Voting System Test Hack Elects Futurama's Bender To School Board
mr crypto writes with this quote from El Reg:
"In 2010 the Washington DC election board announced it had set up an e-voting system for absentee ballots and was planning to use it in an election. However, to test the system, it invited the security community and members of the public to try and hack it three weeks before the election. 'It was too good an opportunity to pass up,' explained Professor Alex Halderman from the University of Michigan. 'How often do you get the chance to hack a government network without the possibility of going to jail?' With the help of two graduate students, Halderman started to examine the software. Despite it being a relatively clean Ruby on Rails build, they spotted a shell injection vulnerability within a few hours. They figured out a way of writing output to the images directory (PDF) on the compromised server, and of encrypting traffic so that the front-end intrusion detection system couldn't spot them. The team also managed to guess the login details for the terminal server used by the voting system. ... The team altered all the ballots on the system to vote for none of the nominated candidates. They then wrote in names of fictional IT systems as candidates, including Skynet and (Halderman's personal favorite) Bender for head of the DC school board."
Why not Zoidberg?
If elected I promise to KILL ALL HUMANS! Hey, you said there'd be hookers at this convention.
What a fool believes, he sees, no wise man has the power to reason away.
"Have you ever tried simply turning off the TV, sitting down with your children, and hitting them?"
Everything I say is a lie. Except that... and that... and that, and that, and that, and that... and that.
Ruby on Rails
And there's your problem. Only an idiot would try to run something that needs high security on Ruby on Fails. Rubyists couldn't write secure code if their life depended on it. Next time hire real programmers not hipsters who spend all day sipping lattes and admiring each other's new pair of skinny jeans.
This was a system created by Rubyists. They don't understand security because that's a "low-level detail" they can't be arsed to learn.
Ya, well, I'm gonna go build my own election system. With blackjack! And hookers!
In fact, forget the election system.
Every single technology profession I have EVER communicated with, does not think electronic voting machines are a good idea. If EVERYONE is in agreement this is a BAD idea, why the FUCK are we still making these things?
That's just it, we took a vote on that and as it turns out about 190% of respondents said that they were in favor of electronic voting...
Because "Insightful" is Secret Slashdot Code for "Funny, but enough so it deserves karma". And "Funny" is Secret Slashdot Code for "So painfully unfunny it induces groaning."
Or possibly Groening. Not precisely clear on that.
New Jersey, India, and China.
Ah yes, the new "Axis of Evil"!
This space for rent. All reasonable inquiries will be entertained at proprietors discretion.