• CREATE AN ACCOUNT
  • LOG.IN
  • CONTENTS
  • CLASSIFIEDS
  • ARCHIVE
  • INFO | ADVERTISING | CONTACT US

  • Home
  • News
    • News Main Page
    • NewsFlash
  • A&E
    • A&E Main Page
    • Movie Times
    • TV Listings
    • A&E Blog
    • Art Galleries
    • Best Bets
  • Opinion
    • Opinion Main Page
    • Columns
    • Voices
    • Letters
    • In Memoriam
    • Obituaries
  • Events
    • Today
    • Search
    • Submit
    • Best Bets
  • Living
    • Living Main Page
    • Outdoors
    • Travel
    • Sports
    • Peeps
  • Food & Drink
    • Food & Drink Main Page
    • All Restaurants
    • Delivery
    • All Bars & Clubs
    • Drink Specials
    • Open Now
  • Outdoors
    • Outdoors Main Page
    • Outside Insider
    • Spotlight On
    • Features
  • Classifieds
    • Real Estate
    • Jobs
    • Autos
  • Personals
  • Obits

Paul Wellman (file)

Giovanni Vigna, pictured with some of his former computer programming, gave a talk on October 23 about why electronic voting machines are flawed.


E-Voting Made Scary

UCSB’s Giovanni Vigna Gives Timely Talk on Why Electronic Voting Is Frighteningly Insecure


Thursday, October 23, 2008
By Matt Kettmann (Contact)
Article Tools
Print friendly
E-mail story
Contact an Editor
iPod friendly
Comments
Bookmark This
del.icio.us. del.icio.us.
Digg! Digg!
furl furl
google google
newsvine newsvine
reddit reddit
technorati technorati
Facebook Facebook
Yahoo! My Web 2.0 Yahoo!

With the big ballot showdown on November 4 looming, a few dozen people on the UC Santa Barbara campus spent their Thursday, October 23, lunch hour digesting some pretty frightening news: Electronic voting machines — the officially appointed wave of our democratic future, being touted as safe, sane, and secure — are entirely vulnerable to election-altering attacks, ranging from the highly technical to the surprisingly simple.

Giovanni Vigna (right) discusses possible hacking strategies with one of his computer programming students during a hacking competition in December 2007.
Click to enlarge photo

Paul Wellman

Giovanni Vigna (right) discusses possible hacking strategies with one of his computer programming students during a hacking competition in December 2007.

The messenger of doom was Giovanni Vigna, the golden-locked, Italian-born professor who runs UCSB’s Computer Security Group, which is considered one of the best places on the planet to learn about programming and hacking. Vigna, along with his mentor Dick Kemmerer and a team of sharp students, were hired in 2007 by the states of California and Ohio to test the security of electronic voting machines. In both cases, the machines — specifically, made by Sequoia Voting Systems in California and ES&S in Ohio — failed to stand up to even the most basic physical breaches, such as the unlocking of supposedly secure doors by using a screwdriver and a finger. The vulnerabilities witnessed from the computer hacking side were even more startling, showing that just one corrupt voting official or poll worker could, with the right amount of motivation, infect a state’s entire voting system within seconds by introducing a specially crafted computer virus to entirely change an election’s result.

As head of UCSB"s Computer Security Group, Giovanni Vigna was hired to test the voting systems in California and Ohio in 2007. Both were vulnerable to attack.
Click to enlarge photo

Paul Wellman

As head of UCSB"s Computer Security Group, Giovanni Vigna was hired to test the voting systems in California and Ohio in 2007. Both were vulnerable to attack.

Though the results of 2007’s tests came out last year, Vigna’s work has received a recent boost in buzz, certainly because of the upcoming election, but also due to YouTube videos of the simulated attack methods that went viral. (See those videos here, or just watch them on this page below.) And with reports this week of election machines in two states flipping early voters’ choices for president — Barack Obama votes were being cast for John McCain in West Virginia, with the opposite happening in Tennessee — Vigna’s talk on Thursday was right on time.

“Outsourcing the people who count your votes is not, in my opinion, a good idea,” Vigna told the crowd. “At this point, all bets are off.”

Vigna’s research has not uncovered any record of bias for one party or the other, just negligence. He believes that the machines were made hastily to get under a deadline imposed by the Help America Vote Act of 2002, which sought to improve voting machine reliability after thousands of electronic votes were discounted in the 2000 election. But because they were made so fast, not enough care was taken to ensure complete security, which is why there are so many ways to physically attack the system. “It’s really a problem keeping these things physically secure,” said Vigna, adding that the most important data-holding devices have to pass through many hands, thereby multiplying the chances for someone to act maliciously. As well, Vigna said, oftentimes these machines are housed overnight in the garages of poll workers, which aren’t necessarily the safest places to be.

