Site icon The Punching Bag Post

How to STeal an Election – Part 3, Hack the Machines

&NewLine;<p class&equals;"wp-block-paragraph">This Part is about possible technical attacks on the voting machines&comma; with participation from either insiders or outsiders&period; This had a great deal of focus in the last election&period; A great many accusations were leveled against Dominion and its partners and subsidiaries&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">Articles have been written that claim the voting machine software has built-in ways to cheat&comma; including ways to manipulate votes as they are being tallied to proportionally reduce the number of votes for a candidate&period; Apparently&comma; within the software&comma; you can actually assign a &OpenCurlyDoubleQuote;weight” to votes for different candidates such that Candidate A’s votes were only worth 80&percnt; of Candidate B’s votes in the final tally of the voting&period;&nbsp&semi; I have not checked this personally&comma; but I have faith in the sources of this information&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">I can’t think of any legitimate reason for a feature like this to be in voting software&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">Additionally&comma; federal officials have claimed that voting machines are not connected to the internet&period;&nbsp&semi; Turns out some have been&period;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">Why are we leasing voting machines that even have the capability to connect to the internet&quest; We already understand the risks&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">And of course&comma; who has access to these machines&quest; Is there an audit trail of when features are turned off and on&comma; or when it is connected to the internet or not&quest;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">No&comma; of course not&period;&nbsp&semi; Nobody gets caught because they are impossible to catch&period; All tracks of tampering with the machine are easily erased&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">Besides this&comma; unless you already know that cheating has occurred and the FBI brings in technicians&comma; you must rely on the manufacturer &lpar;some have already accused either managers or technicians of being complicit&comma; how hard would they be to recruit&quest;&rpar; to look at the machine for tampering&period; &nbsp&semi;And by the way&comma; it is will be in the voting machine leasing contract that no one except company technicians are allowed to inspect the machines&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">So here are the attacks and my evaluation&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><strong>Activate the software that cheats for you<&sol;strong> – These are apparently features designed for Venezuela and other countries with institutionalized cheating&comma; and sources have said they are present in all of the machines&period; They are just supposed to be turned off&period;&nbsp&semi;&nbsp&semi; If the machine happens to be connected to the internet&comma; then this can be attacked remotely&period; If not&comma; then attacked locally by a technician or a technician impersonator&period;&nbsp&semi; <strong><em>Effectiveness – medium for machines modified locally &lpar;harder to scale that way&rpar;&comma; high for machines on the internet&period; Risk – low&period; While the counts will be off in a recount&comma; there is no auditing trail to ensure no attacks have been made on the machine&period;&nbsp&semi; Technicians to turn features on or off are hardly noticed&comma; professional attackers would never be caught&period;<&sol;em><&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><strong>Attack through the internet connection<&sol;strong> &&num;8211&semi; Additionally&comma; an insider could activate the wireless internet connection to the voting machine&period; This is illegal&comma; but if done it would allow someone outside the facility to change the vote counts&period; Even if the cheating software is not turned on&comma; it is reasonable to assume that legitimate processes can be corrupted or tampered with&period;&nbsp&semi; <strong><em>Effectiveness – High&comma; if you are professional&comma; i&period;e are wise enough to make subtle changes and cover your tracks&period;&nbsp&semi; Risk – close to zero&comma; &lpar;again assuming you are a professional&rpar;&period;&nbsp&semi; The problem is the lack of auditing or chain of custody verification&period;&nbsp&semi; Again the recounts will be off&comma; but that apparently doesn’t matter&comma; since judges have ruled to accept the count anyway&period;<&sol;em><&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><strong>Hack the information process&comma; or the computers at the counting center<&sol;strong> – The police and courts generally talk about &OpenCurlyDoubleQuote;chain of custody&period;”&nbsp&semi; That means that data has to be stored&comma; data has to travel and data has to be analyzed&period;&nbsp&semi; At every step&comma; the data must be verified and sworn to&period; <strong><em>The diagram below is from the Dominion Voting Machine Manual<&sol;em><&sol;strong>&period; &nbsp&semi;You can see that they try to handle a boatload of functions and workflows within their &OpenCurlyDoubleQuote;Democracy Suite&period;” &nbsp&semi;Any professional worth his salt is going to find numerous opportunities to intercept&comma; change&comma; corrupt or otherwise influence the election within this complex system&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<div class&equals;"wp-block-image"><figure class&equals;"aligncenter size-full"><img src&equals;"https&colon;&sol;&sol;punchingbagpost&period;com&sol;wp-content&sol;uploads&sol;2022&sol;01&sol;democracysuite&period;jpg" alt&equals;"" class&equals;"wp-image-20292"&sol;><&sol;figure><&sol;div>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">The combination of a professional data thief and an election official would make this nearly risk free&period; This level of manipulation could easily become undetectable since the voting counts could be changed to match the actual votes cast&period;&nbsp&semi; <strong><em>Effectiveness – high in a local election&comma; medium in state or national levels&period; Risk – Low&period;&nbsp&semi; Caveat&comma; since I have not examined this workflow&comma; I cannot assess the risk with certainly&period; I am assuming any vulnerabilities can be found and exploited&period;<&sol;em><&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">My conclusion is that hacking the machines as an outsider attacking online voting machines &nbsp&semi;&lpar;and succeeding workflow&rpar; is serious&comma; but attacks on the machines involving an insider are serious and undetectable&period;&nbsp&semi; &nbsp&semi;Again&comma; never underestimate the power of an insider to screw you over&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">In Part 4&comma; I will talk about mitigation and prevention&period; Believe it or not&comma; it is not that difficult&period; &nbsp&semi;Any security outfit worth its salt can tell you how to do this&period; The police and local prosecutors are familiar with &OpenCurlyDoubleQuote;chain of custody&period;”&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph">So the final question is &&num;8220&semi;How do we secure the most valuable right of a Democratic society&quest;&&num;8221&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><a href&equals;"https&colon;&sol;&sol;www&period;nbcnews&period;com&sol;politics&sol;elections&sol;online-vulnerable-experts-find-nearly-three-dozen-u-s-voting-n1112436">https&colon;&sol;&sol;www&period;nbcnews&period;com&sol;politics&sol;elections&sol;online-vulnerable-experts-find-nearly-three-dozen-u-s-voting-n1112436<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><a href&equals;"https&colon;&sol;&sol;www&period;politico&period;com&sol;magazine&sol;story&sol;2016&sol;08&sol;2016-elections-russia-hack-how-to-hack-an-election-in-seven-minutes-214144&sol;">https&colon;&sol;&sol;www&period;politico&period;com&sol;magazine&sol;story&sol;2016&sol;08&sol;2016-elections-russia-hack-how-to-hack-an-election-in-seven-minutes-214144&sol;<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><a href&equals;"https&colon;&sol;&sol;www&period;cnn&period;com&sol;2019&sol;09&sol;26&sol;politics&sol;hackers-voting-machines&sol;index&period;html">https&colon;&sol;&sol;www&period;cnn&period;com&sol;2019&sol;09&sol;26&sol;politics&sol;hackers-voting-machines&sol;index&period;html<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p class&equals;"wp-block-paragraph"><a href&equals;"https&colon;&sol;&sol;www&period;forbes&period;com&sol;sites&sol;thomasbrewster&sol;2017&sol;07&sol;29&sol;def-con-hacking-election-voting-machines&sol;&quest;sh&equals;62c17cdf1d55">https&colon;&sol;&sol;www&period;forbes&period;com&sol;sites&sol;thomasbrewster&sol;2017&sol;07&sol;29&sol;def-con-hacking-election-voting-machines&sol;&quest;sh&equals;62c17cdf1d55<&sol;a><&sol;p>&NewLine;

Exit mobile version