UC Scientists Release Voting Machine Hacking Video
Belief:
Why I Want to Turn Religious People Into Atheists
Greta Christina
Corporate Accountability and WorkPlace:
4 Myths About Taxes, Debunked
Paul Buchheit
DrugReporter:
The War on Weed: Marijuana Is Basically Harmless -- The Monumentally Stupid Drug War Is Not
Jim Hightower
Environment:
White House Garden Won't Make Up for Obama's Nomination of Pesticide Lobbyist for US Chief Agriculture Negotiator
Jill Richardson
Food:
Don't Be Scared of Food: Are We Being Needlessly Hysterical About Food Safety?
David E. Gumpert
Health and Wellness:
47,000 Women Could Die As a Result of the New Mammogram Guidelines
George Lakoff
Immigration:
Hate Group, FAIR, Is Looking for "Ethnically Ambiguous" Actors to Amplify Its Racism
Adam Luna
Media and Technology:
The Memory Scrub About Why Ft. Hood Happened Is Almost Complete ... If It Weren't for Archives
Mark Ames
Movie Mix:
The Yes Men: Pranksters Out to Fix the World
Mark Engler
Politics:
White House's Ties to Health Care Industry Deeper Than Visitor Records Show
Daniela Perdomo
Reproductive Justice and Gender:
Why Can't We Look Away From Sarah Palin?
Vanessa Richmond
Rights and Liberties:
Citing "National Defense Needs," Obama Administration Says it Won't Sign Ban on Land Mines
Amy Goodman
Sex and Relationships:
Hot Mormon Muffins and Models for Jesus: What's With All the Sexy Christians?
Liz Langley
Take Action:
G-20 Meetings: Nothing Much Happened in the Suites, and There Was Too Much Punch in the Streets
Laura Flanders
Water:
Poseidon's Financial Shell Game: Why Is a Private Desalination Plant Asking for Public Money?
Peter Gleick
World:
Is Obama Following in the Footsteps of Bill Clinton?
Jeff Cohen
The Computer Security Group at the University of California Santa Barbara (UCSB) has released a short, chilling video demonstrating how a single person can hack an election on a touch-screen voting system -- even one with a so-called "Voter Verifiable Paper Trail" (VVPAT) added to it -- in such a way that it is highly unlikely that the manipulation would ever be detected by either the public or election officials.The UCSB Security Group page notes that electronic voting systems are exceedingly vulnerable to malicious manipulation of the type demonstrated in their video.
The video, which shows "just examples of the different ways in which the system can be compromised" is the latest in a similar string of such demonstrations that have been released over the last two years, all showing how easily electronic voting systems can be tampered with, often undetectably.
In the UCSB video posted below, the hack of Sequoia voting system being prepared for use in an entire county, is done in approximately 3 seconds, by a single person with simple insider access and a $10 USB thumb drive. Every machine used in the county, in such a case, would be effected. Moreover, the viral hack would not be discovered by pre-election "Logic and Accuracy" testing -- in cases were election officials actually bother to perform such tests prior to elections -- nor would it likely be discovered even in the event of a complete, 100% post-election audit of the touch-screen "paper-trail" records.
The hack demonstration, prepared by the UCSB scientists as part of California's 2007 "Top-to-Bottom Review" of all of the state's e-voting systems, also reveals how so-called "security seals" placed on such machines after they've been programmed for an election, can be easily defeated without detection ...
How and Why It Was Done
The landmark California study, which employed dozens of the world's top computer scientists and security experts, was commissioned by Sec. of State Debra Bowen. The first-of-its-kind, independent state analysis, included hack tests -- so-called, "Red Team" attacks -- to analyze the security of the e-voting systems. All of the systems studied were easily defeated by the testers.
The UCSB group was in charge of the analysis of voting machines made by Sequoia Voting Systems.
The methods used in the hack of a Sequoia Edge direct recording electronic (DRE, touch-screen) system -- a system which includes the Sequoia Verivote paper-trail printer, as seen in the video -- were original described in the Red Team security analysis [PDF] of the Sequoia systems as published by the Secretary of State.
The video demonstrating the voting system manipulation was prepared at the same time, but had not been released publicly until now. The scientists involved in the tests declined to speak on the record as to their reasons for releasing it at this time.
"We found a number of major flaws that can be exploited to compromise the integrity, confidentiality, and availability of the voting process," explains the UCSB website where the video was released. "In particular, we developed a virus-like software that can spread across the voting system, modifying the firmware of the voting machines."
The page goes on to explain that "The modified firmware is able to steal votes even in the presence of a Voter-Verified Paper Audit Trail (VVPAT)." In addition to the hack of the paper-trail touch-screen system, the UCSB scientists also demonstrate, in the video, how the Sequoia Edge touch-screen voting system may be accessed and manipulated even after so-called "security seals" have been applied to the machine following pre-election programming. The members of the team in the demonstration are seen access the system, while the plastic "security seals" are remain undisturbed in the process.
"Security seals" of this type, as used in California and elsewhere -- seen being easily defeated in the video -- have been cited by election officials and voting machine companies alike as key to the secure use of electronic voting machines such as the one seen being hacked in the video above.
E-Voting "Fatally Flawed"
"The video shows how one can use a simple USB key to infect the laptop used to prepare the cards that initialize the various voting devices. As a result, the cards are loaded with a malicious software component," UCSB explains."When a card is inserted in a voting terminal, the malicious software exploits a vulnerability in the terminal loading procedure and installs a modified firmware, effectively 'brainwashing' the terminal. Later, when the terminal is used by the voters to cast their votes, the firmware uses a number of different techniques to modify the contents of the ballots being cast."
"A number of recent studies have shown that most (if not all) of the electronic voting systems being used today are fatally flawed, and that their quality does not match the importance of the task that they are supposed to carry out."The Latest of Many Such E-Vote Hack Demonstrations
See more stories tagged with: fraud, voting rights
Liked this story? Get top stories in your inbox each week from AlterNet! Sign up now »
You've chosen to turn comments off for the entire site. Would you like to turn them back on?
Support AlterNet
Do you value the information you're getting from AlterNet? Please show your support with a tax-deductible donation.
Feedback
Tell us how we're doing.