...[Mallory intercepts and modifies voting messages]...

Yep, that's a threat that people a whole lot smarter than Drew Johnson
(JamBoi) have analyzed. I'm one of those smarter people, but people
much smarter than me have thought about it too. It's been discussed at
great length on the OVC-DEV list, about a year and half back.

None of it has anything to do with XML. It was very well analyzed (in
much more precise form), in Scheier's excellent _Applied Cryptograph_
(that people have mentioned), years before XML existed.

Some of those people whose intelligence and knowledge is elephantine
compared to Johnson's myrmicine dimensions have proposed the XML
signature standard. I am not per se advocating these particular
cryptology techniques, but the range of concerns are long familiar
among XML developers:

> unique data format and transport protocol "OVCML"
> I mentally add months onto the R&D time

For actual attackers, the addition is *minutes*, not months, of course.

If I seem shortsighted to you, it is only because I have stood on the
backs of midgets.

