2020 US Census Plagued By Hacking Threats, Cost Overruns (reuters.com) 66
Reuters reports: In 2016, the U.S. Census Bureau faced a pivotal choice in its plan to digitize the nation's once-a-decade population count: build a system for collecting and processing data in-house, or buy one from an outside contractor. The bureau chose Pegasystems, reasoning that outsourcing would be cheaper and more effective. Three years later, the project faces serious reliability and security problems, according to Reuters interviews with six technology professionals currently or formerly involved in the census digitization effort. And its projected cost has doubled to $167 million -- about $40 million more than the bureau's 2016 cost projection for building the site in-house. The Pega-built website was hacked from IP addresses in Russia during 2018 testing of census systems, according to two security sources with direct knowledge of the incident. One of the sources said an intruder bypassed a "firewall" and accessed parts of the system that should have been restricted to census developers. "He got into the network," one of the sources said. "He got into where the public is not supposed to go." In a separate incident during the same test, an IP address affiliated with the census site experienced a domain name service attack, causing a sharp increase in traffic, according to one of the two sources and a third source with direct knowledge of the incident.
Re:Clearly this must be Russia's fault (Score:4, Interesting)
When you are the representative of a large organization or a government. Then what you say publicly is extremely important.
There are people who will follow a popular figure or party no matter what. You can see them change their views on a topic change on a dime.
Eg. When Apple Switched to Intel CPU Mac Fan Boys who were like Power PC is so much better than anything Intel can come up with, to be a big Intel fan.
So when a public figure states something, seriously or not. People will take it seriously and a lot of people will blindly change their opinions to be inline, with the leading personality or group.
Threats even from an anonymous source cause the same effect. As we normally feel vulnerable in general. So a tweet seemingly from Russia says We can hack into it. It has to be taken seriously.
Russia does have a lot to gain by hacking our Census information. If they want a particular party to win elections (as they seem easier to work with) then with Census information they can just make areas where people tend to vote a particular way (often rural or urban districts) seem more populated then they actually are, in those cases, additional Representatives will be applied to meet the seemingly population needs.
Re: (Score:2)
As we normally feel vulnerable in general.
Speak for yourself.
Settle down everyone I have the solution (Score:5, Funny)
Re:Settle down everyone I have the solution (Score:5, Insightful)
Medicare is one of the most popular programs in history. https://www.asaging.org/blog/m... [asaging.org]
Your baseless opinions about government do not match what the public actually thinks. This sort of anti-democratic propaganda is destroying our country. The government is we, the people. The reason we, the people, form governments is to protect ourselves from predators wearing human skins. Folks who want small government really just want tyranny of the strong over the weak.
Re: (Score:2)
Well, it is a safety net for the elderly, and last resort or last hope for many of them.
But as it currently is, it eats up a HUGE amount of the US federal budget, and we can barely afford it.
Try adding on millions more and see how well that goes.
They also don't pay enough or cover everything, hence the medicare side packages insurance companies sell.
I mean, I'm disappointed it won't cover my elderly parents' hearing aid needs, nor dental needs.
It
Re: (Score:2)
We can certainly afford medicare because the alternative is worse. If we had medicare for all, we would have even more negotiating power with pharmaceutical and health care providers. France has proven that, if you have free college, you can pay doctors $80,000 a year, on average, and still have enough doctors for a better health care system than the US has.
The federal government can do things efficiently. Just look at how Bill Clinton cut costs without cutting services. You just have to want government to
Re: (Score:2)
You know, I'd not like a world where my Dr. ONLY gets paid $80K a year.
Not going to find many qualified people wanting to do it anymore and have to go through all they have to be a Dr. without proper compensation....especially surgeons, etc..
Re: (Score:2)
Re: (Score:2)
Hell, IT people easily make more than that....
Re: (Score:2)
Re:Settle down everyone I have the solution (Score:4, Interesting)
Oh yes, the insurance companies are so much better.
Re: (Score:2)
The problem here isn't the feds, the problem is in trying to outsource to a private company. The thinking has been broken for some time, both in government and private business. That is, if something is too hard or expensive for us to do it, then let's outsource to someone else who will do a better job for less money! It's ridiculous thinking and it keeps failing.
The biggest problems with governments trying to do something comes from the private industry trying to fleece the government with overpriced co
Re: (Score:2)
Possibly even more basic...is governments trying to do something they are not only NOT good or efficient at doing, but also trying to do things they are NOT charged with doing, ie by their constitution (especially at the Federal Level).
The Interstate Commerce clause, has been bastardized waaaay too much over the years to give the Feds more power than they were supposed to have.
We need not to give them more, but to reign them back in....and gi
Re: (Score:2)
The topic here was the census, which is the government's constitutionally mandated job. They can do it better than any private company, though getting private help is good of course (ie, tabulating machines from IBM in the past). The meme that government is inept in everything is very short sighted and ignores the fact that private industry is also highly inept on a regular basis.
Re: (Score:2)
Re: (Score:2)
Yeah, currently there are people that walk around, going house to house asking for the number of people in your house. They have a clipboard and are very swift and kind. This happens once every 10 years.
But now they're wanting to digitize the whole affair. Seems like they're trying to fix something that's not broken, and that never ends well.
Re: (Score:2)
Well, especially these days...I dunno if I'd want to be out walking around in many neighborhoods, especially without being armed.
Places in Chicago and Baltimore imme
Re: Settle down everyone I have the solution (Score:2)
Don't be evil, at least sometimes? (Score:1)
Can't we require good ol' FB, Google, and NSA to just give us this breakdown?
They clearly know with better accuracy at this point. And I'm sure they would provide the census info for a mere billion.
Re: (Score:2)
If by the targeted Ads I get is any example. FB and Google doesn't really know that information to well.
Local Restaurant chain 150 miles away. (Probably based on the location of my ISP)
Targeted Political ads from a party that I do not belong to and often actively oppose. (Perhaps because I watch Wood Working Videos (That don't cover politics))
Assumes that I have children.... (As I look at friends and family, family pictures?)
My online social media presence, I keep rather reserved. Making it difficult fo
Not a good sign (Score:1)
Test 1.0: "F-"
Got through the Firewall (Score:3)
Better question. Why was a test site open to the internet? They can do virtual networks and do testing as if it was a real world environment.
Re: (Score:1)
Census takers will probably be inputting directly into a centralized database using handheld devices across the internet. How do you test that without opening it to the internet?
Re: (Score:2)
Re: (Score:2)
Re: (Score:3)
The devices have VPN Software with two factor authentication to connect to the site. Yes having a VPN open is a port open to the internet and a possible threat point. However it is way more secure then having a web site public to the internet.
A public website is like locking your doors on your car. a VPN is locking your car doors while in a locked Garage.
What can make it more secure is the VPN will only allow particular MAC addresses to connect.
Re: (Score:2)
I don't know anything about the census software but knowing how our government works in general it wouldn't surprise me one bit if the system was a simple http form that dumped info to a .csv file and the vendor charged $150 million for it.
Re: (Score:3)
Re: (Score:2)
Well, MAC's are pretty easy to spoof.
Just have folks sniff the signals near any Census types carrying their devices and find the MACs they're using might be one method.....
Re: (Score:2)
That+Plus Encrypted Login to a VPN+Second Factor Authentication+Finding the internal server connection+Login and Password to that.
There is no fool proof security system that is functional. However you can make it difficult and expensive to break in.
To have folks sniff near by signals to copy the MAC Address is already an expensive undertaking.
Re: (Score:2)
Re: (Score:2)
What can make it more secure is the VPN will only allow particular MAC addresses to connect.
Along with the use of client certificates and strong ciphers.
Re: Got through the Firewall (Score:2)
Re: (Score:1)
What?
Re: (Score:2, Interesting)
Both George W Bush and Donald Trump (Republicans) won their first term elections with minority votes, with opposition Gore and Clinton actually had received more votes nationally.
This is due to the representative nature of the Electoral Collage. And population shifts means the number of Representatives may be off, having some represent more or less people per their area. The Census is important to realign these counts.
It is to the republicans best interest to keep these electoral lines where they are, as
Re: (Score:1)
Our Founders were a lot smarter than we give them credit for.
The EC is a backstop, a guard against Mob Rule. This isn't some bullshit democracy like England or Australia, where the Gov't can just snap their fingers and declare something so just because they say it. Trump found that out the hard way. But, some think that's exactly how a government should work - snap your fingers and you impose your will on the people. That's a dictatorship or a monarchy, not a republic.
The Left will continue to press its
Re: (Score:3)
Yes, Gerrymandering has been used by both sides. But the flavor done post 2010 - using software and voting data to precisely align districts so that a minority of votes produces a large majority of Republican representation in states like North Carolina is a new thing.
The lower courts ruled that NC's districts violated the constitution - on an equal protection basis, I think. They even had folks involved in drawing the map state that their intention was to skew representation toward Republicans. But the
Re: (Score:2)
Well, that's an interesting approach. Admit that Rucho v. Common Cause was a case about both North Carolina and Maryland, then claim that somehow Maryland is different and doesn't count.
You must be an amazing Supreme Court justice - able to keep your identity secret while posting on slashdot for years! Please use your nerd powers for good!
Re: (Score:2)
The EC wasn't to prevent Mob Rule, but a compromise in These United States to make sure each State has enough power to effect its point of view. The EC allows Mob Mentality to flourish. The elections today are in Swing States, and the political divide isn't actually with Red and Blue states, but Rural and Urban Voters. What we call Blue states, are often more Urban States, and what we Call Red tend to be more rural.
