9 ms·
In Washington State we have a system to track cannabis, the enforcement officers are supposed to be able to get reports from this system. The system is super b
by openthc 5y ago
In Washington State we have a system to track cannabis, the enforcement officers are supposed to be able to get reports from this system. The system is super buggy and also doesn't have meaningful reports. So there is a secondary system for officers to export to Excel documents. In one of the trainings they've been instructed to look for anomalies -- not real analisys, not even a pivot table. One thing they find is "negative quantities" -- but how can that be? (hint: it's bugs in the tracking software). Then enforcement shows up at the cannabis business to audit these negative numbers (or demand the business try to correct the data (which they cannot due to bugs)).
So, crappy software gets law enforcement officers to basically review data "anomalies" created by bugs by visiting a business. The second most expensive method for data sanatization I can imagine. It's a poor use of their time and disruptive to the business.
The system in WA is so buggy that the agency has opted to freeze the software rather than try to fix the issues. The future of government software is bleak -- so long as they keep using closed source packages from low-cost bidders.
- laurent92 5y agoWhy isn’t all software created for the government required to be open-source? Would that really drive the costs up, if the providers don’t have the choice?
- openthc 5y agoThe vendor claimed that if the code was out it would be a security risk. The agency claims the vendor needs to protect their intellectual property rights. We have (some) visibility into other things our taxes pay for -- the software should absolutely be one -- expecially the regulatory compliance ones that drive enforcement action. Edit: also, they were breached anyway shortly after launch (2018) and then an email went around offerting to sell the code and data from their entire system.
- laurent92 5y agoAnd it is true: If their code were out, it would be painfully obvious that it is full of vulnerabilities. Security by obscurity! I know that because I’m myself afraid of making my old app open-source… I wish I had done a bug bounty from day #1. Bug bounties are a killer tool. I wish some lawyers had made a license like “Not open-source but here’s the source for vulnerability research.”
- Kinrany 5y agoThe government could also require a bug bounty, with a centralized agency investigating reports.