Wednesday, 14 February 2007

Hello Wayne!

Glad to see you're taking an interest as well. Any chance you could convince Jason to answer some of my questions, particularly re: Postal votes & why the heck GNU.Free is still available?

Brett Kimberlin

Just came across this article on the Time magazine website about a very strange individual who seems to be at the root of some of the anti-eVoting movement in the US. I'll let you draw your own conclusions...

Tuesday, 13 February 2007

Still there

The source for GNU.Free is still available at the j-dom.org site (linky). I'm still unclear as to why this tremendous threat to democracy is still available online, particularly since the author now feels that eVoting is the worst thing to happen to the world since the A-bomb, why hasn't it been removed? To prove his programming credentials? In the vain hope that someone, somewhere will pickup and finish what he couldn't? Who knows. We can only hope that common sense will prevail and this blot upon the coding landscape be removed, won't someone please think of the children?

Monday, 12 February 2007

Choice quote

"There are concerns about voters' perceptions of these issues. Electronic voting is potentially far more secure than the existing system. At present, I could walk into the polling station, say that I was Mr. Smith of 23, the High street, get a ballot paper, and vote. That system is insecure, but we still have confidence in it because if the real Mr. Smith comes along later and is told that he has already voted, he can prove his identity. It is therefore clear that the other person is the imposter, and people will not lose confidence in the system.

The potential biggest difficulty in the electronic voting pilots will be when Mr. Smith arrives at the polling station and is told that he has already voted electronically. The assumption might then be that someone in his household has stolen his voting card, pin number and user ID. In the same way, banks assume that someone who queries a transaction has had their card and pin number stolen and is at fault for not keeping them secure.

Such problems will challenge voter perceptions, and they raise important questions, particularly given our curious confidence in a system that is the most insecure that we could possibly create and does not even require us to produce ID when we arrive at the polling station. Those questions will be dealt with only by a clear independent report, and I suggest that the Electoral Commission should have that major responsibility."

Couldn't have said it better myself, taken from : http://www.publications.parliament.uk/pa/cm200102/cmstand/deleg3/st020423/20423s03.htm

Wednesday, 31 January 2007

ORG - eVoting campaign

Happy new year. Sorry it's been a while since my last post, the joys of Christmas and the New Year huh? Well the DCA have revealed which authorities are running pilots this year and the nay-sayers are off!

Looks like the Open Rights Group have teamed up with our friend Mr Kitcat for their opposition to the May 2007 eVoting Pilots.

Unfortunately for them they've let him produce a lot of the materials which has lead to more of the usual nonsense being spouted (from the briefing pack):

"Voting is a uniquely difficult question for computer science: the system must verify your eligability to vote; know whether you have already voted; and allow for audits and recounts. Yet it must always preserve your anonymity 4 and privacy"

As we full know voting in the UK is not anonymous and the only reference to this fact (despite the references to constant anonymous votes) is left until the footnotes at the end of the document. Burying the bad news hey?

"To prevent ballot stuffing, we must mark your vote so that we can be sure it came from a real voter, yet we cannot trace this vote to you personally."

Under judicial oversight we can. You might not like the current law, you may wish to challenge the current law, but the current law is the current law. Either lobby Parliament to change it or live with it. It probably does more to protect you than a completely anonymous vote anyway (ooh there'll be letters on that one).

Anyway, even if we lose the requirement to tie a vote to the voter, we can still tie the vote to the credentials (anonymous of course) that were used to cast the vote. Surely that helps significantly?

"Indeed TV production companies encourage multiple-voting as a way to increase their revenue from each vote cast. For the very enthusiastic fan, software is available on the internet which automates dialing, allowing a single individual to vote hundreds of times."

Say that again into my good ear would you? The point seems to be that IVR channels in elections are bad because people will stuff them... yes those credentials allow you to vote as many times as you want and every vote counts. No really. Little know secret that only us eVoter advocates know about. Watch out for some surprises in May, my diallers are ready, and the extra 10 phone lines have been ordered from BT!

Jason then proceeds to do a lovely bait and switch around postal voting (still haven't had an answer to the question "What's the difference between remote eVoting and postal voting for the purposes of coercion and vote selling?) :

"Nevertheless postal voting’s remote nature opens the way for voter intimidation and manipulation."

but then seems to think that

"Postal voting is still paper-based, so the scale of the fraud possible is limited by the logistics of collecting and moving the ballot papers." & "With e-voting the paper is gone, hence the scale of possible fraud becomes as large as the fraudster’s imagination."

is reasonable mitigation for postal voting and the death for eVoting. Say what? The fraudsters are working at the end points here, they still have to visit the person they're coercing or buying off regardless of whether it's eVoting or postal.

"Furthermore, software fraud can be committed long before an election, by someone far beyond the UK’s legal jurisdiction, thereby making detection and prosecution difficult."

Of course it will because I leave sensitive systems plugged into public networks when they're not needed all the time. Force of habit, my bad. And how does the attacker being outside the country make detection more difficult? There's a valid point around prosecution, but certainly not around detection.

That's enough for now...