IRS misses XP deadline, pays Microsoft millions for patches
computerworld.com
computerworld.com
Yes, this is wasteful, but what else could the IRS have done without approval from congress?
[0] http://www.reuters.com/article/2013/03/23/us-usa-fiscal-budg...
Patching the security issues themselves? I know this can be complex in many cases but the security and reverse engineering community have this knowledge, probably not fixing the whole issue but at least blocking it.
I've wrote an article about doing this here: http://blog.nektra.com/main/2013/08/07/using-deviare-to-crea... last year.
You wouldn't want someone downloading random patches off the Internet or hiring a non-MS employee to make a patch without hiring multiple people to verify the integrity and usefulness of the patch (think backdoor) to fix computers handling your tax information. Do you?
I wouldn't.
You wouldn't download a random patch for heartbleed until openssl releases the official notice and patch. Or you won't download because you want the fix from your distro vendor.
Yes. At the end it's all about trust.
With a good community making hotpatches, and explaining their fixes I will install them.
If they just pull patches from the community themselves, when something goes wrong they will have to take the blame themselves and people will think they are foolish being so reckless. As a techie, this option may seem feasible to you but then again you're just some random guy on HN who probably thinks node.js is the be all and end all of IT. I doubt you've got the intelligence (cleary) or the experience (very cleary) to understand how the IT industry works at a human, risk management and legal level.
No, my company sells hard core technology to big vendors and sign the kind of corporate contracts that you refer in your comment. Since the IRS will not solve the issue there is another route: selling a hotpatch service to another vendor who sells to the IRS.
You will have to be reassure that your patch will work and is risk free. If not, get ready for a bill and possibly a congressional hearing.
Good community is great, but you need to shift responsibility whenever possible. Not that there aren't any kernel hackers work in the public service sector, but they have other important things to do than fixing someone else' product if there's a choice.
No, they're paying $11M so they can say "We paid Microsoft $11M! What else could we possibly do?" when something goes wrong.
Oooops. So much for your talking point.
Go away, troll.
I understand that the government has a contract with MS, but it seems like it might actually be costing the government more to take advantage of the contract.
1. Retraining the users, very few people use linux so it would be a massive undertaking to retrain their thousands of mostly non-technical workers to use a new, unfamiliar, operating systems.
2. Microsoft Office. Say what you want about LibreOffice and OpenOffice but when it comes to enterprise grade software MS Office is unrivalved, especially concerning Excel.
Side note: Maybe this gets better in 10 years when lots of things have been written on the managed CLR? Although I don't think the challenge Wine has is running the C++ programs, but implementing all of the stubbed out APIs correctly... the same challenge exists with a C# interface.
With regards to MS Office and MS mail client, sure they are more polished, but does that really matter? Are those people crafting an art piece every time they want to add an image to their report? Just an honest question.
Even if they do run Linux, upgrade is still a pain in the ass.
Also Microsoft Office, basically MS's golden egg, is way farther ahead then Libre Office regardless of what people say. All of MS office's services integrate extremely well with each other as much as it pains me to say.
At the end of the day all these people need is Outlook, Word and XL which are leaps and bounds ahead of Libre Office, which doesn't even have a mail client.
Add in all the lobbyist and money going towards the right campaigns and there's your answer.
I accept that migrating to a new platform would entail an amount of disruption, but I don't see what that has to do with anybody being over 40.
The costs lie in training, upgrading hardware, and upgrading user applications (including things that are closed source, discontinued or developed in house by people who have left the organization).
Unfortunately you'd get most of these problems in Linux too.
But they've upgraded to another Windows version, not a * nix. Windows has taken backwards compatibility support to plaid (11 if you're a fan of a different movie). I worked in an office with a data analysis tool written using Visual Fortran in the 1990s for Windows 95. Without retargeting it it runs just fine with a single launch flag set for Windows to use the appropriate compatibility mode. The cost of upgrading user applications is really the cost of testing user applications. Moving to * nix wouldn't be upgrading, it'd be rewriting/porting or significant testing with Wine or some other compatibility layer. [1]
[1] As others pointed out, as more applications run on the CLR porting to * nix will become easier as CLR support improves on those platforms. But that also requires a rewrite, you can't take an existing Fortran or VB or C++ project and retarget it without effort.
The expensive part is upgrading the hardware to support Win7, rewriting all the software that aren't compatible with Win7, training the personnel to use Win7 (and all the newly re-written software). Now, imagine if they were actually trying to upgrade to Linux. They'd pay much more to train the personnel, they'd have to re-write almost every single software they have been using. On top of that, they'd still pay for custom support (and Linux support is considerably more expensive than Windows support).
In my experience running a small business, Linux support was much cheaper than windows support. The Linux professionals seem to charge more but can almost always fix a problem twice as fast as a the support I get from Windows "professionals". I also ended up having less problems with Linux than I did with Windows (after a few initial bumps in the road). I've also talked to quite a few other entrepreneurs and many of them agree that Linux is a fine and much better choice for start-ups simply because you're starting from a clean slate (So there is no legacy code to deal with) and because 90% of small businesses and start-ups consists of a network of 10 or less computers.
Ubuntu is free to install only because your free time has no monetary value. For organizations whose time has monetary value, the cost of an OS license is swamped by the cost of the time it takes to rewrite applications, retrain users, roll out the upgrade, and fix the inevitable breakages.
And like I said above, these costs are present whether you're using Linux or Windows.
(I run ubuntu with xmonad but have never written my own packages)
I know that in the corporate world there are still very many business applications that are mission-critical and very special-purpose (sometimes custom) that were not written in a cross-platform way, and may not be maintained anymore - I would be shocked to find out that it was not this way in the government too.
XP was released in 2001. If they'd adopted Red Hat they'd have adopted 7, and upgraded 22 times, changing distro once to be on Fedora 20. If they'd adopted Ubuntu they'd have had to wait 3 years for the first release (confusingly numbered 4.10), and now they'd be on release 13. Even Red Hat Enterprise Linux didn't become available until 2002, and you'd be on version 2.1, unsupported since 2009.
If you suck at upgrading and want something that will be supported for 12+ years, Linux is not for you.
Edit: Anyway your point is invalid anyway. The reason the IRS suck at upgrading is because they didn't have the budget to pay for said upgrade. Last I heard, it was free to upgrade the majority of Linux distros. Although there may be many other reasons not to switch to Linux, this is not one of them.
(Except the "110,000 computers" bit, this is just one.)
So, you can't just look at the consumer price tag on a Linux distribution ($0) and compare that to what the IRS is paying Microsoft in support contracts - you have to compare it to the total costs of enterprise Linux support.
And if the IRS is having a hard time migrating off of a version of an OS that was released 12+ years ago to its more recent version, I imagine they'd have a hard time migrating to a completely different operating system altogether.
Even if the incremental costs of upgrading LTS versions of a Linux distro ended up being smaller, they simply don't have the up-front capital to cover the costs of migrating to Linux in the first place.
(Oh, and don't forget that even if they did manage to procure that somehow, as soon as Microsoft gets wind of it, the price for Windows support contracts will magically fall).
We're slowly creeping to R, python, etc., and Linux is allowed as a choice (about 10% of us choose it). That said, my lab made it over to Win 7 about 2 years ago now...
I like the linux alternative, but I like even more that decisions like this are made at a local level, rather than through a massive top-down disruptive push.
Switching would be very, very, expensive - and its not clear that it would help even in the long run.
Additionally, Windows is still THE dominant platform for science and engineering work, especially modeling and simulation. How many engineers (non-CS) do you know that do not use Windows? The most popular CAD software, SolidWorks, is available only on Windows. Alibre, the second most popular one, is also Windows only. The next most popular one, AutoCAD, is Windows and Mac only. 3DStudio Max - Windows only.
Most simulation software is also Windows only, at least when I was a government contractor, that was the case.
