Victor's Blog about the Web, Security and Life

The web for me is a hobby where standards and best practices are daily bread. Security is a concern that everybody must be aware of its details for IT in general, and the web in particular, to be a safer place. My life, on the other hand, is that of a regular Lebanese citizen where politics and social issues are discussed on a daily basis. I hope you enjoy reading my blog and make sure to drop me a comment about any topic you find interesting.

Hacking the Papal Election

Printable Version

victor | 16 April, 2005 08:31

This is an amazing article by my favourite Bruce Schneier sent in his April's CryptoGram Newsletter.

The rules for papal elections are steeped in tradition, and were last codified on 22 Feb 1996. The document is well-thought-out, and filled with details. The article elaborates on the election process overview, then on hacking the election process, concluding that the process itself is secure.
The original article can be found here:
http://www.schneier.com/crypto-gram-0504.html

A summary or the process follows below. The hacking process and the conclusion of Mr. Schneier can be found under the link above.

Election Process Overview


Major points of notion:
  • The election place is a church.
  • The ballot is entirely paper-based.
  • Ballot counting is done by hand.
  • Votes are secret, but everything else is done in public.

Pre-scrutiny phase
  • At least two or three paper ballots are given to each cardinal (including extras in case of mistakes)
  • Nine election officials are randomly selected
    • three "Scrutineers" who count the votes
    • three "Revisers," who verify the results of the Scrutineers
    • three "Infirmarii" , chosen randomly for each ballot, who collect the votes from those too sick to be in the room.
Voting Phase
  • Each cardinal writes his selection on a rectangular ballot paper
  • Emphasizes on handwriting that cannot be identified as his
  • Paper is folded lengthwise and holds it aloft for everyone to see.
Scrutiny Phase
  • Cardinals proceed to the altar one by one.
  • Each cardinal places his folded ballot on the paten (on the altar).
  • Then he picks up the paten and slides his ballot into the chalice.
  • If a cardinal cannot walk to the altar
    • one of the Scrutineers -- in full view of everyone -- does this for him.
  • If any cardinals are too sick to be in the chapel
    • the Scrutineers give the Infirmarii a locked empty box with a slot, and the three Infirmarii together collect those votes.
    • If a cardinal is too sick to write, he asks one of the Infirmarii to do it for him with the other two watching over.
    • The box is opened and the ballots are placed onto the paten and into the chalice, one at a time.
When all the ballots are in the chalice
  • the first Scrutineer shakes it several times in order to mix them.
  • the third Scrutineer transfers the ballots, one by one, from one chalice to another, counting them in the process.
If the total number of ballots is not correct, the ballots are burned and everyone votes again.

To count the votes
  • each ballot is opened and the vote is read by each Scrutineer in turn, the third one aloud.
  • Each Scrutineer writes the vote on a tally sheet.
  • This is all done in full view of the cardinals.
  • The total number of votes cast for each person is written on a separate sheet of paper.

Post-scrutiny phase
  • The Scrutineers tally the votes and determine if there's a winner.
  • The Revisers verify the entire process: ballots, tallies, everything.
  • Then the ballots are burned. (That's where the smoke comes from: white if a Pope has been elected, black if not.)

References:
Related Articles:

Comments

Re: Hacking the Papal Election

Victor | 10/11/2005, 08:05

How about taking some religion while there ;)

Security Assessment

Paul-Marc Bougharios | 04/11/2005, 06:28

So we're supposed to take out from this that:
- a system that overcame time is good
- Small related community, where everyone knows everyone, create hard-to-attack system (Authenticity, accountability)
- Place (Sistine Chapel) where only concerned pple are in (Authenticity again, Integrity)
... and u know the other stuff...

Add comment
 
Accessible and Valid XHTML 1.0 Strict and CSS