CA SoS Debra Bowen Names Teams and Methods to be Used for 'First-of-its-Kind in the Nation' Certification, Decertification Process...
By Brad Friedman on 5/9/2007, 12:28pm PT  

Doing twelve things at once today, so no time for analysis at this point. I'll just run CA Sec. of State Debra Bowen's just released statement on her promised, unprecedented, first-of-its-kind in the nation, "top to bottom review" of all of California's electronic voting systems.

The review will include "red team" hack testing for the first time ever. Done as standard operating procedure for similar security-sensitive, mission-critical commercial systems, this sort of penetration testing has never been performed on America's voting systems. Until now.

The one page summary [PDF] of the plan states:

  • [University of California] will provide specialists from its campuses, as well as experts from public and private universities and private sector companies throughout the United States to create three teams of experts to conduct the reviews.
  • Each system will undergo a thorough document and source code review, red team penetration testing, and a review to determine whether it’s accessible to all voters.
  • The review teams will provide an independent technical evaluation of the voting systems that the Secretary of State will use to carry out her statutory duty with respect to voting systems in determining whether the systems comply with current state and federal law.

There are links within her statement below where you can find more details. For example, the State's review teams will include folks such as computer security expert "hacking" Harri Hursti, and blind technology expert Noel Runyan, who has been highly critical of unverifiable touch-screen DRE voting systems.

More on all of this, perhaps, later after I've had time to review the materials myself. But for now, see the statement below for some killer quotes from Bowen...

FOR IMMEDIATE RELEASE: May 9, 2007

Secretary of State Debra Bowen Unveils Details On Top-to-Bottom
Review of California’s Voting Systems Scheduled To Begin Next Week

SACRAMENTO – Secretary of State Debra Bowen today unveiled the project plan that will be used to conduct her promised top-to-bottom review of the voting systems certified for use in California.

“California voters are entitled to have their votes counted exactly as they were cast,” said Secretary Bowen, the state’s chief elections officer. “This top-to-bottom review is designed with one goal in mind: to ensure that California’s voters cast their ballots on voting systems that are secure, accurate, reliable, and accessible.”

The Secretary of State is entering into an interagency agreement with the University of California to conduct the review – the first of its kind in the nation – that is scheduled to begin the week of May 14 and conclude in late July. UC will assemble three top-to-bottom review teams, drawing specialists from throughout the university system, as well as from public and private universities and private sector companies throughout the country. Each team will consist of approximately seven people and will conduct a review of documents and studies associated with each voting system, a review of the computer source code each machine relies on, and a red team penetration attack to see if the system’s security can be compromised.

“My goal is to get California to a place where voters, elections officials, candidates, and activists have confidence in the results of every election,” continued Bowen. “This kind of a comprehensive review is essential in getting us to that point. One of three things will happen to each voting system that’s being reviewed. The first possibility is that a system will be found to be secure, accurate, reliable and accessible as it stands, so voters can have confidence when they use it on Election Day. Second, a system may be required to use additional safeguards, such as an expanded post-election audit process. The third possibility is that a voting system can’t be made secure, accurate, reliable and accessible even with additional safeguards, so that system may be decertified, which means it could not be used for any election in 2008.”

Details on the project plan, the people who will be conducting the review, and other information can be found in the attached “Frequently Asked Questions” document or by clicking http://www.sos.ca.gov/el...ctions/elections_vsr.htm.

One of the concerns people had with the draft criteria was that the vendors would be held to a new set of standards that would be impossible for them to meet by February 2008,” continued Bowen. “This final project plan makes it clear that the top-to-bottom review is going to determine whether the voting systems certified for use in California comply with existing state and federal laws that require them to be secure, accurate, reliable and accessible.”

In March, Secretary Bowen issued draft criteria and gathered public comments on her proposal. Those comments – over 125 in all – are posted on the Secretary of State’s website at http://www.sos.ca.gov/el...ctions/elections_vsr.htm. The Secretary of State welcomes further comments from the public about the review while it’s underway and she will continue to provide updates on the website. Comments may be submitted to the Secretary of State’s Office by e-mail to votingsystems@sos.ca.gov or by mail to Secretary Debra Bowen, 1500 11th Street, Sacramento, CA 95814, ATTN: Voting Systems Review, 6th Floor.

“Democracy, by definition, is about free, fair and open elections,” concluded Bowen. “My goal is to have election results that are beyond question or doubt. Right now, far too many voters are wondering about the accuracy of California’s election results. We have three statewide elections next year, which makes it even more essential that our voting equipment be secure, accurate, reliable and accessible.”

###