5 ms·
"Eventually, the [Washington] state’s computers started to flag anomalies: out-of-state banks, duplicate email addresses and multiple names using the same bank
by pnw_hazor 6y ago
"Eventually, the [Washington] state’s computers started to flag anomalies: out-of-state banks, duplicate email addresses and multiple names using the same bank accounts. But there and elsewhere, antiquated state computer systems failed to flag foreign IP addresses, repeated computer serial numbers and techniques to mask that number."
The current version of WA employment security dept software was deployed in 2017. It was a boondoggle that cost taxpayers ~$50mm.
edit-to-add-link:
https://www.king5.com/article/news/investigations/years-late-and-millions-over-budget-state-computer-system-called-a-failure/281-346039336 https://www.king5.com/article/news/investigations/years-late...
- lostmsu 6y agoActually, the software cost now is closer to ~$36.05B
- pnw_hazor 6y agoI am talking about the cost of the software for Washington State. Added a link.
- MichaelZuo 6y agoWell it does seem like the true software cost will be at least over $1 billion for Washington state...
- frompdx 6y agoIt was a boondoggle that cost taxpayers ~$50mm. If I recall correctly it is also a third party solution provided by a private company. Oregon plans to adopt the same software after not being able to make payments at all for quite some time due to their own antiquated software [0]. From an article I read at the time: Keiser said Fast Enterprises has since blamed ESD for the lack of fraud protection because the ESD “didn’t purchase additional security” that Fast Enterprises could have offered. [1] Seems unbelievable given the expense. At the time I wrote OPB and said. While I think it is a good thing to choose readymade software rather than developing something new and potentially fail to deliver anything, I feel that Oregon is not paying attention to what is happening on the other side of the Columbia river and is potentially making the same mistakes as Washington. [0] https://www.opb.org/article/2020/09/10/oregon-employment-department-picks-company-to-update-outdated-technology/ https://www.opb.org/article/2020/09/10/oregon-employment-dep... [1] https://www.seattletimes.com/business/technical-error-helped-criminals-in-576-million-unemployment-benefits-scam-state-says/ https://www.seattletimes.com/business/technical-error-helped...
- pnw_hazor 6y agoThe King 5 article says that the WA project was led by Hewlett-Packard and then Microsoft helped out at the end.
- newacct583 6y ago> It was a boondoggle that cost taxpayers ~$50mm. Given that this cost is of the order of the fraud you think it would have prevented if it had been done "right", maybe they were spending too little.
- folkhack 6y agoJust throwing this out there - any highly regulated and/or political entity has the bottom-dollar solution for tech/IT. Got out of the education software sector because of it myself. The problem is that it takes real budgets and effort to build these highly complex systems. It requires teams of competent engineers that are willing to take the extra steps to ensure the systems they're building/connecting are managed in a security-positive manner. When these sort of projects are bid out it's usually the bottom-dollar bidder and/or whoever has the most "good ol' boy" connections; this often doesn't correlate to the previously stated need for technical competency. Also there's the problem of talent. Private vs. public sector development firms typically pay out on different scales for similar work/stress loads. All of this is anecdotal but I'm so not surprised.
- pnw_hazor 6y agoI competed for some gov projects before. The one-trick that produces such bad outcomes is requiring the RFP winners to have done similar projects before. This often freezes out local innovators in favor of large national contractors that specialize in fubar government projects.
- madhadron 6y agoThe solution to this seems to be to make software companies liable for the damages their errors cause. Zero day in Windows allows massive theft? Microsoft's on the line. Your web app let someone drain the state unemployment benefits? Guess who's on the line for that, too. If your company could obviously not cover the kind of problems that could arise, you have to be bonded.
- oh_sigh 6y agoA mere 50 mil on a website? I think the developers should get a presidential medal of freedom for bringing it in at such a low cost. Consider that healthcare.gov cost 40x that much.
- jschwartzi 6y agoAnd that it didn't work at all until USDS took it over.