DEF CON report on vulnerabilities in US election infrastructure [pdf]
1–10 of 145 posts
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#2Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#3Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles:
1. It is important to derive facts through reason and inquiry rather than blind faith.
2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information.
We did not make these principles up ourselves. Rather, these principles are the foundation of the Enlightenment, which has guided modern science to achieve the medical, engineering, and IT advances, among others, that underpin the modern world. Since these principles have largely guided the human race toward progress for the last 500 years, we plan to continue to follow them.
These principles matter most when we put them into practice. Therefore, it is relevant to ask what new facts all the poking and inquiring into our voting systems has identified since the Voting VIllage was established. Among the dozens of vulnerabilities identified in the last two years, four key DEF CON Voting Village findings are grave and undeniable:
1. Supply Chain Insecurity: The voting machine parts supply chain is global and has essentially no security procedures to determine whether the machine parts are trustworthy or pre-hacked before the machine is assembled. Thus if an adversary compromised chips through the supply chain, they could hack whole classes of machines across the U.S., remotely, all at once.
2. Remote Attacks Proven: Despite insistence the fact that machines are “air gapped” from the Internet protects against all remote attacks, both DEF CON 25 and 26 found exploits to hack machines remotely, requiring physical access to the machine.
3. Hacking Faster Than Voting: This year DEF CON also demonstrated that while, on average, it takes about six minutes to vote, machines in at least 15 states can be hacked with a pen in two minutes. It is thus possible for someone to hack a machine while voting in a polling place on Election Day.
4. Hacks Don’t Get Fixed: Finally, we discovered that even when vendors are told about serious flaws in machines by their customers, those flaws go unfixed.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#4I was surprised to read that this remote vulnerability is possible in 23 states. I thought that the United States prides itself on its democracy? How come voting machines are possible in a democracy?
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#5Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#6Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#7The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…
Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates.
Just curious.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#8Virginia went back to paper ballots and optical ballot scanning several years ago. I think the only drawback to this approach is storing the ballots for X years after an election (takes up space). But, it's far more secure and easy for everyone to do. Just like taking a high school test... pencil in the circle. https://en.wikipedia.org/wiki/Optical_scan_voting_system
An electronic scanning system could easily be vulnerable to many of the same issues that are presented here.
Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about everyone that can vote can help count (unlike with electronic counting machines where only a very competent engineer could even begin to audit a machine like that, assuming that they were allowed to even do so), and in places that run elections like this, there is almost never a shortage of people willing to assist counting votes, especially when the election is particularly controversial ("I'm not going to let that [side a] person from screwing over us on [side b]! Let's go get 20 of us there watching to make sure nothing bad is happening!")
Voting should be hard, voting should be expensive (for the country, not for individual people). Why "optimize" the one thing that secures our country with alternatives that are less secure, have more points of failure, and are overall less understood both by the voters and by the people using the machines to tally votes?
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#9In my non-professional opinion, none of these vulnerabilities seem earth-shattering, although the potential lack of paper trails makes some of the touch-screen systems very dicey. Both of the touch-screen systems have the option of a voter-verified paper trail, but it's not clear how widely those option are deployed.
Diebold ExpressPoll-5000
- Use: Used to check in voters at the polling station.
- Vulnerabilities: No voting-specific vulnerabilities were found; generally an insecure WinCE machine. Physical access would be needed to compromise.
- Impact: Could change voter polls to selectively exclude individuals, forcing them to use provisional ballots. Could add voters to polls potentially, but not clear [ed] if this would pass a cross-reference with upstream voter registry.
Dominion AVC Edge
- Use: Touch-screen voting machine. Records votes electronically and [ed: has an optional voter-verified paper ballot audit system. Not clear how widely used the paper ballot system is used with this machine.] Verifies voter eligibility with a smart card distributed by poll staff. [ed: Presumably the smart card cross-referenced with the voter rolls during tally.]
- Vulnerabilities: Physical vulnerabilities, including swapping out the electronic storage. [ed: Not clear if this would be detected by audits against the smart card registration or voter rolls].
- Impact: Removed or changed votes or completely synthetic votes, [ed: if not cross-referenced; or the storage could be re-written to change or spoil existing votes]. [ed: If paper option is not used, then no audit would be possible if storage is compromised].
Dominion Premier/Diebold AccuVote TSx
- Use: Touch-screen voting machine. Records votes electronically and has an optional voter-verified paper ballot system. Verifies eligibility with smart card distributed by poll staff.
- Vulnerabilities: Denial-of-service attacks easily available by unplugging a cable. Smart card is supposed to be reset by the machine, but a substitute smart card can be used that allows unlimited votes. [ed Not clear if this would pass a cross-reference with the voter rolls, or if the machine is equipped to allow such an audit.] Malware could be distributed for the device [ed: through unspecified channels]. Such malware would allow an adversary to compromise many machines without requiring physical access to polling stations.
- Impact: Removed or changed votes or completely synthetic votes [ed: if not cross-referenced with voter rolls; or malware could be used strictly to change votes and still pass the cross-referencing with voter polls. The user-verified paper option could mitigate some of this, but the malware could theoretically spoil the user-verified ballot and produce a new non-spoiled ballot with a changed vote.]
ES&S M650
- Use: Strictly for tallying of paper ballots.
- Vulnerabilities: Physical security at the polling place, and network-based attacks in situations where the devices are networked (not at the polling place, but at the clerks office or similar centralized locations). Thought attempts are made on the device to prevent unauthorized software from being installed, there are known vulnerabilities that allow that to be changed, through a serial control port or by modifying the Zip disks (?!) that are used as the underlying file system.
- Impact: Changing vote tallies. [ed: An audit would be possible because this machine uses a direct voter-filled-out paper trail].