Hackers Fail To Crack Brazilian Voting Machines
blueser writes "From Nov 10th to Nov 13th the Brazilian Government hosted a public hacking contest to test the robustness of its voting machines. 38 participants from private and public IT companies (including the Brazilian Federal Police) were divided into 9 teams, which tried several different approaches to try to tamper with the software installed on the machines, and even to physically interfere in other stages of the process. All attempts (aside from a minor one which would not compromise the overall results) failed, and observations from the participants and neutral observers will be taken into account to improve the process even further. Here is the official announcement for the contest (Google translation; Portuguese original). A summary of the results is available in the Brazilian press (original). Brazilian voting machines use Linux." US voting officials ought to be envious of their Brazilian counterparts, or ashamed, or both. Perhaps this MIT-developed cryptographic voting system offers a way forward.
Simplicity --> greater security (I'm not saying the contest measured something).
http://en.wikipedia.org/wiki/Elections_in_Brazil#The_Brazilian_voting_machines
The source is available to the parties.
NB: The message above might reflect my opinion right now, but not necessarily tomorrow or next year.
"I claim that there is no flaw. It is now your job to find the flaw and prove me wrong."
Not really. It is your job to prove to me that there is no flaw. It's the same thing with a paper ballot. You still have to prove to me that there is not a flaw in the paper ballot. Of course, I can look over the ballot in all of about 15 seconds and see that it's the correct ballot. It's far harder to find a race condition in a voting machine running proprietary software that causes miscounted votes.
-1 disagree is not a modifier for a reason. -1 troll, flaimbait, redundant, overrated are NOT acceptable substitutes.
Actually, they ARE Diebold machines! When I turned 18 and voted for the first time I was really surprised to see that the voting machines here in Brazil have Diebold logos... and this was around the time when electronic voting was starting to make noise in the US due to insecure Diebold machines. However, I suspect that the Brazilian machines are actually designed by some national organization and only the manufacturing of all the thousands of machines is outsourced to Diebold.
Weve been voting with these machines for over 10 years, if Im not mistaken, and not a single major flaw has ever surfaced. Some small problems may have occurred without anyone noticing, but weve never had an election result deviate wildly from poll numbers, so it seems trustworthy to the extent that we can detect.
Goes to show that electronic voting machines or even Diebold are not the whole problem, you just need some transparency and supervision of the whole process... DEFINITELY not closed source!
http://br-linux.org/2009/video-e-fotos-do-boot-do-linux-em-uma-urna-eletronica-brasileira/ (scroll down the page a bit)
According to the newspapers, the successful attempt was on the carrying bag for the media (which I assume carries the data required). It seems lack of physical security still can happen, but the media is supposedly cryptographically signed, so replacing it would be hard in any case.
The source *is* open. Anyone from any political party or organized entity can request and have access to all source and follow all the procedures. The final binaries are signed by all interested parties as well and the system can be audited at any time. I know no system is fail proof but I believe they covered as much as they can and honestly, the paper system is also week to social pressures and bribing as well. That's the week link: people, not technology.
Scientia est Potentia
Given the low prize, it's highly possible.
But Brazil does have a stable political climate. Lot's of claims of corruption, but everything have been on its tracks for so long that is boring.
Latin America is a rather less-than-stable political climate, after all.
You shouldn't generalize. Florida may be part of Latin America by now, but it's certainly not in Brazil.
Proving the absence of something is impossible, or close to it. No matter how hard he looks and says "it still seems to be flawless", you can ALWAYS claim that there is still the possibility of a hidden flaw.
It's always the job of the person claiming the existence of something to prove it, not the other way around. If you think there is a flaw, show us your proof, or at least your reasoning. If you can't, we wont have reason to believe you.
First, is not the Brazilian goverment but the Tribunal Superior Eleitoral (supreme election jury or something like this in English).
And all the test is a ugly lie.
The... "hackers" are public workers, not really hackers. And they are forbidden to use really "hacker" methods like disassemblers, sniffers and etcetera, only the "approved" methods. Is like you ask to a thief to try to bypass your security system, but allows then to use only a paper clip. Ridiculous, but the TSE do not care.
Religion: The greatest weapon of mass destruction of all time