Slashdot Mirror


California Testers Find Flaws In Voting Machines

quanticle writes "According to Ars Technica, California testers have discovered severe flaws in the ES&S voting machines. The paper seals were easily bypassed, and the lock could be picked with a "common office implement". After cracking the physical security of the device, the testers found it simple to reconfigure the BIOS to boot off external media. After booting a version of Linux, they found that critical system files were stored in plain text. They also found that the election management system that initializes the voting machines used unencrypted protocols to transmit the initialization data to the voting machines, allowing for a man-in-the-middle attack. Altogether, it is a troubling report for a company already in hot water for selling uncertified equipment to counties."

15 of 167 comments (clear)

  1. WhiteHat Voting by JavaBear · · Score: 5, Insightful

    I have 2 solutions to all these problems.

    1: Do like the rest of the world, and use a HB #2 pencil.

    2: EFF and the rest of the American White hats get together and develop an Open Voting system, that are freely implementable by any state, that can withstand public scrutiny and peer review.

    1. Re:WhiteHat Voting by morgan_greywolf · · Score: 3, Interesting
      My wishlist of features:

      • All data is stored encrypted and signed.
      • All communications protocols are authenticated, encrypted and signed.
      • There are multiple, redundant backups of all data, including a hard copy paper trail that can be authenticated by a unique signature printed on each ballot
      • Voting machine is all open source -- no binary-only anything, no exceptions. This includes the OS -- so Linux or *BSD. It also includes the firmware, so something like OpenFirmware or whatever.
      • Source and binaries on each machine are independently verifiable
      • Ability for independent auditors to audit each machine at hardware level, application level and OS level.
      • No wireless networks
      • Machines have airgap security WRT the Internet
      • Machines use encrypted filesystems.
      • Machines have tamper-evident seals over everything
      • Good secure configurations -- no unnecessary services running, secure authentication methods, OS patches kept up to date, software consistently audited for security



        • All in all, I want a machine that is custom-configured for electronic voting and locked down so tight the NSA would have trouble getting in.

  2. ATM Machines by Anonymous Coward · · Score: 4, Interesting

    For the last time - issue a voter card and use the cash machines / ATM machines / or whatever you call it in ur location.

    It will even print a receipt.

    If it good enough for your money it is good enough for your vote

    1. Re:ATM Machines by oliverthered · · Score: 4, Insightful

      but the problem is you can tell who voted for who and that's bad.

      --
      thank God the internet isn't a human right.
  3. "common office implement" by jolyonr · · Score: 3, Funny

    Do they really think this sounds more impressive than "paperclip" ?

    Jolyon

    --


    Please read my Canon EOS tech blog at http://www.everyothershot.com
  4. How much more does it take? by Opportunist · · Score: 5, Insightful

    Those machines have been proven time and again that they're insecure, not reliable and that it takes special knowledge to even start verifying their results. Now we add ease of manipulation to the fold.

    How much more does it take to see that it is a BAD idea?

    Yes, paper voting is costy. But we're not talking something where cost is the deciding factor. Democracy is about two things: People participating in the government of their country, and people trusting the government of their country. In a democracy, people have (ok, should have) a say in their country's behaviour. And this in turn should give them a feeling of belonging, they should feel their country takes them serious and as more than just peons who can be ordered around, because they chose their government themselves. This usually means more trust and faith in their rulers, because they themselves chose them (not some divine right to rule or military force, they installed their government).

    Especially the latter part is at risk. If you cannot easily debunk any claims of voting fraud, because the means to vote offer themselves for easy manipulation, you open your country for claims of illegal manipulations that cannot be disproved. You destroy the faith people have in their country and the support. Not that it was really necessary these days, people already started losing faith in the democratic process and democracy altogether. But this has the potential to be the last straw.

    Cost is not an argument when it comes to voting. If you want people to support the government as wanted by the majority, you have to make sure that it will be seen as the will of the majority. If fraud is easy, dissenting people will always claim foul play and you will not have any chance to call them bad losers. You can't prove them wrong, quite the opposite, we have seen now time and again that they have every reason to be suspicious.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  5. This begs the question by oliverthered · · Score: 4, Funny

    Does it make paperclips and Linux illegal in Germany now that they can be used for hacking?

    --
    thank God the internet isn't a human right.
  6. Whats the point of e-voting by gmthor · · Score: 5, Insightful

    I believe the most important thing about e-voting is that you can't pic up a random person from the street, explain him how it works, and after it ask him if the process of voting was done correctly. Paper voting on the other side is so easy that manipulation is easy to realize. I mean the only point of e-voting is that some poor government officials can go home earlier. I want Democracy for everybody.

    --
    How do I uncompress my MD5 archive?
    1. Re:Whats the point of e-voting by Opportunist · · Score: 4, Insightful

      That is exactly the problem with e-voting: You have to trust.

      With normal pen-and-paper voting, all skill you need is being able to count and discriminate between various candidates being chosing on the paper. You don't believe my count? You think I'm trying to fix elections? Here's the ballot, count for yourself.

      With e-voting, you face a problem. You need very special skills to actually conduct a recount (if it is possible at all). Don't believe me that I'm not trying to fix elections in my favor? Sucks to be you if you don't happen to have the skills.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Whats the point of e-voting by Firethorn · · Score: 4, Interesting

      electronic voting machines can be made secure enough

      That's currently the big if right now. It's just not transparent enough, and it's like all the companies building machines forgot completely about security; substituting a little theater instead. In addition, I don't like how a single machine or media failure can take out all of a machine's votes for the election. Two or three of those can throw elections today.

