Security Firm Shows How To Hack a US Voting Machine (bleepingcomputer.com)
An anonymous reader writes: "Three days before the US Presidential Election takes place, California-based security firm Cylance showed the world how easy it is to hack one of the many [electronic] voting machine models that will be deployed at voting stations across the US on Election Day." Bleeping Computer reports that "The machine that Cylance researchers chose for their test was the Sequoia AVC Edge Mk1, one of the most popular models... The technique researchers created modifies the Public Counter, but also the Protective Counter, which is a backup mechanism that acts as a redundant verification system to ensure the first vote results are valid." Physical access is needed to hack the machine, but the hack takes a short time to perform.
FBI Director James Comey said in September that America's voting machines would be hard to compromise because they're not connect to the internet, but these researchers simply used a PCMCIA card to reflash the machine's firmware. Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed. It's Mary and Fred putting a machine under the basketball hoop at the gym."
FBI Director James Comey said in September that America's voting machines would be hard to compromise because they're not connect to the internet, but these researchers simply used a PCMCIA card to reflash the machine's firmware. Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed. It's Mary and Fred putting a machine under the basketball hoop at the gym."
How do bad actors accomplish that on a large scale?
[redacted]
So Sanders has a chance after all.
The most dangerous drug
"Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed..."
Did the FBI just use "clunky and dispersed" as an excuse to dismiss the lack of security surrounding the very core of our democratic process?
What kind of ignorant fuckery is this shit?
How about we properly mitigate security risks with a common sense approach that's a bit better than relying on Mary and Fred under the basketball hoop.
Did he recently meet someone out on a tarmac or something? Just curious...
Apparently a company in Maryland actually builds these...
1. Paper scantron ballot with a serial number.
2. You press down hard and get a carbon copy of your ballot to take home.
3. When the machine scans the ballot, it scans the serial number and the choice.
If we mandated a system like that, validation would be simple. We'd dump the results into a database on Nov 9th and let people compare their serial # to the data that shows up. Instant voter fraud protection because if your vote mysteriously goes from Clinton to Trump or vice versa, you go to law enforcement and show the carbon copy. At that point, it's all but "guilty until proven innocent" on the data entry side.
This episode is even more telling about FBI and James Comey than about the dire state of e-voting.
Sadly incompetent. How much's that guy earning?
"Vote for $CANDIDATE or your daughter has an accident. Bring me your ballot receipt on Tuesday night and we can forget this conversation ever happened."
We have secret ballots for a reason.
What part of "shall not be infringed" is so hard to understand?
"Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed. It's Mary and Fred putting a machine under the basketball hoop at the gym.""
How about some context for this? It reads like a non sequitur. Who are Mary and Fred, what type of machine are they putting in the gym, why does it matter it's under a basketball hoop, what does this have to do with the difficulty of hacking said machine. He's spewing gibberish.
the elections in this country are fair, at this point. It's a system run by corporate and banking interests, posing as a two-party system, talking and walking like it's -- get this -- a democracy.
We should pardon Snowden, let him back and have him run a government-owned voting machine company.
It's the only way for perfect, real time auditing.
Public votes should never be counted by machines. Period.
Mechanical, electronic, digital, frickin' VR based over the internet text message simulation. IDGAF.
All machine options are inferior to paper and pencil ballots, counted by volunteers in a public forum.
Human Volunteers
- Cost less
- Are probably more accurate
- Have no technical/mechanical failures
- Are almost impossible to "hack", cheat, etc
- And most importantly are far more trustworthy than these god dam machines.
I love technology, but it has no place in the mathematics classroom or the polling booth.
Voting machines have been nothing but a massive waste of time and money made to satisfy a tech worshiping fetish of people who really don't know how tech works. Just go back to paper and pencil. The Brits get their elections and referenda done in 24 hours mostly. I think Brexit was counted by the next morning.
... some months from now, regarding the alleged vote-rigging through hacked voting machines during the 2016 presidential elections:
"Although we did not find clear evidence that Hillary Clinton or her colleagues intended to violate laws governing federal elections, there is evidence that they were extremely careless in the handling of voting machines...".
Following the above statement, and after riots and protests in the streets, the FBI reopens the investigation, analyzing 650K contested votes in Florida which proved to be decisive for the outcome of the elections. After one week only, the FBI Director releases a new statement confirming that:
"Based on our review, we have not changed our conclusions that we expressed previously, the reasons not to prosecute stand".
And they lived happily and rigged ever after.
Comey also tried to get encryption backdoored. He was behind the attempt to get Apple to backdoor their phones.
https://www.theguardian.com/technology/2016/feb/25/fbi-director-james-comey-apple-encryption-case-legal-precedent
You don't need to hack lots of voting machines to rig an election, you only need to hack the RIGHT voting machines. The ones in key districts of key states. And don't kid yourself that paper makes it safer, it doesn't.
