<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>gov.uk &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/gov-uk/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Mon, 23 Mar 2026 09:33:26 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>gov.uk &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Book Review: Platformland by Richard Pope ★★★★★]]></title>
		<link>https://shkspr.mobi/blog/2024/12/book-review-platformland-by-richard-pope/</link>
					<comments>https://shkspr.mobi/blog/2024/12/book-review-platformland-by-richard-pope/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sat, 21 Dec 2024 12:34:32 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[Book Review]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[govcamp]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=54574</guid>

					<description><![CDATA[This is an exquisitely detailed and righteously determined look about the how and why of Digital Government.  Richard Pope was there at the beginning of GOV.UK and helped steer it to the magnificent beast it is today. He reflects, clear eyed, on the various successes and failures of the geeky attempt to turn the state into something approaching modernity.  He&#039;s forthright on his views about the…]]></description>
										<content:encoded><![CDATA[<p><img src="https://shkspr.mobi/blog/wp-content/uploads/2024/12/platformland.jpg" alt="Book cover for Platformland featuring lots of interconnected shapes." width="200" class="alignleft size-full wp-image-54575">This is an exquisitely detailed and righteously determined look about the how and why of Digital Government.</p>

<p>Richard Pope was there at the beginning of GOV.UK and helped steer it to the magnificent beast it is today. He reflects, clear eyed, on the various successes and failures of the geeky attempt to turn the state into something approaching modernity.</p>

<p>He's forthright on his views about the lack of vision in most projects:</p>

<blockquote><p>The aim of most digitization programmes is the status quo, delivered more cheaply. This is not surprising. Government business cases are woven from such hopes. The resulting documents are catnip to treasury officials. But efficiency is a trap.</p></blockquote>

<p>All of the advice and lessons are sensible and pragmatic. It is an efficiently written book which avoids the temptation of too much name-dropping or mythologising mundane events.  There is, perhaps, a tinge of bitterness that some projects got dropped or some ideas never quite made it. While the personal is political, he doesn't get into the Politics of the time - but does acknowledge that every decision has a political dimension.</p>

<blockquote><p>Where credentials will ‘live’ is both a technical question and a political question. Apple’s and Google’s digital wallets, and those of Samsung and others, are turning the storage of credentials into a zone of contest between the public and private sectors.</p></blockquote>

<p>Similarly, he is much more interested in what is proven to work and what helps users rather than getting caught up in the various ideologies which spring up around digital government:</p>

<blockquote><p>Privacy debates tend to attract absolutists on both sides, with sometimes-arbitrary arguments that everything must be put under user control in the name of privacy, or the counterargument: that it doesn’t matter what information is reused because people assume the government knows it anyway. Both are unhelpful.</p></blockquote>

<p>Underpinning all of the advice is the realisation that it needs organisational will and political cover to instigate transformation. These things don't happen in isolation and techies need to confront the reality of the way the world is organised.</p>

<p>It is (delightfully) weird seeing friends quoted in this book - and from GovCamp no less! - and gratifying to <a href="https://shkspr.mobi/blog/citations/#falsehoods-programmers-believe-about-families">see one of my posts cited</a>. There's a section about the NHSX Covid tracing app (which I was intimately involved in) - I think it is a fair assessment of what happened and whether those choices were in the best interests of the country. But, again, it is weird seeing your personal history in a book!</p>

<p>Ultimately, it is the sort of book which should be mandatory reading for <em>all</em> Civil Servants and Politicians of <em>every</em> colour. We have to reconfigure the interface between the citizen and the state in order for them to have a more copacetic relationship. We have to redesign the state so that it is able to meet the challenges of today. We have to ensure that it is able to rapidly adapt to the challenges of tomorrow.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=54574&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/12/book-review-platformland-by-richard-pope/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[What the UK Government gets wrong about QR codes]]></title>
		<link>https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/</link>
					<comments>https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 20 Mar 2024 12:34:04 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[domains]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[QR Codes]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=49986</guid>

					<description><![CDATA[One of my most memorable experiences in the Civil Service was discussing link shortening services with a very friendly person from the Foreign and Commonwealth Office.  I was trying to explain why link shortners like bit.ly and ow.ly weren&#039;t sensible for Government use. They didn&#039;t seem to particularly care about the privacy implications or the risk of phishing.  I needed to take a different…]]></description>
										<content:encoded><![CDATA[<p>One of my most memorable experiences in the Civil Service<sup id="fnref:cs"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#fn:cs" class="footnote-ref" title="I am no longer a Civil Servant. The Government's views are not my own. And vice-versa." role="doc-noteref">0</a></sup> was discussing link shortening services with a very friendly<sup id="fnref:friend"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#fn:friend" class="footnote-ref" title="But not so friendly that they'd tell me their surname..." role="doc-noteref">1</a></sup> person from the Foreign and Commonwealth Office.</p>

<p>I was trying to explain why link shortners like bit.ly and ow.ly weren't sensible for Government use. They didn't seem to particularly care about <a href="https://shkspr.mobi/blog/2020/02/bitly-finally-starts-taking-privacy-seriously/">the privacy implications</a> or the risk of phishing.  I needed to take a different tack.</p>

<p>"So, you know how .uk is the UK and .de is Germany, right?"<br>
"Yes."<br>
"What country do you think .ly is for?"</p>

<p>There was some consulting of <a href="https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#LY">ISO 3166-1 alpha-2</a> whereupon the blood drained from their face and they stepped outside to make a phone call.</p>

<p>A little while later, the <a href="https://webarchive.nationalarchives.gov.uk/ukgwa/20220301154404/https://www.ncsc.gov.uk/blog-post/long-and-short-it">National Cyber Security Centre published an explainer about why they weren't using bit.ly any more</a>.</p>

<p>Throughout my time in the Civil Service I advocated for the use of .gov.uk URls everywhere. They're a trusted destination for users, they're under Government control so are less likely to be hijacked, and they don't require users to give their data to third parties.</p>

<p>I helped the Government Communication Service write "<a href="https://gcs.civilservice.gov.uk/blog/link-shorteners-the-long-and-short-of-why-you-shouldnt-use-them/">Link shorteners: the long and short of why you shouldn’t use them</a>."</p>

<p>Today, in the post, I received <strong>six</strong> QR codes for Government services.  Let's take a look at them.</p>

<h2 id="the-good"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#the-good">The Good</a></h2>

<p>Policing Surrey have a QR code which points to <code>surrey-pcc.gov.uk/...</code></p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/PCC.jpg" alt="A leaflet for Surrey Police." width="504" height="512" class="aligncenter size-full wp-image-49992">

<p>Excellent! 10/10! No notes.</p>

<p>Woking Council send out this code which use <code>qr.woking.gov.uk</code></p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/Woking.jpg" alt="A letter about council tax." width="504" height="512" class="aligncenter size-full wp-image-49989">

<p>Brilliant! The use of the <code>qr.</code> subdomain means they can easily track how many people follow the link from the code.</p>

<h2 id="the-bad"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#the-bad">The Bad</a></h2>

<p>Childcare Choices is a leaflet which is, I assume, shoved through everyone's letterbox.  All the URls in the leaflet say <code>gov.uk</code><sup id="fnref:brand"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#fn:brand" class="footnote-ref" title="When I was there, the &quot;Brand Police&quot; were insistent that it should be referred to as GOV.UK in all-caps. The leaflet exclusively uses the lower-case version. Sorry Neil!" role="doc-noteref">2</a></sup> - but what happens when you scan?</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/ChildCare-QR.jpg" alt="A leaflet for Childcare with a prominent QR code." width="504" height="256" class="aligncenter size-full wp-image-49993">

<p>Our old <del>friend</del> enemy Bitly. A user scanning this has no idea where that code will take them. They cannot access the content without giving their data away to Bitly.</p>

<p>Surrey also sent me a leaflet with <strong>two</strong> different QR codes.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/Surrey2.jpg" alt="A leaflet for Surrey - the QR code points to scnv.io." width="504" height="256" class="aligncenter size-full wp-image-49990">

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/Surrey1.jpg" alt="A leaflet for Surrey - the QR code points to scnv.io." width="504" height="256" class="aligncenter size-full wp-image-49991">

<p>There <a href="https://www.beep.blog/io/">are many reasons not to use .io</a>. Of particular interest is the <a href="https://scnv.io/">scnv.io privacy policy</a> which, if you click that link, you will see is missing from their website! What does this company do with the data of people who scan that code? No one knows!</p>

<h2 id="the-ugly"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#the-ugly">The Ugly</a></h2>

<p>Surrey police started <em>so</em> well, but the back of their leaflet is a major disappointment.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/PCC2.jpg" alt="A police leaflet. The QR code is almost invisible." width="504" height="512" class="aligncenter size-full wp-image-49988">

<p>Aside from using an unintelligible Bitly link, the QR code is inverted. The QR standard is very clear that the codes should be black-on-white. Some scanners will have difficulty scanning these white-on-dark codes. They may look æsthetically pleasing, but it's a pretty rubbish experience if you can't scan them.</p>

<h2 id="now-what"><a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#now-what">Now What?</a></h2>

<p><a href="https://shkspr.mobi/blog/2007/12/qr-codes/">I've been writing about QR codes for <em>17 years!</em></a> I'm thrilled that they've finally caught on. But, like any piece of technology, they need to be used sensibly. The <a href="https://shkspr.mobi/blog/2011/05/you-are-too-stupid-to-use-qr-codes-correctly/">rules are pretty straightforward</a> - mostly boiling down to testing your codes and keeping them simple.</p>

<p>Is there a risk <a href="https://shkspr.mobi/blog/2011/12/how-to-prevent-qr-hijacking/">risk of QR hijacking</a>? Possibly. The best defence is to train users to look for a trusted URl.</p>

<p>In this case, using link shorteners is training users to be phished. If they are used to official Government QR codes going to weird locations, they won't notice when a scammer tries to send them to a dodgy site.</p>

<p>Please practice safe QR generation!</p>

<div id="footnotes" role="doc-endnotes">
<hr aria-label="Footnotes">
<ol start="0">

<li id="fn:cs">
<p>I am no longer a Civil Servant. The Government's views are not my own. And vice-versa.&nbsp;<a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#fnref:cs" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:friend">
<p>But not so friendly that they'd tell me their surname...&nbsp;<a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#fnref:friend" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:brand">
<p>When I was there, the "Brand Police" were insistent that it should be referred to as GOV.UK in all-caps. The leaflet exclusively uses the lower-case version. Sorry Neil!&nbsp;<a href="https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/#fnref:brand" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

</ol>
</div>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=49986&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/03/what-the-uk-government-gets-wrong-about-qr-codes/feed/</wfw:commentRss>
			<slash:comments>12</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Are we 'appy about change?]]></title>
		<link>https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/</link>
					<comments>https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Fri, 16 Feb 2024 12:34:05 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[Apps]]></category>
		<category><![CDATA[gov.uk]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=49587</guid>

					<description><![CDATA[Shortly before I left the Civil Service in 2023, I made a complete fool of myself. Someone on Slack was discussing their department&#039;s app and I (rather snidely) asked why it was an app rather than a website. After all, one of the seminal blog posts of GDS was about not building apps.  In response, I was given an eye-roll and told &#34;because that&#039;s how most people get their information, grandpa!&#34; …]]></description>
										<content:encoded><![CDATA[<p>Shortly before I left the Civil Service in 2023, I made a complete fool of myself. Someone on Slack was discussing their department's app and I (rather snidely) asked why it was an app rather than a website. After all, one of the <a href="https://gds.blog.gov.uk/2013/03/12/were-not-appy-not-appy-at-all/">seminal blog posts of GDS was about <em>not</em> building apps</a>.</p>

<p>In response, I was given an eye-roll and told "because that's how most people get their information, <em>grandpa!</em>"<sup id="fnref:gp"><a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fn:gp" class="footnote-ref" title="They didn't actually eye-roll and &quot;grandpa&quot; me, of course. They were perfectly polite. But I sure felt that subtext!" role="doc-noteref">0</a></sup></p>

<p>Last week, I saw this job advert and I got an involuntary shudder.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/02/govuk-app-fs8.png" alt="Advert which says &quot;Fancy working with us on the first GOV.UK mobile app? These Android developer roles are exciting...&quot;" width="720" height="707" class="aligncenter size-full wp-image-49627">

<p>But I am wrong. Time moves on. Some of us find that difficult to cope with. The world is different and that difference is to be embraced.</p>

<p>Let's take a look at what people were saying about mobile apps in government a decade ago:</p>

<blockquote><p>government’s position is that native and hybrid apps are rarely justified - make sure your service meets the Digital by Default Service Standard and it will work well on mobile devices (responsive HTML5)</p>

<p><a href="https://gds.blog.gov.uk/2013/03/12/were-not-appy-not-appy-at-all/">"We're not ‘appy. Not ‘appy at all."</a> (2013)</p></blockquote>

<p>It wasn't a <em>ban</em> on apps, it was merely saying "if you can't build a decent website, then you're probably not competent enough to build a decent app."<sup id="fnref:build"><a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fn:build" class="footnote-ref" title="Again, implied in subtext." role="doc-noteref">1</a></sup></p>

<p>I came to GDS directly from a decade working in the mobile industry. I'd gone from dumbphones, to BlackBerrys, to the explosion of smartphones. Back in 2013, it wasn't immediately obvious who would win the smartphone wars<sup id="fnref:obvs"><a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fn:obvs" class="footnote-ref" title="I'm sure you found it obvious. But most people were sensible and hedged their bets." role="doc-noteref">2</a></sup>. The iPhone app store was only 5 years old. <a href="https://shkspr.mobi/blog/tag/wp7/">Windows Phone 7</a> was being heavily pushed by Microsoft. <a href="https://shkspr.mobi/blog/2012/06/how-do-you-solve-a-problem-like-blackberry/">BlackBerry 10</a> was launching to great fanfare. Symbian was probably dead, but <a href="https://shkspr.mobi/blog/tag/limo/">LiMo</a> and <a href="https://shkspr.mobi/blog/2010/03/choosing-a-new-phone/">Maemo</a> might have had a comeback. Android was a huge fragmented mess. HP was determined to relaunch its fortunes with <a href="https://en.wikipedia.org/wiki/WebOS">WebOS</a> while Mozilla were going after the lower-end handsets with <a href="https://en.wikipedia.org/wiki/Firefox_OS">Firefox OS</a>.</p>

<p>Government services have to be accessible to everyone.  Would departments <em>really</em> have produced apps for half-a-dozen different operating systems? Would they have had the skill and budget to keep them all updated?</p>

<p>Government services shouldn't disturb the market. If the UK had said "Right! You can only submit a tax return using a BlackBerry!" would that have unfairly caused a spike in their market share?</p>

<p>Even still, <a href="https://web.archive.org/web/20151108105101/http://think.withgoogle.com/mobileplanet/en/">smartphone penetration was only at about 60% in the UK</a>.  Did it make sense to spend huge amounts of money for something which wasn't universally accessible?</p>

<p>Back then, a de-facto ban on apps was a sensible precaution.</p>

<p>But today?</p>

<p>I was involved in the <a href="https://shkspr.mobi/blog/2023/04/so-farewell-then-covid-19-app/">UK's COVID-19 App</a>. By that time, there were really only two smartphone OSes in the game; Android and iOS<sup id="fnref:linux"><a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fn:linux" class="footnote-ref" title="Yes, I know you run some weird custom Linux on your phone and are happy recompiling every time there's an update. But you aren't even a statistical blip." role="doc-noteref">3</a></sup>.  The APIs had stabilised such that developing a single app per platform was feasible<sup id="fnref:testing"><a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fn:testing" class="footnote-ref" title="Of course, testing on dozens of different phones with varying ROMs is still expensive and time-consuming." role="doc-noteref">4</a></sup>.</p>

<p>There are also things which the Web just can't do. Apps are needed to read the NFC chips in passports, to use BLE for contact tracing, and to enforce biometric security on accounts.</p>

<p>That contact tracing app, for better or worse, helped show that it was possible for Government to develop national-level apps and that people would install and use them.</p>

<p>Does the world need a "GOV.UK App"? I don't think so. But I'm old and wrong<sup id="fnref:old"><a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fn:old" class="footnote-ref" title="It is rather liberating knowing that many of the truths we cling to depend greatly on our own point of view." role="doc-noteref">5</a></sup>. Research shows that people trust apps more than the web. Lower-income households are more likely to have a shared smartphone than a PC - and an app with multiple accounts is more secure. The web still isn't great at caching data for offline use - so being able to look stuff up when you're out of signal is a must. Apps usually use less data than websites - which is great for people with limited data allowances, or on slow speeds.</p>

<p>Some techies think that we are Keepers of The Sacred Flame.  If we rant hard enough, progress will stop and we'll be comfortable that our knowledge isn't obsolete.  I think I'm rather happy to be freed of that notion.</p>

<p><i lang="la">Tempus fugit, tu senex fossilium. Esne laetus?</i></p>

<div id="footnotes" role="doc-endnotes">
<hr aria-label="Footnotes">
<ol start="0">

<li id="fn:gp">
<p>They didn't actually eye-roll and "grandpa" me, of course. They were perfectly polite. But I sure felt that subtext!&nbsp;<a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fnref:gp" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:build">
<p>Again, implied in subtext.&nbsp;<a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fnref:build" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:obvs">
<p>I'm sure <em>you</em> found it obvious. But most people were sensible and hedged their bets.&nbsp;<a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fnref:obvs" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:linux">
<p>Yes, I know you run some weird custom Linux on your phone and are happy recompiling every time there's an update. But you aren't even a statistical blip.&nbsp;<a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fnref:linux" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:testing">
<p>Of course, testing on dozens of different phones with varying ROMs is still expensive and time-consuming.&nbsp;<a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fnref:testing" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:old">
<p>It is rather liberating knowing that many of the truths we cling to depend greatly on our own point of view.&nbsp;<a href="https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/#fnref:old" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

