RISKS Volume 23
Total Page:16
File Type:pdf, Size:1020Kb
The Risks Digest Volume 23: Issue 1 Forum on Risks to the Public in Computers and Related Systems ACM Committee on Computers and Public Policy, Peter G. Neumann, moderator Volume 23: Issue 1 Friday 7 November 2003 Contents Credit agencies sending our files abroad David Lazarus via Paul Saffo Crypto screwup: Sensitive Israeli missile test inadvertently broadcast Craig S. Bell A new risk for electronic voting Jeremy Epstein California Halts E-Vote Certification Kim Zetter via Monty Solomon Touch screen voting -- like Web site maintenance? William Nico Irish Labour Party urges suspension of e-voting until flaws addressed Patrick O'Beirne E-ZPass, UPS, and Newark Airport Susan Landau Microsoft puts a price on the heads of virus writers NewsScan Microsoft patches their patched patches Robert Bruce Thompson via Dave Farber Remember those jokes about "if AT&T built cars?" Daniel P.B. Smith http://catless.ncl.ac.uk/Risks/23.01.html (1 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 Duh! an electronic signature! Geoff Kuenning Paying employees is not rocket science Paul Robinson Another victim of the d__n bad-word filter! Adam Abrams REVIEW: "High Integrity Software", John Barnes Rob Slade Info on RISKS (comp.risks) Credit agencies sending our files abroad (via Dave Farber's IP) <Paul Saffo <[email protected]>> Fri, 07 Nov 2003 08:47:57 -0800 David Lazarus <[email protected]>, *San Francisco Chronicle*, 7 Nov 2003 [PGN-ed] sfgate.com/article.cgi?file=/c/a/2003/11/07/MNG4Q2SEAM1.DTL IP Archives at: http://www.interesting-people.org/archives/ interesting-people/ Two of the three major credit-reporting agencies (Equifax, Experian and TransUnion, each holding detailed files on about 220 million U. S. consumers) are in the process of outsourcing sensitive operations abroad, and a third may follow suit shortly. Privacy advocates say the outsourcing of files that include Social Security numbers and complete credit histories could lead to a surge in identity theft because U.S. laws cannot be enforced overseas. For their part, the credit agencies say the trend is a necessary cost-cutting move in light of new legislation that would allow all consumers to obtain free copies of their credit reports. (TransUnion http://catless.ncl.ac.uk/Risks/23.01.html (2 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 states that would cost them as much as $350 million a year.) "The application of American law in a foreign country is difficult, if not impossible," said Sen. Dianne Feinstein. "Therefore, the more companies move overseas, the less American law can control the uses for which personal data is put. And this can only represent an increasing threat to the privacy of our citizens." Sen. Barbara Boxer said she would ensure that the matter was raised as senators and House members completed changes to the Fair Credit Reporting Act. "This information is very significant, and I intend to make sure that the conferees who are finalizing the bill are aware of the *Chronicle*'s investigation in hopes that they will protect Americans from such outrageous invasions of privacy," Boxer said. Crypto screwup: Sensitive Israeli missile test inadvertently broadcast <"Craig S. Bell" <[email protected]>> Thu, 06 Nov 2003 22:38:47 GMT A security lapse by Israel Aircraft Industries apparently permitted an internal screening of a missile test to be accessible by satellite dish, unencrypted. http://www.haaretz.com/hasen/spages/357662.html [PGN-ed; also http://catless.ncl.ac.uk/Risks/23.01.html (3 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 http://www.newsday.com/news/nationworld/wire/ sns-ap-israel-missile-test,0,409849.story?coll=sns-ap- nationworld-headlines ] A new risk for electronic voting <Jeremy Epstein <[email protected]>> Thu, 6 Nov 2003 15:56:08 -0500 The RISKS of electronic voting have been discussed often enough in this forum that I won't repeat them further (cf. Rebecca Mercuri's piece in RISKS-22.96). Last week's election in Fairfax County (Virginia) had a new risk I haven't seen covered before. They use WinVote machines, made by Advanced Voting Solutions of Frisco, Tex. These are essentially Windows laptops with a touchscreen and an 802.11 wireless net. (More about that in another RISKS article one of these days.) Seems that during the election, at least eight of the machines failed (out of almost 1000 in use county-wide), and were taken out of the polling places to a central repair facility, and then brought back after some form of "repair" was made (a reboot at the polling place did not solve the problem). The seals were broken, but the voting officials in the precincts were told to resume