[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Moshe Zadka <m@moshez.org>] Independent Count

>> On Mon, 24 Mar 2003 19:58:45 +0100,
>> Russell Coker <russell@coker.com.au> said: 

 > Given that the hashing prevents the secretary from altering a cast
 > vote, how would a malicious secretary fake a vote?

 > They would cast a vote on behalf of a non-voting developer.
 > Obtaining a list of MIA developers is not too difficult.  If
 > someone does not vote then they may not notice if the voting talley
 > indicates that they cast a vote.

	Any audit would show such a vote was added; unless you think
 the secretary can forge a signature from the non-voting member.

 > Is the secretary in a position to add votes to the talley without
 > confirmation messages being sent out or in a position to subvert
 > email to @debian.org addresses to make sure that such mail does not
 > reach it's destination?  If so then they could concievably fake
 > some votes without much risk of getting caught.  I expect that
 > almost no-one checks to make sure that the fact that they did not
 > vote was correctly registered...

	I don't see how this would help. So, I forge logs that say
 mail came in, and ack went out (I can't, but for the sake of
 argument). The people who check logs weould also check the ballot,
 and unless I managed toforge the sig, I shall be caught.

	Does ability to forge mail logs change this? no.

 > To check the actions of the secretary someone else needs access to
 > the signed vote records to ensure that every registered vote is the
 > result of a signed email.

	Any one who has root on master has access.

	Of course, someone has to check the work done by the
 secretary; but this person should not be known in advance, to prevent

	The question then becomes: who watches the watcher?

Hale Mail Rule, The: When you are ready to reply to a letter, you will
lack at least one of the following: A pen or pencil or
typewriter. Stationery. Postage stamp. The letter you are answering.
Manoj Srivastava   <srivasta@debian.org>  <http://www.debian.org/%7Esrivasta/>
1024R/C7261095 print CB D9 F4 12 68 07 E4 05  CC 2D 27 12 1D F5 E8 6E
1024D/BF24424C print 4966 F272 D093 B493 410B  924B 21BA DABB BF24 424C

Reply to: