Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Friday, 28 September 2012

Identity assurance – the clock is ticking, your moderation is awaiting comment

28 September 2012 and a reply to yesterday's enquiry has whizzed in from GDS, followed by a reply to the reply:

steve #

Thanks for your comment, David.

Firstly, please don’t take our lack of posts as evidence of inaction. We’ve actually been incredibly busy over the summer and are expecting a bumper crop of posts in October, to share what we’ve been up to. So, watch this space.

Secondly, DWP are still working to resolve final contractual issues. The outcome will only be made public when final contracts are signed.

Steve

28/09/2012

steve #

Furthermore, this notification will come from DWP, not Cabinet Office or GDS, as it is their framework.

28/09/2012


dmossesq #

Please Note: Your comment is awaiting moderation.

Dear Mr Wreyford

Thank you for your reply.

I don’t mistake the absence of posts for inactivity – as I said, surely there must have been some activity in view of the importance of Universal Credit.

You say that “DWP are still working to resolve final contractual issues”. Ex-Guardian man Mike Bracken made it clear on 1 March 2012 that Identity Assurance belongs to the Cabinet Office and not DWP: “… this approach ensures that, ultimately, HMG-wide Identity Assurance is supplied across central departments via a common procurement portal (to HMG agreed standards) and governed by the Cabinet Office”. Presumably GDS are involved in those “final contractual issues” just as much as if not more than DWP*.

The absence of posts does create a vacuum, though, which draws in all sorts of flotsam …

The Department for Business Innovation and Skills (BIS) midata initiative, for example. Why are GDS using BIS to try to legislate for Personal Data Stores/Inventories (PDSs/PDIs) instead of doing it themselves?

And GOV.UK – why waste a lot of time and money re-writing central government websites? Is it to provide consistent hooks for PDS-based identity assurance in all government communications over the web?

A PDS is a dynamic dematerialised ID card, isn’t it. The public won’t “wear it”. Neither will the banks if the Cabinet Office try to insert PDSs into the nation’s payment systems.

If Google and/or Facebook turn out to be on the list of GDS-approved suppliers of identity assurance services, then DWP and everyone else will have wasted their time negotiating any contractual issues, final or otherwise. Again, the public won’t wear it.

And the GOV.UK team will have wasted their time.

And BIS will have wasted their credibility …

Goodness, just look at all that dust, you never can tell what the vacuum’s going to draw up, can you. The sooner GDS can tell an expectant public what you’ve come up with identity assurancewise, the better.

———-

* While writing this reply of mine, your second reply popped up, trying to push responsibility back on to DWP. Too late, Mr Wreyford. The Cabinet Office burnt their bridges when they made DWP withdraw their December 2011 OJEU notice. You know that. If Universal Credit fails for lack of identity assurance, that will be the Cabinet Office’s fault now and not DWP’s.

28/09/2012
The last comment will only appear on the GDS blog after moderation by them and only if they want it to appear.

Identity assurance – the clock is ticking, your moderation is awaiting comment

28 September 2012 and a reply to yesterday's enquiry has whizzed in from GDS, followed by a reply to the reply:

Thursday, 27 September 2012

Identity assurance – the clock is ticking, your comment is awaiting moderation

27 September 2012 9:30-ish, posted on the Government Digital Service (GDS) blog here and here:
dmossesq #

Please Note: Your comment is awaiting moderation.

Steve Wreyford’s post on OIX is the latest on the ID assurance blog and is dated 14 June 2012, three months ago.

Has there been no activity on identity assurance since then?

Surely there must have been some, GDS are due to announce by the end of September – 85 hours time – which bidders have been approved to provide identity assurance services as per the 1 March 2012 notice in OJEU.

When will we be told who the winners are?

27/09/2012

Identity assurance – the clock is ticking, your comment is awaiting moderation

27 September 2012 9:30-ish, posted on the Government Digital Service (GDS) blog here and here:
dmossesq #

Please Note: Your comment is awaiting moderation.

Steve Wreyford’s post on OIX is the latest on the ID assurance blog and is dated 14 June 2012, three months ago.

Has there been no activity on identity assurance since then?

Surely there must have been some, GDS are due to announce by the end of September – 85 hours time – which bidders have been approved to provide identity assurance services as per the 1 March 2012 notice in OJEU.

When will we be told who the winners are?

27/09/2012

Tuesday, 25 September 2012

Identity assurance – the clock is ticking, ex-Guardian man Mike Bracken's chickens are coming home to roost

The Government Digital Service (GDS) is part of the Cabinet Office and has six projects on hand, including Identity Assurance:
The ID Assurance team are working on accrediting and approving third party identity to facilitate digital transactions between citizens and government.
If "citizens" and the government are to transact business on-line, there must be a rock solid identity assurance service so that each party knows who it's dealing with. Invitations to tender for the service were issued earlier this year.

GDS haven't so far publicly approved any third parties to provide identity assurance, but we shouldn't have long to wait – no more than five days, in fact:
The tendering process will run for several weeks and is expected to report successful bidders in September 2012.
Delays are only to be expected. Identity assurance for the entire population of the UK is a big project.

But in this case there can't be any delays. The joint GDS/DWP notice of the identity assurance project states that identity assurance is required to be ...
... fully operational from spring 2013.
That's six months time if we measure to the start of next spring, or nine months if we measure to the end. Either way, DWP's Universal Credit (UC) scheme has to be up and running by October 2013 and UC depends on identity assurance as Lord Freud, the welfare reform minister, has emphasised – no identity assurance, no UC.

Appearing before the House of Commons Work and Pensions Committee, Lord Freud was asked what is the biggest risk facing UC. His answer – identity assurance.

Why did DWP allow this dependency/risk? Why didn't they write their own invitation to tender?

