12.07.2015 Views

The following is the summary of my comments on ... - Notable Software

The following is the summary of my comments on ... - Notable Software

The following is the summary of my comments on ... - Notable Software

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Subject: [ACCURATE] FULL Summary <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>my</str<strong>on</strong>g> <str<strong>on</strong>g>comments</str<strong>on</strong>g>Date: Tuesday, March 30, 2004 4:27 PMFrom: R. Mercuri To: Cc: "Peter G. Neumann" , Drew Dean, Mercuri Rebecca <str<strong>on</strong>g>The</str<strong>on</strong>g> <str<strong>on</strong>g>following</str<strong>on</strong>g> <str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> <str<strong>on</strong>g>summary</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>my</str<strong>on</strong>g> <str<strong>on</strong>g>comments</str<strong>on</strong>g> <strong>on</strong> <str<strong>on</strong>g>the</str<strong>on</strong>g>current draft versi<strong>on</strong>. Peter and Drew are working <strong>on</strong>making rev<str<strong>on</strong>g>is</str<strong>on</strong>g>i<strong>on</strong>s, if o<str<strong>on</strong>g>the</str<strong>on</strong>g>rs have any thoughts al<strong>on</strong>g <str<strong>on</strong>g>the</str<strong>on</strong>g>lines <str<strong>on</strong>g>of</str<strong>on</strong>g> what I've indicated here, in how to clear up <str<strong>on</strong>g>the</str<strong>on</strong>g>seproblems with <str<strong>on</strong>g>the</str<strong>on</strong>g> draft, please pitch in your thoughts(to Peter and Drew).Peter/Drew -- <str<strong>on</strong>g>my</str<strong>on</strong>g> comment still stands <strong>on</strong> page 0 --it's too much <str<strong>on</strong>g>of</str<strong>on</strong>g> an analys<str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> what <str<strong>on</strong>g>is</str<strong>on</strong>g> wr<strong>on</strong>g and toolittle <str<strong>on</strong>g>of</str<strong>on</strong>g> a what we are going to do to fix things. Same<str<strong>on</strong>g>is</str<strong>on</strong>g> still true <str<strong>on</strong>g>of</str<strong>on</strong>g> page 1. Nothing else new in <str<strong>on</strong>g>the</str<strong>on</strong>g> belowfrom what I sent you before (but I cleaned it up a tadfor general d<str<strong>on</strong>g>is</str<strong>on</strong>g>tributi<strong>on</strong>).I am writing an additi<strong>on</strong>al secti<strong>on</strong> <strong>on</strong> Incident Reporting nowand will peruse prior emails from folks to check to see if<str<strong>on</strong>g>the</str<strong>on</strong>g>re's anything left that I need to provide input <strong>on</strong>.Sorry if it sounds a bit harsh, that's <str<strong>on</strong>g>my</str<strong>on</strong>g> style (for what it's worth),Rebecca Mercuri.PAGE 0:My overall suggesti<strong>on</strong> <str<strong>on</strong>g>is</str<strong>on</strong>g> to have a brief statement <str<strong>on</strong>g>of</str<strong>on</strong>g><str<strong>on</strong>g>the</str<strong>on</strong>g> problem and to devote MOST <str<strong>on</strong>g>of</str<strong>on</strong>g> secti<strong>on</strong> B toa CONCRETE LIST OF DELIVERABLES.Th<str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> FIRST PAGE that <str<strong>on</strong>g>the</str<strong>on</strong>g> reviewers will see.Tell <str<strong>on</strong>g>the</str<strong>on</strong>g>m WHAT WE PLAN TO DO, not what <str<strong>on</strong>g>is</str<strong>on</strong>g> wr<strong>on</strong>g.PAGE 1:C1 Call to arms: Most <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> informati<strong>on</strong> we want toexchange IS secret (not, <str<strong>on</strong>g>is</str<strong>on</strong>g> NOT secret).


