Petition to release the source code to healthcare.gov
1.usa.gov
1.usa.gov
- The code is (probably) garbage
- The code doesn't just need to be 'released' - it needs to be exposed
- Then there will be some hard questions: "Why is it garbage?"
- Embarrassment...
- ...leading to a change in the system that allowed this to happen
This means we need to hire better contractors and hire managers who have technical background and require an audit periodically.
Open sourcing does not solve these two issues. healthcare.gov is not Django project. You can't install that system and the code is going to be big few people will be able to do anything about it. Plus, even if you could read the entire source code, accepting pull request, going through 3rd party security validation is going to take a while and people are probably not going to take your pull request.
What we need is to put the incompetent people out of job and hire good one.
We need to do those things you mentioned in addition to open sourcing the code. Its our code let's see what we paid for.
Yes there are open source softwares that once completed are efficacious in solving the problems they were designed to solve. The point yeukhon was making was the act of open sourcing a project alone doesn't somehow inherently solve problems in its development. At least in this case not the two enumerated problems he sees with the healthcare.gov project.
When Wikileaks gets their hands on government secrets and puts it on a website, they haven't made those secrets 'open source'. That word doesn't even make sense in that context.
Even if I get my hands on the source code of Windows and put it in a GitHub repository, I still haven't made Windows open source.
That is a different petition to the one that has been posted, which states that the reason for open sourcing the code is "so we may help fix any found issues".
The "let's see what we paid for" argument is an appeal to the more general proposition that there should be public scrutiny of public money. There already exist mechanisms for accessing taxpayer-funded content held by government (including source code) under FOI and other legislation. Unless there is some inadequacy in the operation of those laws, I think they answer the point.
Without the facts, everyone's just guessing or making things up. Open source everything on this. It's our money, what was it spent on?
Without that foundation, the petition does not seem to have much utility, notwithstanding its 1000 signatures.
Perhaps the source code should be audited, if only to figure out what happened to the $600,000,000, but it's not clear that that requires open sourcing the code.
Now, the taxpayers purchased the codebase and the codebase could help states that did not offer a state marketplace create one. So I am very supportive of the idea of making it available to various states. But until the thing is running relatively smoothly, I don't see open sourcing it as doing anything but delaying the rollout and making it less reliable and less secure.
Update: it turns out John Oliver has taken a look at the code: http://www.youtube.com/watch?feature=player_detailpage&v=2Qt...
We should however demand an audit to be done and the result to be published.
They should have to make the case to keep it closed, not the other way around.
In the case of web code, there's nothing's new and innovative about the software that is unknown by existing developers. There is the potential for exploits but open source can help plug up those holes by allowing the community to assist in the process.
Sure, dumping the supposed "500 million" lines of code all at once would make it hard to review but they could release one compinent at a time over several months/years and vow to release all future code.
On a side note, wouldn't reviewing and repairing govt software be an excellent teaching tool for schools? How proud would a child be to have their code fix be accepted into production?
Was this achievable in the given time? If so, what was the plan to get there? If not, how should it have been managed?
One specialist said that as many as five million lines of software code may need to be rewritten before the Web site runs properly.
In comparison:
Windows 95 had 15 million lines of code.
Windows 98, 18 million
Windows XP, 35 million
http://www.nytimes.com/2006/03/27/technology/27soft.htmlLuckily for all of us they have about 8 weeks.
I'm sure the SV approach to MVP's and demanding survival in short iterations has something to offer, but really it's going to take SV and FOSS together to figure out how to solve these problems in the first place before we waste two elections cycles talking about Obamacare and finally getting a $680m fail whale. We failed long before the exchanges showed up way overpriced and under-performing.
However, let's say that Obama's 2nd election platform was about a pledge to lower credit-card micro-transaction costs for all consumers and lubricate online payments to lower the price of business creation. Stripe, Dwolla, Square, Venmo, and numerous others are born with a presidential veto to kill protective, industry-spawned legislation for four years, long enough to contend to become the Google of payments and totally disrupt banking, payments, and retail POS. All along the way, as the companies are competitors, they typically do not exchange value or software really, seemingly over-competing when all of them will end up writing bank integration software to get their network into the money system. SV and FOSS seems good at eliminating dead-weight coders and management practices, but can SV companies effectively use resources without meaningless competition and duplication of effort? Not as long as I'm going to be the founder and try to get super rich all by myself we won't...
This is the problem with SV and FOSS that prevents us from coming up with the model that solves problems at the society level and involves government without creating the iron rice-pots that are the seed capital of government contractors.
Remember that successful open source projects do not operate by simply throwing code over the metaphorical wall. Meaning, you're not just asking for the code, you're asking to be a part of a community that needs management. Bug reports, pull requests, contributor agreements - these cost time and manpower/money to curate, which neither CGI nor the Federal government are going to supply overnight. Ultimately, given the rapid deadlines they're supposedly facing, I'd argue that, at this point, they're distractions to the actual development team.
This is where it WAS available on GitHub: https://github.com/CMSgov/healthcare.gov
One of the many forks can be found here: https://github.com/binlain/healthcare.gov
And here's also a public 'announcement': https://www.healthcare.gov/developers/
It really looks like they intended to OpenSource healthcare.gov anyways (or they already did and reverted their decision later).
And before anyone thinks I have no sympathy or am some political hack, I worked in the Clinton White House and wrote a lot of code for them (24 hours in cyberspace anyone?) and a few years later I helped build the GSA schedule system. I know how hard it is tackle politics and design. And that's why I have little tolerance for waste.
I feel like open source is a decision you need to make at the beginning of the project or spend a lot of work at the end ripping out bad decisions. If you're saying you would hack on this and help fix it, I commend you.
The original Content Management System was Percussion CM System also known as Rhythmyx. You can confirm this by googling: "percussion cm system healthcare.gov" (the links will be broken obviously because they don't want to be associated). One of the things that made Percussion good at scaling was that it was "decoupled". It was sort of like a massively complex GitHub Jekyll in which the web pages were statically published thus Percussion would not be as liable for performance.
Now here comes the OSS irony. I remember distinctly that there was a huge political push to replace Percussion with Drupal. That's right. Instead of static pages they wanted a dynamic OSS CMS (not to be confused with the healthcare CMS entity).
Now I don't know what happened after 2010 because I went off to go start my own company but I do remember we warned them of using a dynamic frontend for such a high profile site.
Anyway I have no real opinion on whether or not healthcare.gov should be OSS but thought that information might be useful for some.
Even a FOIA request wouldn't work against a Canadian company.
That said, it's not a single program. I think it is dozens if not 100+ APIs
I mean just look at this chart:
1. I'm sure there's little that's technically interesting in their implementation.
2. I'm sure much of the code is focused on accruing information from various external resources (which puts us back in the blackbox.)
3. I don't need to see the code to believe the site's architecture was poorly implemented.
With politics the way it is right now in DC, I don't trust anything but the facts, I'm sure you do too. Show me the code and contracts, I'm tired of pundits telling me what I should think. Who knows, maybe it's built to spec or maybe the contractors are at fault. Without facts, who knows?
It's nearly impossible to develop complex software that doesn't infringe upon dozens of nonsense software patents. The gov't and its contractors would be a huge target.
One dysfunctional bureaucracy scared of the policies of another dysfunctional bureaucracy.