They did. Then they withdrew it. Apparently at the command of the Cabinet Office. Because next thing, GDS announced that:
... this approach ensures that, ultimately, HMG-wide Identity Assurance is supplied across central departments via a common procurement portal (to HMG agreed standards) and governed by the Cabinet Office.
"Governed by the Cabinet Office" – GDS have put themselves on the spot. If UC fails now, is it Iain Duncan Smith's fault? Or Francis Maude's?

GDS must approve several accredited suppliers of identity assurance services in the next 120 hours. Who's likely to be on the list?

GDS are only offering up to £30 million for the identity assurance service and they're only letting contracts for 18 months.

The Home Office tried for eight years to issue us all with ID cards. They failed.

Which companies can afford to assure the identities of everyone in the UK – or at least the identities of the 21 million expected claimants for UC – for only £30 million? Which companies can afford to take the risk of losing their contract to a competitor only 18 months later? Not many of them. It can only be a short list.

The banks/credit card companies/PayPal, the phone companies, the utility companies and IBM might be big and competent enough. But they have to think about the failure of the Home Office and about reputational risk.

They wouldn't be in control of the identity assurance service. GDS would be, and if anything went wrong, even if it wasn't the contractors' fault, the banks/phone companies/utility companies/IBM would see their brands destroyed.

Any chief executive of a bank/phone company/... who signs up for one of these GDS identity assurance contracts would be roasted by the equity analysts and by their shareholders. Which means they won't.

We can probably forget the insurance companies and the credit rating agencies. Who else does that leave?

Google and Facebook.

In no more than 118 hours now and counting, ex-Guardian man Mike Bracken, executive director of the Government Digital Service and Senior Responsible Officer Owner for the Identity Assurance programme, is going to have to host a press conference at which he announces that he thinks it's a good idea for Google and Facebook to provide the electronic identities of everyone in the UK.

If you get an invitation, don't miss it.

Identity assurance – the clock is ticking, ex-Guardian man Mike Bracken's chickens are coming home to roost

The Government Digital Service (GDS) is part of the Cabinet Office and has six projects on hand, including Identity Assurance:
The ID Assurance team are working on accrediting and approving third party identity to facilitate digital transactions between citizens and government.
If "citizens" and the government are to transact business on-line, there must be a rock solid identity assurance service so that each party knows who it's dealing with. Invitations to tender for the service were issued earlier this year.

GDS haven't so far publicly approved any third parties to provide identity assurance, but we shouldn't have long to wait – no more than five days, in fact:
The tendering process will run for several weeks and is expected to report successful bidders in September 2012.
Delays are only to be expected. Identity assurance for the entire population of the UK is a big project.

Tuesday, 14 August 2012

Cloud computing – we hold these truths to be self-evident ... and we're plumb wrong

Much of government IT is a mess.

That's the problem.

And cloud computing is the solution. What the UK Constitution needs is a government cloud, a G-Cloud.

Is that true? You know it is – it's a no-brainer.

Cloud computing is cheaper than the alternative and it always will be. You know that. It's more flexible – you can spin up new capacity whenever volumes rise, just like that, and switch it off at no cost the minute it's not needed. You don't need to worry, the level of security is higher than could be achieved in-house, someone else does the backups for you and keeps all the applications you have licences for up to date.

That's the sales pitch of the big suppliers of cloud computing services – Amazon, Google, Microsoft, Apple, ... And coincidentally it's the UK government's IT strategy. There can be no doubt.

Now consider this 6 August 2012 article in Wired magazine by Mat Honan:
In the space of one hour, my entire digital life was destroyed. First my Google account was taken over, then deleted. Next my Twitter account was compromised, and used as a platform to broadcast racist and homophobic messages. And worst of all, my AppleID account was broken into, and my hackers used it to remotely erase all of the data on my iPhone, iPad, and MacBook.

In many ways, this was all my fault. My accounts were daisy-chained together. Getting into Amazon let my hackers get into my Apple ID account, which helped them get into Gmail, which gave them access to Twitter. Had I used two-factor authentication for my Google account, it’s possible that none of this would have happened, because their ultimate goal was always to take over my Twitter account and wreak havoc. Lulz.

Had I been regularly backing up the data on my MacBook, I wouldn’t have had to worry about losing more than a year’s worth of photos, covering the entire lifespan of my daughter, or documents and e-mails that I had stored in no other location.

Those security lapses are my fault, and I deeply, deeply regret them.

But what happened to me exposes vital security flaws in several customer service systems, most notably Apple’s and Amazon’s ...
Where was Apple's security? And Amazon's? Where were their backups? Why can't they just go to their backups and retrieve Mr Honan's digital life?

Still. Don't let this dent your confidence in G-Cloud.

Cloud computing – we hold these truths to be self-evident ... and we're plumb wrong

Much of government IT is a mess.

That's the problem.

And cloud computing is the solution. What the UK Constitution needs is a government cloud, a G-Cloud.

Is that true? You know it is – it's a no-brainer.

Cloud computing is cheaper than the alternative and it always will be. You know that. It's more flexible – you can spin up new capacity whenever volumes rise, just like that, and switch it off at no cost the minute it's not needed. You don't need to worry, the level of security is higher than could be achieved in-house, someone else does the backups for you and keeps all the applications you have licences for up to date.

That's the sales pitch of the big suppliers of cloud computing services – Amazon, Google, Microsoft, Apple, ... And coincidentally it's the UK government's IT strategy. There can be no doubt.

Now consider this 6 August 2012 article in Wired magazine by Mat Honan:

Monday, 11 June 2012

A senior Whitehall insider publicly cites 23 reasons why the relationship with Government IT suppliers is poisoned, and no-one disagrees – who cares?