Załącznik nr 15. Z-d ProdukcjiMaszynRolniczych„MESKO –ROL” Spółka zo.o. wSkarżyskuKamiennej, ul.Legi<strong>on</strong>ów 122,26 - 111SkarżyskoKamienna,tel.:(0-41)253-33-89,253-33-63,fax:253-33-09.6. „MardaR” zMaryninak/Lublina,Marynin 1, 21 –030 MOTYCZ,tel./fax.: (0–81)503–20–30, tel.kom.: (0–601) 32–07–75.7. KujawskaFabrykaMaszynRolniczych„KRUKOWIAK”w RedeczuKrukowymk/BrześciaKujawskiego,REDECZumożliwiającezaładunek, transport irozładunek bel zesło<str<strong>on</strong>g>my</str<strong>on</strong>g> i siana T150 iT150/1;– chwytaki bel T 371(współpracuje zładowaczamiczołowymi „TUR 5” i„TUR 6”),– nośnik bel T 367 iładowacze czołoweT426;– rozwijacze bel H 912 dorozwijania belokrągłych siana lubsło<str<strong>on</strong>g>my</str<strong>on</strong>g> zprzeznaczeniem napaszę lub ściółkę,– rozdrabniacze bel H186 do rozdrabnianiaokrągłych bel.2. zawieszane kosiarkirotacyjne 2.–bębnowegórn<strong>on</strong>apędowe Z 133(szer. rob. 1,35 m) i Z175 (szer. rob. 1,65 m) izawieszana Z 275przetrząsaczo –zgrabiarka karuzelowa(szer. rob. 3,0 m). [Z-d„MESKO – ROL” zostałwydziel<strong>on</strong>y zdotychczasowychZakładów Metalowych„MESKO”]System sterowaniamikroklimatem„MardaR”, typ H 276,zwany „komputeremfarmerskim”.2 opryskiwaczeciągnikowe polowe:– zawieszane 600/12H„HEROS”, typ P155/4 o szer. rob. 12m i pojemnościzbiornika 600 dm 3 ;– przyczepiane2500/18PH„GOLIAT”, typ P12/2000 zdnia12.04.2000.13/2001z dnia03.01.2001 r.14/2001z dnia03. 01.2001.współpracujące z ciągnikami wyposaż<strong>on</strong>ymi w dolny zaczep transportowytypu „hitch” klasy 0,9. Chwytak bel T 371 jest narzędziem m<strong>on</strong>towanym naładowaczach „TUR 5” i „TUR 6”; przeznacz<strong>on</strong>y jest do podbierania na poluzwiniętych i pi<strong>on</strong>owo ustawi<strong>on</strong>ych bel i przewożenia ich na skraj pola lub dopobl<str<strong>on</strong>g>is</str<strong>on</strong>g>kiego gospodarstwa (bez przejazdów po drogach publicznych).Nośnik bel T 367 - przeznacz<strong>on</strong>y jest do pobierania na polu i przewożeniazwiniętych bel na skraj pola lub do pobl<str<strong>on</strong>g>is</str<strong>on</strong>g>kiego gospodarstwa oraz do innychprac przeładunkowo - załadunkowych. Rozwijacz bel H 912 - przeznacz<strong>on</strong>yjest do rozwijania bel okrągłych siana lub sło<str<strong>on</strong>g>my</str<strong>on</strong>g> z przeznaczeniem na paszęlub ściółkę. Może być zastosowany do załadunku bel na owijarkę Z 274.Jest przystosowany do współpracy z ciągnikami o mocy od 33 kW.Rozdrabniacz bel H 186 - rozdrabnia okrągłe bele sło<str<strong>on</strong>g>my</str<strong>on</strong>g>, siana <str<strong>on</strong>g>is</str<strong>on</strong>g>ianok<str<strong>on</strong>g>is</str<strong>on</strong>g>z<strong>on</strong>ki. Rozdrobni<strong>on</strong>y materiał kierowany jest przez rynnę wylotową i- w zależności od jej ustawienia - usypuje (pod rynną lub jest rozścielany napowierzchni). Agregowanie: - ciągniki klasy 1,4. Owijarka bel zawieszana Z274 - przeznacz<strong>on</strong>a jest do owijania w folię cylindrycznych bel sianapółsuchego zwiniętych za pomocą pras zwijających stałokomorowych. Jestprzystosowana do współpracy z ciągnikami o mocy od 33. kW. Owijarka belprzyczepiana samozaładowcza Z 281 - owija w folię rozciągliwąsamoprzylepną pojedynczych bel cylindrycznych podsusz<strong>on</strong>ych ziel<strong>on</strong>ek.Współpracuje z ciągnikami o mocy od 33. kW. Ładowacz czołowy T 426 - oudźwigu do 1500kg przeznacz<strong>on</strong>y jest do prac przeładunkowych materiałówobjętościowych, w tym bel cylindrycznych. Ładowacz wyposaż<strong>on</strong>y jest wdwa rodzaje wsporników - do ciągników 4.- i 6.- cylindrowych.Kosiarki Z 133 i Z 175 przeznacz<strong>on</strong>e są do koszenia traw i ziel<strong>on</strong>ekn<str<strong>on</strong>g>is</str<strong>on</strong>g>kołodygowych na łąkach i polach uprawnych o nachyleniu do 12 0 , a doprzetrząsania i zgrabiania skosz<strong>on</strong>ych traw i ziel<strong>on</strong>ek służą przetrząsaczo –zgrabiarki Z 275. Maszyny te współpracują z ciągnikami klasy:• 0,6 i 0,9 - kosiarka Z 133 i przetrząsaczo - zgrabiarka Z 275;• 0,9 - kosiarka Z 175.Przydatność użytkową kosiarek i przetrząsaczo - zgrabiarek oraz ichniezawodność i bezpieczeństwo pracy oceni<strong>on</strong>o w IBMER Oddz. wKłudzienku.Mikroprocesorowy system sterowania mikroklimatem opracowany zostałwg. technologii „1-Wire® Dallas Semic<strong>on</strong>ductor USA” i jest przeznacz<strong>on</strong>y doutrzy<str<strong>on</strong>g>my</str<strong>on</strong>g>wania właściwego mikroklimatu w pomieszczeniach inwentarskich.Zasada pracy systemu sterowania mikroklimatem „MardaR" polega nazałączaniu i wyłączaniu i/lub regulacji obrotów wentylatorów jedn<str<strong>on</strong>g>of</str<strong>on</strong>g>azowych.Bezpieczeństwo użytkowania systemu sterowania mikroklimatem H 276oceni<strong>on</strong>o w IBMER Oddział w Strzeszynie k/Poznania.Opryskiwacze „HEROS” i „GOLIAT” przeznacz<strong>on</strong>e są do wyk<strong>on</strong>ywaniazabiegów ochr<strong>on</strong>y roślin w uprawach polowych oraz do nawożenianawozami mineralnymi rozpuszczalnymi w wodzie (mocznik, roztwory RMSi różne „odżywki”). Opryskiwacze można również stosować do <str<strong>on</strong>g>my</str<strong>on</strong>g>cia wodąmaszyn, nawadniania roślin itp. Opryskiwacze agregowane są z ciągnikamiklasy 0,9 („HEROS”) i powyżej 1,4 („GOLIAT” - agregowanie z ciągnikiempoprzez dolny zaczep transportowy). Bezpieczeństwo użytkowaniaopryskiwaczy oceni<strong>on</strong>o w PIMR w Poznaniu. Ww. opryskiwacze sąk<strong>on</strong>strukcjami zgodnymi z normami i przep<str<strong>on</strong>g>is</str<strong>on</strong>g>ami BHP. Producent tychopryskiwaczy zapewnia także pełną informację o zagrożeniach w2


are comm<strong>on</strong>place to critical computer equipment deployment, suchas that used by <str<strong>on</strong>g>the</str<strong>on</strong>g> Department <str<strong>on</strong>g>of</str<strong>on</strong>g> Defense, <str<strong>on</strong>g>the</str<strong>on</strong>g> health care and avi<strong>on</strong>icsindustries, and banking."Give <str<strong>on</strong>g>the</str<strong>on</strong>g> date/year <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> audit <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> 17 counties in California's equipment (toshow that th<str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>is</str<strong>on</strong>g> CURRENTLY going <strong>on</strong>).Add a sentence after <str<strong>on</strong>g>the</str<strong>on</strong>g> Diebold asserti<strong>on</strong> about checks and balances to explainthat:<str<strong>on</strong>g>The</str<strong>on</strong>g>re <str<strong>on</strong>g>is</str<strong>on</strong>g> NO c<strong>on</strong>figurati<strong>on</strong> c<strong>on</strong>trol and management practices, even <str<strong>on</strong>g>the</str<strong>on</strong>g> mostminimum suggested by NIST, currently used or required by <str<strong>on</strong>g>the</str<strong>on</strong>g> FEC/NASEDprocess to ensure that <str<strong>on</strong>g>the</str<strong>on</strong>g> voting systems being deployed are identical inc<strong>on</strong>structi<strong>on</strong> to those that were certified. Th<str<strong>on</strong>g>is</str<strong>on</strong>g> a serious and dangerousom<str<strong>on</strong>g>is</str<strong>on</strong>g>si<strong>on</strong> by electi<strong>on</strong> authorities.Human factors and usability was actually added to <str<strong>on</strong>g>the</str<strong>on</strong>g> FEC/NASED standards.<str<strong>on</strong>g>The</str<strong>on</strong>g>y paid an outside c<strong>on</strong>sulting firm to come up with some. You are workingwith an old document.Note that <str<strong>on</strong>g>the</str<strong>on</strong>g> IEEE Voting System Standard effort also entirely omits <str<strong>on</strong>g>the</str<strong>on</strong>g>equipment and s<str<strong>on</strong>g>of</str<strong>on</strong>g>tware used to tally <str<strong>on</strong>g>the</str<strong>on</strong>g> votes and report <str<strong>on</strong>g>the</str<strong>on</strong>g> vote totals. <str<strong>on</strong>g>The</str<strong>on</strong>g>ircurrent effort <strong>on</strong>ly pertains to <str<strong>on</strong>g>the</str<strong>on</strong>g> balloting systems.Omit <str<strong>on</strong>g>the</str<strong>on</strong>g> sentence about <str<strong>on</strong>g>the</str<strong>on</strong>g> standards development process not producingsurpr<str<strong>on</strong>g>is</str<strong>on</strong>g>es. That's wr<strong>on</strong>g (and rude to boot).C2. Accuracy and integrity are BOTH essential to <str<strong>on</strong>g>the</str<strong>on</strong>g> voting system. If itproduces <strong>on</strong>ly accurate reports based <strong>on</strong> <str<strong>on</strong>g>the</str<strong>on</strong>g> data it has but that data lacksintegrity, it <str<strong>on</strong>g>is</str<strong>on</strong>g> moot. Reference Saltman's report again here.Trusting groups with diverse interests may be untrustworthy as well, because it<str<strong>on</strong>g>is</str<strong>on</strong>g> generally understood that <str<strong>on</strong>g>the</str<strong>on</strong>g>re may be collusi<strong>on</strong> am<strong>on</strong>g <str<strong>on</strong>g>the</str<strong>on</strong>g> political parties,particularly in regi<strong>on</strong>s <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> country where a certain party <str<strong>on</strong>g>is</str<strong>on</strong>g> dominant.You say "in additi<strong>on</strong> to <str<strong>on</strong>g>the</str<strong>on</strong>g> questi<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> trust" yet your prior paragraphspeaks <str<strong>on</strong>g>of</str<strong>on</strong>g> ACCURACY, not TRUST.Page 3:Do you really mean OPEN standards? Or just agreed-up<strong>on</strong> standards?


Open means something ra<str<strong>on</strong>g>the</str<strong>on</strong>g>r different.Page 4:You should be able to find a place to insert <str<strong>on</strong>g>the</str<strong>on</strong>g> <str<strong>on</strong>g>following</str<strong>on</strong>g>reference in <str<strong>on</strong>g>the</str<strong>on</strong>g> stat<str<strong>on</strong>g>is</str<strong>on</strong>g>tics and audit secti<strong>on</strong>:[*?*] Rebecca T. Mercuri, “On Auditing Audit Trails,”Security Watch, Communicati<strong>on</strong>s <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> ACM, Vol. 46, No. 1,January 2003.Canvassing and reporting -- at <str<strong>on</strong>g>the</str<strong>on</strong>g> end <str<strong>on</strong>g>of</str<strong>on</strong>g> th<str<strong>on</strong>g>is</str<strong>on</strong>g> part, you need tosay something about "we will provide...." and <str<strong>on</strong>g>the</str<strong>on</strong>g>n say whatwe will provide -- like guidelines for canvassing and reporting?and/or ways <str<strong>on</strong>g>of</str<strong>on</strong>g> ensuring that <str<strong>on</strong>g>the</str<strong>on</strong>g> canvassing and reporting <str<strong>on</strong>g>is</str<strong>on</strong>g>being performed correctly...etc....Operati<strong>on</strong>s and procedures --ONLY use "voter verified paper audit trail" throughout <str<strong>on</strong>g>the</str<strong>on</strong>g> document(not "verifiable").Get rid <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> "we believes..." that sounds w<str<strong>on</strong>g>is</str<strong>on</strong>g>hy-washy. Tightenthat up with "it <str<strong>on</strong>g>is</str<strong>on</strong>g> well known" or something MUCH str<strong>on</strong>ger.I thought Avi had recanted <strong>on</strong> h<str<strong>on</strong>g>is</str<strong>on</strong>g> asserti<strong>on</strong> that <str<strong>on</strong>g>the</str<strong>on</strong>g> Diebold smartcardprotocol allowed voters to vote as many times as <str<strong>on</strong>g>the</str<strong>on</strong>g>y wanted -- afterhe worked as a pollworker. You MUST remove that. It's wr<strong>on</strong>g.<str<strong>on</strong>g>The</str<strong>on</strong>g> sentence about <str<strong>on</strong>g>the</str<strong>on</strong>g> preference to paper ballots and (hopefully)verified about <str<strong>on</strong>g>the</str<strong>on</strong>g> voter should be changed to:Our research will indicate <str<strong>on</strong>g>the</str<strong>on</strong>g> level <str<strong>on</strong>g>of</str<strong>on</strong>g> assurance that <str<strong>on</strong>g>is</str<strong>on</strong>g> appliedwhen paper ballots are available for voter verificati<strong>on</strong>.Secti<strong>on</strong> C4"Paperless DRE Systems" should be renamed to "Fully-Electr<strong>on</strong>icDRE Systems" Use voter verified (decide <strong>on</strong> whe<str<strong>on</strong>g>the</str<strong>on</strong>g>r you want ithyphenated or not and be c<strong>on</strong>s<str<strong>on</strong>g>is</str<strong>on</strong>g>tent throughout <str<strong>on</strong>g>the</str<strong>on</strong>g> document).


