Oscars vote vulnerable to cyber attack under new online system, experts warn

InfoSec News <[email protected]> Fri, 3 Feb 2012 03:15:02 -0600 (CST)
Newsgroups gmane.comp.security.attrition.infosec-news
Message-ID <[email protected]>
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--742952673-1953022690-1328260453=:7083
Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8
Content-ID: <alpine.DEB.2.02.1202030314502.7354-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org>
Content-Transfer-Encoding: quoted-printable

http://www.guardian.co.uk/film/2012/feb/02/oscars-vulnerable-cyber-attack=
-experts-warn

By Andrew Gumbel
guardian.co.uk
2 February 2012

Computer security experts have warned that the 2013 Oscars ballot may be=20
vulnerable to a variety of cyber attacks that could falsify the outcome=20
but remain undetected, if the Academy of Motion Picture Arts and=20
Sciences follows through on its decision to switch to internet voting=20
for its members.

The Academy announced last week that it would be ditching its current=20
vote-by-mail system and allowing its members to fill out electronic=20
ballots from their home or office computers to make their choices for=20
best picture and the other big Hollywood prizes, starting in 2013.

It announced a partnership with Everyone Counts, a California-based=20
company which has developed software for internet elections from=20
Australia to Florida, and which boasted it would incorporate "multiple=20
layers of security" and "military-grade encryption techniques" to=20
maintain its reputation for scrupulous honesty in respecting its=20
members' voting preferences.

The ballot change will be a culture shock for an Academy voting=20
community that tends to be older and more conservative: indeed, concerns=20
are already surfacing as to whether all of the Academy voters even have=20
email addresses.

But Everyone Counts' security claims have been met with deep scepticism=20
by a computer scientist community which has grappled for years with the=20
problem of making online elections fully verifiable while maintaining=20
ballot secrecy =E2=80=93 in other words, being rigorous about auditing th=
e=20
voting process, but still making sure nobody knows who voted for what.=20
So far, nobody has demonstrated that such a thing is possible.

[...]


--742952673-1953022690-1328260453=:7083
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_____________________________________________________
Did a friend send you this article? Make it your
New Year's Resolution to subscribe to InfoSec News!
http://www.infosecnews.org/mailman/listinfo/isn
--742952673-1953022690-1328260453=:7083--