Thursday 1 November 2012

G-Cloud team soon to be Eleanor Stewartless

G-Cloud ii has been released. There are now over 3,000 conveniently automated ways for central and local government departments to lose control of their IT through CloudStore.

Eleanor has been closely involved in the project and, as a trained archaeologist, she will be particularly well-placed to go through the remains after it all comes tumbling down, identifying the signs of a once-thriving civilisation. "I look forward to watching it happen from my new role in the FCO", she says – G-Cloud's loss is the Foreign Office's gain.

She will be missed. She said G-Cloud ii would be released on 26 October 2012 and it was. She provided a forum for debate and she confronted criticism openly, e.g. "What the heck can we do to resolve some of the scary and largely unknown legal and policy issues that people are nervous about in a globalised world?". Good question. No answer. But at least she asked. The Foreign Office are lucky.

It's not unknown for Whitehall to be open about criticism. Lin Homer at HMRC is pretty good at it and has been for years. We may yet discover from her, HMRC's side of the story about losing control of all our tax records in the cloud with Skyscape, the one-man company with no track record.

Compare that with the Government Digital Service (GDS).

They said they would announce the names of the UK's so-called "identity providers" by 30 September 2012 and they didn't. Then they said the announcement would be made on 22 October 2012 and it wasn't.

Ask them why they've decided to host GOV.UK on Skyscape and they can't answer.

Post a critical comment* on their blog, and they delete it.

Send them an open letter, and there's no response.

Issue a press release with 17 questions, and you get 0 answers.

Security experts at a Whitehall conference pour scorn on GDS's idea of relying on the social networks for identity assurance and ... silence.

GDS claim to want "participation" as they build the new city on a hill with their (tax) dodgy friends. They don't understand the word. Not the way Eleanor Stewart does.

PS At 10:24 a.m. yesterday a notification was emailed to everyone announcing a new post by Mike Beaven on the GDS blog, Refining transactions with help from the Minister. Click on the link and you get "404: Page Not Found". A Twitter enquiry from Kris Coverdale was met with "we just needed to correct something. We'll be putting it back up again later". That was yesterday. 15 minutes ago, via Tim Lloyd, we have "It wasn't displaying correctly. Trying to resolve now". Just how hard is it to participate?

----------

* A lost fragment from GDS's Less About Identity, More About Trust thread recently discovered by archaeologists. What do GDS know about identity? Or trust? And how many other fragments are missing?
Dear Ms Kidney

Thank you for your 12 October 2012 reply.

As you will see on the G-Cloud blog, I have read and responded to Eleanor’s reply, pointing out that it’s not the OJEU rules I’m interested in but the rules of common sense.

It’s not more information about Skyscape that I’m after but an answer to the question how on earth did GDS go through all the hard work of developing GOV.UK and then host it at a one-man £1,000 company?

GOV.UK is meant to be a major national asset and GDS’s decision to host it on Skyscape looks “dangerous, imprudent, ill-advised, unprofessional, wrong-headed, unbusinesslike, undignified and irresponsible” as I say in my open letter to ex-Guardian man Mike Bracken.

And what similarly awful decisions do we have to look forward to discovering on 22 October 2012? IdA Day?

G-Cloud team soon to be Eleanor Stewartless

G-Cloud ii has been released. There are now over 3,000 conveniently automated ways for central and local government departments to lose control of their IT through CloudStore.

Eleanor has been closely involved in the project and, as a trained archaeologist, she will be particularly well-placed to go through the remains after it all comes tumbling down, identifying the signs of a once-thriving civilisation. "I look forward to watching it happen from my new role in the FCO", she says – G-Cloud's loss is the Foreign Office's gain.

She will be missed. She said G-Cloud ii would be released on 26 October 2012 and it was. She provided a forum for debate and she confronted criticism openly, e.g. "What the heck can we do to resolve some of the scary and largely unknown legal and policy issues that people are nervous about in a globalised world?". Good question. No answer. But at least she asked. The Foreign Office are lucky.

It's not unknown for Whitehall to be open about criticism. Lin Homer at HMRC is pretty good at it and has been for years. We may yet discover from her, HMRC's side of the story about losing control of all our tax records in the cloud with Skyscape, the one-man company with no track record.

