E-voting security under fire in San Diego lawsuit
Machine practices, ballot reliability in doubt
Computerworld - A lawsuit has grown out of alleged breaches in security procedures around electronic voting machines in San Diego County after a hotly contested congressional election, throwing a spotlight on the reliability of the machines themselves.
The suit, filed on Monday, requests that a special election on June 6 to fill the 50th Congressional District seat be invalidated. It also seeks a complete hand recount of the paper ballots, said Paul Lehto, an Everett, Wash.-based attorney handling the case. The suit was filed in Superior Court in San Diego and names Mikel Haas, county registrar of voters, and Brian Bilbray, the winner of the seat, as defendants.
San Diego voters used AccuVote optical-scan and TSx touch-screen systems from Diebold Election Systems.
Whatever the specific merits of the suit, it could heighten some citizens' concerns about e-voting technology if critics' claims of the inherent security deficiencies get debated in court during the run-up to the fall elections.
One of the main points raised by the suit is the so-called sleepover policy, under which Haas directed that all the machines be released to poll worker supervisors before the election. These sleepovers lasted from three days to more than a week.
"During these sleepovers, the voting machines were unsecured, subject to access by innumerable neighbors, strangers and family members, and stored without records or proof of actual chain of custody, eliminating the ability of any person to detect whether or not fraud or improper access to the voting machines occurred," according to the lawsuit.
"The sleepover issue is fairly egregious," said Lehto. Tampering with one card in one device conceivably could change race results.
The suit also alleges that keys for touch-screen voting machines were released to poll workers -- which is a violation of state and federal law. In addition, the suit cites a recent report that alleges testers discovered a "heretofore unknown switch" in the circuitry of the Diebold TS touch-screen system, the predecessor to the TSx. This allows the machine to boot from an external source, which would circumvent the software and safeguards inside completely.
The suit accuses Haas of suppressing or not collecting relevant materials, such as audit logs and electronic programs and ballots, for potential review after the election.
Haas declined to comment in detail about the suit, citing pending litigation, but he did defend the sleepover practice as being something commonly done in California and other states.
"Supervising poll workers take all supplies home following a training class so they are prepared. They are directed to keep it [the machine] secure wherever they are responsible for it," he said.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All IT in Government White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All IT in Government Webcasts