Re: draft of text for new OVC-sponsored bill

From: Ronald Crane <voting_at_lastland_dot_net>
Date: Wed Jan 28 2009 - 15:33:31 CST

Alan Dechert wrote:
> From: "Ronald Crane" <>
>> Alan Dechert wrote:
>>> From: Ronald Crane
>>>> OVC's focus on ballot printers for all voters oversells their
>>>> benefits and understates their security risks, especially
>>>> versus hand-filled, machine-tabulated paper ballot systems.
>>> This is pure opinion. You have absolutely no data with which to
>>> back this up.
>> I have identified a variety of attack forms (presentation, selection,
>> DoS, etc.) and vectors (e.g., attack the voting application
>> website/CDs/hashes/trust tree, instrument various kinds of firmware,
>> use network vulnerabilities) in this and other recent threads on this
>> list.
> Nothing whatsoever specific to the OVC system and procedures.
It hardly matters whether the attacks apply only to OVC's ballot
printer, or also to the larger class of computational ballot
presentation/selection/recording devices of which OVC's ballot printer
is a member; they're still attacks that can be used against OVC's ballot
> I don't think you even bothered to come to the LinuxWorld demo. Maybe
> you could have demonstrated your hacks there. I don't think you would
> have been successful.
Many have criticized existing vendors for asserting that attacks that
have been discovered through analysis (but that have not been
demonstrated) don't exist or can't work. Please adopt a more open
attitude toward critical review; it will only make your products better.


