Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Security of Diebold Election Systems
RABA Technologies ^ | January 20, 2004 | RABA Technologies

Posted on 11/14/2004 10:04:47 PM PST by gbchriste

The State of Maryland election system (comprising technical, operational, and procedural components), as configured at the time of this report,contains considerable security risks that can cause moderate to severe disruption in an election.

The team also verified that the current version of the GEMS software still contains many of the vulnerabilities widely published on the Internet. It was disappointing to see that no obvious attention was paid to addressing these weaknesses.

The quantity and quality of the attacks described above is disturbing, especially given the short time the team had access to the system. Certain shortcuts were taken (e.g., assuming knowledge of the phone number that connects to the GEMS server) but we feel these are reasonable actions that a determined attacker would be able to overcome.

(Excerpt) Read more at raba.com ...


TOPICS: Crime/Corruption; Government; Politics/Elections
KEYWORDS: diebold; electronicvoting
I've been monitoring some of the conspiracy talk over at DU, if for no other reason than the entertainment factor. But since I am a software engineer and intimately familiar with the Microsoft Access database system that underlies the Diebold GEMS software (the program that collects and tabulates all the votes from the various precincts), I figured I would take a few minutes to try to debunk some of the crap floating around about how shoddy and vulnerable the program is.

After all, it would be inconceivable that software as critical as that used in elections would be left vulnerable

I hate to break it to you but based on the cursory research I've done, the Diebold system is a security abomination. Anyone with the most rudimentary computer skills and 5 minutes of training in MS Access can completly alter the election results and leave absolutely no electronic tract of the crime.

My first reading of the DU site and Bev Harris' BlackBoxVoting.org material all pointed to downloadable GEMS software and a sample database that was about 2 or 3 years old. I downloaded it and played with it. It was child's play to manipulate the vote totals. But I assumed that the files I downloaded were left unsecure for some type of marketing or demonstration purposes. Surely, the operational system would be stronger (or so I thought).

Just to be sure I went looking for an independent security assessment of the Diebold system and found the above referenced analysis that was commissioned by the State of Maryland. It is a damning assessment of glaring and unforgivable vulnerabilities in what should be a secure and trustworthy system. Most troubling, the ability to completely bypass all security measures and open the "back end" Access database directly and change the vote tallies has not been corrected by Diebold.

I'm not defending the DU's delusions about a stolen election. While the technical vulnerabilities are real and frightening, as a practical matter it would be extremely difficult (IMHO) to exploit these on the scale necessary to swing a Presidential election. Too many machines in too many places and too many people that would have to be involved. No way to contain a conspiracy that big. Someone would eventually talk.

However, this should be of concern to all Americans who care about our democratic processes. As long as our election systems exhibit such blatant weaknesses, not only will the opportunities for mischief (and the temptations to exploit them) remain, but they also lend credence to those like the DU and tin hat crowd and give them leverage to cast doubt on the legitamcy of an election.

I guarantee if the electoral shoe is ever on the other foot and these weaknesses are not addressed, it will be the FReepers screaming fraud.

1 posted on 11/14/2004 10:04:47 PM PST by gbchriste
[ Post Reply | Private Reply | View Replies]

To: gbchriste

Simple question. How would one actually tap into the machine to alter it? I mean are you supposed to bring in a laptop to do this?

I agree with you entirely that in order for this to be done, every machine in every precinct would have to be altered. How on earth is that done? I just don't see how it's possible. I assume you have to tap into the machine some way?


2 posted on 11/14/2004 10:13:03 PM PST by SideoutFred (Save us from the Looney Left)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SideoutFred

It's well known that the greatest computer security threat in any software system is from the dishonest insider. Anyone in the precinct or elections office could walk right up to the GEMS server, open the tabulator database and change the totals. Read the RABA report. Depending on how up to date the security patches on the GEMS server are, it is also a simple matter for an outsider to dial into the server via modem, take control, and change the files from the outside.


