With improvements, e-voting could be good, says researcher.
WASHINGTON--In a keynote address at this year's ShmooCon, an East Coast computer hacker conference, J. Alex Halderman said that electronic voting machines could be good for the electorate--with some modifications.
Halderman is a graduate student studying under Ed Felten, a professor of computer science at Princeton, who is best known for demonstrating that the electronic voting machines produced by Diebold and other companies are vulnerable to attack. Diebold has since changed the name of election equipment to Premier Election Solutions. Felten was to make the keynote address, but canceled at the last minute due to the flu. Halderman is no less qualified to speak to the convention of computer hackers; this past summer, Halderman and others from Felten's team assisted California Secretary of State Debra Brown in her investigation of electronic voting machines.
At issue are direct-recording electronic (DRE) voting machines. Halderman points out that DREs are, basically, computers, susceptible to viruses, bugs, and crashes. What troubles Halderman and his team is that "a conspiracy of one could launch an attack on all the voting machines in a county or in a state." He said that while paper ballots could be rigged, paperless electronic ballots were even easier to exploit.
With the Diebold machines Halderman studied, he found that the company provided potential attackers with an upgrade process that was easy to manipulate. By giving a malicious file a specific file name, the Diebold DREs simply ran the code, allowing a devious programmer to inject malicious code into one or more voting machines. Since the same PCMIA card can be used to load a specific ballot within a precinct, county, or state, one tainted card could easily spread the infection.
Halderman also found, when working on the voting machines used in California that voting machines could also, with very little work, expose who voted for whom, violating voter secrecy.
Diebold has previously dismissed the claims by Felten, Halderman, and others. Another California e-voting system vendor, Sequoia, issued a press release faulting the secretary of state's study. Despite their objections, most states with electronic voting systems have now required the vendors to provide some kind of a paper audit.
Once the e-voting vendors improve their systems, Halderman said e-voting could ultimately be good. Voters like it. It provides faster reporting. It also offers more accessibility to disabled voters. With the addition of paper receipts, said Halderman, e-voting will also allow for better and less expensive vote auditing.
Currently, Halderman said, recounting votes in a disputed election is costly. Using machine-assisted auditing, however, taxpayers would save money and receive a much more accurate recount. One method Halderman showed at ShmooCon involved auditing only the winning candidate's vote to see if there was any evidence of electronic vote switching. As an example, he cited a recent election in Virgina where less than 1 percent of the vote decided the winner; by the current method, 1 million ballots would need to be recounted, but by his machine-assisted auditing method only 1,000 would be needed.
- Topics:
-
Criminal Hackers,
-
Security
- Bookmark:
- Digg
- Del.icio.us







Why is this marked under criminal hackers? I see no convicted criminal hackers mentioned in this story. Looks like cnet have screwed this one up. Who are you calling a criminal hacker? I can't even see you mention a criminal hacker in your blog entry. Please enlighten us where this deserves to have the criminal hacker tag inserted. You need to be charged with something before you can be called a criminal, even folks on the internet who are called "cyber criminals" aren't in reality. Cyber criminals likely have no criminal record in real life, its just the media who brand people criminals. Yes they may be bad guys, but as for "criminal" that has no legal standing as a publisher, because no one has been sentenced for any unlawful act. So to round up, its wrong for you to mark this blog entry criminal hackers, and its wrong for you in general to mention in quotes and news articles about such things as "cyber criminals may try to exploit X". In reality, the majority of bad guys who hack, research and crack things have no criminal record, so how can the media generalise in who it is the attackers are? They may be malicious hackers(the people who break into things) but criminals they cannot be called.
Very interesting about this topic.
Electronic voting and partial audits - guest blog by Rebecca Mercuri
http://blogs.cnet.com/8301-13554_1-9876062-33.html
Michael Horowitz