Security Firm Shows How To Hack a US Voting Machine (bleepingcomputer.com)
An anonymous reader writes: "Three days before the US Presidential Election takes place, California-based security firm Cylance showed the world how easy it is to hack one of the many [electronic] voting machine models that will be deployed at voting stations across the US on Election Day." Bleeping Computer reports that "The machine that Cylance researchers chose for their test was the Sequoia AVC Edge Mk1, one of the most popular models... The technique researchers created modifies the Public Counter, but also the Protective Counter, which is a backup mechanism that acts as a redundant verification system to ensure the first vote results are valid." Physical access is needed to hack the machine, but the hack takes a short time to perform.
FBI Director James Comey said in September that America's voting machines would be hard to compromise because they're not connect to the internet, but these researchers simply used a PCMCIA card to reflash the machine's firmware. Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed. It's Mary and Fred putting a machine under the basketball hoop at the gym."
FBI Director James Comey said in September that America's voting machines would be hard to compromise because they're not connect to the internet, but these researchers simply used a PCMCIA card to reflash the machine's firmware. Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed. It's Mary and Fred putting a machine under the basketball hoop at the gym."
How do bad actors accomplish that on a large scale?
[redacted]
So Sanders has a chance after all.
The most dangerous drug
"Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed..."
Did the FBI just use "clunky and dispersed" as an excuse to dismiss the lack of security surrounding the very core of our democratic process?
What kind of ignorant fuckery is this shit?
How about we properly mitigate security risks with a common sense approach that's a bit better than relying on Mary and Fred under the basketball hoop.
Did he recently meet someone out on a tarmac or something? Just curious...
Apparently a company in Maryland actually builds these...
1. Paper scantron ballot with a serial number.
2. You press down hard and get a carbon copy of your ballot to take home.
3. When the machine scans the ballot, it scans the serial number and the choice.
If we mandated a system like that, validation would be simple. We'd dump the results into a database on Nov 9th and let people compare their serial # to the data that shows up. Instant voter fraud protection because if your vote mysteriously goes from Clinton to Trump or vice versa, you go to law enforcement and show the carbon copy. At that point, it's all but "guilty until proven innocent" on the data entry side.
"Vote for $CANDIDATE or your daughter has an accident. Bring me your ballot receipt on Tuesday night and we can forget this conversation ever happened."
We have secret ballots for a reason.
What part of "shall not be infringed" is so hard to understand?
"Comey also made the reassuring point that it's hard to "hack into" America's voting system because "it's so clunky and dispersed. It's Mary and Fred putting a machine under the basketball hoop at the gym.""
How about some context for this? It reads like a non sequitur. Who are Mary and Fred, what type of machine are they putting in the gym, why does it matter it's under a basketball hoop, what does this have to do with the difficulty of hacking said machine. He's spewing gibberish.
the elections in this country are fair, at this point. It's a system run by corporate and banking interests, posing as a two-party system, talking and walking like it's -- get this -- a democracy.
Public votes should never be counted by machines. Period.
Mechanical, electronic, digital, frickin' VR based over the internet text message simulation. IDGAF.
All machine options are inferior to paper and pencil ballots, counted by volunteers in a public forum.
Human Volunteers
- Cost less
- Are probably more accurate
- Have no technical/mechanical failures
- Are almost impossible to "hack", cheat, etc
- And most importantly are far more trustworthy than these god dam machines.
I love technology, but it has no place in the mathematics classroom or the polling booth.
Voting machines have been nothing but a massive waste of time and money made to satisfy a tech worshiping fetish of people who really don't know how tech works. Just go back to paper and pencil. The Brits get their elections and referenda done in 24 hours mostly. I think Brexit was counted by the next morning.
... some months from now, regarding the alleged vote-rigging through hacked voting machines during the 2016 presidential elections:
"Although we did not find clear evidence that Hillary Clinton or her colleagues intended to violate laws governing federal elections, there is evidence that they were extremely careless in the handling of voting machines...".
Following the above statement, and after riots and protests in the streets, the FBI reopens the investigation, analyzing 650K contested votes in Florida which proved to be decisive for the outcome of the elections. After one week only, the FBI Director releases a new statement confirming that:
"Based on our review, we have not changed our conclusions that we expressed previously, the reasons not to prosecute stand".
And they lived happily and rigged ever after.
And this isn't the only make of voting machine used in the US. Large scale voting fraud just isn't possible in the US. Thousands of jurisdictions, potentially unique ballots for each jurisdiction, several different types of voting machines, plus absentee and early voting.
Best Slashdot Co
Is wireless access to the machines. A machine does not have to be connected to the internet to be hacked remotely. How many of these machines have wireless cards? Then, all a hacker (or insider) needs to do is pull up to the voting location with a laptop that has a wireless connection and all the right passwords and . . . . code adjusted! There are reports of this happening in Virginia when Mitt Romney went up against Ron Paul in 2012. It was a very close election at one precinct that was going up and down between the two candidates up to a certain point. Then all of the sudden near noontime, it quit going up and down but flat-lined to a 60/40 Romney/Paul split for the rest of the day. How likely is that?
Whoever your candidate is, do you really want that kind of voting situation - where you can never be sure who really won? This is what the Bush push for "accurate electronic voting machines," was all about. They no longer wanted it to be possible for a non-insider to be able to win a major or critical election. I suspect if Gore had won, he would have pushed for the same thing. Most Republican and Democrat candidates at the top are usually on the same team, anyway.
Machines do not make integer mistakes. Humans make them frequently, even when they are not biased. And every human is biased.
Humans can screw up simple integer addition programming -that is true. But, again, it's a human problem not a machine problem.
Humans, when looking at the scale of 100 million operations, are wildly more costly than computers
Humans have a much shorter MTBF than any well engineered machine - and shorter than many poorly engineered machines
Humans are specifically the reason that machines are untrustworthy.
What I do find interesting is that we used the same mechanical machines for 60 years and abandoned them because parts were hard to obtain or expensive, despite there being tens of thousands of them. We replaced them with machines costing 1/4 to 1/2 the amount of new mechanical machines, and just 10 years out are finding that those new machines are so old that their parts (aka OS and other software) are abandoned and/or impossible to maintain. We've spent money on modernization because it seemed so fool proof, and didn't even think about how quickly such technology goes stale.
Is it just my observation, or are there way too many stupid people in the world?
The paper and pencil voting system with manual counting is even more unhackable, and easily verifiable whilst still being anonymous and immune to vote selling ad coercion ...and is used all over the world with no real issues ....
Puteulanus fenestra mortis
If surveillance is peace, then Trump could build new relations with Russia by giving them access to all the domestic surveillance data to show we have nothing to hide.
I just choked on my sandwich. Is this a comedy routine you're putting together? Because that's hilarious. You should suggest that to Trump immediately, it is stupid enough for his next speech.
How about an article on hacking an election? Oh wait that's what politicians normally do. No news there.
We'll make great pets
This woman won 6 of 6 coin tosses to beat Bernie in Iowa.
That is incorrect information that was pushed by the media in initial frenzy of reporting, but completely debunked. Here's the Iowa Register story, which I would the most accurate source for information in Iowa: http://www.desmoinesregister.c...
According to the Register, the report of Hillary winning six coin flips came from social media. Of the seven coin flips to break ties that were actually officially reported through the voting app, Sanders won six, and Clinton one. http://www.cnn.com/2016/02/02/...
Here's a more interesting question: since Clinton did not in fact win a majority of coin tosses, what are the statistical chances that coin flips that happened to get reported in on social media would suggest that she did?
Another link: http://www.theatlantic.com/pol...
http://www.geoffreylandis.com
Geez, it's like no one ever thought of protecting the counters by making a hand-written backup of those numbers after the machines have been certified, but before voting begins.
I am a volunteer poll worker in Virginia. Not only do we record in pen those numbers when we open the equipment, we do a running comparison of the public counter totals to the total number of people who were checked-in on the poll books, every hour. If those numbers are off by even 1, it is a major event, we have to make an immediate report by phone to the registrar, write up what happened on an audit log, and explain it again to the local Board of Elections that evening.
You go messing with those numbers, and you would be caught within the hour in Virginia. Nice try.
"We receive as friendly that which agrees with, we resist with dislike that which opposes us" - Faraday
An abusive spouse is just one of thousands of scenarios of voting coercion.
The U.S. adopted secret ballots for a reason: to make it harder to implement vote buying and coercion. Maybe you're thinking that in modern times when everybody is trustworthy and nobody had bad motives, we don't need this safeguard.
But nevertheless, there is a reason for the secret ballot, and we shouldn't undermine it.
http://www.geoffreylandis.com
People are still under the belief, that the people are electing the president. Good grief...wake up people...until the American public march on DC and take back government, nothing will change. We have the "Bush" bunch, the "Clinton" bunch, senators that have been in office since the 60's, judges that have to wear diapers. Whenever I hear a politician say "I have devoted my career to public service" I just want to PUKE. Political office was NEVER to be a lifetime job. But, we the people are responsible for sending these clowns back year after year. I stopped voting for ANYONE that has been in a government position more than 2 terms years ago. I don't care if they are the best person in the world, two terms is enough!
I'm confused. I read the linked e-mail. It's a bunch of quotes from Republicans raising concerns about Trump's attitude, interactions, and policy proposals. How is this an effort to "stir up world peace" by the Dems? Every quote in that e-mail is from a Republican.
So to pull this off you need (a) a voting machine to play with to learn the techniques and (b) physical access to every voting machine you need to influence.
