|
|
| |
|
| |
|
Security Measures
Obviously, security is a concern whenever online voting is brought
up. Here at CollegeVote.com, we want you to feel confident that your
election will run without any worries about a hacker altering the
results. Hopefully reading this section of our site will help put
your fears at ease. |
| |
|
Our Programmers
- The CV.com programming team has over 10 years experience.
- One member is a key contributor and developer for the NewsPro
Technology. This content management system is used on over 10,000
sites. Varying from the University at Buffalo's GENERATION Magazine,
to Swedish fishing communities, and at least 100 different Quake
gaming sites.
|
| |
|
Our 24 Security Precautions
1. CollegeVote.com uses the Secured Socket Layer protocol
(SSL) to transmit votes (that's why you see https:// as opposed
to http://). SSL is one of the most commonly used secure transmission
protocols used on the World Wide Web. It is so secure that credit
card companies approve its use when transmitting credit card numbers.
2. CollegeVote.com has its own encryption method, guaranteeing that
even if a person managed to get past the initial SSL encryption,
they would have to get past ours as well.
3. If a hacker wanted to cast a vote as another person, they would
need access to a valid voter’s school email address, and their
private email password. This would violate their school’s
policies and procedures and put them at legal risk with their school.
4. We can trace IP addresses and other logged information from votes,
to ensure that if someone starts trying to hack into our system,
we can find them!
5. The election log file will also be compared to log files of similar
schools, looking to see if someone even tried tampering with the
election.
6. No hacker can attempt to guess any user's password more than
three times. After the 3rd attempt, their account is shut down for
a 20 minute time period.
7. Password combinations are in the TRILLIONS. For a person to "brute
force" their way in, it would take countless HOURS to get just
one user's password – even if they could get past the three
attempts per 20 minutes! For all this effort, that hacker can only
vote ONCE with that user name. Since our elections only run for
the maximum of a week, and there is no way a hacker could use brute
force to alter the results of an election.
8. All of our database information has the potential to be encrypted.
9. All of the data on our server is backed up on a second server.
This protects information in case of power failure, internet failure,
and natural disaster.
10. Our servers have redundant power systems and back up generators
to ensure that most disasters will not compromise the election.
11. There are surge protectors guarding our server.
12. We have redundant DNS Services, so that access to our site is
always available.
13. Any updates or service packs created for CollegeVote.com will
not be installed within one week of receiving your candidate information.
This ensures that no candidate can pay CollegeVote.com off!
14. EVERY member of the staff at CollegeVote.com is willing to submit
to a lie detector test to verify that they did nothing to alter
the results of an election.
15. All of our code is created under the programming language's
most strict security settings, ensuring that data cannot be compromised
through malicious attacks.
16. All internet communications are screened for malicious content
before accepted into our system.
17. Any non-ballot information coming into our server is immediately
disregarded, and ignored.
18. Denial of Service (DOS) attacks are minimized through our package
filtering techniques, and because DOS attacks would have to come
from campus, they would violate the college or Universities computing
Policies and Procedures.
19. Because we are tied into each University's system via email,
any student who attempts to hack an election can be held responsible
for violating their school's computer regulations.
20. All code is rechecked by our programming staff on a regular
basis, ensuring that there are no loopholes created.
21. Security patches and service packs are updated in a timely manner.
22 . We often challenge independent hacker groups to test our system,
and try to find weaknesses. If you would like your university to
participate in the next hacker challenge, send us an e-mail to hackerchallenge@CollegeVote.com
23 . CollegeVote.com developed its own file locking and sharing
system to ensure that every vote is counted, without fail.
24 . No person outside our programming team has access to the current
results during an election. The final count is the only thing that
is made public. |
|
|