Because the people counting the vote are also a risk, that is why vote counting is done in public in front of the candidates representatives. In Putin's last but one election, he nearly lost, there was a massive swing at the end. Districts that had already reported locally reported different numbers at the aggregation, suddenly they were 96% turnout and 88% for Putin.
Exactly the same pattern was seen from the pro-Russian districts in the Ukraine elections, ridiculous turnout numbers, not supported by video of voters on the ground, and ridiculous pro-Yanukovych (a Putin puppet leader) margins in those regions. Impossible numbers not matching reality, polls, or actual observed turnout. Democracy requires double checking of everything at all times.
Now think for a second how many times people email passwords around, I bet there are passwords for US election officials emailed at some time, or sent via backdoored or inadequate encryption.
Comey needs to take elections more seriously.
And this isn't the only make of voting machine used in the US. Large scale voting fraud just isn't possible in the US. Thousands of jurisdictions, potentially unique ballots for each jurisdiction, several different types of voting machines, plus absentee and early voting.
Best Slashdot Co
Is wireless access to the machines. A machine does not have to be connected to the internet to be hacked remotely. How many of these machines have wireless cards? Then, all a hacker (or insider) needs to do is pull up to the voting location with a laptop that has a wireless connection and all the right passwords and . . . . code adjusted! There are reports of this happening in Virginia when Mitt Romney went up against Ron Paul in 2012. It was a very close election at one precinct that was going up and down between the two candidates up to a certain point. Then all of the sudden near noontime, it quit going up and down but flat-lined to a 60/40 Romney/Paul split for the rest of the day. How likely is that?
Whoever your candidate is, do you really want that kind of voting situation - where you can never be sure who really won? This is what the Bush push for "accurate electronic voting machines," was all about. They no longer wanted it to be possible for a non-insider to be able to win a major or critical election. I suspect if Gore had won, he would have pushed for the same thing. Most Republican and Democrat candidates at the top are usually on the same team, anyway.
Machines do not make integer mistakes. Humans make them frequently, even when they are not biased. And every human is biased.
Humans can screw up simple integer addition programming -that is true. But, again, it's a human problem not a machine problem.
Humans, when looking at the scale of 100 million operations, are wildly more costly than computers
Humans have a much shorter MTBF than any well engineered machine - and shorter than many poorly engineered machines
Humans are specifically the reason that machines are untrustworthy.
What I do find interesting is that we used the same mechanical machines for 60 years and abandoned them because parts were hard to obtain or expensive, despite there being tens of thousands of them. We replaced them with machines costing 1/4 to 1/2 the amount of new mechanical machines, and just 10 years out are finding that those new machines are so old that their parts (aka OS and other software) are abandoned and/or impossible to maintain. We've spent money on modernization because it seemed so fool proof, and didn't even think about how quickly such technology goes stale.
Is it just my observation, or are there way too many stupid people in the world?
The paper and pencil voting system with manual counting is even more unhackable, and easily verifiable whilst still being anonymous and immune to vote selling ad coercion ...and is used all over the world with no real issues ....
Puteulanus fenestra mortis
Trump should ask his Russian hacker friends to help secure the vote from Crooked Hillary and her Crooked FBI.
Then when he wins legitimately despite the crooked Hillbully polls, he should create '6-Eyes', an information and surveillance network that *includes* Russia. So Putin can keep an eye on US elections to make sure crooked Democrats don't rig it, or crooked American Dem votes don't rig it the way they always do.
If surveillance is peace, then Trump could build new relations with Russia by giving them access to all the domestic surveillance data to show we have nothing to hide.
Reagan and Gorbachev brought down the wall, Trump and Putin could bring down the firewall!
I think it would be better if you gave examples of the crook clintons and their crook ways:
https://wikileaks.org/dnc-emails/emailid/23420
Here they try to stir up world peace and start third world war with totally peaceful nation not harm anyone. Trump needs votes to secure world peace with Putin, is good thing.
How about an article on hacking an election? Oh wait that's what politicians normally do. No news there.
We'll make great pets
This woman won 6 of 6 coin tosses to beat Bernie in Iowa.
That is incorrect information that was pushed by the media in initial frenzy of reporting, but completely debunked. Here's the Iowa Register story, which I would the most accurate source for information in Iowa: http://www.desmoinesregister.c...
According to the Register, the report of Hillary winning six coin flips came from social media. Of the seven coin flips to break ties that were actually officially reported through the voting app, Sanders won six, and Clinton one. http://www.cnn.com/2016/02/02/...
