Re: Voting systems with no OS (was: Re: disclosure; no OS? [Re: OVC-discuss Digest, Vol 36, Issue 10])

From: Fred McLain <mclain_at_zipcon_dot_net>
Date: Sat Nov 03 2007 - 14:07:36 CDT

On Nov 2, 2007, at 7:55 PM, Danny Swarzman wrote:

> Fred,
>
> When you have an embedded system, the software has to be loaded
> somehow. Whatever means you use to load it is the thing that needs
> to be open.

That's the easy part, put it on a memory card or any other mass
storage media and ship it with the box.

>
> When you run on COTS, anybody can reproduce everything you do to
> develop the software.

What gives you that idea? I wrote programs for the RSX-11M operating
system some 20+ years ago. It was COTS. Go reproduce it. At best
you'll get some flavor of it, but not the actual OS I was writing to.

My home linux box updated itself 3 times this last week alone, so it
too isn't the same OS I wrote code for a week ago.

>
> How can the public verify the code on an embedded system?

I would so dearly love to answer this question. Unfortunately that is
exactly what I am working on for my "paying gig" and can not disclose
details. Once my employer files the patent applications involved it
will be public knowledge and I expect I can point you to the answers.

Do you have any response to my other points?

        -Fred-

>
> -Danny
>
> On Nov 2, 2007, at 7:26 PM, Fred McLain wrote:
>
>>
>>> - Ability to load programs. If you depend on an external system to
>>> load the programs, then that external system would require the
>>> same level of scrutiny.
>>
>> Nope, that is nonsense. You do not want to have an ability to
>> "load programs" in a critical system, especially from an "external
>> system". Nor do you want to have any connection to an external
>> system. Voting systems need to be isolated from the network. I've
>> said before, "you can't open a door that doesn't exist".
>
> _______________________________________________
> OVC-discuss mailing list
> OVC-discuss@listman.sonic.net
> http://lists.sonic.net/mailman/listinfo/ovc-discuss
> By sending email to the OVC-discuss list, you thereby agree to
> release the content of your posts to the Public Domain--with the
> exception of copyrighted material quoted according to fair use,
> including publicly archiving at http://gnosis.python-hosting.com/voting-project/

Instant Messaging (IM) Addresses:
Jabber: mclain@jabber.org
Yahoo: appworx_fred, schemalogic_fred
MSN: appworx_fred@hotmail.com, schemalogic_fred@hotmail.com
AIM: mclain98021
ICQ: 6947005
GTalk (Jabber): mclain98021@gmail.com
Skype: fmclain

_______________________________________________
OVC-discuss mailing list
OVC-discuss@listman.sonic.net
http://lists.sonic.net/mailman/listinfo/ovc-discuss
By sending email to the OVC-discuss list, you thereby agree to release the content of your posts to the Public Domain--with the exception of copyrighted material quoted according to fair use, including publicly archiving at http://gnosis.python-hosting.com/voting-project/
==================================================================
= The content of this message, with the exception of any external
= quotations under fair use, are released to the Public Domain
==================================================================
Received on Fri Nov 30 23:17:08 2007

This archive was generated by hypermail 2.1.8 : Fri Nov 30 2007 - 23:17:31 CST