Security concerns prompt D.C. to suspend Web-based overseas voting
Test run of open-source Digital Vote by Mail system exposed some serious flaws
Security issues have prompted election officials in the District of Columbia to suspend a service that aimed to allow overseas voters to cast their ballots via the Web in the November elections.
The vulnerabilities in Washington's new Digital Vote by Mail system were discovered during public testing last week by several security researchers.
Details of the flaws were not immediately available. However, one of them, discovered by a researcher at the University of Michigan, was so serious that it allowed the researcher to take complete control of the system hosting the Web application and tweak it so users who voted would hear a rendition of "Hail to the Victors," a University of Michigan fight song, said one observer of the tests.
A statement on the District of Columbia's Board of Elections and Ethics Web site offered no specific details on the issues that were uncovered. It merely noted that the "current iteration of the ballot return feature" did not meet required security and file integrity standards and was therefore being suspended.
Overseas voters will still be able to use the system to download their blank ballots, print them out, mark them and send them back by mail. They also have the option of sending a copy of their marked ballot back to their precinct by e-mail or fax.
Washington's new digital voting system is designed to make it easier for overseas U.S., military personnel and other citizens to vote in elections. The system is one of many that are being implemented around the country in response to the Military and Overseas Voter Empowerment (MOVE) Act of 2009.
One of the provisions under MOVE requires election officials to provide a Web-based application for delivering ballots to overseas voters. The goal is to allow registered voters who are based overseas to log into a Web site, identify themselves using a previously provided PIN and to download the ballots for their precincts.
Under MOVE, voters are then allowed to print out the ballots, mark them and send them back by mail. They also have the option of sending a copy of their marked ballot back via e-mail or fax.
A third option allows them to use the Web application to digitally mark their ballot and send it back via the same application; this is the method that has now been suspended by election officials as a result of the security concerns.
Jeremy Epstein, a senior computer scientist at SRI International and one of those who have reviewed the design of the system, said on Tuesday that he is familiar with the testing conducted last week by University of Michigan researchers.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
- Protecting Point of Sale Systems from Cyber Attacks
- If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
- Stop Hackers Before They Attack
- Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
- Protection Against Modern Cybersecurity Threats
- Download this case study to learn how this accounting and consulting giant uses Bit9's adaptive application whitelisting to offer employees flexibility without jeopardizing... All App Security White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- Spear Phishing and the Modern Cyber Attack
- Learn how IT teams can protect against spear phishing tactics. Harry Sverdlove, chief technology officer of Bit9 offers a frank discussion about spear...
- Moving Your Email to the Trusted Cloud
- How cloud-based email can help your company.
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All App Security Webcasts