Slashdot Mirror


Hackers Invited To Crack Internet Voting

InternetVoting writes "The Philippine government and the International Foundation for Electoral System will be soliciting hackers to test the security of of their Internet voting system that will be tested in an upcoming pilot program." From the article,"Local and foreign computer hackers will be tapped to try and break into an Internet-based voting system that will be pilot tested by the country's Commission on Elections (Comelec) starting July 10."

18 of 119 comments (clear)

  1. So... by Anonymous Coward · · Score: 3, Insightful

    they got a formal invitation this time?

    I'm sure all the REAL hackers will RSVP.

    1. Re:So... by goombah99 · · Score: 5, Funny

      This is going to piss off that teenager in Helsinki that's been running their elections.

      --
      Some drink at the fountain of knowledge. Others just gargle.
  2. What if by killa62 · · Score: 5, Funny

    1. Find bug
    2. Don't report it
    3. ????
    4. Profit!

    1. Re:What if by quanticle · · Score: 4, Insightful

      Two words: honeypot system.

      The way I would do something like this is to put the voting system inside a fully monitored and logged virtual machine. Then I would open it up to hackers, knowing that all changes to the system state will be logged and can be scanned for malicious actions.

      --
      We all know what to do, but we don't know how to get re-elected once we have done it
    2. Re:What if by Anonymous Coward · · Score: 3, Funny

      Madness...? This IS PHILIPPINES!

    3. Re:What if by mackyrae · · Score: 3, Insightful

      I think they're trusting that more than one person will notice it. With OSS, we know that it's possible someone will find a security bug and not report it because that would benefit them. We also figure that there's a high enough probability of someone else noticing too that the first person's secrecy will be nullified anyway. With the people who pay for each issue you find, the hacker has a better shot at cash through trying to report it first than through hoping nobody else does.

      --
      look! it's a bird, it's a plane, it's....a girl? yes, a girl browsing Slashdot on Linux
  3. Update by Aqua+OS+X · · Score: 5, Funny

    Posted by samzenpus on Wednesday April 18, @10:43PM

    "The Philippine government and the International Foundation for Electoral System will be soliciting hackers to test the security of of their Internet voting system that will be tested in an upcoming pilot program."

    UPDATE:
    Posted by samzenpus on Wednesday April 18, @10:53PM
    Internet voting has now been cracked.

    --
    "Things are more moderner than before- bigger, and yet smaller- it's computers-- San Dimas High School football RULES!"
  4. Phillipine Election 2008 Headlines: by Organic+Brain+Damage · · Score: 5, Funny

    Ferdinand Marcos elected for another term as President with 3,000,000,000 votes. Runner up, D4v1d 3. P3t3rs0n had only 2,000,000,000 votes. Second runner up, Nikolay Sokratov from St. Petersberg had 1,5000,000,000 votes and the remaining 10,000,000,000 votes were split among 1,000,000,000 minor party candidates.

  5. the philippines is famous by circletimessquare · · Score: 4, Interesting

    for handing out wads of cash to the poor to get them to vote a certain way come elections

    200 peso notes famously become scarce before elections

    no need to hack the system to alter the vote, just keep buying the votes

    the philippines is a beautiful land, with beautiful people... and a corrupt political establishment, it's a sad commentary on corruption the philippines, the vote buying

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
  6. Think they have not thought about that? by WindBourne · · Score: 5, Insightful

    Almost certainly, they are recording ALL the packets that travel across the line as well as checking the state of the system. And if not, then they deserve what will happen. And if it is on a OSS platform, then they will be able to modify the kernel so that it gives more info during the cracking attempt.

    --
    I prefer the "u" in honour as it seems to be missing these days.
    1. Re:Think they have not thought about that? by charlieman · · Score: 3, Funny

      What if it get's slashdotted?

  7. If you get in... by Anonymous Coward · · Score: 3, Funny

    ...make sure to add n+1 votes for CowboyNeal!

  8. Re:What a dumb idea by TodMinuit · · Score: 3, Insightful

    Of course any hacker with intentions of being a naughty boy is not going to show up and (a) make himself known or (b) reveal the holes.

    But freelance security professionals and security companies looking to make a name for themselves will.

    --
    I wonder if I use bold in my signature, people will notice my posts.
  9. It actually surprised me by grahamsz · · Score: 4, Interesting

    But someone I did some consulting for years ago had a PC security product that they claimed was unhackable. It was some disk arrangement where the OS could write to the disk, and those sectors would be saved in a scratch table so that when you rebooted the machine it reverted to its original state.

