The entire project is an unsalvageable mess and so is their response - clearly they've outsourced the entire thing to idiots and are trying to cover their ass now that it's been publicized.
The entire project is an unsalvageable mess and so is their response - clearly they've outsourced the entire thing to idiots and are trying to cover their ass now that it's been publicized.
IMO the NPCC should sue Pervade and take them to the cleaners. Pervade are clearly incapable of developing a secure system, and have completely misrepresented their abilities. They also appear to have blatantly lied to the NPCC numerous times.
You're assuming that the point was to actually deliver something of value that would help track cybercrime and that the contract was awarded fairly. I'm not sure this was the case.
Most likely, the brokenness of the system is a feature to justify endless busywork for various people at all levels of the stack, where as a working implementation would not only require little/no maintenance but would actually deliver actionable evidence forcing them to do real police work.
For an infosec company to behave like, there is a huge risk of completely and utterly decimating their reputation, possibly forever.
My guess is that either (1), or both - (2) and (3):
1. There was skulduggery involved during the bidding process
2. Those at the NPCC responsible for awarding the contract did not have the required competence to do so
3. Those at the NPCC tasked with overseeing operations do not have the competence, or even the mindset, to do so
Regardless, to call it an "absolute clusterfuck" would be generous. I'm genuinely disgusted that the NPCC and Pervade have put so many organisations in jeopardy, and furthermore that they continue to do so, even when in possession of the facts. Astonishing.Being incompetent will get you mildly reprimanded. Self-dealing might get you jailed.