Visa Systems Issues
travel.state.gov
travel.state.gov
If it's a purely hw issue, say a piece of highly specialized hardware (hw crypto, piece of old mainframe, etc), it can take a very long time to source it (although a SPOF is surprising in such a critical infrastructure), but it does not take 100 people to work on it, 24/7. It requires a dozen guys making angry phone calls every 2 hours to some suppliers...
If it really takes 100 people 24/7, mostly likely explanation to me is that it's software related and they have to rewrite a critical sw in record time. Causes:
-bugfix (which may be entirely unrelated to secrity)
-emergency migration from one hw vendor to another, for sourcing reason which entails rewrite of a part of the system.
Edit: forgot to put a reference. This is the official website to renew the National Identity Document:
- https://www.citapreviadnie.es/
You also got the big warning notice saying 'This Connection is Untrusted' on Firefox and Chrome? Yep, it's been a feature for many years.
Subcontractor which did the work:
- 2 devs - 1 accountant - 1 project manager
Contracted under:
- 1 project lead - 1 dev lead - 4 QA engineers - 1 lead QA engineer - 3 accountants - 1 lead accountant - 2 document reviewers - 1 lead document reviewer
The actual people doing the work spent 1 month writing documentation and then changed ...10 lines of code. This software was not mission critical, no lives were at stake, and if there was a bug the danger was negligible. That's government in action.
I whole heartedly believe that there are 100 people at work here.
Were all these people 100% on the project? My experience is that these roles usually are overhead for lot's of projects.
It could also be manual verification. Say they had two or more database nodes, a hardware failure on one could cause them to go out of sync and then they need to verify all the divergent changes.
Of course, a backup that can't be restored (or nobody knows how to restore) is more or less equivalent to not having a backup, so this distinction probably doesn't matter.
// always remember to test your restore plan
I _hope_ they don't have someone saying "we had a backup - it was on a RAID set!".
It would surprise me less to discover the reported migration from Oracle on Windows to Oracle on Linux was still partly done, and they were taking solid reliable useable backups - of the old not-yet-decommissioned windows db servers...
(For the record, I've made both of those mistakes (and more) in my career... Fortunately neither represented weeks of 24x7 remedial work by 100s of people.)
There's a pile of folks between a few contractor firms, and the staff in the offices that manage those contracts, whose current top priority is fixing whatever the issue is.
They said specifically that embassies and consulates were having problems doing biometric checks, which I would imagine requires a State system to talk to a number of other federal/intel/defense systems to do records look-ups. If we do some further supposing, that web of interconnected systems may have had some underlying issues and I could definitely see it taking some time to get each firm involved in building or maintaining those systems together to figure out where the issues are and to figure out how to fix it.
This certainly is the case with the UK Passport office when it has issues.
Imagine that software depends on complex hardware, but it's not manufactured anymore, or the gov can not legally buy it anymore (contract expired). If it fails, it must be ported ASAP, what can take that kind of work.
I've never seen something like this happen, but I've seen enough instances of it being possible to imagine it would happen once in a while.
http://foia.state.gov/_docs/PIA/ConsularConsolidatedDatabase...
"The Consular Consolidated Database (CCD) is one of the largest Oracle based data warehouses in the world that holds current and archived data from the Consular Affairs (CA) domestic and post databases around the world. As of December 2009, it contains over 100 million visa cases and 75 million photographs, utilizing billions of rows of data, and has a current growth rate of approximately 35 thousand visa cases every day"
Unclear what's gone wrong this time, but the mention of "biometrics" (like photographs) makes me suspect it's the same system.
http://fcw.com/Articles/2014/10/20/State-Department-database...
Typical quote: "We knew we could run it on one node. We needed to have one very powerful node."
As someone who has done government contracting...it's always alarming when this path is suggested. The last time was a beefy server with about 50TB of ram to keep all data in memory with multiple hard drives to keep backups. Ugh.
I and I'm sure many others would be very interested in a blog post or long-ish comment with anecdotes and lessons learnt...
I wish I could but it wasn't my direct project so I wasn't part of the team implementing it. I'm not even sure it was successfully delivered.
"This is not the same problem we had with the CCD last year, which was a problem with the database caused by a software patch. This is a hardware failure, and we are working to restore system functions."
And just to be clear, that's (mostly) a good thing.
Who would you call?
[1] http://www.law.umaryland.edu/marshall/crsreports/crsdocument...
Now you have two problems.