Giovanni Vigna (center) tallying results in the UCSB 2007 Hacking Competition.
Click to enlarge photo

Paul Wellman (file)

Giovanni Vigna (center) tallying results in the UCSB 2007 Hacking Competition.

But more troubling are the security holes in the computer programming, which are somewhat understandable, because cryptography is a very difficult thing to do correctly, admitted Vigna. He explained that the companies did technically encrypt the data, but then put the encryption key adjacent to the lock, which is analogous to having a safe full of money locked with the combination written outside the door on a Post-It note. He said machines also could be switched easily from test to election mode, thereby fooling honest attempts to assure they worked. And with just one slip of a USB drive into a single machine, the entire system can be corrupted, making the task very easy.

“[The presidential candidates] could stop spending money on their campaigns and give $20 million to one dude,” joked Vigna to the anxious laughter of the concerned crowd. “They could buy the election.”

Basically, Vigna believes that the taxpayers got a raw deal because the machines were so hurried. Although the companies were promising Ferraris, Vigna said, “We bought Pintos.”

He much prefers paper voting, because of the recorded history it leaves. “I know it’s expensive, but this is the most important step in the democratic process,” he said. “This country is outsourcing that step to companies whose goal is not necessarily being accurate. Their goal is making money.”

Though he doesn’t think electronic voting can be flawless unless everyone from programmers to poll workers have a degree in computer science, Vigna does believe that nationalizing the electronic voting machines would be better. And paper trails, even though they too can be corrupted, should be mandatory. Vigna realizes such reforms won’t happen by November 4, but said, “Maybe we have enough momentum to make a change four years from now.”

Story Help (Click-ability)
Double-clicking on any word or phrase in this story will open a reference window with definitions and links to other reference material.

Comments

Discussion Guidelines

Great story. Timely reporting.

david3 (anonymous profile)
October 24, 2008 at 8:39 a.m. (Suggest removal)

Don't worry, McBush will make sure everything is OK.

This information was flying around the internet during the primaries, if you were paying attention.

loonpt (anonymous profile)
October 24, 2008 at 9:19 a.m. (Suggest removal)

Either that guy has a small ring finger or he is giving us all the shocker.

ty (anonymous profile)
October 24, 2008 at 10:19 a.m. (Suggest removal)

ty, you jumped the gun on the shocker siting; photo at the top of this page reveal the other phalanges.

binky (anonymous profile)
October 24, 2008 at 2:23 p.m. (Suggest removal)

How about a machine that gets people to want to vote?

Georgy (anonymous profile)
October 27, 2008 at 8:45 p.m. (Suggest removal)

Post a comment

Username:
Password: (Forgotten your password?)

Comment:

EVENT CALENDAR

Previous Month | Next Month

Today's Events Best Bets Submit an Event

Local Weather

Currently:
Mist
Temperature:
50.0°
Wind:
5 WNW

Surf Report
  • Specials
  • InPrint
  • Top Emails
  • Local Heroes 2008
  • Best Of 2008
  • Tea Fire 2008
  • Blue Green Guide 2008
  • Wedding Guide 2008
  • SBIFF 2008 All Access
  • 2008 Election Coverage
  • Calendar of Fundraisers
  • Local Bands
  • Kid's Mother's Day Issue
  • Made in Santa Barbara
  • California’s Great Olive Oil Flood
  • Santa Barbara’s Alpine Connection
  • Supes Begin 2009 by Tackling Greka Oil Spills
  • Hey Bush, Read This
  • The Meat Puppets Return with a New Record, Bright Future
  • Enjoy Year-Round Fun with the Santa Barbara Ski and Sports Club, Founded in 1955
  1. Just Say ‘Know’ to Teen Sex
  2. Jerry Roberts Beating Wendy McCaw
  3. California’s Great Olive Oil Flood
  4. Who’s Your Farmer?
  5. A Closer Look at the Wildfire Problem
  6. Criminal Defense Attorney Caught Buying Heroin
  • CREATE AN ACCOUNT
  • LOG.IN
  • CONTENTS
  • CLASSIFIEDS
  • ARCHIVE
  • INFO | ADVERTISING | CONTACT US
Google
 
Independent.com Web
Copyright ©2009 Santa Barbara Independent, Inc. Reproduction of material from any Independent.com pages without written permission is strictly prohibited. If you believe an Independent.com user or any material appearing on Independent.com is copyrighted material used without proper permission, please click here.
This is our Privacy Policy.