Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

USENIX ;login: Voting Machine Security Analysis

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Triana Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Dec-13-03 01:24 PM
Original message
USENIX ;login: Voting Machine Security Analysis
Analysis of the Electronic Voting System:

The speaker discussed his and Avi Rubin's experiences auditing the source code of a widely used voting machine.

Among the issues they discovered were that key management is handled by a single #define DES_KEY "XXXX" in the code, where "XXXX" is an ASCII string; this key appears to be the same across all instances of the machine.

Another issue was that the code did not appear to have been audited at all for correctness or security; long stretches of code appear without any comments whatsoever.

Audit features in the code were extremely weak; while changes do appear in an audit log, nothing seems to protect the log itself from being changed.

In response to a write-up on these issues, the company claimed that the "voting system works exactly as designed."

?

One audience member asked if source code was still available. The speaker replied that it was the last time he checked.

http://www.avirubin.com/vote

Printer Friendly | Permalink |  | Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC