14 ms·
Cylance Discloses Voting Machine Vulnerability
- Shank 10y agoI worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn't pictured is the physical security performed with them. Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the election, and no voter was ever permitted in the back of the access panel where the firmware update would take place. Before the machine starts, it gives a "zero" report which is verified independently by poll watchers, and confirms candidate choices are in place as needed. When the polls are closed, we seal everything again before the machines are sent back for reporting (at which point the seals are checked and verified prior to dumping results). If this was really a damaging hack, the protective counter & live counters would show different numbers than what the machine read, but that didn't happen. It very clearly was tampered with, which means these physical measures would counteract any unwanted firmware updates during an election. It's preposterous to think that election judges aren't actively verifying seals during election day and making sure nobody is tampering with them.
- helthanatos 10y agoBut you're assuming that all the officicials dealing with the machines have the same moral standards as you. It's not necessarily the voters that need to be watched...
- Shank 10y agoAt least in Arapahoe County, everything we did was in pairs of republicans and democrats, to ensure that it was a fair election as far as we could. This included seal checking, logging the zero counts, etc. Everything had a paper audit trail for who interacted with what, who signed off on what, and what was going on. I don't know how it worked when the machines were picked up for counting, but I assume similar measures were in place. Edit: Also, poll watchers from both parties could observe our methods. Everyone had a vested interest in verifying that no tampering was taking place, even if that didn't include election workers.
- wfunction 10y ago> everything we did was in pairs of republicans and democrats Question: What constitutes a Democrat or a Republican? Is registering as one enough? What guarantee is there people aren't lying about the parties they identify with?
- oxide 10y agothat's a risk you have to take, at some point. you eventually have to trust that someone isn't lying, somewhere along the chain. what else could be done to further vet volunteers? you can't interrogate people or drug them with serums for the truth, so I think it's safe to assume registering is enough. so, to answer your question, I doubt there is any "guarantee" other than the fact that these are volunteers and you'd have to be a real idiot to falsely register to ensure you can tilt the scales...of bipartisan pairs of Arapahoe County poll volunteers.
- wfunction 10y ago> that's a risk you have to take Well, obviously. But the risk can be high or low, right? You could either let any random voter you don't know walk in and become a volunteer after filling out a form, or you could let maybe ~50 people that the party's head/nominee personally trust pick a set of volunteers nationally based on e.g. personal knowledge or some concrete evidences of their past contributions and allegiance to the party. Or something else; there are lots of possibilities here. So I'm asking what the criteria are so I can understand how likely it is for something to go wrong here... I obviously understand nothing 100% bulletproof, so there's no need to point that out.
- oxide 10y agolet's take this a step further: two republicans, one falsely registered as a democrat, have been paired off at the polling station in Araphaoe County. the lie was bought, the fraud complete. now what?
- 10y ago
- wybiral 10y agoOfficials are more likely to be skilled at hacking paper than electronic devices :)
- pmoriarty 10y agoI'd feel a million times more confident in a simple pen and paper voting system.
- motardo 10y agoYes. With paper ballots, cheating is at least detectable because there is literally a paper trail. With touch screens, maybe the results are correct, maybe the machine miscounted. There is no way to really know.
- wybiral 10y agoThere are digital records more than just a tally. Sure, maybe it's possible (with physical access) to destroyed or altered them, but the same holds for paper.
- pmoriarty 10y agoIt's much harder to undetectably destroy or alter large numbers of paper records than it is to do the same to digital records. It's also sometimes possible to do this to digital records without ever being physically present in their vicinity. Once again, this is much harder with paper.
- nitrogen 10y agoIt's very easy to forge paper records, though. I seem to recall reading about a rigged election in a questionable democracy where the ballot counters were given several file boxes full of fake ballots in addition to their local precinct ballots, with official anti-tampering seals intact.
- im3w1l 10y agoSo now you need a distribution network for fake boxes and people in the precincts that are in on the conspiracy. Such a large org is leak-prone. Contrast that with a group of just 1-3 techies.
- wybiral 10y agoExactly. You could tamper with most systems if you had that much physical access, including paper counts. Which is why there are procedures in place to minimize that potential. Plus an attack like this would be isolated to the single machine (not that it wouldn't be bad, but it wouldn't be applied in a distributed fashion).
- makomk 10y agoWith paper counts, it's easy to verify that the box is empty when it's initially sealed. With voting machines not so much.