using them. The result was a lawsuit by the Republican party http://catless.ncl.ac.uk/Risks/23.01.html (4 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 seeking to invalidate the votes from those machines. There aren't enough votes at stake that it would change any of the election results. Of course, the real problem is that without any sort of physical (paper) record, it's impossible to prove what really happened when the machines were being "repaired". In addition, the "hi tech" vote counting (which was supposed to occur by uploading the results from every precinct to a central computer over a dial-up line) overloaded the servers, and "More than half of precinct officials resorted to the old-fashioned telephone to call in their numbers or even drove the results to headquarters, elections officials said. A handful of precincts went back to paper ballots." The only thing that's surprising here is that the election officials were surprised. See http://www.washingtonpost.com/wp-dyn/articles/A1397-2003Nov5. html California Halts E-Vote Certification (Kim Zetter) <Monty Solomon <[email protected]>> Tue, 4 Nov 2003 19:16:59 -0500 Kim Zetter, Wired.Com, 3 Nov 2003 SACRAMENTO, California -- Uncertified software may have been installed on http://catless.ncl.ac.uk/Risks/23.01.html (5 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 electronic voting machines used in one California county, according to the secretary of state's office. Marc Carrel, assistant secretary of state for policy and planning, told attendees Thursday at a panel on voting systems that California was halting the certification process for new voting machines manufactured by Diebold Election Systems. The reason, Carrel said, was that his office had recently received "disconcerting information" that Diebold may have installed uncertified software on its touch- screen machines used in one county. He did not say which county was involved. However, Secretary of State spokesman Douglas Stone later told Wired News that the county in question is Alameda. ... http://www.wired.com/news/politics/0,1283,61068,00.html Touch screen voting -- like Web site maintenance? <William Nico <[email protected]>> Wed, 5 Nov 2003 09:02:54 -0800 (PST) The 4 Nov 2003 election in Pleasanton, CA had only a School Board choice on the ballot. However, the "Instructions", which comprised the opening page on the touch screen voting machine, were wholly focused in detail on the gubernatorial recall election of 7 Oct 2003! Irish Labour Party urges suspension of e-voting until flaws http://catless.ncl.ac.uk/Risks/23.01.html (6 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 addressed <"Patrick O'Beirne" <[email protected]>> Mon, 03 Nov 2003 19:39:55 +0000 http://www.labour.ie/press/detail.tmpl?SKU=20031103143251 Press Release Gilmore urges suspension of e-voting until flaws addressed Eamon Gilmore TD, Labour Spokesperson on Environment and Local Government Issued on Monday 03 November, 2003 The Labour Party has called for the suspension of plans to extend electronic voting until the e-voting system has been changed. The call was made today (Monday) by the Labour Party Spokesperson on Local Government and the Environment, Eamon Gilmore TD, at a Press Conference to launch a study of electronic voting system which was commissioned by the Labour Party. The report was prepared by two Labour Party members, Shane Hogan and Robert Cochran who are both experienced IT specialists. Deputy Gilmore said: "The report identifies a number of major flaws and deficiencies in the electronic voting system which the Government plans to extend to all areas of the country for the Local and European Elections next year. The major defects are:- * No integrated end-to-end test of the entire system has been conducted to date. The testing of the Integrated Election Software (IES) software was http://catless.ncl.ac.uk/Risks/23.01.html (7 of 21)2005-04-15 12:18:07 The Risks Digest Volume 23: Issue 1 carried out by the UK based Electoral Reform Society in 2002. However for this test the random mix feature of the IES was disabled. An integrated end-to-end test would generally be considered a key part of the implementation of any new technology. * Formal Methods were not used to prove the accuracy of the software. Formal Methods refer to a set of mathematically based techniques that are used in the development of safety-critical software such as airplane navigation or life support machines. The Department of the Environment has not made the actual source code publicly available but it is clear from the technology used and source code review that formal methods were not used and that therefore there are bugs in the software.