Wednesday, November 30, 2005

Update on Secretary of State's security test plans

The attempted hack of a Diebold voting system will not take place today, as previously reported. The terms of the test are still being negotiated. It's my understanding that the Secretary of State's office has been in touch with Finnish programmer Harri Hursti to make the arrangements. More details are featured in Monday's Alameda Newspaper Group story by Ian Hoffman. Excerpts are below.


Back in May, voting activists went on the Internet and for $300 apiece purchased two devices used to record moisture levels in corn.

Certain corn scanners use the same memory cards as Diebold Election Systems' optical scanning machines for ballots and can easily modify them. That makes corn scanners a tool for vote hacking.

Sitting by a hotel pool last spring in Florida, Finnish computer expert Harri Hursti wrote his own program on a memory card so it could alter poll results on a Diebold machine in Leon County and flash a screen message -- "Are we having fun yet?" -- that shocked the local elections supervisor.

Prodded by activists with nonprofit Black Box Voting, California elections officials have agreed to a test hack of the Diebold voting machines running in 17 of its counties, from San Diego to Los Angeles and Alameda to Humboldt.

The test, first reported by The Daily Review last week, originally was scheduled for Wednesday but will likely be delayed until mid-December.


If Hursti or another computer expert succeeds in hacking Diebold's voting machinery, the McKinney, Texas, firm could be forced to redesign software fundamental to each major component of its voting system. Securing new state and federal approvals would bring delay and loss of sales that the company is counting on before next June's primary.

Counties face Jan. 1 state and federal deadlines for acquiring new, handicapped-accessible voting systems that also offer some form of paper record. Those counties relying on Diebold might turn to other voting-system makers.

As a result, there have been extensive, ongoing negotiations between Black Box Voting and the California secretary of state's office, which also is talking to Diebold, about conditions of the test, confidentiality of the results and measures of success. The talks continued over the weekend, but state officials said they remain committed to performing the test.

"Secretary (Bruce) McPherson takes testing these systems very seriously," said his spokeswoman Nghia Nguyen Demovic. "He wants safeguards in place so that every vote cast is secured. He's doing his due diligence to assure voter confidence."

Last week state officials said they will select the voting equipment at random from a California county using Diebold.

Hacking strategies can be caught by recounting the ballots. California law requires a recount in 1 percent of precincts after every election. But in Los Angeles County and other jurisdictions, elections officials do not recount absentee ballots, which are mailed in and scanned at election offices. Absentee ballots are more than a third of the vote in California and in several counties more than half of the vote.

"You just tamper with the GEMS database for the absentee vote, and then if you exclude the absentees from the one percent recount then you completely own the process," said Jim March, a board member of Black Box Voting. The hacks -- there are two -- are almost elegantly simple.

No comments:

Post a Comment