Tags for This Article:

USA United States Of America (7177)  Electronic Voting (2840)  2006 Elections (2728)  Voting Integrity (2696)  Democracy (1926)  Voter Disenfranchisement (1906)  Enemies Of Democracy (937)  Vote Theft (873)  Election- Ballot Access (840)  Voter Fraud (482) 

Populum Tag Cloud
       Control Panel
Fine tune your search to access content
Articles
Diaries Products
Events All
All time
Last 6 mos
Last month
Last week
Last 24 hrs
From:
Month  Day   Year

To:
Month  Day   Year
Alphabet
Popularity
Count ON
Count OFF
This Level
Sub-levels

 

 

 

Tag(s): ; ; ; ; ; ; ; ; ;
Add to My Group
May 12, 2006 at 15:49:03

Critical security alert: Three-level security flaws found in Diebold touch-screens

by Bev Harris, Black Box Voting (Posted by Joan Brunwasser)     Page 1 of 3 page(s)

www.opednews.com

 
 
Tell A Friend

View Ratings | Rate It  

Black Box Voting : Latest Consumer Reports from Black Box Voting: 5-11-06: Three-level security flaws found in Diebold touch-screens
------------------------------------------------------------

Posted by Bev Harris on Thursday, May 11, 2006 - 12:34 pm:



Due to the nature of this report it is distributed in two different
versions. Details of the attack are only in the restricted
distribution version considered to be confidential. Fewer than 50
words have been redacted in the version below.

Overview

http://www.blackboxvoting.org/bbvtsxstudy.pdf
327 KB
Critical Security Alert: Diebold TSx and TS6 voting systems
by Harri Hursti
for Black Box Voting, Inc.

Note: Please refrain from speculation or public discussion of
inappropriate technical details.

This document describes several security issues with the Diebold
electronic voting terminals TSx and TS6. These touch-pad terminals are
widely used in US and Canadian elections and are among the most widely
used touch pad voting systems in North America. Several
vulnerabilities are described in this report.

One of them, however, seems to enable a malicious person to compromise
the equipment even years before actually using the exploit, possibly
leaving the voting terminal incurably compromised.

These architectural defects are not in the election-processing system
itself. However, they compromise the underlying platform and therefore
cast a serious question over the integrity of the vote. These exploits
can be used to affect the trustworthiness of the system or to
selectively disenfranchise groups of voters through denial of service.

Three-layer architecture, 3 security problems

Each can stand alone or combine for 3-layer offense in depth

As an oversimplification, the systems in question have three major
software layers: boot loader, operating system and application
program. As appropriate for current designs, the first two layers
should contain all hardware specific implementations and
modifications, while the application layer should access the hardware
– the touch pad, memory card, the network etc. – only via services and
functions provided by the operating system and therefore be
independent of the hardware design. Whether the architecture in
question follows these basic guidelines is unknown.

Based on publicly available documentation, source code excerpts and
testing performed with the system, there seem to be several backdoors
to the system which are unacceptable from a security point of view.
These backdoors exist in each of these three layers and they allow the
system to be modified in extremely flexible ways without even basic
levels of security involved.

In the worst case scenario, the architectural weaknesses incorporated
in these voting terminals allow a sophisticated attacker to develop an
"offense in depth" approach in which each compromised layer will also
become the guardian against clean-up efforts in the other layers. This
kind of deep attack is extremely persistent and it is noteworthy that
the layers can conceal the contamination very effectively should the
attacker wish that. A quite natural strategy in these types of
situations is to penetrate, modify and make everything look normal.

Well documented viral attacks exist in similar systems deploying
interception and falsification of hash-code calculations used to
verify integrity in the higher application levels to avoid detection.
The three-level attack is the worst possible attack. However, each
layer can also be used to deploy a stand-alone attack. The TSx systems
examined appear to offer opportunities for the three-level attack as
well as the stand-alone attacks.

It is important to understand that these attacks are permanent in
nature, surviving through the election cycles. Therefore, the
contamination can happen at any point of the device's life cycle and
remain active and undetected from the point of contamination on
through multiple election cycles and even software upgrade cycles.

 1  |  2  |  3

 

Contact Editor

 

Bookmark this page: (what's this?)

NETSCAPE      DIGG THIS      Add This Page to Mr Wong!           NEWSVINE      DEl.ICIO.US      Looksmart Furl      My Web      Tag!RawSugar      Blink List     (More...)
Comments: Expand   Shrink   Hide  
No comments

 

Tell A Friend

 


Copyright © OpEdNews, 2002-2008

Blog Ads

 

 

 

 

Most Popular Articles
in the Last 2 Days
(by Recommend Emails)

Special Message for Tibetans Living In and Outside of Tibet Posted by Stephen Fox

Keith Olbermann Broke Up With Me! by Shannyn Moore

Study Confirms Genetically Modified Crops Threaten Human Fertility and Health Safety Posted by sadelaine

SO SAY THE BANKERS: Learn to Love the 'AMERO' by Patrick Henningsen

Getting Through the Coming Depression by Bernard Weiner

Tim Robbins: An Open Letter to the New York City Board of Elections by Tim Robbins

Obama is Already Stirring Controversy by The Old Codger

Kucinich is Still Rockin' My World Toward Peace by Meryl Ann Butler

Senate testimony by police captain reveals 9 sticks of missing dynamite in 'Omaha Two' bombing case by Michael Richardson

This is funny! Good for a chuckle... Posted by Kathryn Smith

Go To Top 50 Most Popular