Slashdot Mirror


11-Year-Old Changes Election Results On Florida's Website: Defcon 2018 (pbs.org)

UnknowingFool writes: At this year's DEFCON, a group of 50 children aged 8 to 16 participated in a hack of 13 imitation election websites. One 11-year-old boy changed the voting results in 10 minutes. A 11 year-old-girl was also able to change the voting results in 30 minutes. Overall, more than 30 of the 50 children were able to hack the websites in some form. The so-called "DEFCON Voting Machine Hacking Village" allowed kids the chance to manipulate vote tallies, party names, candidate names and vote count totals. The 11-year-old girl was able to triple the number of votes found on the website in under 15 minutes.

The National Association of Secretaries of State said in a statement that it is "ready to work with civic-minded members of the DEFCON community wanting to become part of a proactive team effort to secure our elections." But the organization expressed skepticism over the hackers' abilities to access the actual state websites. "It would be extremely difficult to replicate these systems since many states utilize unique networks and custom-built databases with new and updated security protocols," it read. "While it is undeniable websites are vulnerable to hackers, election night reporting websites are only used to publish preliminary, unofficial results for the public and the media. The sites are not connected to vote counting equipment and could never change actual election results."

2 of 202 comments (clear)

  1. Misleading Title by _Sharp'r_ · · Score: 5, Insightful

    11-Year-Old Changes Election Results On Florida's Website: Defcon 2018

    should actually be:

    11-Year-Old Changes Numbers Displayed On Faked Replica HTML Page Setup to be Changed by Kids: Defcon 2018

    --
    The party of stupid and the party of evil get together and do something both stupid and evil, then call it bipartisan.
    1. Re:Misleading Title by AmiMoJo · · Score: 5, Interesting

      Which is normally how security demos work, because hacking the real site would be illegal.

      The point here is that those sites are vulnerable to literal script kiddie attacks. While the government tries to hand wave it away as just an attack on a site showing preliminary results and correctly points out that such a site would not be used to make the official determination of who won, that's missing the point.

      These days such a hack would spawn a brand new QAnon-style conspiracy theory, pushed on social media by the same people did the hack. It would further erode trust in the electoral system, which leads to lower turnout next time. It makes the whole process look like some dictatorship doing a bad job of rigging the votes.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC