Absolutely Devastating Testimony on Internet Voting
Prof. J. Alex Halderman of the University of Michigan describes his group's ability to take complete control of Washington, DC's test of internet voting security.
Friday, October 8, 2010
Wednesday, October 6, 2010
Internet Voting comments by David Jefferson of Verified Voting
(Feel free to forward in full with attribution to David Jefferson of Verified Voting.)
University of Michigan Prof. Alex Halderman has now released some details about his successful attack on the District of Columbia's proposed Internet voting system which has been under test for the last week. (See www.freedom-to-tinker.com.) It is now clear that Halderman and his team were able to completely subvert the entire DC Internet voting system remotely, gaining complete control over it and substituting fake votes of their choice for the votes that were actually cast by the test voters. What is worse, they did so without the officials even noticing for several days.
Let there be no mistake about it: this is a major achievement, and supports in every detail the warnings that security community have been giving about Internet voting for over a decade now. After this there can be no doubt that the burden of proof in the argument over the security of Internet voting systems has definitely shifted to those who claim that the systems can be made secure.
Computer security and election experts have been saying for over 10 years that the transmission of voted ballots over the Internet cannot be made safe with any currently envisioned technology. We have been arguing mostly in vain that:
1) Remote attack: Internet voting systems can be attacked remotely by any government, any criminal syndicate, or any self aggrandizing individual in the world.
2) Effective defense virtually impossible: There are innumerable modes of attack, from very easy to very sophisticated, and if anyone seriously tried to attack an Internet election the election officials would have essentially no chance at successfully defending. The election would be compromised
3) Attackers may change votes arbitrarily: An attack need not just prevent people from voting (bad as that would be), but could actually change large numbers of votes, allowing the attackers to determine the winner.
4) Attacks may be undetected: An attack might go completely undetected. The wrong people could be elected and no one would ever know.
Prof. Halderman demonstrated all of these points:
1) Remote attack: His team of four conducted their attack remotely, from Michigan, via the Internet, without ever getting near Washington, D.C.
2) Effective defense virtually impossible: Although they were restricted from most modes of attack (which would be illegal even in this test situation), they still succeeded in completely owning (controlling) the voting system within about 36 hours after it was brought up, even though they had only 3 days of notice of when it would start. They happened to use one particular small vulnerability that they identified, but they are quite confident that they could have penetrated in other ways as well. Most likely they were the only team to even attempt to attack the system seriously; yet in a real election with something important at stake multiple teams might attack. The fact that the only team that even tried succeeded so quickly is a demonstration lots of other groups from around the world could also have done it.
3) Attackers may change votes arbitrarily:They not only changed some of the votes, they changed them all, both those cast before they took control of the system and those cast afterward. There is no way that officials can restore the original votes without the attackers' help.
4) Attacks may be undetected:The attack was not detected by the officials for several days, despite the fact that they were looking for such attacks (having invited all comers to try) and despite the fact that the attackers left a "signature" by playing the Michigan Fight song after every vote was cast!
This successful demonstration of the danger of Internet voting is the real deal. It doesn't get any better than this, people.
Alex Halderman, his graduate students Eric Wustrow and Scott Wolchok, and their colleague Dawn Isabel, all deserve enormous credit, congratulations, and thanks.
University of Michigan Prof. Alex Halderman has now released some details about his successful attack on the District of Columbia's proposed Internet voting system which has been under test for the last week. (See www.freedom-to-tinker.com.) It is now clear that Halderman and his team were able to completely subvert the entire DC Internet voting system remotely, gaining complete control over it and substituting fake votes of their choice for the votes that were actually cast by the test voters. What is worse, they did so without the officials even noticing for several days.
Let there be no mistake about it: this is a major achievement, and supports in every detail the warnings that security community have been giving about Internet voting for over a decade now. After this there can be no doubt that the burden of proof in the argument over the security of Internet voting systems has definitely shifted to those who claim that the systems can be made secure.
Computer security and election experts have been saying for over 10 years that the transmission of voted ballots over the Internet cannot be made safe with any currently envisioned technology. We have been arguing mostly in vain that:
1) Remote attack: Internet voting systems can be attacked remotely by any government, any criminal syndicate, or any self aggrandizing individual in the world.
2) Effective defense virtually impossible: There are innumerable modes of attack, from very easy to very sophisticated, and if anyone seriously tried to attack an Internet election the election officials would have essentially no chance at successfully defending. The election would be compromised
3) Attackers may change votes arbitrarily: An attack need not just prevent people from voting (bad as that would be), but could actually change large numbers of votes, allowing the attackers to determine the winner.
4) Attacks may be undetected: An attack might go completely undetected. The wrong people could be elected and no one would ever know.
Prof. Halderman demonstrated all of these points:
1) Remote attack: His team of four conducted their attack remotely, from Michigan, via the Internet, without ever getting near Washington, D.C.
2) Effective defense virtually impossible: Although they were restricted from most modes of attack (which would be illegal even in this test situation), they still succeeded in completely owning (controlling) the voting system within about 36 hours after it was brought up, even though they had only 3 days of notice of when it would start. They happened to use one particular small vulnerability that they identified, but they are quite confident that they could have penetrated in other ways as well. Most likely they were the only team to even attempt to attack the system seriously; yet in a real election with something important at stake multiple teams might attack. The fact that the only team that even tried succeeded so quickly is a demonstration lots of other groups from around the world could also have done it.
3) Attackers may change votes arbitrarily:They not only changed some of the votes, they changed them all, both those cast before they took control of the system and those cast afterward. There is no way that officials can restore the original votes without the attackers' help.
4) Attacks may be undetected:The attack was not detected by the officials for several days, despite the fact that they were looking for such attacks (having invited all comers to try) and despite the fact that the attackers left a "signature" by playing the Michigan Fight song after every vote was cast!
This successful demonstration of the danger of Internet voting is the real deal. It doesn't get any better than this, people.
Alex Halderman, his graduate students Eric Wustrow and Scott Wolchok, and their colleague Dawn Isabel, all deserve enormous credit, congratulations, and thanks.
Saturday, July 3, 2010
Scanning Completed, Results Match Well
The county finished processing its last ballots last Thursday, and the transparency project scan was completed yesterday. Preliminary results for a few races show county vote percentages and independent vote percentages varying by no more than 0.05% (one vote in two thousand). The independent results are still missing about fifteen ballots that could not be processed automatically, and there may be other minor adjustments.
No contests are at issue.
It may be a while before the scans are available. For many precincts, only one or two ballots were cast for some parties. Because these ballots could be used to identify an individual voter, we will need to remove them before releasing the set of scans.
No contests are at issue.
It may be a while before the scans are available. For many precincts, only one or two ballots were cast for some parties. Because these ballots could be used to identify an individual voter, we will need to remove them before releasing the set of scans.
Wednesday, June 23, 2010
Scanning Update
The project's volunteer scanners caught up last week with available ballots.
We will scan the last ballots as they are made available to us from the elections office, which is still doing operations like checking provisional ballots.
Ballot scans and an independent count should be available around the end of June.
We will scan the last ballots as they are made available to us from the elections office, which is still doing operations like checking provisional ballots.
Ballot scans and an independent count should be available around the end of June.
Sunday, June 13, 2010
June 2010 Primary
The transparenteers started scanning last Tuesday's ballots on Thursday. Some folks came in on Saturday, as well. Twelve thousand are now scanned, and another sixteen thousand should be scanned by mid-week. We will then pause until the Elections Department makes available the final batch of seven or eight thousand. I believe these are composed mostly of provisionals and absentee ballots received close to the election.
These are 8.5 x 17 ballots. Although the scanner processes them at a rate of 2,500 or so double sided ballots per hour, we're finding a typical throughput of 1,000 per hour.
These are 8.5 x 17 ballots. Although the scanner processes them at a rate of 2,500 or so double sided ballots per hour, we're finding a typical throughput of 1,000 per hour.
Saturday, February 20, 2010
Two Legal 'Situations'
These news items aren't directly related to the Humboldt County Election Transparency Project, but may be of interest to those who are interested in election integrity.
First, New York state recently awarded a voting machine contract to the nation's largest voting machine supplier, ES&S. According to Dominion, another bidder, New York originally ranked Dominion's solution higher. Dominion was also a substantially lower priced bidder. But New York then raised ES&S' ranking after the company added an "ease of use" feature that would, according to Dominion, be illegal in New York due to its compromise of security. Information can be found at Bo Lipari's blog -- http://www.bolipari.com/boblog/2010/02/dominion-sues-to-stop-new-york-city-contract-with-ess/.
Also this morning, news from Clay County, Kentucky, where, according to the Lexington Herald Leader, a former precinct worker has testified in court about how she stole votes from voters using voting machines. She testified that she was instructed in her technique by County Clerk Freddy Thompson, the chief election officer in that county.
The vote-buyers took advantage of some confusion caused by new voting machines the county had that year, White said. The machines had a "Vote" button that people could push to review their choices, then a second button they had to push to record the choices and finish voting.
Meanwhile, here in Humboldt County, CA, we use optically scanned paper ballots with no helpful "Vote" buttons to push but not vote. And, with the cooperation and assistance of County Clerk Carolyn Crnich, the Transparency Project has made available independent scans of every ballot cast in the last three elections, enabling independent recounts.
Monday, January 18, 2010
Cybergate article by Simon Worrall
I'll be very interested in the story this well-respected reporter has in the newest Maxim magazine. I haven't read it yet, but here's his blog entry:
Subscribe to:
Posts (Atom)