August 9th new NICS system

Frankly, given all the unpaid overtime I, and so many other people worked to fix all the code issues, it was kind of a kick in the balls when nothing happened and everybody was like, 'See? Nothing Happened. Look at all the money we wasted.' Yeah, dumbasses, we reviewed and tested 2 million lines of code to make sure nothing happened.

You should know better- nobody gives a shit when you do your job correctly in this industry except maybe your boss and a few non-dumb people around you that understand, and maybe a few other industry people. Otherwise, in computing most people that make things work (whether its coding, IT, infrastructure etc) are pretty much invisible. We're not much different than sanitation engineers or janitors that have a lot of skills. (People rarely notice when guys do these jobs exceptionally well, only when the job is exceptionally poor).

-Mike
 
You should know better- nobody gives a shit when you do your job correctly in this industry except maybe your boss and a few non-dumb people around you that understand, and maybe a few other industry people. Otherwise, in computing most people that make things work (whether its coding, IT, infrastructure etc) are pretty much invisible. We're not much different than sanitation engineers or janitors that have a lot of skills. (People rarely notice when guys do these jobs exceptionally well, only when the job is exceptionally poor).

-Mike
It's like being a plumber. You can do masterful work and no one will ever notice. The work only gets noticed when something goes wrong.
 
I manage a gun store here in Kansas, and used the new system yesterday. It sucks balls and you can now be a tranny on the part where it asks for the buyers gender. The choices are male, female, and unknown, whatever the hell that is. It's super clunky too and buggy as all hell. Typical government work.

Aside from the "unknown" option for "sex", how does it suck? Bad interface? Too slow? Crashes? Something else?
 
It's like being a plumber. You can do masterful work and no one will ever notice. The work only gets noticed when something goes wrong.

Or in my case, people frequently perform the financial derivative equivalent of flushing 5 lbs of linked Italian sausages down the toilet. It's my fault the toilet clogged, and my fault I didn't fix it faster. And it's probably my fault I didn't anticipate that someone would want to flush 5 pounds of sausage down the toilet. (Oh, raw sausage, sorry, we only support flushing cooked sausage.)
 
Aside from the "unknown" option for "sex", how does it suck? Bad interface? Too slow? Crashes? Something else?

It crashed initially but by yesterday afternoon it was up and running, albeit slowly. One of the bugs I noticed is when you type in someone's height, the digits immediately change to "400" every time. The default font is tiny and to receive the status of the check you've got to go through excessive steps that weren't there before.
 
How easy would it be for them to pull staff off of running these checks? It defaults to a proceed after 3 days, right? Could they slow the whole country down to a 3 day wait to buy a gun if they want to?
 
How easy would it be for them to pull staff off of running these checks? It defaults to a proceed after 3 days, right? Could they slow the whole country down to a 3 day wait to buy a gun if they want to?

Obama already pulled all the staff off of processing NICS denial appeals. So, pretty easily I'd say.
 
Obama already pulled all the staff off of processing NICS denial appeals. So, pretty easily I'd say.

And I'm guessing some (if not all), also processed/reviewed UPIN//VAF applications.
Some here are reporting a year or more turn around time.
 
Thinking back, NES insider information is always of the highest quality, as on target as bullets at an NES shoot.
 
I used the new echeck system the other day. I agree it's a downgrade right now in ease of use and readability, extremely klunky and hard to find stuff

It will get easier as people get familiar with it and there will be less bitching.

Ie the height example from above, there were two boxes on the old one, feet and inches, now it's just height. Instead of doing 5 and then 8, you now enter 508

Tabbing through fields is weird right now

Little things like that, but I didn't have any issues completing a check.

Sent from my SM-G900V using Tapatalk
 
Ie the height example from above, there were two boxes on the old one, feet and inches, now it's just height. Instead of doing 5 and then 8, you now enter 508

Sent from my SM-G900V using Tapatalk

They should have kept the 2 fields. if they wanted only one field they should have done Height in inches. It would even have been preferable to do height in feet with decimals over mixing 2 units of data in a single field. this is pretty basic stuff..
 
They should have kept the 2 fields. if they wanted only one field they should have done Height in inches. It would even have been preferable to do height in feet with decimals over mixing 2 units of data in a single field. this is pretty basic stuff..

As a software engineer, I am personally appalled and professionally insulted that anyone would use one field for height in that manner, and actually intend for it to be used that way.
 
As a software engineer, I am personally appalled and professionally insulted that anyone would use one field for height in that manner, and actually intend for it to be used that way.

