Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Looking at the "Voting Machine Security Specifications", it's a verified OS image connecting to a VPN over the internet on election day.

This means that you have to trust the:

  * VPN
  * OS
  * Network stack
  * Display and input drivers (HW and SW)
  * SSD controller
  * CPU
  * CPU's "Management Engine" or equivalent
  * Mainboard chipset
To all be free of exploits and backdoors. You're trusting many, many thousands of people, from hundreds of different companies in several different nations, to not have put backdoors in, despite the fact that backdoors and exploits have been discovered after the fact in essentially all of the listed components.

I don't say this lightly: the authors are dangerous fools. They're fools to think that this is secure enough for an election. And they're dangerous because someone in power might believe them.



You don't even have to trust the software or the hardware. All that is important is votes to be cast as intended and the tally to be correct. End-to-end cryptographically verifiable voting systems achieve that by different means (zero knowledge proofs, etc.) An example is the Pret-a-Voter voting protocol. It uses re-encryption mix nets to provide verifiability (close how Tor works).


You absolutely have to trust the software and the hardware.

Modifications at the hardware/OS level can deliberately misrepresent the voter input from the touch panel, and can then alter what is displayed on the screen to match what the voter expects.

No matter how bulletproof the encryption protocol is, it still needs to be fed a choice via an analog, unencrypted channel because human beings are analog and unencrypted. If you control that channel, it's game over.

And you can't get around that by having a system that enables people to verify their vote at a later time on a second (presumably unhacked) machine, because then you'll also enable the forcing of voters to prove that they've voted the way that they've been coerced to.


You have to trust some hardware, but not necessarily the full stack you listed above.

For example, chipTAN is commonly used in Germany to verify online banking. You have to trust the chip on the banking card and the card reader, but not your computer, network connection, or your smartphone.

A similar device may also work for online voting. The hardware would be simple enough to audit it. Your computer would never learn the vote.


If the chip has its own display and input, and every step of the manufacturing process is carried out under strict supervision by all parties, and every time there's a firmware update the entire software stack is re-audited, then maybe. You raise a good point.

There's the whole business of securely distributing the chips (so they're not swapped out with counterfeits in transit), dealing with theft (and coersion to not report the theft), etc. But yes, if you can get a never-network-connected, brutally simply, completely automated voting device into 230 million hands, then I can't think off the top of my head how to exploit that. I would move on to trying to exploit the tallying system.

At that point, though, is it really cheaper than paper ballots? Perhaps it's worth it to engage more voters, but it still seems like a terrible risk to take - I'm only very grudgingly aware of computer security matters, just because I can't think of a way to exploit it, doesn't mean that one of the 7 billion people out there won't. And it only takes one.

Also I should point out that my original point stands - what you bring up is a million miles from what they proposed in TFA.


Yup, or you get something like this -- https://www.youtube.com/watch?v=EV_c1-YTk8M


You don't have to trust them that much, though. These are all COTS components used in every other computerized system everywhere, so any backdoors the authors want to slip in would have to impact only the voting system, and not raise anyone else's attention.

That's pretty hard. How, for example, are you going to get a CPU bug to do this for you?

I'm not saying it's impossible, but it's sort of like saying that we're fools for using gas-powered engines for the military. Thousands of people design them, so how do we know the designs haven't been sabotaged? You might be right, but you're probably wrong.


To use your metaphor, yes if the military installed a single model of identical, network-connected engine in every vehicle they own, they would absolutely be fools. A single hack could, in a strategically critical moment, disable all motorized assets - every vehicle and generator in the US military shutting down at the same time. That's a disaster.

And you don't have to put in the backdoor just for the election. You can put one in and use it opportunistically. Someone backdoored a huge amount of Juniper VPN hardware, in hopes that it might be useful some day:

http://arstechnica.com/security/2016/01/juniper-drops-nsa-de...

And to answer your question, this is how you get silicon like a CPU to do what you want:

https://www.schneier.com/blog/archives/2012/05/backdoor_foun...

These are just two examples that made the news. It's a practical certainty that there's backdoors in all sorts of COTS components that we don't know about yet. At this point there's nothing above suspicion.

For the scheme in TFA to work, they need a unhackable computer. If there is a single exploit or backdoor that happens to be in it, whoever controls it can pick the US congress, the senate, and the POTUS. Not metaphorically, literally. How is taking that degree of risk, when you know that backdoors and exploits are commonplace, not incredibly foolish?


> so any backdoors the authors want to slip in would have to impact only the voting system, and not raise anyone else's attention.

Except that many of the backdoors are universal backdoors, meaning that they can be remotely updated with new instructions.


People still look for backdoors of that type, though.

Additionally, if you really made something that specific, that was only ever discovered and used to hack an election, and the only people that could have done it were the chip vendor... how do you think that will play out when it's discovered? Or do you, as the attacker, bank on no one ever discovering this, ever?

If you're an engineer working for one of these places, how much do you have to get paid, or what do you have to be threatened with, to make this work out?

This seems much more like a novel written by Ian Fleming, not le Carre...


First, auditing the hundreds of millions of lines of code that it takes to build an OS and userspace every election and midterm is completely unrealistic. Especially given the degree of code obfuscation that is possible.

Second, at the silicon level there's billions of transistors in a CPU, silicon in general is prohibitively expensive to audit, and you can do malicious things by just putting in nigh-undetectable changes in dopant levels:

https://www.schneier.com/blog/archives/2013/09/surreptitious...

Third: you don't need to hide the hack forever. You just need to gain enough power in the election that you can suppress any further investigation.

Given the parade of hacks that make the HN front page every week, at all levels of government and industry, given that the well-funded and incredibly paranoid US military inadvertently deployed backdoored chips, given that existing voting machines have had demonstrable amateur-hour exploits in them:

http://fortune.com/2016/11/04/voting-machine-hack-watch-vide... http://www.pcworld.com/article/135461/article.html

is it really that difficult to believe that voting machines can be hacked?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: