>> On 31 Mar 2003 12:02:14 -0500,
>> Aaron M Ucko <[EMAIL PROTECTED]> said: 

 > Like Sam, I see no particular need for salt beyond the
 > username. However, I did notice a potential anonymity attack: the
 > presence of consistent partial voter lists and dummy tally sheets
 > leaked some information about which voters could have which hashes.

        Wrong.


        Have you actually tried this? the dummy tally sheet is
 present, as is the final tally sheet. Notice that the md5sums show no
 correlation?

        The dummy tally sheet, is just that, a dummy. 

        manoj
-- 
 There's some entertainment value in watching people juggle
 nitroglycerin. Larry Wall in <[EMAIL PROTECTED]>
Manoj Srivastava   <[EMAIL PROTECTED]>  <http://www.debian.org/%7Esrivasta/>
1024R/C7261095 print CB D9 F4 12 68 07 E4 05  CC 2D 27 12 1D F5 E8 6E
1024D/BF24424C print 4966 F272 D093 B493 410B  924B 21BA DABB BF24 424C


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to