Slashdot Mirror


The Diebold Voting-Machine Hack

Warm John writes to mention a short article on Doctor Dobbs Journal about the Hack that couldn't be done. "Hacking a Diebold voting machine was the focus of Cigital's Gary McGraw's keynote at SD Best Practices. He discussed 'Security Analysis of the Diebold AccuVote-TS Voting Machine,' a paper released by Edward Felten, Ari Feldman, and Alex Halderman of the Princeton Center for Information Technology Policy. 'The paper details a simple method whereby the Princeton team was able to compromise the physical security of a Diebold voting machine, infecting it with a virus that could change voting results and spread by memory-card to other machines of the same type.'"

23 of 277 comments (clear)

  1. meme seems appropriate by xanie · · Score: 5, Funny

    I'm in your voting machine stealing your election.

    --
    Fundamentalism stops a thinking mind.
  2. Money more important than a fair vote? by ronkronk · · Score: 4, Insightful

    Man Diebold looks slimier and slimier every passing week, but I'm more disturbed by Joe Demma's, Salt Lake's chief elections officer, response to Bruce Funk's actions. Granted, Funk acted by going around Demma by calling in Black Box Voting to check the Diebold machines, when presumably Demma is supposed to be responsible for that (just my guess as he's the chief elections officer).

    However, Demma seems more incensed at Funk because he may cost the state $40,000 for Diebold's astronomical recertification fee. He doesn't seem to be worried that people might not trust these machines. He doesn't seem to care that a state officer was worried enough to call in a non-profit third party to verify the integrity of these machines. I mean, these things could possibly affect the outcome of a vote, the foundation for a democratic republic! But instead of worrying about these machines he's clearly more upset about the $40,000 and Funk not talking to him about his concerns regarding the voting machines.

    And of COURSE Diebold is going to tell you the machines are fine and fair. Sheesh, they want to make money don't they?

    Isn't it great that chief elections officers have their priorities straight?

    Give me a ballot sheet and a pencil any day over these closed, proprietary black box machines.

    1. Re:Money more important than a fair vote? by partisanX · · Score: 4, Insightful

      Nobody in their right mind who cares about the stability of our democratic republic could condone a continuation of these scandals. If we can't trust the vote, then we can't trust anything about the government, and when enough people feel that way in a democratic republic, bad things happen.

      --
      "Our morality is good, theirs is repressive."- Partisanship Rule #3
    2. Re:Money more important than a fair vote? by Mikkeles · · Score: 4, Interesting

      Avi Ruben also has an interesting blog article on his experiences as a poll worker in the recent Maryland election.

      --
      Great minds think alike; fools seldom differ.
    3. Re:Money more important than a fair vote? by dgatwood · · Score: 4, Insightful

      Nobody in their right mind who understands what's going on can condone the existence of closed-source software in the vote counting or vote taking process at all, whether by Diebold or otherwise.

      If elections officials told the public, "We're going to count by a secret counting method and we won't tell you how we're going to count; you'll just have to trust us that we picked the right person for the job," the public would burn down city hall. Unfortunately, the public hasn't yet realized that this is exactly what is happening....

      Anybody want to raise money for a front page ad in the NY Times? Maybe with a little extra money left over to donate to local fire departments? :-)

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

    4. Re:Money more important than a fair vote? by partisanX · · Score: 4, Insightful

      Golly, do you people lack reading comprehension or just critical thinking skills?

      Funny, I didn't get the feeling the poster mentioned closed source so much to advocate open source software, as to draw the clear paralell between that and a secret ballot counting method implementation. Let me re-read... Yep, he didn't mention using Open Source at all, he mentioned closed source and then followed it with the very valid, extremely painfully obvious paralell between that and a secret ballot counting procedure.

      Do you see that now or is there a problem with YOUR reading comprehension or critical thinking skills?