Decompositi<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> voting machine must be able to PROVE that <str<strong>on</strong>g>the</str<strong>on</strong>g>re <str<strong>on</strong>g>is</str<strong>on</strong>g> nocollusi<strong>on</strong> am<strong>on</strong>g <str<strong>on</strong>g>the</str<strong>on</strong>g> comp<strong>on</strong>ents and that data <str<strong>on</strong>g>is</str<strong>on</strong>g> transferred correctly. Eachtransm<str<strong>on</strong>g>is</str<strong>on</strong>g>si<strong>on</strong> points has a data transfer vulnerability. How to mitigate th<str<strong>on</strong>g>is</str<strong>on</strong>g>?Attesting to <str<strong>on</strong>g>the</str<strong>on</strong>g> s<str<strong>on</strong>g>of</str<strong>on</strong>g>tware it <str<strong>on</strong>g>is</str<strong>on</strong>g> running <str<strong>on</strong>g>is</str<strong>on</strong>g> OK but <str<strong>on</strong>g>the</str<strong>on</strong>g> DATA must have fullintegrity. <str<strong>on</strong>g>The</str<strong>on</strong>g> folks at SRI should have some references <strong>on</strong> th<str<strong>on</strong>g>is</str<strong>on</strong>g>....Security Analys<str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> Proposed Voting Systems -- what you have said in those2 paragraphs <str<strong>on</strong>g>is</str<strong>on</strong>g> not a security analys<str<strong>on</strong>g>is</str<strong>on</strong>g>, it <str<strong>on</strong>g>is</str<strong>on</strong>g> a RISKS analys<str<strong>on</strong>g>is</str<strong>on</strong>g>, since you aredealing with attacks, not necessarily mitigati<strong>on</strong>. Probably you want to change<str<strong>on</strong>g>the</str<strong>on</strong>g> title <str<strong>on</strong>g>of</str<strong>on</strong>g> that secti<strong>on</strong> to "R<str<strong>on</strong>g>is</str<strong>on</strong>g>ks Analys<str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> ...."Design for Audit -- fine, except change verifiable toverified.Cryptographic Protocols --Actually mix nets do not allow "any<strong>on</strong>e" to validate <str<strong>on</strong>g>the</str<strong>on</strong>g> electi<strong>on</strong>. <str<strong>on</strong>g>The</str<strong>on</strong>g>re<str<strong>on</strong>g>is</str<strong>on</strong>g> c<strong>on</strong>siderable obfuscati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> process, and unless you have a Ph.D.in cryptography you probably will not be able to understand that <str<strong>on</strong>g>the</str<strong>on</strong>g> processwas applied correctly to produce <str<strong>on</strong>g>the</str<strong>on</strong>g> vote totals. We need to change <str<strong>on</strong>g>the</str<strong>on</strong>g>sentence to reflect who can ensure that it <str<strong>on</strong>g>is</str<strong>on</strong>g> being d<strong>on</strong>e correctly, and alsoindicate that it <str<strong>on</strong>g>is</str<strong>on</strong>g> inappropriate for a bunch <str<strong>on</strong>g>of</str<strong>on</strong>g> propellor-headed geeks to be <str<strong>on</strong>g>the</str<strong>on</strong>g><strong>on</strong>ly <strong>on</strong>es who can verify that <str<strong>on</strong>g>the</str<strong>on</strong>g> process correctly generated true electi<strong>on</strong>results.S<str<strong>on</strong>g>of</str<strong>on</strong>g>tware Engineering Tools -- OK, but include <str<strong>on</strong>g>the</str<strong>on</strong>g> applicati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> NISTcertificate protocols for allowing <str<strong>on</strong>g>the</str<strong>on</strong>g> end-users (in th<str<strong>on</strong>g>is</str<strong>on</strong>g> case <str<strong>on</strong>g>the</str<strong>on</strong>g> local electi<strong>on</strong><str<strong>on</strong>g>of</str<strong>on</strong>g>ficials) to be able to procedurally ensure that <str<strong>on</strong>g>the</str<strong>on</strong>g> code <strong>on</strong> <str<strong>on</strong>g>the</str<strong>on</strong>g> machine was<str<strong>on</strong>g>the</str<strong>on</strong>g> certified set. It's all very well and good to get it through <str<strong>on</strong>g>the</str<strong>on</strong>g> certificati<strong>on</strong>,but <str<strong>on</strong>g>the</str<strong>on</strong>g>re has to be a way to follow th<str<strong>on</strong>g>is</str<strong>on</strong>g> throughto <str<strong>on</strong>g>the</str<strong>on</strong>g> endpoint where <str<strong>on</strong>g>the</str<strong>on</strong>g> systems are actually being used, or it's moot.(Remember some NIST folks will probably be vetting th<str<strong>on</strong>g>is</str<strong>on</strong>g> proposal, soyou should plug <str<strong>on</strong>g>the</str<strong>on</strong>g>ir good stuf in <str<strong>on</strong>g>the</str<strong>on</strong>g>re as much as you can.)Trusted Hardware Platforms -- <str<strong>on</strong>g>the</str<strong>on</strong>g> questi<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> TCPA must also bemitigated against whe<str<strong>on</strong>g>the</str<strong>on</strong>g>r th<str<strong>on</strong>g>is</str<strong>on</strong>g> provides sufficient "trust" and assurancefor <str<strong>on</strong>g>the</str<strong>on</strong>g> GENERAL PUBLIC (citizens) for n<strong>on</strong>-techies to believe thatit's not just a fancier name for a "black-box". You should plan to assessth<str<strong>on</strong>g>is</str<strong>on</strong>g> as well, in th<str<strong>on</strong>g>is</str<strong>on</strong>g> secti<strong>on</strong>.