Compare that with the Government Digital Service (GDS).

Sunday 28 October 2012

Alarm – adult human being found still working at the Cabinet Office

Thank goodness for Andy Smith. Whoever he is. And even if he isn't.
audio
video (slide to 1:31:30)

Hat tip: Philip Virgo

25 October 2012, and Whitehall held one of its endless conferences/talking shops where people who work for acronyms get together and speak in acronyms. The 9:20 welcome and introduction, for example, were given by John Robertson MP, Chair, apComms and Chi Onwurah MP and Stephen Mosley MP, Co-Chairs, PICTFOR.

All was set fair for a normal day of incomprehensible talk to be minuted and then forgotten when, according to the BBC, Andy Smith, PSTSA Security Manager, Cabinet Office, was asked a question about using social networks:
A senior government official has sparked anger by advising internet users to give fake details to websites to protect their security.

Andy Smith, an internet security chief at the Cabinet Office, said people should only give accurate details to trusted sites such as government ones.

He said names and addresses posted on social networking sites "can be used against you" by criminals.
Andy Smith is quite properly very hard to track down. He's got something to do with security at the PSTSA. The PSTSA has got something to do with the Public Services Network. The security of the PSN is assured in part by the use of PKI, the public key infrastructure, and that, in turn, depends on digital certificates.

In their chart-topping release of 31 July 2012, PSN Certificate Policy IPsec IL3, PSN say:
5.4.8.2 Each CA and RA must ensure that its PKI services are accredited by the PSTSA Accreditation Board (PSAB) to impact levels 4-4-4 and included within an RMADS prior to live operation.
DMossEsq can help a bit here. A CA is a certification authority and an RA is a registration authority but, after that, you're on your own. You could try the glossary at the back of the report where you'll find that RMADS is the Risk Management and Accreditation Document Set but, rather charmingly, under PSTSA it just says "Public Services ???".

So there's Andy Smith, a man who speaks fluent acronym, who works for an acronym so secret that even PSN don't know what it stands for (DKWISF), a man who has something to do with the deepest levels of the security of PSN and when he's asked about social networks, his informed security advice is don't tell them any more of the truth than you have to for your purposes.

Meanwhile, back at the robot Government Digital Service (GDS), the senior boys in charge were getting ready on Monday 22 October 2012 to announce that we should all communicate with the government using our trusty Facebook and Google+ user IDs. But they bottled out of it. It's too ridiculous. Even a child couldn't take the suggestion seriously.

Thank goodness for Andy Smith. Whoever he is. And even if he isn't.

----------

Cribsheet
4 October 2012, IndependentNational 'virtual ID card' scheme set for launch (Is there anything that could possibly go wrong?): "The Government will announce details this month of a controversial national identity scheme which will allow people to use their mobile phones and social media profiles as official identification documents for accessing public services ... The public will be able to use their log-ins from a set list of “trusted” private organisations to access Government services, which are being grouped together on a single website called Gov.uk ... The system will be trialled when the Department of Work & Pensions starts the early roll out of the Universal Credit scheme, a radical overhaul of the benefits system, in April ... Details of the 'identity assurance' scheme are being finalised amid growing concerns over identity theft and other forms of cybercrime ... Members of the Cabinet Office team travelled to the White House in May to exchange ideas with American counterparts working on the National Strategy for Trusted Identities in Cyberspace (NSTIC) ...".

4 October 2012, Government Digital Service, Less About Identity, More About Trust: "If you’d like to know more the Q&A in The Independent gives a pretty good overview (the only thing we’d really quibble with is the headline)".

25 October 2012, Philip Virgo, Government official gives practical security advice - shock horror: "This morning I ... received yet another e-mail covering the latest nonsenses in the ongoing saga of expensive displacement activity that passes for Government (US, EU, HMG etc.) electronic ID policy ...".

25 October 2012, BBC, Give social networks fake details, advises Whitehall web security official: "Mr Smith, who is in charge of security for what he described as the 'largest public services network in Europe', which will eventually be accessed by millions of people in the UK, said giving fake details to social networking sites was 'a very sensible thing to do ... Don't put all your information on websites you don't trust ... When you put information on the internet do not use your real name, your real date of birth', he told a Parliament and the Internet Conference in Portcullis House, Westminster ... 'When you are putting information on social networking sites don't put real combinations of information, because it can be used against you' ...".

