<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: retrograde]]></title>
    <link>http://securityratty.com/tag/retrograde</link>
    <description></description>
    <pubDate>Fri, 07 Sep 2007 15:56:11 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-07-01 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/8f3c8a363be11b86e054f8bbcb357630</link>
      <guid>http://securityratty.com/article/8f3c8a363be11b86e054f8bbcb357630</guid>
      <description><![CDATA[The Forrester Blog For Security &amp; Risk Professionals
GRC - Why Its of LIMITED Interest to Me Mark Curphey - SecurityBuddha.com
Spire Security Viewpoint: Top Ten Strategic Security Metrics
Log...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blogs.forrester.com/srm/2008/06/it-grc-who-is-a.html">The Forrester Blog For Security &amp; Risk Professionals</a></li>
<li><a href="http://securitybuddha.com/2008/06/10/grc-why-its-of-limited-interest-to-me/">GRC - Why It&rsquo;s of LIMITED Interest to Me &laquo; Mark Curphey - SecurityBuddha.com</a></li>
<li><a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/07/top-ten-strategic-security-metrics.html">Spire Security Viewpoint: Top Ten Strategic Security Metrics</a></li>
<li><a href="http://technology.inc.com/managing/articles/200806/logs.html?partner=rss-alert">Log Management: What's in Your Log Files? -- log management -- LogLogic -- log maintenance</a></li>
<li><a href="http://bgidps.typepad.com/bgidps/2008/06/identity-manage.html">Burton Group Identity Blog: Identity Management in Retrograde Motion: Thoughts from Burton Group Catalyst North America 2008</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/324598654" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spire security viewpoint">spire security viewpoint</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/strategic security metrics">strategic security metrics</category>
      <category domain="http://securityratty.com/tag/catalyst north america">catalyst north america</category>
      <category domain="http://securityratty.com/tag/burton">burton</category>
      <category domain="http://securityratty.com/tag/retrograde motion">retrograde motion</category>
      <category domain="http://securityratty.com/tag/log maintenance">log maintenance</category>
      <category domain="http://securityratty.com/tag/mark curphey">mark curphey</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/324598654/anton18">Links for 2008-07-01 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Vote but Verify]]></title>
      <link>http://securityratty.com/article/9b34bf37d65a8994abb6fc1837791e7d</link>
      <guid>http://securityratty.com/article/9b34bf37d65a8994abb6fc1837791e7d</guid>
      <description><![CDATA[Local Rochester-area political blogger Thomas Belknap recently railed about HR 811 , interpreting its requirement of a voter-verified durable paper ballot as a small-minded banning of an attractive...]]></description>
      <content:encoded><![CDATA[	<p>Local Rochester-area political <a href="http://dragonflyeye.net/blog/2007/09/06/congress-moving-banning/">blogger Thomas Belknap recently railed</a> about <a href="http://www.govtrack.us/congress/bill.xpd?bill=h110-811">HR 811</a>, interpreting its requirement of a voter-verified durable paper ballot as a small-minded banning of an attractive future of modern networked reliable electronic voting machines.  I could not resist posting my disagreement into the comments on his blog, and perhaps I am going to convince him, as he edited out my most provocative snide political shots and left in some of my more reasoned comments.</p>
	<p>As a security person, I must point out that if machines do not produce a reliable auditable record, then all you have is a <em>fait accompli</em> fraud-blessing device.  That&#8217;s the short version of the security argument.</p>
	<p>I&#8217;m willing to <a href="http://vote.nist.gov/DraftWhitePaperOnSIinVVSG2007-20061120.pdf">go along with NIST</a> that, as of today, all-electronic systems are an important research topic, not a settled present alternative:</p>
	<blockquote><p>
The approach to software-independence used in op scan is based on voter-verified paper records, but some all-electronic paperless approaches have been proposed. It is a research topic currently as to whether software independence may be able to be accomplished via systems that would produce an all-electronic voter-verified, independent audit trail (known as software IV systems).
</p></blockquote>
	<p>A durable paper ballot requirement is not a retrograde goof, nor a rejection of e-voting.  It&#8217;s a reflection of current reality, that all-electronic e-voting implementations are asking for trouble.  Codifying an allowance for all-electronic systems today would just open the door to arguments about what&#8217;s good enough cryptographically, arguments that will be settled by folks even less competent than our representatives.  Codifying the well-understood voter-verified paper audit trail as a requirement puts an immediate crimp in the shopping spree for fancy-looking machines that are rotten inside - a shopping spree that will continue if this law isn&#8217;t passed, creating an ever-larger lump of sunk investment in pretty bad technology.</p>
	<p>A paper audit trail today isn&#8217;t a rejection of e-voting, it is progress toward a more robust implementation that in the future will, no doubt, also include other alternative durable auditable records.</p>
	<p>For credible background on the security geek consensus, see the above-quoted NIST draft, the <a href="http://usacm.acm.org/usacm/Issues/EVoting.htm">US ACM policy recommendation</a>, or <a href="http://www.schneier.com/blog/archives/2004/11/the_problem_wit.html">Bruce Schneier</a> (University of Rochester physics alumnus!).  Or anything by Ed Felten or Avi Rubin on this subject.  In this case, our representatives seem to be listening to informed advisers.</p>
	<p>Regarding politics: All parties&#8217; oxes have been gored at one time or another by voting fraud or rumors of fraud, so this does seem like an issue on which a consensus could form.
</p>
]]></content:encoded>
      <pubDate>Fri, 07 Sep 2007 15:56:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/all-electronic systems">all-electronic systems</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/all-electronic">all-electronic</category>
      <category domain="http://securityratty.com/tag/paper audit trail">paper audit trail</category>
      <category domain="http://securityratty.com/tag/all-electronic paperless approaches">all-electronic paperless approaches</category>
      <category domain="http://securityratty.com/tag/security geek consensus">security geek consensus</category>
      <category domain="http://securityratty.com/tag/research topic">research topic</category>
      <category domain="http://securityratty.com/tag/consensus">consensus</category>
      <category domain="http://securityratty.com/tag/nist">nist</category>
      <source url="http://L.Bukys.org/2007/09/07/vote-but-verify/">Vote but Verify</source>
    </item>
  </channel>
</rss>