Here's a more interesting question: since Clinton did not in fact win a majority of coin tosses, what are the statistical chances that coin flips that happened to get reported in on social media would suggest that she did?
Another link: http://www.theatlantic.com/pol...
http://www.geoffreylandis.com
Nice to know that the FBI Director really is that stupid and apparently nobody in the organization either could or would educate him.
There is no reason on Earth for electronic voting machines. NONE. Fill in the circle ballots read by a scanner can provide totals just as fast and can be easily cross checked with a couple of random audit counts of the paper copy compared to scanner count. If irregularities are spotted (the examples above often mention targeting key precincts but a statistical analysis done in the heads of political activists would immediately see the issue (why did those precincts show a big shift to one side or the other when none of the other ones did?) and demand a paper count. The only potential issue is if the State powers that be decide to provide insufficient ballots to certain precincts (as Florida has done repeatedly) to reduce the votes in those areas. That is an issue for the courts & for voters to remove people who pull that sort of crap
When your machine is counting, it isn't verifying. A human counter is verifying. He/she is noticing those absentee ballot papers all with the same handwriting.
Machine are trivial to rig on a vast scale in ways that are untraceable.
Machines DO make mistakes, mechanical readers do misread, programs are buggy, harddisks do get corrupted and hardware does break.
Human errors, are not an issue. It is randomly distributed and that randomness can be checked and verified.
Human MTBF is not an issue, there are an infinite number available.
Humans have a vested interest in ensuring elections are not rigged. The machine doesn't give a toss.
You cannot verify computerized voting. You cannot secure it from hackers. It cannot be used.
It's not enough for an election to be counted properly. The people need to be able to confirm for themselves its counted properly.
A chain is only as strong as the weakest link. Having many different jurisdictions and many different types of voting machines means having many different vectors of attack.
No single attach can affect the majority of precincts, or the majority of machines.... but in a tight election, you don't need to compromise them all, you just need some.
Geez, it's like no one ever thought of protecting the counters by making a hand-written backup of those numbers after the machines have been certified, but before voting begins.
I am a volunteer poll worker in Virginia. Not only do we record in pen those numbers when we open the equipment, we do a running comparison of the public counter totals to the total number of people who were checked-in on the poll books, every hour. If those numbers are off by even 1, it is a major event, we have to make an immediate report by phone to the registrar, write up what happened on an audit log, and explain it again to the local Board of Elections that evening.
You go messing with those numbers, and you would be caught within the hour in Virginia. Nice try.
"We receive as friendly that which agrees with, we resist with dislike that which opposes us" - Faraday
An abusive spouse is just one of thousands of scenarios of voting coercion.
The U.S. adopted secret ballots for a reason: to make it harder to implement vote buying and coercion. Maybe you're thinking that in modern times when everybody is trustworthy and nobody had bad motives, we don't need this safeguard.
But nevertheless, there is a reason for the secret ballot, and we shouldn't undermine it.
http://www.geoffreylandis.com
Voting matters?
Really, it doesn't matter who the POTUS is, who the FLOTUS is, who the Governor is, or even who the SCROTUSES are.
Lobbying matters.
Lobbyists write the bills, all the POTUS does is sign them, same with the HOTUS, SCROTUSES, etc.
Lobbying is also tax deductible, and has a much higher chance of getting the law you want and paid for off the floor, and into the hands of the POTUS.
People are still under the belief, that the people are electing the president. Good grief...wake up people...until the American public march on DC and take back government, nothing will change. We have the "Bush" bunch, the "Clinton" bunch, senators that have been in office since the 60's, judges that have to wear diapers. Whenever I hear a politician say "I have devoted my career to public service" I just want to PUKE. Political office was NEVER to be a lifetime job. But, we the people are responsible for sending these clowns back year after year. I stopped voting for ANYONE that has been in a government position more than 2 terms years ago. I don't care if they are the best person in the world, two terms is enough!
As a resident of the Commonwealth, thank you for volunteering.
http://www.paul-robinson.us/index.php/2008/10/25/the_robinson_method_a_really_simple_way_?blog=5
Every time I post this up, nobody replies, it is ignored. It solves virtually all voting fraud problems, and even more so in this day of mobile phone live video uplinks, where observers can live stream both the voting (proving the voting boxes are empty from the beginning, for example) and the 'counting'. (Which in the case of the 'Robinson Method' is actually 'weighing', and therefore hundreds of times quicker.)
People should protest that there is no paper trail.
So to pull this off you need (a) a voting machine to play with to learn the techniques and (b) physical access to every voting machine you need to influence.
My approach is to make a completely fake voting machine, with the same interfaces as the real thing - and just swap the whole machine out when I have physical access to it.
