Conformity Magazine - October 2008 - (Page 26) with historical trends, polls or the expectations of a candidate, calls for an investigation are common. As a trigger for an investigation, this body of information forms a pretty good safeguard. After all, it would be pretty hard to rig an election without the vote totals looking odd, and triggering a call for an investigation from the losing candidate. Although far from perfect, it is an important safeguard. The increasing use of computer forensic techniques is creating even more interesting benefits. An array of techniques are available, and state and local officials are starting to employ them. One growing trend is the use of digital file signatures, commonly called HASH codes, to assure that voting system software has not been modified or tampered with. The Georgia Election Center at Kennesaw State has created a self-booting CD for the state of Georgia. When a system is booted from the CD, every file used by the voting system, including those files the voting applications use in the operating system, is examined and its digital signature is compared to the certified version of the software. The check takes 1.5 to 2 minutes and gives a GO/NO GO result. The check can be made before, after, and even during an election. Parallel monitor testing is another growing tool being used. In a parallel monitor test, sample voting devices are pulled out of service and brought to a test location. The machines are then voted by people using scripts. Typically cameras record every keystroke made during the test. At the end of the election day, the totals are compared to what is expected from the scripts that were voted. The machines don’t know that they are part of a test. If there is any malicious or malfunctioning software, the monitored test will reveal a difference in the total, leading to an investigation of the source of the discrepancy, and how widespread it is in the machines used in the actual election. Other forensic tools are available but have not yet been applied in elections. One technique that security experts use in other areas is to run a separate monitor program simultaneously with an application. The monitor program, as an example, can monitor all reads and writes to election data files. Because all voting software is source code reviewed as part of national certification, the routines that will legitimately read or write election data are well known. The software that legitimately does this is both source code reviewed and extensively tested to assure it is secure and accurate. A monitor program could then simply confirm that only the expected software read and wrote to the election data files. If any other software accessed these files, a record and trigger for an investigation would be created. If the monitor program is provided by an organization separate from the voting software vendor, they become independent actors. Situation Specific Security The security requirements developed so far have taken something of a “one-size-fits-all” approach, and have failed to 2 Conformity oCtober 2008 Figure 3: Voter Privacy Domain http://www.citelprotection.com http://www.citelprotection.com
Table of Contents Feed for the Digital Edition of Conformity Magazine - October 2008 Conformity Magazine - October 2008 Contents Editor's Note FCC Releases Annual Report on National Do-Not-Call Registry Commission Cracks Down (for the Fourth Time!) On Junk Fax Marketer FCC Releases Quarterly Reports on Consumer Inquiries and Complaints Greenpeace Ranks Electronics Manufacturers Standards List For The EU’s Energy Consumption Directive Published EU Commission Publishes Standards List for Directives on Pressure Equipment, Pressure Vessels Standards List for the EU’s Medical Devices Directive Available The IEEE Product Safety Engineering Society: The First Five Years ESD Open Forum Improving Election Security and Accuracy: The Future of Voting System Certification Conformity Assessment and Accreditation: Their Role in the Global Market Design Issues in Extreme EMC Environment Focus On... Test Equipment Buyers Guide Product News Updated Standards List for EU Directive on Active Implantable Medical Devices FDA Warns of Effects from CT Scans on Electronic Medical Devices FDA Provides Report Card on Its PMA Review Process CPSC Releases Import Safety Strategy Other CPSC Actions in the News IEC Standards Update Product Reviews UL Standards Update Telcordia Standards Update From Our “You Can’t Make This Stuff Up” Department Looking Back: Items from Past Issues of Conformity Advertisers Conformity Magazine - October 2008 Conformity Magazine - October 2008 - Conformity Magazine - October 2008 (Page Cover1) Conformity Magazine - October 2008 - Conformity Magazine - October 2008 (Page Cover2) Conformity Magazine - October 2008 - Conformity Magazine - October 2008 (Page 3) Conformity Magazine - October 2008 - Contents (Page 4) Conformity Magazine - October 2008 - Contents (Page 5) Conformity Magazine - October 2008 - Editor's Note (Page 6) Conformity Magazine - October 2008 - Editor's Note (Page 7) Conformity Magazine - October 2008 - Editor's Note (Page 8) Conformity Magazine - October 2008 - Editor's Note (Page 9) Conformity Magazine - October 2008 - FCC Releases Quarterly Reports on Consumer Inquiries and Complaints (Page 10) Conformity