Should gov.uk run a bug bounty?
shkspr.mobi
shkspr.mobi
https://news.ycombinator.com/item?id=3811052
Yes, the probably eventually should, but given how we've gone from terrible websites by contractors to decent ones in a short time, I'm not going to start jumping up and down about it yet.
Although if they could get round to redesigning the 'gateway' crap sooner rather than later it'd be much appreciated. I have already been given 25 different gateway IDs.
Whilst the outcome is positive, the technology churn isn't. In fact, it's a right mess. They've ended up with a huge stack that doesn't need to be there. They're there to provide content efficiently, not redesign the infrastructure. They're using tech because it's cool and fun rather than suitable for the task and cost effective.
I know people are going to compare them to EDS and say "look how far we've come" etc but they are still spending public money and are not beyond scrutiny from us tax payers.
They're not a startup either. The ground they're standing on is different to what they think they're standing on.
Edit: downvoters, please at least have the honour to explain yourselves.
That they're doing a fantastic job of providing content to users efficiently, using appropriate technology and without favouring commercial solutions, is incredible.
Compare the clusterfuck that is http://www.cyberstreetwise.com. Contracted-out websites cannot match the quality and cost effectiveness.
I downvoted you because it's really very difficult to understand what you are actually complaining about: you are trolling.
* Experimentation doesn't make it into production twice unless you're doing something wrong.
* There are proven solutions off the shelf both open source and commercial.
* They should be value driven rather than innovation driven. We aren't paying them to be a research agency.
* There is an ongoing maintenance cost and in-house only knowledge when you do an NIH job of something. That is not efficient.
It's called agile development, and it lets them respond quickly and efficiently to changes in requirements / mission.
See also: Facebook, Twitter, most other tech companies.
That notwithstanding, I'd also be very interested to know how agile is a panacea to fast-changing requirements, especially as opposed to techniques such as designing for change (at the architectural level, so not just the implementation level, i.e. loose coupling, encapsulation and abstraction interfaces).
The money that the fairly small team are spending is a drop in the ocean compared to many government funded projects. If you want to get angry about misspent public funds, I can think of countless other areas that are orders of magnitude worse. The reality is that a small team of people directly employed by the government working fairly effectively can build and discard their stack as many times as they want and still be significantly cheaper than getting a big company to do it.
It's my job to look at dysfunctional teams both from a technology and a process perspective. I've seen teams like this many times before. They are expensive, inefficient and the return is considerably lower than the investment has promised.
Just because the historic approaches are worse doesn't exclude these guys from scrutiny. They'll quite happily piss £40k of dev cost up the wall while other departments are arguing over £200 ultrasounds for cancer patients. Scrutiny must be universal and unforgiving.
I've not been watching them closely, but they are delivering, which seems an extremely strong indication they're not dysfunctional at all.
Every now and then I end up on a gov site they've redone and it's immediately obvious they've had at it because it's easy to use, responsive, etc.
You're sounding like one of those pointy haired bosses that don't understand that good developers play to succeed, and it doesn't always pay off. But if you stop them you end up with crap because the good people leave.
Sounds more like a pointy haired boss to me.
The poster you're replying to is being very vague though, and I think the downvotes are probably deserved in that case. Either give concrete examples of why you dislike the way someone's doing something, or don't post.
There are many more. I'll write them up at some point.
Personally, I agree with you. I've had some experience of them, and was shocked by the general level of inexperience (they build web sites, with virtually no enterprise experience), the unwavering and dogmatic commitment to agile and open source (don't misunderstand me - both are good things but there are times where it just! doesn't! make! sense!), and the lack of security understanding.
UK government security in general has always been compliance-oriented. Want to run a system at a particular sensitivity level? Implement this checklist of controls. Security should be risk-based, and that doesn't happen. Not even at gov.uk.
Some of their exemplar projects have been running since 2011 and still aren't complete. But they're being heralded as poster-children of agile. So spin isn't limited to Whitehall...
The team is talented, without a doubt. It would be nice to see it mature.
Waste of tax pounds!
Ultimately this is probably because experienced people got better offers elsewhere.
They should operate an open submission policy though i.e. a bug report form and actually feed back to people.
Granted that in an ideal world this sort of incentive wouldn't be necessary, but if we lived in an ideal world, code wouldn't have bugs in it, too.
And another reason: If the government pays bounties for confirmed bug reports, a prospective reporter can have some confidence that they won't react to the report by taking punitive action, which might otherwise be a very real concern; HN periodically sees threads about employers and clients reacting extremely badly to unsolicited exploit reports, and the worst those can do stops short of imprisoning somebody.
Of course, all of this assumes a government not so sclerotic that it'll take an interest in fixing bugs without first having to be motivated by a horribly embarrassing public compromise, which means it's probably not going to work in the UK, or for that matter in the US either. But it's a nice thought, I suppose.
Bug bounty rewards are orders of magnitude cheaper than the damage the bugs can cause.
If they have a bug report form at all and employ people to screen and respond to bug reports, the bounty costs probably wont even add up to the cost of 1 additional employee
They're pissing away profit and investor's cash in private companies.
In public organisations, taxpayers don't get to choose if that money is spent or not.
It still doesn't smell right.
* https://github.com/alphagov/
* https://gds.blog.gov.uk/2012/10/12/coding-in-the-open/
Looks great on your CV, you're helping your government do it right, everyone's a winner.
That said, is there a way on GitHub to privately raise a security related issue without the whole world seeing it?
* http://government.github.com/community/
For example:
Sure it's not everything yet, but it's progress. You can still reach the right people and get involved.