YAIVST (yet another internet voting sucks thread)

Status
Not open for further replies.

techs

Lifer
Sep 26, 2000
28,559
4
0
http://www.computerworld.com/s/arti...ng_flaw_could_have_led_to_compromised_ballots

D.C. Web voting flaw could have led to compromised ballots
Flaw in Digital Vote by Mail system let ballots be accessed, modified, replaced.


Computerworld - A major security flaw in D.C.'s new Digital Vote by Mail system allowed researchers to access, modify and completely replace marked ballots in the system.

The flaw was discovered by security researchers at the University of Michigan during public tests of the system last week, a discovery that prompted election officials in the District of Columbia to scale back their use of a Web application for overseas voters in next month's elections.

The ability to change ballots was one among several issues discovered during the tests, which are scheduled to go on until the end of this week.

According to Alex Halderman, an assistant professor of computer science at the University of Michigan, the flaw allowed the researchers to access the database username and password and the public key used to encrypt ballots. In addition, researchers found they could install a backdoor on the server for viewing and recording votes and the names of those who cast them, Halderman said in a blog post yesterday.

To show they had complete control of the system, the researchers even tweaked the application so that voters would be greeted with the University of Michigan fight song when they landed on the vote confirmation page.



At this point they should just give it up. No one can make a secure internet voting system.
 
Status
Not open for further replies.