UK Government's Payment Infrastructure Is Now Open Source(govukpay-docs.cloudapps.digital)
govukpay-docs.cloudapps.digital
UK Government's Payment Infrastructure Is Now Open Source
https://govukpay-docs.cloudapps.digital/#contribute
11 comments
GDS’s GA Premium account contractually prevents Google from investigating the data, and Google self-anonymises with a flag in their API[1]. If you don’t trust them then that’s fine, but for functionality vs cost it seems to be the best option.
For what it’s worth, for extremely sensitive projects like GOV.UK Verify other options are fine; Verify uses a local Piwik instance.
You’re also welcome to block that specific JS or just turn off JS completely on GOV.UK properties - everything has to work without JS to go live on GOV.UK.[2]
[1] https://support.google.com/analytics/answer/2763052?hl=en
[2] https://www.gov.uk/service-manual/technology/using-progressi...
For what it’s worth, for extremely sensitive projects like GOV.UK Verify other options are fine; Verify uses a local Piwik instance.
You’re also welcome to block that specific JS or just turn off JS completely on GOV.UK properties - everything has to work without JS to go live on GOV.UK.[2]
[1] https://support.google.com/analytics/answer/2763052?hl=en
[2] https://www.gov.uk/service-manual/technology/using-progressi...
GDS’s GA Premium account contractually prevents Google from investigating the data
Does it prevent US government from getting this data with a court order?
Does it prevent US government from getting this data with a court order?
This guy is asking the right thing.
It's not about you trusting somebody to handle the data. It's just that the data should not exist at all outside of you and the gov.
As soon as the data exists somewhere else, there is a way to misuse it and a chance it will happen. In todays word, those don't even require a lot of imagination to find because it already happened and is currently happening.
It's not about you trusting somebody to handle the data. It's just that the data should not exist at all outside of you and the gov.
As soon as the data exists somewhere else, there is a way to misuse it and a chance it will happen. In todays word, those don't even require a lot of imagination to find because it already happened and is currently happening.
> Does it prevent US government from getting this data with a court order?
Of course not. Also it does not prevent governments and other organizations from illegally extracting that data from Google, as it happened.
Of course not. Also it does not prevent governments and other organizations from illegally extracting that data from Google, as it happened.
>Google self-anonymises with a flag in their API
Even if they could, they wouldn't be able to find it.
Even if they could, they wouldn't be able to find it.
At what point is it, though? From the Client or when it hits the server. If it is the later, we can’t know if three letter agencies intercept the traffic before it gets anonymized.
Furthermore, it is often possible to de-anonymize data especially if you have an extensive knowledge of users and their data such as google. But even then, you can also de-anonymize data
https://www.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf
https://www.wired.com/2007/12/why-anonymous-data-sometimes-i...
Furthermore, it is often possible to de-anonymize data especially if you have an extensive knowledge of users and their data such as google. But even then, you can also de-anonymize data
https://www.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf
https://www.wired.com/2007/12/why-anonymous-data-sometimes-i...
The client can’t anonymise the IP as it connects to the Google server which then will implicitly know it. What the flag does is tell the server to anonymise it from that point onwards. From my original link:
When a customer of Analytics requests IP address anonymization, Analytics anonymizes the address as soon as technically feasible at the earliest possible stage of the collection network. The IP anonymization feature in Analytics sets the last octet of IPv4 user IP addresses and the last 80 bits of IPv6 addresses to zeros in memory shortly after being sent to the Analytics Collection Network. The full IP address is never written to disk in this case.
When a customer of Analytics requests IP address anonymization, Analytics anonymizes the address as soon as technically feasible at the earliest possible stage of the collection network. The IP anonymization feature in Analytics sets the last octet of IPv4 user IP addresses and the last 80 bits of IPv6 addresses to zeros in memory shortly after being sent to the Analytics Collection Network. The full IP address is never written to disk in this case.
I still can't believe people are happy using Verify.
I very reluctantly tried to use it as I don't want to give all my data to any of the companies you listed, and yet it failed to identify me using the two companies I was allowed to pick.
I really don't see how it's acceptable to force users to give so much personal data to a handful of randomly selected private companies, on the off-chance that they already have it.
I very reluctantly tried to use it as I don't want to give all my data to any of the companies you listed, and yet it failed to identify me using the two companies I was allowed to pick.
I really don't see how it's acceptable to force users to give so much personal data to a handful of randomly selected private companies, on the off-chance that they already have it.
I'm in a similar situation to you. Last time I tried to verify my identity, two of the companies refused to do so because I don't have a full driving license, only provisional; and the other two didn't require a driving license but refused to accept that I exist, naturally without telling me what I should do about it.
The concerning part was what happened when I tried to cancel the process. The companies told me that they would delete all the data I had submitted to them, but when I tried again a year later, I was invited to resume my application, and all my data was still in their systems!
[edit] Just tried to go through the process again to see if anything has changed. I picked Royal Mail as an identity provider but was unable to finish because I had to upload a scan of a phone contract, which I don't have since I use pay as you go! Bloody waste of time!
The concerning part was what happened when I tried to cancel the process. The companies told me that they would delete all the data I had submitted to them, but when I tried again a year later, I was invited to resume my application, and all my data was still in their systems!
[edit] Just tried to go through the process again to see if anything has changed. I picked Royal Mail as an identity provider but was unable to finish because I had to upload a scan of a phone contract, which I don't have since I use pay as you go! Bloody waste of time!
>> GDS’s GA Premium account contractually prevents Google from investigating the data
And we all know that means it's safe forever, and isn't in any sort of jeopardy the moment it crosses a border, or in fact the moment it escapes to a third party at all.
It's all industry standard so it must be fine!
>> For what it’s worth, for extremely sensitive projects like GOV.UK Verify other options are fine; Verify uses a local Piwik instance.
Then gov.uk should use a local Piwik instance for everything, GDS are clearly not incapable of it.
FYI I can and do block google analytics JS. It shouldn't be there in the first place, I shouldn't have to block it when interacting with my own government.
And we all know that means it's safe forever, and isn't in any sort of jeopardy the moment it crosses a border, or in fact the moment it escapes to a third party at all.
It's all industry standard so it must be fine!
>> For what it’s worth, for extremely sensitive projects like GOV.UK Verify other options are fine; Verify uses a local Piwik instance.
Then gov.uk should use a local Piwik instance for everything, GDS are clearly not incapable of it.
FYI I can and do block google analytics JS. It shouldn't be there in the first place, I shouldn't have to block it when interacting with my own government.
Are you at GDS? Please can you tell your friends at HMRC that the login system is the most janky UX I've ever experienced and is prone to social engineering due to how complex it is.
Totally agreed. After I lost my login details to sign into HMRC portal to do my self assessment, it was almost impossible to recover my credentials.
Impossible over the phone as they wanted to send a paper letter to my address and I was just moving to a new place (and doing some travel before that) so I had no more access to the address HMRC had on file.
I finally gave up and just asked my accountant to do it on my behalf. He somehow managed to sort this out with HMRC.
There is no flow to recover your username and password (or generate new one) with your email address which is maddening.
Impossible over the phone as they wanted to send a paper letter to my address and I was just moving to a new place (and doing some travel before that) so I had no more access to the address HMRC had on file.
I finally gave up and just asked my accountant to do it on my behalf. He somehow managed to sort this out with HMRC.
There is no flow to recover your username and password (or generate new one) with your email address which is maddening.
Sadly looks like there's a turf war going on. So dumb.
[1] "HMRC rejects Gov.uk Verify", http://www.computerweekly.com/news/450412927/HMRC-rejects-Go... [2] http://www.computerweekly.com/news/450301278/Revealed-The-ba...