Internet Voting -- wait a sec<strong>on</strong>d -- where <str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g>Rubin/Wagner/Sim<strong>on</strong>s report putting <str<strong>on</strong>g>the</str<strong>on</strong>g> kibosh <strong>on</strong> <str<strong>on</strong>g>the</str<strong>on</strong>g> SERVEproject??? You MUST footnote th<str<strong>on</strong>g>is</str<strong>on</strong>g>. AND YOU HAVE COMPLETELYLEFT OUT THE SOCIOLOGICAL FACTORS HERE. Say somethinglike <str<strong>on</strong>g>the</str<strong>on</strong>g> <str<strong>on</strong>g>following</str<strong>on</strong>g>: "<str<strong>on</strong>g>The</str<strong>on</strong>g> bottom line regarding Internet (remote) votingmust be its high vulnerability for coerci<strong>on</strong> and vote-selling. Any soluti<strong>on</strong>,no matter how secure, must also address and mitigate against <str<strong>on</strong>g>the</str<strong>on</strong>g>se sociologicalfactors." Th<str<strong>on</strong>g>is</str<strong>on</strong>g> secti<strong>on</strong> should also include somed<str<strong>on</strong>g>is</str<strong>on</strong>g>cussi<strong>on</strong> about o<str<strong>on</strong>g>the</str<strong>on</strong>g>r forms <str<strong>on</strong>g>of</str<strong>on</strong>g> networking: Vulnerabilities <str<strong>on</strong>g>of</str<strong>on</strong>g> dedicatednetworks and wireless transm<str<strong>on</strong>g>is</str<strong>on</strong>g>si<strong>on</strong>s, also now being introduced in increasingnumbers into electi<strong>on</strong> systems (for tasks ranging from ballot face programmingthrough end-<str<strong>on</strong>g>of</str<strong>on</strong>g>-night reporting), must be c<strong>on</strong>sidered and mitigated.Remote and Absentee Voting -- Add a sentence explaining that:Traditi<strong>on</strong>al forms <str<strong>on</strong>g>of</str<strong>on</strong>g> bioidentificati<strong>on</strong> may be unacceptable for <str<strong>on</strong>g>the</str<strong>on</strong>g> electi<strong>on</strong>setting, because many voters fear governmental collecti<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> such data, and<str<strong>on</strong>g>the</str<strong>on</strong>g>y may self-d<str<strong>on</strong>g>is</str<strong>on</strong>g>enfranch<str<strong>on</strong>g>is</str<strong>on</strong>g>e if such are required to use <str<strong>on</strong>g>the</str<strong>on</strong>g> systems.C5 Usability and Accessibility - I see you reference <str<strong>on</strong>g>the</str<strong>on</strong>g> UMD study,but <str<strong>on</strong>g>the</str<strong>on</strong>g>y did receive a fairly SUBSTANTIAL NSF grant recently and youmight want to at least menti<strong>on</strong> that we will be coordinating with <str<strong>on</strong>g>the</str<strong>on</strong>g>mto ensure that we are not duplicating efforts. Have some<strong>on</strong>e check <str<strong>on</strong>g>the</str<strong>on</strong>g>irwebsite ASAP to be sure that <str<strong>on</strong>g>the</str<strong>on</strong>g> comp<strong>on</strong>ents you have identified hereare not ALREADY being d<strong>on</strong>e by <str<strong>on</strong>g>the</str<strong>on</strong>g> UMD team (Ben Beders<strong>on</strong> et al).If you overlap <str<strong>on</strong>g>the</str<strong>on</strong>g>ir currently funded work, it will look like we are out<str<strong>on</strong>g>of</str<strong>on</strong>g> touch with what <str<strong>on</strong>g>the</str<strong>on</strong>g>y are doing.I think that a retrospective analys<str<strong>on</strong>g>is</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> Florida 2000 electi<strong>on</strong> <str<strong>on</strong>g>is</str<strong>on</strong>g> akinto beating a dead horse. PULEASE delete that unless you really thinkthat <str<strong>on</strong>g>the</str<strong>on</strong>g>re <str<strong>on</strong>g>is</str<strong>on</strong>g> some way to analyze <str<strong>on</strong>g>the</str<strong>on</strong>g> voting systems and data now that<str<strong>on</strong>g>the</str<strong>on</strong>g>y have ALL been DESTROYED. It <str<strong>on</strong>g>is</str<strong>on</strong>g> an impossible and absurdtask and do not put it into <str<strong>on</strong>g>the</str<strong>on</strong>g> proposal. We want to move FORWARD,NOT BACKWARD.C6 Legal and Policy Issues -- REGISTRATION PROCESS? NO!!!THIS IS A PROPOSAL ABOUT VOTING SYSTEMS!!! You do noteven want to go <str<strong>on</strong>g>the</str<strong>on</strong>g>re with voter reg<str<strong>on</strong>g>is</str<strong>on</strong>g>trati<strong>on</strong>. That <str<strong>on</strong>g>is</str<strong>on</strong>g> a HUGE politicalhotbed that you will be totally criticized for venturing into. TAKE THATOUT OF THE PROPOSAL ASAP! We have our hands full with <str<strong>on</strong>g>the</str<strong>on</strong>g>


