U.S. Army Warns Microsoft To Back Off
declan writes "My CNET News colleague Ina Fried has written an interesting article today about how the U.S. Army has told Microsoft to stop sending free CD-ROMs of Office 2003 to government employees. In what's effectively a cease and desist order, the Army said: 'Your offer of free software places our employees and soldiers in jeopardy of unknowingly committing a violation of the ethics rules and regulations to which they have taken an oath to uphold.' Whoops! Perhaps this is Microsoft's latest way to fight free software at the Pentagon. Remember that just 8 months ago, the Army paid $471 million for Microsoft licenses."
I just returned from days of meetings that involved folks from the NMCI group, NSA, NIST, DoD, NAVSECGRU , CyberCorps and lots of others. I can assure you that within this area of the Fed (cyber-warfare, crypto, security, intel, etc.) that MS is a laughing stock. In the past this hasn't mattered terribly, but you have to understand that now things are very different. NSA/NIST (partnering as NIAP) now set the standard that all other agencies from the CIA down to the Dept. of Ag MUST follow. They establish the common criteria, define new directives and standards, etc. etc. aud nausiem. While MS isn't being thrown out, they are being gelded. It is a matter of time until the attitude held by these folks permiates the Fed as a whole. Linux is being pushed not becuase it's free, but because it's more readily secured. Much talk was bantied about on lots of OSS packages. I personally gave an impromptu class after hours to some of the less technical folks on installing and using Thunderbird + Enigmail + WinPT (GPG). Perhaps Linux/OSS truly is viral. It certainly is spreading as if it were. Keep the faith my friends.
The $20 / $50 rule is one of the key rules on employees accepting gifts from sources outside the government. This information paper is designed for employees of the Department of Defense (DoD).
1. General rule against gifts. DoD employees are generally prohibited from accepting gifts that are from a "prohibited source" or that are offered "because of the employee's official position." [5 CFR 2635.202(a)]
2. Definitions. The definition of "prohibited source" includes companies and organizations that do business or seek to do business with DoD. [5 CFR 2635.203(d)] A gift is offered "because of the employee's official position" if it is offered because of the status, authority or duties associated with the employee's Federal position. [5 CFR 2635.203(e)] "Market value means the retail cost the employee would incur to purchase the gift. An employee who cannot ascertain the market value of a gift may estimate its market value by reference to the retail cost of similar items of like quality." [5 CFR 2635.203(c)]
3. Exceptions. There are about 30 exceptions to the general rule against gifts. One exception, which is called the $20 / $50 rule, provides that an employee may accept gifts of up to $20 in market value per source per occasion, so long as the total market value of the gifts received (under this rule) from one source does not exceed $50 in a calendar year. [5 CFR 2635.204(a)] One may not accept cash under the $20 / $50 rule. [5 CFR 2635.204(a)]
4. Examples. Here are two examples of gifts that may be accepted under the $20 / $50 rule. First, an employee who gives a speech as part of her official duties may accept a thank you gift having a value of $20. Second, an employee may accept three $16 lunches from a DoD contractor in a calendar year.
5. Buying down to $20. If you are offered a gift that has a value over $20, you may not "buy the gift down" to $20. [5 CFR 2635.204(a)] For example, if you are offered a $21 ticket to a baseball game, you may not pay $1.00 to whomever is offering the ticket, and then accept the ticket under the $20 / $50 rule.
6. Combining items. If you are offered two separate items on the same occasion, and each item has a value under $20, and the items together have a value over $20, you may accept one of the items and decline the other. For example, if you give a speech as part of your official duties, and you are offered a $6 coffee mug and a $15 pen as thank you mementos, you may keep one or the other, but not both. [5 CFR 2635.204(a)(Example 2)]
7. Different sources on the same occasion. Under the $20 / $50 rule, you may accept gifts of up to $20 in value "per source per occasion." This means that the $20 limit applies separately to each company or organization that is offering you a gift on a particular occasion. Here is an example from the ethics regulation.
During off-duty time, an employee of the Department of Defense (DoD) attends a trade show involving companies that are DoD contractors. He is offered a $15 computer program disk at X Company's booth, a $12 appointments calendar at Y Company's booth, and a deli lunch worth $8 from Z Company. The employee may accept all three of these items because they do not exceed $20 per source, even though they total more than $20 at this single occasion. [5 CFR 2635.204(a)(Example 5)]
8. Impermissible gifts. If an employee receives a gift that cannot be accepted under the $20 / $50 rule (or any of the other gift rules), the employee must do one of the following (unless the item is accepted by the agency under specific statutory authority). If the gift is a non-perishable tangible item, the employee must either return the item to the donor or pay the market value of the item to the donor. If the gift is a perishable item and it is not practical to return the item (such as flowers or a fruit basket), the item (at the discretion of the employee's supervisor or ethics official) may be given to an appropriate charity, may be sha
Well the Navy has sold its IT soul to the NMCI contract that stipulates that all desktops and servers and office productivity tools will be MS products. All others will be classified as "legacy" applications and will be schedules for rehosting. This includes all things that touch the network - databases, webservers, etc.
As the deployment is progress they are finding that people do more then send email and write word documents and they have to leave some of the existing infrastructure intact and many have two desktop machines - the nmci email kiosk and the other machine where work gets done. This neither lower costs or inceases security - both goals of the contract.
Also if they are successful the Navy will be a sitting duck with a monoculture IT infrastructure and a successful exploit will be able to cripple it in short order.
The NMCI contract is the largest IT contract ever and you hear scant little about it in the press. I sure hope some watchdog group or even the GAO start monitoring the progress of this contract.
My productivity will fall to zero when they take my legacy machine away, but it WILL happen. They have determined that nobody is using the NMCI machines BECAUSE the legacy machines are still available. They are fully aware that the NMCI network is pure shit, but the only way it will be fixed is when people actually USE it and start opening trouble tickets to address problems, and the only way people will use them to find these problems is when they no longer have legacy machines. I expect to walk into my office and find it gone any day now.
To ensure perfect aim, shoot first and call whatever you hit the target
I also work for SPAWAR in an aquisitions branch, but evidently not under the same center as you, since we pay out the nose for each and every MS product (and everything else) we buy. GSA pricing is usually a joke - we end up paying retail for virtually anything IT related. The problem with alternatives is not one of user ability, because as one of the above posters mentioned, the right linux distro would work just as easily as Windows for most navy users. The problem is change (of any kind).
With very few exceptions, we buy nothing but Windows and Intel for PC aquisitons, since woefully few of the senior engineers and scientists (who really dont deserve those titles anymore) know any different. Since it is so hard to fire a govie, the govt. is bloated with people who haven't meaningfully increased their techincal skillset since they graduated from college in the 70s.
SPAWAR, at least, recognizes their problem and a few people with a clue are trying to change things. They are trying to clear out some of the good-old-boy cruft and the stagnant dead weight. Some of the fresh-outta-school new professionals (myself included) are trying to exert what little influence we have to push for some alternative platforms and architectures in the work place. I have a few linux boxes up for internal uses and am working on a mosix cluster, among other things. Not much, but I guess its a start, and the bigwigs are starting to take notice.
We joke that if some monster new windows worm went tearing through the network we would be the only ones with functioning computers. Unfortunately, its probably not so far from the truth.