Tag(s): ; , Add Tags
Add to My Group(s)

View Ratings | Rate It

Permalink
View Article Stats      (1 comment)

Diebold's AccuVote-TS Voting Machine Security

Add this Page to Facebook!
Submit to Twitter
Submit to Reddit
Submit to Stumble Upon

Tell A Friend
Become a Fan
Get Embed HTML Code
By (about the author)

Become a Fan Become a Fan   -- Page 2 of 2 page(s)

opednews.com

Why do smart-cards open the door to vote fraud?

Clandestine, but "properly registered, " voters could enter polling places normally, accept their legitimate ballot smart-card from a poll worker, go to a voting machine and simply insert their own "specially pre-prepared " smart-card into the voting machine rather than the legitimate ballot smart-card. When finished, the clandestine voter would return the legitimate ballot smart-card to a poll worked and exit the polling place.

A clandestine voter could insert a smart-card specially prepared with something as simple as a common Windows virus that would "crash " the voting machine. Poll workers typically are not trained to reset machines back into election mode so "crashed " voting machines would be closed until a technician could be summoned to "fix " the problem.

Such an attack, if mounted by multiple people, could temporarily shut down or slow voting at one or more polling places. For polling places in an area considered to favor one candidate over another, the attack could benefit the opposing candidate by deterring a large number of potential voters from voting.

Even more troubling - specially prepared smart-cards could possibly implement a programmed interface that delivers software code into the voting machine to change votes or other functions. Specially programmed smart-cards used by clandestine voters could, for example, change vote counts on voting machines. Simple software code that subtracts votes from one candidate and adds those votes to another candidate yields the same total vote count. This leaves no evidence or red flag to even suspect this simple vote data change occurred because total votes recorded in memory matches the total number of voters who entered the polling place.

A few voters at a few key polling stations near the end of the Election Day could carry out this type of smart-card attack. There would be nothing out of the ordinary to raise anyone 's concern that an election had been stolen. Malicious program code possibly could even be propagated to the central tabulation machine as it reads a voting machine flash memory cards infected via the same technique.


It is the simplest and most innocent-looking security breach that is often the most successful. Voting fraud using the smart-card, I think, qualifies as both simple and easy with a little advanced planning and preparation.

Any malicious-mind person could envisage this vote fraud scenario during a legitimate voting experience with this voting system. Anyone with a little technical savvy and understanding of Microsoft Windows could likely, in an afternoon, google all the information necessary to plan this type of attack. Smart-card blanks and smart-card read/write devices can be ordered over the Internet in a couple of days.

All the best chain-of-custody procedures, voting machine guards and security seals will not stop smart-card vote fraud hacks. Want more proof? Avi Rubin discusses various smart-card vote fraud hacks in greater in his security analysis ( http://avirubin.com/vote.pdf ) report.

Diebold can make this front-door security issue much less onerous by simply adding a data encryption and password protocol to the smart-cards and the voting machine software that reads and writes the smart-card data it has none today!.

Next Page  1  |  2

 

Bachelors of Science Degree in Computer Science and Business Administration with 25 years of experience working in the Independent Software Vendor Industry.

The views expressed in this article are the sole responsibility of the author
and do not necessarily reflect those of this website or its editors.

Contact Author Contact Editor View Authors' Articles

 

Share this page: (what's this?)                   Tell a Friend: Tell A Friend

Add this Page to Facebook!      Submit to Stumble Upon      Submit to Reddit      Add This Page to Mr Wong!           NEWSVINE      DEl.ICIO.US      Looksmart Furl      My Web      Blink List     (More...)

Comments

The time limit for entering new comments on this article has expired.

This limit can be removed. Our paid membership program is designed to give you many benefits, such as removing this time limit. To learn more, please click here.

Comments: Expand   Shrink   Hide  
1 comments
To view all comments:
Expand Comments
(Or you can set your preferences to show all comments, always)

The machines in question are not standard intel PCs by Jason Schmitz on Sunday, May 14, 2006 at 12:16:03 PM