First of all, I want to make it clear that I'm not accusing anybody for anything mischievous, but...
don't you think it's almost trivial to manipulate the results of that poll? One can create tens of bogus accounts and use'em to change the results, eh?
Where there is a will, there is a way
... or they can create'em on other drupal affeliated sites, then just logon and vote. But as you correctly said (and let me generalize a bit), any system is gameable!
Personally, I don't know any of the candidates, and accordingly have no reason to doubt any, but vandalism is such an entertaining subject to many script kiddies and net junkies, especially when you give them an easy hunt.
I was in a seminar a few days ago about voting machines. The speaker had a degree in computer science and humanities, too, and it was a nice seminar indeed. He touched upon the issue of how electronic voting machines/systems are much susceptible to manipulation and how this might have been the case in the recent American presidential elections.
Anyway, I really don't have much to add here, maybe my post is even irrelevant, though I just wanted to know if you guys are concerned or not.
p.s. Hmm.. this "all the candidates are well known members of the community" doesn't sound quite appealing to me. It's somehow like the "us and them" thing.
you can only login from an
you can only login from an affiliated website if you already logged in before, as I said we disabled new member registration for the duration of the voting. I doubt anyone has been planning for months to interfere with the voting process.
we are not suggesting this system should be used for country elections, any system is gameable what you do is find a good point of balance.
since you must be an active member of the community in order to qualify for adminstrator position and since it's quite easy for the community to demote an admin if needed I don't think we should worry.
if PGP/GPG get's easier or more common we could use new voting system that involves signing your ballot. (debian does that AFAIK)
cheers,
Alaa
http://www.manalaa.net "context is over-rated. who are you anyway?"
Let me add
Even if someone has been planning to interfere, I don't think he had enough time because this election just came out suddenly.. It's not the routine (every xx years) elections.

yeah but they'll have to
yeah but they'll have to create them before elections (new accounts are disabled), and do that over a period of time (several accounts at once would be noticed), and use different emails.
so it takes a bit of an effort to game the system, any system we'll come up with that does not exclude the majority of the members will always be gameable.
all the candidates are well known members of the community, we've got no reason to suspect them, we've got a list of voters that you can look at.
cheers,
Alaa
http://www.manalaa.net "context is over-rated. who are you anyway?"