<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.designnine.com/news" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Security, authentication, authorization</title>
 <link>http://www.designnine.com/news/taxonomy/term/57</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Static magically creates 1,500 votes</title>
 <link>http://www.designnine.com/news/node/1231</link>
 <description>&lt;p&gt;In the continuing saga of voting machines that simply don&#039;t work, here is perhaps the most alarming story to date.  In a Washington, D.C. voting precinct during the primaries, a &quot;static discharge&quot; &lt;a href=&quot;http://www.news8.net/news/stories/1008/558138.html&quot;&gt;magically created&lt;/a&gt; an extra 1,500 votes on the memory cartridge that stores the vote tally.  The only slightly good news is that someone did notice that the manual tally of voters at the precinct was only 326, but what if it had not been caught?&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1231#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/7">Software</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Fri, 03 Oct 2008 07:13:57 -0700</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1231 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>Paper ballots getting the vote</title>
 <link>http://www.designnine.com/news/node/1176</link>
 <description>&lt;p&gt;Paper ballots will be used to &lt;a href=&quot;http://www.boston.com/news/nation/articles/2008/06/17/many_states_turning_to_paper_ballots_for_fall/&quot;&gt;collect votes&lt;/a&gt; in many elections this fall.  There will be a drop in the use of electronic ballot equipment because of security problems, and more states are using paper ballots that are optically scanned because they are easy to use, ease to scan, and provide an auditable paper trail.  The biggest shortcoming of the electronic equipment is the lack of a paper trail that can be used to verify results.  Unfortunately, this shortcoming was widely noted in this column and in many other sources early in the rush to avoid any more hanging chad incidents.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1176#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Tue, 17 Jun 2008 05:02:17 -0700</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1176 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>&quot;Whaling&quot; is newest kind of spam attack</title>
 <link>http://www.designnine.com/news/node/1158</link>
 <description>&lt;p&gt;&quot;Whaling&quot; is a new form of phishing attacks.  It is called whaling because the &lt;a href=&quot;http://news.yahoo.com/s/afp/20080506/tc_afp/usinternetcourtcrime;_ylt=AjhsL9sGKYsDSZftfsZHMHSs0NUE&quot;&gt;spam emails are carefully targeted&lt;/a&gt; towards big fish, or whales.  Spammers have been sending carefully crafted emails that look like an official U.S. Federal Court sub poena.  Clicking on the link embedded in the email secretly installs a keystroke logger on your computer which then sends userids, passwords, and credit card numbers to the spammer.&lt;/p&gt;
&lt;p&gt;We actually got one of those sub poenas about two weeks ago, and it certainly looked official.  But sub poenas are usually delivered in person, and so after looking closely at the email and some of the links, we quickly determined it was spam.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1158#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/35">Privacy</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Tue, 06 May 2008 10:10:14 -0700</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1158 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>E-voting costs 866% more</title>
 <link>http://www.designnine.com/news/node/1138</link>
 <description>&lt;p&gt;A study by a watchdog e-voting group in Maryland called SaveOurVotes found that in that state, the switch to electronic voting machines &lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/04/the-cost-of-e-v.html&quot;&gt;raised the cost of elections by 866%&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;But wait, there&#039;s more!  The counties are still paying off a $67 million dollar loan needed to purchase the machines, even though the machines were found to have serious security flaws and have had to abandoned in favor of the older and more secure optical scanning equipment--which is much less expensive.&lt;/p&gt;
&lt;p&gt;The only good thing about this story is that the state did eventually do the right thing and revert to a more secure voting system.  But the taxpayers still have to pick up the tab for a lot of bad decisions.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1138#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Mon, 07 Apr 2008 05:47:00 -0700</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1138 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>Wireless vulnerabilities</title>
 <link>http://www.designnine.com/news/node/1114</link>
 <description>&lt;p&gt;This moderately technical article (&lt;a href=&quot;http://www.codenomicon.com/resources/whitepapers/Codenomicon_Wireless_WP_v1_0.pdf&quot;&gt;PDF file&lt;/a&gt;) has an extensive discussion of the vulnerabilities of wireless systems, including WiFi, Bluetooth, and WiMax.  Communities interested in investing primarily in wireless broadband should read this article first, as the data presented illustrates why most businesses do not regard wireless as a business class service.&lt;/p&gt;
&lt;p&gt;Here is a short summary of the issues from the article:&lt;br /&gt;
&lt;cite&gt;&lt;br /&gt;
Wireless networks have three additional aspects that make the security of wireless&lt;br /&gt;
networks even more challenging than the security of fixed networks:&lt;/cite&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Wireless networks are always open
&lt;li&gt;Attackers can connect into the network from anywhere and from any distance
&lt;li&gt;Attackers are always anonymous
&lt;/ul&gt;
&lt;p&gt;&lt;cite&gt;&lt;br /&gt;
Wireless networks are always open – Physical media does not protect them. Any device&lt;br /&gt;
that implements the same radio interface can access a wireless network. One common&lt;br /&gt;
assumption is that wireless technologies are secure when authentication and encryption&lt;br /&gt;
are properly deployed. Looking closely at the operation of related protocols, there are&lt;br /&gt;
many message sequences that take place before the authentication. These message&lt;br /&gt;
sequences can always be attacked regardless of the deployed security measures.&lt;br /&gt;
Attacks are not limited by location or distance.&lt;br /&gt;
&lt;cite&gt;&lt;br /&gt;
Attacks are not limited by location or distance. The distance from where the attacker can&lt;br /&gt;
reach the wireless network is only limited by the power of the transmitter. For example,&lt;br /&gt;
Bluetooth attack tools are known to have several-mile radiuses, although valid usage&lt;br /&gt;
scenarios would never attempt such range of coverage for Bluetooth.&lt;br /&gt;
&lt;/cite&gt;&lt;cite&gt;&lt;br /&gt;
Attackers are always anonymous. Although a valid user can be pinpointed with good&lt;br /&gt;
accuracy, an attacker can use directed antennas that will only target a selected victim. It is impossible to guarantee detection of malicious users in wireless networks. As stated&lt;br /&gt;
above, an attacker can also always attack the message sequences that happen before the&lt;br /&gt;
authentication of the device and thus avoid identification.&lt;/p&gt;
&lt;p&gt;&lt;/cite&gt;&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1114#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/10">WiFi and wireless</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Mon, 18 Feb 2008 05:50:05 -0800</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1114 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>Digital photo frames hold more than pictures</title>
 <link>http://www.designnine.com/news/node/1112</link>
 <description>&lt;p&gt;Those digital photo frames that are becoming popular hold more than pictures.  Millions of them apparently come &lt;a href=&quot;http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/02/15/BU47V0VOH.DTL&amp;amp;type=business&quot;&gt;pre-loaded with a potent virus&lt;/a&gt; designed to thwart computer anti-virus programs.  The virus is spread from the frame to a computer when the frame is plugged into a USB port. &lt;/p&gt;
&lt;p&gt;The virus is difficult to remove, and the article recommends plugging a suspect picture frame into a Linux or Macintosh first to see what is stored in the frame memory (and then deleting it).&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1112#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/12">Future trends</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Sun, 17 Feb 2008 10:51:35 -0800</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1112 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>Colorado throws out e-voting machines</title>
 <link>http://www.designnine.com/news/node/1088</link>
 <description>&lt;p&gt;Following on the heels of Ohio, Colorado has &lt;a href=&quot;http://www.thedenverchannel.com/politics/14875334/detail.html&quot;&gt;de-certified the voting machines&lt;/a&gt; used in some of the most populous parts of the state. Diebold, Sequoia, and ES&amp;amp;S machines were among those found to have problems.  The state found that the machines were easy to tamper with, and that the machines lacked any audit trail capabilities, meaning there would be no way to detect tampering if it happened.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1088#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Wed, 19 Dec 2007 06:29:54 -0800</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1088 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>Electronic voting may be banned in Ohio</title>
