Vulnerabilities / Threats
10/24/2012
11:16 AM
50%
50%

Election 2012 Hacking Threat: 10 Facts

Election technology has improved since the 2000 presidential election "hanging chad" debacle, but new and old threats may put your vote at risk.

Could the U.S. elections be hacked, allowing attackers to adjust ballot counts and alter election results?

That threat, to be sure, sounds like little more than a Hollywood movie plot. Furthermore, based on recent reviews of states' voting system readiness, the more likely scenario is that voting systems in key swing states would simply crash. Cue delayed elections and potentially, disenfranchised voters with uncounted votes.

On the other hand, given the widespread and well-documented flaws in electronic voting systems, as well as the potential for such systems to crash or behave erratically, election officials must keep a close eye not just on the voting systems' physical and information security, but also the vote results themselves, to ensure that every vote counts. Here are 10 related facts.

1. Good News: Technology Now Records More Votes Properly

According to a report released earlier this month by the Caltech/MIT Voting Technology Project, which was launched in the wake of the 2000 presidential election, changes in voting technology have reduced the difference between votes cast and votes counted. That difference stems both from technology-related failures, including vote-counting systems being unable to properly read what a user has filled out on an optically scanned paper ballot, as well as from user errors, such as a voter picking two candidates for a single office.

[ Learn more about the tech behind Election 2012: How Voters Play Smartphone Politics. ]

Overall, the difference between votes cast and counted dropped from 2% in 2000, to 1% in 2006. Technologically speaking, what's facilitated that change? Start with awareness--as well as public shaming--after the 2000 presidential elections saw Florida officials become a punchline owing to the failure of the state's circa-1960s punch-card election technology. In particular, vote-tabulating machines weren't able to count ballots with incompletely punched holes, also known as hanging, dimpled, or pregnant chads. While the problem was widespread, the presidential election results hinged on the state's voters, and officials struggled to produce an accurate count of how votes had actually been cast.

2. Key Equipment Meltdowns Could Scuttle Election Results

What do Ohio, Virginia, Colorado, Nevada, and Pennsylvania all have in common? They occupy the top-five list of the "riskiest states for an e-voting meltdown." The list, detailed on the Freedom to Tinker blog, is based in part on the Counting Votes 2012 study of states' election preparedness, the VerifiedVoting.org Verifier database of the election technology that's currently being used by different states, and the relative likelihood that it will fail.

While the four researchers who authored the e-voting meltdown study said that "a meltdown scenario is very unlikely"--as is a "knife-edge selection" of the type that occurred in Florida in 2000--they still decided to review the likelihood that such problems could "cause a state to cast the deciding electoral college vote that would flip the election winner from one candidate to the other." Ohio, beware.

3. Recession Slows New Voting Technology Adoption

In the wake of the 2000 Florida vote-counting debacle, numerous states quickly dumped their antiquated punch-card-type systems. Unfortunately, the rush to find a new solution led many to adopt electronic voting systems--some with touchscreens--without first thoroughly vetting the technology. In short order, security experts began reporting that such technology employed proprietary systems predicated on "security through obscurity," and typically sported numerous physical as well as information security vulnerabilities.

4. Diebold Machines Remain In Use

In particular, Diebold soon became the face of electronic voting machines' failures, in large measure because the company's machines--as well as those of its competitors--were black boxes. Chief amongst electronic voting machines' list of faults, however, was that they failed to generate a paper-based audit trail. As a result, not only could the machines be hacked, but such hacking might never be detected.

Previous
1 of 3
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
BGREENE292
50%
50%
BGREENE292,
User Rank: Apprentice
10/28/2012 | 10:11:22 AM
re: Election 2012 Hacking Threat: 10 Facts
This article could benefit by an option to display the article as a single-page.
BGREENE292
50%
50%
BGREENE292,
User Rank: Apprentice
10/28/2012 | 10:10:27 AM
re: Election 2012 Hacking Threat: 10 Facts
This excellent article is extremely timely, particularly since Romney money underwrites electronic voting machine maker Hart Intercivic-- a clear conflict of interest for the company, if not an outright invitation to vote fraud by operators of the Hart Intercivic products.

http://www.nowpublic.com/world...
tryan205
50%
50%
tryan205,
User Rank: Apprentice
10/26/2012 | 1:58:22 PM
re: Election 2012 Hacking Threat: 10 Facts
Regarding the comment about the 2000 Florida vote"...and officials struggled to produce an accurate count of how votes had actually been cast." Actually the Florida officials, Kathleen Harris in particular, did everything in her power to shut off the recounts and hand the election to George W. Bush, accuracy be damned.
Rob B.
50%
50%
Rob B.,
User Rank: Apprentice
10/25/2012 | 6:45:38 PM
re: Election 2012 Hacking Threat: 10 Facts
Um, it's "voter rolls," not "voter roles." There's quite a difference.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6196
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSp...

CVE-2014-7247
Published: 2014-11-25
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?