</ol>
</div>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=49587&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/02/are-we-appy-about-change/feed/</wfw:commentRss>
			<slash:comments>21</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Weeknotes: fin. (So what did I accomplish?)]]></title>
		<link>https://shkspr.mobi/blog/2023/08/weeknotes-fin-so-what-did-i-accomplish/</link>
					<comments>https://shkspr.mobi/blog/2023/08/weeknotes-fin-so-what-did-i-accomplish/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Fri, 11 Aug 2023 11:34:50 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[employment]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[WeekNotes]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=45868</guid>

					<description><![CDATA[I hate being introspective. But I&#039;m told it&#039;s good for me. A few months ago, I handed in my notice to Cabinet Office. And now I&#039;m no longer a Civil Servant.  It&#039;s hard to sum up those 2,462 days.  Every day brought new challenges. I saw my work presented to the highest offices in the land, discussed on the nightly news, cancelled due to General Elections, and implemented across the nation.  I…]]></description>
										<content:encoded><![CDATA[<p>I hate being introspective. But I'm told it's good for me. A few months ago, I handed in my notice to Cabinet Office. And now I'm no longer a Civil Servant.</p>

<p>It's hard to sum up those 2,462 days.  Every day brought new challenges. I saw my work presented to the highest offices in the land, discussed on the nightly news, cancelled due to General Elections, and implemented across the nation.  I represented my country across the world, helped protect it from attacks both digital and biological, and tried to speak a little truth to power.</p>

<p>Along the way I met some fascinating and fantastic people. I was challenged technically, intellectually, and emotionally. I leave a little less naïve, but just as enthusiastic about the power of open technology to transform the state.</p>

<p>It would be impossible to list everything that made me proud to be a Civil Servant. And I carry with me the memories of hundreds of brilliant people that I met. Whether the informal explosion of creativity which is GovCamp, to the rather more genteel meetings in the House of Commons, everyone I met was generous with their time and passionate about their work.</p>

<p>Here is an (incomplete) list of my highlights in no particular order.</p>

<p>Obviously, the absolute top of the list was meeting Chief Mouser to the Cabinet Office, Larry.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/larry.jpg" alt="Blurry photo of me and a cat. Taken inside Number 10." width="480" height="640" class="aligncenter size-full wp-image-46072">
I know it's a bit "I've danced with a man, who's danced with a girl, who's danced with the Prince of Wales" - but I've scritched a cat who has been scritched by monarchs, emperors, and presidents. That's pretty nifty!</p>

<p>And, yes, I got the obligatory photo of me outside №10.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/no10.jpg" alt="Photo of me doing a silly pose outside Number 10 Downing Street." width="768" height="800" class="aligncenter size-full wp-image-46080">
I learned that it's not a brilliant idea to wear a black shirt while standing in front of a black door. So I tarted up my wardrobe for a subsequent visit.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/No10-red.jpg" alt="Me wearing a red shirt while outside Number 10." width="800" height="800" class="aligncenter size-full wp-image-46081"></p>

<p>It's sometimes a little heady to think of the audiences I've addressed. I spoke around the world on technology matters in Government. But it was absolutely surreal to address the various security services.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/NCSC.jpg" alt="Photo of Terence presenting. The background has the NCSC logo." width="657" height="657" class="aligncenter size-full wp-image-46073">
Obviously, there's no photo pointing the other way!</p>

<p>I had the immense privilege to represent my country at a number of international events. In the final days of the UK's membership of the EU, I was one of the delegates to an EU committee looking at closer co-operation through technical standards. 
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/EU.jpg" alt="Photo of Terence's laptop in front of a UK sign at an EU meeting." width="1280" height="960" class="aligncenter size-full wp-image-46074"></p>

<p>I was also the Government's representative to the W3C - which allowed me to become <a href="https://www.w3.org/TR/2021/NOTE-html53-20210128/">an editor on the HTML5 standard</a>.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/HTML5.3-fs8.png" alt="Screenshot showing my name as one of the editors." width="1015" height="464" class="aligncenter size-full wp-image-46075"></p>

<p>While I didn't get to the UN, I was a delegate to ICANN. Which meant I got to enjoy the experience of simultaneous translation.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/translation-booths.jpeg" alt="Translation booths for English, French, and Spanish." width="1024" height="259" class="aligncenter size-full wp-image-46076"></p>

<p>I've <a href="https://shkspr.mobi/blog/tag/nhsx/">blogged extensively about my time at NHSX</a> - and may blog more once the inquiry has finished.  It was... intense. Being asked to help launch a new team, briefing the Secretary of State on tech matters, launching an app which made headlines around the world, and only once getting into trouble with the press!
<a href="https://twitter.com/MattHancock/status/1146491997659828225"><img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/NHSX-launch.jpeg" alt="Selfie by Matt Hancock, featuring some of the team behind NHSX." width="768" class="aligncenter size-full wp-image-46079"></a></p>

<p>Some of the highlights are less tangible. If you search <a href="https://www.digitalmarketplace.service.gov.uk">the Digital Marketplace</a> you'll see that nearly every project mentions open source, open standards, and open APIs.  If you read various announcements by ministers, departments, and directors you'll see them banging on about the need for interoperability. That is, in part, due to my influence.</p>

<p>One of my main reasons for getting into the Civil Service was because, a decade ago, <a href="https://shkspr.mobi/blog/2014/03/reactions-to-the-unsecured-state/">I was appalled at the lack of security on .gov.uk websites</a>.</p>

<style>.social-embed {all: unset;display: block;}.social-embed * {all: unset;display: revert;}.social-embed::after {all: unset;}.social-embed::before {all: unset;}blockquote:not(*) {all: unset;}.social-embed a {cursor: pointer;}blockquote.social-embed {box-sizing: border-box;border: .5px solid;width: 550px;max-width: 100%;font-family: sans-serif;margin: 0;margin-bottom: .5em;padding: 1em;border-radius: 1em;background-color: white;color: black;display: block;}.social-embed-header {display: flex;justify-content: space-between;}.social-embed-user {display: flex;position: relative;align-items: center;text-decoration: none;color: inherit;}.social-embed-avatar {width: 3em;height: 3em;border-radius: 100%;margin-right: .5em;}.social-embed-user-names-name {display: flex;align-items: center;font-weight: bold;margin: 0;}.social-embed-text {margin-top: .5em;}.social-embed-footer {display: flex;align-items: center;justify-content: space-between;}.social-embed-logo {width: 3em;}.social-embed-hr {border: .1px solid;margin: .5em 0 .5em 0;}.social-embed-meta {text-decoration: none !important;color: unset !important;}.social-embed-reply {display: block;}.social-embed-text a, .social-embed-footer time {color: blue;text-decoration: underline;}.social-embed-media, .social-embed-video {border-radius:1em;max-width:100%;}.social-embed-reply{font-size:.75em;display:block;}.social-embed-meter{width: 100%;background: #0005;}</style>

<blockquote class="social-embed" id="social-embed-442290420937392128"><header class="social-embed-header"><a href="https://twitter.com/blangry" class="social-embed-user"><img class="social-embed-avatar" src="data:image/webp;base64,UklGRlgDAABXRUJQVlA4IEwDAAAQDgCdASowADAAPqlImkmmJKKhNV1YAMAVCWwAnTK9fjSIbhoqFvX0kbZe7lZQD6i7x/Jr9HaHsgrZ5ZXGB3yRoHQEakvV9wkxa/XnnSTAHu9D0MKnOWDiy7kx9tFYO339i7DvueJkHc3eRJa+6m6SSOHqguHCIg7gAP7s4gflUilUqyt6dhlf6VXmaJ7pps7cDOYts/KB3ji1z27C9jyU+h2x0QZuk8/LDyEeQ3gywEc7kgOTt1Jsm2YQfz9NuG3NdMmfIvgjzrrh86H4vfq16PmK7/r4v3GU0UB/9o31PZe3B7gkzikyddoR0L0pVsyNl6wukFQkYNGY+AwK8sUHkpZM9ysqVWN1CAX6N7/BLRRTUEMTf9CYsiNcANLgkJbSp/ner752YrTyT3UeC5pZphSD5Sb8EoKf9JWngwb2cGcYZN+JW/Okk2dqlc8dPTtGYiGhSIaz6GZF1OPwYsUcsB4/JzZRPe9/EMjTC9rgABgRYaKUkGoaDNxUYIJZ3aVeClDClwIPp/tGCJgQ60KWSlVgToYOzCBMSVwlltFnl08rsqGngfH7oMVDN/8I3CqYnLK2d5afJZjzH0qxYgg0olaGkJkvZ/KQgXKRgMGpJ4mbcG7vOT9UKAwNl2G9oC7MuMd3NIpfNThrozAXc8qZCB3ah9FaGg5j9WML5Q+rmPblH2zSh/3m1fbHeoe7MsUSoMWpRhVOHdw85f4fggLGe81V/FuUhmty9mH+42b8/SuVlLMeSCYJrWddUx5H88aoP5i9fXzQanmCQ2V8HOZL6gqlSGAXFcHSBYA3ZHGSmmCF+/bSyb5YA5reNE9En1TwfxqaQ/Q2LSaXdTQoPqmFhALvv1cDa/jF67uDNKVmtfoh11TE+I6n/++vDLbVxSKiPpuZHdK1/6SjwxWvvzP9p/5AVj9PidfKWlhP1lzEe4RCHZhJaz9vpbhmO/tFV7bsKtvMHvd9ENcvgtQ1CmOuooQcnlqShoxcMpOjcKKhIT4JM6XPUkqHCr3piGpm4Bpnn9R0mTfuZPGrJE5nPtVRNxezToBhkMxEUa85FiAjrqRGQJe5DVFPMz9HbmtOQYSrlTx4TT5wsayHWI6bAEcHuLHwtPICqeG8WZQA" alt=""><div class="social-embed-user-names"><p class="social-embed-user-names-name">Alex</p>@blangry</div></a><img class="social-embed-logo" alt="" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciCmFyaWEtbGFiZWw9IlR3aXR0ZXIiIHJvbGU9ImltZyIKdmlld0JveD0iMCAwIDUxMiA1MTIiPjxwYXRoCmQ9Im0wIDBINTEyVjUxMkgwIgpmaWxsPSIjZmZmIi8+PHBhdGggZmlsbD0iIzFkOWJmMCIgZD0ibTQ1OCAxNDBxLTIzIDEwLTQ1IDEyIDI1LTE1IDM0LTQzLTI0IDE0LTUwIDE5YTc5IDc5IDAgMDAtMTM1IDcycS0xMDEtNy0xNjMtODNhODAgODAgMCAwMDI0IDEwNnEtMTcgMC0zNi0xMHMtMyA2MiA2NCA3OXEtMTkgNS0zNiAxczE1IDUzIDc0IDU1cS01MCA0MC0xMTcgMzNhMjI0IDIyNCAwIDAwMzQ2LTIwMHEyMy0xNiA0MC00MSIvPjwvc3ZnPg=="></header><section class="social-embed-text">"Dear The Government, I have found over 500 vulnerable websites. Please fix them?" - <a href="https://twitter.com/edent">@edent</a> <a href="https://twitter.com/blangry/status/442290420937392128/photo/1">pic.x.com/n35wsjbyob</a><a href="https://pbs.twimg.com/media/BiNUy19IUAAemvO.jpg"><img class="social-embed-media" alt="" src="data:image/webp;base64,UklGRqosAABXRUJQVlA4IJ4sAACQHgGdASpvAusBPrVUpU8nJCewInC6IgAWiWVuHFq5qFSDETgA58XlLhFEH1TzPL+WkZuhVfJD6XHjf/wbvVqdFseVf+/0O/NNY5sALu/Pr29/MdXl6kGD8wH8eap/uPRPjK/sY/4kJAvotv+0cKD0SqM5Wvx6dT1YYPUeCnVG7rRiQ0G1qKAoP7h4uY5CQRDVYtKDbaP92S3p1phuIbg0PatKMuwigACCwn5hPuzQJd7g0F7tcFSDmNbOL2vN3LSHNdOO2wPmmhDpzrJ2IovbIRv+13vff8362drGgykxaU1f1fsinHKRZrGabblQqbBtvWmXwaEhW8/2vpCRXhJ2AgZ/srm7ZcOk3PWc4/yYRp2mxXG/lpgav8cdKvqgP7BvY0i1ubD195GXj3dre429tcrVCNVcS/mGJTZPq+yXulcrBOdHjKQX4SSNM+T+q/8wAM2/MI489n1d+5C/rzthzlvkobJch/j+fRPZf976uWcmkcxRiRUUBWQ6C6ynlTj9+hEH3OuNOQ0e/7DF87jo2/827Vkw43L/Qv3p5R61lLodAvK0KS9NoEN0Kc0dZbKEoNNuhhzLHXKwLjm9cGxj/SJdQay75CM+oIpdX7sFjoDTDRlhxnC/SXDZAO6oFls4hqQiF1uW3gyXyaX3pOVxA5PtlLIfSLRD/9ZRMwp1oKNdraSX2mmYsBRMujqD2LZg7nDgm14uOLHeI3mMgc0YfgA82KVN7b4ZNbY3YgRkXvaFXengcHkXV7GsebwH0cQ/3dCl9WZjeQWFaf1AEahjhXtav5ULLWN9Oez2qCze+QWBCfi+QqQ2gi1WrxHbg/Pkij2BjbzFM7566qC/3CU0qFPOuASZewmQZIiPG7/ffLuw0lHAKVT//MHmk52lHYX/gxSbIs7//u4VEAhyTSTVf45WeFNrHC8okiCXGCu6RoCtXrSpdgsxA5NysNRfoszIB2Dq8Immn+3G1TsNtR4qfzGrJLHaCsRb9S7F3YKUtWcw8ZUkZ7I0Gc/NSqJhvwBUWWN4OqLiXWy0iT7wHwm9L9WsK9ETM20Z1AxGawaEcZwltVTfW/iYKlQMlVL/bb5fLUVfK3xBlpkn80GB1F1x+/o7xwPDWCCa8jtVHrqVEoMebEhH9oSWwyogSLROovMfT6ziA5NgDQbPMbAHTEuWIWKsXxarzuGgwrvnYRZ5kpXUiYKGlr/ZQfi9y8zi1bKku5MckUypNx2gpcXfWJ+MeMTTMHVXfDaLUA5v4jnBD4arDMRjcpMT/DgA2e5VS0yobiuSWLdmRuZMxAnMfMFOkDO71/RI6HK+oKvTh243FTRa3pBmUw7V8WqCd/00hLlUqssJmO0KXsZFGXqPt6SQ2zpQ76Dkvqts/dhiY5osnOFqRFH3CKeGKPldSxJ2Fk/0tNlYot3+nvQU5D+89b3sKZ4zUQSoU43dyGV1Bcn76q7ge+5ur3HPfVmieeSC0d6GUFYhPE2W6UkyK797oKBic2UHdtw4CNXLdlhSVvF8Lv9eEjbuEDRMsbdvY8O42QXxE85Efee6A6QJsOkOn37J13ULIvg/gcAsFbdxx0KmMT83sMlvWIB34yhwygT+VsssUMsCevN1TKo2v46KY10640vwxIt21hSGlBqOwsxG+5tSfgCRi+6FRTmCNXptejCQNRDOD1qyPfsm3YzJ3813GlJIgujIPl/fwbs35krkMl5WdER2QU/tc661xyRj29fgK90qVsjpMB25Z1DAg2G9M4cRdViietIAJ3pYSXCCD70hsO+CwE4sTqf/Q/8hgnMEyefa+6RNTrLPET81LNjVrch0a3KpR/0KcIL4BPXBPJ24HqBqZmZszuEOQ5XRJvu+dZ7dS6Me7LR61Vo+j+JH2n9pdLQTrDYgxb4IcbsClDjhZqs8swlCJdfgr5nMkDN7qPugeqO2qm+QWmMLYQCsvEXMYyDlg8V7xufTV7tn27a0NNrl98oujsVc0ySqLZQWvxtTu30tZDBBP9Jz67rdHxpmmNJyCfamOgn0pkmeZMcX+aAMkEkOkhjBQBwQ8eaMutFV+aBSkuzzM5XlbVyfYCuuO/nhCdulKi3OjYbAEPOn1hQQepMAvzvVdRmHRBT/V2cANkifkouIZpeUcMDhB7pkeSIPFKjspr1m1gAoJDXy0BHTUX7xtDjR/NgNlC2hiadUbhI7O08f0WxOypC65Bm2Z5lrE1519LgBVHo74ewvxKp8LmeRzbqyqoFns0vOINzRE5jFtpU5PBtOAT6zekRsFkW8iBCWOZsAhW1ALNj1Mko+DJGRzEec9falHqGyqY+XASrZsjUTyoZW+I1fYzvLhXs+InwOJ58JeMsSxHxK5RDfYqNWfCuLKAeQgfcY4TQXeSo5XL3mqtbgkhTl9zz6Lm0s5UKMBUnMkcMjIGimNQFOFADB8HZnMO2SmNT0mrOMQ2LIghwPvVYFrede1nd0a0QuyA4P9vs1Q2rl7SRZUNwO6ktuiZwCMq42sl8Awwx5iFWc2K0zRfLczN7OL3MUfrH7XUIRgqPCZQ60rE1LQHExKGYqGF2YX18MKj16LtlURYC5CNVRAIXvywPthINHZdN5+xqFvX4b1Jifm0dHpv9zJfx+zwMxFJoLbXLO/6vnf3GAEB0/NLMS9P6jAJsvW0jse1FoCeTXMuX3TIxuxULPLOi2jHXwcsUbdY3wcDcOQ1uHndLOFczp8Zg5H9jTrSmGN8Ut51lRCePBzqwdCqkiBpPjvHUV2cklBmQs25oHhShbrE0FcMMX0Uj8ioUOU17blLhF0eTdaexLG9BLUCSUFLj913V9ZqCmGWLVoSS4DuOlJoNsLMUlY0Q5QH6KuefSIlCqC1RTJwix1MEJnDpluHFEvlW9C/81BgPgHPiJVhmgpY4Ki1bg3xeDTMcdleyworgT4R/YlcKleYcKsa/nREFSaBMfbncJ/ycvNY/+yTpbLH1zfgrO73zLK1IGlZGpO+fivcE+PkfIhXhPiJPHUflVSRVb9WZyBjRcOpHvI1jGIb2MRRf9+9QTv/OZZw9VrV975L2r3tVJgGwZLM5XuhchkE9NT8AA/tJy9BZi365fbQEJJi9L0u1CXAhJzq17RaGfjy0s+jUz5VOCrTzUzbQdp949yj0eCjehS9HvX+D5/rJVdlZEUP7rXvr7Dus0Fy5MR1wi1KiEo/LCjDkZ1TRObMju8fGI4llh/ngOVM9FnDejfCRcFygN2lY+Yi5RvWkZBJUhGf1DpON06n33VSU18/sQLJkm1PydtewykpnzuP+lBQq6nJiHDGbgB2pIxJqtimmipqOzPcFVSW0fiq0lGwLPNmd6Tq4BdBhWTFNVID4jsC8qxiwJ3hCWDpu2kNLrHNO/TmlQgjQZCgy7Qyu8oML+kNdTcjTroAhFx+M+0qeJA8w/3JfakCnVArkid9mMonuM3ro+qv5eShaobHUIsuovPdQr5YR1St0l/gE3Xmgahgq4r01KC0EVVjB5ymNXyRp9gpIsxljOTCZswdpn1Q2s8Kjq2qwu3HbkvI5vHOQsr0LFsc+W8PI6pa3anzS/1/lCXhV0mNPboRef0QFxQ/9lRPUG+RtGlqUSmZxfqAs3TA4yYJOVAnTTBTIwpaiCAzkYlTzqROzxTaIuJ1nII0FLFz7kcimN8KzOM6DBgJVjB6c8byWYp3OWvlADAzxZppM+VQh/EYITv+vbbM5+y1Sph2JgclBpRWgOGzEug502hHpGo54Pb/InRfQ2WdMQF/b53IRMIjgZxmxMHUKfEPiorDhdzNEfY7QRjX4sNVj2xmBK2Bvu3KAXNo+wFj7dxTppWbar9pJ1gfBlUy1msYLhCDP7W1Kg13wWsUIj5NpxugIgkyMXLMiEfLa1YcDZtXE99qTbCA27ipyr1cli5i9G4dGG5rQ7Co8U90G/z9xsoAsFG/5OQy3UCd0nEOfT92vr/aijHdur9TyQC/jn9JzgByvXcHgFl11GORV5SoX9XCgg149w/tg/Zu6jzB2zPRJb2GZCQT0e+8Tbzzc1OdfX5juFhXIYxtB50p86OdEJKMNehG7SAso0G5Abopo/aH2y6+uq/iEZMl5vkKEDJZNlgkrJ5sDl8hzd4XZyprxJOKExuMDBubYI/lLZj2PiDU7tQ4gRTIwAJdR6RguYJ8vz/NnARZfMdIxOAjFyOraapXkLev1kmk7GJh4UMHJ6rRZMlYLGV1GePvHf1lt9w3rtX0VAtPqeuAXP0bckpibsVwAGRXE6qNz0aIh7ve0dA0eN+JKu2jG6zJ3BfLfZRY8y3PpC3FFOgOngnB4IRJPj/6c8c6NVfmqUbAPeJh9fxdFyHEJDHoThBjCF4NSoiAcYgQ/cCS40M+M3XqrXDa6bwCLvVeLI14tXw1laYoMAw97+tW59FzoCLfgzmEqY67QKOrltqkNp6YGV5+eWGADCHRRerbSAsqbq3SxQ6pxnHXo1U5go12ZzW1WqQxA967mDq14dd6ORM8/XSPfF1mXXK+20X/rTPR0v3m7+S4zVVeT7LE763ttDK/r1m5nFWkGM+1m3MXDv/X/1Q6BQCtXj4YXJW0kF7ePGz850gFX7uO+r8iv+j8tMxlAZ+Cansb2hM9mOyXLYSrd3lFVBodXdRTMd3TzqRTrjiMowWj4q7T6onqVpB/PLGo/SA1ex5SupseL1YDFS1NYvjytNT95JjDqQTvhqA+NhZQW3agJl+dZh6szwH1JZWZ8z0dHMnqxRCVgk05gsjqjHhQ6V2tMHQjH1noRjYqZWejQBvBB0UrKhBSpKg8K5iczUH9E23EFIzfC45bVmOhNRQwu1eXIwjG6aziAhgIyEOuhag0KP07dQtrd0c9er8hQ8fqRxe3dh+0r1BB4naaTLqzoqIXWha9GG6i9YHotajNFc9IgHE6BYjl7AdLnBNbjbPf1Ydx8RK2RRO7VHQ+oFfmAbPZScbcCdzbXOTOpj3/oHPFvIIPDpyl8KLjorgNvo3SpCY0SMqsa85t61RPkGo0Xa57Wc7+aMd2xWjs9mXcXWG9V/cVCBfx0v5vtfzchkAfPemsyKcm+VoJIts64YeVbQ6elRAFg6G9z2Ge/KNjNnjrSjCPJXho4SLCtHAM00JPEQkjc+s/rNBF/ZH1yWbaK+zqZgKdLdoP5Rzwa8cINRCkRmF/XPmW8+kbVj6d5/OkQ5t3J8GZM0aldiwQuv90ZMnXDqLgtUFvzCedccb5TXXoxbTG1P5hhoqLoFIpmAQ8tsu2XBv7fOXFt3vltAf+FNbdjSTv5j3FevIjHJetHCP+5naho3uQKDAdKhdnCRzcxAMcUagfrstnwPe3+LjZ1wVUwsmhPJPueSu9HEq4kcA/a30Z225PNil37TESYv0V7uk0yJjz6XMeQPGU85ECIaT13dC3CItF0J2RVYv3L+bHGg2WY8zpqRk4mDhsVOjCzYIyV5W9ezEm9EdZGfwsMdCMkw5XfCyxupjfFl1kpzIW6QKdtVXFUBOpzEqaMtexBvPLaqUqUZN5vD+8UpQJJC6dHmaB5fmRQP+gkZElpHzyS6PUD8P7WLXm3iv49S/VnZviAtMEOvoHKadA6F9lO379BaO+W0/PmV0J3v59+2lRqsuTXG1me3hR73eawVbfHdvhfZKN+s5UMSIMxGIuWhXrN+Uky5MCRpBWg2VZ/ZVi3cHviIC5tCT5IIr7pBaN73ddHJVFBHxIbjKK7oqnOhlnAewWiueWxa/qWeVogQT6IkAVvpvVbw+tIKUIG6oneO5yAII55jMijhjKStioz6gsnT8mxKQHNYxGQdxtWd4sgEiPkEd4U4SHlNzauxLPo3sgfKaTUOhZ5bnGqgK9qZyVRKMpcIFttm7ERq1VK7fyjFFlNJXABYCt4UBj2E39eEphM+ci0rwN7pWEFlW9C+ibCbWYYYc9g/5F6IGKzBhq3/UD/BT2G6A+RwYjAncD5Mxq2/jXZeMjxHpwYBylRTAYj44z+rrmDocZeIgPa5yP6GvPNe6w/a2OHz4Tdvf04Ym7OBESiTK9wH8CiJkIgMFpyHEXMZPenCRC3XAYmKyfneEM8WR4c6SGs9rpC8jmb8tiDsxt2vWELM5t8SMuoCK+eaUG7X5OAtsZTZrAvYJQOi7G+4uPBrWKAJLy9NGredum1xxJLW9UlVEuRJb+M04mxO+ItKctXlV0J0yLeF6JGWbmTJbC2EFNMyGTHSyCScIWxs/soba67XhAW8NF4a8PzbPu1y4QEs6Im8dRJ8OkJ936PuX8qPiPvJ4ziV6c9lgRc2OKxviXKcOuo8Nwn6NHw/HhpyaQZl1vf3nddkFxJvy7/R3WKOMWmAP8ltNvEwzL9J/dkjYEmATj+NUQLWdApgflYLwO/ZXsn4xTqmHESUhx8uFHHc9Oil2edrVhHeaw7nlXuERBg5ucHAf1aGVlM+cViph/xxK4W6P17vmpOcZX0sC41gBg9od+YA8M+6WDichsTCYuu63CYQU8T9Sm7L+DOVH4Xb0nILJPLfrImhut3MWMAiJfOTewZkrLJFZCGE8A3XvjW1EDpwYa16Fmc10jy+99Z678HDH8zqJHESQ4sQnAS6ZL68KWYhU8HjVyELBwLmuWCcIIrCk+2XuOdtQyHhZ82XHcI/0n8vBknn1N2ss/wPpbfO5GSsFTo7m4mGtp/F1K40M8UTlyWC/AXyQo5OpMZ3VPksXNg5l+WOC+yns0XDHz38xir111Vy4eG++QcML8kctVJAMLW8bGeNHMMgoiS8X1p2xtgcxuRIaJJwynCiqgv/dw80QYhWgW+9lfxaJSAdnJUAUJe80GCjn0nR5B1DaXOfX8y4Afyb7PdrqU8Y8K2AQeGIkVHHkq8ctvvHMNlHLxSXv/AWhYjcTWb/XJHjfEZDJNVaEmIm8VxEmrHua+XyX7t46cYWs417PqIPj282JrrzSSbc4CMOUmzixe67VD8WVkB/6dW9xvS3mjcq6SgJOvvs+/FXkDeXvWPLq1mevCYS523hF+XfgYmq8SGAvT7ZqAHsl8rFgyBFjo3+ah7DPrUoSFP5rOM61sryBmrPcdgaTkOJIf+ff0mzn7hBRgfNukdAqgz92D6lYFrm0rx9SaiqBKvI7v98bf5sQy6les5cdOawL21LCaN/enRyyjGi21YknizHiaBkMFyPJDTYO83nGENJTB0ryCBz/7eFQbLXthE48OQdZ8NEQPs/9RHu5S3+kbXX/KrIDO01xBs67p5Cxkm1w8htFBOMdMPySlaSA8tzIiJ+HNdPD7JvOBXs75eqLO0JhiA5lZi14T12Nz6BcWts4g5BYAXjt06DJmZfHvE4YSFmgK4+cCP8XJ5Hd2b8UGcX99Wbs8NvdeacrTV0fusEFINdnIf95UdS/HQFkoDxKR9yx1uO6xeHF6O+64Bib12ntY5LO/zAH5UQu7qe9P5qYECBR6ycGu3E+aEb93oumQ2AK2tVFJWNcxf4VwDCprDAfAQTtZGdz6jTAiAAQuDA8WNKp37f9grPgG8S0JRrxUVeC4UrlPvd3kHH56x4PGfLOmXN3RI4WWHYz6J8ImSFci1yFNyopyGPrjqSKMIiEVNxd1S3WRqWD8Fmuz+leSDQuidgqLBfFJMKqQwMs6h9FTlwDpvuwOFQRj2WJBMymerR/YHGNY8QVUZBVZ+L8P4K3WqU3yO9KO7FKcsUgNcYprCclHLa0v7r5uyGJbKUK4Uh0eqZyLoAVSUelJ35lM5HDsSkJhcwS3pZ8R4a921uxGHKCe73sa/XMFwpFlnuroFbIQvRb7khRZG0xX3dLo8Gu5xL0AiGhneZ0tdczLvalapoG5Bl7ZAqKMIZPdrxPMaV2MkozjK4T2e9gLzP0zKzdln88uCTF671ADyGDzdDwQLbQxObhzjyl6qgl+2QzpaKKRWGywCInMPQUSzGYkumR94RVP9KJ4EwfJTeaO7eOAgV7Kj1+VJPhrORNbUfQ3bbcn9k5Yi6iN8UusykbvEDDYa0mi8eSaVyOyjdaD8cQtJ+OlF7m1lMDKaNxnVde5aoqXqN/Sh+eKQlUih8I/ik/DUxihTYJTZ0K7AFCRdMh2KnS1UUJhw/S+Vf5I0NR5BIbb/blUzA5a2arDVONgldA2JqsdMpObwoifNvhsoFx/YLXGL5TGB8xhgUkZJa66iu7iwb6deQVrj0D1NlT7JSBXcrdM8HSFQQ0E+dQ2Sh4zg6gAUIKHqtHBNsw1qERBnBJhfzEwChdx+0WOrVNM43WerItykOtWJWc7G17Yx2DMzm21eMKRBU/YQD/uLVLUR561KC4Tp7D2CFqtPaeWSyho48nXso49dgll157/LelWeRoc8jJGMWaUndmCQ0IH+OqJCFPrI1/+eqYFTiXahHCYw1NwRK5kS25Mp/AcghepF9PbUp9ztaDpap+NdXpJxP6pBkC1he73srasd8Iv5zmX1d6r5KrBhIbXnbMRnuvEXUPRWJIBfy/t8bUDrKecxB5Xq46mUEN00efSdLpjZkTgHiMlwJSOmATVJlxkmLRcETFZ2GU++iI4ZRc0H5ZaV4YI6ozjyxOqKw02206AnC2ayWsxwl4dsr0XnlRPyItD1ug/MYX60UPCDJYxSdLgJDrC4JZpSpa50hJ3yYFdWo+dhkbjl4+jwY08H4/u6xXdAb8zQpQS1UhhCR4mquC27hsQ9d5yNUZ1gIx16DcVU2C17aPgHFo1CVJEFMzzDg0Km88bPMoMvSu4dyGUVBAvdsjyQIYdwhBIf7AEskkhhEZqtvuUhmkjZiJUMzR3bnvT5cbBAze/lIcKcD2lDjcTEpFHqvg1WXWscyeaF0rtNvfWIsRXQ3+C+n2mdGS5gjZeS5XXjq6VURAPsK3a0K6EyKNtulcZ8A/0r6ZZoFwCFQJRpw/Vgs8HL8X+xgHRODt0Gxxsmpszhinl/cAkkEQlj+/9Bh5AR1Ru9wv8BUeaCkI4LGDKJ5GF3v1zkv3ApK+WQ0OH6zloYc86LaNXG2e6FLPDwd3tCw6+FiS2OAA/yjXuZrCYd1WmiEB7rhxsRR0F3KRFtSB47xWOGY397rp1tOrbbbP1wmfSUSLF3jsJ/QAX8HE8NQaRTf9C717LkrXGWsad2m0JLyVbh5wkEGuMfOnU7P7QGuXqMmdqPhbNKtK+sh8UCG83kL25CgKOkzfWecdGIwM6mM/tnmB+VJGj7GigqXoC1SPNHoP+EnuMpOO3Q5ayE4rzMmgeygvIyU9jT5HBsclKXtJSlq/pRMCxy09JF6aIQDed8hbk+lHSDqUw3Yb/LU7uc52lLGfdEAJrHCNpTfhLZellsgr7y5hJOCUJwMkQkHYDA069K+OeaUlINb57qV28DoHgvPNp9DigiIqsgQtvoS8uvtoEcpXhXs4h9BuXXp3FWh+XLNaVAQsoTAn3WZ70EAbj4Nui7rnc+w3Dt1BMPUVVULfbONDlkHIxeV5zjtLcj9gP08Hbi4LyZeJepZoSy7VB6FgPt9wxbSo4WjKLpayduVyT0MxnCFDzhKvxX7lq1CzFDbzkn/zhWFymfXm6OC3PgKQVi0e8h8up7HEtIL0DMsSuXD0EZVwzu1/MorzSe08xl5pq/GKaZ3QbW1X3fTb+VWOlRIZ3+x3+VuUG2SqeawyhzzzcAXhNZTZhB4Cuse/S8XebAiJgO/iTtu2FGI9oLPgTBlJxvssgeHJz6eAPBTUb975Q6LmFnGJzeERJ3kxBX4gsE9N4o0s312shPn2glSJMvRLHdqxG7HI6SI6RnuI3fQhwRC3pbnt4NDlfjxBSGDAbE4E6slPXa4VYLfCZNU1p1gcY4BRFZp/V1MEYCA4FZTTm7NqO5yTfFX/8bkS198tZe87kRJafvKqUd1wl/gB747HnYA8H5JPfwV+LYkbHpmDESEg6cR852LumgevYx9ZtuUj0usnWWrY4ezHZPMCvoBd2PQHJnf+FHcYMTy6ozBKOfxHDAk7KEd7cpRGlMxckc75ZgluCRSWBQTEYCHAdQH0usYkZYekw40DCRLJUiHy8mHTF9enuo3Ilw6230q1U37m6ryGy+95k8LJMXZKGu1e94lrTOb1sV+RE60lkic6fQ/liJbeJ8V/pIpjHdOH99fAn5BD1eMotpGlhH80YcYYLJEv9TqnsxN7QODsVfGQ7QTcb8IqA6rv+hE8yphyosugLrYi+WZ0oIfXxgeNt+mTCINzg1vEYDiuMf8LRZX+g2RXalVmrLi6ORkN9sH628W2rCPN3O8Pd7YTq5wiz87yhZYpVF5prr9B8I5BdQ5GhOkFErJmQ2Jjl90vWHJG9FwBqA8QfMxi4aShY4uTEllcxRCVt7BX8T7yleE+xwP3xgyv6T+A8JmIusdl8ADyXBi7+iSvVnnDlo0KUvOMI1pgPoQgfd7usYcpC2y8oRygEabgklxkwt7fysMHa9LBCCuQ+IWw2xb0RQZjAZb8aH2u8UG3mlrR8J9jHIep6ojepCzfp5r2HkXtwst8Q55Pgf+bs4WKO6K9muwlf9qG+MggWiBNtYp4v1/WtkLYa4GQOXISDFbDcbpUmzmPZlkgDI2PRgeKKzXIJXP52PppVfwEM5tYvTIJQ0fNhvpVuWFsZTJX19pBsYzVayptCgyB5LSHT9rZtUFJVbaayOT4n37mQX9xCKKfsP5kiW2mRUw8fB1R2LL/BLlHBpCE+irLpvfrcAbWvTrajger3Bd/bSt/nVOyMw+yvziTIV3V8buruU0Y6d1655UA42SxT/Doqgip3lGX6yAhB3P2ds2pA03c8C2dtnumALBBDFldmt0jBFmxWKNifhGQP8wsnXqFkwkLlofMk0oYa+IeZrfjszE/nRBVJiQkwPcWly2bFXVwzfJsW8nG92PgsAPUFHKG/iuRKhcet2XrYXFAH3k2UyIKJrq0V3qM6uK4hZGLR2N73DUYxbowcZua8KJo4Qy4gokpEFTJO4jq3ruQbwRo7fMXBXSARsZM5EMlVbiKPCYtjGcC514OYS0V+tio1cnZD2eqSs4STb/HQNMYynPIXAGxHlzyQgpqo2cxJP3SrukHU3V+ypm8hoGfPdf8smJmnNPSCVI9vncisEBaqEK5SoLX0fBTOTWekYrqbr/OFRtVZOfIw18Qw3HsoAFm2/U4MyxMcYE6HsCGq8WmpYcy92td2XiQDoPNC72jVEj8340+nlNkUbiH14Q4dpFcpdIlvcTS9+YU5pBNcUPwDLvOeGTCAw6gYKe59N2XarYtnyKUz1k8LkbFZeq+wGFYbFJjYfuNiZ6FKVKMQTbm6WNa0wdobJMLT4H0NjZMei7rhZyTJU14MEpNhjkqP6ZVUDzT3jwt1fE0maw90wAIyCM6qjpEd58lIWRgLE9yZ4lQrptUtgK/COUV+CtSmHxLSkWog3T0cDtnEDvZFrEKTRFxSI7TqScaXZUBk9XrBWsXIJ0XKJIM8eGQAL1x0CQ3dHK6Cf/p9nm5CvOGGzi9mwvBBsnaChau+0rNYFTj8UOc5+S7mi+eY5chsbuh+7qSRae+/MTyVNjydcwOuPpKspAk2I6nLseFQ9iuIIZKFU3QGUeKHT0yt+QzTsHU4mo8MrgwnG5I+JouXkPINAQ69VSi2xWooEt+pEKn0xoJTYKRf2skFZ1LdcEKDiR04uQiTqmKA4ZA2f0D7kPVAGceC4EbNDdlCbiaOCRC6wy4Dp2ChEjC3Dz+UUE+gVTDiMG8P/5wAFmENAm2OPQX0hbO4z09+/1NRX0YpBPTznrbUaDmiitMlwWSn3S9zYWPJJSIkCUeQ8OY8UKFRFuy345+lPQtBemrL2Ej+pnO0h81HDjZ2F+GyvUld5W5zkt2laRh8zwHciOa8X9nDsQSWeLZQ4T7j1Wtb2Nye8/M75mti2Gny+vVyZ6U8vT0mMzNzr2CrpbfKHCEU7kX7nNrMVmAglP06/VIfwWHyUwMyppSnTqCjhPVqA6FVI6cTKeaJLREy1zSiX+aUkt/uXuerFbc8DxJVp5+lICphDf05EWargugRhIJ53QpmJVRG/ekXm/33o0eH+fF8Lin8/Tcyr2Maz+iM0BBC6mg6JtF3vv98N4xJWJf2HftXgsNA2oQFw/x9WtMpTsgdM5sgFTCDeU127MaCJ0JNKYiflWKO6uzAM0ucEW7rIUBsx3cXJQdxlWTrFZYEgsbwirdrGgDzal5lUpD7O1tVJTlMnO0LL0Og+muGgUuu5TgjKnxOX9TjVF535FGU6ynuZnVcA06SNJVnIFgVBePYNEdmCmFheug0yWUnKM+cWrGQw5HQrPeFof4hIiypaqxPBNPu+a2tPeRK4wVm2GjhdNXS5GFriXcpT3aod8ZyXCZ5pOqnrvUWwkKY47oYpJcnO9LV69Qyks8kY6VpPp2ohusQhvqweiMGMP1tpkIczOl4JwoDhkim9yx0/7SEAJivfBwzNjkEQw2ZHBmOLmRRQK2/s4sB6syg43Ta6D8GITXT9FSklN8D5T6EnfpfvYe+ksM5uKyNXkLVJwh7C8QtoWazCIlqLbfDqsFbxmSttBG0faBr4L9nL1ktycMZEhpEUYc76jaa6XSG1U96ugs5+DKNB5ikuy0S35opQcON+xO0ZowhYQEdpgeqZTuMEpmRAv1prO4F2Ogg43+FAWytIh93wfpsJOy1uoEem8PStwzZ/6xxdBunTDJmdJOCeubJkvwZsNxJMKj6VdYNbOKfB9GMiHTOZxK5haw2K/DBUk6Fk9GeLHYK6DVsyVsTfBWEfYS1G+a4ayrxMdo1zObOY+ZLlKONXUK/bkVe8MXH0pQkDVCiOp0doZPcyCDz9VbOxiIwt1EV6yOu80YfWMmcIrWG3N4sGBhI3jf4d84IzZ9mxs2qUiEZi329NSPg+42C/fOo2z9GmaPkRxUuV+VMn8HskPG0BnfRfhiJs27iaXJGmmMPrzVx2J98pDeBJiYmoPCBb3EAtKhPQdvyxkWwz0VOBJOpFddKM6uH/80A/eymBqHH83abv/q2EVq/D7j39qstM7/If6TC1/DtX/g8QfndlGxExrtRRK+7WzcZePJeVbLvzwiJ5DlsI+BaEIFLVByX5yde64pgFFUhWPusF6mMIbXidMRpwocJQmctZFgDLWNDbyZLGW1rH9M7MDugbBzSOOEOIoblQmtqHAJl+FOAOYX27+AgpOvHHxZxPUdTM1smkT06t6PakjG5lzljNcoTVgX91Mm0CsdAiu/1D/6IqdrGmLhBIjs6ABZ3ByA2CbTo1iP/nZ1l8JIRfqltW9WrBibBUN8oIWSHQ0aeR19yzl2Sez9Fsu7A4uxfb5XEUHO6aoIWf1O1APvG9yenDeNYAHPml9PS45EhSA4W39deBYkwhgmukMw7RbKfKKPY3/XiBGDarRTfUw6b2fY/KtcaVa0VbzhTQBinNRdeadPIc8ucnt9xxZwNMA+6+URS4UyTZThKlxHnfqah3jlE7NvhKkqVgxFD3l+uUSsSPGzB3JJrvJF11ojSLyxT4OgQ1FOFy+93B/sF4AUn8LzVzTd21oYtz4nKDmDbLcjuR16uyv3HeK8EEvvs/UCPl2QmUukpjrQZ7gRodHfqph9FMq1alvrp/fsz890b92xjjY7nIekrK6VzUXrwiip0zzXwyGfc6PnlVRFaAozReoXRMGecC7yKFpKPZd3XkADpVKHJeFIVonLjjYZZw549+MzSvG60WTioSku2oJRLufhuToMvrM88nlrdjJppdVWMe94w/DQ/pIWbk2mPFIs62Qp4RlxnXoPK2SwfmPA4FS370riuk2xu7tUsDn066DC5PKJJt6+n5EUUay2JVPbyxLkghCyT2aXTJIQNCZjmNnKYGPBG+cqOW+kFFdTnYdTh0cAgQ6Yme801c+gqTU3v4IUOsS1vxz7eRl2O7NxJYeqa6r5mYhWU9joaxbcLw05tKrVSvOzzdq8Sb3erpcH56lMrw3IQTiB/kwZyRp1j5f44pU/P0weIAgCSZqcownR5yf7+2pN7WWKNlVuKDbWqIxbrbD5dYWDTVha/m9FERh8qjAnd5xsKQ9q2GkuqZa5NLHV8gG/Lk9lOPXOTojXzLQaYgka+QcwPTk2oS3Ud2oaY0e0hcQbBkmI0l7R7K11/hCIZx+5mzuUnD36qBUOXCzDJiOggGEqos5W/VvkWsTHDXhFWeglOH4GFJ+gMzCFFshbUrPPUVfTYOLIacnizU6OYl0f04TN4lX/PwZusCJYhPWL2gcMfX9nSJ1kLlV6Us2AeF+26KQOmIMp6mR+Lwl1OQ3ETuu2ZRDwbjsLUegzKiMUqXslQ2k7NL6/XmIa/APosFZBhGXdn66XUQkJwYSep1ch9R3YJwa6kvmuvKKv0pPckyXqpXVg/AwicPikckJMV1E6nh3gxS2GygM79lV52JWxVTeSEC/0Vg8nWVSDE3GDwYgugZE/Mtki1sX1blZx6DbuUWyHjd7X0Wg6HAnqnK6ZyyL69LbT0r8TZ8n0GVrv3NT43k60CMo5QgHaMKX5kCoss6CMnpd7aUtny9lNhMX9ousTBWbJTju+smQAEkeYMMKcJvTibGJ/twUNBBck+rMkdEH0OMXUhpmMXBqhMUPr0VxXWCRrE7DVN+9ph5eJx69NzvvxyLfk5wRaZ9G8AoQyNvFj/GsnUc0TS1bh1fdVl3E8K47mX0u8MDUNxYx0pvg+X+Tvy59aqIcpvrPjZ5KQG2OXOwE0mx1+V0Z0jL3UvfDUFWl8akiC/nEx0tVHOwP+d2elXxUEoWjiXVC3FadeJMd6uJZ+YfIzXAIjEYY9RIxDDFzAuXsv+9eLrej5/QdJPlOeVeVGLPJSQAE34AdVYTfdDbTZOkGIlJ0nMARE5JercDTMw872tDpHsLAAxWHhR8r6hlgOyldBZNwYeg0MItYjPk3uMrs+w5nQEtg3tAgfGhn/AZSXhDEZKAHdY6vpjG1p2mshMPVVJ73LBZPFzcQn8/e5OFftbV2SFrMrW8pGn9bZ2k5Qid8D7fHpVEwUxb+x6G7aOaSZW+AdQkat+wn0CkmRQy+BFDHllSKXToEHBMETV2viLx+puxhcHfvq2LPrMEPBmY0gybMxVJQc7CSERAonRY6oSYqARL5Hgkk4pdx85YGe/uzVm47PTVaWnsjvc9ZgR5tMUZ6V5hLMIZhCZrRst1ejAhP7QnRV8eKhkuGvr9ou5cw13orITWCsy1IGpziy28End63nsjpYWzGnuxBSKaZFsbCzlBT0z4zGCoXMd3KtGaN+m5MJlxxn123Jubg9qk2ExMAAAAA"></a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/blangry/status/442290420937392128" aria-label="3 likes" class="social-embed-meta">❤️ 3</a><a href="https://twitter.com/blangry/status/442290420937392128" aria-label="1 replies" class="social-embed-meta">💬 1</a><a href="https://twitter.com/blangry/status/442290420937392128"><time datetime="2014-03-08T13:27:08.000Z">13:27 - Sat 08 March 2014</time></a></footer></blockquote>

