California Reviews... And Decertifies... More ES&S E-Voting Machines
from the a-lesson-in-weak-security dept
Remember how e-voting firm ES&S was so against letting California's Secretary of State have an independent security team review their e-voting machines? Well, now we know why. The state had already released one damning security report and sued ES&S for giving the state uncertified machines. Now the state has come out with another report on more ES&S machines and the story gets worse and worse and worse. The good news is that California won't certify any of them. The bad news is that ES&S appears to not only be belligerent in not wanting to let California review its machines, but it also seems to be incompetent as well. As Dan Wallach notes in reviewing the report, ES&S appears to have outright ignored issues that the state asked them to address. As for the machines themselves? There seem to be all sorts of problems, including an awful lot of data stored in cleartext rather than encrypted, easily accessible and easily changed or corrupted data, and seldom-used and easily-broken password protection. Physical locks were all easily picked (some within 5 seconds, the rest within a minute). In other words, the security is a near total joke. This, despite the fact that people have been pointing out these kinds of security concerns for over five years. I wonder if the guy from ES&S who showed up a year ago and told us all we had no clue what we were talking about and swearing up and down that the machines were safe will come back and explain these latest results.
9 Comments | Leave a Comment..
- Sad Statement: Senators Behind Two Largest Tech Communities In The US Support PIPA Against Those Communities
- Copyright Tourism: Korean Companies Sue Guy From Australia For Copyright Infringement... In California
- Senator Dianne Feinstein: So Out Of Touch, She Doesn't Realize Tech Companies Are Vehemently Against PROTECT IP
- Why Isn't There A Central Database Of E-Voting Problems?
- Did South Carolina Use Second-Hand E-Voting Machines That Louisiana Decertified?





Reader Comments (rss)
(Flattened / Threaded)
[ reply to this | link to this | view in thread ]
I guess not.
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
follow the yellowbrick road...
[ reply to this | link to this | view in thread ]
Dont think E-voting will ever work
[ reply to this | link to this | view in thread ]
Are Automated Teller Machines secure?
[ reply to this | link to this | view in thread ]
Re: Are Automated Teller Machines secure?
[ reply to this | link to this | view in thread ]
Re: Are Automated Teller Machines secure?
With voting, anonymity is a very important goal. If the voting machine prints out perfectly accurate receipts that you can use to double-check how your vote was counted, then (employers|union bosses|mobsters|etc.) can threaten you into voting for the "right" candidate. So a voting machine is almost the exact opposite of an ATM.
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Add Your Comment