Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

In photos: Security experts, vendors face off on e-voting

Researchers suggested attackers could alter voting results undetected; vendors defended system safety
 

Sign up to receive Security Resource Alerts

May 07, 2004 (Computerworld) -- The U.S. Election Assistance Commission, established by Congress to study ways to improve the voting process in light of problems in Florida and elsewhere during the 2000 presidential election, held its first public hearing in Washington on May 5. The commission heard two very different perspectives on security from a panel of independent university researchers and from executives representing IT vendor companies that manufacture electronic voting systems.









Seen here are (from left) Alfie Charles, vice president of business development at Sequoia Voting Systems; William F. Welsh, a board member of Election Systems & Software Inc.; Kevin Chung, founder and CEO of Avante International Technology Inc.; Mark Radke, director of marketing at Diebold Election Systems; and Neil McClure, general manager of Hart Intercivic Inc.














Kim Brace, president of Election Data Services Inc., opened the hearing by providing a historical overview of voting equipment usage in the U.S. According to Brace, a 2004 survey showed that 675 counties in more than half of the states use electronic voting systems. This amounts to almost 50 million registered voters, or 30% of all registered voters. However, 22 million voters still use some form of punch cards, similar to those used in Florida during the 2000 presidential election, and 1 million voters still use paper ballots. Avi Rubin, a professor at the Johns Hopkins University Information Security Institute, is the leading figure among a group of computer security researchers who have uncovered significant vulnerabilities in the electronic voting systems (download PDF file, "Analysis of an Electronic Voting System"). According to Rubin, without voter-verifiable paper receipts, the 50 million Americans who will use electronic voting machines in the upcoming election will have no way of knowing if their votes were recorded properly. Even worse, the code base powering the software in the systems is so large and complex that there is little way for election officials to know for sure that it is free of malicious code designed to manipulate election results.













"My biggest concern is that in a very large trusted-computing base, the threat of somebody with access to the development environment of the code base, particularly the vendor, basically is in position to make the outcome of the election come out how they would like, and it's virtually undetectable," said Rubin. "The trusted computing base is approximately 50,000 lines of computer code sitting on top of tens of millions of lines of [operating system] code. It is impossible to secure such a large trusted-computing base.

"There's no way to publicly count the vote," added Rubin. "The counting is going on inside the computer. In the case of a controversial election, there are laws in some states that require the ability to do a recount, a meaningful recount. With fully automated computerized voting equipment, there's no way to do any kind of a meaningful recount. You can just reprint the results and get exactly the same results again."

When Rubin and his students studied the Diebold machines, they found "gross, gross security and programming errors," he said.
Ted Selker, a professor at MIT and former IBM fellow who heads the MIT Media Lab's Context-Aware Computing group, said there are methods available to counter the vulnerabilities identified by Rubin. However, encryption would be too difficult to deploy by the November election, he said.

However, Rubin said that the worst thing "is that I'm constantly asked, 'How do the other vendors compare to Diebold?' I have to say, 'I don't know, because I can't get access to their code.' If people who have security expertise are prohibited from getting access to them, then our public is left wondering what is being hidden."













Selker also told the commission that in some cases, registration databases remain full of errors -- a situation that led to between 1.5 million and 3 million votes being lost during the 2000 election. "We don't have any way of checking how many New Yorkers are also registered in Florida," said Selker. "I don't know of any changes that have been made, systemically, as a result of the well-reported problems in Florida in 2000." Stephen Berger, chairman of the standards coordinating committee of the IEEE, said it is important to focus on developing systems that are secure, accessible to people with disabilities and affordable to the jurisdictions that are going to buy them.

The first national standards for voting equipment were established in 1990 and updated in 1998 and again in 2002. Berger was questioned by commission Chairman DeForest Soaries Jr. about the failure to mention in the 2002 update the advantage of requiring systems to provide paper-based verification. Berger said that it was likely a minor oversight but that it is necessary to "fully engage" vendors in the specification process for standards.