<p>I spent the last 18 months helping fix that. The vast majority of .gov.uk sites use HTTPS by default, there are effective policies which stop the worst attacks, and there's continual monitoring in place to detect when things go wrong. The brilliant team at Securing Government Services toil tirelessly to keep everyone in the UK safe. It was a joy and an honour to work with them.</p>

<p>Of course, there are some things which didn't go as planned.</p>

<h2 id="regrets"><a href="https://shkspr.mobi/blog/2023/08/weeknotes-fin-so-what-did-i-accomplish/#regrets">Regrets?</a></h2>

<p>Perhaps I should have agitated harder for there to be an Open Source Program Office. When the Head of Open Source left GDS, there was no one to replace her. I tried getting Government funding for the various OSS projects we use - but there are so many complications around funding non-tangible projects. And, anecdotally, some OSS projects didn't <em>want</em> to receive money from Government. If it had been my full time job, I might have made a dent in it. Alas, it fell by the wayside.</p>

<p>I know it sounds stupid, but I found no adequate way to stem the tide of PDFs being uploaded to GOV.UK.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2023/08/pdf-fs8.png" alt="Tree diagram showing 233,220 PDFs on the website." width="1024" height="1024" class="aligncenter size-full wp-image-46077">
I'd present to people, they'd agree it was a problem, and then nothing would happen. I discussed whether we could just ban departments from uploading them (no), put big warnings on the site discouraging use (maybe), or tell directors that their departments were breaking the rules (yes) - but it didn't make much of a difference. Everyone agrees that PDFs are inaccessible and don't work properly on mobile. But publishers <em>love</em> a fixed layout. So they stay.</p>

<p>It was a similar story with Open Document Format. Over the years, the number of Word Doc and XLSX files diminished. But ODT and ODS uploads never really took off. Partly it was a lack of tooling and partly a lack of native viewers on operating systems. Plain CSV had a resurgence though, which was nice.</p>

<p>I think both of my failures were due to my ideology not accounting for either inertia or fear of change. Sure, I was hampered by Microsoft's defaults and Apple's lack of filetype support - but the major problem was that I never found an adequate way to reassure people that change was necessary <em>and safe</em>.</p>

<p>And the less said about the PAF the better. I tried, I really did!</p>

<p>As I look back, I think the good outweighs the bad. Could I have stormed the Prime Minister's office and screamed at them until they installed Linux on every desktop in Government? No. And even if I had, it wouldn't have made a difference. Civil Servants advise and Ministers decide. That's the maxim. I pushed the agenda of open technology <em>because that's what I was hired to do.</em></p>

<p>It would have been impossible for me to have internally lobbied for <a href="https://www.tomscott.com/law/">letting people handle salmon suspiciously</a> - or whatever. I got involved in a wide range of discussions where I thought my expertise could help (none salmon related) and did my best.</p>

<h2 id="why-leave"><a href="https://shkspr.mobi/blog/2023/08/weeknotes-fin-so-what-did-i-accomplish/#why-leave">Why leave?</a></h2>

<p>7 years is a long time. I went from GDS to NHSX to the Data Standards Authority to CDDO. Each was a new adventure. But each was capped with two unfortunate problems.</p>

<p>The first is that there is no promotion available for people who don't want to line manage teams. I was a subject matter expert at Grade 7. If I wanted to move up to G6, I'd have spent a substantial portion of my time working on clerical, pastoral, and managerial duties. I don't enjoy that - and I'm not very good at it.  People deserve a line manager who is interested in management.  That's not me.  Expertise is valued in the CS - but generalists are needed at the higher levels. I get that - but it puts a career limitation on anyone who does want to specialise.</p>

<p>The second is related; pay. I know it isn't the done thing in polite society to complain publicly about money - but that's a taboo which needs breaking. When I started at the Civil Service I knew that the pay wasn't high but the benefits were great. But every year I received a below-inflation pay rise. I asked various managers if exceeding all my targets would get me a pay rise - but the answer was no. Not their fault - the system is inflexible.  With the cost of living rising, I just couldn't justify working somewhere which couldn't pay me fairly - no matter how much I enjoyed the team or the mission.</p>

<p>I want to do interesting work. And I need to be paid fairly for it.</p>

<h2 id="and-next"><a href="https://shkspr.mobi/blog/2023/08/weeknotes-fin-so-what-did-i-accomplish/#and-next">And next?</a></h2>

<p>Well, my friends, stay tuned. The next season of The Terence Eden Adventures is going to be... <em>interesting!</em></p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=45868&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2023/08/weeknotes-fin-so-what-did-i-accomplish/feed/</wfw:commentRss>
			<slash:comments>13</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Recreating an old UK Government Coat of Arms]]></title>
		<link>https://shkspr.mobi/blog/2019/03/recreating-an-old-uk-government-coat-of-arms/</link>
					<comments>https://shkspr.mobi/blog/2019/03/recreating-an-old-uk-government-coat-of-arms/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sat, 23 Mar 2019 11:38:50 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[logo]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=31762</guid>

					<description><![CDATA[When the NHS was launched in 1948, this leaflet was sent out to everyone.  I wanted to recreate the coat of arms that was on top to print on a t-shirt.  Sadly, the scan available is too low a resolution for most modern purposes.  Wikipedia has vector logos of most of the coats of arms - but not this one.  In desperation, I emailed the College of Arms.  They sent me back the most delightful LMGTFY …]]></description>
										<content:encoded><![CDATA[<p>When the NHS was launched in 1948, <a href="https://warwick.ac.uk/services/library/mrc/explorefurther/digital/health/nhs/">this leaflet</a> was sent out to everyone.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/03/New-NHS.jpg" alt="Yellowing and decaying leaflet talking about the new National Health Service." width="420" height="679" class="aligncenter size-full wp-image-31770">
I wanted to recreate the coat of arms that was on top to <a href="https://shkspr.mobi/blog/2019/03/govgeeks-t-shirts/">print on a t-shirt</a>.</p>

