Vulnerabilities / Threats

7/28/2017
09:40 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

DEF CON Rocks the Vote with Live Machine Hacking

Jeff Moss, founder of the hacker conference, is planning to host a full-blown election and voting system for hacking in 2018 at DEF CON, complete with a simulated presidential race.

DEF CON 25 – Las Vegas – It took just 90 minutes before hackers here today rooted out two zero-day vulnerabilities in a pair of decommissioned voting systems stationed in the hacker conference's first-ever Voting Machine Hacker Village.

DEF CON founder Jeff Moss, aka Dark Tangent, says he and his team recently purchased the used voting machines on eBay for hackers here to hammer away at and find flaws that ultimately get reported to the vendors of the machines. There were 30 pieces of voting equipment in the room, including Sequoia AVC Edge, ES&S iVotronic, Diebold TSX, Winvote, and Diebold Expresspoll 4000 voting machines.

The first two hacks this morning are expected to be the tip of the iceberg: these systems are well-known to be rife with outdated software such as Windows CE, and plenty of ports for hardware exposure, including PCMCIA, serial ports, and even a WEP-based WiFi feature - all of which are ripe for abuse. As of this posting, another hacker had cracked the hardware and firmware of the Diebold TSX voting machine. 

In the first two discoveries of the day, a hacker found a remote access flaw in the WinVote voting machine's operating system, and exposed real election data that was still stored there. Another hacker cracked the Express-Pollbook system, exposing the internal data structure via a known OpenSSL flaw, CVE-2011-4109, allowing remote attacks.

"What this tells me is hackers in less than two hours can figure something out and a nation-state could have this on their hands for months or years," Moss said in an interview here today. "It doesn't have to be nation-states. It could be criminal organizations; it doesn't have to be limited to Russia."

Moss said for DEF CON next year, he's planning an actual election voting simulation at the hacker conference: DEF CON will hold a mock election, possibly with Moss running for president against another as-yet unnamed opponent. Hackers will have their crack at the systems.

"There's never been a security test of a complete voting system … We're trying to build a whole system, but it's hard to get the back-end pieces," he said. "I have confidence by next year we will have a complete end to end voting system set up. We'll have fake elections and people can attack it and at the end of the con," we'll share the results, he said.

While the Voting Village concept evolved out of concerns raised by Russia's tampering with the 2016 US election, it also came amid a backdrop of a cybersecurity industry that's experiencing some soul-searching, and growing pains. Alex Stamos, CISO of Facebook, during the keynote address earlier this week at Black Hat USA urged attendees to channel energy into innovative defensive solutions, rather than just breaking things.

Facebook also upped the ante for its Internet Defense Prize program, to $1 million to encourage more hackers to come up with unique defense solutions for Internet users.

Meanwhile, DEF CON is now 25 years old, a milestone that had Moss reflecting on what comes next for the world's largest hacker conference and the hacking community. "The days of the lone hacker being able to do it all is pretty much [over]. It's much more social, is one of my messages this year," Moss said. "Since you can't know it all, and it's more important about who you know, and they know the stuff you don’t know and can help you."

It's a bit of a throwback to the pre-Google search days, when hackers sought out mentors and other hackers to assist their research and inform their work, he noted. Mentorship is key to this next phase of security innovation, he said.

That doesn't mean offense is dead. "There's a big place for breaking because offense always informs the defense. If you love breaking just keep breaking. You have to recognize that you're operating in a bigger context now," Moss went on to say, noting: "Hacking is not going to slow down. If anything, it's going to become more relevant. We try to stay true to our identity as best we can. It can never be the way it was 20 years ago, but I think we're making the change … the world has moved on and we're moving along with it."

Related Content:

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Kelly Jackson Higgins
100%
0%
Kelly Jackson Higgins,
User Rank: Strategist
7/31/2017 | 12:19:00 PM
Re: Voting for Moss
#TheDarkTangentForPresident
Christian Bryant
50%
50%
Christian Bryant,
User Rank: Ninja
7/31/2017 | 12:10:24 PM
Voting for Moss
This is a great sign.  CTF - while always exciting even when on the same old architecture - needed to evolve to bring a sense of current urgency to the activity.  This is a CTF that is meaningful to everywhere, low-tech to hacker.  With the right visibility this could potentially lead to forever changing our voting tech and processes, ideally to the point where at least this one element in the next election is not a distraction.  Kudos.  I'm voting for Moss, naturally.
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.