3 posted on 11/14/2004 10:16:42 PM PST by gbchriste
[ Post Reply | Private Reply | To 2 | View Replies]

To: gbchriste

I have also done some snooping on this security issue as it relates to these machines and as a person of considerable computer knowledge I say you speak bunk.


4 posted on 11/14/2004 10:17:20 PM PST by spinestein (Do not remove this tagline under penalty of law.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: spinestein

Let's discuss. Have you read the RABA report? What facts am I missing? Have I over stated something? Bunk is not an acceptable technical term. Tell me where I've erred and let's debate on the facts.


5 posted on 11/14/2004 10:23:13 PM PST by gbchriste
[ Post Reply | Private Reply | To 4 | View Replies]

To: gbchriste
"While the technical vulnerabilities are real and frightening, as a practical matter it would be extremely difficult (IMHO) to exploit these on the scale necessary to swing a Presidential election. Too many machines in too many places and too many people that would have to be involved. No way to contain a conspiracy that big. Someone would eventually talk.

However, this should be of concern to all Americans who care about our democratic processes. As long as our election systems exhibit such blatant weaknesses, not only will the opportunities for mischief (and the temptations to exploit them) remain, but they also lend credence to those like the DU and tin hat crowd and give them leverage to cast doubt on the legitamcy of an election.

I guarantee if the electoral shoe is ever on the other foot and these weaknesses are not addressed, it will be the FReepers screaming fraud."


I want to be specific about this. What I have just quoted from your post may not be incorrect, but are technically irrelevant. These questions of security apply at least as well to non-electronic forms of balloting and the security problems are not really a technical issue but rather a general issue of fraud and the possible conspiracy to commit fraud. The Democrat Internet Conspiracy Kooks will cry about this no matter the lack of evidence to support it and the history of at least the last decade shows that it is not in the nature of the type of people who frequent the FR to act the same.
6 posted on 11/14/2004 10:28:06 PM PST by spinestein (I'm not a journalist, but I play one on TV -Dan Rather)
[ Post Reply | Private Reply | To 1 | View Replies]

To: gbchriste

"I guarantee if the electoral shoe is ever on the other foot and these weaknesses are not addressed, it will be the FReepers screaming fraud."

We didn't want these in the first place. We wouldn't have them, either, if Gore hadn't created such a mess in Florida, leading the soft-headed media to drum up demand for better voting machines.


7 posted on 11/14/2004 10:31:03 PM PST by Sofa King (MY rights are not subject to YOUR approval.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: spinestein
I agree that the dangers of having the ballot box "stuffed", so to speak, are present, even in a strictly paper ballot system. You're point is well taken that that patricular threat is not a technical issue per se. However, doesn't prudence and common sense dictate that sufficient measures be taken to prevent such occurences and that those measures be appropriate and tailored to the technology is use, whether paper, optical scan, touch screen, abacus...whatever?

But is there any serious computer professional that can argue in a convincing manner that leaving an elections database open and vulnerable to attack is a good idea?

True, many local officials may have procedures in place to mitigate these dangers (e.g. lock up the GEMS server behind closed doors, strictly control modem availability time, etc), but there is no guarantee of that and the system developer should absolutely take more responsibility for ensuring a secure system.

Regardless of what we think the "reality" of the threat is in the election scenario, I don't think anyone familiar with the MS Access environment could argue that the Diebold implementation is not unacceptably weak, considering the stakes.

8 posted on 11/14/2004 10:39:40 PM PST by gbchriste
[ Post Reply | Private Reply | To 6 | View Replies]

To: spinestein

Your critique also reinforces my greater concern. Not that there is in fact some kind of fraud or vote rigging actually occuring, but that the obvious and manifest weaknesses in the system give credence to those who would seek to undermine the results.


9 posted on 11/14/2004 10:45:30 PM PST by gbchriste
[ Post Reply | Private Reply | To 6 | View Replies]

To: spinestein
These questions of security apply at least as well to non-electronic forms of balloting and the security problems are not really a technical issue but rather a general issue of fraud and the possible conspiracy to commit fraud.

