home *** CD-ROM | disk | FTP | other *** search
- Submitted-by: lewine@cheshirecat.webo.dg.com (Donald Lewine)
-
- In article <1pqcb6INN659@ftp.UU.NET>, jsh@teal.csn.org (Jeffrey Haemer) writes:
- > Electronic Balloting Software
-
- Great idea!
-
- >Quick-and-dirty authentication can be as simple as (1) mail
- >the ballot-request software, which then (2) generates an
- >encryption key and (3) sends it, via postal mail (wouldn't
- >want them to feel _too_ left out!) to the requester, who
- >then (4) uses the out-of-band key to encrypt the ballot,
- >which is then (5) decrypted by the balloting software and
- >(6) counted appropriately -- or at least that's the plan.
-
- The authentication can be even quicker. There is really no need to
- encrypt/decrypt the ballot. Step (3) could send several out-of-band
- passwords; One for yes, one for no, one for abstain, and so on. The
- ballotor can then send back his vote & password along with the clear
- text of any objections/comments.
-
- The passwords would prevent someone from changing a YES vote to a NO
- vote. Encryption of comments, objects and the voters name do not
- add any real security. If we are concerned that an attacker might
- change the text of a comment or objection, we need to also make sure
- that he cannot change the draft I am getting via FTP or E-Mail.
-
- Personally, I am willing to trust the internet with the plain text
- of the draft and the comments. When using plain text there is less
- to go wrong and correction is easier.
-
- >What's wrong with the plan? How can it be made better? How
- >interesting can the vote-counting software get? Should it
- >be written in perl?
-
- How about restricting the vote-counting software to be POSIX.1 and
- POSIX.2 conforming? Let's use some of the portability and verification
- tools we are already building.
-
- --------------------------------------------------------------------
- Donald A. Lewine (508) 870-9008 Voice
- Data General Corporation (508) 366-0750 FAX
- 4400 Computer Drive. MS D112A
- Westboro, MA 01580 U.S.A.
-
- uucp: uunet!dg!lewine Internet: lewine@cheshirecat.webo.dg.com
-
- Volume-Number: Volume 31, Number 33
-
-