Magazine - October 2008 - Standards List for the EU’s Medical Devices Directive Available (Page 11) Conformity Magazine - October 2008 - The IEEE Product Safety Engineering Society: The First Five Years (Page 12) Conformity Magazine - October 2008 - The IEEE Product Safety Engineering Society: The First Five Years (Page 13) Conformity Magazine - October 2008 - The IEEE Product Safety Engineering Society: The First Five Years (Page 14) Conformity Magazine - October 2008 - The IEEE Product Safety Engineering Society: The First Five Years (Page 15) Conformity Magazine - October 2008 - The IEEE Product Safety Engineering Society: The First Five Years (Page 16) Conformity Magazine - October 2008 - The IEEE Product Safety Engineering Society: The First Five Years (Page 17) Conformity Magazine - October 2008 - ESD Open Forum (Page 18) Conformity Magazine - October 2008 - ESD Open Forum (Page 19) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 20) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 21) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 22) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 23) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 24) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 25) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 26) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 27) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 28) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 29) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 30) Conformity Magazine - October 2008 - Improving Election Security and Accuracy: The Future of Voting System Certification (Page 31) Conformity Magazine - October 2008 - Conformity Assessment and Accreditation: Their Role in the Global Market (Page 32) Conformity Magazine - October 2008 - Conformity Assessment and Accreditation: Their Role in the Global Market (Page 33) Conformity Magazine - October 2008 - Conformity Assessment and Accreditation: Their Role in the Global Market (Page 34) Conformity Magazine - October 2008 - Conformity Assessment and Accreditation: Their Role in the Global Market (Page 35) Conformity Magazine - October 2008 - Conformity Assessment and Accreditation: Their Role in the Global Market (Page 36) Conformity Magazine - October 2008 - Conformity Assessment and Accreditation: Their Role in the Global Market (Page 37) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 38) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 39) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 40) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 41) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 42) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 43) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 44) Conformity Magazine - October 2008 - Design Issues in Extreme EMC Environment (Page 45) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 46) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 47) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 48) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 49) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 50) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 51) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 52) Conformity Magazine - October 2008 - Focus On... Test Equipment (Page 53) Conformity Magazine - October 2008 - Buyers Guide (Page 54) Conformity Magazine - October 2008 - Buyers Guide (Page 55) Conformity Magazine - October 2008 - Buyers Guide (Page 56) Conformity Magazine - October 2008 - Buyers Guide (Page 57) Conformity Magazine - October 2008 - Buyers Guide (Page 58) Conformity Magazine - October 2008 - Buyers Guide (Page 59) Conformity Magazine - October 2008 - Buyers Guide (Page 60) Conformity Magazine - October 2008 - Buyers Guide (Page 61) Conformity Magazine - October 2008 - Buyers Guide (Page 62) Conformity Magazine - October 2008 - Buyers Guide (Page 63) Conformity Magazine - October 2008 - Buyers Guide (Page 64) Conformity Magazine - October 2008 - Buyers Guide (Page 65) Conformity Magazine - October 2008 - Buyers Guide (Page 66) Conformity Magazine - October 2008 - Buyers Guide (Page 67) Conformity Magazine - October 2008 - Buyers Guide (Page 68) Conformity Magazine - October 2008 - Buyers Guide (Page 69) Conformity Magazine - October 2008 - Buyers Guide (Page 70) Conformity Magazine - October 2008 - Buyers Guide (Page 71) Conformity Magazine - October 2008 - Buyers Guide (Page 72) Conformity Magazine - October 2008 - Buyers Guide (Page 73) Conformity Magazine - October 2008 - Product News (Page 74) Conformity Magazine - October 2008 - Product News (Page 75) Conformity Magazine - October 2008 - Other CPSC Actions in the News (Page 76) Conformity Magazine - October 2008 - Other CPSC Actions in the News (Page 77) Conformity Magazine - October 2008 - IEC Standards Update (Page 78) Conformity Magazine - October 2008 - Product Reviews (Page 79) Conformity Magazine - October 2008 - UL Standards Update (Page 80) Conformity Magazine - October 2008 - Looking Back: Items from Past Issues of Conformity (Page 81) Conformity Magazine - October 2008 - Advertisers (Page 82) Conformity Magazine - October 2008 - Advertisers (Page Cover3) Conformity Magazine - October 2008 - Advertisers (Page Cover4)
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.