+------------+------------+--------------------------------+
| asset_id | asset_name | asset_data |
+------------+------------+--------------------------------+
| 2147483646 | firstName | Joseph |
| 2147483647 | lastName | Bloggs |
|-2147483647 | phoneNumber| +1 415 555 1234 |
|-2147483646 | email | joebloggs@gmal.com |
+------------+------------+--------------------------------+
(I think I still have brain damage from trying to get "too smart" with a Magento eCommerce site once...)June 4th - OPM breach announced. June 12th - OPM confirms security clearance records exposed.
I'm glad I don't have an urgent need to US visa or passport or any form of vaguely federal security or residency or travel related paperwork to go through.
If this where a business, they'd be losing customers... but thankfully, they're a government apparatus that holds people over a barrel and doesn't have to provide enough decent service to offer enough visas to meet the demand, hence 12-30 million undocumented immigrants.
I don't have the numbers but looking at the amount of illegal immigration into Europe, and looking at what "jobs" most of the semi-legal (refugees, asylum seekers etc.) who also outweigh the amount of high skill labor coming into Europe I won't say this is a US specific problem.
I would also suspect that Canada with it's point based system has the same issue as well. Their immigration system is just more publicized and was given a priority especially during the late 90's and early 2000's since they felt like they were losing the competitiveness with US based companies.
Heck I've been to Canada 3 times in the past 5-6 years and the amount of what i would assume is "illegal" immigration in some of the cities there seems to also be quite high, quite a high percentage of Asian and African decent workers that don't speak English or French and seem to be very wary of people in general.
Leaving aside the issue of whether such a service needs to be centralized or to exist at all, if you substitute human evaluation for a set of algorithmic rules, a systems cracker can corrupt the entire cartel more easily than someone individually subverting possibly thousands of independent human actors.
In terms of many of the other services typically provided by government, yes, those could potentially be replaced by software.
But how about making it more lean? How about modernizing with the times? How about making it all much more transparent and accountable? Couldn't open source software do all of this?
We could start with systems that are used by smaller, poorer countries & grow from there.
A visa processing system might be a good start.
Keep at it. The feeling when it's finally over is great.
I immigrated to Japan - a country often held up as an example of xenophobia and resistance to immigration, and it only took a week for my spouse visa paperwork to be examined and approved. The only cost was for translations of some paperwork from home ($40 at the embassy) and then $20 for the residence card once I was approved.
http://www.fbi.gov/about-us/cjis/identity-history-summary-ch...
So they can record all our conversations in real-time, but it takes 3-4 months to do a simple query of criminal records.
You clearly have not read any of the Snowden docs.
Best friend's wedding might not qualify as a good enough reason, but combined with the long delay it might - definitely worth your time talking to them.
I know someone who got this kind of pass to visit her sick father.
America has been so obsessed with thinking of itself as the "best country in the world!(TM)" for so long, it has meanwhile regressed into a failed state.
'failed state' is certainly hyperbole here -- there are large elements of society which continue to function, despite the problems at the national government level. It would truly be a failed state if, for example, the national government's performance level were propagated to the whole society.
So this amounts to saying that the U.S. is dysfunctional compared to the most developed part of the world, which is almost a tautology.
Not to say that the US hasn't made a lot of stupid laws and policies around immigration, but they're not alone.
have they fixed their data-leak into archive.org yet? (LOL) http://blog.valbonne-consulting.com/2015/05/20/misconfigurat...
Unless they're NEXUS pass holding Canadians, in which case they have been fingerprinted. I just got fingerprinted this weekend for a NEXUS pass; my fingerprints are apparently "perfect". The US CBP agent taking them advised me not to take up a life of crime, as I would be caught very quickly. Or at least to wear gloves.
I arrived two weeks ago, no finger print required.
If your canadian, probably not.
"The Bureau of Consular Affairs reports that the database responsible for handling biometric clearances has been rebuilt and is being tested. 39 posts, representing more than two-thirds of our normal capacity, are now online and issuing visas. We are working to restore full biometric data processing."
If the downtime was anticipated it can always be averted. Even a Fortune 500 can expect some downtime over a period large enough.
Take Sony earlier this year. The US government itself the year before.
But Polish airlines is down too (unrelated systems I guess)... but could this be something coordinated?
Ah... probably not :)
Dated megaliths: 0
(Edit: Sheesh, what's with all the downvotes? Hardware failures are a route-aroundable thing that should never cause downtime... as long as you don't adopt an outdated "here sits the one source of truth, and its name is [fat server manually configured]" psychology. HA clustering is at the point where it's a generic, drop-in thing for arbitrary services. If you fail to recognize the above, go do some learning.)