26 October 2012, Wendy Goodman, I thought her head was going to explode: "For the record, I think it's clear that Smith gave good security advice ...".

26 October 2012, dropsafe, Andy Smith of the #CabinetOffice is a Epic Fucking #Security Hero: "I have said much the same – worse/moreso, even, by suggesting that folk randomise their personal information so that your mother’s maiden name was F3JlfIrOH8 and your favourite colour is uAfhaR." – kindly includes the links to audio and video of the conference above.

26 October 2012, Daily MailUse fake names on Facebook and Twitter, says the head of government internet security: "... It comes at a time when the government is considering allowing people to use their existing log-ins for social networking sites to access a new government website to apply for benefits, passports and driving licences ...".

26 October 2012, GuardianBeing wary of handing over personal details to websites isn't 'outrageous': "I'm not sure making up data is necessarily the best advice Smith could have given, but you can see where he was coming from: if you are suspicious about why a site is asking for your details, don't give them ... you should be a bit discerning about who you share your details with and how much you give out ... Earlier this year, a report into US identity fraud found it was on the rise, in part because of the incredible amount of personal information being shared on public social media profiles ...".

26 October 2012, Dave Birch, The battle of the internet security experts: "Andy is spot on ...".

From the archives
30 October 2008, Daily Mail, Brown's ID card claims 'absolute bunkum' says Government electronic security expert from GCHQ: "Gordon Brown's claims for the £4.5billion ID cards project have been disputed by one of the Government's own electronic security experts ... The Prime Minister and Home Secretary Jacqui Smith have repeatedly said that ID cards will help thwart terror attacks ... Mr Brown said a national ID card scheme could 'disrupt terrorists' while Miss Smith has claimed ID cards will be a 'robust defence' against terrorists using false identities ... But Harvey Mattinson, a senior consultant at the IT security arm of GCHQ, the Government's listening station, said the claims were 'absolute bunkum' ...".

Harvey Mattinson then. Andy Smith now. Should they decide to accept it, there is another mission for the security services, to save us from GDS and their friends by unwinding the contracts HMRC and GDS have signed with Skyscape Cloud Services Ltd:
CESG have rescued the nation before from other-worldly decisions taken by Whitehall. The Home Office wanted to use DWP’s National Insurance number database as the National Identity Register for the ID cards scheme. CESG pointed out that it was inappropriate and that was the end of that.

Let’s hope that they repeat the trick in their review of Skyscape. I look forward to a small piece appearing in the technical press somewhere out of the way regretting that for security reasons which cannot be given the HMRC [and GDS] contract[s] with Skyscape [have] had to be revoked.

Alarm – adult human being found still working at the Cabinet Office

Thank goodness for Andy Smith. Whoever he is. And even if he isn't.
audio
video (slide to 1:31:30)

Hat tip: Philip Virgo

25 October 2012, and Whitehall held one of its endless conferences/talking shops where people who work for acronyms get together and speak in acronyms. The 9:20 welcome and introduction, for example, were given by John Robertson MP, Chair, apComms and Chi Onwurah MP and Stephen Mosley MP, Co-Chairs, PICTFOR.

Saturday 27 October 2012

Identity assurance. Only the future is certain – doom 3

It's Monday 31 October 2011, and six months after his previous identity assurance meeting DMossEsq finds himself at another one. That's the meeting where ex-Guardian man Mike Bracken spoke and which he wrote up on the Government Digital Service (GDS) blog, Establishing trust in digital services.

Three points.

The event was called Ensuring Trusted Services with the new Identity Assurance Programme and there's a natural tendency to think of it as a Cabinet Office event or more specifically a Government Digital Service (GDS) event. It wasn't.

The event was held under the auspices of the Technology Strategy Board (TSB), which is "sponsored" by the Department for Business Innovation and Skills (BIS). There were eight speakers, of whom two were from the TSB and one was from the Skills Funding Agency, which is a "partner organisation" of BIS. That's three out of eight.

Francis Maude, Cabinet Office Minister, announced a £10 million investment by the Cabinet Office in the identity assurance industry and Iain Gray, chief executive of the TSB, announced a £14 million investment and the winners of that funding were exhibiting at the event.

When you consider identity assurance (IdA) you must consider both GDS and BIS as the sponsors/promoters/investors. That's point 1.

Point 2, there is a natural tendency to associate IdA with the administration of benefits. DWP have been chosen to pioneer IdA on UC, the Universal Credit initiative. But that's just the start. It's meant to go viral and crop up everywhere.

The government's White Paper on Individual Electoral Registration relies on IdA (see for example para.52, p.18):
The draft legislation will allow digital identity assurance to be used in future to verify an application to be added to the electoral register.
The BIS paper on A midata future: 10 ways it could shape your choices adds 10 further applications of IdA to the list being contemplated, including applying for a job, managing your budget, looking after your health and choosing a film to watch. BIS say, for example:
midata' could allow individuals to have access to information held about them by various organisations. When getting a new job, an individual could use verification programmes to send necessary proofs to a new employer. For example, instead of making copies and going to the post office, a new employee could get their driving licence, educational qualifications, CRB check and personal identity [emphasis added] all by ticking a set of boxes and clicking 'send'.
IdA is not just about UC. Its tentacles could reach into every aspect of your life.

And point 3?

After Mr Maude had spoken and debate was thrown open to the audience, Neil Fisher of Unisys said, what is true:
Any project with "identity" in the name is doomed to failure.
Thus the name of this little series of posts. Only one more to go.

----------

Updated three years later, 31 October 2014

That meeting in 2011 was energetic and cheerful and noisy.

What a contrast to yesterday's re-run, no Francis Maude this time and no Mike Bracken, please see Kable/Government Computing's Cabinet Office sets out identity assurance expansion aims.

The failure of IDA, the identity assurance scheme, to expand – or rather, its failure to start – is the fault of DWP's December 2011 framework agreement. It remains their fault to this today despite the fact that GDS took it over in March 2012.

Eight so-called "identity providers" had signed up to IDA by January 2013:
  • Three have already pulled out – Cassidian, Ingeus and PayPal.
  • Four of them have yet to be certified trustworthy and haven't signed up a single user – Digidentity, Mydex, the Post Office and Verizon.
  • Since they only get paid for signing people up, the return on their investment in IDA is nil.
  • Only one "identity provider" is left standing – Experian. They have signed up just under 800 people.
  • Since they get paid just pence per registration, they have something of the order of £8 to show for two years work.
And now GDS are planning a second framework agreement.

They've changed the name from "IDA" to "GOV.UK Verify". Otherwise it's business as usual:
  • Suppose they get five "identity providers" on board and suppose that 45 million Brits register with all five of them.
  • That's 225 million registrations for an estimated £105 million to be offered by the new framework agreement.
  • For approximately 47 pence each, the "identity providers" have to register you in the first place, check your registration once a year and assure an unknown number of relying parties an unknown number of times that you are you.
  • The liabilities are onerous. Nothing is ever GDS's fault. And all for 47p.
Who's going to jump at that opportunity?

No-one.

No-one who values their company, their career and their reputation.

Sauve qui peut.

RIP IDA.

Identity assurance. Only the future is certain – doom 3

It's Monday 31 October 2011, and six months after his previous identity assurance meeting DMossEsq finds himself at another one. That's the meeting where ex-Guardian man Mike Bracken spoke and which he wrote up on the Government Digital Service (GDS) blog, Establishing trust in digital services.

Three points.

The event was called Ensuring Trusted Services with the new Identity Assurance Programme and there's a natural tendency to think of it as a Cabinet Office event or more specifically a Government Digital Service (GDS) event. It wasn't.

Friday 26 October 2012

Identity assurance. Only the future is certain – doom 2 (corrected)

Why didn't the Government Digital Service
make its planned 22 October 2012 announcement about IdA?
Are the "identity providers", sensibly, having second thoughts?

Wednesday 20 April 2011, seven months after his previous meeting, and DMossEsq finds himself at another one to discuss identity assurance (IdA or IDA).

In between whiles, Martha Lane Fox has sent her famous letter to Francis Maude advocating the MLF Prerogative, an amendment to the British Constitution whereby whoever is in charge of GOV.UK will have the power of veto over government policy and will be able to enforce that power using SWAT teams with sharp teeth.

