Senators Demand Voting Machine Vendor Explain Why It Dismisses Researchers Prodding Its Devices (bleepingcomputer.com)
Four US senators, members of the US Senate Select Committee on Intelligence, sent a letter on Wednesday to Election Systems and Software (ES&S), the largest voting machine vendor in the US, asking for clarifications on why the vendor is trying to discourage independent security reviews of its products. From a report: The four senators who signed the letter are Kamala D. Harris (D-CA), Mark Warner (D-VA), Susan Collins (R-ME), and James Lankford (R-OK). The senators sent the letter to ES&S following the conclusion of the Voting Village at the DEF CON 26 security conference held in Las Vegas at the start of the month, where security researchers found several security vulnerabilities in the company's products. "We are disheartened that ES&S chose to dismiss these demonstrations as unrealistic and that your company is not supportive of independent testing," the letter reads. "Many of the world's leading electronics and software companies have opened their arms to the research community, maintaining active presences at the largest security research conferences and inviting 'white hat' hackers to probe their products to identify how they can improve product security," the letter continued. At DEF CON, security researchers found vulnerabilities in the voting machines of other vendors. Only ES&S is mentioned in the senators' letter because of the company's dismissive approach to external security research.
Fruit machines in casinos have to be state certified as honest with their code vetted regularly. Voting machines are largely unregulated.
"Made up/misattributed quote that makes me look smart. I am on
How back in the early 2000s here on Slashdot we all were complaining how these electronic voting machines were the work of the devil in how easy they were to hack?
Fast forward to 2018, they're now viewed as Russian hacking devices.
Seems like we're on a collision course to return to the old style paper ballots.
Shame no one listens to us. It seems most tech crises would be avoided! Thankfully we get to bill $300/hr when Mr. Executive's screw up comes to roost!
Unless you've spent time running an election, it's hard to appreciate just how distributed the process is. Virginia, where I am an officer, has 2,400+ separate voting precincts.
None of our voting equipment is networked, not even locally within the precinct. None of the equipment even have the hardware necessary to be networked.
Nearly 4 million people voted in the last Presidential race. The recount margin is 1%, so the winner and the loser must be within 1% of each other for a recount to be called.
Thus for a hack to be effective and not be scrutinized by a recount, you'd have to win 1% of 4 million, or 40,000 votes.
How likely is it that you will be able to hack your way into enough precincts, defeat the chain of custody, get your hands on the machines to do your dirty work -- UNDETECTED -- for EACH and every election (each election has a different ballot, and the order is chosen randomly), and change 40,000 votes? Otherwise, what would be the point of the attack?
Local elections are secure, disconnected facilities. Anytime I see some hacker "fair" where they've got the covers off and people are probing the equipment, I just laugh. As if. We run a tight ship, and in 238 years of doing this job, we've learned a thing or two about how people try to cheat.
It's not VOTING you have to worry about, it's REGISTRATION. Registration has many times more attack vectors.
"We receive as friendly that which agrees with, we resist with dislike that which opposes us" - Faraday
"We hold ourselves to a higher standard, knowing that our products and services help maintain democracy in the jurisdictions we service."
Yeah, right. This is Diebold of former infamy, first changing their name to Premier Election Solutions, and then again merging with Election Systems & Software (ESS).
Same shit, different wrapper. Why would any state give them a third chance after the first screw-ups? The canapés must be very tall and the drinks very big.
There's a limited number of people that are going to be at any single voting station, so manual counts of paper ballots wouldn't take that long, happening in parallel all over the country. The ballots can even be kept for a little while, in case recounts are necessary.
File under 'M' for 'Manic ranting'