OVSTA
Source Code Report
Hart System 6.2.1 (Conditional Reapproval following the Top-to-Bottom Review - December 6, 2007)
Read the report at Hart InterCivic ↗
Source Code Review of the Hart InterCivic
Voting System1
SrinivasInguva
StanfordUniversity2
EricRescorla
NetworkResonance
HovavShacham
UniversityofCalifornia,SanDiego
DanS.Wallach
RiceUniversity
July20,2007
1ThisreportwaspreparedattheUniversityofCalifornia,BerkeleyundercontracttotheCaliforniaSecre-
taryofStateaspartofa“Top-to-Bottom”reviewofelectronicvotingsystemscertifiedforuseintheStateof
California.
2Allauthoraffiliationsareforidentificationonly.
Executive Summary
ThisreportconsiderssecurityissuesinHartInterCivic’svotingsuite,version6.2.1.Thisreportwas
preparedattherequestoftheCaliforniaSecretaryofState,aspartofa“top-to-bottom”reviewof
thestate’selectronicvotingsystems. Thisdocumentisthefinalreportoftheteamthatexamined
theHartvotingsystemsourcecode.
Hart’s system consists of back-office election management components (SERVO, Rally, Tally,
eCMManager, BOSS,BallotNow)whichareusedtoconfigureandcollectdatafromprecinctde-
vices(eScan,eSlate,Judge’sBoothController).Theelectionmanagementsoftwarerunsonordinary
Windowsmachineswhereastheprecinctdevicesareembeddedprogramsrunningonspecialized
hardware.
Component-to-component networks are pervasive in Hart’s architecture. A JBC and one or
more eSlates are networked together at polling place for voting. JBCs, eSlates, and eScans are
networkedwithSERVOforpre-andpost-electionsetup,auditing,andreset. RallyandTallycom-
municateoveramodem(orleasedline)totransmitremotevotingrecords. Inaddition, theother
componentscommunicateindirectlythroughPCMCIAmemorycardscalled“MobileBallotBoxes”
(MBBs). Buildingasecurenetworkedsystemofthistyperequiresadoptinganattitudeofdefensein
depth: itmustbedesignedandimplementedinsuchawaythatacompromisedcomponentcannot
inducemisbehaviorinothercomponentsthatcommunicatewithit.
OurexaminationindicatesthatHart’ssystemisnotdesignedalongtheselines. Instead,thede-
signofthecomponentsmostlyassumesthatanyothercomponentoftheHartsystem(oranything
thatappearstobeone)istrustable:
Unsecurednetworkinterfaces NetworkinterfacesintheHartsystemarenotsecuredagainstdi-
rectattack.VoterscanconnecttounsecurednetworklinksinapollingplacetosubverteSlates,
aswellastoeavesdroponcastvotesandtoinjectnewvotes.PollworkerscanconnecttoJBCs
or eScans over the management interfaces and perform back-office functions such as modi-
fyingthedevicesoftware. Theimpactofthisisthatamaliciousvotercouldpotentiallytake
overoneormoreeSlatesinaprecinctandamaliciouspollworkercouldpotentiallytakeover
allthedevicesinaprecinct. Thesubvertedmachinescouldthenbeusedtoproduceanyre-
sultsoftheattacker’schoice,regardlessofvoterinput. Weemphasizethatthesearenotbugs
intheHartsoftware,butratherfeaturesintentionallydesignedintothesystemwhichcanbe
usedinafashionforwhichtheywereneverintended.
Vulnerabilitytomaliciousinputs Becausenetworkeddevicesmaybeconnectedtoother, poten-
tiallymaliciousdevices,theymustbepreparedtoacceptrobustlyanyinputprovidedbysuch
devices. TheHartsoftwareroutinelyfailstocheckthecorrectnessofinputsfromothercom-
ponents,andthenproceedstousethoseinputsinunsafeways. Themostdamagingexample
ofthisisthatSERVO,whichisusedtobackupandverifythecorrectnessofpollingplacede-
vicescanitselfbecompromisedfromthosesamedevices. Thisimpliesthatanattackercould
subvertasinglepollingplacedevice,throughitsubvertSERVO,andthenuseSERVOtore-
programeverypollingplacedeviceinthecounty. Althoughwehavetestedsomeindividual
componentsofthisattack,wedidnothavetimetoconfirmitinanend-to-endtest.
