California’s e-voting systems are full of holes

Public hearing today will discuss security flaws

Written by Andrew Charlesworth

Democracy has taken another blow in the US where a team of investigators has found fundamental security flaws in all the e-voting systems it tested in California.

The tests were carried out over the last two months as part of a review of e-voting by California Secretary of State Debra Bowen.

Advertisement

According to the Californian government website the review was “designed to restore the public's confidence in the integrity of the electoral process and … ensure that California’s voters are being asked to cast their ballots on machines that are secure, accurate, reliable, and accessible.”

But it has achieved exactly the opposite.

A public hearing on the report is being held today in the State capital, Sacremento.

The team of investigators, led by Matt Bishop from the Davis University of California, concluded that “the security mechanisms provided for all systems analysed were inadequate to ensure accuracy and integrity of the election results.”

Bishop’s team was able to forge voter cards and manipulate counts from voting terminals and even the reports from servers which aggregate results. They found terminals and servers where they could overwrite firmware, run malicious code and even undo screws on protective locks to gain access to the innards of voting machines.

“Many of the components tested appear to have been hardened by taking their basic design and adding security features,” Bishop reported. “As a result, the testers were able to exploit inconsistencies between the protective mechanisms and that which they were intended to protect.”

The systems tested were supplied by Sequoia, Diebold and Hart InterCivic. Systems supplied by Election Systems and Software arrived too late to test.

Bishop said his researchers were impeded in obtaining sufficient security data to carry out their tests and recommends in his report that in future all vendors be compelled to provide all the source code and documentation for their systems before testing commences.

“All team members felt that they lacked sufficient time to conduct a thorough examination, and consequently may have missed other serious vulnerabilities,” reported Bishop.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Podcast image

02 Oct 2008

14.35 MBComputing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit More...

Shaun Nichols and Iain Thomson

26 Sep 2008

3.43 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

HP iPaq 514

Rumours hint at HP iPhone rival

Vendor's iPaq line may gain touch model   More...

Ask.com

Ask.com bullish about the future

Search firm outlines plans for market share gains   More...

National Identity Fraud Prevention Week

Nine out of 10 firms put customer data at risk

National ID fraud event reveals lax corporate attitudes   More...

Virtualisation

Virtualisation set to drive SaaS adoption

Software-as-a-service delivery model was too costly before virtualisation   More...

Primary Navigation