Showing posts with label Civil Society and Democracy. Show all posts
Showing posts with label Civil Society and Democracy. Show all posts

Friday, March 13, 2020

Steven Sinofsky on Crisis Leadership

I read the original Twitter thread and felt the need to be able to reread it, probably more than once.  Thankfully, an annotated version is now available on Sinofsky’s Medium blog.

It is worth reading.  It is worth understanding that any crisis arises and must be addressed under chaotic conditions.

There’s also the matter of preparation.  There can be strategies and plans for the foreseeable.  And, as is frequently reported, when the crisis erupts, the plans go out the window.  Yet we are better prepared for having done the planning, actually made the preparatory arrangements, and gained some level of training even if not the same as having been tested in response to a previous crisis.

Friday, February 21, 2020

Bruce Schneier on Policy vs Technology

Bruce Schneier posted this IEEE Security & Privacy essay on his blog today.

Read the posturing in the comments and wonder about the ones that resonate with you.

Compare with the thrust of the article and the purpose and nature of law and politics.

Discuss among yourselves.

Friday, February 14, 2020

Complexifying Elections: Technological Wishful Thinking over Accountability and Demonstration

Via ACM TechNews, Computerworld’s Lucas Mearian reports MIT researchers say mobile voting app piloted in U.S. is rife with vulnerabilities

There is a fundamental tension between having secrecy of ballots and a desire for auditability and detection/prevention of fraudulent manipulation of the voting system.

The TL;DR: The most important question concerning electronic/internet technical mediation of a voting system is this: When the system is determined to fail or corrupted on election day, what fall-back is in place for swift and certain recovery?

The next question is, what provisions are there for detecting such an incident is occurring or has occurred?

The Quandary

Insistence by researchers that paper ballots be the best choice has to do more with avoiding additional vulnerabilities and exploits that can be invisible, massive, difficult to audit, and not subject to the usual verification of chains of custody and handling between the means of submission (polling places and mail/drop systems) and current means of authenticating the registered voter and/or the unopened ballot.  Paper-ballot systems  limit the varieties of attack and their potential absence of detection.  Integrity of the system is grounded on human activity and the transparency of election administration. 

The paper ballot provides the best case of privacy, with the only connection being the handover of a ballot to a registered voter or the receipt of a sealed ballot before removal and introduction into processing.  The secrecy of the voter’s balloting is established at that point.

It is also the case that widespread fraud against voting systems has never been demonstrated, as much as it is feared by those who are contemptuous of voters not like themselves.  The small numbers of cases tend to be more pathetic than any serious rigging, such as the greater impact of voter suppression and distortion of choice through gerrymandering.

In some sense, those current manual-system provisions and safeguards do not go away.  Adding technological solutions is more complex and requires much more understanding, preparation, and dependence on specialized skills and appropriate conceptual models not possessed by polling place workers, those in election headquarters, and the management/administration, however well-intentioned. 

Advocates of technological fixes are on a death-spiral starting with the abandonment of paper ballots and continual fix and repair, adding complexification without addressing the importance of standard security requirements and especially risk management that applies to the delivery of invisible technology. 

A particular problem with citizen-facing voting technology is that it is not possible to have the normal cycles of learning and improvement.  It has to work the first time and every other time.  Furthermore, adversaries are not obligated to reveal their ability to penetrate and manipulate a system until it is too late. 

There is nothing new here in the difficulty of creating and deploying technical systems in which there are critical privacy and security requirements.  What is new is the impact on an area that is much more fragile in the face of disruption and breakdowns and the lost of trust inevitable breakdowns invite.  If the producers of technical components resist transparency for whatever reason, one must presume defects, not believe perfection with no evidence, only wishful thinking.

Thursday, February 13, 2020

What does “Winner” Mean?

As of today, there have been two Democratic Party Presidential Candidate Nomination events: the 2020 Iowa Caucus and the 2020 New Hampshire Primary. 

At this point, the Associated Press and other news media are distressed that they are “unable to declare a winner.”  Really?  What self-important ridiculousness.  

This is neither horse-race nor sporting event.  There is no such title and reward distinct from what is already determined: delegates pledged to different candidates going into the National Democratic Party Convention later this year.  Simple boring facts.

The candidates will, of course, step into the media-distorted view and proclaim their fortunes for their own purposes.  The behavior is akin to prize fighters claiming their advance to the title.  There are even metaphors such as “knocked out.”

We are seeing politics in the manner that politics is useful in a democratic society.  Noisy, disruptive, thrashing about, looking for consensus and if not consensus, determination of a way ahead in the face of uncertainty.

There are inside-baseball dramas of course, a feast brought about by failures of accountability and transparency, in the case of the Iowa Caucus operation. 

Although there has now been the equivalent of a public hanging, it remains unclear whether the lessons to be found in that process are being learned.  I’m thinking of the unfortunate introduction of technology and inadequate/absent risk management.

The processes behind the conduct and resolution of elections tend to be good enough until something “too close to call” arises.  Then reforms arise.  The injection of technology and technology fads offering technological cures to technological failures suggest that the lessons about human responsibilities, and our mutual fallibility, are not willingly recognized and learned.