back
86 comments
You wouldn't know the background motivating this decision unless you have been a frustrated user of the nearly non-functional software of Bulgarian state institutions.

Ludicrous amounts of money are paid by the government to a selected niche of companies for developing all kinds of useless websites which barely work under load and have abysmal implementations with blatant security holes. This law can act as a safeguard against such "epic failures", so that the taxpayers can be aware of what they are actually paying for. 300k euros for a static website? Let's hope it's over.

I hope it helps, but it doesn't seem like a sure thing on the face of it. To the extent these big, expensive government projects are similar to smaller “dumb-customer” projects, I don’t think this will help.

Anything that requires working with a hard to work with organization is “expensive” in one way or another. You need to sell them the project, which could take months or years. You need to figure out what they need, which will be difficult and you’ll be wrong because no one knows, nevermind articulating it . You’ll be forced to take numerous long cuts to meet unnecessary requirements. There will be iterations, slow progress, long waits for client input, training…

The companies who succeed at this are the ones who are experts in this process. They sell well. They’re good at “managing the process” and winning when a project is 3 years overdue, over budget, the spec is on iteration 46, and no one can remember the original goal.

OTOH, if the government is developing software, why shouldn’t it be open source. At the least, its good transparency.

Yes, this is mostly about preventing taxpayer rip-off for trivial software. Similar fraud schemes are exploited in almost every infrastructure development project. The government would repave a road with 1/3 of the official budget and the rest would be shared among the officials and shady business owners.

The Bulgarian government is unable to undertake a surveillance project of any substantial scale simply because it lacks the technological expertise.

I do not think you can imagine what kind of money (huge amounts) and what kind of software (worse possible you can release) is developed in fraudulent schemes where corrupt governments meet corrupt businesses. Having them by law open spurce I believe it will stop a lot of money to be wasted and quality of software to be much better compared to what is happening now.
This is the same or even worse in Romania. I just sent to Romania prime minister a link to this article via his FB account. I am curious to see if I will get any kind of answer.
If you have a government sponsored monopoly like that, at least do a half-way decent job. I will never understand getting paid $300k for a static website and being so desperate to squeeze another ounce of profit out of an already absurdly profitable contract that you shoot yourself in the foot by not at least delivering something pretty.

I mean, wow.

The predetermined companies chosen to execute these projects have never operated in real market conditions and they employ underpaid, demotivated people. No competent programmer would ever want to work there. Most of these companies are actually ill-transformed former communist enterprises which started importing and selling hardware in the 1990s, doing the occasional state software project when it comes up.
What happens is they pocket $295k and spend $5k on an actual project. In Poland a company got ~$150k to make a system to collect and count votes for local elections, it failed spectacularly. It turned out they employed one 23 year old CS student to make everything over about a half year. No public salary data, but I bet they paid her something like $800/month. The saddest thing is she got most of the blame for failure, if you google her name it's the only thing that comes out.
You mean like the Obamacare website that cost nearly $2 Billion to develop?

By none other than CGI, HQ'd down the street from me in Montreal?

Governments and Big Corps have quite an ability to spend money :). Understand that it's a game of distribution of power - not outcomes, and you understand it a little bit better :).

Exceptionalism and efficiency is for small companies and startups, for the most part.

In all fairness to CGI and company, the government set them up for abject failure, no dream team of programmers could have succeeded with it taking the role of integrator for which is did not have the talent or realization of the testing required, so many delayed decisions, and last minute changes (like a very big one a week or two before), being forced to use an unfamiliar database that, worse, implemented an unfamiliar paradigm (wasn't an RDBMS), etc.

I wrote more details on this on HN at the time, ask and I'll dig some up.

Considering the US is a powerhouse of software engineering, and this was a state project, why did they pay CGI a Canadian company to do this?
How exactly is open source going to fix that? The same companies can write the same garbage code for too much money with open source software just as easily. In fact they're probably already using open source.
Their end code must now be open source. Taxpayers can review the code they produce and raise a stink.
> 300k euros for a static website? Let's hope it's over.

That is actually not that bad considering the fact that to sell to the government usually requires going through a lengthy bureaucratic process that involves metric tons of meetings, paperwork, constant back-and-forth, changes and revisions, guarantees, insurance, etc, that costs the seller easily north of 100k+ just to get started.

Meaning the cost is not in the product nor service, it is rather in the process.

I hope our country gets to your level. Our online tax system is an excel sheet and the site doesn't handle load well.
I remember the CEO of Information Services JSC (the de-facto Bulgarian monopolist in governement software procurement), prof. Mihail Konstantinov, making the ridiculous claim on TV that "We can't release the source code of the elections counting software. Anyone who has the source can hack into the system, even children know that. If you don't understand that, you should tear your diploma". Glad to see that morons such as him will no longer have the final say.
If it makes you feel better, the Australian government said the same thing:

"Ronaldson refused to table any documents relating to the case, stating that publishing the source code could lead to the EasyCount software being hacked. "In relation to the source code for the Senate counting system, I am advised that publication of the software could leave the voting system open to hacking or manipulation," he said. "In addition, I am advised that the AEC classifies the relevant software as commercial-in-confidence as it also underpins the industrial and fee-for-service election counting systems."" [1]

Australia's federal senate vote count software is a Visual Basic application. It was developed when an upgrade to Windows 2000 broke the previous COBOL application. [2]

[1] http://www.zdnet.com/article/government-blocks-aec-source-co...

[2] http://www.itnews.com.au/news/the-tech-behind-was-senate-rec...

These politicians are right - simply opening the existing source, with all it's flaws, bugs, and security holes, would be dangerous. It would be a huge help to any malicious party. I don't think they're suggesting open source is worse from a security point of view; they're saying that you can't open up an existing product without doing a lot of work first.

Where they are wrong is in the assumption that keeping the source closed makes them safe from an attack.

I don't see the huge issue with using VB. You can engineer a solution in a modern language terribly, and similarly engineer a VB application well.

However I do suspect that they engineered the VB application terribly. But them using VB should not automatically disqualify them from writing good code.

Actually, we made sure that the e-voting provisions in the new electoral code explicitly require the whole software to be open source. Especially for voting this is mandatory, otherwise there is no trust.
And how do you ensure that the actual deployed code doesn't differ from the one posted on GitHub?
That's awesome to hear. Many thanks for your efforts :)
Unlike private companies, the CEO of Information Services is a political position rather than an actual management position. The decision-making power within the company rests in the hands of the regional chapter executives, who devise and negotiate the projects their chapter will take on. Coordination between the chapters is usually done by the Sofia head chapter's executive(who is not the CEO). The likelihood of prof Konstantinov actually being involved in a decision made by the company is pretty low.

The election counting software is as open as it can be, without having open source. There is a clear specification that is published online on the actual mechanics of the voting process(e.g. how votes are translated into representatives). Records detailing the actual paper vote tallies, signed off by regional vote organizers and managers, are accessible in electronic and paper format. The committee handling the voting process encourages independent verification of the software's calculations.

It's far more likely(and often documented by journalists) that a party would commit voting fraud by purchasing votes or bribing vote organizers, rather than hacking the election software.

The quote was slightly off, apologies. I was quoting from memory, this was 3 years ago, and I can no longer edit the parent post. What he actually said was more like (translation): "Only someone who does not know how to turn on the computer, can suggest that the election counting software's source should be made public" [1].

[1] http://www.mediapool.bg/mihail-konstantinov-podade-ostavka-k...

Whichever subject Prof. Konstantinov is an expert in, it's not cryptography: https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle.
He is a professor in Mathematics, and is often invited in popular TV shows as a supposed "expert" on elections, software, and politics in general.
Estonia has published it's e-voting solution on Github: https://github.com/vvk-ehk/evalimine
> It means that whatever custom software the government procures will be visible and accessible to everyone. After all, it’s paid by tax-payers money and they should both be able to see it and benefit from it.

I've been thinking that way for a long time, nice to see I'm not alone. Let's hope other jurisdictions follow suit.

Would be nice if bigger nations like USA, UK/GB, Germany would adopt this policy and have to open source the exploits and root kits that where develop with tax payers money.

Open source XKeyscore, yay!

The UK government's digital services implement Open Standards for most of the code they develop. While this isn't something that third party vendors have to do, GDS/PDS/MOJDS/HMRCDigital are all rapidly reducing the amount of work external vendors do for government anyway.

https://github.com/alphagov

Yes, in the linked presentation I mention GDS as a good example. The US also has a lot of opensource projects.
I think, the USA even already has a law like that, except that projects that were started prior to that law don't have to be open-sourced, so that's how XKeyscore is protected...
"The fact that something is in the law doesn’t mean it’s a fact, though."..."companies will surely try to circumvent it."

Yeah, this is very well said. Most laws in Bulgaria are either not enforced or "avoidable" :)

This is very interesting, I wish more countries followed suit.

In my ideal fantasy world, at some point other countries might have a look at one of the open source projects of Bulgaria and collaborate when the goals align closely.

It would be cool to have a Bulgarian version of the US Government's 18F:

https://18f.gsa.gov/

They have public standards for government websites, server HTTPS configs, website user interfaces, etc. On GitHub!

https://github.com/18F

It mentions "OpenOffice", which is now defunct.

In any case it is good. Future procurements will show how well the law is applied.

OpenOffice isn't defunct, it is still in development: https://www.openoffice.org.
Although not strictly "defunct", point taken - changed it to LibreOffice.
This is Bulgaria. We treat laws as something below "vague recommendations".
I've personally seen the Dutch government spend millions implementing open source software. This was something that could've been fixed for a fraction using a closed source solution. After a couple of years, the project was canceled and the closed source solution was implemented anyway.

I'm not saying that using OSS is a bad thing. I don't, however, think that 'OSS only' is the solution to the problem at hand.

More background please? Because unless they were cutting corners in a huge way (probably security-wise), I don't see how open source would be so much more expensive than closed source. The statement that "[it] could've been fixed for a fraction using closed source" seems very weird since there are no fundamental differences in how one writes open or closed source code.
All this means is that new implementations of software created by contractors will required to be licensed differently than before (with an OSS license), so that contracted work is able to be audited by the public.
That is great news, hope it works out well.
If facebook, google, twitter and others are able to run their world scale software on OSS solutions without being hacked, I am sure that OSS can power some national scale software as well.
They ARE being hacked from time to time :) But they also know that and they run bug-bounty programs.
Every law passed by Bulgarian parliament serves only one purpose - to put pressure on somebody, so people in the shadows can get a slice.

edit: A new government agency is tasked with enforcing the law

Ah, I see now.

I know the people who stand behind this and believe me, they have 0 (zero) dependence on the oligarchy and moreover they are a team of experts who have been in the private sector until recently. This law is one against the status quo.
The GERB party doesn't do any politics or strategic decisions in favour of the nation. Its sole purpose is to keep bureaucracy high and its favoured companies busy by distributing EU funds through "power channels". More bureaucracy means easy money for that same "elite".