[1] "HMRC rejects Gov.uk Verify", http://www.computerweekly.com/news/450412927/HMRC-rejects-Go... [2] http://www.computerweekly.com/news/450301278/Revealed-The-ba...
> GDS’s GA Premium account contractually prevents Google from investigating the data
What's the penalty for completely disregarding that?
Is it anywhere near large enough to justify them not disregarding it?
More to the point: Pretty much the only thing a contract can do is impose a monetary penalty. Even if it's quite large, it's still only money, and Google rakes in money by the bushel basket from selling data to advertisers. Therefore, it isn't a very convincing penalty.
What's the penalty for completely disregarding that?
Is it anywhere near large enough to justify them not disregarding it?
More to the point: Pretty much the only thing a contract can do is impose a monetary penalty. Even if it's quite large, it's still only money, and Google rakes in money by the bushel basket from selling data to advertisers. Therefore, it isn't a very convincing penalty.
in this specific case they would be messing with the UK government on a controversial topic in the public view... the contractual penalty would be the least of their worries
> messing with the UK government on a controversial topic in the public view
Is it in the public view? How many Daily Mail headlines about Google Analytics have you read ever?
Is it in the public view? How many Daily Mail headlines about Google Analytics have you read ever?
So how does the average user verify this API flag then?
This kind of stuff should be opt-in for users, but Google know that hardly anyone would want to be tracked by them if they were given a clear choice.
This kind of stuff should be opt-in for users, but Google know that hardly anyone would want to be tracked by them if they were given a clear choice.
It's nice that Verify uses an internal analytics system, but the whole point of Verify is to outsource identifying people to private companies.
That's because there was massive protest against a centralised ID system in the UK, which led to it being shut down.
https://www.theguardian.com/politics/2010/may/27/theresa-may...
https://www.theguardian.com/politics/2010/may/27/theresa-may...
Right, but those companies don’t know what services people are trying to use Verify for (in the same way that the services don’t know which identity provider you used). The part of Verify that uses Piwik is the hub in the middle that brokers the identity flow.
But you still have to give the Verify companies enough data that a breach of their systems would be very serious. Eg. If the Post Office (an organisation that recently falsely sent a load of employees to prison due to their own cocked up IT project) gets hacked, they have (or could have) dates of birth, 6 years of addresses, email addresses, etc. of a good number of gov.uk users.
You don’t give the majority of those details to the Post Office (or other providers), they ask you questions about the data they already hold on you. The passport and driving licence information is checked via APIs provided from the government to accredited companies, and the system is designed such that that data isn’t stored by the identity providers (beyond a flag to say that that form of identity has been verified).
That's all good; but most users aren't aware of blocking Javascript on specific domains.
Privacy is opt-in, not opt-out.
Privacy is opt-in, not opt-out.
I know you get asked this kind of question in every thread, but do you know where I can send questions about the judiciary.gov site?
They hold the coroner's letters to prevent future deaths, but the search is not useful.
It would be good if I could search and return every letter about eg deaths by suicide or railway deaths or etc.
It seems a shame to have all these reports to prevent future death locked away.
They hold the coroner's letters to prevent future deaths, but the search is not useful.
It would be good if I could search and return every letter about eg deaths by suicide or railway deaths or etc.
It seems a shame to have all these reports to prevent future death locked away.
Well that's the point of making it open source. So you can point that out. I just hope people will finally get than opening is just half of the work, the other half is actually properly interacting with people crossing the door you just opened.
The UK is in Five-Eyes and Google is a US intelligence partner - they would know even without analytics on the site, don't worry.
I'm not seeing GA on that page. Has someone removed it in the last 48 minutes?
That page is some docs about the service.
https://www.payments.service.gov.uk/
That's the actual service and it includes GA, or at least it did earlier.
https://www.payments.service.gov.uk/
That's the actual service and it includes GA, or at least it did earlier.
I went through a visa application process for the UK over the past few months. The main gov.uk site is a very good website for finding information, well designed, works on mobile, etc. Coming from the US, that was quite refreshing -- there's no equivalent in the US as everything is scattered across 100 different agency websites in 50 states.
However the "business logic" of gov.uk is still sorely lacking. For the actual visa application process and payment, I was bounced around between 4-5 different third party websites handling different aspects of the process. I'm sure further integration with gov.uk is on the roadmap, and it will certainly be nice.
As a new resident of the U.K., though, I have to admit I've been pleasantly surprised and very happy with the gov.uk website so far.
However the "business logic" of gov.uk is still sorely lacking. For the actual visa application process and payment, I was bounced around between 4-5 different third party websites handling different aspects of the process. I'm sure further integration with gov.uk is on the roadmap, and it will certainly be nice.
As a new resident of the U.K., though, I have to admit I've been pleasantly surprised and very happy with the gov.uk website so far.
Canada's is same way. I am from India, and been in US for about half a decade. US's process is completely old school.
Canada had plans to integrate all citizen services through one account dashboard, curious to see how countries roll-out services like those in next decade or so.
Canada had plans to integrate all citizen services through one account dashboard, curious to see how countries roll-out services like those in next decade or so.
It will be especially difficult in the US where many of those services are federated across all fifty states.
If you haven’t heard of this before there’s a good introduction to the project at https://gds.blog.gov.uk/2015/07/23/making-payments-more-conv...
Linked from that: "Nearly two million adults in the UK do not have a bank account"
http://www.bbc.com/news/business-31830117
http://www.bbc.com/news/business-31830117
Related: http://www.moneysavingexpert.com/banking/basic-bank-accounts
There is actually a legal requirement for banks to offer no-credit no-fee accounts, in order to help people get into the banking system and take advantage of the associated discounts, but obviously they don't advertise it much.
There is actually a legal requirement for banks to offer no-credit no-fee accounts, in order to help people get into the banking system and take advantage of the associated discounts, but obviously they don't advertise it much.
I lived in England for about a year in 2009 - 2010 and I never had a bank account there. I was willing to open one, but a law (which probably existed to prevent fraud and laundering) made it very hard to do so without proof of permanent residence in the UK, which I did not have. Eventually I decided it was easier for me to upgrade my French Mastercard to the Gold level, where I had no extra fees when withdrawing or paying in pounds (nowadays I think you need Platinum for that).
As a French national you would only need 2 things to open a UK bank account: your French passport and some kind of document that shows you have a UK address.
Proof of address used to be easy as any utility bill would do, but now days it's trickier because so much is done online and paper bills don't get sent out much any more! And, of course, it's a problem if the bills at your house are in someone else's name. (They won't accept print outs from the Internet for obvious reasons...)
However, if you're registered for paying tax in the UK then you would certainly have a letter from Jobcentre Plus or HMRC showing your address. This would be accepted by your bank.
Another option is to get a UK driver's license, which is pretty easy and inexpensive if you already have a driver's license from your (EU) home country.
Proof of address used to be easy as any utility bill would do, but now days it's trickier because so much is done online and paper bills don't get sent out much any more! And, of course, it's a problem if the bills at your house are in someone else's name. (They won't accept print outs from the Internet for obvious reasons...)
However, if you're registered for paying tax in the UK then you would certainly have a letter from Jobcentre Plus or HMRC showing your address. This would be accepted by your bank.
Another option is to get a UK driver's license, which is pretty easy and inexpensive if you already have a driver's license from your (EU) home country.
If only they accepted PDFs and banks actually digitally signed the PDFs they create for you to download
Not accepting printouts is ridiculous. It's trivial to fake a letter.
I had a similar issue when I was opening a bank account a while ago. I didn't actually get any bills in the mail, so I printed off my ISP bill, which was a pdf of what they send you in the mail. Obviously, the printer didn't fold it to fit in an envelope.
The person at the bank asked if it was a printout or actually from the mail since it didn't have any creases in it, they said they could only accept it if it was from the mail.