state requirements (all <str<strong>on</strong>g>of</str<strong>on</strong>g> which are different) for dealing with <str<strong>on</strong>g>the</str<strong>on</strong>g>voting systems <str<strong>on</strong>g>the</str<strong>on</strong>g>mselves, recounts, ballot layouts, and so <strong>on</strong>.COMPLETELYTAKE OUT BOTH OF THOSE PARAGRAPHS. You can start with <str<strong>on</strong>g>the</str<strong>on</strong>g><strong>on</strong>e that says "<str<strong>on</strong>g>the</str<strong>on</strong>g> sec<strong>on</strong>d stage <str<strong>on</strong>g>is</str<strong>on</strong>g> voting itself" but leave out that sentence andjust start with "One key area <str<strong>on</strong>g>of</str<strong>on</strong>g> research will focus <strong>on</strong> <str<strong>on</strong>g>the</str<strong>on</strong>g>interacti<strong>on</strong> between new voting technologies and ...." <str<strong>on</strong>g>The</str<strong>on</strong>g>n <str<strong>on</strong>g>the</str<strong>on</strong>g> votetabulati<strong>on</strong> and canvassing part <str<strong>on</strong>g>is</str<strong>on</strong>g> really <str<strong>on</strong>g>the</str<strong>on</strong>g> SECOND stage <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> process,but just really "ano<str<strong>on</strong>g>the</str<strong>on</strong>g>r aspect <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> process...." Leave out <str<strong>on</strong>g>the</str<strong>on</strong>g> 4th stagebecause <str<strong>on</strong>g>the</str<strong>on</strong>g>re <str<strong>on</strong>g>is</str<strong>on</strong>g> NO WAY to deal with that. If you MUST put somethingin about lawsuits -- you want to say something about "providing informati<strong>on</strong>that would be useful to plaintiffs, defendants and judges regarding <str<strong>on</strong>g>the</str<strong>on</strong>g>appropriate setup, operati<strong>on</strong> and deployment <str<strong>on</strong>g>of</str<strong>on</strong>g> voting systems and <str<strong>on</strong>g>the</str<strong>on</strong>g> c<strong>on</strong>duct<str<strong>on</strong>g>of</str<strong>on</strong>g> recounts and canvasses." You want to go <strong>on</strong> here somewhatabout <str<strong>on</strong>g>the</str<strong>on</strong>g> difficulty in understanding <str<strong>on</strong>g>the</str<strong>on</strong>g> technology, and that our groupcould be a useful resource to <str<strong>on</strong>g>the</str<strong>on</strong>g> legal community in providing informati<strong>on</strong>that would allow technical understanding <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> equipment that was used, itsflaws and problems, etc.C7 Educati<strong>on</strong> and Outreach Plan -- Fine.C8 Technology Transfer Plan -- Th<str<strong>on</strong>g>is</str<strong>on</strong>g> secti<strong>on</strong> <str<strong>on</strong>g>is</str<strong>on</strong>g> <strong>on</strong> TECHNOLOGYTRANSFER yet you start by downgrading th<str<strong>on</strong>g>is</str<strong>on</strong>g> entire proposal bysaying that you d<strong>on</strong>'t expect to get any cooperati<strong>on</strong> from <str<strong>on</strong>g>the</str<strong>on</strong>g> majorvendors. THIS IS BUNK. Instead say: "<str<strong>on</strong>g>The</str<strong>on</strong>g> major vendors haveparticipated with many <str<strong>on</strong>g>of</str<strong>on</strong>g> us <strong>on</strong> <str<strong>on</strong>g>the</str<strong>on</strong>g> IEEE voting standards developmentteam, and have a vested interest in having improved accuracy, integrity,reliability, usability, auditability, blah blah, in <str<strong>on</strong>g>the</str<strong>on</strong>g>ir products. Weexpect that <str<strong>on</strong>g>the</str<strong>on</strong>g>y will engage in <strong>on</strong>going d<str<strong>on</strong>g>is</str<strong>on</strong>g>cussi<strong>on</strong> with our researchgroup, and potentially <str<strong>on</strong>g>of</str<strong>on</strong>g>fer products for testing and evaluati<strong>on</strong>."