<p>Sadly, the scan available is too low a resolution for most modern purposes.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/03/New-NHS-Logo.jpg" alt="An ink-smeared logo." width="355" height="355" class="aligncenter size-full wp-image-31771">
<a href="https://en.wikipedia.org/wiki/Royal_coat_of_arms_of_the_United_Kingdom">Wikipedia has vector logos of most of the coats of arms</a> - but not this one.</p>

<p>In desperation, I emailed <a href="https://www.college-of-arms.gov.uk/">the College of Arms</a>.  They sent me back the most <em>delightful</em> <abbr title="Let me Google That For You">LMGTFY</abbr> I've ever received.</p>

<blockquote><p>Thank you for your e-mail which Rouge Croix Pursuivant has received as Officer in Waiting for the week.</p>

<p>The Royal Arms you sent depict the Crown as used by Kings George V and VI.  In 1953, The Queen chose to use St Edward’s Crown (which has a dip beneath the orb on the top, as opposed to having a semi-circular top).</p>

<p>Government Departments use the Royal Arms without the Crest (the lion on top of the crown).  If you google “British government coat of arms” - images, you will see what various departments are using, either the open line drawing shown under “commons.wikimedia”(line one far right) or the more stylised black versions (as used by the FCO) which may reproduce better when photoreduced to a tiny size.</p>

<p>Nothing here is digitised, the College never having been publicly funded.  If another Department cannot supply you with a high quality version, I can either send you a new drawing or scan in a previous one.  In either case, I will have to charge for it – hence my advice on self-help above!</p></blockquote>

<p>Using a <a href="https://shkspr.mobi/blog/2018/04/tools-to-defeat-fake-news-reverse-image-search/">reverse image search</a>, I discovered a <a href="https://www.alamy.com/british-museum-annual-report-of-the-general-progress-of-the-museum-for-official-use-british-museum-amp-british-museum-natural-history-annual-report-of-the-general-progress-of-the-museums-for-the-year-1935-with-a-return-of-the-number-of-persons-admitted-to-the-museums-and-a-statement-of-the-principal-objects-added-to-the-collection-crown-copyright-reserved-london-published-by-his-majestys-stationery-office-to-be-purchased-directly-from-hm-stationery-office-at-the-following-addresses-adastral-house-kingsway-london-wc2-120-george-street-edinburgh-2-j-york-street-manchester-image234251298.html?mid=41152&amp;siteID=MRu_ISar6sQ-6_42FOgcPfgFoqiaD_LaZQ&amp;utm_source=LS&amp;utm_medium=affiliate&amp;utm_content=US">stock photo site</a> had a copy.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/03/RH31WP.jpg" alt="A lion and a unicorn covered with a watermark." width="1300" height="1221" class="aligncenter size-full wp-image-31764">

<p>Annoyingly, they've slapped a watermark over it and seem to be claiming copyright.  Which is nonsense as the same image is <a href="https://www.flickr.com/photos/internetarchivebookimages/20409728022/">freely available from The Internet Archive on Flickr</a>!  It's from the British Museum's Annual Report of <strong>1925</strong>!</p>

<p><img src="https://shkspr.mobi/blog/wp-content/uploads/2019/03/20409728022_fea72dabf1_o.jpg" alt="A lion and a unicorn." width="832" height="724" class="aligncenter size-full wp-image-31763">
There are <a href="https://www.flickr.com/search/?tags=bookidbritishmuseumann25brit">several version of this image available</a></p>

<p>With a little bit of editing, I turned it into a black-and-white version, which has cleaned up pretty well.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/03/crestbwdespeckled.png" alt="A nicely sharpened image of the coat of arms." width="832" height="724" class="aligncenter size-full wp-image-31765"></p>

<p>That's... <em>OK</em>. Not brilliant. Just fine. Even with better scans, there's a limit to what can be recovered from a 100 year old print.</p>

<p>I thought about trying to recreate it using the Wikipedia vector version as a template:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/03/585px-Royal_Coat_of_Arms_of_the_United_Kingdom_HM_Government.svg_.png" alt="A colourful and detailed coat of arms." width="585" height="480" class="aligncenter size-full wp-image-31773"></p>

<p>But there are some challenges:</p>

<ul>
<li>The "Honi soit qui mal y pense" is in lower case on the 1925 version.</li>
<li>The lion's tail is significantly different.</li>
<li>The crowns are a different style.</li>
<li>The "Dieu et mon droit" are laid out differently.</li>
</ul>

<p>So I think I'll just stick with my cleaned up version. If you think you can do better - or if you have a higher quality scan - please drop a note in the comments box.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=31762&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/03/recreating-an-old-uk-government-coat-of-arms/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[When GOVUK is NSFW]]></title>
		<link>https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/</link>
					<comments>https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/#respond</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Tue, 15 Dec 2015 12:11:50 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Unsecured State]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=22119</guid>

					<description><![CDATA[I don&#039;t particularly like picking on the security of Government websites.  I do it a lot - but I always feel guilty about besmirching the good name of the many talented people who work in the Civil Service.  Today&#039;s flaw, however, is a particularly basic mistake which simply shouldn&#039;t be allowed to happen by any competent site owner.  What Is An Open Redirect?  A redirector is a small web service …]]></description>
										<content:encoded><![CDATA[<p>I don't particularly like picking on the security of Government websites.  <a href="https://shkspr.mobi/blog/tag/unsecured-state/">I do it a lot</a> - but I always feel guilty about besmirching the good name of the many talented people who work in the Civil Service.</p>

<p>Today's flaw, however, is a particularly basic mistake which simply shouldn't be allowed to happen by any competent site owner.</p>

<h2 id="what-is-an-open-redirect"><a href="https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/#what-is-an-open-redirect">What Is An Open Redirect?</a></h2>

<p>A redirector is a small web service which takes the user to a new web page.  It's a simple enough concept - if you visit:
<code>http://www.planningportal.gov.uk/PpWeb/jsp/redirect.jsp?url=http://bbc.co.uk</code></p>

<p>you'll be taken to the BBC's homepage.  It's an older technique which allows a website to track which external links you clicked on.</p>

<p>Unfortunately, <a href="https://www.owasp.org/index.php/Unvalidated_Redirects_and_Forwards_Cheat_Sheet">this can be abused</a>.  Spammers can use links like:
<code>http://GoodSite.com/?url=BadSite.com</code> to trick people into visiting illegitimate web pages.</p>

<p>When those links are used in an email, it can help bypass spam filters.  The presence of a .gov.uk domain adds the appearance of legitimacy to any phishing attempt.</p>

<p>Abuse of Open Redirects is perfect for phishing, spamming, trolling, and all manner of digital nastiness.</p>

<h2 id="what-does-it-look-like"><a href="https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/#what-does-it-look-like">What Does It Look Like?</a></h2>

<p>Here's the NSFW portion of the blog.  Google crawls the web - and your emails - looking for links.  When it finds them, it adds them to its search index.  We can ask Google to give us all the results for the word <code>X</code> on website <code>Y</code> by performing a search for <code>"X site:Y"</code>.</p>

<p>This lets us see all the times a UK Government site has been used to spew spam.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2015/12/gov-open-redirect-fs8.png" alt="Page of Google results showing pornographic links on a UK Government pages" width="960" height="989" class="aligncenter size-full wp-image-22120"></p>

<p>As a guess, the spammers have abused the open redirect and pasted those links on forums, in comments, and social media.  Google dutifully follows and indexes them.</p>

<p>PlanningPortal.gov.uk is the only UK Government site which I could find which has this vulnerability.  The US Government has vastly more sites with this particular problem - many of which seem to link to deeply disturbing content.</p>

<h2 id="how-to-stop-such-wickedness"><a href="https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/#how-to-stop-such-wickedness">How to stop such wickedness?</a></h2>

<p>There's an easy way, a hard way, and a pragmatic way to prevent this sort of vulnerability.</p>

<p>The easy way is - <strong>don't use a redirect service</strong>.  If you want to link to an external website, just use a normal link.  There really is limited use for them these days.  Tracking can be accomplished by JavaScript analytics libraries without hijacking your user's browser.</p>

<p>The hard way is - create a whitelist of sites which can be linked through your redirect service.  This is difficult because someone has to constantly maintain exactly which links are allowed through.  You also have to manage which links are broken or are no longer acceptable.</p>

<p>If you absolutely <em>need</em> an open redirect and don't have the staffing levels to manage it, the pragmatic solution is this:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2015/12/Minnesota-Redirect-fs8.png" alt="You clicked an external URL. If you proceed, you will leave the Federal Exective Board of Minnesota's website." width="766" height="456" class="aligncenter size-full wp-image-22125"></p>

<h2 id="final-thoughts"><a href="https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/#final-thoughts">Final Thoughts</a></h2>

<p>This isn't a new or innovative attack - <a href="http://googlewebmastercentral.blogspot.co.uk/2009/01/open-redirect-urls-is-your-site-being.html">Google have been warning about this vulnerability <strong>for the last 7 years</strong></a>!</p>

<p>Websites need constant care and maintenance against an evolving threat landscape.  If a site contains such basic errors, I think it's reasonable to suspect that it is probably dangerously broken in other ways.</p>

<p>The UK Government should be holding GOV.UK website managers to a higher standard than this.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=22119&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2015/12/when-govuk-is-nsfw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[A Complete List of Every UK Government Domain Name]]></title>
		<link>https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/</link>
					<comments>https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Tue, 10 Nov 2015 08:29:12 +0000</pubDate>
				<category><![CDATA[politics]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[NaBloPoMo]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=21509</guid>

					<description><![CDATA[Eight years after I published this blog post, I helped officially release all these domain names as open data! Funny how life works out, eh?  Would you like to know every domain name the UK Government had registered?  Of course you would!  There could be all sorts of interesting tit-bits hidden in there (ProtectAndSurvive.gov.uk? EbolaOutbreak2017.nhs.uk? MinistryOfTruth.police.uk?)  Rather than…]]></description>
										<content:encoded><![CDATA[<p><ins datetime="2023-10-07T12:46:30+00:00">Eight years after I published this blog post, I helped <a href="https://www.gov.uk/government/publications/list-of-gov-uk-domain-names">officially release all these domain names as open data</a>! Funny how life works out, eh?</ins></p>

<p>Would you like to know every domain name the UK Government had registered?  Of course you would!  There could be all sorts of interesting tit-bits hidden in there (ProtectAndSurvive.gov.uk? EbolaOutbreak2017.nhs.uk? MinistryOfTruth.police.uk?)</p>

<p>Rather than relying on Freedom of Information requests, or <a href="https://www.gov.uk/government/publications/list-of-gov-uk-domain-names">Open Data</a>, we can go straight to the source of domain names - the DNS!</p>

<h2 id="shut-up-and-give-me-the-codez"><a href="https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#shut-up-and-give-me-the-codez">Shut Up And Give Me The Codez!</a></h2>

<p><a href="https://shkspr.mobi/blog/wp-content/uploads/2015/11/Gov-UK-Domains.zip">Download all UK Government host names</a>
.gov.uk 15,436 records
.nhs.uk  4,877 records
.police.uk 466 records
.mod.uk 268 records
.parliament.uk 91 records</p>

<p>That's... quite a lot!  The majority are <a href="https://en.wikipedia.org/wiki/Hostname">host names</a> - only around 2,247 of the GOV.UK ones are domain names.  Many of them are not currently live.</p>

<p>Still, I wonder how many are new?</p>

<blockquote class="social-embed" id="social-embed-663708175590416384" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/lesteph" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRsYBAABXRUJQVlA4ILoBAADQCQCdASowADAAPrVMnUunJCKhrjQMyOAWiWYAsR+OiVAre5jsXlmHVVrY37gUHwdb2KlWikZgQjgnP/h2ugx+dp/AssS7sjQGvf6OQabVcKU/pT1BoAAA/vcT36pUF88qZCAv/gdHfqJ+MALpBWGjCNlNOk8nEMr22fT7FJdfI0SLWXL3RbbT1xSQhcG6SYhN54mZIcUuoK0haX0gmp/+IB5/Azef5kwXnDQV3mcxi7IzGwweo41KF878n+oC4G4cUeAM6sgDQqWfTX0Yskv9Q8XSNvGWC6pW+63eqJih5qMNv7+mn9q6VwQl65eeympv/ehRxSoD3JQl//oQwocDoAUvWxNmmALfzRGDieJTzdS1+FLWqNdGcVd8usKH8Uz88q7YL241f920zgAILCjQsIytZPAO6YAIZ2JP/YXNmKtqpkkkm59KitwQXQ2TR9+TLcwHvFFkNuJ/D3+UOLqNoAB3f42iLhuktMoL8WeD03eGGeWVhmmfXEvSFCI0rTci02CKeDyhftB/XRCbOOx+1AIJ2w16bxEappEDz45EI50aYu+vNLOXnarmGDP9eZuoMAT+2ha01AAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Steph Gray</p>@lesteph</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Not intended snarkily, but has web rationalisation/no new govt domains been formally abandoned as a policy now?</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/lesteph/status/663708175590416384"><span aria-label="0 likes" class="social-embed-meta">❤️ 0</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2015-11-09T13:22:14.000Z" itemprop="datePublished">13:22 - Mon 09 November 2015</time></a></footer></blockquote>

<blockquote class="social-embed" id="social-embed-663709264842764288" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><blockquote class="social-embed" id="social-embed-663708470949093377" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/lesteph" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRsYBAABXRUJQVlA4ILoBAADQCQCdASowADAAPrVMnUunJCKhrjQMyOAWiWYAsR+OiVAre5jsXlmHVVrY37gUHwdb2KlWikZgQjgnP/h2ugx+dp/AssS7sjQGvf6OQabVcKU/pT1BoAAA/vcT36pUF88qZCAv/gdHfqJ+MALpBWGjCNlNOk8nEMr22fT7FJdfI0SLWXL3RbbT1xSQhcG6SYhN54mZIcUuoK0haX0gmp/+IB5/Azef5kwXnDQV3mcxi7IzGwweo41KF878n+oC4G4cUeAM6sgDQqWfTX0Yskv9Q8XSNvGWC6pW+63eqJih5qMNv7+mn9q6VwQl65eeympv/ehRxSoD3JQl//oQwocDoAUvWxNmmALfzRGDieJTzdS1+FLWqNdGcVd8usKH8Uz88q7YL241f920zgAILCjQsIytZPAO6YAIZ2JP/YXNmKtqpkkkm59KitwQXQ2TR9+TLcwHvFFkNuJ/D3+UOLqNoAB3f42iLhuktMoL8WeD03eGGeWVhmmfXEvSFCI0rTci02CKeDyhftB/XRCbOOx+1AIJ2w16bxEappEDz45EI50aYu+vNLOXnarmGDP9eZuoMAT+2ha01AAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Steph Gray</p>@lesteph</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/charlottejee/status/663708325570301952">Replying to @charlottejee</a></small><a href="https://twitter.com/charlottejee">@charlottejee</a> stuff like <a href="http://exportingisgreat.gov.uk">exportingisgreat.gov.uk</a>, <a href="http://workplacepensions.gov.uk">workplacepensions.gov.uk</a> etc</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/lesteph/status/663708470949093377"><span aria-label="0 likes" class="social-embed-meta">❤️ 0</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2015-11-09T13:23:25.000Z" itemprop="datePublished">13:23 - Mon 09 November 2015</time></a></footer></blockquote><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/charlottejee" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRuACAABXRUJQVlA4INQCAACwDACdASowADAAPrVEnEmnI6KhLjv8yOAWiUAVyeP/R7WY7lt/tSvDqJU30ZSvADSoTQ/JR51PMtb9LZzKFwgI+31r4Vt5D8YVBw0Mq/rpCEGij9lEhGulR77wjOIdYpylS+BrK/RoFhvTOIbpAAD+/v/rUufqspnjwGuje4xCf0sHDEe9PEFE24qrKdO/PSuGLPPfXuL96khkdzEXXH/i0Jty4aQRb66+eKShf2dot7VsavPLwwn9naLe1bGD81DnN31cqqkiK8c7WvqzthjcDc9Lc+iFoWo4SPelx3Nfsh3IBZLKTAyTh0d8iGAz8Z3XAOB4aEtdGpyG0q19OGUwHY2MJI4ETZlS3nPTehXzmiP2GK+ZtSfSCT6w+4VU1X0JPfCtswP3rQSqWIwQheY2SYa+aQdsIT+RxQm12exO+f3zMR8RCbaZPpU8G/V5r6lLKM6EKJ7Ms1SrSvGrOhSX/fbZ3DjkpeE1/9G/6a2Kxt1b9wwCQbj/thetTHi/0aGcSADTnYxsmu4U+pMSnpE0VB7rOm4Be5XnxLXg8c3Z3YNssbN+skc0lCu2HweO6EyU4O9FDY7pH5+mVteUYqdP4X26dDhf/WUz0/bF7YT7PEbIJTVn0u7Xu3P7ckOILPfyLXihvtolrcTl5bz6c9iTX/rAsIuHSSlcP5i3PaFjTZyAWe9B9fEFkY42sL85FnTJtH0JwQTMNI/nH/42eqCJQGe3vLePZcjcpvqR25mkPPacNPNVnTEUfjk4+n8Z6WjOFverCM7jNGmKbvJl4ajYGp7MtAeGXpN//W+GJ8j3bvhf8casVpz52+jub/y06az1lmnCx0Q91ZdVGnstTxhSHygTdqD1QiNl3EQp0ovgRsXKAYzDf5UfHX9fWtEt6b7Rcd7cftfDOhsBG3R/hUUb7PTWS9aTKhWwQ6p9ZL8T9jOl5pg8jWGzR6I84aT8UC6KpQAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Charlotte Jee</p>@charlottejee</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/lesteph/status/663708470949093377">Replying to @lesteph</a></small><a href="https://twitter.com/lesteph">@lesteph</a> This seems to say new domains need approval rather than that they aren't allowed: <a href="https://www.gov.uk/government/publications/naming-and-registering-government-websites/central-government-naming-and-registering-websites">gov.uk/government/pub…</a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/charlottejee/status/663709264842764288"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2015-11-09T13:26:34.000Z" itemprop="datePublished">13:26 - Mon 09 November 2015</time></a></footer></blockquote>

<p>The Gov.UK file is a CSV which also show when the domain was first registered (if available).</p>

<h2 id="geeky-details"><a href="https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#geeky-details">Geeky Details</a></h2>

<p>The Domain Name System (DNS) lists every single domain name (example.com).  It tells your computer which IP Address is associated with a Domain Name.  If your local DNS doesn't know where example.gov.uk lives, it goes to the ISP's DNS.  If they don't know, they ask an upstream provider's DNS.  And so on, until someone asks the .gov.uk nameserver for an authoritative response.</p>

<p>So, <a href="http://jordan-wright.com/blog/2015/09/30/how-to-download-a-list-of-all-registered-domain-names/">can you download every domain name in existence</a>?  No, not easily.  It usually involves filling out lots of forms and giving some compelling reason why you want it.</p>

<p>However, <a href="https://scans.io/">Rapid7's sonar project</a> provides a sort of "best guess" for all the domain names which it can see.</p>

<p>To download the <a href="https://opendata.rapid7.com/"><em>entire</em> file is 12GB</a>.  That's the zipped version.</p>

<p>Once unzipped, it's a <strong>whopping 67GB</strong></p>

<p>A quick look at the file shows it contains 1,408,097,159 records.  Youch!  That's a lot of domain names!</p>

<p>This is what the file looks like</p>

<pre>$ head 20150926_dnsrecords_all
cshengmei.com.h310.6dns.net,a,103.225.196.101
reseauocoz.cluster007.ovh.net,cname,cluster007.ovh.net
cse-web-cl.comunique-se.com.br,a,200.166.77.69
ext-cust.squarespace.com,a,198.185.159.176
ext-cust.squarespace.com,a,198.185.159.177
ext-cust.squarespace.com,a,198.49.23.176
ext-cust.squarespace.com,a,198.49.23.177
ghs.googlehosted.com,cname,googlehosted.l.googleusercontent.com
isutility.web9.hubspot.com,cname,a1049.b.akamai.net
sendv54sxu8f12g.ihance.net,a,54.241.8.193
sites.smarsh.io,a,199.47.168.63
www.triblocal.com.s3-website-us-east-1.amazonaws.com,cname,s3-website-us-east-1.amazonaws.com
*.01ete21.cn.cname.yunjiasu-cdn.net,a,162.159.210.34
*.01ete21.cn.cname.yunjiasu-cdn.net,a,162.159.211.34</pre>

<p>As a brief primer, a <a href="https://en.wikipedia.org/wiki/CNAME_record">CNAME</a> points to another domain name.  An <a href="https://en.wikipedia.org/wiki/List_of_DNS_record_types#A">A Record</a> points to an IP address.  There are <a href="https://en.wikipedia.org/wiki/List_of_DNS_record_types">lots of different domain records</a>.</p>

<p>Ok, so let's get all the *.gov.uk records out of there...</p>

<pre>grep "gov\.uk" 20150926_dnsrecords_all
0-19insalford.info,soa,ns0.ictservices.co.uk postmaster.salford.gov.uk 2010022204 28800 7200 604800 86400
019186.gov.ukpfl.cn,a,122.9.230.117
100days.local.gov.uk,a,198.154.241.231
101.gov.uk,a,216.146.46.10
101.gov.uk,a,216.146.46.11
101.gov.uk,mx,20 sms2.101.gov.uk
101.gov.uk,ns,ns1.p08.dynect.net</pre>

<p>Ah! Ok, we're picking up some websites which are <em>pointing</em> to a gov.uk site (potentially useful) and some false positives like "019186.gov.ukpfl.cn".  Let's just look at records where the first column ends with .gov.uk":</p>

<pre>grep "\.gov\.uk," 20150926_dnsrecords_all
100days.local.gov.uk,a,198.154.241.231
101.gov.uk,a,216.146.46.10
101.gov.uk,a,216.146.46.11
101.gov.uk,mx,20 sms2.101.gov.uk
101.gov.uk,ns,ns1.p08.dynect.net
101.gov.uk,ns,ns2.p08.dynect.net
101.gov.uk,ns,ns3.p08.dynect.net
101.gov.uk,soa,ns1.p08.dynect.net hostmaster.cscdns.net 2014121100 3600 600 604800 1800
1901redirect.nationalarchives.gov.uk,a,193.132.104.151
1sttouch.powys.gov.uk,a,212.219.229.79
1t6c3c0p2r0m934.forestry.gov.uk,a,212.38.180.45
2011.census.gov.uk,a,94.126.106.132
2014.colneyheathparishcouncil.gov.uk,a,81.27.85.11
2050-calculator-tool-wiki.decc.gov.uk,cname,wiki.2050.org.uk</pre>

<p>OK, so how do we de-duplicate these?  The first thing to do is manipulate the data.  We only want the first column.  There are an number of ways to do this in Linux, I prefer to use the <a href="http://codeinthehole.com/writing/csvfilter-a-python-command-line-tool-for-manipulating-csv-data/">Python tool CSVfilter</a>.</p>

<p>To install <code>sudo pip install csvfilter</code>.</p>

<p>To grab only the first (zeroth) column <br><code>cat 20150926_dnsrecords_all | csvfilter -f 0 &gt; out.csv</code></p>

<p>Now, this doesn't quite work.  Why? Because <a href="http://www.viewdns.info/dnsrecord/?domain=0xf0f.com">some DNS records contain incredibly strange data</a>!  You can manually clean up the data, but that's a bit boring and utterly impossible to load into Excel or any other normal editor.</p>

<p>Here's what I did...</p>

<ol>
    <li>Copy all the lines containing gov.uk into a new file <br><code>grep "\.gov\.uk," 20150926_dnsrecords_all &gt; govuk.csv</code></li>
    <li>Create a new file with only the first column <br><code>cat govuk.csv | csvfilter -f 0 &gt; govuk0.csv</code></li>
    <li>Sort the file and make sure each line in unique <br><code>sort govuk0.csv | uniq &gt; govuk.txt</code></li>
</ol>

<p>Hey presto! A more-or-less complete list of every .gov.uk website which is registered.  The same can be performed for .NHS.uk, .police.uk, .MOD.uk etc.</p>

<h2 id="getting-the-dates"><a href="https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#getting-the-dates">Getting The Dates</a></h2>

<p>Time to crack out the Ruby!</p>

<p>Using the <a href="http://whoisrb.org/">WHOIS</a> library, I wrote a simple script to parse the text records and query when the domain name was created.</p>

<pre lang="ruby">#!/usr/bin/env ruby
require 'whois'

c = Whois::Client.new

File.open( "govuk.txt" ).each do |line|
   begin
      r = c.lookup(line.chomp)
      puts "#{line.chomp},#{r.created_on}"
   rescue Whois::Error =&gt; e
   rescue StandardError =&gt; e
   end
end
</pre>

<p>This isn't <em>perfect</em> - there are only records for the third level of gov.uk - and no records at all for Parliament, MOD, Police, and NHS.  It is also a bit slow to run through the thousands of records - but we can see a few interesting bits and bobs.</p>

<h3 id="created-in-2015"><a href="https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#created-in-2015">Created in 2015</a></h3>

<p>I suspect some of these are merely renewals, rather than brand new domains.</p>

<pre>seemis.gov.uk,2015-10-29 00:00:00 +0000
yjb.gov.uk,2015-10-28 00:00:00 +0000
crbonline.gov.uk,2015-10-23 00:00:00 +0100
coi.gov.uk,2015-10-14 00:00:00 +0100
gibraltar.gov.uk,2015-07-29 00:00:00 +0100
dorsetforyou.gov.uk,2015-03-19 00:00:00 +0000
ico.gov.uk,2015-03-19 00:00:00 +0000
bridgnorthtowncouncil.gov.uk,2015-01-29 00:00:00 +0000
</pre>

<h3 id="oldest"><a href="https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#oldest">Oldest</a></h3>

<pre>wdc.gov.uk,2003-06-03 00:00:00 +0100
west-dunbarton.gov.uk,2003-06-03 00:00:00 +0100
clacks.gov.uk,2003-06-02 00:00:00 +0100
bassetlaw.gov.uk,2003-04-29 00:00:00 +0100
dti.gov.uk,2003-03-13 00:00:00 +0000
</pre>

<p>Sadly, clacks.gov.uk has very little to do with <a href="http://www.theguardian.com/books/shortcuts/2015/mar/17/terry-pratchetts-name-lives-on-in-the-clacks-with-hidden-web-code">Terry Pratchett</a>!</p>

<h3 id="thats-all-folks"><a href="https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/#thats-all-folks">That's all folks!</a></h3>

<p>Spotted anything unusual? Found a better way to do things?  Stick a comment in the box!</p>

<hr>

<p>If you've enjoyed this post, you can <a href="http://www.amazon.co.uk/gp/registry/wishlist/13GFCFR2B2IX4?tag=shkspr-21">buy me something from my Amazon Wishlist</a>.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=21509&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2015/11/a-complete-list-of-every-uk-government-domain-name/feed/</wfw:commentRss>
			<slash:comments>5</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[How I Got The UK Government To Adopt ODF]]></title>
		<link>https://shkspr.mobi/blog/2014/07/how-i-got-the-uk-government-to-adopt-odf/</link>
					<comments>https://shkspr.mobi/blog/2014/07/how-i-got-the-uk-government-to-adopt-odf/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 23 Jul 2014 11:15:07 +0000</pubDate>
				<category><![CDATA[politics]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[open standards]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=10694</guid>

					<description><![CDATA[Well, it&#039;s not often I get to completely influence the UK Government&#039;s approach to open standard.  GOV.UK is adopting .ODF as their official document standard!  All documentation will be also made available in HTML &#38; PDF.  Sweet!  Yeah, yeah, so I only played a small part in the (no doubt) hideously complicated process - but I&#039;m happy to take full credit :-)  Last year, the UK Government opened…]]></description>
										<content:encoded><![CDATA[<p>Well, it's not often I get to completely influence the UK Government's approach to open standard.  <a href="https://gds.blog.gov.uk/2014/07/22/making-things-open-making-things-better/">GOV.UK is adopting .ODF</a> as their official document standard!  All documentation will be also made available in HTML &amp; PDF.  Sweet!</p>

<p>Yeah, yeah, so I only played a small part in the (no doubt) hideously complicated process - but I'm happy to take full credit :-)</p>

<p>Last year, the UK Government opened up a <a href="http://standards.data.gov.uk/">Standards Hub</a>.  They were actively soliciting for challenges that the UK Government could take on.</p>

<p>I was one of the first to respond.</p>

<blockquote class="social-embed" id="social-embed-384362507483500544" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/edent" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRkgBAABXRUJQVlA4IDwBAACQCACdASowADAAPrVQn0ynJCKiJyto4BaJaQAIIsx4Au9dhDqVA1i1RoRTO7nbdyy03nM5FhvV62goUj37tuxqpfpPeTBZvrJ78w0qAAD+/hVyFHvYXIrMCjny0z7wqsB9/QE08xls/AQdXJFX0adG9lISsm6kV96J5FINBFXzHwfzMCr4N6r3z5/Aa/wfEoVGX3H976she3jyS8RqJv7Jw7bOxoTSPlu4gNbfXYZ9TnbdQ0MNnMObyaRQLIu556jIj03zfJrVgqRM8GPwRoWb1M9AfzFe6Mtg13uEIqrTHmiuBpH+bTVB5EEQ3uby0C//XOAPJOFv4QV8RZDPQd517Khyba8Jlr97j2kIBJD9K3mbOHSHiQDasj6Y3forATbIg4QZHxWnCeqqMkVYfUAivuL0L/68mMnagAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Terence Eden is on Mastodon</p>@edent</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">My suggestion for open formats in government has been published - <a href="http://standards.data.gov.uk/challenge/offer-documents-multiple-open-formats">standards.data.gov.uk/challenge/offe…</a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/edent/status/384362507483500544"><span aria-label="2 likes" class="social-embed-meta">❤️ 2</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2013-09-29T17:02:17.000Z" itemprop="datePublished">17:02 - Sun 29 September 2013</time></a></footer></blockquote>

<p>You can <a href="http://standards.data.gov.uk/challenge/offer-documents-multiple-open-formats">read my modest proposal on the standards hub</a>.</p>

<p>The crux of my proposal was this:</p>

<blockquote><p>Each user - whether they work for the Government or are a citizen - has the right to read documents.

A user should not be expected to purchase new equipment or install new software, just in order to read an official document.</p></blockquote>

<p>I don't think that's too much to ask.  You may buy a computer every 6 months - but there are plenty of citizens who only have access to a Windows 95 PC.  Or a Nintendo Wii.  Or an eReader.  Or who don't have admin rights to install new software.</p>

<p>Many of these devices are perfectly serviceable - and <em>all</em> are guaranteed to read either PDF or HTML.  Open standards means zero extra cost for the citizen.</p>

<h2 id="next-steps"><a href="https://shkspr.mobi/blog/2014/07/how-i-got-the-uk-government-to-adopt-odf/#next-steps">Next Steps</a></h2>

<p>Based on my suggestion, two challenges were created:</p>

<ul><li><a href="http://standards.data.gov.uk/challenge/viewing-government-documents">Challenge: Viewing government documents</a></li>
<li><a href="http://standards.data.gov.uk/challenge/sharing-or-collaborating-government-documents"> Challenge: Sharing or collaborating with government documents</a></li>
</ul>

<p>After several months of wrangling, the Government announced a solution to both of these challenges - <a href="https://www.gov.uk/government/news/open-document-formats-selected-to-meet-user-needs">Open document formats selected to meet user needs</a>.</p>

<blockquote>When departments have adopted these open standards:

<ul>
<li>citizens, businesses and voluntary organisations will no longer need specialist software to open or work with government documents</li>
  <li>people working in government will be able to share and work with documents in the same format, reducing problems when they move between formats</li>
  <li>government organisations will be able to choose the most suitable and cost effective applications, knowing their documents will work for people inside and outside of government</li>
</ul>
<p>The <a href="https://www.gov.uk/government/publications/open-standards-for-government">selected standards</a>, which are compatible with commonly used document applications, are:</p>

<ul>
<li>PDF/A or HTML for viewing government documents</li>
  <li>Open Document Format (<abbr title="Open Document Format">ODF</abbr>) for sharing or collaborating on government documents</li>
</ul>

<cite><a href="https://www.gov.uk/government/news/open-document-formats-selected-to-meet-user-needs">     Cabinet Office and The Rt Hon Francis Maude MP </a></cite>
</blockquote>

<p>And, <strong>boom</strong>, just like that the open standard of ODF is mandated across government.  In the future, you won't have to buy Microsoft Office just to read or respond to a government document.  You won't need the latest and greatest computer, or cutting edge software.</p>

<p>Here's the thing. I don't know what would have happened if I hadn't made my initial contribution.  Perhaps someone else would have.  The tide is turning away from the proprietary standards of the past and Governments around the world are embracing Open Standards.</p>

<p>But I did contribute.  I did make my voice heard.  And the world has changed a little bit for the better.</p>

<p>And now it's up to you.  Find a <a href="http://standards.data.gov.uk/">challenge on the Government's website</a>, contribute, engage, make <em>your</em> voice heard,</p>

<hr>

<p>Huge thanks to <a href="https://gds.blog.gov.uk/author/hadley-beeman/">Hadley Beeman</a> for telling me about the Open Standards Challenge, and to <a href="https://mojdigital.blog.gov.uk/author/tracey-williams/">Tracey Williams</a> for keeping me informed of its progress.  Much of real credit for this amazing achievement belongs to <a href="https://gds.blog.gov.uk/author/linda-humphries/">Linda Humphries</a> for running the consultation, and to <a href="https://www.gov.uk/government/people/francis-maude">The Rt Hon Francis Maude MP</a> for listening to such wise counsel.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=10694&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/07/how-i-got-the-uk-government-to-adopt-odf/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[The Unsecured State Part 5 - Abandoned Inquiries]]></title>
		<link>https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/</link>
					<comments>https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Fri, 07 Mar 2014 12:03:24 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Unsecured State]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=9848</guid>

					<description><![CDATA[This is part 5 of a series of blog posts looking at the security of the UK Government&#039;s web infrastructure.    The primary cause of the vulnerabilities I&#039;ve exposed over this series is abandonment.  In a flurry of excitement a website is commissioned and created.  Then, as time wears on, people begin to drift away from the project.  Job titles change, people are reshuffled, and senior…]]></description>
										<content:encoded><![CDATA[<p>This is part 5 of a <a href="https://shkspr.mobi/blog/tag/unsecured-state/">series of blog posts</a> looking at the security of the UK Government's web infrastructure.</p>

<hr>

<p>The primary cause of the vulnerabilities I've exposed over this series is <strong>abandonment</strong>.</p>

<p>In a flurry of excitement a website is commissioned and created.  Then, as time wears on, people begin to drift away from the project.  Job titles change, people are reshuffled, and senior management's gaze focuses elsewhere.</p>

<p>Who is now responsible for updating and maintaining the software?  No one.  Like an unwanted puppy, it has been abandoned on the street and proceeds to pick up all manner of diseases in its malnourished state.</p>

<p>So we move on to the tragic fate of the abandoned Public Inquiry website.  Long after "lessons have been learned" these sites stand in monument to the vast human undertaking required to make sense of a tragedy.</p>

<p>Not so much.</p>

<h2 id="leveson"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#leveson">Leveson</a></h2>

<p>The <a href="http://www.levesoninquiry.org.uk/">Leveson Inquiry</a> last updated its website in November 2012.
<a href="http://www.levesoninquiry.org.uk/"><img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Lord-Justice-Leveson.jpg" width="262" height="194" class="alignleft"></a>
Since then, it has been left to rot.  Much like the Noble Lord's proposals on regulating Britain's feral media.</p>

<ul>
    <li>The <a href="https://web.archive.org/web/20121104135114/https://www.levesoninquiry.org.uk/wp-login.php">admin page is freely available</a> - although "protected" by an expired SSL certificate.</li>
    <li>The <a href="http://www.levesoninquiry.org.uk/?page_id=3954&amp;s=Blair">search functionality is broken</a>.  Reducing its usefulness.</li>
    <li>The outdated WordPress 3.7.1 powers the site.</li>
</ul>

<p>That's fairly mild.  As weeks turn into years, we can expect the site to decay further.</p>

<p>What about Inquiries which ended many years ago?  The <a href="https://web.archive.org/web/20140409154253/https://www.nationalarchives.gov.uk/webarchive/public-inquiries-inquests.htm">National Archives maintains a list of all previous inquiries</a> and an archive of their original websites.</p>

<p>Taking a look through some of the more high profile site reveals a very sorry state.</p>

<h2 id="victoria-climbie"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#victoria-climbie">Victoria Climbié</a></h2>

<p><a href="https://en.wikipedia.org/wiki/Murder_of_Victoria_Climbi%C3%A9">Victoria Climbié was tortured and murdered by her guardians</a>.  The <a href="https://www.gov.uk/government/publications/the-victoria-climbie-inquiry-report-of-an-inquiry-by-lord-laming">public inquiry</a>, headed by Lord Laming, had a hugely positive effect on the way child protection works in the UK.</p>

<p>The <a href="https://www.gov.uk/government/publications/the-victoria-climbie-inquiry-report-of-an-inquiry-by-lord-laming">official report</a> - along with hundreds of news sites - still link to this long abandoned site.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Climbie-Report-fs8.png" alt="Climbie Report-fs8" width="571" height="117" class="aligncenter size-full wp-image-10174">

<p>Rather than keeping the website running, keeping all the documents in public view, the domain was allowed to lapse.</p>

<p>Where upon a "<a href="https://twitter.com/BenedictSykes">Mr Benedict Sykes</a>" bought the domain, and it became stuffed full of barely related keywords and adverts.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Climbie-Spam-fs8.png" alt="Climbie Spam" width="720" height="417" class="aligncenter size-full wp-image-9923">

<p>Benedict is a "<a href="http://uk.linkedin.com/in/bensykes">creative, innovative and extremely credible Online Marketing Manager</a>".</p>

<p>I'm not sure how credible it is to take a report into a murdered child and then use it to sell links to investment guides and addiction councelling.  But then I don't have the same well defined set of ethics as Mr Sykes...</p>

<blockquote><p>At Benedict we adopt a simple ethical code for all online activities taken on behalf of our clients. Our ethics are based around our belief that the internet's true purpose is to supply users with the right information at the right time. We abide by Google's rules and go further in being guided by our own philosophy on what the internet should and could be one day.
</p><p><cite><a href="https://web.archive.org/web/20140328020615/http://www.benedict.co.uk/Benedict/internet_marketing_ethics.html">Benedict's Ethical Philosophy</a></cite>
</p></blockquote>

<p>A fine way to profit from a child's senseless death.</p>

<h2 id="harold-shipman"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#harold-shipman">Harold Shipman</a></h2>

<p>The serial killer <a href="http://www.theguardian.com/society/2005/aug/25/health.shipman">Harold Shipman murdered around 250 people</a>.  The inquiry into his activities found serious failings in the way the state controls doctors, pharmacists, and coroners.  The total cost of the inquiry was £21 million.</p>

<p>That wasn't enough money to keep the site registered in perpetuity, apparently.</p>

<p>It has now been taken over by <a href="https://twitter.com/garyptaylor/">Gary Taylor</a> - an affiliate marketer - who has redirected it to a spam site full of loan adverts.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Shipman-Website-fs8.png" alt="Shipman Website" width="500" height="" class="aligncenter size-full wp-image-10176">

<p>Both the Shipman Inquiry website and the new spam site are registered to Gary.  He links to the personal loans site in his <a href="https://web.archive.org/web/20140223035138/https://plus.google.com/113820714107468001605/posts">Google+ profile</a>.  On <a href="https://twitter.com/garyptaylor/status/318833884919889920">his</a> <a href="https://web.archive.org/web/20140415041429/http://www.3ac.co.uk/gaming-google-3ac-domains-seo-case-study">personal website he boasts about his SEO prowess</a>.</p>

<p>It's not Gary's fault that the Government couldn't be bothered to keep the site running - indeed, he appears to have bought it from <a href="http://who.is/domain-history/the-shipman-inquiry.org.uk">some other 3rd party</a>.</p>

<p>The site should have been left standing in memorial to the victims.  A tribute to let their families know that the state recognises their loss and will do everything in its power to stop such horrors from being inflicted on other people.</p>

<p>But now it's just a sordid way for the Midlands Young Entrepreneur Of The Year (2008) to make a few quid.</p>

<h2 id="bloody-sunday"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#bloody-sunday">Bloody Sunday</a></h2>

<p>After £190 million and 10 years, the <a href="https://en.wikipedia.org/wiki/Bloody_Sunday_Inquiry">Saville Report into Bloody Sunday</a> was published in 2010.</p>

<p>Despite all that time and money, the site is now a haven for spammers.  Thousands of news websites point there, countless newspapers will have made reference to the site, all now unwitting pawns in an anonymous  <del datetime="2014-02-18T22:08:39+00:00">spammer's</del> SEO Expert's game.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Bloody-Sunday-Spam-fs8.png" alt="Bloody Sunday Spam" width="600" height="400" class="aligncenter size-full wp-image-9925">

<h2 id="the-iraq-war"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#the-iraq-war">The Iraq War</a></h2>

<p>Hey, remember when the Security Services said Iraq had Weapons of Mass Destruction which could be launched within 45 minutes?  Yeah, turns out they lied.</p>

<p>The Butler Review came to the conclusion that the "intelligence" which used to justify the war with Iraq was unreliable.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Butler-Review-Spam-fs8.png" alt="Butler Review Spam" width="600" height="400" class="aligncenter size-full wp-image-9927">

<p>The Hutton Inquiry investigated the apparent suicide of Dr David Kelly. Prior to his death, he had been exposed as the person behind claims that the Government "sexed up" the intelligence relating to Weapons of Mass Destruction.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Hutton-Spam-fs8.png" alt="Hutton Spam" width="480" height="320" class="aligncenter size-full wp-image-9928">

<p>Both Inquiry websites are now used by spammers.  Profiting from the bloody consequences of war - all because the British state cannot pay for the upkeep of a few websites.</p>

<h2 id="c"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#c">&amp;c.</a></h2>

<p>And so it goes on.  There are around a dozen <a href="https://web.archive.org/web/20140409154253/https://www.nationalarchives.gov.uk/webarchive/public-inquiries-inquests.htm">Public Inquiry Sites</a> which have been allowed to lapse and are now in the hands of spammers.</p>

<p>Even when the government has managed to keep hold of the domain - they aren't managing their portfolio properly.  <a href="http://news.bbc.co.uk/1/hi/uk/4021285.stm">Zahid Mubarek was murdered</a> by a violent racist after the prison service placed them in a cell together.  The Home Office spent year resisting calls for an inquiry until the Law Lords ordered David Blunkett to set one up.</p>

<p>Today www.ZahidMubarekInquiry.org.uk is still owned by the Home Office - but no longer has a working website behind it.  It's as if they want to flush the reports of an institutional racist prison service down the memory hole.</p>

<p>This is our digital heritage - and it is being squandered.</p>

<h2 id="legacy"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/#legacy">Legacy</a></h2>

<p>Over the last week I've exposed how <a href="https://shkspr.mobi/blog/2014/03/uk-parliament-xss-flaw-disclosed/" title="The Unsecured State Part 1 - UK Parliament XSS Flaw (Disclosed &amp; Fixed)">Parliament's website was open to attack</a>, how a key <a href="https://shkspr.mobi/blog/2014/03/edubase-xss-disclosed/" title="The Unsecured State Part 2 - EduBase XSS (Disclosed &amp; Fixed)">Department for Education database could be hijacked</a>, that the <a href="https://shkspr.mobi/blog/2014/03/2000-nhs-security-vulnerabilities-disclosed/" title="The Unsecured State Part 3 - 2,000+ NHS Security Vulnerabilities (Disclosed)">NHS is riddled with insecure websites</a>, and that <a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/" title="The Unsecured State Part 4 - UK Government Websites Spewing Spam">local government websites don't fare much better</a>.</p>

<!--
For too long our "free market" rulers have decreed that competition and devolved decision making is the key to our online security.  It is not.

Simply put, it is a way to abdicate responsibility.  We are in a lamentable situation where the state outsources the digital credibility of the nation to either the lowest bidder or the highest party donor - with little thought for the consequences.
-->

<p>There needs to be a radical re-think in the way that the state approaches digital infrastructure.  This means long term legacy planning - not just thinking in terms of election cycles.  It means employing people who know what they are talking about - not just the heads of "Think Tanks".  It means no longer being afraid of technology - but rather embracing the promise it brings of a better world <em>for all</em>.</p>

<p>Sadly, for now, when dealing with the UK Government's attitude to their websites, I think it best to hang a large banner above your browser reading "<abbr title="Abandon All Hope — Ye Who Enter Here"><strong>Lasciate ogne speranza, voi ch'entrate</strong></abbr>"</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=9848&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-5-abandon-hope-all-ye/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[The Unsecured State Part 4 - UK Government Websites Spewing Spam]]></title>
		<link>https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/</link>
					<comments>https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 06 Mar 2014 08:20:24 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Unsecured State]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=9899</guid>

					<description><![CDATA[This is part 4 of a series of blog posts looking at the security of the UK Government&#039;s web infrastructure.    Over the last few days, I&#039;ve shown that hundreds of websites run by branches of the UK state are in a perilous state of disrepair. There are multiple sites with hugely embarrassing XSS flaws, running ancient and unsecured software, languishing unmaintained and long since abandoned.  What …]]></description>
										<content:encoded><![CDATA[<p>This is part 4 of a <a href="https://shkspr.mobi/blog/tag/unsecured-state/">series of blog posts</a> looking at the security of the UK Government's web infrastructure.</p>

<hr>

<p>Over the last few days, I've shown that hundreds of websites run by branches of the UK state are in a perilous state of disrepair. There are multiple sites with hugely embarrassing XSS flaws, running ancient and unsecured software, languishing unmaintained and long since abandoned.</p>

<p>What are the consequences of failing to invest in security and maintenance?  The websites become a haven for cyber-criminals.  They exploit weaknesses in the sites and use them to push dodgy pills, fake goods, and all manner of illicit schemes.</p>

<p>The exploits which we are about to see range from the trivial - comment spam - to the extremely serious - complete site takeovers.</p>

<p>All the sites mentioned in this blog were notified on 19th February about the specific flaws found.  I've no idea how these sites were compromised, nor whether any citizens' data are at risk.  All I know is that a disastrous attitude to "cyber security" is rotting away within the *.gov.uk namespace.</p>

<h2 id="complete-site-takeover"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/#complete-site-takeover">Complete Site Takeover</a></h2>

<p>This looks like the perfect site to by some "Genuine* Fashionable Boots", doesn't it?
<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Hillingdon-Boots.jpg" alt="Hillingdon Boots" width="720" height="536" class="aligncenter size-full wp-image-9906">
It is seemingly hosted with the endorsement of the Conservative run London Borough of Hillingdon.  One of the most prosperous borough in London, and they can't even afford to hire a website security team.</p>

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>The Leadership Centre is funded by the government department for Communities and Local Government.  Its mission?</p>

<blockquote><p>We believe it takes great leadership to create thriving and prosperous communities so we work with and support senior leaders from across the public sector to help them shift their thinking on leadership.</p></blockquote>

<p>Sadly, that doesn't extend to thinking about leading technology teams.  The site has been abandoned for around the last 3 years.  In that time, it has become riddled with spam.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/LocalLeadership-Spam-fs8.png" alt="LocalLeadership Spam-fs8" width="600" height="400" class="aligncenter size-full wp-image-9907"></p>

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>At the other end of the spectrum, we have the tiny borough of Amble.  With a population of barely 6,000, their website plays host to a number of webpages extolling the virtue of knock-off boots.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Amble-Spam-fs8.png" alt="Amble Spam-fs8" width="600" height="400" class="aligncenter size-full wp-image-9908">

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>The town of Kidwelly is nearly 900 years old.  It has a <a href="http://en.wikipedia.org/wiki/Kidwelly#History">rich history</a> including medieval castles, nature reserves, and an annual festival.</p>

<p>As far as Google is concerned, it also maintains a cottage industry for cut-price "blue pills".</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Hacked-Gov-UK-Site-in-search-listings-fs8.png" alt="Hacked Gov UK Site in search listings-fs8" width="600" height="495" class="aligncenter size-full wp-image-9904">

<p>Having spoken to the council, they have told me that the local police are currently dealing with the matter.</p>

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>Can we reasonably expect small parish councils under the yoke of austerity to have top-notch web security teams?  If they are able to find the resources necessary to fund the protection of their digital assets, that's great - but it's highly unlikely.</p>

<p>Instead, Central Government needs to heavily invest in making sure that all councils - big and small - are able to <em>competently</em> run web sites and services.</p>

<h2 id="comment-spam"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/#comment-spam">Comment Spam</a></h2>

<p>Every blog attracts comment spam.  Fraudsters leaving vaguely plausible comments in the hope that publication will see a flurry of extra hits on their site.  The bigger and more prestigious the site, the more likely the site is to be targeted.  And the .gov.uk name is <em>very</em> prestigious.</p>

<p>Amongst the Government sites playing host to spam is the Foreign and Commonwealth Office's blog page for  the British Ambassador to Somalia.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/FCO-Spam-fs8.png" alt="FCO Spam-fs8" width="600" height="400" class="aligncenter size-full wp-image-9909">

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>The Northern Ireland Assembly is the devolved legislature for Northern Ireland. It has hundreds of comments, seemingly all of which promoting dodgy deals.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/NIA-Spam-fs8.png" alt="NIA Spam-fs8" width="600" height="400" class="aligncenter size-full wp-image-9910">

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>A book of condolence in Oldham for a much loved community member now plays host to spammers.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Oldham-Condolence-Spam-fs8.png" alt="Oldham Condolence Spam-fs8" width="575" height="681" class="aligncenter size-full wp-image-9913">

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>Lewes, and many other councils, have open forums which are overrun with spam messages.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Lewes-Spam-fs8.png" alt="Lewes Spam-fs8" width="600" height="400" class="aligncenter size-full wp-image-9914">

<p style="width:3em;margin-left:auto; margin-right:auto;">—❦—</p>

<p>Even the UK National Archives have seen fit to save some comment spam for future generations to ponder.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/National-Archives-Spam-fs8.png" alt="National Archives Spam-fs8" width="600" height="207" class="aligncenter size-full wp-image-9912"></p>

<h2 id="hidden-links"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/#hidden-links">Hidden Links</a></h2>

<p>Finally, we get to the murky world of hidden links.  These are spamming messages not designed to be seen by humans.  They are hidden within the web pages' source code in the hopes that Google and other search engines will see them and increase the spamming site's popularity.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Gov-Spam-Source-Code-fs8.png" alt="Gov Spam Source Code-fs8" width="600" height="400" class="aligncenter size-full wp-image-9905">

<p>The spam covers the usual range from pharmaceuticals to knock off designer goods.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/Land-Registry-spam-fs8.png" alt="Land Registry spam" width="600" height="300" class="aligncenter size-full wp-image-9951">

<p>Again, there are several sites which exhibit this malicious behaviour.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/03/East-Devon-HTML-Spam-fs8.png" alt="East Devon HTML Spam-fs8" width="600" height="400" class="aligncenter size-full wp-image-9921">

<h2 id="what-can-be-done"><a href="https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/#what-can-be-done">What Can Be Done?</a></h2>

<p>The State needs to <strong>take responsibility</strong> for the websites run in its name.  If site owners are unable or unwilling, then those sites should be removed from the web.  It is simply too dangerous to allow them to stay online without decent security measures in place.</p>

<p>It is time that the Government started to treat cyber-security as a serious subject.  They love putting out press releases, and making grand sounding plans with shadowy agencies - what they need to do is spend some money on basic front-line services.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=9899&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/03/the-unsecured-state-part-4-uk-government-websites-spewing-spam/feed/</wfw:commentRss>
			<slash:comments>5</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Should GOV.UK Run A Bug Bounty?]]></title>
		<link>https://shkspr.mobi/blog/2014/02/should-gov-uk-run-a-bug-bounty/</link>
					<comments>https://shkspr.mobi/blog/2014/02/should-gov-uk-run-a-bug-bounty/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Tue, 04 Feb 2014 12:05:27 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=9760</guid>

					<description><![CDATA[Cyber Security is of vital national importance.  As the United Kingdom places more of its infrastructure onto the Internet, bugs and glitches go from minor inconveniences to full scale national emergencies.  Suppose, for a moment, that a hacker were to interrupt payment processing for banks, or tamper with the UK&#039;s water supply, or cut off the phone lines.  The economic damage alone could run…]]></description>
										<content:encoded><![CDATA[<p>Cyber Security is of vital national importance.  As the United Kingdom places more of its infrastructure onto the Internet, bugs and glitches go from minor inconveniences to full scale national emergencies.</p>

<p>Suppose, for a moment, that a hacker were to interrupt payment processing for banks, or tamper with the UK's water supply, or cut off the phone lines.  The economic damage alone could run into the billions.</p>

<p>Anyone discovering such a flaw could illegally exploit it for their own gain, or sell the vulnerability to the highest bidder.</p>

<p>The computer industry's solution to this problem is the "<a href="https://bugcrowd.com/list-of-bug-bounty-programs/">Bug Bounty</a>".  Any security researcher / hacker who finds a security bug in, say, Facebook - is then able to disclose that bug directly to Facebook in return for cold, hard cash.  And a generous "thank you" note.  This provides an economic incentive to find and <em>safely</em> reveal bugs.</p>

<p>Some companies band together to provide <a href="https://hackerone.com/ibb">bug bounties for critical Internet infrastructure</a>.  The giants of Capitalism banding together in Socialism to protect their interests. Lovely!</p>

<p>Ideally, I think, Governments should compel businesses to provide bug bounties.  Think of it like a form of punitive fine - inapplicable to responsible companies.  Force the privatised utilities, large companies, and infrastructure providers to pay up for security flaws in their software and hardware.</p>

<p>It's not so unreasonable; the Government already <a href="https://ico.org.uk/action-weve-taken/">fines companies for breaches of the Data Protection Act</a> - so why not fine companies for breaches of a future "Computer Security Act".</p>

<p>But that will be a long time coming.  Let's start closer to home.</p>

<h3 id="why-doesnt-the-uk-government-offer-a-bug-bounty-for-its-services"><a href="https://shkspr.mobi/blog/2014/02/should-gov-uk-run-a-bug-bounty/#why-doesnt-the-uk-government-offer-a-bug-bounty-for-its-services">Why doesn't the UK Government offer a bug bounty for its services?</a></h3>

<p><img src="https://shkspr.mobi/blog/wp-content/uploads/2014/02/Gov-UK-Bugs-fs8.png" alt="Gov UK Bugs" width="570" height="320" class="aligncenter size-full wp-image-9767">
Imagine that you've just found a gaping huge security flaw in HMRC.  With a single command from your computer, you can subtly alter your tax status - or see how much tax an individual has paid - or erase evidence that someone has paid their owed tax.</p>

<p>Ignoring the <a href="http://www.legislation.gov.uk/ukpga/1990/18">illegal aspect of acting on your findings</a> - where's the incentive to responsibly report the problem?  After all, you'd get a huge pay-day from selling it to the criminal underworld.</p>

<p>Let's step back a bit - how would you even <strong>successfully</strong> report your findings to the Government?</p>

<p>Assuming you've even <em>heard</em> of <a href="https://www.gov.uk/government/policy-teams/office-of-cyber-security-and-information-assurance">Office of Cyber Security and Information Assurance</a> the only way of contacting them is via email.  They don't offer a PGP key, so there's no way of contacting them securely.  Oh, and based on my experience, they don't reply.</p>

<p>One could also try contacting the affected Government agency.  But again, based on my experience, they won't have the first clue of how to respond to a reported security flaw.</p>

<p>Finally, one could try escalating to <a href="https://web.archive.org/web/20140217164922/http://www.cesg.gov.uk/AboutUs/contactus/Pages/Contact-GovCertUK.aspx">GCHQ's GovCertUK</a> - the security agency charged with protecting vital national computing infrastructure.  They <a href="https://web.archive.org/web/20130625170330/http://www.cesg.gov.uk/Publications/Documents/pgp_page.txt"><em>do</em> offer a PGP key</a> - but its validity expired at the end of January 2014...</p>

<p>Wouldn't it be brilliant if our shiny new <a href="https://www.gov.uk/">GOV.UK</a> were to offer an easy to use form for reporting security vulnerabilities?  Obviously, they would need a team acting as a clearing house for all the reports they receive, and the legal authority to test the vulnerabilities reported.</p>

<p>Finally, if a bug was found within the Government’s IT infrastructure, they could force it to be fixed and offer the reporter a suitable reward.  It needn't be monetary, of course, it could just as easily be a medal, an honour, or a Peerage - whatever they deem suitable for strengthening the nation's security.</p>

<p>Is this something the Government should be involved in?  Or should citizens simply exhaust themselves trying to report bugs with little prospect of them being fixed and no prospect of a "thank you" - let alone a reward?</p>

<p>Without a bug bounty, what incentive does the Government have for keeping its electronic infrastructure secure?  Or do they just believe that the "stick" of criminal sanctions is larger than the carrot of rewarding decent behaviour?</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=9760&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/02/should-gov-uk-run-a-bug-bounty/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Browser Statistics for UK Government Websites]]></title>
		<link>https://shkspr.mobi/blog/2012/10/browser-statistics-for-uk-government-websites/</link>
					<comments>https://shkspr.mobi/blog/2012/10/browser-statistics-for-uk-government-websites/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 11 Oct 2012 11:16:53 +0000</pubDate>
				<category><![CDATA[politics]]></category>
		<category><![CDATA[gov.uk]]></category>
		<category><![CDATA[statistics]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=6383</guid>

					<description><![CDATA[One of the great things about publicly blogging for the last 5 years, is that I can remind myself of what I was doing this time last year. Or several years ago.  The Terence Eden of October 2009 was a busy chap! 22 blog posts! What a guy :-)  One post which caught my eye recently, was asking &#34;What are the browser statistics for 10 Downing Street?&#34;  Here was their answer  UK Prime…]]></description>
										<content:encoded><![CDATA[<p>One of the great things about publicly blogging for the last 5 years, is that I can remind myself of what I was doing this time last year. Or several years ago.</p>

<p>The <a href="https://shkspr.mobi/blog/2009/10/">Terence Eden of October 2009</a> was a busy chap! 22 blog posts! What a guy :-)</p>

<p>One post which caught my eye recently, was asking "<a href="https://shkspr.mobi/blog/2009/10/browser-statistics-of-10-downing-street/">What are the browser statistics for 10 Downing Street?</a>"</p>

<p>Here was their answer</p>

<blockquote class="social-embed" id="social-embed-4549222839" lang="cy" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/10DowningStreet" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRugAAABXRUJQVlA4INwAAABQBgCdASowADAAPrVGoEmnI6MhLjgMyOAWiWkABRAe255KmcvngTIHZUZBs7q+gBls3fOCafekoFoRAAD++fsTk7Rl64MygtEv7WfR+YvwKawSuOB34F76rSTwynqUi4e2s52811JwS6k6w5xaP90fx+/gCgEdHTmIEDTtSYi2J86lXj1RTOB/HfXJ9y/+qi5oKgkFt3TsGTzoBxfTjAx6S1VWeCy3jYbtBusa2YuTW8fOOzY+7G07555Mula3+V5pNC8fVL5WUMBbZM8/1jxXJp/z/vAzIxNqIAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">UK Prime Minister</p>@10DowningStreet</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/4529469389">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> Top are: IE7 22%, IE8 20%, IE6 12%, Firefox3.5.3 9%, FF3.5.2 7%, FF3.0.14 5%, FF3.0.13 4%, Safari 4.0.3 4%, Chrome 2.0.172.43 2%</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/10DowningStreet/status/4549222839"><span aria-label="2 likes" class="social-embed-meta">❤️ 2</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2009-10-02T09:46:44.000Z" itemprop="datePublished">09:46 - Fri 02 October 2009</time></a></footer></blockquote>

<p>So, three years later, how have things changed?</p>

<p>Firstly, I asked the team behind the (still in beta) GOV.UK</p>

<blockquote class="social-embed" id="social-embed-256332331424559106" lang="nl" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><blockquote class="social-embed" id="social-embed-256276366373298176" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/edent" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRkgBAABXRUJQVlA4IDwBAACQCACdASowADAAPrVQn0ynJCKiJyto4BaJaQAIIsx4Au9dhDqVA1i1RoRTO7nbdyy03nM5FhvV62goUj37tuxqpfpPeTBZvrJ78w0qAAD+/hVyFHvYXIrMCjny0z7wqsB9/QE08xls/AQdXJFX0adG9lISsm6kV96J5FINBFXzHwfzMCr4N6r3z5/Aa/wfEoVGX3H976she3jyS8RqJv7Jw7bOxoTSPlu4gNbfXYZ9TnbdQ0MNnMObyaRQLIu556jIj03zfJrVgqRM8GPwRoWb1M9AfzFe6Mtg13uEIqrTHmiuBpH+bTVB5EEQ3uby0C//XOAPJOFv4QV8RZDPQd517Khyba8Jlr97j2kIBJD9K3mbOHSHiQDasj6Y3forATbIg4QZHxWnCeqqMkVYfUAivuL0L/68mMnagAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Terence Eden is on Mastodon</p>@edent</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Anyone from <a href="https://twitter.com/GDSTeam">@GDSTeam</a> know if they'll be releasing browser statistics - or any other user metrics? <a href="http://shkspr.mobi/blog/2009/10/browser-statistics-of-10-downing-street/">shkspr.mobi/blog/2009/10/b…</a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/edent/status/256276366373298176"><span aria-label="0 likes" class="social-embed-meta">❤️ 0</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2012-10-11T06:13:41.000Z" itemprop="datePublished">06:13 - Thu 11 October 2012</time></a></footer></blockquote><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/SamJSharpe" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRvoBAABXRUJQVlA4IO4BAADwCgCdASowADAAPqVGm0mmJCKhNVqqqMAUiUAYbP/o2daPjGByVanOKwyJUDcmz9+08Cz7aDonkSabt+PbZqO4qXcAOXnly+5Fv/8R5v6yA1qQ3GVBJdeuOi6hcf8TtYAA/vnRf4dasZBCbZ4rSNz6mxsoGfZX3xkcXh+djhWntULV0mNlKleFjx5CslndUp0p9FUDu65x0ffI/qJlPrptuztDW9uB9JGR4dVJsgTsycVN6pg/KLyRG/xZ9DxOUcK2or61HDeicd2LPKg70RhC6qTnsB6jfsLlY+OsWr2T2m6K1EErdQ/ZRyL7PZkhzTBt+MEuSHgPZOqU4YOYLtnJjGXNVnFFiVjeJL0tu8JZVsL13HPp02TJQ2y5Rf5BKL10jtEW3f8Up3n3Ojj50qJCeDk5QxnwZygf3tFDfg7hEHLzQv8nQ/NbQC3AwwLNKgo+f6eIZinJ+DZkKKlHImVOCwCj8hC97wWwBi2+ag6SB2gnrRuCE5pkFj3M7+rWIzd9Pv5goCOrEy8R03qZPrqiwG8ElEyJPcMTDh54MEt8DntAlMcKAJdkqMjdbgqXGy7M3TZ5wP/76E1SoKalznKr1I22kTIwxZFVaQwfyASrlN1TfLJwvISFQKHgUpjq0gS9+iMl0Sf2ZbkHrwAAAA==" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Sam Sharpe</p>@SamJSharpe</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/256276366373298176">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> very rough stats (-bots -spiders): FF 28%, IE&lt;6 10%, IE7 12%, IE8 21%, IE9+ 13%, Safari 11%, Opera 3.5% /cc <a href="https://twitter.com/GDSTeam">@GDSTeam</a></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/SamJSharpe/status/256332331424559106"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2012-10-11T09:56:04.000Z" itemprop="datePublished">09:56 - Thu 11 October 2012</time></a></footer></blockquote>

<p>Then, I asked for the whole of the parliament.uk space</p>

<blockquote class="social-embed" id="social-embed-256335836738633728" lang="nl" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><blockquote class="social-embed" id="social-embed-256334581853216768" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/edent" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRkgBAABXRUJQVlA4IDwBAACQCACdASowADAAPrVQn0ynJCKiJyto4BaJaQAIIsx4Au9dhDqVA1i1RoRTO7nbdyy03nM5FhvV62goUj37tuxqpfpPeTBZvrJ78w0qAAD+/hVyFHvYXIrMCjny0z7wqsB9/QE08xls/AQdXJFX0adG9lISsm6kV96J5FINBFXzHwfzMCr4N6r3z5/Aa/wfEoVGX3H976she3jyS8RqJv7Jw7bOxoTSPlu4gNbfXYZ9TnbdQ0MNnMObyaRQLIu556jIj03zfJrVgqRM8GPwRoWb1M9AfzFe6Mtg13uEIqrTHmiuBpH+bTVB5EEQ3uby0C//XOAPJOFv4QV8RZDPQd517Khyba8Jlr97j2kIBJD9K3mbOHSHiQDasj6Y3forATbIg4QZHxWnCeqqMkVYfUAivuL0L/68mMnagAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Terence Eden is on Mastodon</p>@edent</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/blangry/status/256333429078110208">Replying to @blangry</a></small>@blanalive If you've got any going. Would be better to have them published regularly than on an ad-hoc basis.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/edent/status/256334581853216768"><span aria-label="0 likes" class="social-embed-meta">❤️ 0</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2012-10-11T10:05:01.000Z" itemprop="datePublished">10:05 - Thu 11 October 2012</time></a></footer></blockquote><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/blangry" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRlgDAABXRUJQVlA4IEwDAAAQDgCdASowADAAPqlImkmmJKKhNV1YAMAVCWwAnTK9fjSIbhoqFvX0kbZe7lZQD6i7x/Jr9HaHsgrZ5ZXGB3yRoHQEakvV9wkxa/XnnSTAHu9D0MKnOWDiy7kx9tFYO339i7DvueJkHc3eRJa+6m6SSOHqguHCIg7gAP7s4gflUilUqyt6dhlf6VXmaJ7pps7cDOYts/KB3ji1z27C9jyU+h2x0QZuk8/LDyEeQ3gywEc7kgOTt1Jsm2YQfz9NuG3NdMmfIvgjzrrh86H4vfq16PmK7/r4v3GU0UB/9o31PZe3B7gkzikyddoR0L0pVsyNl6wukFQkYNGY+AwK8sUHkpZM9ysqVWN1CAX6N7/BLRRTUEMTf9CYsiNcANLgkJbSp/ner752YrTyT3UeC5pZphSD5Sb8EoKf9JWngwb2cGcYZN+JW/Okk2dqlc8dPTtGYiGhSIaz6GZF1OPwYsUcsB4/JzZRPe9/EMjTC9rgABgRYaKUkGoaDNxUYIJZ3aVeClDClwIPp/tGCJgQ60KWSlVgToYOzCBMSVwlltFnl08rsqGngfH7oMVDN/8I3CqYnLK2d5afJZjzH0qxYgg0olaGkJkvZ/KQgXKRgMGpJ4mbcG7vOT9UKAwNl2G9oC7MuMd3NIpfNThrozAXc8qZCB3ah9FaGg5j9WML5Q+rmPblH2zSh/3m1fbHeoe7MsUSoMWpRhVOHdw85f4fggLGe81V/FuUhmty9mH+42b8/SuVlLMeSCYJrWddUx5H88aoP5i9fXzQanmCQ2V8HOZL6gqlSGAXFcHSBYA3ZHGSmmCF+/bSyb5YA5reNE9En1TwfxqaQ/Q2LSaXdTQoPqmFhALvv1cDa/jF67uDNKVmtfoh11TE+I6n/++vDLbVxSKiPpuZHdK1/6SjwxWvvzP9p/5AVj9PidfKWlhP1lzEe4RCHZhJaz9vpbhmO/tFV7bsKtvMHvd9ENcvgtQ1CmOuooQcnlqShoxcMpOjcKKhIT4JM6XPUkqHCr3piGpm4Bpnn9R0mTfuZPGrJE5nPtVRNxezToBhkMxEUa85FiAjrqRGQJe5DVFPMz9HbmtOQYSrlTx4TT5wsayHWI6bAEcHuLHwtPICqeG8WZQA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Alex</p>@blangry</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/256334581853216768">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> IE8 23% IE9 17% Chrome 21/22 16% FF15 7.7% IE7 6.5% Safari 4% IE6 1.6%</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/blangry/status/256335836738633728"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2012-10-11T10:10:00.000Z" itemprop="datePublished">10:10 - Thu 11 October 2012</time></a></footer></blockquote>

<p>These are, as they say, to be taken with a pinch of salt.</p>

<p>It's interesting to see the collapse of IE6, and the huge rise in Chrome.  More interesting still, is the difference between the general parliamentary site and GOV.UK.  There also doesn't appear to be a significant mobile presence - unless they're rolled up into the main stats.</p>

<p>One thing is for sure, it would be great to see these sort of official statistics regularly. Not least to counter the "must support IE6" and "Who on Earth uses Chrome" crowds.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=6383&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2012/10/browser-statistics-for-uk-government-websites/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
	</channel>
</rss>