I bet what happened was the specs specified one field (because they didnt actually look at the existing system when they wrote them.) and didn't specify the units, and after they went live they had an oh Sh!t moment and they came up with this stupid strategy to work around the problem.
 
Agree, but it's a bit different from putting your name, SSN, DOB, address, etc. Over unsecured WiFi.

This such an egregious violation of 210 CMR 17 that I spewed coffee. Hope their WISP is up to date, because I believe in the event of a breach, Maura would lend special attention to an FFL with regards to fines, etc. And E&O insurance doesn't cover being intentionally dumb.
 
The field probably originated in India and was intended for centimeters then some imbecile decided to port the code for use here and couldn't figure out how to make it work so they just mashed it together. Because adding another "input" in the form is so ****ing difficult. [rolleyes]
 
The field probably originated in India and was intended for centimeters then some imbecile decided to port the code for use here and couldn't figure out how to make it work so they just mashed it together. Because adding another "input" in the form is so ****ing difficult. [rolleyes]

BUT THE XTRA FIELD MAKES THE UI 'clunky' ....and stuff! [wink]

It won't run on an 8086 processor anymore
 
This such an egregious violation of 210 CMR 17 that I spewed coffee. Hope their WISP is up to date, because I believe in the event of a breach, Maura would lend special attention to an FFL with regards to fines, etc. And E&O insurance doesn't cover being intentionally dumb.

Although I used to do computer support for small companies, I'm no expert on computer security and I left the computer business behind in 2006 . . . a lot has changed since then.

When a FFL is at a gun show, typically Carole charges them $50/show to use the WiFi that the facility has (Big E, Shriner's Auditorium, Best Western, etc.) and they are at the mercy of whatever security the facility has setup (I'll bet next to nothing). As the news reported last night, someone's home security cams were hacked and broadcast worldwide live. This stuff happens all the time. Proving who caused the breach is usually very difficult to impossible. And FFLs can't even read the BATFE books (CDs) that they are sent to determine what is legal, so you can't expect them to be intelligent enough to try to secure their transactions (in a store or at a show).

And the only time that the state will go after them is if they smell money they can suck out of them to feed the state coffers. They could care less about those whose identities get stolen (even the Feds only offered "after the fact" monitoring service for those affected).
 
This is no excuse

There's no reason why an FFL cant dump a SoHo firewall on that network and put their own computers behind it....this is at best 10 minutes of work....

There are a lot of really good ones out there for between 500 and 800 bucks that will handle most everything except a targeted/0-day attack

Dell now owns Sonicwall, Checkpoint has a number of well priced SoHo FW's. Barracuda.....the list of good options is lengthy.

Ignorance of risks, "don't care" and "no desire to spend the money" are the most probable reasons.

NOTE: Reasons, not excuses!
 
This is no excuse

There's no reason why an FFL cant dump a SoHo firewall on that network and put their own computers behind it....this is at best 10 minutes of work....

There are a lot of really good ones out there for between 500 and 800 bucks that will handle most everything except a targeted/0-day attack

Dell now owns Sonicwall, Checkpoint has a number of well priced SoHo FW's. Barracuda.....the list of good options is lengthy.

All way overkill for this stuff. You guys make it sound like this is fort knox or something. If someone is going to break into the system it's going to be on the back end not the front end. Not that it's impossible but it's improbable. The dumpster at an average FFL is a bigger security risk than any of this is.

-Mike
 
If I can walk down the street with an iPhone and see your WiFi you are doing it wrong. Throwing "security" cameras on an unencrypted AND visible network is simply asking to be broadcast worldwide. A few minutes and some research goes a long ways.

I'm not saying you deserve to be hacked but, jfc you may as well ride the T with wifi enabled while checking your email and bank accounts.

If you handle NPI in any manner then you need to be on top of your security. Way too much at stake for FFL's to be callous with this data. Lord knows the .gov is already bad enough at securing networks.
 
Last edited:
Not overkill at all if they are dealing with PII

Any dealer that cant justify a 500 dollar expense to protect their customers information doesnt deserve my business

You don't need a 500 dollar firewall to protect that stuff. A machine that isn't a pile of shit (EG, only used for official business shit, not surfing, etc) and some kind of modestly secure connection is more than enough.

Of course I'm not sure how all of these systems work. (there are a bunch of tie ins with electronic BG checks and they're not all done with the ATF web portal thing being discussed here. ) Obviously if data is stored locally on a disk for any period of time, it should be encrypted, etc.

-Mike
 
Back
Top Bottom