NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Registration
Slice by Program

California finds e-voting riddled with flaws

By: Robert McMillan, IDG News Service(07-30-2007)

California Secretary of State Debra Bowen has revealed that researchers commissioned by the State of California have found security issues in every electronic voting system they tested.

A report was published late last week as part of a complete review of the state's e-voting systems initiated earlier this year by Bowen's office. Its findings were not encouraging for backers of e-voting.

"The security teams were able to bypass both physical and software security in every system they tested," says Bowen.

The report documents 15 security problems found in the devices. For example, researchers were able to exploit bugs in the Windows operating system used by the Diebold GEMS election management system to circumvent the system's audit logs and directly access data on the machine. They were able to get a similar level of access to Sequoia WinEDS data as well.

Testers were also able to overwrite firmware, bypass locks on the systems, forge voter cards, and even secretly install a wireless device on the back of a GEMS server.

Bowen is set to decide by August 3 which systems will be certified for use in the 2008 presidential primaries. She declined to comment on how the report's findings would affect this decision until she had completely reviewed the report.

"The severity of it, what it means...that's a matter for us to investigate and pull apart and analyze between now and [this] Friday."

But she did acknowledge the security problems found by researchers were important. "It's a big deal for many people in this country," she said. "We are a democracy and our very existence as a democracy is dependent on having voting systems that are secure, reliable and accurate."

California's review is the most thorough testing of voting machine technology yet undertaken in the U.S.

A team of researchers assembled by the University of California has spent the past two months evaluating the security, accessibility and manufacturer documentation of voting machines.

A "red team" of penetration testers attempted to gain access to the voting systems to see if they could disrupt an election or alter the results, while another team examined the source code to the machines.

Researchers examined devices manufactured by Diebold Election Systems Inc., Hart InterCivic Inc. and Sequoia Voting Systems Inc.

Representatives from Diebold and Sequoia said they needed more time to review the research before commenting in depth. "We are very anxious to review the findings," said Michelle Shafer, a Sequoia spokeswoman. "We will be providing our official response...early next week."

She noted, however, that the "testing done during this Top to Bottom Review did not employ the processes and procedures used in the conduct of an actual election."

Another vendor, Election Systems & Software Inc. (ES&S) was so late in providing access to their products that their systems would be evaluated at a later date, Bowen said.

The ES&S systems are used by Los Angeles County, and Bowen wouldn't say whether the absence of ES&S from the report might leave the county without certified voting systems in February.

Voting systems are purchased by local county officials in California, but they must be certified by the Secretary of State's office before they can be used in an election.

With California at the forefront of voting system reforms, the report would be closely scrutinized by state officials across the country, said Kim Alexander, president and founder of the California Voter Foundation.

"Even though we've made a number of improvements to voting systems in California, doubts persist about the reliability of our voting equipment."

In 2004, for example, voting was delayed by several hours in many San Diego precincts as the city struggled to roll out a new US$31 million Diebold electronic voting system.

The report was conducted under added time constraints. In March, California Governor Arnold Schwarzenegger moved the date of the state's 2008 presidential primary vote ahead from June to February 5.

State law mandates that the Secretary of State must give counties at least six months' notice if machines are to be de-certified, forcing Bowen to make a decision on the matter by August 3.

Bowen said it was unfortunate there was not more time for study and debate, but that putting off the review was not an option. "I don't want any doubt about the reliability of our voting systems come February 5, 2008," she said.

Related content:

E-voting to premiere at federal elections

E-voting the way forward for municipalities, survey finds

Report slams UK e-voting trials

E-voting applications to stay public

A new culture grows in Edmonton

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada