Crypto stars sound off on e-voting, digital rights management
IDG News Service - SAN FRANCISCO -- A panel of distinguished cryptographers at the RSA Conference here weighed in on a variety of hot button issues, including electronic voting and rights management for digital media.
Speaking at the annual Cryptographers Panel on Tuesday, Ronald Rivest, co-creator of the RSA encryption algorithm, backed calls for paper ballots to supplement insecure electronic voting technology, while fellow luminaries Paul Kocher and Whitfield Diffie predicted heated battles between privacy advocates and intellectual property owners over the issue of digital rights management.
Rivest cited recent analysis of Diebold Inc. electronic voting systems after a leak of the source code for those systems as evidence that such systems were inadequate to ensure the authenticity of votes cast.
Analysis of the Diebold source code showed that the company's programmers failed to use accepted authentication methods to secure voting data and cast doubt on the ability of Diebold or other companies to patch the code in time to guarantee the results of approaching elections, including this year's presidential elections, he said.
To ensure the outcome of elections where electronic voting kiosks are used, municipalities should implement voter verifiable technology that would produce a paper copy of each ballot that is cast, Rivest said.
Speaking to an audience of fellow cryptographers and security experts, Rivest cautioned against the "digitizing" of votes. "We know only too well the difficulties of securing complex electronic systems," Rivest said. Technology companies and municipalities should "go slow," and "keep it simple," relying on paper ballots and audit trails to verify the data collected by electronic voting kiosks, he said.
Speaking after Rivest, Kocher, president and chief scientist of Cryptography Research Inc. cited "failed economies" in a number of areas of technology adoption that are causing pain for corporations and ordinary computer users.
The inability of entertainment companies to control the technology used to play their products -- music and movies -- has resulted in a flood of piracy that's hurting those companies, Kocher said. Similarly, the way e-mail is sent and received makes it easy for spammers to flood users' inboxes with unsolicited messages, he said. The technology community and the private sector need to address those issues if they want to solve problems like piracy and spam. Failing that, government regulation may be needed to mandate security standards, he said.
Concerns about piracy and terrorism may spell the end of computers and computer networks that are entirely controlled by their owners, said Diffie, chief security officer at Sun Microsystems Inc. The ongoing battle between entertainment companies and



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts