Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: JustaTech
Mainly what makes your online interaction secure is security at the institution you do business with. Almost nothing you do makes any real difference. Sure, you can type crap from your phone into the computer every time you log in and pretend that adds security but it doesn't.

Yes, the fob is secure because it uses PKI and the private key cannot be stolen from the fob. Ewerything else you use, from passwords to questions to text messages to any kind of software can be compromised and under the right conditions compromized en masse. Not just one vote, millions of votes if 2FA is your voting "security"

You won't get notified by email either or if on the odd chance you do I'll make sure you get dozens of notifications so you will ignore the useful one (actually Google does that already when I use the same account on multiple laptops and phones).

If you really want a purely tech solution then hand each voter a PKI fob in person upon presentation of ID and credentials. I've written browser extensions, both PKCS #11 and Microsoft CSP. Software tokens are not secure, only hardware is secure. I've also written the server side java and client javaascript to use FIDO U2F to secure web accounts. FIDO U2F fobs are secure just like the PKI fobs (some fobs do both).

74 posted on 12/06/2020 2:47:33 PM PST by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 72 | View Replies ]


To: palmer

The server side software would be open source, you WOULD be notified by email if your account was changed (that is very standard practice on my planet, I don’t know about yours), and the most important thing is that any large-scale tampering would be NOTICED. People would look up their ballots in the published list and find they don’t match, and red flags would go up. As for the tabulation, anyone would be able to download the published list into Excel and run the totals for themselves.

Transparency means you can see the evidence of tampering easily. The only thing an attacker could do is spoil the election possibly, but there would be no way to alter the outcome without detection.


82 posted on 12/06/2020 6:18:52 PM PST by JustaTech (A mind is a terrible thing)
[ Post Reply | Private Reply | To 74 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson