Live data from Hacker News

Cyber Attackers Crash Muni Computer System Across SF

sanfrancisco.cbslocal.com

41–43 of 43 posts

Re: Cyber Attackers Crash Muni Computer System Across SF

#41
post #29

Earlier quoted context omitted.

It's been what, 2 days, over a holiday weekend? Where do they get that many new computers and what does it cost, is that in the budget? Are they insured? Do they have the staff on hand to fix it? Do they even know what the fix actually is? If they rolled out a bunch of new hardware how would they know it wouldn't just get re-infected? Are you going to stomach a fare hike or increased taxes for a computer system swap…

My understanding is that the SFMTA has contractors on call to fix this. The machines are probably contracted out to a third party. I'll get to find out soon enough for sure!

So what'd you find out?

Also sounds like it's back up so I call myself impressed.

Re: Cyber Attackers Crash Muni Computer System Across SF

#42
post #37

Earlier quoted context omitted.

The most secure voting machine certified in my county runs Android Jelly Bean from 2012. It's fish in barrels all the way down...

As much fun as Android is, I don't _think_ there's any public RCEs that recent, while I can think of a couple of recent Windows XP+ RCEs that are probably also doable-but-unpatched on Win2k: [1] - https://www.cvedetails.com/cve/CVE-2013-3175/ [2] - https://www.cvedetails.com/cve/CVE-2012-1852/ [3] - https://www.cvedetails.com/cve/CVE-2012-0173/ [4] - https://www.cvedetails.com/cve/CVE-2012-0002/ (Those were just the…

Well, the most common voting machines are iVotronics from ten years ago, which are pretty laughable. Dr. Appel at Princeton already hacked these systems back in 2006. There's even a flash card on the top of the machine, which even the state's hand-picked pen tester had to admit could be accessed even with a tamper-proof lock in place.

It's starting to bother me that the PA election officials keep saying that the voting machines aren't connected networked together, and that one would need 4,500 cards to compromise an election. It's just flatly false, since every county feeds into a central system such as Unity or GEMS, which themselves are provably insecure, and can be infected via the compact flash cards when they're collected. You would only need a few people in key counties to swing an entire election.

What I would give for the days of hanging chads...

Post reply on HN