NEWS & POLITICS  
comments_image -

The Latest Spin From Voting Machine Makers: What Problems?

At a Texas legislative hearing, manufacturers say scientists who studied their machines were not looking at "real world" issues.
 
 
LIKE THIS ARTICLE ?
Join our mailing list:

Sign up to stay up to date on the latest News & Politics headlines via email.

 
 
 
 

Last week, I testified before the Texas House Committee on Elections (you can read my testimony). I've done this many times before, but I figured this time would be different. This time, I was armed with the research from the California "Top to Bottom" reports and the Ohio EVEREST reports. I was part of the Hart InterCivic source code team for California's analysis. I knew the problems. I was prepared to discuss them at length. Wow, was I disappointed. Here's a quote from Peter Lichtenheld, speaking on behalf of Hart InterCivic:

Security reviews of the Hart system as tested in California, Colorado, and Ohio were conducted by people who were given unfettered access to code, equipment, tools and time and they had no threat model. While this may provide some information about system architecture in a way that casts light on questions of security, it should not be mistaken for a realistic approximation of what happens in an election environment. In a realistic election environment, the technology is enhanced by elections professionals and procedures, and those professionals safeguard equipment and passwords, and physical barriers are there to inhibit tampering. Additionally, jurisdiction ballot count, audit, and reconciliation processes safeguard against voter fraud.
You can find the whole hearing online (via RealAudio streaming), where you will hear the Diebold/Premier representative, as well as David Beirne, the director of their trade organization, saying essentially the same thing. Since this seems to be the voting system vendors' party line, let's spend some time analyzing it.

Did our work cast light on questions of security? Our work found a wide variety of flaws, most notably the possibility of "viral" attacks, where a single corrupted voting machine could spread that corruption, as part of regular processes and procedures, to every other voting system. In effect, one attacker, corrupting one machine, could arrange for every voting system in the county to be corrupt in the subsequent election. That's a big deal. At this point, the scientific evidence is in, it's overwhelming, and it's indisputable. The current generation of DRE voting systems have a wide variety of dangerous security flaws. There's simply no justification for the vendors to be making excuses or otherwise downplaying the clear scientific consensus on the quality of their products.

Were we given unfettered access? The big difference between what we had and what an attacker might have is that we had some (but not nearly all) source code to the system. An attacker who arranged for some equipment to "fall off the back of a truck" would be able to extract all of the software, in binary form, and then would need to go through a tedious process of reverse engineering before reaching parity with the access we had. The lack of source code has demonstrably failed to do much to slow down attackers who find holes in other commercial software products. Debugging and decompilation tools are really quite sophisticated these days. All this means is that an attacker would need additional time to do the same work that we did.

Did we have a threat model? Absolutely! See chapter three of our report, conveniently titled "Threat Model." The different teams working on the top to bottom report collaborated together to draft this chapter. It talks about attackers' goals, levels of access, and different variations on how sophisticated an attacker might be. It is hard to accept that the vendors can get away with claiming that the reports did not have a threat model, when a simple check of the table of contents of the reports disproves their claim.

Was our work a "realistic approximation" of what happens in a real election? When the vendors call our work "unrealistic", they usually mean one of two things:

submit to reddit

-
Email
Print
Share
LIKED THIS ARTICLE? JOIN OUR EMAIL LIST
Stay up to date with the latest News & Politics headlines via email
See more stories tagged with: security, voting machines, voting rights
Advertisement
Most Read
Most Emailed
Most Discussed
On REDDIT
On DIGG
 
loading most read content ..
Advertisement
Fox, Breitbart, and Ricketts Try to Bring Back D'Souza's Pseudo-Birtherism

By Steve M | No More Mister Nice Blog

 
 
Activists Speak Out Against Lack of Access to Bradley Manning

By Agence France Presse

 
 
NYPD Catches Sexual Assailant, Then Lets Him Go Free Because He Didn't Feel Like Being Questioned

By Jill F | Feministe

 
 
Gov. Scott Orders Purging of Florida’s Voter Rolls - Just in Time For Prez Election

By Adele Stan | Washington Monthly

 
 
Abortion Clinics Across Country Put On Alert In Wake of Georgia Clinic Arson Cases

By Robin Marty | RH Reality Check

 
 
Former GOP Congresswoman Blasts New GOP Women’s Caucus: ‘They’re Not Voting In Best Interest Of All Women’

By Josh Israel | ThinkProgress

 
 
Debbie Wasserman Schulz is Wrong on Wisconsin

By LaFeminista | DailyKos

 
 
Pro-Coal Group Pays People to Wear Its Shirts at EPA Hearing

By Heather Moyer | Sierra Club

 
 
Kids Inundate NY Governor With Concerns About Fracking

By Seth Gladstone | Food and Water Watch

 
 
Shareholders, Top Doctors Demand McDonald's Assess its Health Impacts

By Sara Deon | Civil Eats

 
 
 
 
 
loading ...
POWERED BY DIGG'S USERS
 
[ page served from web 1 ]