I told them I would just walk outside, fold it up, and walk back in, it was exactly the same as what you'd get in the mail. They ended up accepting it, even though technically they weren't meant to.
It's ridiculous, I don't actually physically receive mail from anything. All my bills etc. are done electronically, I even sign contracts electronically.
I had a similar issue when I was opening a bank account a while ago. I didn't actually get any bills in the mail, so I printed off my ISP bill, which was a pdf of what they send you in the mail. Obviously, the printer didn't fold it to fit in an envelope.
The person at the bank asked if it was a printout or actually from the mail since it didn't have any creases in it, they said they could only accept it if it was from the mail.
I told them I would just walk outside, fold it up, and walk back in, it was exactly the same as what you'd get in the mail. They ended up accepting it, even though technically they weren't meant to.
It's ridiculous, I don't actually physically receive mail from anything. All my bills etc. are done electronically, I even sign contracts electronically.
Good point - I wonder how many of those millions are non-permanent residents. The ID requirements are onerous, and like most countries it's easy to get stuck in a cyclic dependency loop of paperwork.
I'm happy to see that they are using GNU Guix: https://github.com/alphagov?q=guix
Every interaction I have with a gov.uk portal is a painful UX disater - most recently passport and driver license, both had a submitting payment stage. I can't imagine anyone saying 'wow look how at the gov.uk got it right' lets use their code, a glorified CMS system with forms and payments bolted on - badly - so badly.
Just rechecked it's still complete crap. They can't support the back button, no post / redirect pattern, confirm form resubmission. https://passportapplication.service.gov.uk/
Just rechecked it's still complete crap. They can't support the back button, no post / redirect pattern, confirm form resubmission. https://passportapplication.service.gov.uk/
The ‘Apply for a passport’ you linked to service is pretty old now and doesn’t reflect GDS’s current recommendations; as far as I understand it it was more of a reskin of an already existing system than anything done from the ground up. However there’s a newer service available from https://www.gov.uk/apply-renew-passport that is much more modern and actively developed. I’m not sure why they’re both still up (although HM Passport Office could probably tell you), but I’m also not sure how you got to the old one because all of the generic ‘passport’ searches I did on GOV.UK took me eventually to the newer version.
The link you posted redirects to original UX disaster after answering ten or so questions (each their own page and a click next). Seems you will only stay on the new site for booking and paying for a traditional walkin appointment.
> (each their own page and a click next)
I think it's made that way so that it works without Javascript.
I think it's made that way so that it works without Javascript.
Ah, OK. I didn’t work on it so good to know, hopefully it’ll have been completely modernised by 2019 when I need to reapply.
There are very few positive comments here, but I think it's fantastic that this progress has been made (even if it's not perfect). I had no idea the sites could be used without JS at all; that's brilliant!
[deleted]
Interesting, if you check out the tech it's mostly Java for the backend and Javascript for the front-end.
does this affect MiCard`s ?
http://www.manxradio.com/news/isle-of-man-business/micard-de...
http://www.manxradio.com/news/isle-of-man-business/micard-de...
nepotism2018(4)
This looks more like a manual. Where does it say that the infrastructure is open source ? I didn't see any source code.
Look at the section marked ‘Key Open Source components’ and click on each microservice’s name to get to the repo.
Well spotted thanks !
Read down a bit further https://govukpay-docs.cloudapps.digital/#key-open-source-com... the main components are linked to in the 'components' column. The link to the GitHub account also provide a filter on AlphaGov https://github.com/alphagov?q=pay-
I do not feel that reporting every online interaction I have with my government in the UK, back to a huge corporate in the US, is in any way appropriate. But I can't even get anyone to engage on the issue.
When I tried to raise it I got directed to a helpdesk ticket on a site run by an SV helpdesk-as-a-service company.
I appreciate that gov.uk have done some great stuff getting the UK government online, and their designs and Open Source attitude are refreshing, but this is a a serious privacy issue.