<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: P100M Reward For Hacking of Automation System</title>
	<atom:link href="http://www.betterphilippines.com/uncategorized/p100m-reward-for-hacking-of-automation-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.betterphilippines.com/uncategorized/p100m-reward-for-hacking-of-automation-system/</link>
	<description>Blogging For A Better Philippines&#124;Pointing Out Truths Others Deny Or Ignore</description>
	<lastBuildDate>Wed, 28 Sep 2011 04:34:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: jovy</title>
		<link>http://www.betterphilippines.com/uncategorized/p100m-reward-for-hacking-of-automation-system/comment-page-1/#comment-1669</link>
		<dc:creator>jovy</dc:creator>
		<pubDate>Sat, 06 Feb 2010 22:27:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.betterphilippines.com/?p=304#comment-1669</guid>
		<description>As long as it was online through internet, It would be vulnerable in any kind of attack such as SQL(Structured Query Language)injection/Bruteforce method attacks/sniff/remote access/Remote Administrative Tool (RAT) or I&#039;d rather say etc. coz there&#039;s a lot of ways to access computers,white hat/black hat hacker is no necessary,the important is the result,There&#039;s no secured in the internet, and i would like to tell you all, the most secured computer is the one which is not connected on the Internet and it was turned off with a lots of security guard around it and it was inside the concrete barrier sealed with iron with high voltage, at bakit nga po pala tayo nag English,Eh nandito tayo sa sarili nating bayan at pilipino. tayo...</description>
		<content:encoded><![CDATA[<p>As long as it was online through internet, It would be vulnerable in any kind of attack such as SQL(Structured Query Language)injection/Bruteforce method attacks/sniff/remote access/Remote Administrative Tool (RAT) or I&#8217;d rather say etc. coz there&#8217;s a lot of ways to access computers,white hat/black hat hacker is no necessary,the important is the result,There&#8217;s no secured in the internet, and i would like to tell you all, the most secured computer is the one which is not connected on the Internet and it was turned off with a lots of security guard around it and it was inside the concrete barrier sealed with iron with high voltage, at bakit nga po pala tayo nag English,Eh nandito tayo sa sarili nating bayan at pilipino. tayo&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.betterphilippines.com/uncategorized/p100m-reward-for-hacking-of-automation-system/comment-page-1/#comment-107</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Wed, 22 Apr 2009 11:12:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.betterphilippines.com/?p=304#comment-107</guid>
		<description>&quot;i have a few questions. what exactly was tested then? what was it tested for? was it tested for vulnerabilities or just to see if it works?&quot;

RA 9369 mandates pilot testing of automated election system in at least one real election.  Originally, it was supposed to have happened during the 2007 elections in 6 cities and 6 provinces. 1 city and 1 province in Luzon, 1 city and 1 province in Visayas, and 1 city and 1 province in Mindanao.

This was later revised to make it applicable to the ARMM elections and thereby comply with RA 9369.

Before pilot testing could begin, the Comelec through the technical advisory committee had to scrutinize the system that would be employed in the ARMM.  This is a thorough check, meaning all software and hardware used had to pass muster and all requirements for an automated election machine.  This includes security features -- features that would prevent hacking and other means of tampering the votes and the voting results.

Using the automated election machines itself in ARMM was the real live test.

This happened on Aug. 11, in which around 1.5 million ARMM residents voted.

The results were that cheating still happened but this was on the level of the users (vote buying, flying voters, etcetera) and was hardly significant on the regional level.

But as to wholesale vote manipulation or cheating the actual result on the provincial/regional level by manipulating the system itself to produce favorable results for a candidate in particular, this did not happen. 

If the system could have been hacked, it should have been hacked then.  It wasn&#039;t.</description>
		<content:encoded><![CDATA[<p>&#8220;i have a few questions. what exactly was tested then? what was it tested for? was it tested for vulnerabilities or just to see if it works?&#8221;</p>
<p>RA 9369 mandates pilot testing of automated election system in at least one real election.  Originally, it was supposed to have happened during the 2007 elections in 6 cities and 6 provinces. 1 city and 1 province in Luzon, 1 city and 1 province in Visayas, and 1 city and 1 province in Mindanao.</p>
<p>This was later revised to make it applicable to the ARMM elections and thereby comply with RA 9369.</p>
<p>Before pilot testing could begin, the Comelec through the technical advisory committee had to scrutinize the system that would be employed in the ARMM.  This is a thorough check, meaning all software and hardware used had to pass muster and all requirements for an automated election machine.  This includes security features &#8212; features that would prevent hacking and other means of tampering the votes and the voting results.</p>
<p>Using the automated election machines itself in ARMM was the real live test.</p>
<p>This happened on Aug. 11, in which around 1.5 million ARMM residents voted.</p>
<p>The results were that cheating still happened but this was on the level of the users (vote buying, flying voters, etcetera) and was hardly significant on the regional level.</p>
<p>But as to wholesale vote manipulation or cheating the actual result on the provincial/regional level by manipulating the system itself to produce favorable results for a candidate in particular, this did not happen. </p>
<p>If the system could have been hacked, it should have been hacked then.  It wasn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lpgd</title>
		<link>http://www.betterphilippines.com/uncategorized/p100m-reward-for-hacking-of-automation-system/comment-page-1/#comment-95</link>
		<dc:creator>lpgd</dc:creator>
		<pubDate>Tue, 21 Apr 2009 03:23:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.betterphilippines.com/?p=304#comment-95</guid>
		<description>i see your point. that&#039;s the problem with software. you can never be sure it is 100% secure. i agree completely with your point that exposing the system to more testing may ultimately result in the scrapping of automation altogether. however, i am of the opinion that if no further testing will be done the risk of it being manipulated later on -- God forbid on election day itself -- will remain a big concern.

you mentioned that the system was subjected to testing during the armm elections. i have a few questions. what exactly was tested then? what was it tested for? was it tested for vulnerabilities or just to see if it works? don&#039;t get me wrong these are not rhetorical questions i&#039;m really asking because i&#039;m a little confused with the whole set up. if the system was tested before then it means the system -- hardware and software -- is already in place. if that&#039;s the case then what the heck is being bidded out now? i&#039;m thinking if we&#039;re just about to procure new or additional hardware and/or software for this then it would be prudent to conduct further testing. just my thoughts.

if only the government handled this whole automation business more seriously right from the beginning. the way it has turned out the government didn&#039;t even have a clear timetable for it. i mean had the government set a definite timetable, which should have also covered vulnerability tests, and stuck to it then this whole automation business would have been conducted more smoothly. 

i&#039;m not sure if i&#039;m making sense here and i blame the government particularly the comelec for it. all their dillydallying and non-transparency have made a mess of everything.

btw, i heard from the grapevine that a local group once presented their own automated system to the comelec a couple of years back. (btw, this group isn&#039;t the computer professionals&#039; union you talked about in your previous post.) the system they presented is purely software, one that can be installed and run effectively on ordinary computers. the group explained that this feature alone would cut down the cost of automating the system significantly. of course, the group also highlighted the fact that their system is proudly philippine made. the group even offered to have the system tested/hacked by anyone. to cut the story short, the comelec as a whole was apparently impressed with the system. but then, after the presentation., a ranking comelec official asked the group, &quot;do you have foreign partners?&quot; hmm. why ask the question when the group was quite clear on their being all filipino right from the start. does the comelec have a fascination for foreign entities? if so, why?

