Feeds

Senate leader explains poll “hack”

Evil cookies take the biscuit

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

Senator Frist's office has elaborated on its explanation of why it pulled a website poll about the Iraq war last week. We could find no evidence of a security breach at the Senate, although this was the primary reason suggested by a Frist spokesperson on Friday. In fact, the poll was hosted outside the Senate firewall, his office now confirms.

The poll was discovered by bloggers, including Tom Tomorrow, who linked to the poll while it was showing a majority in favor of the war. By the time the poll was pulled, the vote count had swung to the Noes.

"Our computer guy has identified one individual who voted 8,700 times," the spokesperson told us today. Apparently, the software deleted the cookie and voted again.

So why not simply discard the 8,700 suspect votes?

"We suspended the poll because it had been tampered with," he said. "If those votes came from 8,700 unique users we would not have had to suspend the poll."

Well, quite. Although it doesn't really answer the question of why those 8,700 votes weren't discarded, and the good votes allowed to count.

It's certainly a puzzle. Previous polls on the Frist website explain that the system detected and disallowed multiple voting. To do so effectively it must log a voter's IP address, rather than rely on a cookie.

But what if, as one readers suggested, the "hacker" was using a dial-up connection? Dial-up connections typically allocate different IP numbers each time you connect.

Well, assuming each connection could be completed in 1 minute and 20 seconds, a single dial-up user would need more than eight days to vote 8,700 times, assuming the he didn't sleep, that the ISP had 8,700 numbers to allocate, and that it didn't allocate the same number twice from its pool of IP numbers.

So we can rule that one out.

"We will ensure that this kind of tampering doesn't happen again," said the spokesperson.

Online election ballots, anyone? ®

Related Story

Senate Leader scraps website war poll, blaming hackers

Remote control for virtualized desktops

More from The Register

next story
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
NSA mass spying reform KILLED by US Senators
Democrats needed just TWO more votes to keep alive bill reining in some surveillance
'Internet Freedom Panel' to keep web overlord ICANN out of Russian hands – new proposal
Come back with our internet! cries Republican drawing up bill
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.