# audit finds voting machines used in three states were breathtakingly easy to hack

**URL:** https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782
**Category:** Politics & Elections
**Created:** [April 15, 2015, 9:45pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782 "2015-04-15T21:45:53Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)
#### Post date: [April 15, 2015, 9:45pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/1 "2015-04-15T21:45:53Z")

</div>

From [Ars Technica](http://arstechnica.com/tech-policy/2015/04/meet-the-e-voting-machine-so-easy-to-hack-it-will-take-your-breath-away/):

> [@Terrifying Article](#):
>
> Virginia election officials have decertified an electronic voting system after determining that it was possible for even unskilled people to surreptitiously hack into it and tamper with vote counts.
> 
> The AVS WINVote, made by Advanced Voting Solutions, passed national Voting Systems Standards and has been used in Virginia and, until recently, in Pennsylvania and Mississippi. It used the easy-to-crack passwords of “admin,” “abcde,” and “shoup” to lock down its Windows administrator account, Wi-Fi network, and voting results database respectively, according to a scathing security review published Tuesday by the Virginia Information Technologies Agency. The agency conducted the audit after one Virginia precinct reported that some of the devices displayed errors that interfered with vote counting during last November’s elections.

From the [report (PDF)](http://elections.virginia.gov/WebDocs/VotingEquipReport/WINVote-final.pdf) on the state website:

> [@Terrifying Report](#):
>
> During a recent election, one precinct in Virginia reported unusual activity with some of the devices used to capture votes. The devices were displaying errors that interfered with the ability to collect votes. In order to diagnose the problem, the Department of Elections (ELECT) initiated a review of the devices to identify the cause of the problems. As part of the review, ELECT engaged Commonwealth Security and Risk Management staff in the Virginia Information Technologies Agency (VITA) to perform a security analysis of the devices.
> 
> As a result of the findings included in this report, VITA recommends discontinuing use of the Advanced Voting System WINVote devices. The security review determined that the combination of weak security controls used by the devices would not be able to prevent a malicious third party from modifying the votes recorded by the WINVote devices. The primary contributor to these findings is a combination of weak security controls used by the devices: namely, the use of encryption protocols that are not secure, weak passwords, and insufficient system hardening.
> 
> Security deficiencies were identified in multiple areas, including physical controls, network access, operating system controls, data protection, and the voting tally process. The combination of critical vulnerabilities in these areas, along with the ability to remotely modify votes discretely, is considered to present a significant risk. This heightened level of risk has led VITA security staff to conclude that malicious third party could be able to alter votes on these devices. These machines should not remain in service.

I’m not sure how long these machines were in use, or in how many precincts. But, wherever these machines were in use, someone with not a lot of skill could sit in the parking lot, access the machines, change votes, and probably never be detected. I especially love that the machines recorded votes in MS Access databases. Look, I made my living as an Access developer for years. Access is awesome for some things. But not for _running a damn election!_

The audit also found that there were USB ports exposed on the exterior of the machine and you could easily boot to removable media. Once you do that, you can do all kinds of fun stuff to the data. Someone walking in off the street would probably be detected trying to boot to removable media while he was in the booth. But election workers would have all the time they wanted. Take a machine out of rotation, upvote your candidate, done.

Is there any evidence of vote tampering where these machines were used? No. But, then there wouldn’t be, since there was almost no logging and no effective integrity checking in place.

So, raspberries all around to Advanced Voting Solutions and to election officials in Virginia, Pennsylvania, and Mississippi. Way to handle the mechanism of our democracy, guys.

---

<div class="post-metadata">

### Author: ![Smapti](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/smapti/32/17938_2.png) [@Smapti](https://boards.straightdope.com/u/Smapti)
#### Post date: [April 15, 2015, 9:48pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/2 "2015-04-15T21:48:39Z")

</div>

Gee, isn’t it such a _good thing_ that we all immediately demanded electronic voting machines in the wake of 2000?

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [April 15, 2015, 10:10pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/3 "2015-04-15T22:10:50Z")

</div>

> [@Smapti](#):
>
> Gee, isn’t it such a _good thing_ that we all immediately demanded electronic voting machines in the wake of 2000?

Since all electronic voting systems are the same, with identical problems and benefits? Is that what you are implying?

---

<div class="post-metadata">

### Author: ![doorhinge](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@doorhinge](https://boards.straightdope.com/u/doorhinge)
#### Post date: [April 15, 2015, 11:18pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/4 "2015-04-15T23:18:50Z")

</div>

Since every computer can be hacked, and very few people, let alone your average poll watcher, have the ability to uncover altered software, I am not in favor of using electronic voting machines, regardless of who manufactured, or is supplying the machines.

Pencil and paper ballots work just fine. They just take longer to count, but the politicians aren’t expected to take or leave office the day after the election.

---

<div class="post-metadata">

### Author: ![BrotherCadfael](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@BrotherCadfael](https://boards.straightdope.com/u/BrotherCadfael)
#### Post date: [April 16, 2015, 1:07am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/5 "2015-04-16T01:07:02Z")

</div>

The old mechanical voting machines were often delivered to polling places in Chicago with a couple of thousand votes already recorded.

Nothing new under the sun.

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [April 16, 2015, 1:54am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/6 "2015-04-16T01:54:56Z")

</div>

> [@doorhinge](#):
>
> Since every computer can be hacked, and very few people, let alone your average poll watcher, have the ability to uncover altered software, I am not in favor of using electronic voting machines, regardless of who manufactured, or is supplying the machines.
> 
> Pencil and paper ballots work just fine. They just take longer to count, but the politicians aren’t expected to take or leave office the day after the election.

That’s why separate machines should be used for recording and tallying, with a paper ballot record which can be easily recounted.

---

<div class="post-metadata">

### Author: ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)
#### Post date: [April 16, 2015, 3:24am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/7 "2015-04-16T03:24:27Z")

</div>

Question: why in the world would a voting machine given an admin the ability to change vote totals? Something is fishy here. I’m an admin at my job and there are only so many things that are customizable. I can’t go in and change sales numbers. If I had access to the code I could screw with it by changing how sales are calculated, but uncompiled code wouldn’t be on a voting machine. In any system worth a damn, you can only change things that are meant to be changed, such as logins, permissions, inventory, prices, etc. Stuff that isn’t supposed to be edited, but is what it is once calculated, you can’t just go in and change.

So if admins can change vote totals, even if it’s not hackable, WTF? Why would we trust even admins with the completely unnecessarily ability to change vote totals? There’s just no reason an admin needs to ever be able to do that.

---

<div class="post-metadata">

### Author: ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)
#### Post date: [April 16, 2015, 3:36am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/8 "2015-04-16T03:36:01Z")

</div>

A Windows admin account is different from an admin account in a (properly designed) application. A Windows admin account by definition has access to everything. The type of admin account that you’re talking about is specific to your sales application and is separate from the accounts in the operating system itself. If somebody logged into the operating system that your sales data lives on as an admin, they could change whatever they like.

---

<div class="post-metadata">

### Author: ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)
#### Post date: [April 16, 2015, 3:45am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/9 "2015-04-16T03:45:57Z")

</div>

This can be demonstrated with simple BASIC code:

10 IF VOTE$=“JOHN KERRY” THEN KERRY=KERRY+1  
20 IF VOTE$=“GEORGE BUSH” THEN BUSH=BUSH+1  
30 PRINT KERRY  
40 PRINT BUSH

There is no way to alter the output of that code without changing the code itself. Unless I add code allowing such editing. Which would be crazy.

I actually created a simple thing like that for a school in 2004 that wanted to hold a mock election for the students. Took all of ten minutes and the only ability the admin had was to turn it on or off.

---

<div class="post-metadata">

### Author: ![TimeWinder](https://avatars.discourse-cdn.com/v4/letter/t/bcef8e/32.png) [@TimeWinder](https://boards.straightdope.com/u/TimeWinder)
#### Post date: [April 16, 2015, 4:00am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/10 "2015-04-16T04:00:18Z")

</div>

> [@adaher](#):
>
> There is no way to alter the output of that code without changing the code itself. Unless I add code allowing such editing.

Sure there is. Just off the top of my head: (1) exploit a buffer overrun in another process to write over the count location of the variable’s memory. (2) exploit an elevation of privilege to “lock” one of the memory locations. (3) Insert a dongle between the keyboard and the computer that changes “JOHN KERRY” to “GEORGE BUSH.” (4) Modify the display driver to add a few digits after the string “GEORGE BUSH” before printing a number. (5) Modify the display driver to ignore the running app and replace it with whatever outcome you want. (6) Have an entirely separate program raise itself in front of yours and do whatever the heck it wants. (7) Combine several of the above to force the vote count memory locations to “roll over” by granting it lots of extra votes. (8) Modify the loader for applications to initialize memory to something other than zero.

