Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Panel members find security flaws in Internet voting system

'A dedicated and experienced hacker could subvert the election rather easily,' said one expert
 

Sign up to receive Security Resource Alerts

January 22, 2004 (Computerworld) -- A federally funded Internet-based voting system scheduled for use in the 2004 primary and general elections has several unresolvable security vulnerabilities that leave it open to widespread vote tampering and privacy breaches.
That is the opinion of four members of a 10-person peer review group assigned to identify potential flaws in the Secure Electronic Registration and Voting Experiment (SERVE) system being built for the U.S. Department of Defense's Federal Voting Assistance Program (FVAP). The system is being developed as part of a government initiative to make it easier for U.S. armed force personnel, the Merchant Marines and overseas civilians to vote.
The SERVE system is expected to be used by absentee voters from 50 counties in seven states and is designed to handle up to 100,000 votes.
According to the panel members, who publicly aired their concerns yesterday, the risks are so serious that it is recommending that further development of SERVE be immediately shut down and not attempted again until "both the Internet and the world's home computer infrastructure have been fundamentally redesigned."
The problems lie in the inherent insecurities associated with Internet and PC-based systems, said David Wagner, an associate professor at the University of California, Berkeley, and one of the security experts assigned to review the prototype SERVE system.
These include viruses and worms, denial-of-service attacks and Web-site spoofing, Wagner said. An attack on the main SERVE system or any of the PCs being used by voters, using any of these methods, could seriously compromise the results, Wagner said.
"SERVE is susceptible to large-scale election fraud that could be launched from outside the reach of U.S. law and go completely undetected," he said.
For instance, it would be relatively easy for malicious hackers to insert spoofed Web pages that appear to belong to the SERVE system but are actually designed to alter votes or prevent them from being cast. A voter using a PC infected with a virus or worm could easily jeopardize the integrity of the system, Wagner said. And the particularly dangerous part is that such hacks could be carried out without ever being detected.
"I think that a dedicated and experienced hacker could subvert the election rather easily," said Avi Rubin, a professor at Johns Hopkins University and one of the security experts that reviewed SERVE. "I don't think that Internet-based voting such as SERVE can be made secure enough for use until we can develop computer systems that are not vulnerable to viruses and Trojan horses, and until we can develop an Internet that is resistant to denial-of-service attacks."
The full report is available online at http://www.servesecurityreport.org.
The two other members of the team

Continued...
1 | 2 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
Mozilla updates Firefox 3.1 with Alpha 2 build
Microsoft explains Seinfeld-Windows TV ad: just a 'teaser'
Mozilla: Firefox is faster than Chrome
More top stories...
iPhone 3G owner sues Apple, AT&T over dropped calls, app crashes
At 10, Google reiterates commitment to CIOs
Analysts: Google spreading itself too thin
Users of Windows XP SP3 who try out IE8 Beta 2 won't be able to uninstall either one under certain circumstances.
Google has gone from innovative upstart to fat-and-happy industry leader in what seems like record time. Preston Gralla explains.
Microsoft's latest beta of IE8 includes better tab management, new services such as Web Slices and Accelerators, and the new 'porn mode.'
These leading-edge graduate schools are moving at the pace of the IT workplace, delivering coursework that's relevant to today's IT professionals.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
Identity & Security Management Zone

Ads by TechWords

See your link here
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary live webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Online Security Issues in Regulated Industries
Download this research paper, free for a limited time, compliments of Webroot!
(Source: Webroot Software) In June 2008, Computerworld invited IT and business leaders to participate in a survey on online security initiatives at their organizations. The goal of the survey was to better understand Web and e-mail security issues faced today within the regulated education, financial services, government and health care industries. The following report represents top-line results of that survey.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Death to PST: Hidden Cost of Email Mismanagement
Extend, Replace, or Convert; which is the best way forward for COBOL Applications?
The Trend from Unix to Linux in SAP Data Centers
View more whitepapers