Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

DetlefK

(16,423 posts)
Tue Jul 31, 2018, 11:05 AM Jul 2018

At IT security-conference, it took hackers 2 MINUTES to hack a voting-machine.

https://www.theroot.com/a-conference-asked-hackers-to-see-which-voting-machines-1797434629

When attendees at the Def Con computer security conference—perhaps the biggest gathering of computer hackers in the world—were challenged to hack into 30 voting machines, they went to work. They breached the first one in about two minutes, according to CNET and USA Today. Within 24 hours, attendees had broken into every single voting machine.

I’m sure you’re thinking, “With months of planning and coding, a really good computer expert could probably break into any system.” Well, the experiment, called the “Voter Hacking Village,” wasn’t announced beforehand. The organizers simply went online and—OK, this is the insane part—bought 30 voting machines off eBay!

If that fact stunned you, here are a few other things that might surprise you:

The machines with Advanced Voting Machines’ WINVote system, used in Virginia, Pennsylvania and Mississippi, all had the same password. The password (you might want to take a deep breath here) was “abcde.” The password could not be changed.
One group hacked the WINVote system through Wi-Fi, while another needed only a USB keyboard and mouse. An intern at a security company called Synack demonstrated that changing votes was as easy as updating a Microsof Office document. “You just update the votes and change it back,” she said.
One ExpressPoll voting machine, a voter tablet used as recently as April 2017 in a Georgia special election, had 600,000 voter registrations still on it, according to Wired. A hacker broke into that system in 45 minutes. The hacker was 16 years old.
9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
At IT security-conference, it took hackers 2 MINUTES to hack a voting-machine. (Original Post) DetlefK Jul 2018 OP
The password cannot be changed?!!! hedda_foil Jul 2018 #1
Wow, that was a stupid choice. Blue_true Jul 2018 #9
ICYMI - RandomAccess Jul 2018 #2
black box voting, anyone? some of us remember 2000. niyad Jul 2018 #5
Wow.. Kentonio Jul 2018 #3
wow, they must have gotten the really slow hackers. niyad Jul 2018 #4
Even here on DU if you post that Russian/trump operatives hacked... brush Jul 2018 #6
Between the denials of tampering on the one hand... LanternWaste Jul 2018 #8
WHAT IN GOD'S NAME ARE THE MACHINES DOING ON EBAY? shraby Jul 2018 #7

Blue_true

(31,261 posts)
9. Wow, that was a stupid choice.
Tue Jul 31, 2018, 12:35 PM
Jul 2018

Unbelievable that systems would be made that would not allow users to set unique passwords. But even with unique passwords, hackers can break in if encryption protocol is weak, all they need is for a system admin to get careless with a password, in that case, even encryption can be defeated.

Most private VPN have a base level of encryption. Employees sign in with a password that the system recognizes and once the employee is on, the system constantly changes the base password to defeat someone who tries to piggyback on the employee, but don't have the employee password and IP address. The system is pretty strong, but if the employee is targeted and is careless, a hacker can get both the person's password and IP address, then try to mirror the employee's access privs.

brush

(53,810 posts)
6. Even here on DU if you post that Russian/trump operatives hacked...
Tue Jul 31, 2018, 12:16 PM
Jul 2018

into voting rolls of several states in 2016 and most likely had an effect on the election outcome—like maybe the counting of votes, or as you point out, altering voter registrations—you get the repug talking point back that there is no evidence that the Russian hackers had any effect on the election.

I of course always answer them by responding they can believe that if they want to but I don't have to.

 

LanternWaste

(37,748 posts)
8. Between the denials of tampering on the one hand...
Tue Jul 31, 2018, 12:34 PM
Jul 2018

and the bevy of pro-Putin posts we saw in 2016-17 trivializing US foreign policy vis-a-vis Moscow, it can really smell like Borscht around here at times.

Latest Discussions»General Discussion»At IT security-conference...