Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

TalkingDog

(9,001 posts)
Wed Mar 14, 2012, 02:47 PM Mar 2012

US e-voting system cracked in less than 48 hours

http://www.h-online.com/security/news/item/US-e-voting-system-cracked-in-less-than-48-hours-1463881.html

Researchers at the University of Michigan have reported that it took them only a short time to break through the security functions of a pilot project for online voting in Washington, D.C. "Within 48 hours of the system going live, we had gained near complete control of the election server", the researchers wrote in a paperPDF that has now been released. "We successfully changed every vote and revealed almost every secret ballot." The hack was only discovered after about two business days – and most likely only because the intruders left a visible trail on purpose.

In 2010, the developers of the municipal e-voting system that enables voters living abroad to vote via a web site, invited security experts to conduct tests. The university researchers say that the project was developed in cooperation with the Open Source Digital Voting Foundation (OSDV) and that other US states have also worked on services similar to Washington's "Digital Vote-by-Mail Service". They also praise the system's transparency as exemplary but point out that its architecture has fundamental security weaknesses and was not able to withstand a shell injection and other common hacker techniques.

The security experts investigated common vulnerable points such as login fields, the virtual ballots' content and filenames, and session cookies – and found several exploitable weaknesses. Even the Linux kernel used in the project proved to have a well known vulnerability. They were also able to use the PDFs generated by the system to trick the encryption mechanism, while unsecured surveillance cameras provided additional insights into the infrastructure. While the open source nature of the code made their work somewhat easier, they believe that attackers would have been able to make quick headway even if the system had been proprietary.

The researchers conclude that it is generally difficult to build secure online voting systems. One small configuration or implementation error would undermine the entire voting process. Even if central servers were not used, which would be prime targets for hacking attempts, there would still be a number of other points of attack. Fundamental advances still need to be made in security, they say, before e-voting will truly be safe.
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
US e-voting system cracked in less than 48 hours (Original Post) TalkingDog Mar 2012 OP
This is some distubing stuff, but it also validates for me the fact that the mfcorey1 Mar 2012 #1
Electronic voting should be banned. drm604 Mar 2012 #2
...and I agree with you. bvar22 Mar 2012 #7
Slots vs Voting machines benld74 Mar 2012 #3
Just like they like it. Rex Mar 2012 #4
Agreed kurt_cagle Mar 2012 #5
Just a thought... I always send these along to my state and local election boards. Please consider TalkingDog Mar 2012 #6

mfcorey1

(11,001 posts)
1. This is some distubing stuff, but it also validates for me the fact that the
Wed Mar 14, 2012, 03:02 PM
Mar 2012

2000 elections and others that right wingers mysteriously won were hacked. I will always believe it.

drm604

(16,230 posts)
2. Electronic voting should be banned.
Wed Mar 14, 2012, 03:06 PM
Mar 2012

I say this as someone with a Comp Sci degree and over 25 years in IT.

bvar22

(39,909 posts)
7. ...and I agree with you.
Wed Mar 14, 2012, 04:46 PM
Mar 2012

Also BAN Computer based Vote tabulators,
and Vote by Mail.

The BEST way to secure our voting system:

*One day, 24 hour Voting period, National Holiday

*Paper Ballots deposited in a transparent Ballot Box

*Ballots Hand Counted at the polling station in a publicly observable, transparent method with live Internet Video feeds, similar to the Casino Video Security. The ballot boxes will remain at the polling under security surveillance until the tally is certified. No boxes removed or transported to another location before certification.

*Multiple Independent Exit Polls and Observers

The 24 hour vote-in-person holiday is necessary for valid Exit Polls and public observation.
If voting is important enough to you, you will be there.

Voting by Mail is one of the least secure methods of protecting our vote.
Who counts & tallies your vote, and HOW do you KNOW?




kurt_cagle

(534 posts)
5. Agreed
Wed Mar 14, 2012, 03:56 PM
Mar 2012

I've been working in IT for the last thirty years, including several projects for government agencies where security was paramount, and have been following the e-voting issues closely. There is no question to me that e-voting as it exists today has become a potent mechanism for corruption. The systems are too easily hacked, too easily compromised "out of the factory" (take a look at how closely Diebold is to the Republican party) and have generally been at the center of controversial votes since their inception. I do not find it at all unusual that the Republican party has managed to gain the entrenchment that it has since 2000 - that's when voting machines were first rolled out in any meaningful way.

TalkingDog

(9,001 posts)
6. Just a thought... I always send these along to my state and local election boards. Please consider
Wed Mar 14, 2012, 04:21 PM
Mar 2012

doing the same. Sometimes they have no idea.

Latest Discussions»General Discussion»US e-voting system cracke...