Feeds

Diebold voting systems critically flawed

'It is like the nuclear bomb for e-voting systems'

Intelligent flash storage arrays

Members of BlackBoxVoting did not look to go national at first, but searched for a state that might take action on the issue. With that in mind, their first choice was not Pennsylvania, but California.

The selection was understandable. The Golden State had plenty of battles with election systems makers and even decertified Deibold's touch screen systems in April 2003. Yet, three years later, BlackBoxVoting did not make much headway with state officials, possibly because California's Secretary of State is elected, where Pennsylvania's is appointed, said BlackBoxVoting's Harris.

"There is a lot less politicking that can happen in Pennsylvania than in California," she said. "The very people that are responsible for remediation are running for election right now, and it adds more complexity to the issues."

With little interest from California, Harris turned to Carnegie Mellon's Shamos and Pennsylvania.

After hearing the details of the issue, Shamos knew that he needed to get Pennsylvania officials involved. Within a week, the state held a conference call with Diebold and, under threat of decertification, asked the company to come clean on the security issue. Diebold acknowledged the issue, but classified the threat as low, Shamos said.

The computer scientist's estimation of the flaw is less charitable.

"There are two types of security holes," he said. "The ones that are designed in and which you didn't think about the security implications beforehand or a bug- a mistake - in the program code. This is the first kind: It is not a bug; it's a horribly designed feature."

Other independent sources and the report released this week by BlackBoxVoting also called the security issue a design flaw. To ease system upgrades for Diebold technicians, the company allowed anyone with a memory card and knowledge of certain file names to upgrade any of three levels of system software: the boot loader, the operating system and the application itself.

"There seems to be several backdoors to the system which are unacceptable from a security point of view," stated BlackBoxVoting's report, penned by computer security expert Hursti. "These backdoors exist in each of these three layers and they allow the system to be modified in extremely flexible ways without even basic levels of security involved."

Shamos cautioned against overemphasizing the threat. Poll-worker-level access to the machines is needed for several minutes to accomplish the attack. More importantly, an insider's knowledge of the source code of the machines would be needed to actually attempt to impact an election, he said. With that said, the threat should be taken seriously, he stressed.

"It is a feasible exploit," Shamos said. "You don't have to dip into the realm of science fiction to figure out how someone could make use of this."

Shamos, as often a critic of BlackBoxVoting as not, said the organization did well to approach election officials quietly about the flaw rather than go public with the details.

Based on the findings in the report, the Commonwealth of Pennsylvania issued an order last week to election officials to sequester any systems until a statewide election on May 16 and reload the machines with an authorized copy of election software to be provided by the Department of State for Pennsylvania.

Already, Iowa and California have warned their election officials of the flaw, according to the Associated Press, and Shamos expects more to come.

"Once Pennsylvania does something, then the other states have to follow," he said. "The dominoes have started falling. States cannot sit on this forever."

Internet Security Threat Report 2014

More from The Register

next story
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
'Cowardly, venomous trolls' threatened with TWO-YEAR sentences for menacing posts
UK government: 'Taking a stand against a baying cyber-mob'
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Arab States make play for greater government control of the internet
Nerds told to get lost in last-minute power grab bid at UN meeting
Zippy one-liners, broken promises: Doctor Who on the Orient Express
Series finally hits stride, but Clara's U-turn is baffling
Don't bother telling people if you lose their data, say Euro bods
You read that right – with the proviso that it's encrypted
Apple SILENCES Bose, YANKS headphones from stores
The, er, Beats go on after noise-cancelling spat
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.