Planning to E-Vote? Read This First

With less than three months before the presidential election, the hotly contested state, Ohio, along with others, continue to have problems with E-voting technology















Share on Tumblr

Brunner and Premier have locked horns several times since she took office in January 2007 over whether the company's DRE (direct recorded election) touch-screen electronic voting technology works properly and is secure. The problem came to a head in April, when election officials in Ohio's Butler County detected a vote count discrepancy during the primary election. The county board of elections staff determined that the Premier DRE system had malfunctioned and failed to count votes from memory cards uploaded to the system's vote tabulation computer server, Brunner says, adding, "This is not what we bargained for."

Suspecting problems with all of the e-voting technology that had so far cost Ohio $112 million, Brunner last year commissioned Project EVEREST, a comprehensive security review of the electronic voting technology used throughout Ohio, to identify any problems that might make elections vulnerable to tampering. During the 10-week project, teams of academic researchers from Pennsylvania State University, the University of Pennsylvania and WebWise Security (a security firm formed in 2005 by faculty and students from the University of California, Santa Barbara's security research group) examined DRE touch-screen and optical-scan voting systems from Premier, Election Systems and Software (ES&S) in Omaha, Neb., and Austin, Tex.–based Hart InterCivic as well as the software that manages these systems.

EVEREST researchers found exploitable security weaknesses in all three vendors' systems, Brunner said in a statement when the project concluded in December. "Many of these vulnerabilities represent practical threats to the integrity of elections as they are conducted in Ohio," she said. "We found vulnerabilities in different vendor systems that would, for example, allow voters and poll workers to place multiple votes, to infect the precinct with virus software or to corrupt previously cast votes—sometimes irrevocably."

"None of the systems out there are even remotely adequate given the importance of the data they handle," says Patrick McDaniel, a Penn State professor of information security who led the EVEREST testing. A lot of the attacks that McDaniel and his team tested could be carried out at a polling place or county elections office in a matter of seconds. An example: when researchers placed a piece of white tape over part of an e-voting system's scanner, they were able to effectively block it from reading the entire ballot. In other words, a person could put the tape in a place that kept the system from counting votes for a particular candidate. The team also found that the keys to unlock Hart's ballot box could also be used to open the ballot boxes on the Premier systems.

In a more serious attack, McDaniel found that his researchers could replace the memory card in some of the e-voting systems. "Any software you put on your card would uploaded into the system's computer," he says.

Premier had already responded to EVEREST's findings as well as a similar project commissioned by California Secretary of State Debra Bowen called Top-to-Bottom Review in March by issuing a report that emphasized that the EVEREST researchers did their work with "no physical or operational security controls" and did not simulate realistic election day conditions. Premier could not be reached for comment.

The EVEREST researchers don't dispute that. Sandy Clark, an EVEREST researcher and the computing systems manager of Princeton University's Atmospheric and Oceanic Sciences Program, said at the Last HOPE hacker's conference held last month in New York City that she and her EVEREST colleagues "treated the project as a hack."



8 Comments

Add Comment
View
  1. 1. John_Toradze 09:36 PM 8/18/08

    As a software engineer, there I say it is absolutely impossible to make an electronic voting system that can be trusted. Period. I have been through all the BS that proponents and people that work on the concept have said. It cannot be done. A major reason it cannot be done is that unique identifiers for users that can be traced to them are out. All the explanations otherwise are handwaving baloney.

    The only variant that could be trusted at all is one that spits out a hard copy on strong plastic or card stock. Then those cards can be inserted into a separate, dumb machine. But even this requires a unique identifier, and it can be hacked with a denial of service attack by manufacturing multiple identical identified cards, thereby destroying that vote in an audit.

    Reply | Report Abuse | Link to this
  2. 2. RecordRat 02:24 PM 8/19/08

    Brunner's own studies showed that all computerized voting systems can be hacked. Over 50 scientific studies corroborate that software can be altered without detection, because malware can erase itself. It is absolutely ludicrous that public elections are run on the worse possible technology available - undetectably mutable software. So, for 2008, we'll have another election that provides us with no rational basis for confidence in reported results.

    See Debunking: http://snipurl.com/31wg5
    Warning: http://snipurl.com/31v1x
    Full 50+ Bibliography: http://snipurl.com/30nhj

    Reply | Report Abuse | Link to this
  3. 3. markg8 11:16 AM 8/20/08

    The optical scanners are just as hackable and prone to breakdown as the touch screen machines. That's not very clear in the article especially with Burner's quote at the end. If we're to have confidence in our elections then count the ballots by hand. All the machines are undetectable vote fraud enabling junk.



