Posted on 11/14/2004 10:04:47 PM PST by gbchriste
The State of Maryland election system (comprising technical, operational, and procedural components), as configured at the time of this report,contains considerable security risks that can cause moderate to severe disruption in an election.
The team also verified that the current version of the GEMS software still contains many of the vulnerabilities widely published on the Internet. It was disappointing to see that no obvious attention was paid to addressing these weaknesses.
The quantity and quality of the attacks described above is disturbing, especially given the short time the team had access to the system. Certain shortcuts were taken (e.g., assuming knowledge of the phone number that connects to the GEMS server) but we feel these are reasonable actions that a determined attacker would be able to overcome.
(Excerpt) Read more at raba.com ...
After all, it would be inconceivable that software as critical as that used in elections would be left vulnerable
I hate to break it to you but based on the cursory research I've done, the Diebold system is a security abomination. Anyone with the most rudimentary computer skills and 5 minutes of training in MS Access can completly alter the election results and leave absolutely no electronic tract of the crime.
My first reading of the DU site and Bev Harris' BlackBoxVoting.org material all pointed to downloadable GEMS software and a sample database that was about 2 or 3 years old. I downloaded it and played with it. It was child's play to manipulate the vote totals. But I assumed that the files I downloaded were left unsecure for some type of marketing or demonstration purposes. Surely, the operational system would be stronger (or so I thought).
Just to be sure I went looking for an independent security assessment of the Diebold system and found the above referenced analysis that was commissioned by the State of Maryland. It is a damning assessment of glaring and unforgivable vulnerabilities in what should be a secure and trustworthy system. Most troubling, the ability to completely bypass all security measures and open the "back end" Access database directly and change the vote tallies has not been corrected by Diebold.
I'm not defending the DU's delusions about a stolen election. While the technical vulnerabilities are real and frightening, as a practical matter it would be extremely difficult (IMHO) to exploit these on the scale necessary to swing a Presidential election. Too many machines in too many places and too many people that would have to be involved. No way to contain a conspiracy that big. Someone would eventually talk.
However, this should be of concern to all Americans who care about our democratic processes. As long as our election systems exhibit such blatant weaknesses, not only will the opportunities for mischief (and the temptations to exploit them) remain, but they also lend credence to those like the DU and tin hat crowd and give them leverage to cast doubt on the legitamcy of an election.
I guarantee if the electoral shoe is ever on the other foot and these weaknesses are not addressed, it will be the FReepers screaming fraud.
Simple question. How would one actually tap into the machine to alter it? I mean are you supposed to bring in a laptop to do this?
I agree with you entirely that in order for this to be done, every machine in every precinct would have to be altered. How on earth is that done? I just don't see how it's possible. I assume you have to tap into the machine some way?
It's well known that the greatest computer security threat in any software system is from the dishonest insider. Anyone in the precinct or elections office could walk right up to the GEMS server, open the tabulator database and change the totals. Read the RABA report. Depending on how up to date the security patches on the GEMS server are, it is also a simple matter for an outsider to dial into the server via modem, take control, and change the files from the outside.
I have also done some snooping on this security issue as it relates to these machines and as a person of considerable computer knowledge I say you speak bunk.
Let's discuss. Have you read the RABA report? What facts am I missing? Have I over stated something? Bunk is not an acceptable technical term. Tell me where I've erred and let's debate on the facts.
"I guarantee if the electoral shoe is ever on the other foot and these weaknesses are not addressed, it will be the FReepers screaming fraud."
We didn't want these in the first place. We wouldn't have them, either, if Gore hadn't created such a mess in Florida, leading the soft-headed media to drum up demand for better voting machines.
But is there any serious computer professional that can argue in a convincing manner that leaving an elections database open and vulnerable to attack is a good idea?
True, many local officials may have procedures in place to mitigate these dangers (e.g. lock up the GEMS server behind closed doors, strictly control modem availability time, etc), but there is no guarantee of that and the system developer should absolutely take more responsibility for ensuring a secure system.
Regardless of what we think the "reality" of the threat is in the election scenario, I don't think anyone familiar with the MS Access environment could argue that the Diebold implementation is not unacceptably weak, considering the stakes.
Your critique also reinforces my greater concern. Not that there is in fact some kind of fraud or vote rigging actually occuring, but that the obvious and manifest weaknesses in the system give credence to those who would seek to undermine the results.
So since non-electronic voting systems have flaws, we should accept electronic voting systems that have the same flaws? huh? I thought the goal was to fix these flaws.
I challenge everyone to get the RABA report linked above. There's some "technobabble" in it but over all I think its very accessible to and understandable by any reasonably intelligent layman.
Let me say this about the Red team they used in the study. I'm not personally familiar with any of the names, but if the credentials listed are accurate you can take this thing to the bank. Several of the Red team members have 10 and 15 years of experience at the National Security Agency (NSA). In my 26 years in Air Force Intelligence I had lengthy and repeated involvement with this agency. It is the global "Gold Standard" where computer security is concerned. If the Red team members are who they purport to be, this assessment would be virtually impossible to refute.
Check it out.
Signing off for now.
Click the picture & goto "last" for the latest on Vote Fraud:
I prefer a modern voting system that has been proven using formal methods to work the way it is designed. There is no reason not to use technology, just it needs to be done securely.
The real problem is at the local level , we had an election setteled by 33 votes ... We have a very intrenched "good ol boy " system around here.
Now I don't mind because I'm a good ol boy .. but ..
When the outcome of an election is trusted to a select few , we are placing ourselves on a very slippery slope.
Perhaps a presidential election would be hard to fix ... but the local mayor, house of rep or perhaps state senetor ? ... thats not that tuff.
The thing that sets off the alarm to me here in Georgia .. is ... no one seems to care .
It's that "let's just keep this between you and me" attitude. I really think that it boils down to the preception that perhaps "we " can use it to our advantage.
a shame
By going to a modern cryptographically secure system, you can get rid of this type of influence in the election process. The machine can be made provably secure where it can not be tampered with. I really wonder if there is pressure from both sides to make sure this does not happen.
P.S. I am not talking about the current crop of machines but an open source type system built from the group up to be secure, not security added in as an afterthought.
"Formal methods" apply to logical and mathematical proofs. While such formally proven technology has a part to play in a secure voting system, it is not the hard part. Indeed, the role of such technology, such as fancy encryption algorithms, in voting systems is often used to buffalo (as in intimidate by display of power) the populace.
Voting is a people problem, more than a mathematical problem.
The common man must come out of the polling place knowing that his vote was registered correctly.
Personally, I remain convinced that this means that while there is a place for a nice, colorful electronic screen to place ones vote, making it easier for more people to be comfortable that they made the choice they intended, this has to be converted, right before their eyes, to a simple paper ballot that they can see is right, meaning with their votes visible and understandably written.
This paper ballot would be what is cast and counted, and if necessary, recounted.
In addition to being visibly trustworthy to the common voting citizen, it has to be openly trustworthy to us nerds, who the common person looks to to understand less obvious risks of technology.
This thing needs to be, at all key and critical interfaces, such as when votes pass from the individual citizen to the polling place, and from there are consolidated, open, simple, and verifiable.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.