- revelation 10y agoThe machines are sent back to a central point, without getting a report at the individual polling stations? I think I see the problem.
- Shank 10y agoResults were printed out from the machines and posted outside the actual vote center after the election (Colorado law requires publishing the results of all electronic votes). If you were to visit a vote center after the polls closed, you'd see a tally report per machine on the window, visible for anyone to see. The machines themselves were sent back and dumped. I don't actually remember if we printed 2 copies of everything (such as a copy for someone to tally up too).
- azernik 10y agoIn CA (Alameda County), we print out two copies - one to be posted publicly, and one to be returned to the central collection center. The collection center gets the paper printout of results, the memory card, and a printout of the system logs.
- gergles 10y ago> It's preposterous to think that election judges aren't actively verifying seals during election day and making sure nobody is tampering with them. I've been an election worker around the country and have never been in a jurisdiction that did seal checks during the election - only once at the beginning and once at the end. Granted, I've never been in a jurisdiction using DREs, but still. I agree physical security is a defense here, but this just reiterates, to me, how dangerous DRE voting machines are.
- Shank 10y agoI have no experience with non-DRE seal checking. Our seals had the machine serial numbers on them, with watermarks, etc. If a seal was mysteriously broken, it was in our best interest to take it out of service anyway, because suddenly the legitimate votes on that machine come into question.
- azernik 10y agoIn Alameda County, CA we use what look superficially to be the same machines, and have similar physical security measures - there are seals on all access points (e.g. on the cover protecting the power switch), and whenever we access one of them we save the seal's tag, log its ID, and log the ID of the replacement. At the end of the day you end up with basically a series of tags on a form that show chain of custody (the two people - always more than one - that handle the machine with a seal removed have to sign off on each change of tag). EDIT: Note that we use these machines with an optional paper-printout add-on, and they're a non-default option mostly used to increase ballot accessibility - most people vote on paper ballots that are fed into a scanner on-site, so the scanner results can be cross-checked against the physical ballots in case of a disputed result.
- scoot 10y agoSo someone could spoil all the votes by breaking the seals?
- 10y ago
- slim 10y agoYou mean I could void all the votes simply by tampering with the seal? Seams like an easy attack
- Shank 10y agoThe answer to many physical security questions is "it depends." I don't have my materials on me anymore, but in general, seal tampering means a lot of extra scrutiny on the people watching the machines and transporting them. The chain of custody will pin the blame on the last person who signed off, and things get investigated as needed. The system doesn't have something in place typically that says "if (sealVoided) { throw out election }" it just means that additional precautions are taken to ensure everything is good. It's never a binary answer, unfortunately.
- sschueller 10y agoI think that is correct. If the seal is broken you can not guarantee that the votes are correct especially if there is no paper trail. So for maximum impact make sure you go break the seal at the end of the day... How many votes are stored on a single machine in a large district?
- Mtinie 10y agoInternally applied seals would be one form of defense against this vector. Breaking the external seals would put the device into the "needs further investigation" category. After the election the device would be inspected and the internal seals confirmed. If those were still intact, the results from the machine could be certified.
- deleted 10y ago[deleted]
- mixologic 10y agoWhat happens if they find tampering of the seals? Does all the votes of that particular machine become questionable? If someone were to tamper with the seals on many of the machines, and they target precincts that tilt heavily in favor of one party or the other, couldn't they theoretically invalidate a lot of ballots that are likely to help their opponents?
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- tropo 10y agoSuppose the election ends, and it's time to verify the seals. Oops, they are broken. Now what? All the seals can do is cast doubt on the results. You can't bring back the voters to try again. Even if you could, time has passed and they might vote differently. You could toss out the results, but that affects things too. If you toss out the results, an example attack is: break the seals in areas with undesired voters Similar attacks can be done if you call voters back. Maybe this allows for more-favorable hours or different media exposure.
- godelski 10y agoReally what it seems is that we need more audits on machines. If democracy is to be a pivotal part of our election process we need to release the source code of these machines to ensure that we find and solve problems.
- seanwilson 10y agoSeems like a decent place to apply formal verification as well to show the machines are bug free. Voting machines are critically high impact if they have bugs and (famous last words) the complexity of the software seems low.