      In addition, most of the advocates of paper voting have been talking about optical scan ballots. This opens up recounts to multiple solutions - Company X's scanner, Company Y's scanner, verified by hand if deemed necessary.

      I am not one of those who believe that hand counting is automatically the most accurate - but optical scanning is old tech at this point, very accurate, and most importantly - auditable.

      Secure and accurate Voting is always going to be complicated and tough - especially when you figure that you normally have at least two parties with people willing to cheat, who may be in the system.

      --
      I don't read AC A human right
  7. Don't kid yourself... by fahrbot-bot · · Score: 3, Interesting
    I mean the only point of e-voting is that some poor government officials can go home earlier.

    ...there's more money to be made than with paper and pencil voting. Producing cheap, insecure machines without a paper trail increases companies' profit margins. Lawmakers have be lax and slow to respond, probably because their hands are so comfortable in those companies' pockets. Obviously, the only ones who care are "some" of the voters. Hopefully, that will become "most".

    I, for one, like seeing my vote on hardcopy.

    --
    It must have been something you assimilated. . . .
  8. Paper Seals = DoS? by kieran · · Score: 4, Insightful

    If the machines have paper seals in an accessible place, then you could very easily DOS the vote of a district that is known to be unfavourable to you simply by slicing the seal with your thumbnail, without ever having to hack the machine at all!

  9. Criminal organizations by paulproteus · · Score: 3, Informative

    If I defrauded a state and sold it uncertified voting equipment, I'd be in jail.

    Why isn't this organization, which has clearly committed a criminal act, in jail?

    --
    |/usr/games/fortune
  10. Moving into the electronic age... by doit3d · · Score: 3, Interesting

    ...can be a good thing, but this really concerns me. I'm all for changing with the times, don't get me wrong. I just feel that electronic and software items which play such a critical role in the much corrupt political system we have today do need more oversight from public entities, not private companies or political agencies. I feel we are far from where we need to be for electronic voting in the US to be reliable or trustworthy. I do have hope that it can be an option in the future though.



    I opt to kill a few trees to retain the paper method for now. I was forced to use an electronic voting machine (Diebold) in my district during the last local election in my state. I will not be using one regardless come the next election. Anyone can manipulate the machine behind the privacy fence surrounding the machine, without anyone knowing about it. Who is to say it cannot be tampered with even before the people are given access to the machine to cast their vote. I do not feel comfortable using an electronic voting device at this time.



    I am almost 100% convinced that major elections do not matter anymore in this country in this day and age. The rich, and the corrupt have a strangle hold on our government and the media. Just look at the biased mass media coverage that is happening today. It is as if the media has already made the decisions for us about the elections, and those who own the media have very powerful ties to the government. There are no real debates between candidates, but they are still called debates. There are no tough questions, and there are no truthful straight forward consistent answers but from a couple of candidates, which are silenced and kept from the publics knowledge by powerful people whom are in control. I do have some hope, but it is fading fast.



    I honestly feel that there will be another civil war in this country if things continue the way they are. It will not be the Whites against the Blacks, against the Hispanics, etc... It will be the poor against the rich. You know where the corporations and the corrupt politicians will stand when this happens. Change takes ballots or bullets. Sooner or later people will be tired of trying to make change peacefully with ballots.



    It may not happen in my lifetime, but I think it will happen sooner than anyone thinks if the current path is followed. All it will take is someone high up in the military to finally get fed up with the corruption to take the action of cleaning house. We have already seen first hand the dissent in the military ranks all the way to the top. Several generals have peacefully resigned/retired and spoken in protest to the insane, illogical decisions made by the current administration and the path it has taken us down. Sooner or later someone with a bigger set of balls will do something about it if this continues.



    It would not be a good thing to have this happen, but if things continue the way they are I would sadly be in support of it. It would be a rough road, but change is needed in a bad way. We are currently on a path of assured economic destruction, which will have effects far and wide around the world. We should learn from the past history of other, once large and powerful Republics. It seems to me that we are doomed to repeat history unless there is change.



    I hold the hope though, that this vast information highway called the internet will tip the field in the favor of the people in due time. The option to see and read more news from many sources, rather than the few sources force fed to the masses controlled by the powerful and corrupt few. The internet has broadened my view of things. This too may not happen in my lifetime, but I hold hope that it will foster a peaceful change in time.



    I hope for a peaceful change, but I am very afraid of what could and might happen.

    --
    "This is America... where the will of the few outweigh the outrage of the many..." - Unknown
  11. REALLY open the voting... by zippthorne · · Score: 3, Interesting

    Every vote is assigned to an ID. Not your ID, but a relatively random numerical one. When the voting is done, the entire votes database is made available on DVD (or whatever medium is appropriate to storing 300 million records. I wouldn't expect much space at all, I'd bet the IDs take up more space than the actual data.

    Then independent organizations can tally the votes themselves and verify that the election was on the up and up. They can also allow people to check their votes in the database to verify individually that the database itself is correct. Assuming the database has been distributed in whole to all of the various organizations, mis-votes should be easy enough to discover.

    Then it only remains that you need to protect people's anonymity. A ticket that can be used to verify an individual vote on behalf of a person can also be used to verify that vote to the satisfaction of a vote-buying machine (or worse.)

    A solution is to obscure the information by giving each voter not one, but a list of ID numbers and told which one is theirs privately. That way, nefarious organizations wouldn't be able reliably say they've been given the correct number, which should kill their scheme. It's not a perfect solution, though, and I can already see flaws in it, but that just means it needs a bit more work before it's ready for prime time.

    --
    Can you be Even More Awesome?!