• On MP3.com: Free music videos
February 16, 2008 6:21 AM PST

With improvements, e-voting could be good, says researcher.

WASHINGTON--In a keynote address at this year's ShmooCon, an East Coast computer hacker conference, J. Alex Halderman said that electronic voting machines could be good for the electorate--with some modifications.

Halderman is a graduate student studying under Ed Felten, a professor of computer science at Princeton, who is best known for demonstrating that the electronic voting machines produced by Diebold and other companies are vulnerable to attack. Diebold has since changed the name of election equipment to Premier Election Solutions. Felten was to make the keynote address, but canceled at the last minute due to the flu. Halderman is no less qualified to speak to the convention of computer hackers; this past summer, Halderman and others from Felten's team assisted California Secretary of State Debra Brown in her investigation of electronic voting machines.

At issue are direct-recording electronic (DRE) voting machines. Halderman points out that DREs are, basically, computers, susceptible to viruses, bugs, and crashes. What troubles Halderman and his team is that "a conspiracy of one could launch an attack on all the voting machines in a county or in a state." He said that while paper ballots could be rigged, paperless electronic ballots were even easier to exploit.

With the Diebold machines Halderman studied, he found that the company provided potential attackers with an upgrade process that was easy to manipulate. By giving a malicious file a specific file name, the Diebold DREs simply ran the code, allowing a devious programmer to inject malicious code into one or more voting machines. Since the same PCMIA card can be used to load a specific ballot within a precinct, county, or state, one tainted card could easily spread the infection.

Halderman also found, when working on the voting machines used in California that voting machines could also, with very little work, expose who voted for whom, violating voter secrecy.

Diebold has previously dismissed the claims by Felten, Halderman, and others. Another California e-voting system vendor, Sequoia, issued a press release faulting the secretary of state's study. Despite their objections, most states with electronic voting systems have now required the vendors to provide some kind of a paper audit.

Once the e-voting vendors improve their systems, Halderman said e-voting could ultimately be good. Voters like it. It provides faster reporting. It also offers more accessibility to disabled voters. With the addition of paper receipts, said Halderman, e-voting will also allow for better and less expensive vote auditing.

Currently, Halderman said, recounting votes in a disputed election is costly. Using machine-assisted auditing, however, taxpayers would save money and receive a much more accurate recount. One method Halderman showed at ShmooCon involved auditing only the winning candidate's vote to see if there was any evidence of electronic vote switching. As an example, he cited a recent election in Virgina where less than 1 percent of the vote decided the winner; by the current method, 1 million ballots would need to be recounted, but by his machine-assisted auditing method only 1,000 would be needed.

Recent posts from Defense in Depth
High-tech bank robbers phone it in
How 'carders' trade your stolen personal info
Anatomy of a botnet
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Add a Comment (Log in or register) 5 comments
Cnet can you explain a few things
by n3td3v February 16, 2008 7:56 AM PST
"Topics:Criminal Hackers, Security"

Why is this marked under criminal hackers? I see no convicted criminal hackers mentioned in this story. Looks like cnet have screwed this one up. Who are you calling a criminal hacker? I can't even see you mention a criminal hacker in your blog entry. Please enlighten us where this deserves to have the criminal hacker tag inserted. You need to be charged with something before you can be called a criminal, even folks on the internet who are called "cyber criminals" aren't in reality. Cyber criminals likely have no criminal record in real life, its just the media who brand people criminals. Yes they may be bad guys, but as for "criminal" that has no legal standing as a publisher, because no one has been sentenced for any unlawful act. So to round up, its wrong for you to mark this blog entry criminal hackers, and its wrong for you in general to mention in quotes and news articles about such things as "cyber criminals may try to exploit X". In reality, the majority of bad guys who hack, research and crack things have no criminal record, so how can the media generalise in who it is the attackers are? They may be malicious hackers(the people who break into things) but criminals they cannot be called.
Reply to this comment
DRE Voting Machines
by rtatlow February 16, 2008 8:16 AM PST
By their nature, fraud is undetectable with paperless DRE voting machines. A paper trail provides some detectablility, but not as easy as optical scanned ballots with random sampling.
Reply to this comment
there's a better way...
by lewac February 17, 2008 7:48 AM PST
use your computer. you'd probably need to boot into a distro of linux though then launch a secure app out of there specifically designed for voting at ALL levels of government (from your local HOA all the way to national and eventually even international elections).
Reply to this comment
Movie: "hacking democracy"
by Phil-IT February 18, 2008 7:22 AM PST
Great yet scary movie I saw last week.
Very interesting about this topic.
Reply to this comment
Rebuttal from Dr. Rebecca Mercuri
by mhinnewyork February 21, 2008 10:22 AM PST
For a rebuttal to this, see
Electronic voting and partial audits - guest blog by Rebecca Mercuri
http://blogs.cnet.com/8301-13554_1-9876062-33.html
Michael Horowitz
Reply to this comment
Powered by Jive Software
advertisement
Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right