This thought-experiment shows that with those two things (a machine to play with and physical access) there is no conceivable security measure that'll be 100% effective. So control access to the physical machines and your problem is solved.
www.sjbaker.org
The problem exists 10x at the accumulation and counting locations. But dont worry the Non-Biased Media is there to do final tabulations and announce the winner for you.
Thank you for correcting the record.
You're welcome.
Did you read the leaks where the rest of the Clinton staff scorns CTR?
I don't particularly care about the campaign's click-through rate (CTR).
http://www.geoffreylandis.com
So if someone shows up, checks in, then doesn't actually vote...it throws you into chaos? I think that's something you might not want to advertise too widely!
www.sjbaker.org
Thanks for the info. Let's go a bit deeper.
Say the totals don't match by a couple. What happens to the votes from that particular machine (or the polling place in general)?
Could these type of activities be used not to alter the results of an election, but for disruption?
BlameBillCosby.com
As we've seen over the past year, everyone involved in the election is of unimpeachable character so nothing untoward will occur :P
Requiem for the American Dream
There, problem solved.
And stop making voting machines accessible to the Internet.
-- Tigger warning: This post may contain tiggers! --
It's much easier than that in fact.
There's a non profit that found out that the software in the voting machines is already prepared to easily rig the results:
http://blackboxvoting.org/
Is that you Donald?
A statement from social media is wrong, here, the proof is in another candidate's social media app!
Uh, no.
The "app" mentioned in the article is the Microsoft app used to report precinct results to the state office; it had nothing to do with social media. This was deployed by the Iowa Caucus (and used by both Republican and Democratic caucus, for what it's worth), but only used by about half the precincts (the other half just phoned the results in)
The app, from what people say, was slow and crashed a lot, but don't blame the results on the app-- the app was just the means used to report results.
http://www.geoffreylandis.com
FBI Director James Comey is making this his next security ask of the nation. The FBI needs to be able to hack the voting machines because how will they identify suspects without it? It is clearly impossible for the FBI to do their jobs without this capability.
And because terror!
You just proposed the "security by obscurity" approach to voting machine security.
You said it's hard for you to know what the security-- if any-- is for the physical location of voting machines, and since you don't know how to find out, that means they're secure!
Note that you haven't pointed to any reason to think at all that this information is being kept secret-- you just stated that you don't know, and therefore since you don't know, you "guess" that only a handful of people know.
http://www.geoffreylandis.com
Man, seems like everyone is wanting to spread FUD on elections items.
Let's see, OH, yes, Wired ran a guide yesterday to how to rig an election in 10,000 easy steps:
https://www.wired.com/2016/10/wireds-totally-legit-guide-rigging-presidential-election/?mbid=social_twitter
Way easier just to pay off your special interest groups.
The Kai's Semi-Updated Website Thingy
...how easy it is to hack a person taking votes. A few hundred dollar bills and 2 minutes is all it takes.
So in the video we see someone using a text editor to change the data collected. This means that they had to get the firmware OFF the machine first, then plug the PCMCIA card into a laptop and edit the data file, then they put the card back in and updated the firmware to reflect the new numbers. But they have to do this in front of poll watchers--don't the print the results right when the polls close before they unplug and turn off the machines?
Also it seems to me that simply requiring the printing of hourly totals while the polling is occurring can prevent this type of fraud.
It wasn't exactly that the story was pushed by the media, it was just that the election process in Iowa is more complicated than it should be and you have to be more of an expert than most of the consultants who the news uses in order to get it. The media coverage from media who didn't understand it got a lot of coverage because it drove user interest.
If readers are worried that the Cylance research spells some kind of doom, don't. US officials have already explained that attacks on the actual voting machines are almost impossible, and not something they fear. If they happen, they'll occur in one or two isolated precints, but not in a coordinated nation-wide attack.
Freedom to fear. Freedom from thought. Freedom to kill.
I guess the War on Terror really is about freedom!
Your comments, over and over, can be summarize to this: "I don't know fact X, therefore fact X is hard to find out."
You have never actually tried to find out where voting machines are stored. You don't know whether it's hard or not. Saying that the information is hard to get is a logical fallacy known as "argument from ignorance."
...
Note that you haven't pointed to any reason to think at all that this information is being kept secret....
And you haven't given any reason to think it's readily available.
So, if you don't know whether the system is secure-- and you repeat several times that you don't know-- is the conclusion "therefore it is secure" justified?
(In any case, the best you can say about your argument that security by obscurity works is that breaking the security might need an inside man.)
http://www.geoffreylandis.com
Curso NR 10 online curso NR 10 curso NR 10 online