    Reply | Report Abuse | Link to this
  4. 4. uncoveror 11:51 AM 8/21/08

    The whole point of these machines from day one was to rig elections. The ruling class have never had any interest in giving the rabble a real voice. Elections are no more real than a wrestling show if they can help it.

    Reply | Report Abuse | Link to this
  5. 5. jack dumnphy 01:14 PM 8/21/08

    Not to mention the standards were written by politicians with no software knowledge, and then left to be evaluated by test houses in collusion, like systest in colorado: http://www.opednews.com/articles/SysTest-Labs-under-Fire-Fo-by-Rady-Ananda-080815-39.html

    Reply | Report Abuse | Link to this
  6. 6. Ska-T 09:20 PM 8/21/08

    The vote is the foundation of democracy. To put private, for profit corporations in charge of recording and counting the people's vote is short sighted. To allow them to count the vote with proprietary software in secrete invites tyranny.
    "Fascism should more properly be called corporatism because it is the merger of state and corporate power." - Benito Mussolini.
    "It's not the people who vote that counts. It's the people who count the votes." - Josef Stalin

    Reply | Report Abuse | Link to this
  7. 7. Tocque Deville 10:56 AM 8/22/08

    Another election approaches and yet another establishment media outlet does a story decrying the perils of e-voting too late to do anything about it.

    Good job. This issue has been obvious to anyone with a PC for almost a decade. Not only have numerous tests been conducted proving that computerized voting (not to mention tabulation which is just as vulnerable and was omitted from this article), but there is more than compelling evidence that computerized systems have thrown elections.

    These systems aren't imperfect. If one were to design a system for election rigging, they could not have done better.

    It is nice that SciAm has decided to cover this issue. But it's too little too late. We are about to hand over yet another American election to a few private companies who have shown nothing but contempt for the principles of open, transparent democracy.


    Reply | Report Abuse | Link to this
  8. 8. neel 09:33 AM 3/18/10

    'EVMs illegally being used for a decade' -Legal Research Paper published in India at Chennai

    Author - Ajay Jagga, Punjab & Haryana High Court Lawyer, India

    Sanjay Sharma, TNN, Feb 22, 2010, 03.44am IST
    CHANDIGARH: The electronic voting machines (EVMs) are being used in violation of the Information Technology Act 2000, a research paper has revealed.

    Author of the research paper, advocate Ajay Jagga, told The Times of India, on Sunday that as per IT Act, 2000, a verifiable audit trail has to be provided in case of any electronic record, which is now admissible as evidence as per Evidence Act but in case of electronic voting, the voter does not get any receipt with regard to his voting.

    The research paper recently attracted the attention of experts when a conference on "EVMs: How trustworthy? " in Chennai passed a unanimous resolution on February 13, to approach the Election Commission of India (ECI) for bringing the electronic voting procedure in tune with IT Act, 2000.

    Jagga said he would soon approach ECI seeking formation of legal committee to remove the illegality or will knock the doors of court.He said the voter comes across a beep and flash, but what has happened inside the machine and whether the data has been recorded as per the wish of the elector, is not know. It is just like deposited money in the bank and official of the bank says no receipt is required.

    The lawyer said, "Unless the voter gets a receipt like the one we get in ATM or after the use of debit or credit cards, all electronic transactions including a vote, are illegal." What is the evidence that the vote cast has really been recorded and that it has been recorded in the manner the voter intended, he asked.

    For the purpose and to protect the secrecy of ballot, all such receipts, after the voter has checked his transaction, should be put in a box which should remain with ECI to be produced as evidence in case of a dispute, he said. The government amended the relevant laws in 1989 to equate EVM with ballot and ballot box to facilitate transition from ballot paper to EVM but the IT Act 2000 created a new complication that has to be immediately resolved in the interest of fairness of things, Jagga pointed out.

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

Tweets could not be retrieved at this time

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital

Latest from SA Blog Network

  SA Digital

Science Jobs of the Week

Email this Article

Planning to E-Vote? Read This First

X
Scientific American MIND iPad

Tap into your MIND

Get Both Print & Tablet Editions for one low price!

Subscribe Now >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X