If the government switches to Linux, they'll have to switch en masse - having some people on Linux and others not won't work very well at that scale of bureaucracy. And when even most engineering software isn't available on Linux, that isn't gonna happen.
It's a concept so basic I'm stunned that anybody would be so bold to write a sarcastic comment about it.
Work with government long enough and you'll find the majority of "waste" comes not from spendthrift government layabouts, but insane auditing and transparency requirements (which require oodles of paperwork and three people to review it to make sure you're not wasting taxpayer money), hamstrung budgets (renting the same building at exorbitant rates because Congress will give you the money for that, but not to buy it outright, which would be far cheaper; paying for continued XP support because you couldn't get the funding for an upgrade), hiring contractors for decades-long jobs, and a legion of other controls in place to save us from government excess.
I'm by no means saying that we should let them run around doing whatever they want, damn the cost, but keep in mind that auditing and transparency have a cost, and we need to look at what's cheaper in the long run and not just in the short term.
I sincerely doubt that the IRS, a revenue department, is running efficiently and is underfunded. I did a cursory search to see if I'm making up crazy claims and it seems like the lack of funding is largely self-reported.[1]
I sincerely believe that this is due to a lack of planning and just 'kicking the ball down the field.' Why go through all the annoying conversations about upgrades when you're going to retire or leave before it matters?
Microsoft first set the end of support for 2011. As a nod to their massive XP user-base, they pushed EOS to 2014. You're suggesting that the IRS is rational in paying for emergency patches to something that they received a 3 year extension on? Windows 7 was released EOY 2009 -- it's not as if they were stuck for lack of options.
This is crap planning and I really doubt that consequences exist.
[1] http://www.taxpayeradvocate.irs.gov/2012-Annual-Report/irs-f... (side note: I like the "automation is bad, boo" bullet-point)
Not everyone that is audited is guilty of tax-evasion.
While I understand write offs when it comes to a business for costs of doing business, there are FREE alternatives (like ubuntu) that the IRS could use. I'm not anti-Microsoft (in fact I'm deving an app for windows phone right now), but seems to me that whoever is managing the IRS' budget are idiots, and their decisions really need to be audited.
Edit: That reminds me, I need to do my taxes.
From 2008 to 2014 it's a long time for any migration to take place. Six years? They could have migrated to OpenVMS and have a team write custom software for them in six years for Christ's sake!
How is this a responsible use of taxpayer money?
It would be much more expensive in terms of hours lost to make the switch.
And they are switching to 7. Inherently, they have the retraining costs already, and Lubuntu or Zorin is much more linear a change than going from no-search no-dock quicklaunch to Windows 7.
EDIT:
Also, retraining to Windows 7 is not really an issue. The issues with going to * nix are numerous. Non-COTS applications that'd need to be ported/recreated. Email infrastructure (what's the state of support for MS Exchange in the * nix world? That is, any applications that integrate as well with Exchange servers as Outlook?). I forgot about the server side in my other post. So much is running on Windows servers. SharePoint has become the de facto document sharing system, this is nicely integrated with MS Office, any * nix equivalent? Exchange is their email server, but does far more than just email - keeping contacts up to date, calendars, shared/group inboxes. Is there a singular application that can replace Outlook in the * nix world? Would they have to switch to 4 or 5 applications to do what one application did before? Will they play well with each other and properly share information (that is, if I create a calendar event in the calendar app will it be integrated well enough with the mail app to let participants now, and then re-sync later on once they've replied? I've never tried to do that in the Linux world, what applications support this?).
EDIT AGAIN: Anyone know how to insert a * next to a word without triggering italics? * <space> nix just doesn't flow right.
And it's not as if KDE 4 (or God forbid, GNOME 3) is so similar to Windows XP as to minimize retraining costs.
I just booted a live Kubuntu and just switched the launcher, removed the activities / show desktop / virtual switcher widgets, switched the desktop from widget to folder mode, and added a quicklaunch widget. Looks and feels exactly like XP at that point. The only exception would be the file manager.