On 20 October 2011, when he was still an Executive Director of the Cabinet Office, Chris Chant delivered a famous speech to the Institute for Government about Government IT. He said that:

Introducing Chris Chant
Chris has a long track record of success in delivering complex business and technology change in the public sector. Most of his work has involved working in successful partnership with multiple public sector bodies and the largest IT suppliers in the industry, where he has championed innovative approaches which challenge attitudes on both sides of the partnership. His recent work has included stints as the Programme Director in the Cabinet Office leading the UK Government’s move to cloud computing and data centre consolidation across the public sector. Previously, Chris was Director of London 2012 Integration and Assurance and also Chief Information Officer within the Government Olympic Executive, and also held specific responsibility for ensuring integrated delivery of the security systems required. Before that, Chris was CIO for Defra, where he led a major IT service improvement programme with a strategic outsourcing partner. After his early career in the (then) Inland Revenue and later, HMRC, he worked at the cabinet Office where he was programme director for a range of large and complex multi-agency IT services, including the Government Gateway.
  1. Government IT is outrageously expensive ...
  2. ... and ridiculously slow
  3. It is poor quality ...
  4. ... and not user-centric
  5. No-one knows how many staff are employed or what they do or how much they cost
  6. No-one knows whether contracts with suppliers can be terminated or how much it would cost to do so
  7. No contract should be signed for a term of more than 12 months but they are – they are signed for years into the future, far beyond the time when anyone could know what will be wanted by then
  8. Procuring Government IT should be like buying a suit from Marks and Spencer – M&S do not make you promise in advance to buy x suits over the next y years before opening a shop in your vicinity
  9. The Government doesn't know what IT systems it owns, how much they cost and even whether they are used
  10. They don't know if users have given up using systems and, if so, why
  11. Government can't communicate with its customers securely
  12. Government pays £3,500 p.a. per PC
  13. Staff should be allowed to use Twitter and YouTube at work but they're not
  14. Call centre staff should have access to the systems they are trying to support but they don't
  15. 80% of Government IT is supplied by just five contractors
  16. Departments outsource their strategy to contractors and consultants
  17. It can cost £50,000 to get a single line of program code amended
  18. It can take 12 weeks to get a new server commissioned whereas with Amazon there is no wait
  19. Government should use small and medium size suppliers whose IT practices are more "agile" but instead they stick with the big ponderous suppliers
  20. Government keeps paying for IT resources even if they're not used
  21. They waste time and money as one department after another performs the same job of assessing the same products for the same job
  22. Prices are not forced down, competition is not working and there is no incentive for contractors to do a good job ...
Mr Chant recommended several times over the ensuing months that Government IT professionals who couldn't deliver a better service should consider their position.

In the event, they're still in place, and it's Mr Chant who has gone – he retired at the end of April 2012 ...

... but not before giving one last speech (25 April 2012, SOCITM Spring Conference) in which he revealed a 23rd problem – that Government departments have in the past agreed, at the suppliers' insistence, not to tell each other how much they are paying for IT services:
There were times when we couldn't talk between government departments about one organisation's contracts with another ... Not being able to discuss contracts between government departments is crazy.
No-one has contradicted Mr Chant.

Not a soul. Not a politician, not a civil servant, not a contractor, not a consultant. No-one.

We may take it, then, that Mr Chant's view of the current state of Government IT is accepted without demur. He is right. This is the state of the art. This is the conventional wisdom – the relationship between Whitehall and its IT suppliers is poisoned and the public are being fleeced. After three decades of outsourcing and privatising. Three decades of introducing private sector methods and private sector personnel.

Mr Chant's views are consonant with the findings week after week of the National Audit Office and with the judgements of the Public Accounts Committee and the Public Administration Committee, see for example Public Administration Committee – Twelfth Report, Government and IT– "A Recipe For Rip-Offs": Time For A New Approach (18 July 2011).

To be fair, Mr Chant does offer a new approach. Cloud computing. Which, the way he tells it, will solve all 23 problems at a stroke. That is the new IT strategy being pursued by Whitehall, see particularly HMG's G-Cloud (Government Cloud) website and blog.

But beware. Where is Government IT strategy made, according to Mr Chant? Answer – in the offices of the suppliers.

HMG's sales promotion of cloud computing is indistinguishable from the suppliers of cloud computing's own sales literature. Often, they are the same suppliers who suffer from the 23 deficiencies above who now claim to be "agile" and to be committed to cutting costs by – Mr Chant's figure – up to 82%.

Is it likely that the same Whitehall officials dealing with the same suppliers will reverse the lucrative practices of 30 years and now show mercy to the taxpayer? Is it likely that the same Whitehall officials dealing with new suppliers, like Google and Amazon and maybe Facebook, will deliver any better value for money to the public?

No.

to be continued ...

A senior Whitehall insider publicly cites 23 reasons why the relationship with Government IT suppliers is poisoned, and no-one disagrees – who cares?

On 20 October 2011, when he was still an Executive Director of the Cabinet Office, Chris Chant delivered a famous speech to the Institute for Government about Government IT. He said that:

