Electronic Voting Machine Cracker Challenge
An anonymous reader writes "In the ongoing debate on the security of electronic voting, an Atlanta area programmer has confronted Georgia election officials on the potential for fraud in its statewide electronic voting system. She claims that she can be prepared to crack the system within a week, and officials have accepted the challenge." What makes this even more interesting is that the election officials are encouraging the woman, so that any possible exploit can be found and remedied.
Moreover, they said, paper ballots can be tampered with more easily than electronic ones, and they're harder to tabulate.
Sorry, don't believe that. A few locations in memory are easier to change than thousands of paper ballots. Hanging chads notwithstanding...
Nice comeback at the end -
Asked Williams, the computer security expert: "Are you saying there's no such thing as a secure and accurate computer? Do you fly on airplanes?"
I think I'd counter that by asking if he knew of any airplane where all members of the general public were allowed access to the terminals used by the pilots? And if so - does he fly with them?
I don't think I'm very happy. I always fall asleep to the sound of my own screams.
It's going to be her and several other programmers. they have had the source code for months, and know what the problem is. the machines run windows and Access.
blackbox Voting
photosMy Photostream
Although it's good to have an independant security audit of the hardware/software, it's still a far cry from what I would call development of a secure system.
...? What are the logging/auding possibilities? How secure is the data transmitted? How secure is that data stored?
...
Did an independant auditor (or security specialist) audit the design - both hardware and software - from a security point of view? Where there independant audits/reviews of the coding or assembly of the hardware? Can you trust the developers or factory workers? Who is monitoring the deployment, development, good working,
Who will monitor the people who are in charge of the system?
Ultimately, you have to trust someone. And putting trust in the wrong kind of people is the biggest security risk there is
http://blog.astyran.sg
[100% ISO 646 Compliant]
SVM, ERGO MONSTRO.