Slashdot Log In
Hackers Invited To Crack Internet Voting
Posted by
samzenpus
on Wed Apr 18, 2007 09:43 PM
from the I-wonder-what-will-happen dept.
from the I-wonder-what-will-happen dept.
InternetVoting writes "The Philippine government and the International Foundation for Electoral System will be soliciting hackers to test the security of of their Internet voting system that will be tested in an upcoming pilot program." From the article,"Local and foreign computer hackers will be tapped to try and break into an Internet-based voting system that will be pilot tested by the country's Commission on Elections (Comelec) starting July 10."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
So... (Score:3, Insightful)
I'm sure all the REAL hackers will RSVP.
Re:So... (Score:5, Funny)
Parent
Re:So...failure to disclose vulnerability? (Score:3, Insightful)
Re:So...failure to disclose vulnerability? (Score:4, Insightful)
Democracy is valued in some countries you know...
Parent
If you need invitations, this is not for you (Score:2)
What if (Score:5, Funny)
2. Don't report it
3. ????
4. Profit!
Think they have not thought about that? (Score:5, Insightful)
Parent
Re: (Score:3, Funny)
All the better (Score:2)
Re:What if (Score:5, Insightful)
The way I would do something like this is to put the voting system inside a fully monitored and logged virtual machine. Then I would open it up to hackers, knowing that all changes to the system state will be logged and can be scanned for malicious actions.
Parent
Re: (Score:3, Funny)
Re:What if (Score:4, Insightful)
Parent
Re: (Score:2, Insightful)
Sounds like a diebold system to me.
Re: (Score:2)
What a dumb idea (Score:3, Insightful)
Of course any hacker with intentions of being a naughty boy is not going to show up and (a) make himself known or (b) reveal the holes.
Re:What a dumb idea (Score:4, Insightful)
But freelance security professionals and security companies looking to make a name for themselves will.
Parent
It actually surprised me (Score:5, Interesting)
They took it to one of the big conventions and had a briefcase with $10k in it for the first person that could make a permanant change to the disk without opening the case. Guys showed up with their own latex gloves so they wouldn't leave prints and one managed to come up with the proprietory vendor unique command set for the particular drive model that was in the system.
I don't think that was really the sort of adversary that they expected would show.
Parent
Re: (Score:2)
What's to stop someone from controlling/buying other people's votes? In a normal election you vote alone and secretly. Online it's very easy to have someone guiding/controlling your mouse.
What happens when you're raised in a house that always votes for X but you want to vote for Y?
Update (Score:5, Funny)
"The Philippine government and the International Foundation for Electoral System will be soliciting hackers to test the security of of their Internet voting system that will be tested in an upcoming pilot program."
UPDATE:
Posted by samzenpus on Wednesday April 18, @10:53PM
Internet voting has now been cracked.
Phillipine Election 2008 Headlines: (Score:5, Funny)
Re: (Score:2)
Re: (Score:2)
Wow...the system has already been cracked and the formatting system altered...fast work!
Re: (Score:2)
the philippines is famous (Score:5, Interesting)
200 peso notes famously become scarce before elections
no need to hack the system to alter the vote, just keep buying the votes
the philippines is a beautiful land, with beautiful people... and a corrupt political establishment, it's a sad commentary on corruption the philippines, the vote buying
But surely all elections are bought to some degree (Score:2)
Whether that self-interest is 200 Pesos thrust into their hand as they walk into the booth, or 200 Pesos less tax paid due to new tax system voted in doesn't make much difference.
Actually the more I think about it - In the Phillippines the cash seems to be given to you by the politician if you promise to vote for them. In the 'democratic West',we get nothing for our vote apart from the promise from the politician. Personally I'd prefer to see the cash in my hand, ra
Reverse engineering corruption (Score:3, Insightful)
In the context of corruption, perhaps this will be handy, Reverse engineering corruption [nytka.org]. The essay has quite a few hidden references to Slashdot subculture [wikipedia.org].