Introducing Chris Chant
Chris has a long track record of success in delivering complex business and technology change in the public sector. Most of his work has involved working in successful partnership with multiple public sector bodies and the largest IT suppliers in the industry, where he has championed innovative approaches which challenge attitudes on both sides of the partnership. His recent work has included stints as the Programme Director in the Cabinet Office leading the UK Government’s move to cloud computing and data centre consolidation across the public sector. Previously, Chris was Director of London 2012 Integration and Assurance and also Chief Information Officer within the Government Olympic Executive, and also held specific responsibility for ensuring integrated delivery of the security systems required. Before that, Chris was CIO for Defra, where he led a major IT service improvement programme with a strategic outsourcing partner. After his early career in the (then) Inland Revenue and later, HMRC, he worked at the cabinet Office where he was programme director for a range of large and complex multi-agency IT services, including the Government Gateway.
  1. Government IT is outrageously expensive ...
  2. ... and ridiculously slow
  3. It is poor quality ...
  4. ... and not user-centric
  5. No-one knows how many staff are employed or what they do or how much they cost
  6. No-one knows whether contracts with suppliers can be terminated or how much it would cost to do so
  7. No contract should be signed for a term of more than 12 months but they are – they are signed for years into the future, far beyond the time when anyone could know what will be wanted by then
  8. Procuring Government IT should be like buying a suit from Marks and Spencer – M&S do not make you promise in advance to buy x suits over the next y years before opening a shop in your vicinity
  9. The Government doesn't know what IT systems it owns, how much they cost and even whether they are used
  10. They don't know if users have given up using systems and, if so, why
  11. Government can't communicate with its customers securely
  12. Government pays £3,500 p.a. per PC
  13. Staff should be allowed to use Twitter and YouTube at work but they're not
  14. Call centre staff should have access to the systems they are trying to support but they don't
  15. 80% of Government IT is supplied by just five contractors
  16. Departments outsource their strategy to contractors and consultants
  17. It can cost £50,000 to get a single line of program code amended
  18. It can take 12 weeks to get a new server commissioned whereas with Amazon there is no wait
  19. Government should use small and medium size suppliers whose IT practices are more "agile" but instead they stick with the big ponderous suppliers
  20. Government keeps paying for IT resources even if they're not used
  21. They waste time and money as one department after another performs the same job of assessing the same products for the same job
  22. Prices are not forced down, competition is not working and there is no incentive for contractors to do a good job ...

Thursday, 31 May 2012

A suggestion for Jon Ungoed-Thomas and Philip Johnston, published on a blog provided "free" by Google

Two articles in the Sunday Times by Jon Ungoed-Thomas – Your emails, sex secrets and health details – all harvested by Google and Google grabs secrets of private lives – and one in the Telegraph next day by Philip Johnston – That car in your street was a Google Street View search engine.

While Google was filming our streets it was also collecting information about our WiFi networks. Without permission and without telling anyone. That was a mistake, said Google when they were found out, which is an odd thing for Google to say. The whole point about Google is that they don't make mistakes.

The US Federal Communications Commission are fining Google $25,000 for impeding their investigation of the matter. Google had revenues in 2011 of $37.905 billion on which it made profits of $9.737 billion. The fine amounts to 81 seconds of profits and is thought not to have dealt a mortal blow to the company's share price.

According to Jon Ungoed-Thomas, Google's telecommunications interception system was designed by Mr Marius Milner, a Trinity College Cambridge maths graduate, who handed it over to Google recommending that they'd better get a ruling from a privacy lawyer before using it.

At which point the claim that Google's Street View cars used Mr Milner's system by mistake all over the world for several years starts to look a bit threadbare.

We all know that Google record our web searches and read our email and do something with the information they glean there about our preferences and interests. We never pay them for the use of any of their excellent services. We know there's something odd there. Where does the $38 billion annual revenue come from? We latter-day Dr Faustuses prefer not to ask.

Mr Johnston muses in his article about the attitude of the young today, incontinently spraying their personal information all over the web, no sense of decency, or privacy, no dignity. Or words to that effect. He is rewarded for this perfectly sensible observation by being called an "old fart" by one of Google's astrosurfers commenting below the line.

DMossEsq made a much politer comment but it was deleted. Several times. Every time it was submitted. So quickly that it must have been deleted by an automated old fart.

No such indignity on the Sunday Times website (a website readers pay for, incidentally), where the comment was published and is still there:
... Note that the Department of Business Innovation and Skills want Google to help provide us all with "personal data stores" as part of the department's midata project.

And that the Cabinet Office look to Google to provide us with electronic identities so that public services can all become "digital by default".

And that Whitehall's plans for a G-Cloud – a government cloud – rely on Google and others storing our data on their servers in a gigantic leap of faith in so-called "cloud computing".

HMG seems to be desperate to invite Google into our lives and to hand over the responsibility for public administration to Google in a re-run of the Pied Piper of Hamelin, http://www.dmossesq.com/2012/04/amazon-google-facebook-et-al-latter-day.html

Why? Have they given up? Is government too difficult for them?
There's the story Messrs Ungoed-Thomas and Johnston should be writing, surely – in the name of modernisation and transformational government, the middle-aged delinquents of Whitehall are openly planning to hand over our personal data en masse to Google and others. How much will that free lunch cost us?

A suggestion for Jon Ungoed-Thomas and Philip Johnston, published on a blog provided "free" by Google

Two articles in the Sunday Times by Jon Ungoed-Thomas – Your emails, sex secrets and health details – all harvested by Google and Google grabs secrets of private lives – and one in the Telegraph next day by Philip Johnston – That car in your street was a Google Street View search engine.

While Google was filming our streets it was also collecting information about our WiFi networks. Without permission and without telling anyone. That was a mistake, said Google when they were found out, which is an odd thing for Google to say. The whole point about Google is that they don't make mistakes.

The US Federal Communications Commission are fining Google $25,000 for impeding their investigation of the matter. Google had revenues in 2011 of $37.905 billion on which it made profits of $9.737 billion. The fine amounts to 81 seconds of profits and is thought not to have dealt a mortal blow to the company's share price.

Sunday, 22 April 2012

Amazon, Google, Facebook et al – the latter-day pied pipers of Hamelin

The earliest mention of the story seems to have been on a stained glass window placed in the Church of Hamelin c. 1300. The window was described in several accounts between the 14th century and the 17th century ... This window is generally considered to have been created in memory of a tragic historical event for the town. Also, Hamelin town records start with this event. The earliest written record is from the town chronicles in an entry from 1384 which states: "It is 100 years since our children left". (Wikipedia)

---------- o O o ----------
The children
In December 2011, Facebook had 845 million monthly active users, of which 483 million were daily active users. That's a lot of children.

While children follow the music, grown-ups follow the money.

As Martin Sorrell says, influencing social networks is an extremely powerful way of building brands and trust in brands. That's why the hidden persuaders pay for Facebook, Google and other platforms. That's why the people who think they are the users don't pay. We're not the users, we people who do scores of Google searches every day and who meticulously update our Facebook pages and who tweet our every passing thought. Users pay. We're the product.

Mr Zuckerberg doesn't work hard every day developing Facebook because he loves organising parties. And Mr Schmidt doesn't spend a fortune every day improving search algorithms, giving away Google AdWords coupons and suggesting the optimal route between A and B on Google Maps because he hates people to get lost. Only a child would believe that.

Mr Sorrell (WPP) gives money to Messrs Zuckerberg (Facebook) and Schmidt (Google). And Messrs Zuckerberg and Schmidt give us to Mr Sorrell. Willing buyer, willing seller, we're neither – in this exchange we're the product.

The burgomasters
Meanwhile in the Whitehall district of Hamelin, a confused burgomaster is trying to think how to kickstart the economy. If only my townspeople would maintain a personal data store ... I could launch a midata initiative ... hey wait a minute, 30 million of them already have Facebook pages and a growing number have Google+ accounts ... maiden's prayer ... answer ...

Meanwhile in the Whitehall district of Hamelin, another confused burgomaster is trying to think how to modernise public administration. If only my townspeople had electronic identities ... I could launch an Identity Assurance service (IdA) ... public services could become digital by default ... the Government Digital Service (GDS) ... hey wait a minute ...

Meanwhile in the Whitehall district of Hamelin, all the confused burgomasters are justifiably sorry for themselvesAs if we haven't got enough problems ... kickstarting the economy ... communicating with the townspeople ... the bloody townspeople – excuse my French – and their damned residents' associations ... always moaning ... the Public Administration Select Committee ... the Public Accounts Committee ... the Home Affairs Committee ... it's never-ending ... and the wretched impertinent National Audit Office ... ILA ... CSA ... Tax credits ... NPfIT ... FiReControl ... ID cards ... Libra ... NOMS ... Aspire ... IABS ... UC ... RTI ...

... which brings us to ...

The rats
Infested with management consultants with scaly tails and bloated bewhiskered contractors, the Hamelin government IT systems are "unacceptable", says the Schweinhund Chris Chant – pardon my Switzerdeutsch – and it's about time the burgomasters who aren't up to the job got out.

So who will rid us of the rats?

The piper(s)
Tim Berners-Lee?
... individual users were not yet being allowed to exploit all the information relating to them to make their lives easier. Armed with the information that social networks and other web giants hold about us, he said, computers will be able to "help me run my life, to guess what I need next, to guess what I should read in the morning, because it will know not only what's happening out there but also what I've read already, and also what my mood is, and who I'm meeting later on".
Maybe not.

Martha Lane Fox?
Asked by a local authority official whether older channels needed to be "shut off" for savings to be realised, she replied: "Yes, absolutely. That's fundamental to digital by default.

"It's not an option to keep sending people paper when they are perfectly able to use a digital service. It's not an option to keep a call centre going when you see volume go dramatically down. So of course, you have to turn channels off."
Maybe not.

Werner Vogels? (Who? You know. Werner. Werner Vogels. The Chief Technology Officer of Amazon Web Services, AWS. That's who.)
"We are trying to break through the traditional model of enterprise software development," Vogels said, reiterating the AWS mantra for those who have not heard it before. "Core to the old style of doing business was that enterprises were being held hostage with very long-term contracts because that was the only way that you were able to drive your costs down. What is important is that you should keep your providers on their toes every day.

"If we are not delivering the right quality of services, you should be able to walk away. You, the consumer of these services, should be in full control. That is core to our philosophy. And with that also comes the belief that if you help us gain economies of scale, and if we together operate to get increased efficiencies out of our platform, you should benefit from that."

This is why, Vogels said, AWS has cut its prices 19 times on various services – it now offers more than 30 services, ranging from compute and storage clouds to various database, load balancing, and application frame work services. The most recent price cuts, announced in early March, have resulted in some S3 customers seeing their bills drop by 40 per cent and some EC2 users seeing a 32 per cent drop.

"Why would we do this?" asked Vogels rhetorically. "Because we believe that we should help you be more successful. If you are more successful, in the long run, we will have benefit from that as well. This is a pure win-win situation for all of us."
Now you're talking my language, said each burgomaster, assuming that the other burgomasters knew what the Double Dutch Mr Vogels was talking about. A 32% cut for the EC2s? Sounds good. And the S3s are doing even better, with 40%! Maybe Chris Chant was right. Maybe we should modernise ourselves ... and get rid of those rats once and for all.

And it's not just AWS. There are more pipers where they came from. Google cloud services. Microsoft Windows Azure. IBM SmartCloud. Apple iCloud. To name but a few.

Music to my ears, said each burgomaster, as though they'd never heard of predatory pricing and antitrust, and they all went off for a free lunch.


---------- o O o ----------


In some accounts it is hard to tell the burgomasters from the children. Or the rats from the pipers, come to that. Harder still when you see how many burgomasters were recruited by rats after their early and well-funded retirement, or joined pipers.

The earliest mention of the story seems to have been in a doodle on the home page of Google c. 2028. The doodle was described in several tweets between the 21st century and the 24th century ... This doodle is generally considered to have been created in memory of a tragic historical event for the town when all central and local government records went up in a puff of smoke or, more poetically, a "cloud".

Also, the Whitehall town log now starts with this event. The earliest text record is from the town Facebook page in an entry from 2112 which states simply:


----------

Updated: 3.3.14
NHS England patient data 'uploaded to Google servers', Tory MP says

A prominent Tory MP on the powerful health select committee has questioned how the entire NHS hospital patient database for England was handed over to management consultants who uploaded it to Google servers based outside the UK ...

