Saturday, July 28, 2018

WOTC - Re-election of Donald Trump

I asked this question in the Wisdom of the Crowd:
Do you expect President Trump to be re-elected in 2020?

Here are the responses:
39 % - No. He will lose the general election.
34 % - Yes. He is quite popular.
20 % - No. He will lose the Republican nomination.
7 % - No. He will not stand for re-election

Yes - 34%. No 66%.

See the pie chart at:
http://www.wisdomofthecrowd.sg/chart.aspx?ID=760

WOTC - Lapses reported by Auditor General

I asked this question in the Wisdom of the Crowd:

Are you concerned with the findings of the Auditor General on lapses in government agencies?

Here are the responses:
57 % - I have major concern over these lapses.
29 % - The government agencies are quite slack in doing their work.
10 % - As there are many transactions, a few oversights are to be expected.
5 % - These lapses are normal and should not raise any concern.

85% are concerned; 15% find it to be acceptable.

See the pie chart at: 
http://www.wisdomofthecrowd.sg/chart.aspx?ID=759

WOTC - Change to NS Policy

I asked this question in the Wisdom of the Crowd:
What change is required for our National Service strategy?

Here are the responses:
38 % - Continue NS. But reduce the full time consription to 1 year.
25 % - Continue NS. But reduce the reservist training.
19 % - Stop NS. Rely on professional army
17 % - Continue the current policy to have a credible defense capability.

83% want the NS commitment to be reduced or abolished. 17% want to continue it as it is.

See the pie chart at:
http://www.wisdomofthecrowd.sg/chart.aspx?ID=761

Friday, July 27, 2018

Allow limited access through the Internet

The SingHealth has disabled the connection through the Internet for access to their computer system. This is causing inconvenience to doctors who need to access the system to book appointments and to view the patient records.

I wish to suggest another approach for SingHealth IT department to handle.

a) Some of the functions are to be handled by the staff. These functions can be disabled for Internet access. They have to be accessed only through the premises, i.e. using Intranet and checking the IP addresses.

b) The doctors in the community can be allowed to access the system for restricted functions, such as booking of appointments, placement of orders or for access to patient recoreds. Each user ID can be limited to a certain number of transactions a day, e.g. 100 transactions. There is no need to allow the user to access 100,000 transactions in a day.

I hope that this approach is possible. We should not allow the system to grind to a halt or for the operations to be placed on an inefficient mode.




Cost-plus pricing

During the years before 1980, the government sold HDB flats based on cost of construction. The flats were affordable. They have to be sold back to the HDB at the controlled prices.

The HDB shops were also rented at low cost.

This was before the days of "asset enhancement".

I prefer the system of housing and shops being sold at cost of construction. This allows the cost of living to be kept low.

This is an example of cost-plus pricing, rather than market pricing.

Thursday, July 26, 2018

Separate access between Internet and Intranet

DPM Teo said that the health database should be separated from the Internet.  This will cause problems because the database is used by doctors within the community.

I like to suggest how this issue can be handled.

Within a computer system, there is a portion that is accessed through the Intranet and another portion through the public Internet.

The staff working in the hospitals can access the database using the Intranet that is not linked to the Internet. This will prevent hackers from accessing the system that is used by the staff.

The staff has more functions and the access is strictly through the Intranet - where there is better control.

The doctors in the wider community can access the database using the Internet, but the functions are restricted. They can only access one patient record at a time and the access is logged.

This approach recognizes that the public access through the Internet should be restricted to a limited function.

New MRT trains

The Land Transport Authority pays $827 million for 66 new trains. Each train has 6 cabines. So the cost per cabin is $2 million. THis excludes the support fees which increases the cost to $1,200 million..

This is obtained from a competitive tender which is participated by five tenderers.

It will be useful to compare the prices paid in other countries for their trains.

Pay attention to what is happening on the ground

It is important for senior people to pay attention to what is happening on the ground on a day to day basis.

For example, the managers of a bus company should check if the bus services are being run punctually.

If the traffic condition cause the buses to bunch together, it is beyond the control of the bus drivers or the supervisors. But the bunching could be due to lack of adherence to the time schedules.

With database technology, it is possible to identify the cases of bunching of buses and to inquire about the reason. Is this being done?

If the management does not pay attention, the rot goes down the line. The workers on the ground knows that their managers do not care, so they will also slacken.

I have observed that some buses are not captured in the bus arrival data. I suspect that these buses have faulty trackers and are not reporting their location. This has been happening for many years.

The fact that these faults are not corrected indicate that the management is not paying attention.


Hacking of SingHealth database

DPM Teo has revealed more information about the hacking of the SingHealth database.

https://www.channelnewsasia.com/news/singapore/internet-separation-should-have-been-implemented-teo-chee-hean-10558584

He talked about internet separation. I wonder how this could prevent the hacking and still allow the wider community to access the information?

The critical information is still missing. How did the hacker retrieve information from the database servers?

I have speculated in another post that it is a page that is accessible to the staff that has been hacked. I wonder if my guess is correct.

http://tklcloud.com/Feedback/feedback2.aspx?id=252

Competition commission and medical charges

Singapore has a competition law and a commission set up to enforce the law.

The purpose is to ensure that businesses do not collide to increase prices for consumers.

One of the bad decisions taken by the commission is to ask the Singapore Medical Association to remove its guidelines for charges by doctors and specialists.

When the guidelines were removed, the doctors could charge any price that they liked. In the past, if the prices were too high, the SMA would take action against the doctors.

The guidelines did not set a minimum price for doctors. They tell the doctors and the public the reasonable prices to expect.

After the removal of the guidelines, the medical fees went up to high levels. This was one of the key factors for the large increase in medical frees in recent years.

The solution is to allow the medical association to reinstate its guidelines and to play the role of protecting the interest of consumers.

It is ironic that the competition commission, which was supposed to take care of consumers, made a decision that become very bad for consumers.

http://tklcloud.com/Feedback/feedback2.aspx?id=256

WOTC - Re-election of Donald Trump

I asked this question in the Wisdom of the Crowd:

Do you expect President Trump to be re-elected in 2020?

Here are the responses:
39 % - No. He will lose the general election.
34 % - Yes. He is quite popular. 
20 % - No. He will lose the Republican nomination.
7 % - No. He will not stand for re-election
Yes - 34%. No - 66%.

See the pie chart at: 
http://www.wisdomofthecrowd.sg/chart.aspx?ID=760

WOTC - Findings of Auditor General

I asked this question in the Wisdom of the Crowd:

Are you concerned with the findings of the Auditor General on lapses in government agencies?

Here are the responses:
57 % - I have major concern over these lapses.
29 % - The government agencies are quite slack in doing their work.
10 % - As there are many transactions, a few oversights are to be expected.
5 % - These lapses are normal and should not raise any concern.

See the pie chart at: 
http://www.wisdomofthecrowd.sg/chart.aspx?ID=759

Wednesday, July 25, 2018

Customer verification

The Privacy and Data Protection Act (PDPA) requires organizations to protect the privacy of their customers.

As a result, the organizations have to verify their customer before giving information concerning the customer accounts and transactions.

But organizations have a bad way of verifying their customer. They ask the customer to give their personal ID, such as NRIC and some personal details, such as the mother's maiden name or how many accounts you have with us.

I wish to suggest a better way. Allow the customer to give a 6 digit pin number for verification. Each customer should be able to choose a number that they can remember. For example they may wish to 6 digits that they can remember easily.

This should be different from the PIN number that is used for ATM transactions. But it is really up to the customer.

The chance of a stranger knowing the PIN number is 1 in a million.

I hope that our organizations can adopt this common sense approach.

Mischievous posting

A mischievous user posted in my Feedback website a redirection link. When the feedback is displayed, it is redirected to another page, instead of displaying the content.

I found out this mischief. I have since added a check to stop any direction instruction in the content field of the feedback in these two websites:

www.tklcloud.com/feedback
www.tklcloud.com/conv

When a vulnerabilty or mischief is detected, it is possible to take remedial action.

A similar approach can be taken for hacking, such as what has happened with Singhealth. It is useful to share information about how the hacking occured, so that other websites can prevent this kind of abuse.

I do not belief in maintaining secrecy, which is a common habit in Singapore.




Low Trading Volume in Singapore Exchange

Someone told me that the Singapore Exchange is experiencing low trading volume for two reasons:
a) The customers have to complete the Customer Account Review
b) The cessation of price information on Teletext
These two factors have discouraged many old folks, who are not in touch with the latest technology, from trading in the Singapore Exchange. They contributed to the trading in the past.

Hacking into SingHealth Database

We have sketchy information about how the "sophisticated hacker" who is probably state sponsored, carried out the cyber attack.

Here are the information that were released:

a) 1.5 million records were accessed of patients who made visits during a certain period (about 5 years)

b) It seemed that the records of other patients who did not make a visit during this period were not accessed.

c) The DPM said that we have to review the connection to the internet.

d) The hacker got access to a front end terminal.

e) The data was extracted over a period of two weeks.

Based on this information, this is my quess on what had happened:

f) The hacker was able to get the login ID and password of the staff using the affected terminal.

g) There was a page that allows the staff to view the details of all the patients making a visit on a certain date or period and maybe for each hospital or all hospitals.

h) The hacker was able to use this page to patiently download the data of the patients who visited each hospital for each day.

If my guess is correct, then the vulnerability that could be prevented are:

i) All staff access should be through the intranet, rather than the internet.

I shall wait for the discussion in the Commission of Inquiry hearing to see if my guess is correct.

Tan Kin Lian

Hacking into SingHealth Database

I suggest that SingHealth should tell the public how the hacker was able to access the data.

It might get some ideas from the public on how such hacking could be prevented.

It does not help when the people involved said that it is due to "sophisticated hacking" possibly by a state sponsored organization.

Similar cases of massive hacking activities in other countries are also kept secret - I think. If there is transparancy, it is likely that a solution could be found.

WOTC - SMRT COO

I asked this question in the Wisdom of the Crowd:

Do you agree with SMRT's decision to retain the service of its COO Alvin Kek?

Here are the responses:
38 % - No. His service should be terminated.
35 % - No. He failed to set a good example to his subordinates by commiting a criminal offence. 
19 % - Yes. His drink driving offense is not related to his work performance. 
8 % - Yes. A demotion is an appropriate punishment.

See the pie chart at: 
http://www.wisdomofthecrowd.sg/chart.aspx?ID=758

WOTC - NS deferment for Ben Davis

I asked this question in the Wisdom of the Crowd:

How do you describe Mindef's decision to deny NS deferment for Ben Davis?

Here are the responses:
47 % - They are destroying the passion and career of young men.
27 % - They should be more flexible.
18 % - They are consistent in applying the policy on NS deferment 
9 % - Every male should serve NS diligently 

See the pie chart at: 
http://www.wisdomofthecrowd.sg/chart.aspx?ID=757

WOTC - PAP leaders

I asked this question in the Wisdom of the Crowd:

How do you describe the current PAP leaders

Here are the responses:
60 % - They look after their own interest.
33 % - They are incompetent.
6 % - They are competent 
2 % - They work hard to take care of the problems facing the people.

See the pie chart at: 
http://www.wisdomofthecrowd.sg/chart.aspx?ID=756

Blog Archive