to this day this group continues to wait for the comelec to give their system another look but to no avail.</description>
		<content:encoded><![CDATA[<p>i see your point. that&#8217;s the problem with software. you can never be sure it is 100% secure. i agree completely with your point that exposing the system to more testing may ultimately result in the scrapping of automation altogether. however, i am of the opinion that if no further testing will be done the risk of it being manipulated later on &#8212; God forbid on election day itself &#8212; will remain a big concern.</p>
<p>you mentioned that the system was subjected to testing during the armm elections. i have a few questions. what exactly was tested then? what was it tested for? was it tested for vulnerabilities or just to see if it works? don&#8217;t get me wrong these are not rhetorical questions i&#8217;m really asking because i&#8217;m a little confused with the whole set up. if the system was tested before then it means the system &#8212; hardware and software &#8212; is already in place. if that&#8217;s the case then what the heck is being bidded out now? i&#8217;m thinking if we&#8217;re just about to procure new or additional hardware and/or software for this then it would be prudent to conduct further testing. just my thoughts.</p>
<p>if only the government handled this whole automation business more seriously right from the beginning. the way it has turned out the government didn&#8217;t even have a clear timetable for it. i mean had the government set a definite timetable, which should have also covered vulnerability tests, and stuck to it then this whole automation business would have been conducted more smoothly. </p>
<p>i&#8217;m not sure if i&#8217;m making sense here and i blame the government particularly the comelec for it. all their dillydallying and non-transparency have made a mess of everything.</p>
<p>btw, i heard from the grapevine that a local group once presented their own automated system to the comelec a couple of years back. (btw, this group isn&#8217;t the computer professionals&#8217; union you talked about in your previous post.) the system they presented is purely software, one that can be installed and run effectively on ordinary computers. the group explained that this feature alone would cut down the cost of automating the system significantly. of course, the group also highlighted the fact that their system is proudly philippine made. the group even offered to have the system tested/hacked by anyone. to cut the story short, the comelec as a whole was apparently impressed with the system. but then, after the presentation., a ranking comelec official asked the group, &#8220;do you have foreign partners?&#8221; hmm. why ask the question when the group was quite clear on their being all filipino right from the start. does the comelec have a fascination for foreign entities? if so, why?</p>
<p>to this day this group continues to wait for the comelec to give their system another look but to no avail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://www.betterphilippines.com/uncategorized/p100m-reward-for-hacking-of-automation-system/comment-page-1/#comment-93</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Tue, 21 Apr 2009 00:01:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.betterphilippines.com/?p=304#comment-93</guid>
		<description>Perhaps Comelec Spokesperson James Jimenez could have pointed out that the only testing required by the law RA 9369 or the Amended Automated Election Law is the pilot testing of the Automated Election System and this was already done in ARMM.

Further assurances could have been gotten by the groups and personalities now advocating for further &quot;testing&quot; if they attended the hearings or deliberations on the technical aspects of the automated election system.

And also, the more you open the Automated Election System to attempts at hacking, the more vulnerable it becomes.  If you open it up right now, especially if people get access to the source code, you&#039;ll be able to map out exactly how you can manipulate the system.  It&#039;ll take time to rework the flaws plus to reinstall new security features and in the end, Comelec may not implement it.

That&#039;s the real danger and if we don&#039;t get to have automated elections in 2010, we will never have automated elections ever.

This is what is really getting to me, BP.</description>
		<content:encoded><![CDATA[<p>Perhaps Comelec Spokesperson James Jimenez could have pointed out that the only testing required by the law RA 9369 or the Amended Automated Election Law is the pilot testing of the Automated Election System and this was already done in ARMM.</p>
<p>Further assurances could have been gotten by the groups and personalities now advocating for further &#8220;testing&#8221; if they attended the hearings or deliberations on the technical aspects of the automated election system.</p>
<p>And also, the more you open the Automated Election System to attempts at hacking, the more vulnerable it becomes.  If you open it up right now, especially if people get access to the source code, you&#8217;ll be able to map out exactly how you can manipulate the system.  It&#8217;ll take time to rework the flaws plus to reinstall new security features and in the end, Comelec may not implement it.</p>
<p>That&#8217;s the real danger and if we don&#8217;t get to have automated elections in 2010, we will never have automated elections ever.</p>
<p>This is what is really getting to me, BP.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