And it is not like you wouldn't be deploying custom images to all your machines - you could tweak all the theming to use MS Windows styles. Hell, some people even got KDE looking like 7 years ago: http://www.lirent.net/2009/05/windows-7-transformation-pack-...
Did you remember to remap Alt-F2 for Krunner (which looks nothing like on XP...) to Win-R?
Did you fix the Lock Screen to look exactly like XP?
I can tell you as a KDE dev myself that although you can do amazing things regarding look-n-feel, there is still a big difference. Even on things that are not very different between the two, that simply becomes an "uncanny valley".
I really doubt that people in most government agencies are using these features.
And if they're intelligent enough to use these features, learning to use Unity would not be a huge hurdle.
For a specific example: unless LibreOffice or Google Sheets develops a solid equivalent to the Solver add-in, replacing Excel will be a non-starter in any department that deals with Engineering data.
2. Custom Windows-only applications
3. Really, really good price on support contracts - which they'd insist on getting if they switched to any *nix. Oracle (formerly Sun), IBM, RedHat (?). Are there any other major players in the OS world that can offer anywhere near the level of support that the government has come to expect?
4. And as Igglyboo said, MS Office. So many workflows in corporate environments depend on that damned suite, it'd be difficult to move away from it at the moment.
---
There are many offices that could make the transition. They use all web applications and various office suite tools (Excel, Word, PowerPoint mostly). The other applications they use would be things like Acrobat (but office suites can generate PDFs directly these days) and software to fill out forms (not handled as DOC/DOCX files or PDFs). The latter may be able to transition to signed/fillable PDFs. But these aren't the majority. Too many offices (particularly anything involving project management or inventory management) just depend too much on custom desktop applications that would take too much to port over or rewrite. It's like trying to modernize the avionics systems of an aircraft: in theory it'd be great, in practice your developers will kill themselves.
>How is this a responsible use of taxpayer money?
The same way the govt decides to purchase Cisco's $25,000 wifi routers for city libraries.
Look, I'm a programmer turned engineering manager and I totally get where you're coming from with this comment, but you just don't seem to get how and why things are the way they are.
Speaking personally, I managed a project a few years ago to replace MS Office 2003 with Libre Office 4.0 (we actually started with OpenOffice but when Oracle acquired Sun and The Document Foundation was created to house the OO.o fork, we switched out of antipathy for Oracle). The mission was to remove MSO from as many machines as feasible, and the decision of what was feasible was, for the most part, left to me. We managed to convert about 20% of users, and these were composed of about 75% machines that never executed any Office app anyway and about 20% of machines whose users were just consumers of files other people created. Only about 5% of the machines converted belonged to creators. We found that most macros and custom formatting and blahblahblah were fairly straightforward to convert to work in LibreOffice, but the UI/UX was horrific, sometimes things just didn't work, and productivity was adversely affected far beyond the cost of the licenses.
We migrated to Gmail and Google Apps from Exchange+Outlook at the same time and saw similar adoption issues with Google Drive ("Docs" at that time -- in 2008). We (I) didn't make the mistake of forcing the issue this time and relied on coercion and organic growth to build the foundation for broad support. Today we are seeing about 1500 Sheets and ~500 Docs & Presentations created weekly (~22,000 users). Most of them still have MS Office on their machine, too.
Because, guess what, the right tool for the job is important.
(another commenter noted the haphazard and often ridiculous release schedule and evolution of RedHat / Fedora, BSD and Ubuntu over the past ten years or so. In my company, the Linux guys are mostly on their own to build their own environment because it became too unpleasant for corporate IT to create and maintain a standard image that worked well enough for most people most of the time. The devs these days tend to prefer Arch and Ubuntu and the sysadmins often run Fedora (our prod servers are almost always RHEL ... because guess what -- support is kinda important to most companies, especially big ones that aren't technology companies and where internal support is often understaffed and underequipped to DIY everything.)
This probably comes off rantier than I had hoped, and for that I apologize. Perhaps I'm just getting to CIO'y in my old age. :(
To me, that seems like a very prudent decision.
In short, it's not a confidence-inspiring roadmap, and I think waiting a year is a valid choice.