Re: (Score:2, Funny)
If you get in... (Score:3, Funny)
Re: (Score:2)
I live in the Philippines... (Score:3, Insightful)
On a related topic = I can't believe our Comelec is advertising this thing, a few months ago they don't even have a feasible electronic voting solution. I remember that they got a "Diebold" like deal for use in the last national elections but we know that the expensive machines had been now rotting in warehouses (and never had seen the light of the day, that makes Diebold more succesful). There are even local programmers/firms who are willing to "donate" their services just to make the election electronic but I guess that did not work out.
And I still don't have that promised "Electronic Voter's ID" when I registered at 18 (I'm in my 20's now). Now, how could they validate if I am the one who had casted my vote.. Hmmm...
As I said, nothing to see here.. move along.. I'm going to make some coffee...
Regards,
political posturing, external hackers not problem. (Score:2)
i dont know many people outside the phillipines who get up every morning saying "i really have a stake in rigging the phillipine election this year".
Re:political posturing, external hackers not probl (Score:2)
Re: (Score:2)
That is a rigged election. I'm not a scientist, so I can state the obvious. Someone flipped the switch. And there are so many others, with margins so slim that recounts are not automatic and therefore expensive. And the few recounts that have occured have Diebold techs cherrypicking districts to recount that mat
A cunning plan (Score:2)
Theater (Score:2)
The right way to do this is to publish everything and pay people like Adi Shamir and Ross Anderson for blocks (big blocks) of consulting time. Even that's futile without the will and the budget to fix problems -=>WHEN<=- the security people find them.
What they're doing is a good way to get headlines and to impress the impressionable. It's not a good way to make sure a system is secure.
This is the way it should be done! (Score:2)
I personally think the OSTG, FSF, or some other open source advocacy group needs to start an open source, high profile, project to create an "uncrackable" solution for electronic voting. I know uncrackable is unobtainable, but there is a level where physical access to internal components is required to
Incentive? (Score:2, Interesting)
Either way, if it's less than what someone running for president can give you, then creating problems for themselves
100% foolproof guaranteed exploit (Score:4, Insightful)
2. Hold gun to their head and insist that they vote for who you tell them to
3. Watch them cast the vote
4. Tell them that you will kill them and their pet rabbit if they tell anyone
5. Win the election
Sadly, that is a problem that will always exist if people aren't voting in a private cubicle in a public place.
After the recent postal voting in the UK, it was found that many heads of families coerced the rest of the family into voting a certain way. That just can't happen in a private cubicle where you can always lie to dad later, but vote for who you want to now.
Procedural comparison (Score:5, Insightful)
How things work outside the United States:
How things work in the United States:
Internet Voting (Score:2)
In a voting booth, you can put your vote wherever you want, even if someone bribed or threatened you or your family to make you vote his way. You can put your mark somewhere else, nobody will know.
At home, your vote can be checked before it's sent.
make it easier on the hackers (Score:2)
So they should publish the source code to the machines. There's nothing like a good public mugging
WRONG. Q: Can it be manipulated by insiders? (Score:3, Insightful)
Yes. Always, untraceably, if you can manipulate the traces.
This test they are running is worthless. They are playing to the myth of the superhacker, master of all crimes. The problem with evoting is that the evoting system programmers own the democracy, and you cannot test for that.
These evoting systems are the answer to the question: how do we fix elections without anyone noticing, or even understanding the system so that they notice that we can? The paper systems are foolproof, if done correctly, as in Canada. Those systems aren't broken. So we are fixing an uncrackable system for one that is cracked by design.
People. Someone is really determined to own democracy. Follow the money.
Re: (Score:2)
Re: (Score:3, Funny)
Re: (Score:3, Funny)
Hey mods, supress your knee-jerk reaction (Score:3, Interesting)
Whoever modded this as troll missed an important point: no hacking/counterhacking measures will prevent voters being influenced by their bosses or bribed or forced to vote by abusive spouses, yada, yada, yada, you get the point.
Unless of course the e-voting procedure requires a signoff from a trusted third party who assures that the voter isn't showing their vote to their boss /person who paid t
Re: (Score:2)
Re:Hey mods, supress your knee-jerk reaction (Score:4, Insightful)
Parent
Re: (Score:2)
Re: (Score:2)