Terence Eden. He has a beard and is smiling.

Terence Eden’s Blog

Theme Switcher:

NHS Goes To War Against Open Source

· 8 comments · 1,000 words · Viewed ~6,462 times


All source code repositories must be private by default. Repositories may be internal where there is a legitimate need for visibility within the enterprise. Repositories must not be public unless there is an explicit and exceptional need, and public access has been formally approved by the Engineering Board. Purpose Public repositories materially increase the risk of unintended disclosure of source code, architectural decisions, configuration detail, and contextual information that may be exploited — particularly given rapid advancements in Al models capable of large-scale code ingestion, inference, and reasoning (e.g. developments such as the Mythos model). This red line establishes a default-closed posture for code while the organisation assesses the impact of these changes and ensures that any public publication of code is a deliberate, reviewed, and justified decision. • For P&P Public repositories we will switch to Private on Monday the 11th May 2026 • Teams that have a need for an exemption need to declare this to the Engineering mailbox by COP Wednesday 6th May 2026 • Teams can change to private at any time ahead of this • Central tracking of public repositories: NHSE public repositories.xlsx

The NHS is preparing to close nearly all of its Open Source repositories. Throughout my time working for the UK Government - in GDS, NHSX, i.AI, and others - I championed Open Source. I spoke to dozens of departments about it, wrote guidance still in use today, and briefed Ministers on why it was so important. That's why I'm beyond disappointed at recent moves from NHS England to backtrack on…

How Can Governments Pay Open Source Maintainers?

· 14 comments · 1,000 words · Viewed ~3,562 times


A tiny lego Storm Trooper eats a chocolate coin.

When I worked for the UK Government I was once asked if we could find a way to pay for all the Open Source Software we were using. It is a surprisingly hard problem and I want to talk about some of the issues we faced. The UK Government publishes a lot of Open Source code - nearly everything developed in-house by the state is available under an OSI Approved licence. The UK is generally pretty…

Vanguard - The Government Project to get British Businesses to use the Internet

· 3 comments · 1,200 words · Viewed ~488 times


Vague graph showing how adopting technologies is beneficial.

Email isn't an obvious business benefit. Imagine it is the early 1980s and you need to communicate with people across the country. A first-class letter will cost you 17p - about 60p in today's money. The letter will be delivered the next day and you'll have your answer back the day after. By contrast, a single computer terminal was likely to set you back around £3,000 - and that's before you …

The (theoretical) risks of open sourcing (imaginary) Government LLMs

· 13 comments · 850 words · Viewed ~243 times


A t-shirt with the slogan "Make things open it makes things better."

Last week I attended an unofficial discussion group about the future of AI in Government. As well as the crypto-bores who have suddenly pivoted their "expertise" into AI, there were lots of thoughtful suggestions about what AI could do well at a state level. Some of it is trivial - spell check is AI. Some of it is a dystopian hellscape of racist algorithms being confidently incorrect. The…

It has never been cheaper to commit a crime

· 5 comments · 400 words · Viewed ~243 times


Screenshot of legislation showing the fines.

The UK has what is known as a "Standard Scale" of fines for criminal acts. For example, breaking the law may incur "a fine not exceeding level 4 on the standard scale". Part of the reasoning behind this, so I understand, is to make it simpler for the Government to update the value of those fines. Rather than having to change every law in the land - and have tedious votes on them - it's possible…

A (partial) list of vanity identifiers

· 8 comments · 400 words · Viewed ~458 times


A tiny lego Storm Trooper eats a chocolate coin.

One of those things that organisations love to do is issue identifiers. My credit card provider issues me with a Customer ID, a Billing ID, a Reference Number, and an online login ID. All of which are different. And none of which match the embossed plastic card they sent me. The state also issues identifiers. I know, I know, I am not a number, I am a free man. But I have a passport number which…

Episode 31 - Modernising the Ministry of Justice

· 100 words


The emojified face of Kim Rowan.

How do you modernise the technology of a huge organisation like the UK's Ministry of Justice? Kim Rowan has some bright ideas. 🔊 💾 Download this audio file. Read Kim's post on the Application Modernisation Team For more technical posts, read the Just-Tech blog on Medium. …

Don't redact FOI answers with a marker pen

· 500 words · Viewed ~3,049 times


(Disclaimer - I currently work for GDS, although I don't work on FOI. This is an opinion piece and doesn't represent the views on any of my employers - past, present, or future.) The Irish government recently complied with a Freedom of Information Act request from journalists at RTÉ. The journalists wanted copies of messages sent via a WhatsApp group. The Irish government complied and sent out …

How I Got The UK Government To Adopt ODF

· 3 comments · 600 words · Viewed ~866 times


Screenshot of a Gov.UK page which says Using Open Document Formats (ODF) in your organisation.

Well, it's not often I get to completely influence the UK Government's approach to open standard. GOV.UK is adopting .ODF as their official document standard! All documentation will be also made available in HTML & PDF. Sweet! Yeah, yeah, so I only played a small part in the (no doubt) hideously complicated process - but I'm happy to take full credit :-) Last year, the UK Government opened…

The Unsecured State Part 4 - UK Government Websites Spewing Spam

· 5 comments · 800 words · Viewed ~5,158 times


This is part 4 of a series of blog posts looking at the security of the UK Government's web infrastructure. Over the last few days, I've shown that hundreds of websites run by branches of the UK state are in a perilous state of disrepair. There are multiple sites with hugely embarrassing XSS flaws, running ancient and unsecured software, languishing unmaintained and long since abandoned. What …

Should GOV.UK Run A Bug Bounty?

· 4 comments · 700 words · Viewed ~1,976 times


Cyber Security is of vital national importance. As the United Kingdom places more of its infrastructure onto the Internet, bugs and glitches go from minor inconveniences to full scale national emergencies. Suppose, for a moment, that a hacker were to interrupt payment processing for banks, or tamper with the UK's water supply, or cut off the phone lines. The economic damage alone could run…

"Let's ban tiny phones!" - UK Government

· 7 comments · 300 words · Viewed ~10,131 times


The BBC is reporting that the Government is so afraid of prisoners having access to concealed mobile phones, they want to introduce a ban. UK officials are considering banning the sale of small mobile phones designed to resemble car key fobs. A government spokesman told the BBC that it was discussing the issue with the National Trading Standards Board and the Serious Organised Crime Agency. It …