(Look, maybe <str<strong>on</strong>g>the</str<strong>on</strong>g>y w<strong>on</strong>'t but why tell <str<strong>on</strong>g>the</str<strong>on</strong>g> NSF th<str<strong>on</strong>g>is</str<strong>on</strong>g>???)C9 Management Plan -- I think that <str<strong>on</strong>g>the</str<strong>on</strong>g> sentence about J<strong>on</strong>es, thoughhighly complementary (and true) would be d<str<strong>on</strong>g>is</str<strong>on</strong>g>puted by o<str<strong>on</strong>g>the</str<strong>on</strong>g>r folks(Shamos) who have also bridged various d<str<strong>on</strong>g>is</str<strong>on</strong>g>ciplines effectively inth<str<strong>on</strong>g>is</str<strong>on</strong>g> field. I think you might want to play up J<strong>on</strong>es' qualificati<strong>on</strong>s(having served as a machine inspector for h<str<strong>on</strong>g>is</str<strong>on</strong>g> state, creating <str<strong>on</strong>g>the</str<strong>on</strong>g> premierebody <str<strong>on</strong>g>of</str<strong>on</strong>g> research <strong>on</strong> optically scanned voting systems, etc.) ra<str<strong>on</strong>g>the</str<strong>on</strong>g>r than<str<strong>on</strong>g>the</str<strong>on</strong>g> vague complements you wrote. ;-)


C10 Evaluati<strong>on</strong> Plan -- Add to <str<strong>on</strong>g>the</str<strong>on</strong>g> l<str<strong>on</strong>g>is</str<strong>on</strong>g>t <str<strong>on</strong>g>of</str<strong>on</strong>g> evaluati<strong>on</strong> methods --* Adopti<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> ACCURATE results and suggesti<strong>on</strong>s by vendors, members<str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> electi<strong>on</strong> community, and reflecti<strong>on</strong> in leg<str<strong>on</strong>g>is</str<strong>on</strong>g>lati<strong>on</strong>.I think you sort <str<strong>on</strong>g>of</str<strong>on</strong>g> said that in <str<strong>on</strong>g>the</str<strong>on</strong>g> paragraph below <str<strong>on</strong>g>the</str<strong>on</strong>g> bullets, but youcan firm it up more.You might want to note somewhere that ACCURATE does not (??) planto patent or pr<str<strong>on</strong>g>of</str<strong>on</strong>g>it from its developments, so that <str<strong>on</strong>g>the</str<strong>on</strong>g>y can be used by all. Isth<str<strong>on</strong>g>is</str<strong>on</strong>g> correct? Or <str<strong>on</strong>g>is</str<strong>on</strong>g> that just implied by govt. funding, or do peoplehave problems with th<str<strong>on</strong>g>is</str<strong>on</strong>g>. But you might want to say something aboutit somewhere.Footnotes/References<str<strong>on</strong>g>The</str<strong>on</strong>g> format <str<strong>on</strong>g>is</str<strong>on</strong>g> inc<strong>on</strong>s<str<strong>on</strong>g>is</str<strong>on</strong>g>tent. Sometimes you use initials, sometimesyou have last name first, sometimes you have first name first. Decide<strong>on</strong> a style for all <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>the</str<strong>on</strong>g> citati<strong>on</strong>s and edit <str<strong>on</strong>g>the</str<strong>on</strong>g>m all to be <str<strong>on</strong>g>the</str<strong>on</strong>g> same.For <str<strong>on</strong>g>the</str<strong>on</strong>g> <strong>on</strong>es you currently have for me, both are somewhat wr<strong>on</strong>g.<str<strong>on</strong>g>The</str<strong>on</strong>g>y should be as follows:[38] Rebecca T. Mercuri. Electr<strong>on</strong>ic Vote Tabulati<strong>on</strong>: Checks and Balances.Ph.D. <str<strong>on</strong>g>the</str<strong>on</strong>g>s<str<strong>on</strong>g>is</str<strong>on</strong>g>, School <str<strong>on</strong>g>of</str<strong>on</strong>g> Engineering and Applied Science, Department <str<strong>on</strong>g>of</str<strong>on</strong>g>Computer and Informati<strong>on</strong> Systems, University <str<strong>on</strong>g>of</str<strong>on</strong>g> Pennsylvania, 2001.University Micr<str<strong>on</strong>g>of</str<strong>on</strong>g>ilms #3003665. http://www.notables<str<strong>on</strong>g>of</str<strong>on</strong>g>tware.com/Papers/<str<strong>on</strong>g>the</str<strong>on</strong>g>sdefabs.html[39] Rebecca Mercuri. A Better Ballot Box? IEEE Spectrum, Vol. 39, No. 10,October 2002.http://www.spectrum.ieee.org/WEBONLY/publicfeature/oct02/evot.html

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!