incredible, when will people be fired?
“In addition, GSA told
Devis at its debriefing that contractor risk was not a determining
factor in the award decision, despite the fact that a majority of the
evaluation panel found the Symplicity proposal to be
“unacceptable” and
offering “little confidence” of successful performance,” he added.
wow fully insane, why have technical committees if you are just going to give them to dumb companies
So basically, you're saying that government should spend only money to implement open source database like mysql or postgresql.
While I have all the disregard for MySQL and all the appreciation for postgresql, this is really a dangerous approach. The source for applications used by governments really HAS TO BE closed source. And this is just because government doesn't need that vulnerabilities should be made public and exposed so any 17 year old to be able to take advantage of my SSN.
I'd feel very nervous knowing that my SSN is stored on piece-of-crap mysql database.
Get real.
Posted by: gigiduru | October 30, 2007 at 13:34
actually i didn't say anything to that effect, since i don't know what was technically proposed by the companies. My beef is that 3 years on and GSA has wasted money and more importantly time and ignored their internal controls.
And security through obscurity isn't the answer to any system, betting that the design will be so good no one will break it is asking for trouble (look up Pollard).
As for your SSN, sign-up with one of the the credit watch services, I just assume my SSN will get out via a bank data-breach, etc. (which it has)
Posted by: john s | October 30, 2007 at 18:19