July 30, 2007 2:21 PM PDT

Computer scientists hack Calif. e-voting machines

Forgive me if this isn't some major news flash, but let's document it for posterity anyway: University of California computer scientists have recently shown it's possible to carry out a bevy of hacks on electronic voting machines currently certified for use in the Golden State.

In reports released late last week, the researchers chronicle their five-week endeavor, at the request of California Secretary of State Debra Bowen, to exploit examine machines made by Hart InterCivic, Sequoia Voting Systems and Diebold. The same models are also in use in many other states, according to a database compiled by the Election Reform Information Project.

Their conclusion? "The security mechanisms provided for all systems analyzed were inadequate to ensure accuracy and integrity of the election results and of the systems that provide those results," wrote principal investigator Matt Bishop, a computer science professor at the University of California, Davis. (Click here for a PDF of that report.)

In each case, the testers were able to overwrite at least some of the firmware used on the machines and replace it with malicious programs--which, at times, could alter the recording, reporting and tallying of votes.

There were other flaws as well. With the Diebold AccuVote-TSX system, they found that a "well-known static security key" was used by default on the machine. On the Hart eSlate machine, the testers succeeded in remotely capturing the audio from an audio-enabled vote session, which poses a potential violation to a voter's privacy.

The researchers were quick to note that they didn't attempt to quantify how difficult or plausible it would be to pull off the attacks. Most of the attacks could be prevented by better physical security surrounding the devices, staff training and contingency planning. The testers also said their study would have benefited from additional time and that they were denied all the code and information--in particular, from Hart representatives--needed to conduct thorough scrutiny.

The Secretary of State planned to hold a public hearing on Monday in Sacramento to receive feedback on the reports from the voting machine vendors subject to the tests and from public commenters. California must act on any changes to its 2008 election equipment by Friday.

Sequoia, for its part, put out a press release that criticized the study's approach. The company said it concluded "none of the threats outlined represent a realistic threat if the normal, procedural mitigations are in effect."

The findings are likely to fuel an ongoing Capitol Hill debate over whether to ban the use of electronic machines that lack paper trails. According to a recent New York Times report, sponsors of such an effort in the House of Representatives are hoping to pass a compromise version--requiring the paperless machines to be scrapped by 2012 instead of 2008--before Congress departs for its August recess at week's end. The Senate, however, appears to be moving more tentatively.

But the California findings suggest the paper trail requirement may not be a cure-all by itself: the testers, after all, were also able to manipulate the paper receipts produced by touch-screen machines in the Diebold and Hart machines.

Recent posts from News Blog
Sprint HTC Touch Diamond outed early
Woman to virtual ex: 'I won't be ignored!'
Swiss secret sauce to power green choppers
iLink to deliver answers to military online communities
Vonage names new CEO
Add a Comment (Log in or register) 4 comments
What's the point?
by tobart July 30, 2007 4:11 PM PDT
I really don't see the point of electronic voting machines at all. As far as I can see they have two purposes:
1) To make their manufacturers bucketloads of cash.
2) To give the underdogs more chances to mess with elections.

As a studying computer scientist, I don't see these being "hack proof" any time soon, if ever.

...I just don't see the point.
Reply to this comment
OS E-Voting
by LinuxRules July 30, 2007 4:56 PM PDT
Never, never, never use M$ on your computers. The voting software should have been open source from the beginning. On top of all this most machines have no paper trail, no way of knowing the vote count if there is a malfunction.

PA is only now requiring a paper trail only one year after we spent millions on new e-vote machines with no paper. Politicians do not care how much tax payer money they spend and waste. What Idiots!
Reply to this comment View reply
Just Basic
by rbiz July 31, 2007 7:15 AM PDT
With the myriad (read "myriad" as 10's of 1000's per month) of
successful hacks and worms and viruses always going on with
computers that run on MS Windows, why wouldn't a company
choose anything and everything except Windows-based solutions?

It's really suspicious why Windows is almost always the default
solution for computer-based solutions for the U.S. government.
There are almost no good reasons why this is almost always so,
and a whole lot of good reasons why it should not be so.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

News Blog topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Samsung contemplating SanDisk acquisition

    South Korean consumer electronics giant is considering a buyout of the chipmaker to reduce its NAND flash memory costs, according to PaidContent.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • The Open Road

    Analysts as a lagging indicator of success

    Gartner, Forrester, and other analyst firms tends to be great predictors of the past, probably because that's where they get their money.

  • Beyond Binary

    Memo: Windows chief on new ads

    Windows business unit head Bill Veghte send a memo to troops late Thursday promising that the debut Seinfeld/Bill Gates ad was just an "icebreaker."

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    About time: Joost to launch browser-based player

    Company's desktop client failed to catch on with the public so Joost is retooling, but is it to late to catch Hulu and YouTube?

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    Google and 'Vanity Fair' party with the GOP

    Google and Vanity Fair hosted one of the most talked-about parties at the Republican convention.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Gadgettes, the blog

    Gadgettes 105: The Sing, Sing a Song Episode

    We have music on the brain in today's episode of Gadgettes. Don't worry, we won't destroy your ear drums with ear-piercing renditions of your least favorite '80s tunes. Instead, we'll soften the blow with a slew of musical gadgets and accessories.

  • Green Tech

    Green news harvest: Stolen solar panels, hydrogen at home

    Tata to bring small, all-electric car to Norway next year; a banner years for wind power; a home hydrogen-filling station; comparing the presidential candidates on plug-in cars; a microbial fuel cell for developing world; tips on greening your PC.