    They took it to one of the big conventions and had a briefcase with $10k in it for the first person that could make a permanant change to the disk without opening the case. Guys showed up with their own latex gloves so they wouldn't leave prints and one managed to come up with the proprietory vendor unique command set for the particular drive model that was in the system.

    I don't think that was really the sort of adversary that they expected would show.

  10. Re:So...failure to disclose vulnerability? by Yvanhoe · · Score: 3, Insightful

    Because they're living there ?
    Democracy is valued in some countries you know...

    --
    The Wise adapts himself to the world. The Fool adapts the world to himself. Therefore, all progress depends on the Fool.
  11. 100% foolproof guaranteed exploit by Builder · · Score: 3, Insightful

    1. Go to relatives house
    2. Hold gun to their head and insist that they vote for who you tell them to
    3. Watch them cast the vote
    4. Tell them that you will kill them and their pet rabbit if they tell anyone
    5. Win the election

    Sadly, that is a problem that will always exist if people aren't voting in a private cubicle in a public place.

    After the recent postal voting in the UK, it was found that many heads of families coerced the rest of the family into voting a certain way. That just can't happen in a private cubicle where you can always lie to dad later, but vote for who you want to now.

  12. Procedural comparison by Random+BedHead+Ed · · Score: 4, Insightful

    How things work outside the United States:

    • Government announces plan to implement a voting system.
    • Government devises detailed plan for a system, working with experts in field.
    • Government runs pre-launch plan for rigorous testing of system reliability. Experts invited to oversee tests.
    • System implemented, possibly with modifications based upon lessons learned in testing.

    How things work in the United States:

    • Government announces plan to implement a voting system.
    • Industry lobbyists head to Washington. Meet with lawmakers, attempting to steer business toward their sponsors.
    • Dinners held, bribes exchanged.
    • Select lawmakers refuse to give in to lobbyists, are denied funding for upcoming campaigns, lose next election. Most capitulate, are re-elected.
    • Revised bill reintroduced. Spending increased by a factor of 10.
    • Experts review bill, criticize flaws, are ignored. Who needs 'em?
    • Bill to implement system passes. Includes provision allowing NSA to nuke a US city without prior oversight if it finds suspicious activity in said city. Pre-absolves president of guilt for said annihilation. Also includes subsidy of corn processing industry in midwest, tax breaks for plastics industry executives. Last-minute rider added to provide additional funding for superhighway from Mexico to Kansas (now standard in all bills), and provide funding for evangelical law school that advocates a new wars to prevent the coming of the Antichrist.
    • President signs bill in televised ceremony. Pen used to sign bill is framed.
    • System implemented with no modifications. Massive failures nationwide.
    • Experts point out that they predicted failures, are ignored again. Who needs 'em? Industry spokespersons call experts 'communists trying to undermine the free market,' deny there are any problems. Evening news ignores story, focuses on a recent celebrity divorce.
    • Lawmakers vow to raise new spending bill to correct problems. Lobbyists return to Washington ...
  13. Re:Hey mods, supress your knee-jerk reaction by skarphace · · Score: 3, Insightful

    I would like to know what's so seriously wrong with Paper ballots counted by people that we want to abandon them? People have
    2000 Florida, USA is one example.

    I would like to know why so many places are trying to move to more expensive, more complex, less secure means of voting when a better method already exists. I'm all for using computers where they have a place, such as things like filing taxes, but I fail to see the need for computers in voting.
    You just answered your own question. It's exactly like taxes. It keeps you from having to go somewhere or mail something out to get (taxes/voting) done. This'll allow people to vote from work, take 5 minutes at breakfast to place their vote before leaving for work. All kinds of good reasons for the voters.

    It doesn't speed up the counting process.
    Oh yes it does. Tabulation takes seconds instead of days/weeks/months. You only have to do a hand count if it's challenged.

    It doesn't make it any cheaper.
    Yes it does. Computers are cheaper then people.

    And it doesn't put any extra security into the system.
    Now this is the #1 argument against electronic/internet voting. This is also the reason I'm still on the fence about the whole thing. There are many benefits but if all it accomplishes is to allow people to rig elections easier, then it's not worth it. Until they start paying more attention to the security aspect, I'm staying on the fence.
    --
    Bullish Machine Tzar