Home
Refresh   Tag(s): ; ; ; ; ; ; ; ; ; ; (more...) ; ; ; ; ;  (less...)
Add to My Group
December 10, 2007 at 16:08:24

View Ratings | Rate It

2007 Technology Tests of Computerized Voting Systems

submit to twitter
submit to reddit
submit to digg

Tell A Friend

By Rady Ananda (about the author)     Page 3 of 8 page(s)

opednews.com     Permalink

“To reduce over 500 pages to two pages, at least a few important findings -- especially about design flaws not relating to security issues -- had to be sidestepped.” 

Below is a partial reproduction of Dr. Hoke’s summary of California’s TTBR:

Election management/tabulation software For all voting systems (“VS”), the system architecture depends on a commercial operating system known to have security vulnerabilities. All vendors failed to secure this system properly. System architecture had not been designed with either basic or sophisticated security protections. All systems failed to follow standard security design principles.  

All systems were susceptible to viruses that could be introduced from a number of vectors, including from voting device memory cards. (Viruses and other rogue programming can, e.g., “flip” votes among candidates, scramble tabulation data, delete voting data, and cause system programming to fail.)  

Viruses could infect the central computer and then be spread to all the voting devices when their memory cards are prepared for the next election.  

System logs of operator activity (“audit logs”) could be overwritten or erased, meaning that insider attackers could manipulate voting data and results, and then erase the logging inventories that would show the access and activity; or, could be used to frame a different employee. 

Systems permitted relatively easy bypassing of passwords, thus permitting broader access than authorized.  

In each VS, many other security holes exist that could compromise the system’s ability to report accurate election results -- or any results.  

Voting Devices  

All systems failed to follow standard security design principles, and lacked even basic security protections. All systems’ devices (DREs and precinct-based optical scanners) were subject to easy, undetectable attacks that could occur during the normal time that a voter would be at a voting machine casting a ballot.  

Some devices permitted the researchers to introduce malicious code onto a voting machine in under a minute, while appearing to be in the process of voting.  

All DRE touchscreen voting units permit a voter to generate and cast multiple ballots during a normal time voting could occur, in ways that would be largely undetectable to poll workers unless they were specially trained and closely supervising the voter’s activity at the unit (voter privacy might still be compromised).  

Some DRE devices permitted the researchers to damage the Voter-Verified Paper Audit Trail (VVPAT) covertly, so the voters could verify that their votes were printed correctly, but after the election the VVPAT could not be read.  

Other DRE devices could be modified to store votes incorrectly, but print them on the VVPAT correctly (for example, a voter’s choice of John Adams results in the VVPAT printing “John Adams” but the DRE stores the vote as a vote for “Thomas Jefferson”).  

Documentation Review  

The NASED “qualification” (certification) of all systems was based on testing lab (“ITA”) studies that were seriously flawed. While the ITA reports varied significantly, generally it was not possible to ascertain whether the lab had conducted the independent tests needed to determine VS satisfaction of FEC 2002 standards.

Next Page  1  |  2  |  3  |  4  |  5  |  6  |  7  |  8

 

In 2004, Rady Ananda joined the growing community of (more...)
 

The views expressed in this article are the sole responsibility of the author
and do not necessarily reflect those of this website or its editors.

Contact Author Contact Editor View Authors' Articles

 

Book Recommendations for "Bibliography California"
California Impressionists
by Susan Landauer

$24.95
Lowest New Price $15.65

Number of pages: 104
Publisher: University of California Press

California Local History; A Bibliography and Union List of Library Holdings,
by Margaret Miller Rocq

$65.00
Lowest New Price $155.45

Number of pages: 628
Publisher: Stanford Univ Pr

NORTHERN CALIFORNIA ART: AN INTERPRETIVE BIBLIOGRAPHY TO 1915. With Additions and Bibliographical Research by Ellen Schwartz.
by Joseph Armstrong, Jr. Baird

$50.00

Number of pages:
Publisher: Library Associates, Univ. Library, Univ. of California, Davis,

View All Book Recommendations

Share this page: (what's this?)                   Tell a Friend: Tell A Friend

FACEBOOK      DIGG THIS      Add This Page to Mr Wong!           NEWSVINE      DEl.ICIO.US      Looksmart Furl      NETSCAPE      My Web      Tag!RawSugar      Blink List     (More...)

Comments: Expand   Shrink   Hide  
5 comments
To view all comments:
Expand Comments
 

Excellent article! - One More Vulnerability to Mention by Runner on Tuesday, Dec 11, 2007 at 10:43:46 AM
Got citations? by Rady Ananda on Tuesday, Dec 11, 2007 at 1:30:15 PM
If voting could change things - they'd make it illegal. by Mr M on Tuesday, Dec 11, 2007 at 12:11:57 PM
BTW by Mr M on Tuesday, Dec 11, 2007 at 12:15:49 PM
thanks for the kudos by Rady Ananda on Tuesday, Dec 11, 2007 at 2:10:30 PM

 
Want to post your own comment on this Article? Post Comment


 

 

 

Tell a Friend: Tell A Friend

Copyright © 2002-2009, OpEdNews

Powered by Populum