From https://www.politico.com/newsletters...indings-759382
First in MC: DEF CON reveals election security findings
By TIM STARKS
09/26/2019 10:00 AM EDT
With help from Eric Geller, Mary Lee, Martin Matishak and Matthew Brown
HAPPY THURSDAY and welcome to Morning Cybersecurity! It’s a weird tradition we have here. Send your thoughts, feedback and especially tips to tstarks@politico.com. Be sure to follow @POLITICOPro and @MorningCybersec.
FIRST IN MC: VENDORS, WE HAVE A PROBLEM
Popular new electronic voting machines “have not been designed with security considerations in mind,” and their weaknesses “open the door for various methods to attack the election process,” DEF CON’s Voting Machine Hacking Village said in its 2019 report, provided first to POLITICO. Hackers visiting the village found several flaws in these ballot-marking devices, including default passwords and clear-text administration credentials in the ES&S AutoMARK and an unencrypted file system on the Dominion ImageCast Precinct. BMDs are also susceptible to denial-of-service attacks, the report found, because resolving errors (including deliberate ones) requires a reboot.
Village organizers concluded that BMDs’ flaws raise “broad questions about their security and impact on overall election integrity if they were to be put into general use in elections.” But the problems uncovered went beyond BMDs, which are common replacements for paperless devices because they retain the convenience of a touchscreen. The village brought in other equipment, and the report said hackers used new and previously identified exploits to breach “every one of the devices in the room.”
Testers found a machine hard-coded to ping an overseas IP address with no explanation, and an e-poll book made by VR Systems — believed to be a victim of Russian hacking in 2016 — lacked a firmware password, enabling hackers to boot it into any operating system they wanted. Village organizers said most of the discovered attacks were possible under live-election conditions.
These findings demand scrutiny of BMDs, nationwide use of paper ballots and risk-limiting audits, as well as “dramatically increased funding” for local officials, the village’s organizers said in their report, which will be officially released later today. They also criticized voting machine vendors’ security engineering practices. “Historically, security measures provided by the hardware / low-level programming have been systematically turned off in all classes of devices used as part of the election infrastructure,” they wrote. “Unfortunately, this was found to be true also with newer generations of voting equipment in the Village.” Dominion did not respond to a request for comment, nor did the Election Assistance Commission. ES&S said it "look[ed] forward to reviewing the report."
Announcement
Collapse
No announcement yet.
First in MC: DEF CON reveals election security findings
Collapse
-
Created by:
The Dark Tangent
- Published: September 26, 2019, 16:29
- 0 comments
Categories
Collapse
Article Tags
Collapse
- article (3)
- aviation (3)
- badge (6)
- badge life (9)
- badgelife (7)
- contest (4)
- ctf (3)
- dc27 (66)
- dc28 (7)
- defcon27 (65)
- def con 28 (6)
- defcon28 (6)
- feds (3)
- first defcon (3)
- hardware (3)
- iot (4)
- joe grand (4)
- policy (3)
- prepare (3)
- review (3)
- speaker (3)
- village (9)
- voting (9)
- voting machine (9)
- voting village (3)
Latest Articles
Collapse
-
by number6Title: U.S. officials now worry about election logistics more than hacking
By: Joseph Menn
D: Friday, August 07, 2020 8:46 p.m
S: whtc.com
URL1=https://whtc.com/news/articles/2020/...cking/1047441/...-
Channel: Election Security Articles
August 17, 2020, 10:52 -
-
by number6URL1=https://www.cnn.com/2019/09/26/polit...nes/index.html
Title1: Hackers find voting machines used throughout the US are vulnerable to attack...-
Channel: Election Security Articles
September 30, 2019, 17:35 -
-
Voting Village report explores vulnerabilities in ballot-marking devices calls for paper-based auditFrom:
https://www.cyberscoop.com/def-con-v...lage-report-2/
Written by Sean Lyngaas
Sep 26, 2019 | CYBERSCOOP
DEF CON Voting Village report explores vulnerabilities in ballot-marking devices, calls for paper-based audits
After finding security weaknesses in two ballot-marking devices at this year’s DEF CON Voting Village, researchers are calling for “more comprehensive studies” of equipment that is increasingly a part of the voter experience....-
Channel: Election Security Articles
September 26, 2019, 16:28 -
-
From https://www.politico.com/newsletters...indings-759382
First in MC: DEF CON reveals election security findings
By TIM STARKS
09/26/2019 10:00 AM EDT
With help from Eric Geller, Mary Lee, Martin Matishak and Matthew Brown
HAPPY THURSDAY and welcome to Morning Cybersecurity! It’s a weird tradition we have here. Send your thoughts, feedback and especially tips to tstarks@politico.com. Be sure to follow @POLITICOPro and @MorningCybersec.
...-
Channel: Election Security Articles
September 26, 2019, 16:15 -