Domain: bradblog.com
Stories and comments across the archive that link to bradblog.com.
Stories · 8
-
Will Hackers Try To Disrupt the Iowa Caucuses?
Hugh Pickens writes "The Iowa Republican Party is boosting the security of the electronic systems it will use to count the first votes of the 2012 presidential campaign after receiving a mysterious threat to its computers in a video urging its supporters to shut down the Iowa caucuses .... 'It's very clear the data consolidation and data gathering from the caucuses, which determines the headlines the next morning, who might withdraw or resign from the process, all of that is fragile,' says Douglas Jones, a computer science professor at the University of Iowa who has consulted for both political parties. The state GOP fears such a delay could disrupt the traditional influence of Iowa's first-in-the-nation vote. 'With the eyes of the media on the state, the last thing we want to do is have a situation where there is trouble with the reporting system,' says Wes Enos, a member of the Iowa GOP's central committee. The GOP is encouraging party activists who run the precinct votes to use paper ballots instead of a show of hands, which has been the practice in some areas so the ballots can provide a backup in the event of any later confusion about the results. 'There is really only one way — and it needn't be a secret — to help assure that results cannot easily be manipulated by either Anonymous or by GOP officials themselves,' writes Brad Friedman. 'The hand-counted paper ballot system, with decentralized results posted at the "precincts," is the only way to try and protect against manipulation of the results from either insiders or outsiders.'" -
DC Suspends Tests of Online Voting System
Fortran IV writes "Back in June, Washington, DC signed up with the The Open Source Digital Foundation to set up an internet voting system for DC residents overseas. The plan was to have the system operational by the November general election. Last week the DC Board of Elections and Ethics opened the system for testing and attracted the attention of students at the University of Michigan, with comical results. The DC Board has postponed implementation of the system for 'more robust testing.'" Update: 10/06 02:42 GMT by T : University of Michigan computer scientist J. Alex Halderman provides an explanation of exactly how the folks at Michigan exploited the DC system. -
Kentucky Officials "Changed Votes At Voting Machines"
The indispensible jamie found a report out of Kentucky of exactly the kind of shenanigans that voting-transparency advocates have been warning about: a circuit court judge, a county clerk, and election officials are among eight people indicted for gaming elections in 2002, 2004, and 2006. As described in the indictment (PDF), the election officials divvied up money intended to buy votes and then changed votes on the county's (popular, unverifiable) ES&S touch-screen voting systems, affecting the outcome of elections at the local, state, and federal levels. -
Diebold Admits Flaw In Voting Software
NewYorkCountryLawyer writes "At a public hearing in California, Diebold's western region manager has admitted that the audit log system on current versions of Premier Election Solutions' (formerly Diebold's) electronic voting and tabulating systems — used in some 34 states across the nation — fails to record the wholesale deletion of ballots, even when ballots are deleted on the same day as an election. An election system's audit logs are meant to record all activity during the system's actual counting of ballots, so that later examiners may determine, with certainty, whether any fraudulent or mistaken activity had occurred during the count. Diebold's software fails to do that, as has recently been discovered by Election Integrity advocates in Humboldt County, CA, and then confirmed by the CA Secretary of State. The flaws, built into the system for more than a decade, are in serious violation of federal voting system certification standards." -
Master Diebold Key Copied From Web Site
Harrington writes "In another stunning blow to the security and integrity of Diebold's electronic voting machines, someone has made a copy of the key which opens ALL Diebold e-voting machines from a picture on the company's own website. " Update: 02/06 17:40 GMT by Z : We previously discussed this story, early last year. -
Diebold Security Foiled Again
XenoPhage writes "Yet again, Diebold has shown their security prowess. This time they posted, on their website, a picture of the actual key used to open all of their Diebold voting machines. Ross Kinard of Sploitcast crafted three keys based on this photo. Amazingly enough, two of the three keys successfully opened one of the voting machines. But fear not, Diebold has removed the offending picture, replacing it with a picture of their digital card key. Take that, hackers!" -
Opening Diebold Source, the Hard Way
Doc Ruby writes to tell us about an article in the Baltimore (MD) Sun, reporting that someone sent a package to a former legislator containing what appears to be Diebold source code. From the article: "Diebold Election Systems Inc. expressed alarm and state election officials contacted the FBI yesterday after a former legislator received an anonymous package containing what appears to be the computer code that ran Maryland's polls in 2004... The availability of the code — the written instructions that tell the machines what to do — is important because some computer scientists worry that the machines are vulnerable to malicious and virtually undetectable vote-switching software. An examination of the instructions would enable technology experts to identify flaws, but Diebold says the code is proprietary and does not allow public scrutiny of it." Read on for more of Doc Ruby's comments and questions.
Maryland's primary elections last month were ruined by procedural and tech problems. Maryland used Diebold machines, even though its Republican governor "lost faith" in them as early as February this year, with months to do something about it before Maryland relied on them in their elections.
The Diebold code was secret, and was used in 2002 even though illegally uncertified — even by private analysts under nondisclosure. Now that it's being "opened by force," the first concern from Diebold, the government, and the media is that it could be further exploited by crackers. What if the voting software were open from the beginning, so its security relied only on hard secrets (like passwords and keys), not mere obscurity, which can be destroyed by "leaks" like the one reported by the Sun? The system's reliability would be known, and probably more secure after thorough public review. How much damage does secret source code employed in public service have to cause before we require it to be opened before we buy it, before we base our government on it? -
Diebold Insider Comments on Voting System Flaw
Call Me Black Cloud writes "A Diebold insider is blowing the whistle on the company's continued lack of concern about security holes in its voting software. The insider wrote to Brad Friedman, a somewhat shrill political blogger, claiming the company is instructing technicians to keep quiet about the security flaws. This is despite the vulnerability being listed on the US-CERT website for the last year. A Diebold company rep admits the software can be remotely accessed via modem, but states, "it's up to a jurisdiction whether they wish to use it or not...I don't know of any jurisdiction that does that." The insider disputes that, claiming several counties in Maryland made use of the feature in 2004." This in addition to the fact that Blackboxvoting already hacked the system using a chimp last year.