California Reviews… And Decertifies… More ES&S E-Voting Machines

from the a-lesson-in-weak-security dept

Remember how e-voting firm ES&S was so against letting California’s Secretary of State have an independent security team review their e-voting machines? Well, now we know why. The state had already released one damning security report and sued ES&S for giving the state uncertified machines. Now the state has come out with another report on more ES&S machines and the story gets worse and worse and worse. The good news is that California won’t certify any of them. The bad news is that ES&S appears to not only be belligerent in not wanting to let California review its machines, but it also seems to be incompetent as well. As Dan Wallach notes in reviewing the report, ES&S appears to have outright ignored issues that the state asked them to address. As for the machines themselves? There seem to be all sorts of problems, including an awful lot of data stored in cleartext rather than encrypted, easily accessible and easily changed or corrupted data, and seldom-used and easily-broken password protection. Physical locks were all easily picked (some within 5 seconds, the rest within a minute). In other words, the security is a near total joke. This, despite the fact that people have been pointing out these kinds of security concerns for over five years. I wonder if the guy from ES&S who showed up a year ago and told us all we had no clue what we were talking about and swearing up and down that the machines were safe will come back and explain these latest results.

Comments on “California Reviews… And Decertifies… More ES&S E-Voting Machines”

Rusty Shackleford says:

Dont think E-voting will ever work

besides the troubles in the technology… the people running the countries are so dirty that even when you have the best guy in the world running for office… you wouldnt know it because he sounds like all the rest… and thatsa real shame for the people. Getting these machines into the voting process only creates the opportunity for more underhanded events to happen… such as recounts are useless… the number is the number… and that can be changed by whoever sees fit to change it… I would love to see evoting work… I just dont think, in t5his dishonest world it will ever work to the satisfaction of the people

Donald King (user link) says:

Re: Are Automated Teller Machines secure?

ATMs are in a different category than voting machines. If an ATM has a security flaw, the bank knows who owns what account and which ATM was used when, and both you and the bank have all the paper records you’ll ever need.

With voting, anonymity is a very important goal. If the voting machine prints out perfectly accurate receipts that you can use to double-check how your vote was counted, then (employers|union bosses|mobsters|etc.) can threaten you into voting for the “right” candidate. So a voting machine is almost the exact opposite of an ATM.

