July 30, 2007 2:21 PM PDT

Computer scientists hack Calif. e-voting machines

Forgive me if this isn't some major news flash, but let's document it for posterity anyway: University of California computer scientists have recently shown it's possible to carry out a bevy of hacks on electronic voting machines currently certified for use in the Golden State.

In reports released late last week, the researchers chronicle their five-week endeavor, at the request of California Secretary of State Debra Bowen, to exploit examine machines made by Hart InterCivic, Sequoia Voting Systems and Diebold. The same models are also in use in many other states, according to a database compiled by the Election Reform Information Project.

Their conclusion? "The security mechanisms provided for all systems analyzed were inadequate to ensure accuracy and integrity of the election results and of the systems that provide those results," wrote principal investigator Matt Bishop, a computer science professor at the University of California, Davis. (Click here for a PDF of that report.)

In each case, the testers were able to overwrite at least some of the firmware used on the machines and replace it with malicious programs--which, at times, could alter the recording, reporting and tallying of votes.

There were other flaws as well. With the Diebold AccuVote-TSX system, they found that a "well-known static security key" was used by default on the machine. On the Hart eSlate machine, the testers succeeded in remotely capturing the audio from an audio-enabled vote session, which poses a potential violation to a voter's privacy.

The researchers were quick to note that they didn't attempt to quantify how difficult or plausible it would be to pull off the attacks. Most of the attacks could be prevented by better physical security surrounding the devices, staff training and contingency planning. The testers also said their study would have benefited from additional time and that they were denied all the code and information--in particular, from Hart representatives--needed to conduct thorough scrutiny.

The Secretary of State planned to hold a public hearing on Monday in Sacramento to receive feedback on the reports from the voting machine vendors subject to the tests and from public commenters. California must act on any changes to its 2008 election equipment by Friday.

Sequoia, for its part, put out a press release that criticized the study's approach. The company said it concluded "none of the threats outlined represent a realistic threat if the normal, procedural mitigations are in effect."

The findings are likely to fuel an ongoing Capitol Hill debate over whether to ban the use of electronic machines that lack paper trails. According to a recent New York Times report, sponsors of such an effort in the House of Representatives are hoping to pass a compromise version--requiring the paperless machines to be scrapped by 2012 instead of 2008--before Congress departs for its August recess at week's end. The Senate, however, appears to be moving more tentatively.

But the California findings suggest the paper trail requirement may not be a cure-all by itself: the testers, after all, were also able to manipulate the paper receipts produced by touch-screen machines in the Diebold and Hart machines.

Recent posts from News Blog
Cuba and Venezuela to lay undersea Internet cable
Pubmatic: Online ad prices stay flat
Intel rides high on strong notebook demand
For teens, the future is mobile
Sun issues upbeat fourth-quarter forecast
Add a Comment (Log in or register) 4 comments (Page 1 of 1)
What's the point?
by tobart July 30, 2007 4:11 PM PDT
I really don't see the point of electronic voting machines at all. As far as I can see they have two purposes:
1) To make their manufacturers bucketloads of cash.
2) To give the underdogs more chances to mess with elections.

As a studying computer scientist, I don't see these being "hack proof" any time soon, if ever.

...I just don't see the point.
Reply to this comment
OS E-Voting
by LinuxRules July 30, 2007 4:56 PM PDT
Never, never, never use M$ on your computers. The voting software should have been open source from the beginning. On top of all this most machines have no paper trail, no way of knowing the vote count if there is a malfunction.

PA is only now requiring a paper trail only one year after we spent millions on new e-vote machines with no paper. Politicians do not care how much tax payer money they spend and waste. What Idiots!
Reply to this comment View reply
Just Basic
by rbiz July 31, 2007 7:15 AM PDT
With the myriad (read "myriad" as 10's of 1000's per month) of
successful hacks and worms and viruses always going on with
computers that run on MS Windows, why wouldn't a company
choose anything and everything except Windows-based solutions?

It's really suspicious why Windows is almost always the default
solution for computer-based solutions for the U.S. government.
There are almost no good reasons why this is almost always so,
and a whole lot of good reasons why it should not be so.
Reply to this comment
Powered by Jive Software
advertisement
  • About News Blog

  • Recent posts on technology, trends, and more.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Torvalds attacks IT industry 'security circus'

  2. Mozilla updates Firefox with three security patches

  3. Photos: Game on at E3

  4. Mom continues to chase Prince over 'fair use'

  5. Circuit board orders point to new MacBooks?

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

advertisement
On The Insider: Sarah Jessica Parker's Mole Removed
Advanced
search
Advanced
search
Visit other CBS Interactive sites