Noorinsecureuseofcryptography The standard method for securing network communication
ofthetypeinuseintheHartsystemistouseacryptographicsecurityprotocol. However,we
i
foundanotablelackofsuchtechniquesinHart’ssystem. Instead,communicationsbetween
devicesgenerallyhappenintheclear,makingattackfareasier.
CryptographyisusedforMBBs,butthekeymanagementinvolvesasinglecounty-widesym-
metrickeythat,ifrevealed,wouldallowanattackertoforgeballotinformationandelection
results. Thiskeyisstoredinsecurelyinvulnerablepolling-placedevices,withtheresultthat
compromiseofasinglepollingplacedeviceenablesanattackertoforgeelectionMBBscarry-
ingelectionresultsforanydeviceinthecounty.
Failuretoprotectballotsecrecy Hart’s system fails to adequately protect ballot secrecy. A poll
worker or election official with access to the raw ballot records can reconstruct the order in
which those votes were cast. Combined with information about the order in which voters
casttheirvotes,thiscanbeusedtoreconstructhoweachvotervoted. InthecaseoftheDRE,
itisalsopossibletoreconstruct,foreachvote,theorderinwhichthevoteswereauthorized.
Combinedwithinformationabouttheorderinwhichvoterswereauthorized, thiscanlike-
wisebeusedtoreconstructhoweachvotervoted. Furthermore,avoterwhohastemporary
access to an eSlate device can extract and reconstruct all the votes cast on that device up to
thatpointintime. HemaybeabletosimilarlyreconstructallvotescastonanyothereSlate
connectedtothesameJBC.
Manyoftheseattackscanbemountedinamannerthatmakesthemextremelyhardtodetect
andcorrect. Weexpectthatmanyofthemcouldbecarriedoutinthefieldbyasingleindividual,
withoutextensiveeffort,andwithoutlong-termaccesstotheequipment.
A manual examination of the paper trail would act as a defense against some of our attacks;
othersmaybemitigatedbyneworexistingproceduralcontrolsbyelectionofficials,orbychanges
totheHartsystem.Wherereasonable,weattemptedtoidentifysuchmitigationsandtoassesstheir
effectiveness. Insomecases,theremaybenosimple,effectivefixes.
We have deliberately avoided addressing the broader issue of whether or how this system
should be used for voting in California. Making that judgement requires assessing not only the
technicalissuesdescribedinthisreportbutalsotheproceduresandpolicieswithwhichthesystem
isused.