Brit Williams, a professor at Kennesaw University in Georgia, said there are other elements besides security that must be considered when developing a new electronic voting system. "We have to look at availability, reliability, maintainability, usability and even affordability," said Williams.

Williams recommended establishing a nationwide secure voting system software laboratory similar to the one established by the National Institute of Standards and Technology that is used to certify security for law enforcement software. "They [would] compute a hash signature on [submitted software], and that signature can be used in a court case or in a challenge to verify that [the] software that's in use in the field is in fact unaltered from the software that's in the source library," he said. "We do that in Georgia, and we run signatures against the installed software to verify that it has not been altered from the software that was certified."
Neil McClure, general manager of Hart Intercivic in Austin, said product changes should be based on risk assessments, not solely on the existence of vulnerabilities. He discounted the threat of electronic tampering, saying it would require a long-term commitment by a well-motivated attacker.

"In Orange County, Calif., for example, there are 2,200 precincts, 1,723 polling places, five languages and ballot rotation on top of that," said McClure. "It's a hugely complex problem just to get it right."














Mark Radke, director of marketing at Diebold Election Systems, called the "questions and doubts raised" by Rubin and other researchers "theoretical in nature."

"What's been missing from these laboratory-originated critiques has been the real-world experience of the voting booth," said Radke. "The March Super Tuesday election tells a compelling story: zero security-related problems at the more than 55,600 Diebold touch-screen stations deployed around the country."
Kevin Chung, founder and CEO of Avante International Technology, said his company developed a voter-verifiable paper system not because of security concerns, but primarily to confirm to the voters how their votes were counted and that they were counted correctly.

"However, if [electronic] voting systems are to be used, voter-verifiable paper audit trail is the only reasonable means to assure security," said Chung. "It helps to expose all errors or tampering during and after the ballot has been stored in electronic memory." He added, however, that it still doesn't replace the need for good processes for auditing.













William F. Welsh, board member of Election Systems & Software, said that his company has contracts to install more than 50,000 e-voting systems and that 50% of all registered voters currently use an ES&S system.

Electronic voting systems have "made the election process easier, more accessible and certainly, in many cases, more fun," said Welsh. "It's also been made more reliable. When it comes to capturing voter intent, electronic voting has no equal."

However, Welsh acknowledged that because of the newness of the technology, "some are questioning the security of today's electronic voting options." As a result, the response should be rational and proportional to the probability of the threats, he said. "No one would buy a safe that could be easily opened, but everybody buys a safe that can be cracked," said Welsh. "The same is true for voting systems. The issue is not if they are secure, but if they present barriers that are sufficiently formidable to give us confidence in the integrity of the process."



All photos by Dan Verton.




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"It's IT Blogwatch: in which Grisoft, maker of the AVG anti-virus package, backs down in its attempt to DDoS the..." Read more...
Read more Security posts or See all Blogs
Google gives away home-cooked Web application security scanner
HP eyes move of support facilities out of Colorado Springs
Microsoft trumpets security additions in upcoming IE8
More top stories...
How much is too much? Upgrade your notebook without going over the line
French ruling on counterfeit goods could have far-reaching effects for eBay
Apple cuts price of high-end SSD MacBook Air by $500
All it takes is a couple hours and about $125 to breathe new life into an old laptop. Here's how.
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
There are some things your CIO definitely doesn't want to hear. Also don't miss the flipside, Five things you should always tell your boss.
With its latest version, Mozilla's browser continues to raise the bar for what Web browsers should be.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this webcast, free, compilments of Webroot Software
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Eliminate SPAM, Gain Productivity
Get this white paper now!
(Source: MessageLabs) Learn all about the dangers and the costs of spam in all its forms - from stock-touting to spreadsheet. Also, understand the drawbacks of traditional hardware- and software-based defenses - and the unique benefits of MessageLabs multi-layered, managed Anti-Spam solution; as illustrated by a real-world case study where MessageLabs stopped spam cold.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Deploying Virtualized NetWare on Linux Whitepaper
Toward More Flexible, Next-Generation Collaboration Solutions
Driving Business Success Through Workgroup Choice and Flexibility
View more whitepapers