The patient information had been obtained by PA Consulting, which claimed to have secured the "entire start-to-finish HES dataset across all three areas of collection – inpatient, outpatient and A&E".
Update 2.6.14

A rueful article by Hugh Muir in the Guardian, Internet giants wooed us, but the honeymoon is over, nails the point, "we have been seduced. We have been lured by soft music and friendly adverts into a relationship that is anything but equal, and threatens to turn abusive".

Updated 26.8.14
We wanted the web for free – but the price is deep surveillance
Advertising has become the online business model but by its very nature it involves corporations spying on users to produce more targeted results

Updated 27.8.14
Data guardian Sir Nigel Shadbolt on privacy versus freedom
... today we’re paying more attention to the big corporates and internet giants that sit on huge deposits of our data and stare back at us from the other side of the screen. Google, for example, has become a monopoly more powerful than many states.

Updated 26.4.15
Amazon Web Services is showing traditional IT players how they need to change

Amazon Web Services (AWS) is clearly doing something right. The e-commerce giant has split out AWS revenues for the first time in its latest financial results, revealing a $5bn business growing at nearly 50% year on year.

AWS has shown the big, traditional IT players the way to do public cloud - defining the market for infrastructure (IaaS) and platform as a service (PaaS) along the way, forcing the likes of IBM, HP, Oracle and Microsoft to respond. Amazon is by far and away the dominant public cloud player ...
Always worth reading, that is from Bryan Glick's latest editorial in Computer Weekly magazine. He's right about that. The Pied Piper is surging.

Mr Glick adds:
Amazon has achieved $5bn of cloud revenue at a time when there are still widespread fears about cloud - related particularly to security and data protection - that prevent many large organisations, especially in heavily regulated sectors like financial services, from moving to public cloud. But those fears will be overcome; the sceptics will be convinced; the laggards will be forced to catch up. A tipping point is approaching.
Is that right?

Are the sceptics laggards? Or are they the responsible custodians of our "security and data protection"? Ours and our children's.


Amazon, Google, Facebook et al – the latter-day pied pipers of Hamelin

The earliest mention of the story seems to have been on a stained glass window placed in the Church of Hamelin c. 1300. The window was described in several accounts between the 14th century and the 17th century ... This window is generally considered to have been created in memory of a tragic historical event for the town. Also, Hamelin town records start with this event. The earliest written record is from the town chronicles in an entry from 1384 which states: "It is 100 years since our children left". (Wikipedia)

---------- o O o ----------
The children
In December 2011, Facebook had 845 million monthly active users, of which 483 million were daily active users. That's a lot of children.

Friday, 6 April 2012

What's the matter with our leaders, that they can imagine we welcome mass surveillance? A blogger suggests the answer


To the Cabinet Office, it is quite unremarkable to suggest that we should all apply to private sector companies for an electronic ID so that we can transact with the government, see for example this post by ex-Guardian man Mike Bracken – Establishing trust in digital services. Given that there are 60 million of us here in the UK, those private sector companies would have to be pretty big to manage the volumes. As big as Facebook, for example, who already have 30 million active users in the UK. Or Google, the company that "walked Francis Maude through the identity ecosystem". At least that's what ex-Guardian man Mike Bracken says in Thoughts on my recent trip to the West Coast with Francis Maude, Minister for the Cabinet Office.

To ordinary human beings, the idea is utterly inept.

To the Department of Business, Innovation and Skills, it is quite unremarkable to suggest that we should all collect together our personal data in a file and give it to suppliers so that they know what we want to buy from them, please see for example Ed Davey, problem-solver – midata. Only a mooncalf could possibly agree (The case for midata – the answer is a mooncalf).

To ordinary human beings, the idea is utterly inept.

To the civil service all across Whitehall, it is quite unremarkable to suggest that all the personal data about us held by the government should be stored on computers operated by the likes of Google and Amazon. Whereas the suggestion is of course actually bonkers – Cloud computing is bonkers or, as HMG put it, a "no-brainer".

To ordinary human beings, the idea is utterly inept.

To the Home Office, it is quite unremarkable to suggest that all our phone calls, emails, web browsing etc ... should be monitored by GCHQ.

To ordinary human beings, the idea is utterly inept.

Whitehall and the senior politicians put in to bat for Whitehall clearly have a very odd idea of human nature. It's worth trying to work out what's odd about it. It doesn't help simply to keep saying that it's odd. We need to make a bit of progress. And in that endeavour the blogger Scott Grønmark has taken the first important step.

Mr Grønmark says that in 2005 it occurred to him that the government has many of the symptoms of autism – Talk to the hand! - why all organisations turn autistic – and that he is thinking of writing a book about it. He has returned to the subject about 10 times over the years (according to Google). Let's hope that he does finally write that book.

What's the matter with our leaders, that they can imagine we welcome mass surveillance? A blogger suggests the answer


To the Cabinet Office, it is quite unremarkable to suggest that we should all apply to private sector companies for an electronic ID so that we can transact with the government, see for example this post by ex-Guardian man Mike Bracken – Establishing trust in digital services. Given that there are 60 million of us here in the UK, those private sector companies would have to be pretty big to manage the volumes. As big as Facebook, for example, who already have 30 million active users in the UK. Or Google, the company that "walked Francis Maude through the identity ecosystem". At least that's what ex-Guardian man Mike Bracken says in Thoughts on my recent trip to the West Coast with Francis Maude, Minister for the Cabinet Office.

To ordinary human beings, the idea is utterly inept.

Wednesday, 28 March 2012

Cloud computing is bonkers or, as HMG put it, a "no-brainer"


The failures of government IT projects are well-known and have been for decades, during which the problems have been intractable. Now a solution is being championed by Her Majesty's Government – cloud computing.

What is cloud computing? And is it the answer?

