Systemic Issues in the Hart InterCivic and Premier Voting Systems: Reflections Following Project EVEREST∗

نویسندگان

  • Kevin Butler
  • William Enck
  • Harri Hursti
  • Stephen McLaughlin
  • Patrick Traynor
  • Patrick McDaniel
چکیده

In response to growing concern about the security and integrity of elections in the state of Ohio, Secretary of State Jennifer Brunner set in motion a comprehensive study of the electronic voting equipment used throughout the state. Known as Project EVEREST (Evaluation and Validation of Election Related Equipment, Standards and Testing), this study attempted to assess the risks associated with Ohio’s current voting systems. In this paper, we discuss the systemic vulnerabilities and weaknesses discovered during the academic team’s evaluation of the Hart InterCivic and Premier Elections Solutions (formerly Diebold) hardware and software. We begin by describing a methodology for identifying and confirming vulnerabilities aimed at preventing vendor deniability so prevelant in voting systems analysis. Both systems’ studies began with an independent analysis of known vulnerabilities and quickly expanded. The Hart analysis expanded on previous findings and discovered 27 new vulnerabilities. Most notably, we discovered a large swath of undocumented functionality within the Hart system that could be highly dangerous in an election environment. Like previous evaluations, our analysis of the Premier system notes that the platform is plagued by systemic security issues; however, our evalu-

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Systemic Issues in the Hart InterCivic and Premier Voting Systems: Reflections on Project EVEREST

The State of Ohio commissioned the EVEREST study in late summer of 2007. The study participants were charged with an analysis of the usability, stability, and security of all voting systems used in Ohio elections. This paper details the approach and results of the security analysis of the Premier and Hart systems within the EVEREST effort. As in previous studies, we found the election systems t...

متن کامل

Hart InterCivic, Inc

Hart InterCivic traces its roots to 1912 as a provider of products and services for state and local government. For over 90 years, Hart has been supplying election products and services, including voting supplies and paper balloting products, to election customers across the nation. Throughout our company’s history, Hart InterCivic has supported all types of elections from paper, to lever machi...

متن کامل

An Analysis of the Hart Intercivic DAU eSlate

This paper reports on an analysis of the Hart InterCivic DAU eSlate unit equipped for disabled access and the associated Judge’s Booth Controller. The analysis examines whether the eSlate and JBC can be subverted to compromise the accuracy of vote totals, the secrecy of the ballot, and the availability of the system under the procedures in place for Yolo County. We describe several potential at...

متن کامل

Security Evaluation of ES&S Voting Machines and Election Management System

This paper summarizes a security analysis of the DRE and optical scan voting systems manufactured by Election Systems and Software (ES&S), as used in Ohio (and many other jurisdictions inside and outside the US). We found numerous exploitable vulnerabilities in nearly every component of the ES&S system. These vulnerabilities enable attacks that could alter or forge precinct results, install cor...

متن کامل

EVEREST : Evaluation and Validation of Election - Related Equipment

∗ This report was prepared by teams from Pennsylvania State University, the University of Pennsylvania, and WebWise Security, Inc. as part of the EVEREST voting systems analysis project initiated by the Secretary of State of Ohio in the Winter of 2007. Unless otherwise indicated, all analyses detailed in this report were carried out at the home institutions between October 1, 2007 and December ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008