this post was submitted on 24 Jan 2024
139 points (96.6% liked)

Technology

59678 readers
4133 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Computer scientist shows how to tamper with Georgia voting machine, in election security trial: “All it takes is five seconds and a Bic pen.”::An expert witness for plaintiffs seeking to bar Georgia's touchscreen voting machines showed a crowded courtroom how he could tamper with election res

top 31 comments
sorted by: hot top controversial new old
[–] SnotFlickerman@lemmy.blahaj.zone 67 points 10 months ago* (last edited 10 months ago)

https://citp.princeton.edu/our-work/voting/

https://www.youtube.com/watch?v=ZVWIOwSkMew

What's really sad is this is literally the same guy who proved the same thing in 2006. (I'm going on a limb and assuming this is the same J. Alex Halderman who wrote this paper at Princeton)

This has been an ongoing problem for almost twenty fucking years.

I went looking for this info because it spurred a memory. The "bic pen" was a part of this hack nearly 20 years ago, and the reference to it made me remember the original.

Fucking travesty.

[–] stoy@lemmy.zip 48 points 10 months ago (3 children)

I have said it before and I'll say it again, electronic voting does not work and is a bad idea.

The election system is dependant on trust, trust that the votes are not changed nor counted incorrectly.

This works with paper ballots, you keep the ballot box sealed and under observation by observers from different parties, they can then verify that the ballots have not been changed after voting, you count the ballots together, in front of everyone, they can then verify that counting was done correctly.

With electronic voting the votes are cast by interacting with buttons on a black box, no one is able to verify that the votes are recorded correctly nor that they are counted correctly during the actual election.

[–] fidodo@lemmy.world 29 points 10 months ago (2 children)

In California we have electronic voting machines that are basically glorified printers. You go through the vote flow, then it prints your ballot and you can verify it's correct before it goes in the ballot box. All the upside of electronic voting and none of the downsides. Since it's printed consistently it's easier to electronically count as well without mistakes that can happen from scanning hand filled ballots. Even human vote counters can mistakenly read a hand filled ballot.

[–] Grellan@lemm.ee 6 points 10 months ago (2 children)

That's how it is in Georgia to. You make your selection, receive a print out which has your chooses visible on kt, put that into the counting machine which is next to a table where you get your I voted sticker so it's monitored for tampering. They then take your print out and put it in a box for manual recounts if called for.

[–] Waldowal@lemmy.world 3 points 10 months ago (1 children)

But don't you then put it into a scanner that actually tallies the votes? The paper exists, but my understanding is it's not a hand count. There is still opportunity to manipulate the scanner.

[–] Passerby6497@lemmy.world 5 points 10 months ago

But you still have the paper ballot so that when it's time for a recount you can validate the electronic and paper copies match.

[–] kalpol@lemmy.world 2 points 10 months ago

How it is in Texas too.

[–] stoy@lemmy.zip 2 points 10 months ago

That is fine, and a good usecase

[–] yuki2501@lemmy.world 19 points 10 months ago (1 children)
[–] bionicjoey@lemmy.ca 5 points 10 months ago (2 children)
[–] SnotFlickerman@lemmy.blahaj.zone 5 points 10 months ago

And also literally the guy from the OP article, who is the same guy who first demonstrated this kind of hack in 2006.

[–] PipedLinkBot@feddit.rocks 1 points 10 months ago

Here is an alternative Piped link(s):

https://www.piped.video/watch?v=w3_0x6oaDmI

https://www.piped.video/watch?v=LkH2r-sNjQs

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I'm open-source; check me out at GitHub.

[–] Steve@communick.news 8 points 10 months ago* (last edited 10 months ago)

I like the system we have in New Mexico. (Yes it's one of the 50 states)

You can go to any poling place, and they print you a local ballot for where you live, right there. You fill in the bubbles with your choices, then run it through a scanner machine on your way out.

You get instant counting and can track results live all day. If there's a technical problem, or any uncertainty in the results, you can always go back to the paper and hand count.

It gives the benefits of all the options.

[–] bionicjoey@lemmy.ca 40 points 10 months ago (2 children)

It scares the shit out of me that the US has so fully adopted voting machines. They are incredibly unreliable and it would be so easy for a bad actor to hack an election. Especially with FPTP, it would be so easy to goose the numbers in a couple of key districts and swing an election for whomever you wanted to win. It's almost definitely already happened several times.

In Canada we still do voting on paper, but then the votes are counted electronically and the paper copy is kept for recounting by a human later if needed. It's sort of the best of both worlds.

[–] evatronic@lemm.ee 11 points 10 months ago

It's not everywhere.

States that do vote by mail are just like you describe -- paper ballots collected and counted by computer, with the paper preserved.

[–] fubarx@lemmy.ml 4 points 10 months ago

Not all states are fully electronic. Many districts (including mine) are run on paper ballots that are then scanned.

I would be more concerned about the upstream tabulation systems. The possibility of making bulk changes is much more harmful than tampering with single voting machines.

There was a mad dash to electronic voting after the Bush v Gore hanging chad fiasco. A lot of people are still focusing on the voting machines vs. the integrity of centralized tabulation systems.

[–] AdmiralShat@programming.dev 22 points 10 months ago

Anyone who knows even the slightest bit about how computers work know this is a bad idea.

[–] beefontoast@lemmy.world 13 points 10 months ago (2 children)

What is the gdpr reason this website is not available to users in Europe?

[–] Porcupirate@lemmy.world 24 points 10 months ago (1 children)

I believe some websites say “fuck it, fuck them” and block European IPs rather than put in the work to become GDPR compliant

[–] 7heo@lemmy.ml 2 points 10 months ago
[–] robocall@lemmy.world 6 points 10 months ago (3 children)
[–] NegativeInf@lemmy.world 21 points 10 months ago

Huddled around a voting machine in a federal courtroom, a small crowd watched as expert witness Alex Halderman demonstrated how someone could meddle with a Georgia election within seconds.

Halderman, a University of Michigan computer scientist, changed results of a hypothetical referendum on Sunday alcohol sales. He flipped the winner in a theoretical election between President George Washington and Benedict Arnold, the Revolutionary War general who defected to the British. He rigged the machine to print out as many ballots as he wanted.

All he needed was a pen to reach a button inside the touchscreen, a fake $10 voter card he had programmed, or a $100 USB device that he plugged into a cord connected to a printer, rewriting the touchscreen’s code.

Halderman delivered his presentation during an election security trial evaluating whether Georgia’s voting system is vulnerable to manipulation or programming errors. All in-person voters in Georgia make their choices on touchscreens that print out paper ballots.

Election officials countered Halderman’s testimony with assurances that real-world elections in Georgia have never been hacked and security precautions prevent the possibility of interference.

“All of these things worry me — just how easy these machines would be to tamper with. It’s so far from a secure system,” Halderman testified Thursday. “There are all kinds of politically motivated actors that would be eager to affect results.”

Under questioning from attorneys defending Georgia’s Dominion voting equipment, Halderman said there’s no evidence that the vulnerabilities he showed have ever been exploited in an actual election.

Through eight days of the trial, attorneys for the liberal-leaning Georgia voters and activists who are plaintiffs in the case have tried to convince U.S. District Judge Amy Totenberg that she should order the state to prohibit further use of the voting touchscreens as the 2024 elections approach. Voters would instead fill out paper ballots by hand.

Testimony in the case included evidence about the January 2021 breach in Coffee County, when tech experts hired by supporters of Donald Trump copied Georgia’s election software, then distributed it to conspiracy theorists across the country. The plaintiffs have also sought to prove that the secretary of state’s office hasn’t done enough to protect election security and voters’ rights.

But State Election Board member Matt Mashburn told the judge that hacking would be difficult to pull off during an election.

Credit: arvin.temkar@ajc.com

“There are serious potentialities. Now, how practical they are to put in place is a different question,” Mashburn said Wednesday, according to a court transcript.

Flaws in voting machines would be difficult to exploit at more than one voting machine at a time, minimizing the potential danger, he said.

“I just didn’t think it was realistic,” Mashburn said. “Is it something you’ve got to change the whole system for? ... I just don’t believe that is very likely. It is possible, but it is not very likely.”

Halderman testified that he discovered vulnerabilities after he was given access to a Fulton County touchscreen, called a ballot-marking device, as an expert witness in the case. He reported his findings to the U.S. Cybersecurity and Infrastructure Agency, which validated the technology weaknesses in June 2022.

Election officials have said Georgia’s voting equipment is secured by locks and seals, poll workers overseeing precincts, preelection testing and audits of paper ballots.

Halderman said a wrongdoer, hidden behind a privacy screen at a voting precinct, wouldn’t necessarily be caught by election workers. Changing a touchscreen’s programming would take seconds or minutes but potentially create “chaos” in a major election, when it would be difficult to determine which ballots were legitimate, he said.

It isn’t necessary to open up a voting machine or remove security seals to gain “superuser” access to a touchscreen and change its programming, Halderman testified. Any voter could bring a forged voter card, pen or USB drive loaded with malicious code to a voting machine.

In one of Halderman’s hacks, the text on the ballot would reflect the candidate the voter picked, but the computer QR code counted by a ballot scanner would count the opposite choice. Georgia lawmakers are considering legislation that would remove QR codes from ballots.

The vulnerabilities Halderman showed in court would only affect one voting machine at a time, but he also testified that many more votes could be changed if someone gained access to election management servers overseen by state and county election officials.

Attorneys for Secretary of State Brad Raffensperger, the defendant in the case, contend that the mere possibility of election tinkering doesn’t amount to a violation of voting rights protected by the U.S. Constitution, such as free speech and equal protection rights.

“Plaintiffs have failed to produce a single shred of evidence to substantiate the supposed ‘risks’ they fear,” a court filing by the defendants states. “There is no evidence that their ballots or any ballots cast using a BMD (ballot-marking device) were not accurately counted or that any vote has been changed. ... Weighing risk is a political and not judicial decision.”

Witnesses for the defendants this week will attempt to dispute the plaintiffs’ allegations with testimony from Georgia election officials and cybersecurity experts.

The case will be decided by Totenberg, who was appointed by President Barack Obama, in the weeks after the trial concludes

[–] Ghostalmedia@lemmy.world 11 points 10 months ago (1 children)

Give me 5 seconds and a bic pen. I’ll get it open.

[–] ada@lemmy.blahaj.zone 7 points 10 months ago (1 children)
[–] Ghostalmedia@lemmy.world 8 points 10 months ago (1 children)

Please, call me Richard Dean Anderson

[–] JaymesRS 2 points 10 months ago

I think you’re thinking of Col. Jack O’Neill.

The 2 “L”s are important, you wouldn’t want to confuse him with Col. Jack O’Neil.