Heck, your program is buggy all by itself once you exceed the number of votes than an integer can store and you get an overflow.

I’ve fixed or hardened code against all of those sorts of attacks and many more in the last few years – security is hard, and “I could knock this off in ten minutes” comments expose more ignorance than skill (ignoring the use of BASIC, which doesn’t help that case, either). Hacking programs isn’t done by “changing the code itself” and recompiling; it’s done by seemingly innocuous things _around_ the program modifying the environment in which it runs.

---

<div class="post-metadata">

### Author: ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)
#### Post date: [April 16, 2015, 4:05am UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/11 "2015-04-16T04:05:26Z")

</div>

What you cited are methods other than just “going in and changing vote counts” by an unskilled person, which is what the article said was possible. I used the code not to demonstrate security(anyone who knows BASIC and can hit BREAK can alter the code easily), but to demonstrate that the designer of an application controls what even an admin can alter. Companies do not just put sales data in a database that a CEO or whoever can then just change to something they prefer to show to shareholders. The numbers the program produces are the numbers the program produces. And there’s no reason to grant ANYONE the ability to change those numbers simply by altering a field.

If indeed a poll worker with the admin rights can just change the votes, that’s the actual problem, not hacking.

---

<div class="post-metadata">

### Author: ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)
#### Post date: [April 16, 2015, 1:32pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/12 "2015-04-16T13:32:33Z")

</div>

**Adaher** , your BASIC code is not really analogous to the situation here. Your code just holds a variable in memory and increments it. In an actual voting application, the individual votes have to be recorded to storage, such as by writing a record of each vote to a database. What the testing of these devices found was that it is trivially easy to access that database and change the records. This can be done by totally bypassing the application that is supposed to be writing the vote records to the database. Even if the application itself is protected from tampering, it writes the votes to an unprotected storage area that can be altered by means other than the application. So, fiddling with the application code is not necessary.

It is possible to design an application so that someone with admin rights on the OS cannot access the data in the application. You can use database encryption in such a way that OS admins cannot read the data without a separate login to the application. However, that was not done in this case.

Anyway, in this case, the testing discovered that it was trivially easy to gain admin access to the box. So, one issue, as **adaher** indicates, is that administrators can change votes, which in a well-designed system they would not be able to. Compounding this weakness is that anyone with a little skill can gain administrator rights on the system by quickly joining the wireless network and breaking into the voting machine.

It’s an incredibly lazy design. But, then, lots of applications are designed in an incredibly lazy and insecure manner. OK by me, though. I make my living responding to security breaches, so the more crappy systems out there, the more work for me.

---

<div class="post-metadata">

### Author: ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)
#### Post date: [April 16, 2015, 2:31pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/13 "2015-04-16T14:31:12Z")

</div>

**adaher** , when I’m root on a system, I have complete control of that system. I can replace files or encryption keys, write over the memory your app is running in, etc. Absolutely nothing is off limits, that’s the point of being root. Once you have the access necessary to actually administer a system, you can do anything to it, include replace the operating system.

Now, even in a system with severe auditing, there is a person who has the ability/responsibility to maintain the auditing system. It boils down to the age-old question of who watches the watchmen.

In this case, they left the key under the mat, and didn’t even hire watchmen.

---

<div class="post-metadata">

### Author: ![Evil\_Captor](https://avatars.discourse-cdn.com/v4/letter/e/f17d59/32.png) [@Evil\_Captor](https://boards.straightdope.com/u/Evil_Captor)
#### Post date: [April 16, 2015, 3:20pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/14 "2015-04-16T15:20:57Z")

</div>

And yet IIRC the two big voting machine manufacturers won’t let anyone check their software because it’s proprietary. Gives me a warm feeling all over, lemme tell ya.

---

<div class="post-metadata">

### Author: ![doorhinge](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@doorhinge](https://boards.straightdope.com/u/doorhinge)
#### Post date: [April 16, 2015, 3:25pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/15 "2015-04-16T15:25:22Z")

</div>

> [@BrotherCadfael](#):
>
> The old mechanical voting machines were often delivered to polling places in Chicago with a couple of thousand votes already recorded.
> 
> Nothing new under the sun.

