ Python script, or a few command line tools.
They are using the "defense" that it may be difficult to do, but their aim (avoiding the more sinister possibilities) is to stop precedent for other unwieldy requests.
You’ve never dealt with a bad log setup. Things I’ve seen:
- inconsistent format depending on which part of the software was logging (think of some modules using logging lib and others using print())
- multiline logs without any indication they are multiline
- logs in some dumb binary format that requires the original software to reverse into legible text
There are more, but the point is that logs are not often designed to be parsed and searched. They are normally added by developers to be human readable means of reversing internal state to debug issues. Anything above that is (shockingly) bonus material that doesn’t make it into home-grown enterprise/govt software.
I'm not sure how this is relevant. I've seen miles of incompetence in my career, that someone can fudge something up royally doesn't change the fundamental purpose of the thing. The point of log files is to store and make retrievable data about server state and actions over time. That someone somewhere can screw that up doesn't change that.
In this particular case, I find it unlikely they rolled some custom bizarro log file format regardless because of the nature of the subject matter: Proxy server log files. It's unlikely they rolled their own proxy server (and they certainly don't imply any particular difficulties like that in court statements) so we're most likely talking about reading standard Apache logs or something similar.
That’s a point of log files. However, it’s not the point tons of developers have in mind when they add log statements. Developers are primarily concerned with state required to reproduce bugs, not long term standardized storage containing enough information for useful attribution or even all important state transitions. You would be surprised how many developers don’t even bother logging item deletions because it’s such a trivial code path.
You’re idea of “the fundamental purpose” is from an operators view. It rarely lines up with the developers’ views and you’re in for a bad time if you think people who don’t see your perspective are “fudging something up royally” with “miles of incompetence”.
https://en.wikipedia.org/wiki/MAI_Systems_Corp._v._Peak_Comp....
P.S. Please correct me if I got any of this wrong.
What it really stands/stood for is the notion that a "copy" sufficient for the operation of copyright law occurs when a program is loaded from disk to RAM, and therefore it's possible to infringe copyright merely by using software that you aren't personally licensed for.
MAI basically used this theory to make third-party maintenance of their systems illegal, so Congress responded by amending the Copyright Act, but in an extremely narrow way: there's a carve out specifically for maintenance and repair.
[1] https://www.vice.com/en_us/article/4xaqz9/hillary-clinton-te...
If we replied to a lawful order with "This demands 'research' instead of simply a 'search'," they would tell us tough-shit.
Otherwise they would send armed men to steal your stuff.
The false comments, basically gave them opportunity to claim that citizens were equally divided and they could just ignore them, when in reality people were overwhelmingly against the changes.
The whole FCC change reminds me of ICANN and .org TLD. Overwhelmingly unpopular to the public but driven by special interests.
I'd suggest this describes most lobbying. When something's overwhelmingly popular to the public, no one has to get paid to make that clear to the powers-that-be.
I think the reason the case is being fought is the same reason, it's not about whether people actually like net neutrality, they clearly don't. The point is to rules lawyer through the situation - oh well the comments were a wash, oh well there seems to have been fraud, let's ignore the comments entirely, oh well we can actually really easily tell which comments were fraudulent, but the rules have been in place for years now so it's a moot point.
I disagree with you here, those who are informed are are for net neutrality, not against it.
No one wants ISP (or in fact anyone) deciding what sites they can visit or not.
A lot of people do want that because they view prohibiting it as a government take over of the internet. I personally think that is absurd, but it's a very popular opinion.
Can you point to some places where this opinion is expressed? I've never encountered it.
HN for starters.
https://news.ycombinator.com/item?id=9107915
https://news.ycombinator.com/item?id=14347013
https://news.ycombinator.com/item?id=9114134
https://news.ycombinator.com/item?id=20166118
And many more examples if you search.
But not just here, I've seen this opinion represented pretty much anywhere I see net neutrality discussed. Anecdotally, it's nowhere near a majority opinion, but it's definitely not an uncommon one.
I happen to think they are wrong as a matter of tactics in this particular case: governments gave ISPs the special privileges they have now, and if we can't get governments to just withdraw those privileges altogether and force ISPs to compete on a level playing field, net neutrality regulation might be the "least worst" alternative we can actually achieve.
But as far as being skeptical of government regulation in general, and government regulation of any form of mass communication in particular, as a longer term strategic position I think they are right. Net neutrality regulation, even if we could get it, would not allow us to just sit back and relax, problem solved. We would still have to be prepared to protest the next time the government tries to overreach, and the next, and the next, and the next...
A distinction without a practical difference. They do want ISPs to decide what sites they can and cannot visit because that is the defacto state of affairs in a world without net neutrality, it is only that they are satisfied with the decisions the ISPs have made thus far.
Is like trying to convince people that first amendment should be abolished, because it is enforced by the government and they should not control what we can say or not. It is flipping the whole thing upside down, and many confused people are supporting it, when they really want the opposite.
The most common argument I hear against net neutrality is that it's unnecessary government overreach and that ISPs would never try to dictate network traffic in a draconian fashion because it would be bad for business. I won't list all the problems with this reasoning since I'd be preaching to the choir, but this is a belief that a lot of people have.
I know a software engineer who is very much against net neutrality. He also happens to be very much pro free market (in the “no regulation at all” approach).
Is he also in favor of ending the monopolies that ISPs have over Internet access in most places in the US? I'm also pro free market, and if ISPs were a free market I would also be against net neutrality as a government regulation. But ISPs are not a free market; they are huge beneficiaries of government regulation. So net neutrality is one of those unfortunate cases where we need government regulation to offset the effects of other government regulation. That's the bet we can do if having a truly free market is not an option.
After all, it is a transaction between to private entities.
I'd like to call that view "free as in oligopoly".
Interestingly I've learned that there is a big difference between "left libertarians" and "right libertarians". I think the left libertarians and the socialist anarchists could actually be allies if they could get past all their language differences and knee jerk reactions. My roommate is a knowledgeable left libertarian and it's amazing how similar our end goals are but how different our language and conceptual frameworks for getting there can sometimes be.
Yeah, it's from the Bible. Yeah, Paul was talking about something completely different from political programs. It still seems to fit. There are people who seek to destroy the existing system first, in order that there will be no alternative but to build a replacement. They thereby show that they seriously doubt their ability to persuade people that their alternative is better. (They also assume that their alternative is the only alternative, or at least is the one that will be chosen. They are, I think, over-optimistic in doing so.)
If the state actually did help the less privileged, that would be one thing. But the state programs that claim to help the less privileged, mostly don't. And even when they do, the hoops the less privileged have to jump through to get the help are ridiculous. My wife and I have a friend who is on food stamps; he's disabled and unable to work, has been for years. Every year when his food stamps come up for renewal, even though not a single thing has changed with his situation, the county finds a way to screw it up and we have to call them and get it straightened out. Imagine what happens to people who don't have friends that can help them navigate the system.
The root of the problem is not that helping the less privileged is a bad thing; it's that the state is the worst possible tool for the job.
> I get really frustrated with libertarian types that would dismantle useful state programs before we've got something to replace them.
We do have something to replace them: private charity. Anyone can found a nonprofit charity organization to help the less privileged. And they would do a much better job of it than the state does. The fact that the state is doing it at all hurts the actual ability to help people, because the people who would actually do a good job at it are thinking that the state is already taking care of it so they don't have to. Which means that there are actually more people who need help that are not getting it, than there would be if the state were simply out of the business altogether and everybody knew that it was up to them, as private individuals and private charities, to do it.
Also, "we have an idea that could in theory replace them" is not the same as "we have the structures in place and shown capable to replace them".
I would want to see a lot of data to back this up--and it would have to be accurate data, including accurate data on how often the state makes things worse instead of actually helping. I don't have such accurate data on a global scale, and I don't think you do either. The state does not even measure how much harm its employees do; it has no incentive to do so.
> "we have an idea that could in theory replace them" is not the same as "we have the structures in place and shown capable to replace them".
"Replace" assumes that the current structures are providing a net benefit. If they're actually a net cost--if they do more harm than good, all things considered, which I suspect is true for the state if we could actually get accurate data on all the harm as well as all the good--then replacing them with nothing whatever would still be a net gain. Of course replacing them with something that actually did the job the state is supposed to do would be better still, but the perfect should not be the enemy of the good.
Could you give an example of what you mean by this?
However they have such different terms for things they typically get really upset at each other when talking. For example they use the term “capitalism” very differently. Socialist anarchists are against “capitalism” for a lot of reasons, but one of them is that is enables cronyism. However libertarians are pro “capitalism” and yet very against cronyism. So both groups are strongly against cronyism, but they can’t seem to get along well enough to fight cronyism together.
Libertarians advocate for “capitalism” which they see as markets unimpeded by the state. Anarchists also don’t want the state interfering in their exchanges. They may place rules on their exchanges but this would be on a voluntary basis, so they could seemingly coexist with libertarians who just want to rely on markets.
Both sides also seem to be against intellectual property restrictions. Another place to work together.
In my personal vision, an anarchist communist society could, and I think should, still take advantage of markets for certain situations. I think it makes sense for individuals to be protected by communal structures, but those communes might use markets to distribute goods in addition to politically coordinated exchanges.
Libertarians don’t want much of the above, but if it’s truly voluntary they’re not against it either. Though they are super touchy when you talk to them about this and they don’t accept any of it until they understand you really want it to be voluntary.
My libertarian friend also really surprises me sometimes. He said recently the state should release control of all hospitals to the hospital workers who have been running them. Like they did some kind of homesteading so they should be the ones to own the hospital. Well that sounds a lot like a worker owned collective!
Maybe start here? https://www.youtube.com/watch?v=kl2WH88wmWc
If you have questions I'd be happy to answer them, but I'd recommend doing more research before making sweeping generalizations about "anarchists", "libertarians", "capitalism", etc.
I think you’re missing my point. I think left libertarians and socialist anarchists could be allies. They seem to want almost the same thing. They just can’t stand talking to each other because they use terms that make the other extremely skeptical. It’s difficult for me to use precise language when trying to bring two groups together who use that language very differently. So I know I’m speaking in broad terms. Certainly anarchist and libertarian are very broad and not all of them think alike.
But I think people who like the idea of anarchist socialism might actually like what certain left libertarians have to say. That is my point.
Don’t take my word for it. Check out Roderick Long and you tell me if he makes sense to you.
What gives you the impression that these are different groups that "could be allies" but "can't stand talking to each other"? Every resource I can find seems to say that social anarchism is a subset of left libertarianism.
Example: https://en.wikipedia.org/wiki/Left-libertarianism#/media/Fil...
"Here, disclosing the originating IP addresses and user-agent headers would help clarify whether and to what extent fraudulent activity interfered with the comment process for the FCC's [net neutrality repeal], and more generally, the extent to which administrative rulemaking may be vulnerable to corruption. This serves a vital public interest because of the importance of public comments in agency rulemaking," Schofield wrote.
I have had the same thought, and I am not sure why the veracity of the comments is fomenting so much anger. No matter what the comments had said, the FCC would have done the same thing; Pai had been very clear about his opinion on net neutrality over the course of many years.
As for your actual premise, ‘the comments didn’t matter’, the rest of your comment invalidates your premise. Because if the comments did not matter, then the FCC would feel no need to fake the result.
What you mean to say is, ‘the comments would not effect the outcome of the FCC’s decision.’ And we can have a proper opinionated debate as to whether that is true. But the comments clearly ‘matter’.
First rule of any good investigative reporting: follow the money. Whoever paid for the comments must have had some motivation for committing fraud and identity theft en masse.
The fact that the FCC is fighting to keep the comment-purchasers IP address(es) secret is telling in and of itself though I suppose.
[1] https://medium.com/ragtag-notes/bot-or-not-verifying-public-...
[2] https://medium.com/@csinchok/an-analysis-of-the-anti-title-i...
>Based on this analysis, we estimate that 91% of all anti-net-neutrality submissions, and 79% of all pro-net-neutrality submissions, came from bots.
Their survey data is mostly inconsistent with the WSJ data. See https://archive.fo/sp9Q7. WSJ had multiple orders of magnitude higher sample size, so I'd go with their numbers.
https://www.wsj.com/articles/millions-of-people-post-comment...
[1] https://arstechnica.com/tech-policy/2017/12/dead-people-amon...
Pai knows this, and the fact that the public comments on net neutrality rulemaking were so obviously manipulated has made people think there is at least a possibility that he, or the FCC, was complicit, in order to flout the APA. The fact that the agency has gone out of its way to cover the situation up does not inspire much confidence, either.
TL;DR: A bunch of comments on a website could result in the FCC's actions being struck down in court.
Long story short, that is why comments on a website genuinely matter to the regulatory process.
EDIT: as a side note, the current administration has been sued a lot over APA violations. Most of the lawsuits brought by states against the federal government you hear about in the news hinge on the APA. An example off the top of my head is the repeal of DACA. Now, DACA was an executive order and could have been un-done by an executive order (executive orders are mostly not subject to the APA). But Trump did not make an executive order repealing DACA: instead the Attorney General removed the rule himself, which means his decision was subject to APA review. As a part of this he had to publish a document explaining why he was going to repeal it. In it he said the reason he was repealing DACA was because he believed it was unconstitutional. A number of states have sued over this change, and one of the legal arguments used is an APA violation, because there is no evidence that DACA is unconstitutional. Which gets to what I find interesting about the APA; it forces the person making the change to specifically spell out their reasoning and rationalization for making that change. If their reasoning is faulty you can sue, and the federal government can't defend it by throwing about alternative rationales for the decision.
If you read SCOTUS opinions, it feels like every other case with the U.S. government involves the APA. It's a powerful piece of legislation preventing agencies from abusing their rule-making power.
I don't have much of a problem with this ruling given that all commenters were warned:
"every commenter was provided with a privacy notice, stating that '[a]ll information submitted, including names and addresses, will be publicly available via the Web.'"
If they are asking for them, and piping them into /dev/null, that's a scandal that FOIA requests can reveal. It also gives political capital for a subsequent administration to overturn a ruling with minimal fuss.
sadly in this inter connected world it is far easier to name and shame people which thwarts any useful discussion, it is no different than voter intimidation; which is why one side wants to do away with secret ballots in unionization pushes.
winning is all that is cared about.
what are we going to do when either the NYT or another organization links back those ids to private individuals, just hashtag apologize and ignore it?
The NYT of any other organization can pull the filing and see each and every name and address associated with a comment. No combing or linking back to IDs needed. It’s all there for the entire world the see as part of the public record. The information that will be exposed by this ruling is the IP address(es) of whoever fraudulently commented using other people’s names and addresses.
He does uses simpleton sort of language and pretends to be friendly neighbour but if you pay at least a little bit of attention then it's just full of lies, diversions and every possible argumenting fallacy.
People were actually really upset with the host for allowing this.
I expect the NYT will just find thousands of comments written with IE6 from AWS IP addresses.
Can't wait to see it.
These logs could form the basis of a legal record generated by the executive branch of the government and even if they weren't they are likely subject to a legal hold as a result of on-going legal action.
Records in the government sense are very important to form an open trail of policy decisions and overall function of government. Deleting them accidentally can get you a firm slap on the wrist while deleting them intentionally can put you in legal trouble (and worse if you're doing it to cover-up wrongdoing).
The National Archives (NARA) holds on to all the various records generated by the functioning of the federal government for various time periods based on the content of the records. As to payment - costs are incurred in part by the generating agencies and then the taxpayers funding NARA.
Further reading: Privacy Act of 1974, [1], FCC's Comment Filing System System of Records in the Federal Register [2], Paperwork Reduction Act of 1980 (more towards only collecting necessary info), and FCC's Website Notices [3].
[1]: https://www.archives.gov/about
[2, Word .doc]: https://www.fcc.gov/omd/privacyact/documents/records/FCC-CGB...
I have since I actually submitted a comment on this very rulemaking. Your description is correct.
Even in countries implementing the gdpr, I’d expect that metadata is retained in this sort of usecase.