Ludicrous amounts of money are paid by the government to a selected niche of companies for developing all kinds of useless websites which barely work under load and have abysmal implementations with blatant security holes. This law can act as a safeguard against such "epic failures", so that the taxpayers can be aware of what they are actually paying for. 300k euros for a static website? Let's hope it's over.
Anything that requires working with a hard to work with organization is “expensive” in one way or another. You need to sell them the project, which could take months or years. You need to figure out what they need, which will be difficult and you’ll be wrong because no one knows, nevermind articulating it . You’ll be forced to take numerous long cuts to meet unnecessary requirements. There will be iterations, slow progress, long waits for client input, training…
The companies who succeed at this are the ones who are experts in this process. They sell well. They’re good at “managing the process” and winning when a project is 3 years overdue, over budget, the spec is on iteration 46, and no one can remember the original goal.
OTOH, if the government is developing software, why shouldn’t it be open source. At the least, its good transparency.
The Bulgarian government is unable to undertake a surveillance project of any substantial scale simply because it lacks the technological expertise.
I mean, wow.
By none other than CGI, HQ'd down the street from me in Montreal?
Governments and Big Corps have quite an ability to spend money :). Understand that it's a game of distribution of power - not outcomes, and you understand it a little bit better :).
Exceptionalism and efficiency is for small companies and startups, for the most part.
I wrote more details on this on HN at the time, ask and I'll dig some up.
That is actually not that bad considering the fact that to sell to the government usually requires going through a lengthy bureaucratic process that involves metric tons of meetings, paperwork, constant back-and-forth, changes and revisions, guarantees, insurance, etc, that costs the seller easily north of 100k+ just to get started.
Meaning the cost is not in the product nor service, it is rather in the process.
"Ronaldson refused to table any documents relating to the case, stating that publishing the source code could lead to the EasyCount software being hacked. "In relation to the source code for the Senate counting system, I am advised that publication of the software could leave the voting system open to hacking or manipulation," he said. "In addition, I am advised that the AEC classifies the relevant software as commercial-in-confidence as it also underpins the industrial and fee-for-service election counting systems."" [1]
Australia's federal senate vote count software is a Visual Basic application. It was developed when an upgrade to Windows 2000 broke the previous COBOL application. [2]
[1] http://www.zdnet.com/article/government-blocks-aec-source-co...
[2] http://www.itnews.com.au/news/the-tech-behind-was-senate-rec...
Where they are wrong is in the assumption that keeping the source closed makes them safe from an attack.
However I do suspect that they engineered the VB application terribly. But them using VB should not automatically disqualify them from writing good code.
The election counting software is as open as it can be, without having open source. There is a clear specification that is published online on the actual mechanics of the voting process(e.g. how votes are translated into representatives). Records detailing the actual paper vote tallies, signed off by regional vote organizers and managers, are accessible in electronic and paper format. The committee handling the voting process encourages independent verification of the software's calculations.
It's far more likely(and often documented by journalists) that a party would commit voting fraud by purchasing votes or bribing vote organizers, rather than hacking the election software.
[1] http://www.mediapool.bg/mihail-konstantinov-podade-ostavka-k...
I've been thinking that way for a long time, nice to see I'm not alone. Let's hope other jurisdictions follow suit.
Open source XKeyscore, yay!
Yeah, this is very well said. Most laws in Bulgaria are either not enforced or "avoidable" :)
In my ideal fantasy world, at some point other countries might have a look at one of the open source projects of Bulgaria and collaborate when the goals align closely.
They have public standards for government websites, server HTTPS configs, website user interfaces, etc. On GitHub!
In any case it is good. Future procurements will show how well the law is applied.
I'm not saying that using OSS is a bad thing. I don't, however, think that 'OSS only' is the solution to the problem at hand.
edit: A new government agency is tasked with enforcing the law
Ah, I see now.