Advertisement
Home arrow ITsec News arrow A psychologist's job: electroning voting machines carrying double or triple personality
Saturday, 06 September 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  10244  66.24%
Win 2003  3645  23.57%
Win 2000  1034  6.69%
FreeBSD  352  2.28%
SolarisSunOS  106  0.69%
Other  85  0.55%

Total attacks: 15466 of which 4898 single ip and 10568 mass defacements

Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
Visitors' Map
A psychologist's job: electroning voting machines carrying double or triple personality PDF Print E-mail
User Rating: / 2
PoorBest 
Written by Roberto Preatoni   
Monday, 07 August 2006

dieboldElectronic Voting Technology is still a controversial topic: on the one hand there is the need to improve voting operations through an effective method for votes computation, on the other there are some perplexity due to the effective security of this technology.

Diebold's electronic voting technology has been tested for long before being introduced officially, but now, researchers at the Open Voting Foundation have come up with what they call as "the most seriois flaw" in electronic voting technology yet documented.

The Register reported last week that according to the Open Voting, "it's possible to get Diebold's AccuVote TS touchscreen voting machine by toggling a single switch, to boot from an unverified external flash drive instead of the device's built-in firmware , which is stored on a EPROM chip..."

Jvotingmachineeopardizing this technology now, means opening the voting maching and being uncommonly skilled about hardware and programming, but there are plenties of crackers that would like to take this challenge...

To be more precise, the problem seems to reside in the poor design of the motherboard which resembles those motherboard used in the old NeoGeo arcade videogames.

Old school hackers know very well how easy was to tamper that electronic, substituting the Eprom or even mounting a multiple Eprom set.

This kind of tricks seems working fine also on this voting machine; at least three ways to tamper with the machine behaviour have been identified so far.  It is basically possible by adding an additional Flash memory to the motherboard; the switches allowing to choose if booting from withing the original Eprom or the new Flash memory are already present, all you need to do is... to switch them.

In this way, the machine would carry a double personality one standard, the second evil. To be more precise, it has been found also the way to add a third personality by implementing an external flash memory.

More details about the full tricks at Opening Voting Foundation's website. 

The problem indeed aren't just the attempts to pilot voting operation, but also those people who would try to overcome voting machine's security tools to win a personal challenge or -quoting Zone-H digital attack Archive - "..just for fun!". The problem is that the developers did't manage in creating a voter-audited paper trail during elections tallied by the machine: to rig an election it would be enough to have access to the machines and possessing a screwdriver: anything it will be possible with the Diebold TS, without leaving a trace.

Around the world, many countries are attempting to make electronic voting technology safer and safer, but by now the system is far from being perfect, especially where electronic methods have completely replaced traditional ones. A digital attack could easily vanify the pools and no trace would be left in order to allow the commission to verify the election's outcome.


Comments Index (Total Messages: 0)


Post Reply
Name:Guest
Title:
Comment:



Enter this security word

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
Advertisement
 
Top! Top!