Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

BBV-RE: alteration of Audit Log in Access. Incredible emails.

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
spotbird Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Sep-21-03 06:11 PM
Original message
BBV-RE: alteration of Audit Log in Access. Incredible emails.
I don't know if I'm the first to find this thread or not, but it supports everything Bev has been saying all along.
http://www.sunrise.it/s/lists/support.w3archive/200110/msg00122.html

--------------------------------------------------------------------------------

To: <support@gesn.com>
Subject: RE: alteration of Audit Log in Access
From: "Ken Clark" <ken@gesn.com>
Date: Thu, 18 Oct 2001 09:55:02 -0700
Importance: Normal
In-reply-to: <ODEFIJCCLAAIGHHAOEJIKECACCAA.nfglobal@earthlink.net>

--------------------------------------------------------------------------------

Its a tough question, and it has a lot to do with perception. Of course everyone knows perception is reality.

Right now you can open GEMS' .mdb file with MS-Access, and alter its contents. That includes the audit log. This isn't anything new. In VTS, you can open the database with progress and do the same. The same would go for anyone else's system using whatever database they are using. Hard drives are read-write entities. You can change their contents.

Now, where the perception comes in is that its right now very *easy* to change the contents. Double click the .mdb file. Even technical wizards at Metamor (or Ciber, or whatever) can figure that one out.

It is possible to put a secret password on the .mdb file to prevent Metamor from opening it with Access. I've threatened to put a password on the .mdb before when dealers/customers/support have done stupid things with the GEMS database structure using Access. Being able to end-run the database has admittedly got people out of a bind though. Jane (I think it was Jane) did some fancy footwork on the .mdb file in Gaston recently. I know our dealers do it. King County is famous for it. That's why we've never put a password on the file before.

Note however that even if we put a password on the file, it doesn't really prove much. Someone has to know the password, else how would GEMS open it. So this technically brings us back to square one: the audit log is modifiable by that person at least (read, me). Back to perception though, if you don't bring this up you might skate through Metamor.

There might be some clever crypto techniques to make it even harder to change the log (for me, they guy with the password that is). We're talking big changes here though, and at the moment largely theoretical ones. I'd doubt that any of our competitors are that clever.

By the way, all of this is why Texas gets its sh*t in a knot over the log printer. Log printers are not read-write, so you don't have the problem. Of course if I were Texas I would be more worried about modifications to our electronic ballots than to our electron logs, but that is another story I guess.

Bottom line on Metamor is to find out what it is going to take to make them happy. You can try the old standard of the NT password gains access to the operating system, and that after that point all bets are off. You have to trust the person with the NT password at least. This is all about Florida, and we have had VTS certified in Florida under the status quo for nearly ten years.

I sense a loosing battle here though. The changes to put a password on the .mdb file are not trivial and probably not even backward compatible, but we'll do it if that is what it is going to take.

Ken


From: owner-support@gesn.com On Behalf Of Nel Finberg
Sent: Tuesday, October 16, 2001 11:32 PM
To: support
Subject: alteration of Audit Log in Access


Jennifer Price at Metamor (about to be Ciber) has indicated that she can access the GEMS Access database and alter the Audit log without entering a password. What is the position of our development staff on this issue? Can we justify this? Or should this be anathema?

Nel
Printer Friendly | Permalink |  | Top
spotbird Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Sep-21-03 06:26 PM
Response to Original message
1. I'm bumping my own post.
This looks important. It says to me that there are ways to change the vote without a trail.

Any thoughts?
Printer Friendly | Permalink |  | Top
 
grasswire Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Sep-21-03 06:39 PM
Response to Reply #1
3. and without a password...
..it appears.
Printer Friendly | Permalink |  | Top
 
gristy Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Sep-21-03 06:34 PM
Response to Original message
2. Lots of BBV threads on this email database in past 24 hours
If anyone has't been keeping up, find them in GD.
Printer Friendly | Permalink |  | Top
 
TorchTheWitch Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Sep-21-03 07:09 PM
Response to Reply #2
4. this one was up before
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 11:13 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC