Live data from Hacker News

The Insecurity of Secret IT Systems

schneier.com

11–20 of 26 posts

Re: The Insecurity of Secret IT Systems

#12

Regarding voting systems, all we ever needed was open source software. Voters were incorrectly recording their paper ballots. A PC with a punch card machine attached and running open source software could have correctly punched these cards. And we also could have had another system that read the cards right there in the polling place that the voter could use to confirm their ballot was correctly encoded. Or an phone…

As much as I agree that the software should be open source, that's not nearly enough. There are large numbers of rootkits and vulnerabilities for Linux, for instance. There would be a huge incentive to modify the software of these machines in some undetectable way in order to influence elections.

There's been a lot of scholarly literature written on how to do secure electronic voting, and I understand the consensus is that some sort of voter verifiable paper audit trail is the only way to match or exceed the security of the paper ballot system.

Re: The Insecurity of Secret IT Systems

#13

Regarding voting systems, all we ever needed was open source software. Voters were incorrectly recording their paper ballots. A PC with a punch card machine attached and running open source software could have correctly punched these cards. And we also could have had another system that read the cards right there in the polling place that the voter could use to confirm their ballot was correctly encoded. Or an phone…

I think open source is not the end solution, though is a great solution.

As with any software there are always vulnerability just waiting for someone to exploit. Before we say "oh government contractors suck", judge our any private product out there. Github is not open source and yet people constantly find vulnerability.

What we need is proper security audit, done by the right professionals and done continuously. The problem is security professionals are very very expensive! That may be the incentive to open source since then the crowd can be your testers. But the thing is: how do we apply to private customers? Not every company can open source their work. What can we do? Are security audit tools out there enough? Can we do better?

Should military stuff be open source? Because of national defense? Well, voting system is a national priority and if hacked can mean a big national crisis. So why shouldn't F16 software be open-sourced? It would make system cheaper, more reliable in theory. No one wants to do that. So if you believe in keeping military system private, how should the government keep their system secure and reliable? What tools do they get?

Trade market. They can't open source their trading system. How can they make the system more secure and reliable? What tools can they use while keeping some maintenance cost down? (maybe a bad example since trading system is managing TONS of money).

Re: The Insecurity of Secret IT Systems

#15
"Smart security engineers open their systems to public scrutiny, because that’s how they improve. The truly awful engineers will not only hide their bad designs behind secrecy, but try to belittle any negative security results."

Or restated:

All bad engineers try to hide their work from the public, therefore all good engineers try to show their work to the public. I'm sure there is a logical fallacy in there somewhere.

Re: The Insecurity of Secret IT Systems

#16
post #12

Regarding voting systems, all we ever needed was open source software. Voters were incorrectly recording their paper ballots. A PC with a punch card machine attached and running open source software could have correctly punched these cards. And we also could have had another system that read the cards right there in the polling place that the voter could use to confirm their ballot was correctly encoded. Or an phone…

As much as I agree that the software should be open source, that's not nearly enough. There are large numbers of rootkits and vulnerabilities for Linux, for instance. There would be a huge incentive to modify the software of these machines in some undetectable way in order to influence elections. There's been a lot of scholarly literature written on how to do secure electronic voting, and I understand the consensus i…

stretchwithme addresses that in the third (and subsequent) sentences of his comment. I know that's a lot to read, but still. They were in fact describing a voter-verified paper trail system.

Re: The Insecurity of Secret IT Systems

#17
post #12

Regarding voting systems, all we ever needed was open source software. Voters were incorrectly recording their paper ballots. A PC with a punch card machine attached and running open source software could have correctly punched these cards. And we also could have had another system that read the cards right there in the polling place that the voter could use to confirm their ballot was correctly encoded. Or an phone…

As much as I agree that the software should be open source, that's not nearly enough. There are large numbers of rootkits and vulnerabilities for Linux, for instance. There would be a huge incentive to modify the software of these machines in some undetectable way in order to influence elections. There's been a lot of scholarly literature written on how to do secure electronic voting, and I understand the consensus i…

with electronic voiting the wrong question is often asked...

"How can we build a fraud proof system"

While it is a nice ideal, it is not realistic...

The real question should be

"How can we build a system that has less fraud than todays system"

That is far more achievable, today no one really knows how rampant voter fraud is, if at all, due to the nature of the outmoded, non-accountable system the trust is placed with corruptible humans at the polling places, I personally believe that fraud is rampant.

Re: The Insecurity of Secret IT Systems

#18
post #16
post #12

Earlier quoted context omitted.

As much as I agree that the software should be open source, that's not nearly enough. There are large numbers of rootkits and vulnerabilities for Linux, for instance. There would be a huge incentive to modify the software of these machines in some undetectable way in order to influence elections. There's been a lot of scholarly literature written on how to do secure electronic voting, and I understand the consensus i…

stretchwithme addresses that in the third (and subsequent) sentences of his comment. I know that's a lot to read, but still. They were in fact describing a voter-verified paper trail system.

He appeared to specifically exclude that possibility by requiring a machine to read it.

This entire discussion is predicated on a mistaken assumption that we have significant levels of fraud – often asserted but never convincingly supported – or that electronic systems reduce those odds. We'd be much better off sticking with a simple optical system which can be reviewed and scored by hand and providing a computer-assisted system to help those who have difficulty to fill in that ballot. As a plus, this system is really cheap and easy to scale rather than requiring a bunch of expensive computers and support staff for an infrequent event.

Re: The Insecurity of Secret IT Systems

#19
post #12

Regarding voting systems, all we ever needed was open source software. Voters were incorrectly recording their paper ballots. A PC with a punch card machine attached and running open source software could have correctly punched these cards. And we also could have had another system that read the cards right there in the polling place that the voter could use to confirm their ballot was correctly encoded. Or an phone…

As much as I agree that the software should be open source, that's not nearly enough. There are large numbers of rootkits and vulnerabilities for Linux, for instance. There would be a huge incentive to modify the software of these machines in some undetectable way in order to influence elections. There's been a lot of scholarly literature written on how to do secure electronic voting, and I understand the consensus i…

If you can look at the paper ballot it produces and confirm your choices are punched, there's no problem.

And people were already looking at their ballots so they could punch the right holes.

Even if only 5% checked their physical ballot to make sure its right, that's enough to detect something fishy.

Just to be clear, the actual physical ballots would still be counted they way they were before 2000. The only thing that needed to be improved was the punching of the holes.

So have a machine punch and have the human visually confirm. Or the phone app or a myriad of other machines confirm. They can't all be controlled by one root kit.

Re: The Insecurity of Secret IT Systems

#20
post #16
post #12

Earlier quoted context omitted.

As much as I agree that the software should be open source, that's not nearly enough. There are large numbers of rootkits and vulnerabilities for Linux, for instance. There would be a huge incentive to modify the software of these machines in some undetectable way in order to influence elections. There's been a lot of scholarly literature written on how to do secure electronic voting, and I understand the consensus i…

stretchwithme addresses that in the third (and subsequent) sentences of his comment. I know that's a lot to read, but still. They were in fact describing a voter-verified paper trail system.

acdha, I proposed machines and apps voters could use to confirm their ballot was punched correctly, to make sure the first machine isn't compromised.

These apps could be made by anybody with access to the details of the particular ballot. In other words, those in control of voting can't control a myriad of independent app developers.

People could also do what they did before: put their ballot into the old voting device and look at the holes themselves.

The actual counting of the ballots could be done however it was done before.

Post reply on HN