Maybe it's time the FBI upgraded to touch screens anyway.
2. Backdoor prone black box. Something like Windows - buy licenses, get support from a 3rd party, be ignorant about product itself due to withheld software freedoms - works for the small to medium business. When you are federal scale, it makes no sense to spend tens or hundreds of millions in MS tax when you could, for a fraction of the price with a small dev team, maintain your own Linux fork. And while the IRS is on the "same side" as the NSA, who puts back doors in Windows, it should be hard to sleep at night knowing Microsoft could be bought off like that, and that China might do the same. Unless they get special source access to inspect it, at that scale they might.
3. No package management. For enterprise deployments, I've dealt with enough small businesses who just sit on half a decade old Firefox or Chrome because they can't enable the auto updater and didn't set up an Active Directory applications server. So the middle road is just having your own package repository of updates with all the machines synced to it pushing whatever new stuff you want available automatically.
And you could also throw in that a GNU/Linux distros modularity makes it much more reasonable to deploy to servers, embedded devices, and desktops at once with one maintenance crew. And if the IRS is running Windows Server.... taxpayer dollars at work, all right.
2. Didn't like my response to this, may edit later.
3. Now this is reasonable, software installation on Windows sucks by default. However, there are some good tools out there for handling the distribution of software. I recall using some when I worked in IT at a university. Ghost had a way to do it that was essentially taking a snapshot, installing, then another snapshot. The difference was what got installed onto the rest of the computers. There was also a piece of software we used that let us handle on-demand software installation for things with limited keys (like Matlab), I don't remember (a decade ago now) what this one was. Not baked in, but it was more than serviceable as I recall.
4. IRS probably still has a fair number of mainframes. If they're like other federal agencies they'll have a mixture of Solaris, Windows and Linux servers installed depending on the contract at the time the information system was put together. Again, that modularity would be nice, but it's hardly practical unless the fed establishes one organization to be responsible for making, supporting and distributing this OS. Then you'd get a bunch of folks on the right bitching about government interfering with business, and people on both sides bitching about the security/privacy implications.
2. You are severely overestimating the ability of the government to hire a "small dev team" competent enough to build a custom Linux fork. The bulk of cost, no matter if they go Windows or Linux, is support. That's because it's really, really hard to manage software entirely through internal means, even if the product is completely open-source.
Furthermore, who's to say that the feds don't already have access to Windows source? At this point, it's impossible to know, but the idea that MS could be "bought off" by China is absurd. They're an American company whose operations and finances are largely based in the United States. You would have to have a high-ranking executive (or collection of executives) commit blatant treason, high the bribery money in some other country, AND convince a large number of MS developers to be completely quiet about an exploit placed in Windows source code on purpose. And not an exploit placed there under the threat of criminal punishment by the "legitimate" American government but an exploit that would send hundreds of employees to federal prison. I'm paranoid enough to admit that it is theoretically possible, but waaaaaay less likely than waaaaaaay more things that we should be legitimately worried about.
3. You say there's "no package management" and then you go on to explain how there is package management but that it's not setup correctly. The IRS is not a small business. Microsoft provides high-end support to them so that they can properly setup Active Directory and WSUS. And if they went Debian or Ubuntu, they'd pay the same money to properly setup those package managers.
Not to mention all the sheer costs of deploying and transitioning to a completely new infrastructure, as well as training thousands of relatively low-skill workers to use a completely foreign system. Oh, and rebuilding tons of custom software that wouldn't be in any public package repository anyway.
Anyway, OP's original point was that Windows 7 and 8 are garbage compared to XP, which is blatantly wrong. They're both very stable operating systems, and while it's fine to debate WHEN MS should cut off support for XP, it's an inevitable fact that they eventually MUST. The IRS has to upgrade eventually, and they've had a heads up for a while. It should've been done already.
[1] https://help.ubuntu.com/community/Installation/SystemRequire...
If you calling Windows 7 a disaster compared to XP, am sorry but you have no idea what you are talking about!