Something of that same aggression has transmitted itself to the Treasury room in which we meet. The testosterone level is oppressive. A roomful of salesmen who were promised no money last September. And yet here they are again. Wolves, howling, scenting money, leaking from a wounded government.

And here, again, the Identity & Passport Service aren't. According to DMossesq's contemporaneous notes:
To someone's dyspeptic eye, IDA looks like a non-starter, another elaborate and expensive plan which turns out to be fantasy, doomed to failure when it confronts reality. The timetable for IDA was presented and described as not over-ambitious. That is perfectly accurate. The timetable is not over-ambitious. It looks more like the psychedelic product of a prolonged session on hallucinogenic drugs. Far from being merely over-ambitious, it is quite simply impossible.

Take for example the claim that by 2014 IDA will be able to support a central N electoral registration application ... Someone asked about that and was told that protocol dictates that, in the run-up to imminent local elections, that matter can't be commented on by the civil service.

Someone not me asked if the Identity & Passport Service are involved in IDA. No, came the reply, IPS are still "reeling" ... That someone may, like me, have thought hmmm, if there's going to be a central N electoral register, that sounds like a job for IPS's GRO (the General Register Office). If the Cabinet Office have their heart set on a central N electoral register, then they must prepare themselves to reel just as much as IPS, because it won't happen, not through IDA at least ...
And:
The Cabinet Office have apparently talked Francis Maude into accepting IDA and G-Digital [digital by default] and G-Cloud. Billions of pounds will be spent. And wasted. Why? To what end? To allow people to communicate with the government digitally. Someone put his hand up and pointed out that we can already do that, through the Government Gateway.

Someone got the distinct impression that certain people wished that hadn't been mentioned ... The GG is old and uses proprietary components and it records too much personal data, we were told. Hmmm, those are insuperable problems. But only if you first decide that they are insuperable. The Cabinet Office and DWP want to kill off the GG, says a dyspeptic of someone's acquaintance, only because otherwise they don't get to play with cloud computing and a lot of shiny new Christmas present data centres.

Most public services are delivered by local authorities. Have they been involved in the design of IDA? No, there are too many of them, we were told. And anyway, they're autonomous, it was said. Like the devolved authorities. Is that a dutiful recognition of the reality of localism? Or maybe a supercilious assumption that the local and devolved authorities will do what they're jolly well told – it's hard to tell the difference. Someone's suspicion is that the move to IDA, G-Digital and G-Cloud is one great big strategy to ensure that Whitehall stays in control, it holds the reins in the centre, it ensures that localisation never happens. If the GG has to be sacrificed along the way, so be it. And if the taxpayer has to spend billions on new data centres, ditto.
It's no fun reeling. Five directors were kicked off the Board of IPS when they finally admitted the ID cards game was up. Sarah Rapson became Chief Executive and Registrar General for England and Wales:
  • Despite being Chief Executive of the Identity & Passport Service she is not invited to help with identity assurance.
  • Despite being the Registrar General, the proposed central N electoral registration will be nothing to do with her.
Obviously the best people leave. Quickly. But then who's left?

Left with "IPS" or "GDS" on their CV. Or an unexplained gap.

It's no fun for the suppliers either.

The biometrics suppliers, for example. They were going to make ID cards foolproof. They haven't been invited back for the identity assurance party. Just because their products don't work. It hardly seems fair.

"1677" it says over the door of each branch of Lloyds Bank. 335 years it's taken to build the brand and it would all go up in smoke overnight if the bank associates itself with IdA. RBS, the Royal Bank of Scotland, similarly. The association would be all downside for Vodafone as well. And any other bank. And any other telco. Or retailer. What would Tesco have to gain? Nothing. They could only lose. Ditto Sainsbury's and the others.

Remember what happened to IPS. And to the biometrics suppliers. And to PA Consulting – banned from government work along with other consultants by Francis Maude despite all PA's hard work helping Whitehall to waste hundreds of millions on ID cards and other projects.

If you're the Chairman or Chief Executive of Boots the chemists, say, and you sign up with GDS to become an "identity provider" – the name really ought to ring alarm bells – the equity analysts will take you apart, your shareholders will rebel and you'll never get another non-executive directorship. You'll be the man or woman who destroyed the Boots brand. Because if my Boots the chemists-issued electronic ID causes me to be defrauded, even if that's the result of Whitehall incompetence, I'm not just going to blame Whitehall, I'm going to blame Boots, too.

It's all risks for Boots and Tesco and Vodafone and Lloyds and no reward. An irrational bet. A reverse arbitrage. A guaranteed loss.

Why didn't the Government Digital Service make its planned 22 October 2012 announcement about IdA? Are the "identity providers", sensibly, having second thoughts?

----------

N It transpires that there is no proposal to create a single, central electoral register and DMossEsq apologies for introducing this error. The government White Paper on Individual Electoral Registration explicitly states in the Foreword that:
No additional information will be placed in the electoral register and the register will continue to be created and held locally – there will be no new national dataase.

Identity assurance. Only the future is certain – doom 2 (corrected)

Why didn't the Government Digital Service
make its planned 22 October 2012 announcement about IdA?
Are the "identity providers", sensibly, having second thoughts?

Wednesday 20 April 2011, seven months after his previous meeting, and DMossEsq finds himself at another one to discuss identity assurance (IdA or IDA).

In between whiles, Martha Lane Fox has sent her famous letter to Francis Maude advocating the MLF Prerogative, an amendment to the British Constitution whereby whoever is in charge of GOV.UK will have the power of veto over government policy and will be able to enforce that power using SWAT teams with sharp teeth.

Something of that same aggression has transmitted itself to the Treasury room in which we meet. The testosterone level is oppressive. A roomful of salesmen who were promised no money last September. And yet here they are again. Wolves, howling, scenting money, leaking from a wounded government.

Identity assurance. Only the future is certain – doom 1

The ID cards scheme made IPS into pariahs in Whitehall.
The same fate awaits GDS.

Monday 20 September 2010, the aftermath of the comprehensive failure of Whitehall's plans to introduce government ID cards to the UK, and DMossEsq finds himself at a meeting to discuss identity assurance:
Attendees included suppliers -- consultants, PKI people, lawyers, telecommunications people, credit rating agencies, defence contractors and retailers -- and civil servants from the Cabinet Office, obviously, and DWP. No-one from the Home Office, HMRC, the Department of Health, the Department for Education ...
According to his contemporaneous notes:
No coherent case could be made for the NIAS [= National Identity Assurance Service, precursor to IdA, now IDAP, the Identity Assurance Programme]. No-one could see what the benefit would be to anyone, whether the assembled suppliers, the citizen consumers or even the government departments. There is no money on the table. The team in charge at the Cabinet Office comprises exactly two people and the Secretary of State, Francis Maude, needs to see private sector interest before there is any question of money being made available.
And:
Further, and quite unexpected, the astonishing degree of No2ID's success, or of the Home Office's failure, depending on how you look at it, became painfully, embarrassingly and almost sadly evident as one supplier after another said that if there was the slightest hint in public that this (non-)project had anything to do with the National Identity Service and the Home Office, then they couldn't possibly be seen to be involved, and as if that wasn't enough, the person from DWP said the same. Any connection would be seen as diseased. A contagion. The Home Office and the Identity & Passport Service have become unmentionable.
The putative suppliers to the Government Digital Service's identity assurance programme may care to remind themselves of the reputational damage they face if they allow themselves to be linked with IDAP. Two years ago, with the example of the pariah IPS [the Identity & Passport Service] in front of them, the banks and the mobile phone companies and the credit referencing agencies understood the risks – all 32 of them. The risks haven't changed.

And GDS may care to take note of IPS's fate. Most of the GDS team imagine that they're working on a noble project to improve the user experience of a public service website. They are. But the other side of that coin, without which the project is pointless, is identity assurance, the same identity assurance sought by IPS.

The same affliction of disease and contagion awaits.

Identity assurance. Only the future is certain – doom 1

The ID cards scheme made IPS into pariahs in Whitehall.
The same fate awaits GDS.

Monday 20 September 2010, the aftermath of the comprehensive failure of Whitehall's plans to introduce government ID cards to the UK, and DMossEsq finds himself at a meeting to discuss identity assurance: