Home > PING with Aviel Rubin
Information Security magazine:
EMAIL THIS

PING with Aviel Rubin

30 Oct 2006 | By Dennis Fisher, Executive Editor, Security Media Group

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Electronic voting machines will be more widely deployed than ever before during this month's mid-term elections. To Aviel Rubin, a professor of computer science at Johns Hopkins University and co-author of a seminal 2004 report on security problems in e-voting machines, this isn't just a cause for concern, it's a matter of national security. His new book, Brave New Ballot, shows just how little has changed in the last two years.

Have electronic voting machines gotten any more secure since your initial paper?
Rubin: It's very difficult to tell because [Diebold and other manufacturers] are very secretive with their code. But if you know software, you know it isn't something that could evolve into a secure system. You can't improve an overcooked steak by cooking it more.

Is it possible to build a secure e-voting machine?
Rubin: One of the biggest problems with electronic voting doesn't have anything to do with whether they're secure, it's whether they're transparent and whether they might be rigged. And a system that's fully electronic does not give people who use it the confidence that there's any kind of audit capability, that the votes are recorded correctly and there isn't cheating. So if for no other reason than transparency, I think we shouldn't be using fully electronic systems.

How closely are lawmakers paying attention to this, if at all?
Rubin: I think it's got their attention now. There's a lot of media coverage around this issue. Lawmakers, at least every one that I know of, have to get elected so they have to be very concerned with the mechanism by which they get elected.

How much do you think the report itself affected the electoral process?
Rubin: I think it's definitely the catalyst that got things started. But I don't think it would've had the effect it did if it wasn't the right time for it. The machines were pretty widely adopted and almost nobody was questioning their security, aside from some activists and some computer scientists. So if our report gets credit for anything, it's being the first to say it in a very public way that got everyone's attention. The media deluge was such that they realized they were on to a story that no one had realized before.

What would be the ideal set-up for implementing electronic voting?
Rubin: In the short term the things to really press for are optically scanned paper ballots. And they can be machine-generated or hand-generated as long as the voter has a chance to verify them. In the long term, I'm increasingly impressed by the cryptographic solutions. These solutions allow you to verify not only that your vote was recorded, but that it was in the final tally. So they give you a lot more than we have today. But they are quite opaque to people. Even with a Ph.D. in math or computer science you can have a hard time understanding how they work. And then there's the issue of recovering if the software's failing and you just don't realize it. What do you do at the end of the election if the software wasn't working right? I think we're a long way off, but in my lifetime I hope to see voting on these types of systems.

BROWSE BY TAG
Information Security Laws, Investigations and Ethics,   Information Security Management,   Application and Platform Security,   Software Development Methodology,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Software Development Methodology
Microsoft extends SDL program, adds Agile development template
Malware in Google attacks uses spaghetti code
Self-defending Web applications thwart attacks
Information security book excerpts and reviews
Software piracy group offers cash to whistleblowers
Quiz: How to build secure applications
How to detect software tampering
Developers Need Help with Security Errors
Should security tests be part of a software quality assurance program?
Does an EULA make it truly illegal to decompile software?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
FERPA  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts