DC To Pursue Online Voting Despite Hacks

  /     /     /  
Publicated : 22/11/2024   Category : security


DC To Pursue Online Voting Despite Hacks


Elections board commits to fixing problems after researchers easily commandeered a demo version of Washington, D.C.s web-based voting system.



While hacker exploits scrapped Washington, D.C.s plans to offer an Internet-based voting option for absentee voters in the 2010 general election, the citys election board says its more encouraged than ever to create a secure digital voting system.
The lesson learned is not to be more timid, but more aggressive about solving the problem in exactly the way that we have chosen, Paul Stenbjorn, director of information services for the citys board of elections and ethics (BOEE), wrote on the boards website in response to criticism this week. Our task is to continue pursuing a robust, secure digital means for overseas voters to cast their ballot rather than resorting to email or fax.
As part of an ongoing
public evaluation
of the systems privacy and security, researchers at the University of Michigan last month discovered vulnerabilities that gave them almost total control of the server software, including the ability to change votes and reveal voters secret ballots, according to a
blog post
by Michigan assistant professor Alex Halderman, who headed up the universitys efforts.
D.C.s system allows users to log onto a website with a unique pin, download a PDF ballot and either return it by mail or upload the completed ballot via the site. The back-end server then encrypts and stores the ballots.
After 36 hours of probing the software, the researchers determined that while the server replaced the user-defined filename for the uploaded PDF file with an automatically generated one, it kept the file extension provided by the voter, and by formatting the extension as code, the researchers were able to cause the server to execute commands that a privileged user might have, such as collecting system passwords and encryption keys and viewing and modifying completed ballots.
In response, the city not only suspended the electronic voting option, but also temporarily stopped testing the system in order to fix the vulnerability. However, testing resumed on Wednesday.
Stennbjorn noted that the board of elections public tests originally grew out of its dissatisfaction in the lack of best practices, risk models, and collaborative frameworks developed at a National Institute for Standards and Technology workshop this year, and that it anticipated the possibility of just this result.
Our public test had been hacked, which you would think would have been an objectively bad thing for the BOEE, Stenbjorn wrote. Youd think wrong. Our goal was simple: determine if the application as developed passed muster, and if not, determine better mechanisms for security, transport, and usability for future releases.
For his part, Michigans Halderman expressed concern that such systems might contain other security flaws. If this particular problem had not existed, Im confident we would have found another way to attack the system, he wrote. Everything weve seen suggests that the design is brittle. It may someday be possible to build a secure method for submitting ballots over the Internet, but in the meantime, such systems should be presumed to be vulnerable based on the limitations of todays security technology.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
DC To Pursue Online Voting Despite Hacks