Experts outline e-voting security requirements
A major effort is needed to ensure election transparency, but time is short
June 30, 2004 12:00 PM ETComputerworld -
A panel of IT security experts yesterday proposed a series of detailed recommendations that they said state and local jurisdictions must act on immediately to ensure the security of electronic voting systems and the accuracy and transparency of the November presidential election.
In a report released by the Brennan Center for Justice at the New York University School of Law and the Leadership Conference on Civil Rights, four high-profile IT security experts, including Howard Schmidt, a former White House cybersecurity adviser, outlined a comprehensive strategy for certifying the security and reliability of touch-screen direct recording electronic (DRE) voting systems. Those systems will be used by 30% of registered voters in the upcoming presidential election.
While analysts in the security and elections communities praised the report, most agreed that it may have come too late for states and local jurisdictions to act upon.
Chief among the panel's eight recommendations is a call for elections officials to hire a well-qualified, independent security team to examine the potential for operational failures and malicious attacks against DRE voting systems. According to the report, such an expert security team "must be free of any business relationships with any voting system vendors or designers" and must be granted unfettered access to all software code and configuration data.
The panel also recommended that all jurisdictions contract for independent "red team" exercises to uncover any hidden physical and electronic vulnerabilities in DRE systems. And it urged election officials to make public information about the level of cooperation received from DRE system vendors.
Site-specific security procedures and physical security also weighed heavily in the panel report. For example, the experts urged jurisdictions to use "tamper tape" on all vulnerable hardware devices and to document strict procedures for repair of systems. An investigation after the 2000 election, for example, found that all 32,000 of Maryland's touch-screen terminals had the same locks and keys, making every machine accessible to anyone with one of the keys. The keys could also be easily reproduced at three local hardware stores.
In addition, systems that malfunctioned in Fairfax County, Va., were removed for repair and returned to service during election day, the report said -- raising the possibility that votes could have been altered with no process in place to spot any problems.
Margaret Luca, a spokeswoman for Fairfax County, disputed the assertion that the machines were put back into service.
She said the audit logs from each machine show that they were not returned to service on Election Day except to collect the vote at
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
IT Modernization in Government
As IT budgets are slashed, IT management pressures rise and legacy systems linger in government organizations, modernizing the IT infrastructure and applications has...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
Subscribe to Computerworld
