4 ms·
Can't they just wipe them clean and restart? How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair
by caseysoftware 5y ago
Can't they just wipe them clean and restart?
How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review?
If they are compromised, I'd love to see a post mortem and understand how they were compromised and how that can be mitigated going forward.
- torgoguys 5y agoNo reason for your question to be downvoted. I've done my small part to reverse that. I doubt the officials suspect the machines have been compromised, but they have no way of knowing. There are chain of custody rules to help ensure integrity of the systems. Those have been violated so the machines can't be used until they've been carefully examined and recertified. Putting this in a money context might help some--lets say you owned slot machines that could have big payouts. Would you let rando unauthorized person to be alone with one of your machines in a private office, doing upgrades, and still trust the machine? Probably not. You'd want to take a look at it top to bottom before trusting it to do any payouts. The person might not have done anything wrong but you've got to be sure first, and since there are other ways these things could be compromised than just adding unauthorized software to the hard drive, a clean install isn't enough.
- caseysoftware 5y agoSo far the claim is "an unauthorized person's name was entered into the log of people who were present for a secure software update conducted by Dominion employees" and not "rando unauthorized person to be alone with one of your machines." If someone seeing an update executed compromises the machines, that's a HUGE problem. But I think you're spot on with the slot machine comparison. In a casino, asking security to turn off the cameras monitoring an area would be a breach in itself. They wouldn't do it and would report someone who requested it. In this situation, "how could an official could order it?" and "why did the security team do it?" are both things to look into. Was this standard operating procedure? If so, for how long and when else did it occur? And broader, are there other jurisdictions where they had similar security lapses? If so, when, where, and for how long? Further, were those machines also removed from service and analyzed?
- mschuster91 5y ago> How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review? As soon as an unidentified attacker has unsupervised access to a piece of hardware it's game over. An exploit that uses persistence features like embedding itself into the BIOS/UEFI firmware (see e.g. https://www.coresecurity.com/core-labs/articles/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense https://www.coresecurity.com/core-labs/articles/the-bios-emb...) can be very hard to get rid of - so hard that it's likely easier to dispose of the machines entirely.
- unanswered 5y agoDo you have a source for "an attacker having unsupervised access" to these machines or are you just making that up?
- rsfern 5y agoIt’s literally the first sentence of the linked article… Edit — I see you’ve specified unsupervised where the article specifies “unauthorized”. However, given they turned off the security cameras I think it’s kind of splitting hairs
- unanswered 5y agoThere were other people present, making it not "unsupervised". By ignoring this distinction both you and the above commenter are spreading disinformation for what appear on the surface to be nefarious political goals.
- mschuster91 5y agoWe have no way of knowing what went down in that location. The fact that unauthorized people were present with video surveillance turned off and the machines were running for a software upgrade is enough to assume at least one could have been compromised in a matter of seconds - if only by a sleight-of-hand hidden insertion of an USB stick. Voting integrity is fundamental to a democracy.
- PragmaticPulp 5y ago> Can't they just wipe them clean and restart They’re now evidence in an ongoing investigation. They don’t know exactly what happened to them because the perpetrators deliberately disabled the security cameras monitoring the machines before doing whatever they did. Wiping them could destroy evidence or it could miss a different issue (hardware modification, for example). The only reasonable response is to quarantine the machines as evidence and replace them with new machines with a known chain of custody. > How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review? There’s more to the story, including someone intentionally disabling the security cameras that monitored the machines for at least a week. With a gap in the surveillance of the machines combined with a QAnon-associated leak and an intruder who misled the office, it’s time to start fresh and set the old machines aside as evidence.
- rsynnott 5y ago> Can't they just wipe them clean and restart? I mean, _probably_. There's malware that's extremely difficult to get rid of, but probably it wasn't used here. But it looks like they have elections coming up in a few weeks, so "do it on paper" is probably a not-unreasonable precaution, particularly given the general pattern of dodginess, in particular the thing about the video surveillance. If nothing else, if you phone up the manufacturer and tell them that a weird pillow website devotee allowed some unknown third party to potentially mess with the machines, the manufacturer is probably _not_ going to say "yeah, that'll definitely be fine, use them"; they won't want to take the risk. This is probably a return-to-manufacturer job.
- deleted 5y ago[deleted]