E-voting's Rush to Failure
Computerworld - In the wake of the painful experiences of 2000, the choice of the mechanism used to record and tally votes in this year's presidential election may be almost as controversial as the battle between the candidates. Unfortunately, a hefty portion of state and local jurisdictions have prematurely adopted electronic voting systems.
E-voting in this year's election is a terrible idea because of both real technical limitations and the perception that the systems are unreliable and vulnerable to tampering. That's something of a problem, considering more than 30% of all voting in the election will be done on electronic machines.
This isn't just a public relations issue or one that will go away when citizens get used to the technology. A mounting record of problems with e-voting has tarnished elections in Georgia, California and Texas, among other places, and seems to justify widespread voter skepticism.
Part of the problem arises from the complexity of e-voting systems. The code that makes up these systems is so large that there's no efficient way for election officials to ensure that it's free of malware or to completely debug it, according to testimony Johns Hopkins University professor Avi Rubin gave before the U.S. Election Assistance Commission this spring.
The technology simply isn't ready to be used for the most basic and critical function in any democracy. And even if it were, the processes and protocols needed to monitor even high-performing systems aren't in place, judging by the report from IT security experts assembled by the Brennan Center for Justice at New York University School of Law and the Leadership Conference on Civil Rights. The panel's mandate was to devise a strategy for ensuring the security of touch-screen direct-recording electronic (DRE) voting systems.
The recommendations of the group are all eminently sensible: Train all election workers on security procedures. Develop random testing procedures to detect malicious code or bugs in e-voting software. Create and follow standardized procedures for responding to security threats and incidents. You get the idea. But it's a little alarming that the panel had to make these recommendations to fill an existing procedural gap.
To be fair, the chief recommendation of the panel isn't so obvious, and following it is essential to the success of any e-voting system. According to the report, each jurisdiction that plans to use an e-voting system should hire a well-qualified independent security group to evaluate the system's potential for failure and vulnerability to attack. The outside security team should be free of ties to systems vendors and be



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All IT in Government White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All IT in Government Webcasts