| Sumario: | This article focuses on source-available e-voting software. Source-available software, whether proprietary or nonproprietary, has garnered significant attention. The arguments in favor of taking a source available approach in general are numerous, but only those of specific relevance to e-voting systems are discussed in this article. If a system's security is based on a secret design that becomes public knowledge, then security is compromised and the genie cannot be put back into the bottle. Cryptographers and security professionals use peer review to provide assurance for the quality of their systems. A security scheme whose source code and design is known, yet continues to offer a useful level of protection, is a good one. Changes to source code are difficult to prevent in an e-voting system, whether or not it uses source-available code. The same applies at the design level. This article shows that source-available software fails to address the fundamental challenges involved in adding technology to the voting process.
|