[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
CA Voting System Review notes
"I was especially struck by the utter banality of most of the flaws.  
Exploitable vulnerabilities arose not so much from esoteric  
weaknesses that taxed our ingenuity, but rather from the garden- 
variety design and implementation blunders that plague any system not  
built with security as a central requirement. There was a pervasive  
lack of good security engineering across all three systems, and I'm  
at a loss to explain how any of them survived whatever process  
certified them as secure in the first place. Our hard work  
notwithstanding, unearthing exploitable deficiencies was surprisingly  
-- and disturbingly -- easy."
http://www.crypto.com/blog/ca_voting_report/