On-line voting, technology, Black Hat, Havard
SOURCE: CNET NEWS.com
E-voting critic calls on hackers to expose flaws
Published: July 29, 2004, 12:22 PM PDT
By Robert Lemos
Staff Writer, CNET News.com
LAS VEGAS--Electronic voting systems have major security problems and hackers should make it their mission to find the flaws, an e-voting critic told security researchers on Thursday.
Speaking at the Black Hat Security Briefings here, Rebecca Mercuri, a fellow at a Harvard-affiliated research center and a noted e-voting critic, called the current voting process a statistical game of shells, one that e-voting machine makers are playing for profits.
"The data is not being collected in any meaningful way," she said. "Citizens should demand full accountability in election data at the precinct, county and state levels."
To hold voting machine makers to their promises of security, hackers should try to circumvent the systems and reveal their problems, she said. She pointed to a $10,000 reward promised by e-voting proponent Michael Shamos, a computer scientist at Carnegie Mellon University, as additional incentive.
Mercuri wants voting machine makers to stop being secretive about their security, or lack thereof, and stop legal pursuits of students and researchers that attempt to analyze their source code. She has formally called for two voting-system technology makers--machine maker Advanced Voting Solutions and verification system make VoteHere--to open up their systems as part of a contest.
The call to arms is the latest move in a debate between researchers who believe that the U.S. election system has too many security holes, and those who believe the system works well as a whole. The latest salvo in the debate has focused on electronic voting machines, known more formally as direct recording electronic, or DRE, machines.
Bev Harris, a well-known voting-security activist, joined Mercuri in the presentation, stressing that the system needs to be fixed, and soon.
"What we have is poorly designed software that isn't tested properly, and they don't use the tested software anyway," she said. "And we have bad operating procedures, and we don't follow them anyway...
Click on the link provided for more...
"