Vulnerabilities / Threats
10/24/2012
11:16 AM
50%
50%

Election 2012 Hacking Threat: 10 Facts

Election technology has improved since the 2000 presidential election "hanging chad" debacle, but new and old threats may put your vote at risk.

Could the U.S. elections be hacked, allowing attackers to adjust ballot counts and alter election results?

That threat, to be sure, sounds like little more than a Hollywood movie plot. Furthermore, based on recent reviews of states' voting system readiness, the more likely scenario is that voting systems in key swing states would simply crash. Cue delayed elections and potentially, disenfranchised voters with uncounted votes.

On the other hand, given the widespread and well-documented flaws in electronic voting systems, as well as the potential for such systems to crash or behave erratically, election officials must keep a close eye not just on the voting systems' physical and information security, but also the vote results themselves, to ensure that every vote counts. Here are 10 related facts.

1. Good News: Technology Now Records More Votes Properly

According to a report released earlier this month by the Caltech/MIT Voting Technology Project, which was launched in the wake of the 2000 presidential election, changes in voting technology have reduced the difference between votes cast and votes counted. That difference stems both from technology-related failures, including vote-counting systems being unable to properly read what a user has filled out on an optically scanned paper ballot, as well as from user errors, such as a voter picking two candidates for a single office.

[ Learn more about the tech behind Election 2012: How Voters Play Smartphone Politics. ]

Overall, the difference between votes cast and counted dropped from 2% in 2000, to 1% in 2006. Technologically speaking, what's facilitated that change? Start with awareness--as well as public shaming--after the 2000 presidential elections saw Florida officials become a punchline owing to the failure of the state's circa-1960s punch-card election technology. In particular, vote-tabulating machines weren't able to count ballots with incompletely punched holes, also known as hanging, dimpled, or pregnant chads. While the problem was widespread, the presidential election results hinged on the state's voters, and officials struggled to produce an accurate count of how votes had actually been cast.

2. Key Equipment Meltdowns Could Scuttle Election Results

What do Ohio, Virginia, Colorado, Nevada, and Pennsylvania all have in common? They occupy the top-five list of the "riskiest states for an e-voting meltdown." The list, detailed on the Freedom to Tinker blog, is based in part on the Counting Votes 2012 study of states' election preparedness, the VerifiedVoting.org Verifier database of the election technology that's currently being used by different states, and the relative likelihood that it will fail.

While the four researchers who authored the e-voting meltdown study said that "a meltdown scenario is very unlikely"--as is a "knife-edge selection" of the type that occurred in Florida in 2000--they still decided to review the likelihood that such problems could "cause a state to cast the deciding electoral college vote that would flip the election winner from one candidate to the other." Ohio, beware.

3. Recession Slows New Voting Technology Adoption

In the wake of the 2000 Florida vote-counting debacle, numerous states quickly dumped their antiquated punch-card-type systems. Unfortunately, the rush to find a new solution led many to adopt electronic voting systems--some with touchscreens--without first thoroughly vetting the technology. In short order, security experts began reporting that such technology employed proprietary systems predicated on "security through obscurity," and typically sported numerous physical as well as information security vulnerabilities.

4. Diebold Machines Remain In Use

In particular, Diebold soon became the face of electronic voting machines' failures, in large measure because the company's machines--as well as those of its competitors--were black boxes. Chief amongst electronic voting machines' list of faults, however, was that they failed to generate a paper-based audit trail. As a result, not only could the machines be hacked, but such hacking might never be detected.

Previous
1 of 3
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
BGREENE292
50%
50%
BGREENE292,
User Rank: Apprentice
10/28/2012 | 10:11:22 AM
re: Election 2012 Hacking Threat: 10 Facts
This article could benefit by an option to display the article as a single-page.
BGREENE292
50%
50%
BGREENE292,
User Rank: Apprentice
10/28/2012 | 10:10:27 AM
re: Election 2012 Hacking Threat: 10 Facts
This excellent article is extremely timely, particularly since Romney money underwrites electronic voting machine maker Hart Intercivic-- a clear conflict of interest for the company, if not an outright invitation to vote fraud by operators of the Hart Intercivic products.

http://www.nowpublic.com/world...
tryan205
50%
50%
tryan205,
User Rank: Apprentice
10/26/2012 | 1:58:22 PM
re: Election 2012 Hacking Threat: 10 Facts
Regarding the comment about the 2000 Florida vote"...and officials struggled to produce an accurate count of how votes had actually been cast." Actually the Florida officials, Kathleen Harris in particular, did everything in her power to shut off the recounts and hand the election to George W. Bush, accuracy be damned.
Rob B.
50%
50%
Rob B.,
User Rank: Apprentice
10/25/2012 | 6:45:38 PM
re: Election 2012 Hacking Threat: 10 Facts
Um, it's "voter rolls," not "voter roles." There's quite a difference.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1774
Published: 2015-04-28
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

CVE-2015-1863
Published: 2015-04-28
Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.

CVE-2015-3340
Published: 2015-04-28
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

CVE-2014-6090
Published: 2015-04-27
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix...

CVE-2014-6092
Published: 2015-04-27
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause...

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.