So secure was the annual contest to fill three director and four officer positions that when one trustee lost his cryptographic key to unlock the results, the error made it impossible.

  • Technus@lemmy.zip
    link
    fedilink
    English
    arrow-up
    96
    ·
    22 hours ago

    Assuming they were using threshold cryptography, they could have easily configured some redundancy into the system, e.g. by requiring 3 out of 5 people to decrypt it instead of 3 of 3.

    It’s easy to blame the one guy for losing the key, but he could have gotten hit by a bus or lost the hard drive in a house fire and they would have been equally as screwed. This is more of a system design failure than a PEBKAC failure.

    • quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      8 hours ago

      The article concludes that’s exactly what they’re doing. Both changing to 2/3 and also providing clearer instructions to key holders.

    • Pup Biru@aussie.zone
      link
      fedilink
      English
      arrow-up
      45
      ·
      21 hours ago

      in complex systems design, you never blame human error. humans are fallible, and if the system doesn’t account for human error then it’s just a matter of time until failure occurs. look for a way to make the system tolerate or eliminate human error

      • Tar_Alcaran@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        11
        ·
        16 hours ago

        Normal error theory even takes the view that errors are inevitable in complex systems and that you need to design them so that the effects of those errors can’t escalate.

        • Pup Biru@aussie.zone
          link
          fedilink
          English
          arrow-up
          3
          ·
          14 hours ago

          literally the same concept as a comment i just wrote about russian hypersonic missiles breaking apart mid flight because they didn’t put limits on how fast they can change course when going mach 5 aha

      • SuperNovaStar@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        4
        ·
        16 hours ago

        look for a way to make the system tolerate human error

        Ah, if only managers understood this principle.

        My motto is that “all failures are management failures.” But I’m not far enough up the chain to really implement that 😅

      • fatalicus@lemmy.world
        link
        fedilink
        English
        arrow-up
        18
        ·
        16 hours ago

        Which is stupid, since the reason they had 3/3 was that two people could not collaborate to change the results, which they now can with 2/3.

        Should have been changed to 3/5 instead.

        • Technus@lemmy.zip
          link
          fedilink
          English
          arrow-up
          3
          ·
          14 hours ago

          Exactly, it’s worse all around.

          And it’s not like it’s hard to use a different configuration; the threshold and total number of keys are just parameters of the algorithm.