Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

E-vote vendors submit software for safekeeping

But critics say the vendor move won't guarantee integrity of system

October 27, 2004 12:00 PM ET

Computerworld - WASHINGTON -- With less than a week to go before the presidential election and concerns still lingering about the integrity and security of the software used by tens of thousands of electronic voting machines, five voting machine makers agreed to submit their software to the National Software Reference Library (NSRL) for safekeeping, federal officials said yesterday.
While the move to store the software for comparison in the event of questions about the integrity of e-voting systems has been positively received, the decision comes more than three months after the U.S. Election Assistance Commission officially called on the vendors to submit their software to the NSRL.
In a July 13 advisory letter, EAC Chairman DeForest Soaries said that doing so would "facilitate the tracking of software version usage," a critical concern for some observers who say vendors have in the past installed patches and upgrades prior to and during elections without those pieces of software having been inspected.
The NSRL is designed to collect software and incorporate file profiles computed from the software into a reference data set (RDS) of information. The RDS can be used by law enforcement, government and industry organizations to review files on a computer by matching the profiles in the RDS. The National Institute of Standards and Technology will maintain the voting software library.
According to the NSRL's Web site, the five vendors that have submitted software are: Diebold Inc., Election Systems & Software Inc., Hart InterCivic, Sequoia Voting Systems and VoteHere.
Soaries also said that the EAC will solicit information about suspicious electronic voting system activity, including software programming, and, if necessary, will request aggressive investigation from the U.S. Department of Justice Elections Crimes Branch. The EAC will also document incidents and record data concerning e-voting equipment malfunctions during the election.
Alfie Charles, a spokesman for Sequoia Voting Systems, said the NSRL will store "pristine copies" of vendor software "to help prepare for the inevitable challenges that take place whenever there are close elections." He also said that "this election is likely to be the most litigated and challenged contest we have ever seen."
Security experts and grass-roots voter advocacy groups, however, are skeptical of the vendor move.
Avi Rubin, a professor at Johns Hopkins University and a leading critic of the security controls put in place by e-voting system vendors, called the reference library "smoke and mirrors." The real threat to the election, he said, is that if "the code is already rigged, storing the hashes only guarantees the malicious code will be there



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

IT Modernization in Government
As IT budgets are slashed, IT management pressures rise and legacy systems linger in government organizations, modernizing the IT infrastructure and applications has...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....