Hackers Invited To Crack Internet Voting 119
InternetVoting writes "The Philippine government and the International Foundation for Electoral System will be soliciting hackers to test the security of of their Internet voting system that will be tested in an upcoming pilot program." From the article,"Local and foreign computer hackers will be tapped to try and break into an Internet-based voting system that will be pilot tested by the country's Commission on Elections (Comelec) starting July 10."
So... (Score:3, Insightful)
I'm sure all the REAL hackers will RSVP.
Re:So...failure to disclose vulnerability? (Score:3, Insightful)
Re:So...failure to disclose vulnerability? (Score:4, Insightful)
Democracy is valued in some countries you know...
Re: (Score:1, Interesting)
If you need invitations, this is not for you (Score:2)
Re:So... (Score:5, Funny)
Hey mods, supress your knee-jerk reaction (Score:3, Interesting)
Whoever modded this as troll missed an important point: no hacking/counterhacking measures will prevent voters being influenced by their bosses or bribed or forced to vote by abusive spouses, yada, yada, yada, you get the point.
Unless of course the e-voting procedure requires a signoff from a trusted third party who assures that the voter isn't showing their vote to their boss /person who paid t
Re: (Score:2)
Re:Hey mods, supress your knee-jerk reaction (Score:4, Insightful)
What if (Score:5, Funny)
2. Don't report it
3. ????
4. Profit!
Re: (Score:1, Informative)
Re: (Score:3, Funny)
Re:What if (Score:4, Insightful)
Re: (Score:2, Insightful)
Sounds like a diebold system to me.
Re: (Score:1)
Re: (Score:2)
Re: (Score:1)
"Yes this is madness. They're allowing people to attempt to crack the voting system with no fear of getting into trouble. If somebody does crack into it, they can either report how they did it so the system can be fixed, or they can use the security hole to rig an election."
As in if they hack it now and don't report it they can use it later. I replied if they hack it now,
the maintainers of the voting software can, if
Think they have not thought about that? (Score:5, Insightful)
Re: (Score:3, Funny)
All the better (Score:2)
Re: (Score:1)
Re:What if (Score:5, Insightful)
The way I would do something like this is to put the voting system inside a fully monitored and logged virtual machine. Then I would open it up to hackers, knowing that all changes to the system state will be logged and can be scanned for malicious actions.
What a dumb idea (Score:3, Insightful)
Of course any hacker with intentions of being a naughty boy is not going to show up and (a) make himself known or (b) reveal the holes.
Re:What a dumb idea (Score:4, Insightful)
But freelance security professionals and security companies looking to make a name for themselves will.
It actually surprised me (Score:5, Interesting)
They took it to one of the big conventions and had a briefcase with $10k in it for the first person that could make a permanant change to the disk without opening the case. Guys showed up with their own latex gloves so they wouldn't leave prints and one managed to come up with the proprietory vendor unique command set for the particular drive model that was in the system.
I don't think that was really the sort of adversary that they expected would show.
Re: (Score:1)
Re: (Score:2)
What's to stop someone from controlling/buying other people's votes? In a normal election you vote alone and secretly. Online it's very easy to have someone guiding/controlling your mouse.
What happens when you're raised in a house that always votes for X but you want to vote for Y?
Very Nice (Score:1)
Re: (Score:1)
Re: (Score:2)
Update (Score:5, Funny)
"The Philippine government and the International Foundation for Electoral System will be soliciting hackers to test the security of of their Internet voting system that will be tested in an upcoming pilot program."
UPDATE:
Posted by samzenpus on Wednesday April 18, @10:53PM
Internet voting has now been cracked.
Phillipine Election 2008 Headlines: (Score:5, Funny)
Re: (Score:2)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Re: (Score:2)
Wow...the system has already been cracked and the formatting system altered...fast work!
Re: (Score:2)
Re: (Score:1)
Re: (Score:2)
Re: (Score:1)
I wouldn't source People's Daily Online, which is known for having just a little bias [people.com.cn], especially when China hasn't been doing very well in the area of abductions [amnesty.org] or human [hrw.org] rights [amnesty.org] itself.
Re: (Score:1)
I wouldn't source People's Daily Online
ok, how about these:
Philippines guilty of violations: forum [smh.com.au]
Independent tribunal probes Philippines killings [radioaustralia.net.au]
Obama Says US Should Monitor Killings in RP [asianjournal.com]
Is this genuine, a honeypot or both? (Score:1)
Re: (Score:1)
that "formal" invitation is just a front.
Bring It Back To Earth, Folks (Score:1)
the philippines is famous (Score:5, Interesting)
200 peso notes famously become scarce before elections
no need to hack the system to alter the vote, just keep buying the votes
the philippines is a beautiful land, with beautiful people... and a corrupt political establishment, it's a sad commentary on corruption the philippines, the vote buying
Re: (Score:2, Funny)
But surely all elections are bought to some degree (Score:2)
Whether that self-interest is 200 Pesos thrust into their hand as they walk into the booth, or 200 Pesos less tax paid due to new tax system voted in doesn't make much difference.
Actually the more I think about it - In the Phillippines the cash seems to be given to you by the politician if you promise to vote for them. In the 'democratic West',we get nothing for our vote apart from the promise from the politician. Personally I'd prefer to see the cash in my hand, ra
Reverse engineering corruption (Score:3, Insightful)
In the context of corruption, perhaps this will be handy, Reverse engineering corruption [nytka.org]. The essay has quite a few hidden references to Slashdot subculture [wikipedia.org].
Re: (Score:1)
Media Circus (Score:1)
If you get in... (Score:3, Funny)
Re: (Score:1)
Re: (Score:2)
I live in the Philippines... (Score:3, Insightful)
On a related topic = I can't believe our Comelec is advertising this thing, a few months ago they don't even have a feasible electronic voting solution. I remember that they got a "Diebold" like deal for use in the last national elections but we know that the expensive machines had been now rotting in warehouses (and never had seen the light of the day, that makes Diebold more succesful). There are even local programmers/firms who are willing to "donate" their services just to make the election electronic but I guess that did not work out.
And I still don't have that promised "Electronic Voter's ID" when I registered at 18 (I'm in my 20's now). Now, how could they validate if I am the one who had casted my vote.. Hmmm...
As I said, nothing to see here.. move along.. I'm going to make some coffee...
Regards,
Re: (Score:1)
I think there is something to see here. This is great security policy -- inviting people to test the security of systems.
The U.S. gov't is too worried about it's appearance to invite criticism. It's like an insecure high school girl.
political posturing, external hackers not problem. (Score:2)
i dont know many people outside the phillipines who get up every morning saying "i really have a stake in rigging the phillipine election this year".
Re:political posturing, external hackers not probl (Score:2)
Re: (Score:2)
That is a rigged election. I'm not a scientist, so I can state the obvious. Someone flipped the switch. And there are so many others, with margins so slim that recounts are not automatic and therefore expensive. And the few recounts that have occured have Diebold techs cherrypicking districts to recount that mat
A cunning plan (Score:2)
Theater (Score:2)
The right way to do this is to publish everything and pay people like Adi Shamir and Ross Anderson for blocks (big blocks) of consulting time. Even that's futile without the will and the budget to fix problems -=>WHEN<=- the security people find them.
What they're doing is a good way to get headlines and to impress the impressionable. It's not a good way to make sure a system is secure.
Huh? (Score:1)
"When Scytl presented the system, everybody was impressed on the security features. It is covered by international patent and it has been declared secured by no less than Switzerland and everyone in the global community should respect that decision," Tuason told reporters in a conference Tuesday.
Switzerland is now the global arbiter of the well defined "secured" and the global community should accept that? Huh? This quote is either a really bad translation or high comedy.
Re: (Score:2)
This is the way it should be done! (Score:2)
I personally think the OSTG, FSF, or some other open source advocacy group needs to start an open source, high profile, project to create an "uncrackable" solution for electronic voting. I know uncrackable is unobtainable, but there is a level where physical access to internal components is required to
Incentive? (Score:2, Interesting)
Either way, if it's less than what someone running for president can give you, then creating problems for themselves
Re: (Score:1)
Making it public, though, is more likely to attract the attention of more hackers, especially foreign ones.
I mean, how does the average hacker go about contacting the average morally dubious third world Presidential candidate, to arrange for payment to rig the election?
That's not exactly the sort of thing you can solicit for on craigslist.
Re: (Score:3, Funny)
100% foolproof guaranteed exploit (Score:4, Insightful)
2. Hold gun to their head and insist that they vote for who you tell them to
3. Watch them cast the vote
4. Tell them that you will kill them and their pet rabbit if they tell anyone
5. Win the election
Sadly, that is a problem that will always exist if people aren't voting in a private cubicle in a public place.
After the recent postal voting in the UK, it was found that many heads of families coerced the rest of the family into voting a certain way. That just can't happen in a private cubicle where you can always lie to dad later, but vote for who you want to now.
Re: (Score:1)
Re: (Score:2)
In the UK, they don't even hold a gun to their kids / wife's head - they just preach on about honouring the father and doing what they are told. In this circumstance, I have very little sympathy for the victims - they should grow a pair and tell daddy where to get off.
But in a country where guns are prev
Re: (Score:2)
Here in Canada, it would be pretty simple for me to personally go around voting at every station in the city. All I need to do is forge a power bill, and that's really gosh darn easy. Now, unless I can forge 2 pieces of photo ID along with, I'll end up going to jail afterwards.
The point is, a small number of votes is easily messed up, but what we want to ensure is that someone can't mess up the whole ballot box.
Procedural comparison (Score:5, Insightful)
How things work outside the United States:
How things work in the United States:
Internet Voting (Score:2)
In a voting booth, you can put your vote wherever you want, even if someone bribed or threatened you or your family to make you vote his way. You can put your mark somewhere else, nobody will know.
At home, your vote can be checked before it's sent.
make it easier on the hackers (Score:2)
So they should publish the source code to the machines. There's nothing like a good public mugging
WRONG. Q: Can it be manipulated by insiders? (Score:3, Insightful)
Yes. Always, untraceably, if you can manipulate the traces.
This test they are running is worthless. They are playing to the myth of the superhacker, master of all crimes. The problem with evoting is that the evoting system programmers own the democracy, and you cannot test for that.
These evoting systems are the answer to the question: how do we fix elections without anyone noticing, or even understanding the system so that they notice that we can? The paper systems are foolproof, if done correctly, as in Canada. Those systems aren't broken. So we are fixing an uncrackable system for one that is cracked by design.
People. Someone is really determined to own democracy. Follow the money.
at least... (Score:1)
This is truly a wonderful thing. (Score:2)
Hacker here is just a buzz word, but basically it's an open invitation for all security experts and amatures to
inspect and search for hole and problems before commiting to a potentially flawed system.
This is trully the only way to ensure a secure system and also provide a level of confidence to the public that will need to trust it.
In the USA our systems are terrably flawed and there has been much evidence that they deliberately cover up security h
Voting... (Score:1)
And the goal is? (Score:1)
Make sure that the software they use to commit election fraud is safe from hackers?
Election fraud is as likely, if not more, to come from the government (or parts thereof) organizing the elections as it is to come from outsiders. And insiders don't need to crack the electronic voting servers, they have direct access to them.
This is why electronic voting cannot be trusted. There is no way for the voter to verify the software being run on election day.
Re: (Score:3, Funny)
Re:Forget profit; this isn't even appealing for fa (Score:2)
But, no one understood the problem in reporterland, and sure as hell citizens haven't cared. The big collapses have occurred -- and NO ONE CARED.