HMG runs a blog called G-Cloud (the government cloud), on which last Friday Adrian Scaife from the Ministry of Justice posted an answer to the first question above, "A No Brainer":
Cloud computing is so easy to understand that even simple folk like me get the idea.
Mr Scaife should know all about the traditional problems of government computing. He works for NOMS, the National Offender Management Service, the travails of which have rarely been out of Private Eye for the past eight years. To pick just one of the hiccoughs suffered, in March 2009 the National Audit Office published a report on the NOMS computer system which includes this:
3.17 At the end of October 2007, £161 million had been spent on the project overall. We have not been able to ascertain precisely what this money was spent on because NOMS did not record expenditure against workstream before July 2007 ...
This patrician insouciance of Whitehall's when it comes to public money is just one of the aggravating features of government IT collected together in a report by the Public Administration Select Committee, Government and IT- "A Recipe For Rip-Offs": Time For A New Approach, a report which with good grace Mr Scaife refers to. It's a long report and readers may care to start with the contribution entitled Whitehall, Red Light District beginning at page Ev w7 to get the flavour of it. Clause 5 deals with cloud computing.

Mr Scaife's post promotes five alleged benefits of cloud computing which he says will help to solve the current problems of government IT:
  • No CapEx – you can stand up services in days, hours or in some cases minutes – try before you buy: spin up an AWS instance, sign up for Google Apps for Business or an Office 365 free trial and touch and feel it for yourself ...
  • Metered Services – you only pay for what you use.  If it doesn’t fit the bill, switch it off.  If it does work you can grow it incrementally ...
  • Scalability, flexibility, elasticity – All baked in.  You want to add a couple of hundred gigs of storage, another 50 or 5000 users, a new tenancy for an application, just switch it on.  And when your business changes and you don’t need it any more – no exit costs, just switch it off ...
  • Cheaper – the economies of scale the global-class cloud providers can realise drive unit costs to a level that can never be achieved through an on-premise approach.  In many cases, cloud services are free at the point of use because of these economies of scale, and because they are typically monetised by advertising – you can normally lose the ads for a paid business version of a cloud service ...
  • Vendor-led Innovation – One of the great things about cloud is that you don’t have to do upgrades, the cloud provider does it.  New features, patches, and upgrades are all part of the package.  Because the global market is a competitive place, as well as getting better, services can get cheaper too: AWS reduced their prices twice in 2011 ...
If there is no CapEx, no capital expenditure, then what Mr Scaife foresees is a new world in which government doesn't buy any expensive computers (any servers) itself. But someone has to buy them. The people buying them are AWS, Amazon Web Services, and other suppliers of cloud computing services. Someone must pay for all the spare capacity which would allow HMG to "scale up" any time it wants to, no delays involved. And someone must keep paying for it when HMG decides at the drop of a hat to "switch off". All that redundancy must be reflected in the costs.

What we're looking at is a return to the 1970s and timesharing. Back then, most companies couldn't afford mainframes or minicomputers and so they rented time on computers provided by the likes of GEISCO – General Electric Information Services Company – and Comshare and other smaller bureau operators. Timesharing costs went through the roof and the whole business was gratefully abandoned when PCs arrived in the 1980s.

HMG is welcoming the timesharing zombie back into Whitehall. And Mr Scaife, at least, offers no reason to believe that costs won't go through the roof again just like the last time.

Mr Scaife's post barely considers the potential disadvantages of cloud computing. The document is more like a piece of sales literature than a balanced assessment.

There are other opinions of the new world being sold to us here:
  • The OECD, for example, recommend that "cloud computing creates security problems in the form of loss of confidentiality if authentication is not robust and loss of service if internet connectivity is unavailable or the supplier is in financial difficulties".
  • ENISA, the EU's information security agency, casts more doubt on the advisability of cloud computing, concluding that "its adoption should be limited to non-sensitive or non-critical applications and in the context of a defined strategy for cloud adoption which should include a clear exit strategy".
  • Larry Ellison, the founder of Oracle, says frankly: "The interesting thing about cloud computing is that we've redefined cloud computing to include everything that we already do. The computer industry is the only industry that is more fashion-driven than women's fashion. Maybe I'm an idiot, but I have no idea what anyone is talking about. What is it? It's complete gibberish. It's insane. When is this idiocy going to stop?"
  • And as for Richard Stallman, he says that cloud computing is a "trap":
... Richard Stallman, founder of the Free Software Foundation and creator of the computer operating system GNU, said that cloud computing was simply a trap aimed at forcing more people to buy into locked, proprietary systems that would cost them more and more over time.

"It's stupidity. It's worse than stupidity: it's a marketing hype campaign," he told The Guardian.

"Somebody is saying this is inevitable – and whenever you hear somebody saying that, it's very likely to be a set of businesses campaigning to make it true."
The Guardian quote one actual user of real live cloud computing services as follows:
We went ahead and moved our business to public cloud computing about 18 months ago. It has been a nightmare, there have been times when the company is down because our collaboration software, Basecamp, is unreachable. We also have an Amazon cloud solution. How secure is this, what if there is a breach? How do you even call Amazon, they don't even have a phone number for us? The level of transparency is not there.
Mr Scaife's assumption is that cloud computing offers greater security than can be achieved in-house. But how do you know? According to the Guardian again:
Despite these efforts, tough issues remain. One is that organisations often cannot perform audits to verify the vendor's claims. Google, for example, does not allow it. "It does more to impede the security, letting everybody in to take a look at everything," Feigenbaum says.
Google is another supplier of cloud computing and Eran Feigenbaum is their director of security for Google Apps. Are we really to believe that Google can provide higher security than HMG?

Maybe. We are used to finding fault with HMG. That doesn't mean that Google are faultless.

Let's be clear what Mr Scaife is talking about here. All our tax records, all our state education records, all our state healthcare records and state housing records, all our National Insurance and state pension records, all our criminal records, ... could be stored on Amazon web servers or Google web servers or anyone else's web servers.

