Oscars vote vulnerable to cyber attack under new online system, experts warn
InfoSec News <[email protected]> Fri, 3 Feb 2012 03:15:02 -0600 (CST)
| Newsgroups | gmane.comp.security.attrition.infosec-news |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --742952673-1953022690-1328260453=:7083 Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8 Content-ID: <alpine.DEB.2.02.1202030314502.7354-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org> Content-Transfer-Encoding: quoted-printable http://www.guardian.co.uk/film/2012/feb/02/oscars-vulnerable-cyber-attack= -experts-warn By Andrew Gumbel guardian.co.uk 2 February 2012 Computer security experts have warned that the 2013 Oscars ballot may be=20 vulnerable to a variety of cyber attacks that could falsify the outcome=20 but remain undetected, if the Academy of Motion Picture Arts and=20 Sciences follows through on its decision to switch to internet voting=20 for its members. The Academy announced last week that it would be ditching its current=20 vote-by-mail system and allowing its members to fill out electronic=20 ballots from their home or office computers to make their choices for=20 best picture and the other big Hollywood prizes, starting in 2013. It announced a partnership with Everyone Counts, a California-based=20 company which has developed software for internet elections from=20 Australia to Florida, and which boasted it would incorporate "multiple=20 layers of security" and "military-grade encryption techniques" to=20 maintain its reputation for scrupulous honesty in respecting its=20 members' voting preferences. The ballot change will be a culture shock for an Academy voting=20 community that tends to be older and more conservative: indeed, concerns=20 are already surfacing as to whether all of the Academy voters even have=20 email addresses. But Everyone Counts' security claims have been met with deep scepticism=20 by a computer scientist community which has grappled for years with the=20 problem of making online elections fully verifiable while maintaining=20 ballot secrecy =E2=80=93 in other words, being rigorous about auditing th= e=20 voting process, but still making sure nobody knows who voted for what.=20 So far, nobody has demonstrated that such a thing is possible. [...] --742952673-1953022690-1328260453=:7083 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _____________________________________________________ Did a friend send you this article? Make it your New Year's Resolution to subscribe to InfoSec News! http://www.infosecnews.org/mailman/listinfo/isn --742952673-1953022690-1328260453=:7083--