Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

1–10 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#3
The conclusion:

Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles:

1. It is important to derive facts through reason and inquiry rather than blind faith.

2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information.

We did not make these principles up ourselves. Rather, these principles are the foundation of the Enlightenment, which has guided modern science to achieve the medical, engineering, and IT advances, among others, that underpin the modern world. Since these principles have largely guided the human race toward progress for the last 500 years, we plan to continue to follow them.

These principles matter most when we put them into practice. Therefore, it is relevant to ask what new facts all the poking and inquiring into our voting systems has identified since the Voting VIllage was established. Among the dozens of vulnerabilities identified in the last two years, four key DEF CON Voting Village findings are grave and undeniable:

1. Supply Chain Insecurity:​ The voting machine parts supply chain is global and has essentially no security procedures to determine whether the machine parts are trustworthy or pre-hacked before the machine is assembled. Thus if an adversary compromised chips through the supply chain, they could hack whole classes of machines across the U.S., remotely, all at once.

2. Remote Attacks Proven: ​Despite insistence the fact that machines are “air gapped” from the Internet protects against all remote attacks, both DEF CON 25 and 26 found exploits to hack machines remotely, requiring physical access to the machine.

3. Hacking Faster Than Voting: ​This year DEF CON also demonstrated that while, on average, it takes about six minutes to vote, machines in at least 15 states can be hacked with a pen in two minutes. It is thus possible for someone to hack a machine while voting in a polling place on Election Day.

4. Hacks Don’t Get Fixed: ​Finally, we discovered that even when vendors are told about serious flaws in machines by their customers, those flaws go unfixed.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#5
Virginia went back to paper ballots and optical ballot scanning several years ago. I think the only drawback to this approach is storing the ballots for X years after an election (takes up space). But, it's far more secure and easy for everyone to do. Just like taking a high school test... pencil in the circle.

https://en.wikipedia.org/wiki/Optical_scan_voting_system

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#6
Some of the vulnerabilities are, appallingly, mundane multi-user operating system misconfigurations that have been known about since the 1960s and 1970s. The one where simply connecting a serial terminal yields a root login session with no password is particularly egregious.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#7
post #3

The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…

> it takes about six minutes to vote

Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates.

Just curious.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#8
post #5

Virginia went back to paper ballots and optical ballot scanning several years ago. I think the only drawback to this approach is storing the ballots for X years after an election (takes up space). But, it's far more secure and easy for everyone to do. Just like taking a high school test... pencil in the circle. https://en.wikipedia.org/wiki/Optical_scan_voting_system

And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes.

An electronic scanning system could easily be vulnerable to many of the same issues that are presented here.

Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about everyone that can vote can help count (unlike with electronic counting machines where only a very competent engineer could even begin to audit a machine like that, assuming that they were allowed to even do so), and in places that run elections like this, there is almost never a shortage of people willing to assist counting votes, especially when the election is particularly controversial ("I'm not going to let that [side a] person from screwing over us on [side b]! Let's go get 20 of us there watching to make sure nothing bad is happening!")

Voting should be hard, voting should be expensive (for the country, not for individual people). Why "optimize" the one thing that secures our country with alternatives that are less secure, have more points of failure, and are overall less understood both by the voters and by the people using the machines to tally votes?

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#9
Here's a quick summary of the machines that they have reported vulnerabilities in. I've used [ed] to mark where I'm adding relevant content not present in the report.

In my non-professional opinion, none of these vulnerabilities seem earth-shattering, although the potential lack of paper trails makes some of the touch-screen systems very dicey. Both of the touch-screen systems have the option of a voter-verified paper trail, but it's not clear how widely those option are deployed.

Diebold ExpressPoll-5000

- Use: Used to check in voters at the polling station.

- Vulnerabilities: No voting-specific vulnerabilities were found; generally an insecure WinCE machine. Physical access would be needed to compromise.

- Impact: Could change voter polls to selectively exclude individuals, forcing them to use provisional ballots. Could add voters to polls potentially, but not clear [ed] if this would pass a cross-reference with upstream voter registry.

Dominion AVC Edge

- Use: Touch-screen voting machine. Records votes electronically and [ed: has an optional voter-verified paper ballot audit system. Not clear how widely used the paper ballot system is used with this machine.] Verifies voter eligibility with a smart card distributed by poll staff. [ed: Presumably the smart card cross-referenced with the voter rolls during tally.]

- Vulnerabilities: Physical vulnerabilities, including swapping out the electronic storage. [ed: Not clear if this would be detected by audits against the smart card registration or voter rolls].

- Impact: Removed or changed votes or completely synthetic votes, [ed: if not cross-referenced; or the storage could be re-written to change or spoil existing votes]. [ed: If paper option is not used, then no audit would be possible if storage is compromised].

Dominion Premier/Diebold AccuVote TSx

- Use: Touch-screen voting machine. Records votes electronically and has an optional voter-verified paper ballot system. Verifies eligibility with smart card distributed by poll staff.

- Vulnerabilities: Denial-of-service attacks easily available by unplugging a cable. Smart card is supposed to be reset by the machine, but a substitute smart card can be used that allows unlimited votes. [ed Not clear if this would pass a cross-reference with the voter rolls, or if the machine is equipped to allow such an audit.] Malware could be distributed for the device [ed: through unspecified channels]. Such malware would allow an adversary to compromise many machines without requiring physical access to polling stations.

- Impact: Removed or changed votes or completely synthetic votes [ed: if not cross-referenced with voter rolls; or malware could be used strictly to change votes and still pass the cross-referencing with voter polls. The user-verified paper option could mitigate some of this, but the malware could theoretically spoil the user-verified ballot and produce a new non-spoiled ballot with a changed vote.]

ES&S M650

- Use: Strictly for tallying of paper ballots.

- Vulnerabilities: Physical security at the polling place, and network-based attacks in situations where the devices are networked (not at the polling place, but at the clerks office or similar centralized locations). Thought attempts are made on the device to prevent unauthorized software from being installed, there are known vulnerabilities that allow that to be changed, through a serial control port or by modifying the Zip disks (?!) that are used as the underlying file system.

- Impact: Changing vote tallies. [ed: An audit would be possible because this machine uses a direct voter-filled-out paper trail].

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#10
There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district are susceptible without having to wade through pages and pages of text.
Post reply on HN