 <link>http://www.designnine.com/news/node/1085</link>
 <description>&lt;p&gt;New studies of electronic voting machines in Ohio has led a top official there to &lt;a href=&quot;http://www.bradblog.com/?p=5443&quot;&gt;call for a ban&lt;/a&gt; on the machines.  The Ohio Secretary of State noted &quot;critical security failures&quot; on the machines that made it easy to tamper with vote counts.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1085#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/50">Ohio</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Tue, 18 Dec 2007 06:32:13 -0800</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1085 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>Voting machines may finally get fixed</title>
 <link>http://www.designnine.com/news/node/1019</link>
 <description>&lt;p&gt;Legislators are finally getting the message about faulty electronic voting machines, and perhaps some of these machines will get auditable paper trails in time for the 2008 election.  The House of Representatives is working on a bill that will require &lt;a href=&quot;http://pressesc.com/news/79928072007/agreement-reached-ban-paperless-voting&quot;&gt;better accountability&lt;/a&gt; for the electronic ballot systems for all Federal elections, starting with the fall 2008 elections.&lt;/p&gt;
&lt;p&gt;The really galling part of this is that all this was completely avoidable.  Many of us in the IT business saw this train coming a long way off.  Unfortunately, a lot of local governments, who buy most voting equipment, were happy to ignore technical experts without a financial stake in the outcome and instead fell hook, line, and sinker for the promises of vendors, who were giddy over the windfall market that fell into their laps--nearly every voting machine in America was going to be replaced!&lt;/p&gt;
&lt;p&gt;The taxpayers get to pay twice for this fiasco, but at least it is going to get fixed.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/1019#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/14">Policy and regulation</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Tue, 31 Jul 2007 05:25:23 -0700</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">1019 at http://www.designnine.com/news</guid>
</item>
<item>
 <title>California reviews electronic voting</title>
 <link>http://www.designnine.com/news/node/980</link>
 <description>&lt;p&gt;The state of California has put together an &lt;a href=&quot;http://www.ss.ca.gov/elections/voting_systems/ttbr/qa.pdf&quot;&gt;extensive plan&lt;/a&gt; to review every voting system in use in the state.  The work will use several groups of indepedent scientists with excellent credentials who will review both electronic voting systems and other, older voting systems, including paper-based balloting.  &lt;/p&gt;
&lt;p&gt;The state is serious about this; the plan includes the use of independent &quot;red teams&quot; that will work independently to try to break into the electronic systems.  This is not likely to be very difficult, since you can go right to YouTube and watch a &lt;a href=&quot;http://www.youtube.com/watch?v=aZws98jw67g&quot;&gt;short video&lt;/a&gt; on how to break into some systems.&lt;/p&gt;
&lt;p&gt;The tragedy here is that this kind of analysis and review should have been done before California spent a half billion tax dollars buying untested voting equipment. State and local officials in California and in every other state ignored the pleas of computer scientists and technology experts across the country and blindly wasted billions buying flawed equipment.  Most of it will end up being replaced.&lt;/p&gt;
&lt;p&gt;The good news:  at least the problem is getting fixed before a massive vote fraud creats a constitutional crisis in a major election.  Let&#039;s hope every state addresses this issue promptly.&lt;/p&gt;
</description>
 <comments>http://www.designnine.com/news/node/980#comments</comments>
 <category domain="http://www.designnine.com/news/taxonomy/term/21">California</category>
 <category domain="http://www.designnine.com/news/taxonomy/term/57">Security, authentication, authorization</category>
 <pubDate>Thu, 10 May 2007 06:42:43 -0700</pubDate>
 <dc:creator>acohill</dc:creator>
 <guid isPermaLink="false">980 at http://www.designnine.com/news</guid>
</item>
</channel>
</rss>