The Swing states, tend to have some good sized cities and rural areas as well. So the agen
Why? (Score:2)
Why is "firewall" in quotes?
Re: (Score:1)
Re: (Score:2)
Currently not fixable (Score:3)
This can not be done with generic computers and OS.
Computers, and the internet, are designed to be open. It's built into there most basic concept.
If we want to go electronic, we need a custom OS, on custom boxes, and a non internet delivery system of data.
Good news, the system doesn't need to be complex since all they will do is run a completely custom machine and only need to handle vote counts.
No need for complex video drivers, not need for and sounds outside of a beep, and so on.
Less complexity, fewer vectors for attack.
Components need to be simple and made by an evaluated and trusted company manufacture hear in america.
It needs a separate system hard wired to compare a 'md5' of the OS every minute.
The ONLY thing that can be written to needs to be the vote count.
And it needs to be made by a non partisan transparent government agency.
Then users should get 2 receipts, one for a box and one to compare vote.
And that's just the start.
Re: (Score:2)
This can not be done with generic computers and OS.
That's as may be, but why are you talking about voting? The article is about census taking.
Re: (Score:2)
If they aren't allowed to ask if they are US citizens... does it really matter?
It never is (Score:3)
" reasoning that outsourcing would be cheaper and more effective."
It never is, long term. Short term? perhaps, but we are talking about the government, so long term is critical; which is why it should be developed in house.
I've been through ,any project were a government agency is 'upgrading' away from main frames into something like SAP or Oracle.
Every time, the cost exceeded updating the mainframe within 5 years.
With less reliability in the system, more maintenance, and vendor support is a toss of the dice.
Outsourcing is great for a company that has bonus driven executives the go away after 3-5 years.
Well, great for them, not for the company, long term.
Re: (Score:2)
Re: (Score:2)
For that matter, they could probably just ask Google which most likely has all of the data that census bureau cares about anyways. Between them Facebook and Amazon I wouldn't be surprised if you could put together a scary accurate profile of 90% of the country.
90%? Who are these amazing secret agent 10% who have managed to escape the gaze of the all-seeing eye?? There definitely aren't that many Amish in the country.
Choosing what to ask for (Score:3)
Constitutionally, the Census is to count how many people live where, to use in making sure that the House of Representatives is appropriately representing the people. THAT information does not need a lot of security, other than making sure it is not contaminated.
HOWEVER, we are now getting asked things that aren't so generic. What sex are the people in the household? What are their ages? What is their racial makeup? Marital status? This information is sensitive enough to warrant heightened security.
Of course, it's also the information needed to gerrymander districts to make sure certain groups get control over as many people as possible...
Re: (Score:2)
Re: (Score:3)
I don't understand WHY that question got turned down or they folded.
Asking citizenship is NOT a new question....it had been asked on many census' in the past, only on relatively recent ones had it been dropped, but historically it had been used before.
And really it makes perfect sense to use it, I mean it is FOR knowing
Re: (Score:2)
Asking citizenship is NOT a new question....it had been asked on many census' in the past, only on relatively recent ones had it been dropped, but historically it had been used before.
Describe “recent”. On the short form, the last time citizenship question was asked was 1950. The long form had it as recent as 2000; however, the long form asked for everything including household plumbing.
And really it makes perfect sense to use it, I mean it is FOR knowing where US citizens live and how best to represent them, no?
1) The Constitution specifically calls for a count of "persons" not citizens. 2) The count of persons helps to determine resource allocation not just vote distribution. Counting only citizens will undercount. Case in point, one of my friends, Bob (not his real name) is from England and is here
cost overruns? (Score:1)
Wow, they're going to be spending $40M more than projected....
Which will amount to 0.004% of this year's deficit. The Census Bureau obviously isn't managing to hold up its proper share of Washington's spending.
Rather more seriously, there are ALWAYS cost overruns on US Government projects, quite possibly because they have an unlimited amount of money to spend, so noone cares....
Note that if you can just create more money when you spend more than you take in in taxes, you effectively have an unlimited am
Re: (Score:2)
Wrong Mod (Score:2)
Abolish it (Score:1)
Also, if you want to piss off a White Supremacist, note the Constitution requires counting "residents". Not "citizens", not "legal residents". So constitutionally, you must count illegal aliens. Trying to scare them off
Re: (Score:1)
Screw off with your white supremacist bile. I've never met a legal immigrant who was in favor of illegal immigration and half of my family are immigrants. It is important to know how many illegal immigrants are in the country. Why do you oppose this?
They start by hiring anyone they can find (Score:2)
Keep it in house (Score:2)