4 ms·
What little has been described offers plenty of attack surface. The white paper has this to say about how paper copies of votes are printed out: > When the po
by apo 7y ago
What little has been described offers plenty of attack surface. The white paper has this to say about how paper copies of votes are printed out:
> When the polls close, members of each county clerk’s staff insert two cryptographically secure thumb drives into the vendor’s administrative portal laptop. Once the two thumb drives are verified, votes on the blockchain are automatically assembled as PDF files for each county. The Secretary of State’s office sends each county one PDF file containing all the marked ballots submitted by voters of that county. The clerk’s staff prints the ballots on cardstock with a ballot printer capable of printing up to 20” two-sided ballots (see Fig. 4). Each printed ballot contains the anonymous ID of the voter (see highlight in Fig. 5). Tabulation and the consolidation of results is done automatically by scanning the paper ballot into the precinct tabulator of the primary voting system (see Fig. 6).
https://sos.wv.gov/FormSearch/Elections/Informational/West-Virginia-Mobile-Voting-White-Paper-NASS-Submission.pdf https://sos.wv.gov/FormSearch/Elections/Informational/West-V...
How do the clerks get these thumb drives? What's the protocol for storage until used? Who has access to them? What physical security features do the drives implement?
If I were going to attack this system, the thumb drives seem like a juicy target with plenty of social engineering opportunities.