> [@Fear\_Itself](#):
>
> That’s why separate machines should be used for recording and tallying, with a paper ballot record which can be easily recounted.

Voting machines are usually stored in a locked facility for two years, and are guarded by the cheapest security firm the taxpayers can afford.

In a large city, political parties may each spend $5 to $10 million for a mayor, governor, state, or federal legislator’s campaign(s).

I’ll suggest that an unscrupulous person could offer an unscrupulous programmer $1,000,000 to write software that guarantees that the candidate(s) of my choice will win the election. The software must also have the ability to remove itself. I will guarantee that the programmer will have unlimited access to the voting machines beginning sometime after midnight until, let’s say, 0500.

On election day, the average voter suspects that something is wrong with the voting machine they are using. They report the issue to the average poll watchers. The machine should then be taken aside, senior voting officials should be notified, and the maintenance company called (because no one else knows how the proprietary software operates). Maybe the hack will be discovered, maybe it won’t.

OTOH, pencils and marking pens are easy to trouble-shoot, reliable, and cheap to replace.

---

<div class="post-metadata">

### Author: ![BobLibDem](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/boblibdem/32/3149_2.png) [@BobLibDem](https://boards.straightdope.com/u/BobLibDem)
#### Post date: [April 16, 2015, 4:10pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/16 "2015-04-16T16:10:22Z")

</div>

> [@doorhinge](#):
>
> Since every computer can be hacked, and very few people, let alone your average poll watcher, have the ability to uncover altered software, I am not in favor of using electronic voting machines, regardless of who manufactured, or is supplying the machines.
> 
> Pencil and paper ballots work just fine. They just take longer to count, but the politicians aren’t expected to take or leave office the day after the election.

I’m in complete agreement with doorhinge. Make paper ballots and retain them for a number of years for potential audits and recounts. Read them with optical scanners if you want but save the paper trail. Electronic voting could lead to the day where the side with the best hackers wins.

---

<div class="post-metadata">

### Author: ![Ravenman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ravenman/32/2929_2.png) [@Ravenman](https://boards.straightdope.com/u/Ravenman)
#### Post date: [April 16, 2015, 4:27pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/17 "2015-04-16T16:27:45Z")

</div>

> [@adaher](#):
>
> This can be demonstrated with simple BASIC code:
> 
> 10 IF VOTE$=“JOHN KERRY” THEN KERRY=KERRY+1  
> 20 IF VOTE$=“GEORGE BUSH” THEN BUSH=BUSH+1  
> 30 PRINT KERRY  
> 40 PRINT BUSH

If BASIC were used to write voting machine software, I fear it may end up more like [this.](https://www.youtube.com/watch?v=JbnjusltDHk)

---

<div class="post-metadata">

### Author: ![Velocity](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/velocity/32/18006_2.png) [@Velocity](https://boards.straightdope.com/u/Velocity)
#### Post date: [April 16, 2015, 4:42pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/18 "2015-04-16T16:42:54Z")

</div>

But…but…but…the American electoral process is the most trustworthy and accurate in the world!

---

<div class="post-metadata">

### Author: ![Snowboarder\_Bo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/snowboarder_bo/32/229_2.png) [@Snowboarder\_Bo](https://boards.straightdope.com/u/Snowboarder_Bo)
#### Post date: [April 16, 2015, 5:53pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/19 "2015-04-16T17:53:30Z")

</div>

> [@Velocity](#):
>
> But…but…but…the American electoral process is the most trustworthy and accurate in the world!

It must be: everyone now has to show ID before their vote can be changed! 😛

---

<div class="post-metadata">

### Author: ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)
#### Post date: [April 16, 2015, 5:58pm UTC](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782/20 "2015-04-16T17:58:46Z")

</div>

> [@adaher](#):
>
> And there’s no reason to grant ANYONE the ability to change those numbers simply by altering a field.
> 
> If indeed a poll worker with the admin rights can just change the votes, that’s the actual problem, not hacking.

Actually, if you were a salesman with a huge sale that did not get recorded correctly, you definitely want someone to change the figure before your commission check is cut.

As for your second point, you just don’t want someone with admin/admin combination to have that access.

[Next page](https://boards.straightdope.com/t/audit-finds-voting-machines-used-in-three-states-were-breathtakingly-easy-to-hack/717782.md?page=2)