So since non-electronic voting systems have flaws, we should accept electronic voting systems that have the same flaws? huh? I thought the goal was to fix these flaws.

10 posted on 11/14/2004 10:46:06 PM PST by killjoy (I'm John Kerry and I'm relieved of duty.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: gbchriste
Well I've been traveling all day from the east coast to Las Vegas. It's 11:00 PM in Las Vegas but 1:00 AM on by body clock so I'm going to bow of this thread for the time being. Hopefully there will be some thoughtful discussion tomorrow.

I challenge everyone to get the RABA report linked above. There's some "technobabble" in it but over all I think its very accessible to and understandable by any reasonably intelligent layman.

Let me say this about the Red team they used in the study. I'm not personally familiar with any of the names, but if the credentials listed are accurate you can take this thing to the bank. Several of the Red team members have 10 and 15 years of experience at the National Security Agency (NSA). In my 26 years in Air Force Intelligence I had lengthy and repeated involvement with this agency. It is the global "Gold Standard" where computer security is concerned. If the Red team members are who they purport to be, this assessment would be virtually impossible to refute.

Check it out.

Signing off for now.

11 posted on 11/14/2004 11:03:06 PM PST by gbchriste
[ Post Reply | Private Reply | To 1 | View Replies]

To: gbchriste
Yes, prudence does dictate that sufficient measures be taken to prevent fraud, or at least reduce it as much as possible and my use of the word "bunk" was inaccurate at least. The RABA report (Jan 20, 2004) notes numerous problem areas with the Diebold system and also relies heavily on the Hopkins report and the SAIC report to bring to attention deficiencies in security. Briefly, they are:
-Failure to fully comply with SW-CMM and SSE-CMM software -standards
-Lack of hard verifiable backups (Paper Copies)
-Ease of fraudulent smart card use
-The use of C++ (not sure how important this is)
-Numerous ways of defeating security that are not -self-contained (meaning anyone who breaks into the machine -by guessing a password or using fraudulent smart cards then -has easy access to manipulate the count
-a laundry list of other issues

I confess I have never thought any electronic ballot counter was ever a good idea for the simple reason that all of the above problems are inherent in an electronic system and are in fact irreducible to a level acceptable to the public. Even if every single one of the dozens of problems referred to in the reports are 100% fixed there will be new problems to take their place that will still leave voters distrustful.

Again, I want to be specific. These issues of security may be genuine (however large or small) but they are irrelevant in that the majority of voters will continue to be distrustful of the idea of touching a computer to register a vote and not having anything tangible to prove its existence.
12 posted on 11/14/2004 11:15:41 PM PST by spinestein (I'm not a journalist, but I play one on TV -Dan Rather)
[ Post Reply | Private Reply | To 8 | View Replies]

To: killjoy
"So since non-electronic voting systems have flaws, we should accept electronic voting systems that have the same flaws? huh? I thought the goal was to fix these flaws."

Right. The goal is to fix the flaws, not come up with a brand new technology to make more and larger flaws. I prefer a voter filling out a paper ballot by hand and stuffing it into a box. This computer ballot technology is something the politicians on the left demanded even though they knew it would lead to more ambiguity and uncertainty in election results. Now they have gotten what they wanted; Democratic Internet Conspiracy Kooks screaming about election fraud and it takes someone with a computer science degree to debunk their crackpot theories.
13 posted on 11/14/2004 11:26:00 PM PST by spinestein (I'm not a journalist, but I play one on TV -Dan Rather)
[ Post Reply | Private Reply | To 10 | View Replies]

To: gbchriste; All
We've been following this for a long time... crosslinking:

Click the picture & goto "last" for the latest on Vote Fraud:


14 posted on 11/15/2004 1:01:03 AM PST by backhoe ("We met at Dawn- and destiny Prevailed...")
[ Post Reply | Private Reply | To 1 | View Replies]

To: spinestein
The goal is to fix the flaws, not come up with a brand new technology to make more and larger flaws. I prefer a voter filling out a paper ballot by hand and stuffing it into a box. This computer ballot technology is something the politicians on the left demanded even though they knew it would lead to more ambiguity and uncertainty in election results. Now they have gotten what they wanted; Democratic Internet Conspiracy Kooks screaming about election fraud and it takes someone with a computer science degree to debunk their crackpot theories.

I prefer a modern voting system that has been proven using formal methods to work the way it is designed. There is no reason not to use technology, just it needs to be done securely.

15 posted on 11/15/2004 6:10:34 AM PST by killjoy (I'm John Kerry and I'm relieved of duty.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: killjoy

The real problem is at the local level , we had an election setteled by 33 votes ... We have a very intrenched "good ol boy " system around here.
Now I don't mind because I'm a good ol boy .. but ..
When the outcome of an election is trusted to a select few , we are placing ourselves on a very slippery slope.

Perhaps a presidential election would be hard to fix ... but the local mayor, house of rep or perhaps state senetor ? ... thats not that tuff.

The thing that sets off the alarm to me here in Georgia .. is ... no one seems to care .

It's that "let's just keep this between you and me" attitude. I really think that it boils down to the preception that perhaps "we " can use it to our advantage.

a shame


16 posted on 11/15/2004 8:18:28 AM PST by THEUPMAN (#### comment deleted by moderator)
[ Post Reply | Private Reply | To 15 | View Replies]

To: THEUPMAN
The real problem is at the local level , we had an election setteled by 33 votes ... We have a very intrenched "good ol boy " system around here. Now I don't mind because I'm a good ol boy .. but .. When the outcome of an election is trusted to a select few , we are placing ourselves on a very slippery slope.

By going to a modern cryptographically secure system, you can get rid of this type of influence in the election process. The machine can be made provably secure where it can not be tampered with. I really wonder if there is pressure from both sides to make sure this does not happen.

P.S. I am not talking about the current crop of machines but an open source type system built from the group up to be secure, not security added in as an afterthought.

17 posted on 11/15/2004 10:51:13 AM PST by killjoy (I'm John Kerry and I'm relieved of duty.)
[ Post Reply | Private Reply | To 16 | View Replies]

Comment #18 Removed by Moderator

To: killjoy
Voting is more of a political and social issue than a mathematical issue. It has to be by a system that ordinary people can understand and trust, as well as a system that highly motivated, extra ordinary people cannot abuse, at least not easily, in large numbers.

"Formal methods" apply to logical and mathematical proofs. While such formally proven technology has a part to play in a secure voting system, it is not the hard part. Indeed, the role of such technology, such as fancy encryption algorithms, in voting systems is often used to buffalo (as in intimidate by display of power) the populace.

Voting is a people problem, more than a mathematical problem.

The common man must come out of the polling place knowing that his vote was registered correctly.

Personally, I remain convinced that this means that while there is a place for a nice, colorful electronic screen to place ones vote, making it easier for more people to be comfortable that they made the choice they intended, this has to be converted, right before their eyes, to a simple paper ballot that they can see is right, meaning with their votes visible and understandably written.

This paper ballot would be what is cast and counted, and if necessary, recounted.

19 posted on 12/07/2005 7:31:33 AM PST by ThePythonicCow (To err is human; to moo is bovine.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: killjoy
Yes - an Open Source system. A closed source system is accessible only to the sufficiently motivated. If access is illegal, only illegals will have access.

In addition to being visibly trustworthy to the common voting citizen, it has to be openly trustworthy to us nerds, who the common person looks to to understand less obvious risks of technology.

This thing needs to be, at all key and critical interfaces, such as when votes pass from the individual citizen to the polling place, and from there are consolidated, open, simple, and verifiable.

20 posted on 12/07/2005 7:35:58 AM PST by ThePythonicCow (To err is human; to moo is bovine.)
[ Post Reply | Private Reply | To 17 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson