Posted on 12/06/2007 6:13:34 AM PST by antiRepublicrat
Earlier this year, California Secretary of State Debra Bowen established strict new standards for electronic voting machines, requiring independent code audits, Red Team security testing, and support for paper records. The Red Team testing process primarily involves subjecting the machines to review by security experts who attempt to hack the software and bypass the physical security mechanisms. Recent Red Team tests of ES&S voting machines have uncovered serious security flaws.
Previous Red Team tests commissioned by the state of California revealed significant vulnerabilities in devices sold by Diebold and Sequoia. At the time, ES&S declined to participate in the testing, citing lack of preparedness. The tests on the ES&S machines were finally conducted in October, and the results, which were recently published (PDF), show that products from ES&S are as insecure as the rest.
The first round of tests focused on the physical security of the Polling Ballot Counter (PBC), which the Red Team researchers were able to circumvent with little effort. "In the physical security testing, the wire- and tamper-proof paper seals were easily removed without damage to the seals using simple household chemicals and tools and could be replaced without detection," the report says. "Once the seals are bypassed, simple tools or easy modifications to simple tools could be used to access the computer and its components. The key lock for the Transfer Device was unlocked using a common office item without the special 'key' and the seal removed."
After bypassing the physical security of the voting machines, the Red Team researchers were able to gain direct access to all of the files on the systems, including password files. "Making a change to the BIOS to reconfigure the boot sequence allows the system to be booted up using external memory devices containing a bootable Linux copy," according to the researchers. "Once done, all the files can be accessed and potentially modified, including sensitive files such as the password file which can be cracked by openly available cracker programs. New users may be added with known passwords and used by the same attacker or other attackers later."
The Election Management System workstations were also found to be vulnerable, with critical security codes stored in files as plain text. The Red Team also discovered that the Election Loader System used unencrypted protocols to transmit election initialization data to the PBC units, which implies vulnerability to a man-in-the-middle attack. The Election Loader System is populated with data from an Election Distribution CD, which is generated by a special Election Converter Application. The researchers were able to break the encryption used on the generated CD to "breakdown the CD, revise the election definition, and replace the CD with a new encrypted CD with an alternate election definition." The researchers note that this tactic could be used to alter vote tallies.
ES&S is already in serious trouble in California for selling uncertified voting machines to several counties in violation of state law. The results of the Red Team test, which demonstrate beyond doubt that the security of ES&S voting machines is utterly inadequate for use in elections, make it seem unlikely that ES&S will be able to continue peddling their defective products in the state.
I do not like e-voting. Too much room for mischief. Paper ballots are essential. Electronic counting okay.........
I really don’t like e-voting. I believe it seriously undermines confidence in the results of an election. There’s no way that the average voter can be certain that there was no tampering. And there’s really no need for it. Sure, it gives results faster and probably saves some labor and printing costs. But I don’t believe those savings are worth the risks.
Yet it can never be trusted. No more recounts. Lawyers and software engineers in court instead...
Basically you are putting all your trust in the people who operate them. Without a paper record that the voter reviews that can be physically recounted it is doomed to be abused.
I’m not that convinced that this is a valid test. Why? Elementary my dear Dr. Watson. Physical security of the voting machines is assumed to be non-existent. That is a bad assumption. If whatever agency is responsible for the voting machines can’t keep them out of the hands of hackers, there is not a damn thing anyone can do. Give hackers infinite access, time and money of course they can crack the damn things.
That said, here in my corner of the People’s Republik we use paper ballots with optical scanning to count the votes. I personally think that is the way to go because it provides a paper audit trail. Require photo ID and do away with mail in voting and you have a tight system that is reasonably accurate (when combined with paper ballots and scanners). If you’re really worried, then require an independent audit based on the paper records. Not all that hard to do, but it does cost a bit.
There is only one answer: photo id., paper ballot and indelible ink thumb dip.
Ahh, but the one big saving grace of evoting is that the dems can’t go into the basement and “find” boxes of uncounted ballots during recounts.
And you are happy with the integrity of poll workers and whoever manages/works in the facility where these things are stored ?
Believe me, I’ve done security audits from front door to rooftop and every system in between, and this is a huge no-no.
You store this stuff the way we used to store classified hardware and I’d be happy enough. Bonded storage in an enclosed cage with full time human monitoring and dual entry to touch the hardware. Two persons in control of the hardware at all times to and from the polling place. And so on. If it was good enough for the “items” we were working on, it’s good enough for voting machines.
Yeah, but I’ll bet the classified hardware was a little better protected than these - took longer to open, had no external ports like floppies or usb or cd - etc.
The secure machines I’ve worked on have no way you can plug in an external device and bypass security like they could with these, and booting into an OS where they could quickly hack or copy at will was not a quick option - you’d have to have hacked the server first.
We’ll all I’d want on the software side, once the physical security was in place, would be that the image on the disk be wiped and recreated from a secure source prior to use. Bottom line, I like paper trail, so this implementation is not my first choice. Paper ballot (scannable) is my suggestion - along with photo id, and no mail in ballots (again, fraud prevention).
Same. We use optical scan ballots in my county.
The problems with e-voting are:
1) Each machine costs too much, therefore districts will not buy enough machines for high turnout years. Expect long lines.
2) Each machine is esentially a computer that will be stored away for months, and sometimes four years at a time, then be expected to just fire up again come election time.
The answer is the optically scanned ballot and here is why:
1) The system scales up and down easily and cheaply to match the anticipated turnout of the election. Each polling station is really just a table to hold the ballot. You can set up as many or as few tables as necessary for the anticipated turnout. With a ballot read times of less than one second, a single Optical Scan Reader can read ballots for a precinct no matter what the volume.
2) You only need one OCR per pricinct, so you get them out for each and every election. They are exercised more often, and there are many fewer of them to store. Because there are fewer to store, they are more likely to be stored in a properly conditioned room.
3) You retain the optical ballots for a manual recount.
“Im not that convinced that this is a valid test. Why? Elementary my dear Dr. Watson. Physical security of the voting machines is assumed to be non-existent.”
I made a few changes: That is a bad assumption. If whatever agency is responsible for the voting boxes and paper ballots cant keep them out of the hands of tamperers, there is not a damn thing anyone can do. Give tamperers access, time and money of course they can stuff the damn things.
The vendors need a way to reliable reset the machines to a known working state, and verify that they are working properly. After the machines are set up for the election, real physical security is required to make sure they are not tampered with before the election starts, and observers should be allowed to watch for tampering during the election.
Simple locks and tamper resistant seals are not designed to guard against a skilled person that has a significant amount of time alone with the machines, and making the machines invulnerable to such attacks is not practical.
The only real solution is to provide physical security and independent observers to watch over the machines between the time when they are set up until post election canvasing is complete and it is verified that the machines operated properly.
The vast majority of the security problems these tests find are not really problems with the systems because the situations in which they could be exploited require failures in the chain of custody of the machines that should never happen. If you allow the machines to be left alone, there is almost nothing you can do to keep them secure.
This is also not a problem that is restricted to electronic voting. If you leave people alone with a ballot box, they can alter the results of the election as well.
The Diebold machines we use here print a paper ballot that the voter can see through a transparent window in the machine and visibly verify that it records their vote properly. The machines keep a paper trail that can be used in post election canvasing to ensure that they votes were recorded properly, and there's no hanging chads to worry about.
This of course has not stopped the hysteria over electronic voting here.
I agree that a paper record is necessary, but going back to punch cards isn't the right solution.
Our ballots here are like the SAT tests. You fill in a circle with a marker pen next to the candidates name. You put the paper into a machine the size of a HP laser printer and it tallies the marks, stores the ballot inside a locked drawer and you walk away..........
We use ES&S machines here in Aiken County, SC. And I have served as both a poll manager and a roving technical troubleshooter.
That said, this article is very one sided. I am not defending ES&S. But, gee, was ES&S given a chance to respond to these allegations? If they were, what was their response?
FWIW, I have also worked the polls where optical scanning was used. To me this seems to be a more reliable system. Not tamper proof (no system will ever be) but at least you have paper for recounts.
In security it's physically secure (as in a controlled-access datacenter) or it isn't. These machines will be left unattended with various party hacks all over the state, so you have to assume the opponent has access. You are correct that in security physical possession means your system will be hacked given time and resources, thus there are two major things we can do:
- Detect tampering. This cannot be 100% since the attacker has possession, but it can be done a lot better than it was. For example, digitally sign each vote, and have paper printouts include the text representation of the signature. A modified system would have an invalid signature.
- Increase the time and required skill level. A Democrat hack would have only so much time to do the deed, so we have to make it take longer to do it. The use of high-security locks would help, as they are unpickable by an amateur, and a pro would still need some time. After that, forget BIOS, use EFI. Sign it (verify the authenticity) and use it to encrypt and sign the disk, the OS and the voting application. Use it to trap and control various sensitive operations below the level of the OS (such as accessing anything outside the machine). The precinct manager would have a crypto key issued by the state that can turn on his machines if nothing's been tampered with.
Is it perfect? No, that's impossible. Would it take a long time and a high skill level to bypass it? Definitely. And that's enough to stop local party hacks from committing vote fraud through the machines.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.