- kijin 10y agoThe counting app itself might be low-complexity, but I'm pretty sure the app runs on some kind of off-the-shelf OS with hundreds of millions of lines of code and at least a few known vulnerabilities. A somewhat outdated version of Windows is a common choice, as is some random non-LTS version of Ubuntu. I don't think OpenBSD is particularly popular among self-serve kiosk manufacturers.
- DSMan195276 10y agoI think it's worth adding that if it doesn't use some off-the-shelf OS, then the complexity of the software just jumped a few levels because you're talking about writing a lot more lower-level components to make it work. Using an off-the-shelf OS is almost definitely the better way to go unless there's some obvious reason that it won't work (Like architecture issues). I would also add that the choice of OS matters a lot less then configuration - If you do your configuration carefully and strip down the active components in the system, then you can make any of them secure enough for this task. And if you do a poor job of it, then even OpenBSD isn't going to save you. That said, while I do agree the voting software should be open-source in principle, I'm not really as concerned with hackable bugs in that software that can only be exploited through physical means. If they have physical access to the machine like in this video then you're already shot - ideally you have preventive measures that will make it obvious when physical access has occurred. If you don't physically secure the machine, then it doesn't really matter how good the code is.
- top_post 10y ago"The decision to announce the research findings was intended to encourage increased sales and revenue for Q4 2016."
- rsobers 10y agoUgh.
- code_duck 10y agonot sure are aware, but the actual quote is "The decision to announce the research findings was intended to encourage remediation of the vulnerabilities prior to Election Day".
- campuscodi 10y ago3 days before the election.... sure it was...
- code_duck 10y agoIt doesn't seem likely they were seeking contracts or revenue at this time either. Perhaps making a political statement?
- alexandercrohde 10y agoI think it's high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility. Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I'd perhaps start at https://www.verifiedvoting.org/ https://www.verifiedvoting.org/
- grzm 10y agoverifiedvoting.org looks like a good resource for taking action. If you're interested in learning more about verifiable/auditable voting systems, Wikipedia has some useful references: https://en.wikipedia.org/wiki/End-to-end_auditable_voting_systems https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy... I also found this slide deck from Ron Rivest interesting: Auditability and Verifiability of Elections ACM-IEEE talk March 16, 2016 https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf
- empath75 10y agoThey don't even need to throw the election. Two or three machines with absurd results in favor of Clinton or Trump would be enough to push the county into civil unrest.
- code_duck 10y agobut so far the country as a whole has shown almost no interest in the insecurity of electronic voting machines.
- Pinckney 10y agoAbsurd results aren't what you want, since they're readily dismissed as localized, and people could believe that hacking had no effect on the overall result. You want to prove that hacking took place, but subtly, so that people can imagine it was widespread. More effective would be to preselect a precise number of votes for a few machines in a swing state, with totals just 3-4 percentage points higher than what polling indicates for that precinct. Email a few journalists before the election: "I'm a engineer working to hack the election for Clinton, but I'm sickened by it and I want to blow the whistle... attached are encrypted tallies for the voting machines we compromised in precinct XXX. I know we have a team in YYY and I think in ZZZ, but I wasn't able to get data for those machines out. Decryption keys will follow Nov 15th."
- seanwilson 10y agoIs there any way you can prevent hacks like this that require physical access? I guess cryptographically signing the updates, adding tamper proof seals and requiring multiple people to approve updates would help. The general mantra however is that once a hacker has physical access to your machine all bets are off. Also, what happens if there's a random hardware/software glitch where incrementing one vote actually increments 10 votes? Is this checked for? How much reliance is there on the software and hardware being error free?
- Shank 10y agoWe definitely have seals, but for technical solutions, look at how Apple secures their devices. Signed firmware updates, public key crypto, and a well thought chain of trust solve these issues. The problem is that the actual poll creation is done on a per county basis. I don't know how you would do this in such a way that every random county an precinct in America could have signing keys, firmware updates, etc., just sitting around ready to roll to build elections with.
- TACIXAT 10y agoSign the firmware and include that data as a configuration file.
- seanwilson 10y ago> The problem is that the actual poll creation is done on a per county basis. I don't know how you would do this in such a way that every random county an precinct in America could have signing keys, firmware updates, etc., just sitting around ready to roll to build elections with. You mean creating and distributing the keys would be problematic if every county had their own keys? Are there any practical solutions to this? Couldn't you only have a few keys that are used for many counties and updates should be verified and signed by multiple people? Each county could still verify the contents of the update was correct (e.g. correct names on the ballot).
- empath75 10y agoThe real problem is that the people buying and making these systems don't really care about security, either out of incompetence or malice.
- mpweiher 10y agoI really don't see what problem these machines are solving, except for "as an operative, I would like additional vectors to manipulate the election". In Germany, we get (a) a paper ballot (b) a pen Works perfectly. And quickly.
- rblatz 10y agoHow are the paper votes tabulated? If it's by machine you've just kicked the can further down the road.
- mpweiher 10y agoBy hand.
- jackweirdy 10y agoSame in the UK. Anyone who can vote can also take part in "The Count", where groups of volunteers count the votes in regional centres.
- chipperyman573 10y agoWouldn't that be easy to spoof numbers? Getting a few hundred people to add 10 or 15 to a candidate in a swing state could make a huge difference.
- valleyer 10y agoGetting a few hundred people to do anything without it leaking is hard. Plus, the paper records are retained, so a recount could specifically identify the culprits.
- tajen 10y agoThere are 3 volunteers to tell, write and cross-check the paper ballot; and it's a public audience, meaning that there are a bunch of witnesses, including families who want to teach kids why the votes can be trusted, and party representatives who want to check that the election is not tampered with. It's hard to cheat when so many people can testify.
- jakeogh 10y agoWhy Electronic Voting is a BAD Idea - Computerphile: https://www.youtube.com/watch?v=w3_0x6oaDmI https://www.youtube.com/watch?v=w3_0x6oaDmI
- peterarmstrong 10y agoDear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot can be counted, as many times as needed. And since the thing which is counted is the same physical thing which can be audited, we can always verify the results if anything goes wrong. You've had some problems with your ballots 16 years ago, and we're not sure why you haven't fixed this by now. After all, you've gotten people to the moon and robots to Mars--surely you'd want a fair, verifiable presidential election? (Especially when one of the two candidates is, frankly, terrifying to all your friends around the world.) Love, Canada
- emodendroket 10y ago> Why can you not just do paper voting with simple ballots, like in Canada? Many districts use paper ballots with optical scanners but this is totally up to the discretion of the county/state.
- blazespin 10y agoExactly, more people counting is not a problem. It's actually a good thing. Why not get more people involved in the electoral process? It's beyond me why anyone would want to undermine this. Plus, I don't get the mail in states. What's up with that? Why mess with a process that works?
- chipperyman573 10y agoI live in a mail-in state (WA) and in my opinion it's a pretty great system. I got my ballot almost two weeks ago and just sent it in last week. I was able to fill it out when I had free time and drop it in a ballot box (there's one about 5 minutes from where I live by foot, and I could always just mail it in if I wanted to). Lining up to vote at the polls would've been a lot more time-consuming because I would have to line up and I would've had to write down all my votes anyway, then move them onto an official ballot.
- deleted 10y ago[deleted]
- imode 10y agolovely! more paranoia about the upcoming competition for a single political position. as if I needed more of a reason to say "wow, this is rigged", now I see this! I can't imagine how well this will go. november is a cake walk. january is where the fun starts.
- based2 10y agohttps://www.schneier.com/blog/archives/2006/11/voting_technolo.html https://www.schneier.com/blog/archives/2006/11/voting_techno...
- sfifs 10y agoI wonder why countries don't use India's simple and scalable electronic voting systems. The latest ones have voter verified paper audit trails. They even have pooling systems to prevent counts from any single voting booth become known to prevent voter intimidation. https://en.m.wikipedia.org/wiki/Electronic_voting_in_India https://en.m.wikipedia.org/wiki/Electronic_voting_in_India
- tribby 10y agoI believe you've answered your own question, unfortunately.
- noir-york 10y agoDemocracy must not only be done, but also seen to be done. Trust in that most essential of democratic processes - vote counting - must be absolute. Approaching vote counting as a mere technical problem that can be solved with enough technical safeguards misses the point. You cannot just ask a democracy to beta test vote counting and fix the bugs post-election - that will kill trust in the process. Politics is polarised enough as is and you will find demagogues who will latch on to anything to reduce the legitimacy of an election. It shouldn't even be up for discussion that trust and legitimacy are the most important goals in vote counting. Stick to paper voting and only introduce e-voting in parallel and not as the authoritative and final vote counting solution.