5 ms·
It'll be a win/win situation if baseless allegations of fraud are punished, and every detail of how voting machines work, including source code, are made public
by the_local_host 6y ago
It'll be a win/win situation if baseless allegations of fraud are punished, and every detail of how voting machines work, including source code, are made public.
- tartoran 6y agoI agree but wouldn't making the source code becoming public make the machines more prone to hacking?
- rtkwe 6y agoNot if they're well designed, if the security of the system depends on it's function being completely secret it's not secure.
- tartoran 6y agoYes, security by obfuscation is not good but imagine a bad actor discovers a bug and by the time the bug gets discovered and patched they could do a lot of harm in an election. Somehow I agree with the idea of making the code public only with the idea in mind that it gets scrutinized my more eyeballs but since we're talking about elections maybe this changes the perspective a bit?
- rtkwe 6y agoIf you have the access to the machines to hack a number of them you likely already have the access to dump and analyze the source code, the physical access required is basically the same in both cases and getting the code initially is easier because you only need one machine (/maybe/ two to see if there's any interesting differences) where the final hack would require more. Also just because the code isn't released doesn't mean it's secure that same bad actor can theoretically hack the same code out of the writing company to start with. It's a debate we've had with secure messengers the benefit of having that many eyes on a piece of software outweighs the minor risk of a secret zero day.
- lokedhs 6y agoNot if they are secure. In the security community, if the integrity of the platform requires information about the platform to be secret, it's not secure. The keys should be secure, but the design of algorithms and implementation of the system should not be.
- gnulinux 6y agoNot at all, it's actually the opposite. Security by obscurity is a terrible way of securing software since once someone backward-engineers it, you're hacked. Instead, if you open source it, all security researchers will be able to audit the code and be paid bounty money if they find bugs (and believe me, they will find bugs).
- scoopertrooper 6y agoOpen sourcing software security flaws more prone to discovery, but also enables more people to discover the flaws, which can be a good thing. If you hide away the source code, then only criminal actors and security agencies can evaluate security flaws. Open sourcing, at least, places legitimate security researchers on equal footing with these groups, so flaws can be disclosed publicly and rectified. That being said, I think there are sufficient safeguards in the process that effectively mitigate any potential compromising of Dominion software. The software prints out the voters' ballot and the voter is given an opportunity to review the ballot before scanning it with a separate machine and it entering a locked box. This allows for a manual recount to guard against any possible shenanigans. One additional step they could take, would be for the voter to verify their vote after scanning. This would ensure that they actually read the ballot. Though I could see that causing problems if the voter, for whatever reason, decided to repudiate their vote while travelling between the two machines.