Home
Archive
Newsletters
Video
Blogs
Discuss
About
Search
Donate
Advertise
  • AlterNetYour turn

Support AlterNet
Do you value the information you're getting from AlterNet? Please show your support with a tax-deductible donation.


Feedback
Tell us how we're doing.

Advertisement
Advertisement

Step by Step Guide to Hacking Electronic Voting Machines

Posted by Brad Friedman, Brad Blog at 9:10 AM on September 10, 2008.


UC computer scientists release video on how to hack a sequoia touch-screen voting machine.

Share and save this post:

      

      

Share on Facebook       

AlterNet Social Networks:
follow us on twitter
find us on Facebook

Got a tip for a post?:
Email us | Anonymous form

Get Video in your
mailbox!

 


The Computer Security Group at the University of California Santa Barbara (UCSB) has released a short, chilling video demonstrating how a single person can hack an election on a touch-screen voting system --- even one with a so-called "Voter Verifiable Paper Trail" (VVPAT) added to it --- in such a way that it is highly unlikely that the manipulation would ever be detected by either the public or election officials.


The video which shows "just examples of the different ways in which the system can be compromised" is the latest in a similar string of such demonstrations that have been released over the last two years, all showing how easily electronic voting systems can be tampered with, often undetectably.


In the UCSB video posted below, the hack of Sequoia voting system being prepared for use in an entire county, is done in approximately 3 seconds, by a single person with simple insider access and a $10 USB thumb drive. Every machine used in the county, in such a case, would be effected. Moreover, the viral hack would not be discovered by pre-election "Logic and Accuracy" testing --- in cases were election officials actually bother to perform such tests prior to elections --- nor would it likely be discovered even in the event of a complete, 100% post-election audit of the touch-screen "paper-trail" records.


The hack demonstration, prepared by the UCSB scientists as part of California's 2007 "Top-to-Bottom Review" of all of the state's e-voting systems, also reveals how so-called "security seals" placed on such machines after they've been programmed for an election, can be easily defeated without detection...
























How and Why It Was Done...


The landmark California study, which employed dozens of the world's top computer scientists and security experts, was commissioned by Sec. of State Debra Bowen. The first-of-its-kind, independent state analysis, included hack tests --- so-called, "Red Team" attacks --- to analyze the security of the e-voting systems. All of the systems studied were easily defeated by the testers.


The UCSB group was in charge of the analysis of voting machines made by Sequoia Voting Systems.


The methods used in the hack of a Sequoia Edge direct recording electronic (DRE, touch-screen) system --- a system which includes the Sequoia Verivote paper-trail printer, as seen in the video --- were original described in the Red Team security analysis [PDF] of the Sequoia systems as published by the Secretary of State.


The video demonstrating the voting system manipulation was prepared at the same time, but had not been released publicly until now. The scientists involved in the tests declined to speak on the record as to their reasons for releasing it at this time.


"We found a number of major flaws that can be exploited to compromise the integrity, confidentiality, and availability of the voting process," explains the UCSB website where the video was released. "In particular, we developed a virus-like software that can spread across the voting system, modifying the firmware of the voting machines."


The page goes on to explain that "The modified firmware is able to steal votes even in the presence of a Voter-Verified Paper Audit Trail (VVPAT)."


In addition to the hack of the paper-trail touch-screen system, the UCSB scientists also demonstrate, in the video, how the Sequoia Edge touch-screen voting system may be accessed and manipulated even after so-called "security seals" have been applied to the machine following pre-election programming. The members of the team in the demonstration are seen access the system, while the plastic "security seals" are remain undisturbed in the process.


"Security seals" of this type, as used in California and elsewhere --- seen being easily defeated in the video --- have been cited by election officials and voting machine companies alike as key to the secure use of electronic voting machines such as the one seen being hacked in the video above.


E-Voting "Fatally Flawed"...


"The video shows how one can use a simple USB key to infect the laptop used to prepare the cards that initialize the various voting devices. As a result, the cards are loaded with a malicious software component," UCSB explains.


"When a card is inserted in a voting terminal, the malicious software exploits a vulnerability in the terminal loading procedure and installs a modified firmware, effectively 'brainwashing' the terminal. Later, when the terminal is used by the voters to cast their votes, the firmware uses a number of different techniques to modify the contents of the ballots being cast"


The UCSB Security Group page notes that electronic voting systems are exceedingly vulnerable to malicious manipulation of the type demonstrated in their video.


"While most critical systems are continuously scrutinized and evaluated for safety and correctness, electronic voting systems are not subject to the same level of scrutiny," they write.


"A number of recent studies have shown that most (if not all) of the electronic voting systems being used today are fatally flawed, and that their quality does not match the importance of the task that they are supposed to carry out."


The Latest of Many Such E-Vote Hack Demonstrations...


The Sequoia Edge system seen being hacked in the video above is the same type of system on which The BRAD BLOG had revealed another serious flaw, just days before the 2006 general election. As we reported at the time, a yellow button on the back of each voting machine (as can be seen in the UCSB video as well) can be pressed in such a way as to put the system into "manual mode," allowing for an unlimited number of votes to be cast by a single individual.


The hack demonstration video published by the California academics wouldn't be the first such video to detail exactly how an electronic voting system can be hacked by a single malicious individual. Other notable cases include:





  • A 2006 Princeton University study revealed how to carry out a similar viral attack on a Diebold touch-screen voting systems, resulting in the spread of a vote-flipping virus, that would spread from machine to machine after access to just one of them (DISCLOSURE: The machine used in Princeton's testing was supplied to us by a Diebold insider. We then passed it on to the university for the first such independent study of such a voting system.) Story here, video demo here...






  • While the Princeton scientists also demonstrated how the lock on a Diebold touch-screen system could be opened with either a standard hotel mini-bar key --- or even a paper clip in about 10 seconds time --- another enterprising individual found he was able to fashion a homemade key that would open the Diebold system as well. The key was made after modeling it after a photograph of the key --- the same one is used for every Diebold machine --- as, incredibly enough, posted on the company's website. Story here, video here...






  • A 2006 HBO documentary, Hacking Democracy, showed a paper-based, Diebold optical-scan tabulator being manipulated in a mock election which flipped the results reported by the system. That landmark hack disclosed still-uncorrected security flaws in all Diebold systems (both touch-screen and optical-scan). The exact same Diebold, paper-based tabulators were used in last January's anomalous New Hampshire primary. Video here...



  • A one-minute 2006 hack demonstration of an e-voting system used in the Netherlands, shows how a key chip can be replaced in such a system in just 60-seconds. PDF analysis here, video here...



"Paper-Trails" Are Meaningless...


The UCSB demonstration of the Sequoia Edge with Verivote hack is notable, however, given that many proponents of electronic voting --- including many Democrats and their various public interest group supporters, such as People for the American Way (PFAW), Common Cause, Verified Voting, NYU's Brennan Center for Justice and others --- have argued that adding paper-trails (VVPATs) to such systems would mean that any manipulation of the system would be discovered during an examination of the paper-trails after an election. As the video shows, post-election examinations or audits of touch-screen paper-trail systems hacked in this way, would not easily --- if at all --- reveal the manipulation.


Following Bowen's "Top-to-Bottom Review", touch-screen systems made by Sequoia, Diebold and ES&S were restricted to use of one-per-precinct only, in order to marginally meet the disabled-accessible voting requirements of the federal Help America Vote Act (HAVA). She also required a 100% hand-count of the paper-trails produced by such systems, even though the UCSB team found that such audits would not necessarily catch voting system manipulation. Many states around the country continue to allow unfettered use of such hackable voting systems. None, other than California, require 100% post-election audits.


A similar DRE system made by Hart InterCivic was allowed for full use, almost inexplicably, after the California testing, in two different counties.


Despite the quickly mounting scientific evidence persuading against the use of such systems in American elections, Congressman Rush Holt (D-NJ) and Senator Diane Feinstein (D-CA) have proposed a number of bills which would allow for the continued use of touch-screen voting systems with paper-trails. The Republican caucuses in each chamber have so far stymied all such legislation, even as they argue in favor of the use of all such electronic systems, with or without the often misleading paper-trails.


MORE COVERAGE: See John Byrne at RAW STORY and Rady Ananda at OpEdNews.

Digg!

Tagged as: voting machines, hacking, electronic vote

Brad Friedman writes the BradBlog.


What Sarah Palin's "Jewish people will be flocking to Israel" prediction really means
Palin's associated with a religious tendency whose leaders promote anti-Jewish conspiracy theory
Post by Bruce Wilson. November 21, 2009.
Hmmm ... Why Do So Many Wingnuts Have Such an Obsessive Fear of Being Raped?
It's all they can talk about in the right-wing media.
Post by Staff. November 20, 2009.
Sarah Palin Running for President ... of Facebook?
Ana Marie Cox and Naomi Klein point out that Sarah Palin seems to be campaigning for President. But of what?
Post by AlterNet Staff. November 19, 2009.
Advertisement
Comments Turn comments off sitewide Give us feedback »
Comments closed.
The comments for this story have been closed. Thank you to everyone who participated.
View:
Wow! This is stunning!
Posted by: Xynyx on Sep 10, 2008 10:33 AM   
Current rating: 5    [1 = poor; 5 = excellent]
Now, all I have to do is change my name to "XXXXXX" and I am pretty much guaranteed to become a United States Senator for at least one state. What a return on investment!

But seriously, this is what the paper ballot people have been saying all along. We can't trust the machines, because they can be too easily compromised.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

» VerifiedVoting.org Posted by: fanny666
» RE: VerifiedVoting.org Posted by: BradBlog
Will your vote count?
Posted by: Lauren on Sep 10, 2008 10:54 AM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
WishTV Part One

An I-Team 8 investigation finds serious questions about security and troubling concerns on both how the technology is sold, and who is getting rich on public money.

I think the guys who were really pushing this after the 2000 election knew it was totally hackable. That would have been part of their big plan, wouldn't it?

Isn't investigative reporting a wonderful thing? Thank you, Wish TV, this is great.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

Homeland Stupidity, was the 2004 Election Hacked?
Posted by: Lauren on Sep 10, 2008 11:06 AM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
Was the 2004 Election Hacked?

Diebold delivering the election to Bush? Say it isn’t so! Evidence is mounting that it is, indeed, so.

This report from Common Dreams alleges that the Florida vote was rigged by the misuse of Diebold tabulating machines and shows evidence that the county-by-county vote is inconsistent with exit polls and party registrations only in those counties where Diebold equipment was used.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

I will be
Posted by: Floresta on Sep 10, 2008 11:25 AM   
Current rating: 5    [1 = poor; 5 = excellent]
sending this out to everyone I know!
Thank you researchers at UCSB and elsewhere.
I most certainly do not want the GOP to *win* again...

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

In Addition
Posted by: JSquercia on Sep 10, 2008 11:43 AM   
Current rating: 5    [1 = poor; 5 = excellent]
The Republicans are already deep into their voter suppression attacks with Virginia making noise about Students voting from College Campuses , Florida is resurrecting the idea that a voter must Produce an ID that matches a state data base and just now I heard that a county in Michigan is going to use Foreclosure lists to challenge voters whose homes are in Foreclosure .
This is truly SCAREY . Isn't it IRONIC that the 2000 Election spurred this effort towards Electronic Voting . We should have Paper Ballots and weekend voting .

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

» RE: In Addition Posted by: Lauren
RE: the only way to get things changed is
Posted by: lbrlw13 on Sep 10, 2008 2:11 PM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
I thought happened already in 2000 (lol)!

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

Why Voting machines in the first place?
Posted by: modeler on Sep 10, 2008 2:10 PM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
Is it to hard to count? Paper ballots are evidence and cheating can easily be proven. But then the makers of those gizmos are mainly stout Repugnicans. If they cant get votes honestly they can always use their chiseling product.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

So this is what it comes down to
Posted by: QQOblivion on Sep 10, 2008 2:53 PM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
So this is what the election will come down to.
Which side can hack the most votes. That's it.
Do Obama's people already have someone working on this? You know the McCain campaign does.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

Lacking common sense
Posted by: curiousone on Sep 11, 2008 4:59 AM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
I wonder if these so called intellectuals would publish the way to hack the Pentagon computers if they figured out how. Or maybe the Passport office computer systems. Wow what a way to make an already unfair election a total joke!

I find it hard to believe that a group of people, with such an education, could be without the common sense to realize when they have helped "screwed the pooch". It is one thing to hack the computers and publicize the issue. It is entirely another to give anyone the information required to actually do it. I wonder if these hacks are aquainted with the concept of NATIONAL SECURITY!

I am curious why common sense is something that does not seem to exist in the US.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

Paper trail to take home to check on the internet
Posted by: jreal on Sep 11, 2008 9:15 AM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
There should be a paper trail to take home with your vote and a chronological code (not your actual name) that you can check on the internet.

Just type in your city, state, and find your number code to see if your results match your paper.

There should be an alphabetical listing of all the people who did vote on another page (that adds up the same as the chronological order) so that people can see if someone is on there that probably shouldn't be, and leaves open for community investigation (Not anyone may be able to check every single person, but many people will know about people within their circles and a little bit beyond). (This page won't show whom, or what they voted for).

Some people may be worried about privacy. All you have to do is say you lost the paper if intimidated. Besides, we're not even living in a democracy anymore anyways.

Do we all want to be in a Democracy or not.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

only honest election is a "raise hands" election
Posted by: billwald on Sep 11, 2008 11:41 AM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
There will never be an honest election of 50 million voters. Only way is for people to put their names where their mouth is.

First, post all county voter lists on the web. This way anyone can check for dead people and whomever.

Second post all votes with names and addresses in spread sheet format. Every person can check his own vote. Every person can make his own tally.

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

ONE SECOND...!
Posted by: Ahimsa on Sep 12, 2008 2:42 PM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
Why is this not repeated incessantly in the news?
At least in the less right-wing ones?
This is the single most important issue of all!
Why election and candidates and messages and lies...?
If it is all decided already...

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]

RECEIPT
Posted by: Ahimsa on Sep 12, 2008 2:45 PM   
Current rating: Not yet rated    [1 = poor; 5 = excellent]
When we make a purchase and we don't get a receipt, the retailer can get in trouble. Since we treat elections as consumers, then it makes sense to demand a receipt for our transaction, the most important one in this business of (pseudo) democracy.
Hey, does this smell like legal action? Can we citizens sue?
No, seriously...

[« Reply to this comment] [Post a new comment »] [Rate this comment: 1 - 2 - 3 - 4 - 5]