Where would those servers be? Where would our data be? They could be anywhere. Anywhere where Amazon/Google can provide their allegedly scalable and flexible services most cheaply. Who has jurisdiction over the data if it's in Vanuatu (formerly the New Hebrides but now the Ripablik blong Vanuatu)? How do you enforce any British law there?

HMG might or might not be able to keep control. The US have taken steps to do so already, and not just to control their own data:
There is also concern about the US anti- terrorism legislation called the Patriot Act, which gives the US government a right of access to any data stored on US soil, and possibly any data on servers belonging to a US company, if it is deemed necessary for security investigations. In some cases, that is not an acceptable risk.
Mr Scaife acknowledges this problem:
Special needs
The operation of separate and parallel ICT systems for government departments is analogous to operating separate water or electricity supplies for government departments.  It is expensive, often unnecessary, and the benefits are dubious.  At the same time, government is in a unique position in that it must both protect assets of national security, and that it must provide adequate protection of the personal data entrusted to it.
If government is going to protect national security and the confidentiality of personal data, then that surely points firmly against cloud computing and Mr Scaife's putative cost savings won't be available after all. Alternatively, if HMG is determined to try to achieve those putative savings, will the population no longer be relying on HMG? Will we be relying instead on the good will of Amazon and Google? Is the job too difficult, and HMG is giving up on the business of government?

Having asserted that government's responsibilities are unique, three paragraphs later Mr Scaife says:
Government is now beginning to recognising the potential cloud has to help us deliver ‘better for less’, to drive down costs and to improve services.  Our job now is to seize the opportunity to capitalise on that.  Cloud is a ‘no-brainer’, but we need to avoid getting into a tiz about how scary it sounds to us and how ‘special’ we think we are.
Clearly, his point is that government computing requirements are not unique after all – "we need to avoid getting into a tiz about how ... ‘special’ we think we are". He thinks that's an argument for adopting cloud computing. It isn't. It's the reverse.

Anyone using the cloud has lost control of their data and of their costs. Do lawyers store your confidential data in the cloud? Let's hope not. They shouldn't. There's nothing special about government in this respect. HMG shouldn't adopt cloud computing either, any more than lawyers. Not if they're going to maintain national security. Not if they're going to take the confidentiality of personal data seriously. And not if they have a brain.

Public administration in the UK is in a parlous state. No-one doubts that there are real problems. Cloud computing is not the answer.

----------

PS For what it's worth, DMossEsq posted a comment on the G-Cloud blog raising some of the questions above. The comment has been published but the last sentence, including a link to this article, has been removed. It's a small thing but was the comment edited in the UK? Or Vanuatu? How will you defend your position if your tax records are edited? And what if they're copied by Google, at the request of the US government? While framing your answers, please follow Mr Scaife's advice and try to "avoid getting into a tiz about how scary it sounds to [you] and how ‘special’ [you] think [you] are".

Cloud computing is bonkers or, as HMG put it, a "no-brainer"


The failures of government IT projects are well-known and have been for decades, during which the problems have been intractable. Now a solution is being championed by Her Majesty's Government – cloud computing.

What is cloud computing? And is it the answer?

Friday, 9 March 2012

You know you've arrived when ...

Towards the end of a long and illustrious career, already garlanded in the seats of power the world over, what bauble could possibly further crown his achievement? This was the conundrum perplexing DMossEsq.

The Governership of Hong Kong? Too late.

The Order of the Garter? All things considered, no.

Could he be the next Pope? His lips are sealed.

The answer recently came to him. At last. As so often in today's global world, it was thanks to Google.

Enter "david moss" "cabinet office" into Google, go down to the bottom of the page, click on 3 or above and, when the page has refreshed, towards the bottom of the page you will see:
In response to a legal request submitted to Google, we have removed 1 result(s) from this page. If you wish, you may read more about the request at ChillingEffects.org.
One hit has been removed from Google's list. Which one? You want to know. You click on the read-all-about-it link and you get:
Notice Unavailable

Defamation Complaint to Google
Sent by: [individual]
To: Google

The cease-and-desist or legal threat you requested is not yet available.

Chilling Effects will post the notice after we process it.
Defamation? What defamation? This could be fruity. Who is the individual who complained? There is a certain dignity in these matters. Pray God it's not someone dull.

ChillingEffects.org? No, me neither.

Some sort of a kangaroo court? No. According to their website, Chilling Effects is:
A joint project of the Electronic Frontier Foundation and Harvard, Stanford, Berkeley, University of San Francisco, University of Maine, George Washington School of Law, and Santa Clara University School of Law clinics ...

Chilling Effects aims to help you understand the protections that the First Amendment and intellectual property laws give to your online activities. We are excited about the new opportunities the Internet offers individuals to express their views, parody politicians, celebrate their favorite movie stars, or criticize businesses. But we've noticed that not everyone feels the same way. Anecdotal evidence suggests that some individuals and corporations are using intellectual property and other laws to silence other online users. Chilling Effects encourages respect for intellectual property law, while frowning on its misuse to "chill" legitimate activity.
Mystifying. Has DMossEsq defamed someone? Allegedly. Has someone allegedly defamed DMossEsq? Who knows? It's not clear. Let's hope that Chilling Effects hurry up and process the "cease-and-desist or legal threat" submission. The suspense waiting for them to post their notice will be hard to bear. Is DMossEsq at last the subject, or even the object, of that must-have for a career to be complete, a superinjunction?

You know you've arrived when ...

Towards the end of a long and illustrious career, already garlanded in the seats of power the world over, what bauble could possibly further crown his achievement? This was the conundrum perplexing DMossEsq.

The Governership of Hong Kong? Too late.

The Order of the Garter? All things considered, no.

Could he be the next Pope? His lips are sealed.

The answer recently came to him. At last. As so often in today's global world, it was thanks to Google.