      --
      "Our morality is good, theirs is repressive."- Partisanship Rule #3
    5. Re:Money more important than a fair vote? by symbolic · · Score: 4, Insightful

      However, Demma seems more incensed at Funk because he may cost the state $40,000 for Diebold's astronomical recertification fee.

      Huh? Diebold is certifying its own machines? To say that this is like the fox guarding the henhouse would be a gross oversimplification...it's more like the fox has control of a large percentage of the henhouses throughout the country, and is working diligently to ensure this does not change.

    6. Re:Money more important than a fair vote? by megaditto · · Score: 4, Funny
      If elections officials told the public, "We're going to count by a secret counting method and we won't tell you how we're going to count; you'll just have to trust us that we picked the right person for the job," the public would burn down city hall.


      If elections officials told the public, "To protect your Freedom we are going to count by an undisclosed counting method and we won't help terrorists by telling the evildoers how we're going to protect the public and count the votes; you'll just have to support our troops and the person we picked for the job," the public would greet you as liberators

      There, corrected it for ya.
      --
      Obama likes poor people so much, he wants to make more of them.
  3. Scary by sm62704 · · Score: 4, Informative

    In Illinois we get a paper printout that you check for accuracy and put in a ballot box; we can actually have a real recount.

    That's incredibly weird, considering this IS Illinois, where they say "vote early, vote often," where dead people still have a right to vote, and the last two governors who lost elections went to prison (or will, in the case of Ryan).

    --
    mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
  4. America Has A Rootkit by Jeremiah+Cornelius · · Score: 5, Funny

    And no, SpybotSD can't help you.

    --
    "Flyin' in just a sweet place,
    Never been known to fail..."
  5. Re:The box was not production hardware... by ronkronk · · Score: 4, Interesting

    I've seen plenty of pro-Microsoft and pro-Diebold posts get modded up. All you have to do is have a clear point, and show it. You didn't manage that. You said the fraud happens, and it doesn't make a difference if we can trace it or not.

    It does make a difference. With a punch card, or a paper ballot, or even a mechanical voting both anyone can trace when fraud has occured. And in those cases we implement some security, track where the fraud came from (if we can) and redo the election.

    With the current generation of electronic voting machines, we can't do that. I don't care who makes a good machine, but Diebold hasn't made one. And they've defended that design as if they think it is a good machine. Geeks don't like people who pretend a bad design is a good design. We'll tear into them. If they routinely defend bad design by saying it is good design and overlooking what we think are obvious flaws we'll notice, and start to expect that. Until they change, a group that decides who they like on the technical ability of a company won't like them. They are lying about their technical quality; at least in our eyes.

  6. Re:The box was not production hardware... by rodgster · · Score: 4, Interesting

    Maybe this is an example of free market forces at work.

    One customer wants a secure, hardened, auditable, time proven machine with a user verifiable paper trail.

    The other doesn't need any of those features.

    Therefore two entirely disparate product lines.

    One is designed to protect $.

    The other is designed to protect democracy.

    --
    Who will guard the guards?
  7. Re:The box was not production hardware... by Frymaster · · Score: 4, Interesting
    Geeks don't like people who pretend a bad design is a good design. We'll tear into them

    it's called 'peer review' and in the science world it's not only expected but mandatory.

    my question is this: has diebold's product undergone any sort of peer review? if it's important enough for someone studying the genetic inheretance of grey hair, it's important enough for someone entrusted with running an election for the most powerful person in the world, dontcha think?

  8. Re:Could be modded as flamebait... by nezroy · · Score: 4, Informative
  9. Re:The first person to do this is going to be stup by Marxist+Hacker+42 · · Score: 4, Interesting

    I'll get mod-bombed right back down to Good Karma for this- but I have to say that I'm not at all sure it didn't happen in Ohio and Florida in 2004. The exit poll numbers, which had previously been extremely accurate in just about every election I'd ever heard of, were way off in those two states on the Presidential race- but the numbers were close enough that everybody focused on recounts instead (where possible).

    --
    SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
  10. We've heard it before but... by Sgt_Jake · · Score: 5, Interesting

    How come no one seems to be asking the slot machine manufacturers to make voting machines? They deal with millions - or billions - of dollars a day and seem to be able to account for every single penny accurately. As an added bonus, all they'd really have to do is change the 7's to donkeys and jackpots to republicans... Pull the lever for your new rep! Seriously though - they're the people who should be making the machines...

    1. Re:We've heard it before but... by hmccabe · · Score: 4, Funny

      A vote for Cherry is a vote for Plum. Thanks for throwing away your vote, asshole.

  11. The video is excellent by bsandersen · · Score: 4, Insightful
    I have just finished watching the video on the Princeton site and I must say it is very well done. Any reasonably motivated alert person who watches this video will see the problem we're trying to highlight.

    It isn't enough for computer software professionals to discover problems like this; we need to be able to communicate our results effectively to the non-technical public. Too often we find something disturbing and decend into technical jargon and lose our audience. The Princeton team has done an excellent job avoiding that pitfall and communicating this threat.

    Now, if only we could find a reasonably motivated and alert politician to actually act on this.

  12. Re:firmware flash by __aaclcg7560 · · Score: 5, Funny

    You don't want to do any flashing around these machines. The little old ladies behind the voting table will be watching you like a hawk and they're swoop down on you so fast with their canes before you could even think about flashing anyone. If you want a safe voting experience, you must see no evil, hear no evil or speak no evil when the voting machine flashes you!

  13. Re:Soo.. by OWJones · · Score: 5, Informative

    Thank you for stealing an earlier post of mine absolutely verbatim.

    -the real jdm

  14. My experience with Diebold by Anonymous Coward · · Score: 4, Funny


    Welcome to democratic government, brought to you by Diebold(R)!

    Please choose a candidate:
    (1) The incumbent guy who's against the terrorists.
    (2) The weasly other guy who likes terrorists and wants your child to
            be gay.

    [press 2]

    You have chosen option (2), for gay marriage. Are you sure?

    [press no]

    Please choose a candidate.

    [press 2]

    Let's not be too hasty. We don't want the terrorists to feel good.
    Do you want the terrorists to feel good?

    [press no]

    You have chosen option (1), for the incumbent. Are you sure?

    [press cancel]

    This may forfeit your vote! Are you sure you wish to cancel not
    voting for option (1)?

    [press yes]

    Thank you for your participation in the democratic process! Printing
    receipt ...

    Sorry! Out of paper.

  15. Re:Who would want to tamper? Terrorists by Chris+Burke · · Score: 5, Funny

    The Possible Future, Nov 4th, 2008
    "While exit polls conducted by our station and others showed Sen. Hillary Clinton and Sen. John McCain neck-in-neck at nearly 50% in this highly contested state of Ohio, initial results from available precincts shows the winner of the state, and thus the country, as Osama bin Laden, with 107% of the vote. A tape allegedly featuring Mr. bin Laden was broadcast by the al Jazeera network just minutes ago, in which the terrorist mastermind said he was pleased by the clear mandate the capitalist pig masses had given him, and that he hoped his transition from a cave somewhere in Pakistan to the Oval Office would go smoothly. Back to you, Tom."

    I don't know, think that would wake people up?

    --

    The enemies of Democracy are
  16. Army of One by Doc+Ruby · · Score: 5, Informative

    Ed Felten is also the guy who hacked the MS DLL that "integrated" IE into Windows to remove IE without destroying the OS, proving in court that Microsoft's defense of their illegal bundling, "it was technologically necessary", was a lie. Though Felten was not even a Windows specialist, and certainly didn't have the source code to delete IE cleanly, he was the the key to the court finding that MS had violated their antibundling consent agreement, the key to finding they'd violated their monopoly status.

    Now he's the guy proving Diebold voting systems are insecure.

    Isn't anyone else in our giant, brilliant "computer science" industry doing anything? Or are they all working for the bad guys?

    --

    --
    make install -not war