Home
Refresh   Tag(s): ; ; ; ; ; ; ; ; ; ; (more...) ; ; ; ; ;  (less...)
Add to My Group
December 10, 2007 at 16:08:24

View Ratings | Rate It

2007 Technology Tests of Computerized Voting Systems

submit to twitter
submit to reddit
submit to digg

Tell A Friend

By Rady Ananda (about the author)     Page 6 of 8 page(s)

opednews.com     Permalink

If the authentication key necessary to validate voter cards is the same across precincts, as we understand to be common practice in Florida, these cards could easily be modified to be used at any other precinct within a county. 

Data and smart card passwords can now be set by election workers. The authentication protocol is not secure, allowing an attacker to create counterfeit, validating smart cards, including voter cards. 

There is no integrity protection of stored electronic ballots and ballots are stored sequentially.  This defeats voter privacy by allowing a voter’s selections to be tied to a voter’s name. 

Audit logs are not cryptographically protected and data transmitted over communication lines is neither authenticated nor encrypted. 

A custom, malicious bootloader is possible if the terminal is delivered to a polling place in “debug mode.”  If not in debug mode, an attacker can open the case and move a hardware switch to enable this attack.    An attacker can hide preloaded votes on a forged memory card that the terminal will recognize. 

FLORIDA: Software Review and Security Analysis of the Diebold Voting Machine Software Supplemental Report, Security and Assurance in Information Technology (SAIT) Laboratory Florida State University, August 2007.  

This report reflects the narrow investigative scope requested by FLDoS (Florida Department of State). These results are not comprehensive in any sense, nor is this report an endorsement of the system’s overall security. We examined only a small subset of the flaws from the SAIT Diebold Report.

All other flaws identified in that report remain in the code base, including vulnerability to a sleepover attack that may allow an intruder to manipulate vote computation or worse.

Significant, critical vulnerability remains in this code base independent of repairs documented in this report. 

Until voting systems are developed for “high assurance”, election officials face an unnecessarily high risk and must exercise significantly expanded election security procedures to mitigate known and unknown software vulnerability. 

The signature flaw was fixed.  This makes it much more difficult for preloaded votes to be hidden. 

(Note: Other flaws reported to have been fixed were not detailed above. ~ RA)  

KENTUCKY 2007 Voting Expert Letter to KY Attorney General, public version posted at Review of Diebold/Premier, Hart InterCivic, and ES&S. 

The review relies on the completeness and accuracy of the testing by the Independent Testing Authorities (ITA) for conformance to voluntary Federal guidelines (Voting systems Standards 2002). However, it has been well established that the ITAs do not adequately perform this role. 

The ITA reports used for Federal certification and included in the review packages used by the SBE certifiers are cursory…. (as) reinforced by the fact that none of the ITAs identified the flaws found by the California or Florida source code review teams. 

Because the ITA reports are of limited value, the quality examination of the machines as part of the certification processes is crucial, but it too can best be described as cursory. 

Next Page  1  |  2  |  3  |  4  |  5  |  6  |  7  |  8

 

In 2004, Rady Ananda joined the growing community of (more...)
 

The views expressed in this article are the sole responsibility of the author
and do not necessarily reflect those of this website or its editors.

Contact Author Contact Editor View Authors' Articles

 

Book Recommendations for "Bibliography California"
California Impressionists
by Susan Landauer

$24.95
Lowest New Price $15.87

Number of pages: 104
Publisher: University of California Press

California Local History; A Bibliography and Union List of Library Holdings,
by Margaret Miller Rocq

$65.00
Lowest New Price $155.45

Number of pages: 628
Publisher: Stanford Univ Pr

NORTHERN CALIFORNIA ART: AN INTERPRETIVE BIBLIOGRAPHY TO 1915. With Additions and Bibliographical Research by Ellen Schwartz.
by Joseph Armstrong, Jr. Baird

$50.00

Number of pages:
Publisher: Library Associates, Univ. Library, Univ. of California, Davis,

View All Book Recommendations

Share this page: (what's this?)                   Tell a Friend: Tell A Friend

FACEBOOK      DIGG THIS      Add This Page to Mr Wong!           NEWSVINE      DEl.ICIO.US      Looksmart Furl      NETSCAPE      My Web      Tag!RawSugar      Blink List     (More...)

Comments: Expand   Shrink   Hide  
5 comments
To view all comments:
Expand Comments
 

Excellent article! - One More Vulnerability to Mention by Runner on Tuesday, Dec 11, 2007 at 10:43:46 AM
Got citations? by Rady Ananda on Tuesday, Dec 11, 2007 at 1:30:15 PM
If voting could change things - they'd make it illegal. by Mr M on Tuesday, Dec 11, 2007 at 12:11:57 PM
BTW by Mr M on Tuesday, Dec 11, 2007 at 12:15:49 PM
thanks for the kudos by Rady Ananda on Tuesday, Dec 11, 2007 at 2:10:30 PM

 
Want to post your own comment on this Article? Post Comment


 

 

 

Tell a Friend: Tell A Friend

Copyright © 2002-2009, OpEdNews

Powered by Populum