[lit-ideas] more voting insecurity

  • From: Eric Yost <mr.eric.yost@xxxxxxxxx>
  • To: Lit-Ideas <lit-ideas@xxxxxxxxxxxxx>
  • Date: Fri, 23 Sep 2005 15:24:17 -0400

Some List members may remember Howard Dean hacking the Diebold election machine on MSNBC. Here's a potential source of election fraud reported in some of the political blogs. Who needs voter intimidation when the results themselves can be hacked?


______

http://icantbelieveitsnotademocracy.blogs.com/weblog/2005/week37/index.html

Bradblog has an exclusive story titled: A DIEBOLD INSIDER SPEAKS!. In exclusive stunning admissions to The BRAD BLOG some 11 months after the 2004 Presidential Election, a "Diebold Insider" is now finally speaking out for the first time about the alarming security flaws within Diebold, Inc's electronic voting systems, software and machinery. The source is acknowledging that the company's "upper management" -- as well as "top government officials" -- were keenly aware of the "undocumented backdoor" in Diebold's main "GEM Central Tabulator" software well prior to the 2004 election. A branch of the Federal Government even posted a security warning on the Internet.

Pointing to a little-noticed "Cyber Security Alert" issued by the United States Computer Emergency Readiness Team (US-CERT), a division of the U.S. Department of Homeland Security, the source inside Diebold -- who "for the time being" is requesting anonymity due to a continuing sensitive relationship with the company -- is charging that Diebold's technicians, including at least one of its lead programmers, knew about the security flaw and that the company instructed them to keep quiet about it.

"Diebold threatened violators with immediate dismissal," the insider, who we'll call DIEB-THROAT, explained recently to The BRAD BLOG via email. "In 2005, after one newly hired member of Diebold's technical staff pointed out the security flaw, he was criticized and isolated."

In phone interviews, DIEB-THROAT confirmed that the matters were well known within the company, but that a "culture of fear" had been developed to assure that employees, including technicians, vendors and programmers kept those issues to themselves.

Go and read the whole thing. You know, Canada uses paper ballots in its elections and the ballots are counted by people, not machines. And they don't wait days or weeks for election results. It is cheaper and safer (if voting integrity matters to you). So why did Ohio and Florida spend so much money buying and implementing electronic voting machines and scanners? Oh, I thought so.

_________

http://www.bradblog.com/archives/00001838.htm


The "Cyber Security Alert" from US-CERT was issued in late August of 2004 and is still available online via the US-CERT website. The alert warns that "A vulnerability exists due to an undocumented backdoor account, which could [sic: allow] a local or remote authenticated malicious user [sic: to] modify votes."


"I was aware of the Diebold security flaw and had heard about the Homeland Security Cyber Alert Threat Assessment website, so I went there and 'bingo,' there it was in black and white," the source wrote. "It blew me away because it showed that DHS, headed by a Cabinet level George Bush loyalist, was very aware of the 'threat' of someone changing votes in the Diebold Central Tabulator. The question is, why wasn't something done about it before the election?"

The CEO of North Canton, Ohio-based Diebold, Inc., Walden O'Dell has been oft-quoted for his 2003 Republican fund-raiser promise to help "Ohio deliver its electoral votes to the president next year." O'Dell himself was a high-level contributor to the Bush/Cheney '04 campaign as well as many other Republican causes.

"A very serious problem...one malicious person can change the outcome of any Diebold election"

The voting company insider, who has also served as a spokesperson for the company in various capacities over recent years, admits that the "real danger" of this security vulnerability could have easily been exploited by a malicious user or an insider through remote access.

"I have seen these systems connected to phone lines dozens of times with users gaining remote access," said DIEB-THROAT. "What I think we have here is a very serious problem. Remote access using phone lines eliminates any need for a conspiracy of hundreds to alter the outcome of an election. Diebold has held onto this theory [publicly] for years, but Diebold has lied and has put national elections at risk. Remote access using this backdoor means that one malicious person can change the outcome of any Diebold election."

The ability to connect to the system remotely by phone lines and the apparent lack of interest by Diebold to correct the serious security issue in a timely manner -- or at all -- would seem to be at odds with at least one of their Press Releases touting their voting hardware and software.

------------------------------------------------------------------
To change your Lit-Ideas settings (subscribe/unsub, vacation on/off,
digest on/off), visit www.andreas.com/faq-lit-ideas.html

Other related posts:

  • » [lit-ideas] more voting insecurity