My approach is to make a completely fake voting machine, with the same interfaces as the real thing - and just swap the whole machine out when I have physical access to it.
This thought-experiment shows that with those two things (a machine to play with and physical access) there is no conceivable security measure that'll be 100% effective. So control access to the physical machines and your problem is solved.
www.sjbaker.org
Thank you for correcting the record.
You're welcome.
Did you read the leaks where the rest of the Clinton staff scorns CTR?
I don't particularly care about the campaign's click-through rate (CTR).
http://www.geoffreylandis.com
True, but Bush/Gore vote count in FL aside, how many elections are really that close? MOST elections don't even require counting the absentee ballots to know who won. As much as some would like to cast our election vote counting processes in to doubt, there really isn't an issue.
Vote fraud still needs to be looked for and dealt with strictly when found, regardless of if it affected the outcome, but those who trot out voter fraud as a reason somebody won or lost really don't have a case in the vast majority of the cases.
"File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
So if someone shows up, checks in, then doesn't actually vote...it throws you into chaos? I think that's something you might not want to advertise too widely!
www.sjbaker.org
The scales become the target.
Thanks for the info. Let's go a bit deeper.
Say the totals don't match by a couple. What happens to the votes from that particular machine (or the polling place in general)?
Could these type of activities be used not to alter the results of an election, but for disruption?
BlameBillCosby.com
As we've seen over the past year, everyone involved in the election is of unimpeachable character so nothing untoward will occur :P
Requiem for the American Dream
There, problem solved.
And stop making voting machines accessible to the Internet.
-- Tigger warning: This post may contain tiggers! --
it is virtually impossible to get a "hanging chad" while voting properly, with a single ballot. Both sides knew it, but didn't want their little secrets exposed, since both sides were culpable. Which is why we got the theater of inspectors looking at the ballots trying to determine "intention" of the voter, based on a Hanging Chad.
Florida was exposure of the fraud, it is just that too few people actually recognized it for what it was.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
A statement from social media is wrong, here, the proof is in another candidate's social media app!
Uh, no.
The "app" mentioned in the article is the Microsoft app used to report precinct results to the state office; it had nothing to do with social media. This was deployed by the Iowa Caucus (and used by both Republican and Democratic caucus, for what it's worth), but only used by about half the precincts (the other half just phoned the results in)
The app, from what people say, was slow and crashed a lot, but don't blame the results on the app-- the app was just the means used to report results.
http://www.geoffreylandis.com
You just proposed the "security by obscurity" approach to voting machine security.
You said it's hard for you to know what the security-- if any-- is for the physical location of voting machines, and since you don't know how to find out, that means they're secure!
Note that you haven't pointed to any reason to think at all that this information is being kept secret-- you just stated that you don't know, and therefore since you don't know, you "guess" that only a handful of people know.
http://www.geoffreylandis.com
Which is why Bush went to court to stop the recounts... And Why the courts eventually agreed and rightly put a stop to all the foolishness... AND why they have electronic voting machines now.
Legally, Bush got FL's electors the moment FL's Secretary of State state certified the results, which was days before the courts got involved and the media frenzy hit full stride with their under vote, over vote, and dimpled chad stupidity. What amazed me was how many courts let the garbage continue, despite the clear meaning and intention of the law which all parties agreed to before the first vote was cast which showed Bush as the winner.
"File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
Man, seems like everyone is wanting to spread FUD on elections items.
Let's see, OH, yes, Wired ran a guide yesterday to how to rig an election in 10,000 easy steps:
https://www.wired.com/2016/10/wireds-totally-legit-guide-rigging-presidential-election/?mbid=social_twitter
Way easier just to pay off your special interest groups.
The Kai's Semi-Updated Website Thingy
...how easy it is to hack a person taking votes. A few hundred dollar bills and 2 minutes is all it takes.
If readers are worried that the Cylance research spells some kind of doom, don't. US officials have already explained that attacks on the actual voting machines are almost impossible, and not something they fear. If they happen, they'll occur in one or two isolated precints, but not in a coordinated nation-wide attack.
Freedom to fear. Freedom from thought. Freedom to kill.
I guess the War on Terror really is about freedom!
Your comments, over and over, can be summarize to this: "I don't know fact X, therefore fact X is hard to find out."
You have never actually tried to find out where voting machines are stored. You don't know whether it's hard or not. Saying that the information is hard to get is a logical fallacy known as "argument from ignorance."
...
Note that you haven't pointed to any reason to think at all that this information is being kept secret....
And you haven't given any reason to think it's readily available.
So, if you don't know whether the system is secure-- and you repeat several times that you don't know-- is the conclusion "therefore it is secure" justified?
(In any case, the best you can say about your argument that security by obscurity works is that breaking the security might need an inside man.)
http://www.geoffreylandis.com
Curso NR 10 online curso NR 10 curso NR 10 online