ii
Table of Contents
1 Introduction 1
1.1 SystemOverview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
1.2 Methodology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
2 Limitations 4
3 ThreatModel 7
3.1 ReferenceModel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
3.1.1 Pre-Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
3.1.2 Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
3.1.3 Post-Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
3.2 AttackerGoals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
3.2.1 ProducingIncorrectVoteCounts . . . . . . . . . . . . . . . . . . . . . . . . . . 10
3.2.2 BlockingSomeorAllVotersfromVoting . . . . . . . . . . . . . . . . . . . . . 11
3.2.3 ViolatingBallotSecrecy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
3.3 AttackerTypes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
3.3.1 Outsiders . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
3.3.2 Voters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
3.3.3 PollWorkers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
3.3.4 ElectionOfficials . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
3.3.5 VendorEmployees . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
3.4 TypesofAttacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
3.5 MechanismsforTamperSealing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
4 OverviewofSystemArchitecture 19
4.1 Pre-Election . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
4.2 PreparingVotingDevices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
4.3 Election-DaySetup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
4.4 AuthorizingandCastingVotes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
4.5 VoteCollectionandTallying . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
4.6 Post-ElectionAuditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
5 ArchitecturalIssues 24
5.1 AuthenticationFailures. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
5.2 LeastPrivilegeViolations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
5.3 InputValidation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
5.4 MisuseofCryptography . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
6 DetailedAnalysis 28
6.1 DeviceManagement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
6.2 eSlate-JBCCommunication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
6.2.1 DetailedDescription . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
6.2.2 TappingtheInterface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
iii
6.2.3 HijackingtheInterface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
6.3 SoftwareIntegrityChecks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
6.4 BufferManagementVulnerabilitiesinBack-EndSystems . . . . . . . . . . . . . . . . 46
6.5 PrivilegeIssuesinBack-endSystems . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
6.6 Windows-relatedVulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51
6.7 CryptographicKeyManagement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
6.8 MBBVoteStorage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
6.9 Rally/Tally’sUseofTLS/SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
6.10 VerifiedBallotOptionIssues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
6.11 CodeQualityandMiscellaneous . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
7 AttacksontheFullSystem 72
7.1 CompromisingVoterPrivacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
7.1.1 VoteBuyingoneSlateSystems . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
7.1.2 VoteBuyingoneScanSystems . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
7.1.3 InformationGathering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
7.2 AlteringtheFinalVoteCount . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
7.2.1 eScan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
7.2.2 eSlate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
7.2.3 VotinginOtherPrecincts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
7.2.4 DenialofService . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
7.3 SubvertingallDREDevicesinaPrecinct . . . . . . . . . . . . . . . . . . . . . . . . . . 77
7.4 SubvertingalltheDevicesinaCounty . . . . . . . . . . . . . . . . . . . . . . . . . . . 77
8 DetectionandRecovery 79
8.1 Detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79
8.1.1 TheOnePercentManualRecount . . . . . . . . . . . . . . . . . . . . . . . . . 80
8.1.2 TotalVoterCounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
8.1.3 MechanicalLogComparisons . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81
8.1.4 TamperSeals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81
8.1.5 ParallelTestingandLogicandAccuracyTesting . . . . . . . . . . . . . . . . . 81
8.1.6 FirmwareForensics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
8.2 Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
9 RecommendationsforFutureAnalysis 84
9.1 TimeLimitation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
9.2 InadequateInformationaboutProcedures . . . . . . . . . . . . . . . . . . . . . . . . . 84
9.3 InsufficientAccesstoMaterials . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85
9.4 DifficultyinTestingHypothesesaboutSystemOperation . . . . . . . . . . . . . . . . 86
10 SummaryofFindings 87
Bibliography 88
A SystemComponentsandVersions 92
iv
List of Issues
Issue1 TheJBCismanagedviaanaccessibleparallelport. . . . . . . . . . . . . . . . . . . 30
Issue2 TheeSlateismanagedviaaserialportconnectedtotheJBC . . . . . . . . . . . . . 31
Issue3 TheeScanismanagedviaanaccessibleEthernetport . . . . . . . . . . . . . . . . . 32
Issue4 TheJBCvoterregistrationinterfacecanbeusedtogeneratevoteraccesscodes . . 32
Issue5 eSlate-JBCcommunicationisinsecure . . . . . . . . . . . . . . . . . . . . . . . . . . 37
Issue6 FormatstringvulnerabilitiesinJBCreportmode. . . . . . . . . . . . . . . . . . . . 39
Issue7 TheJBCaccesscodegeneratorisinsecure . . . . . . . . . . . . . . . . . . . . . . . . 40
Issue8 TheJBCwillacceptvotesfromeSlatesthatarenotinanauthorizedstate . . . . . 41
Issue9 eSlate/JBCinternalCRCchecksdonotdetectattacks . . . . . . . . . . . . . . . . . 42
Issue10 JBCinternalversioncheckingisbroken . . . . . . . . . . . . . . . . . . . . . . . . . 43
Issue11 SERVO-baseddevicefirmwarecheckingcanbespoofed . . . . . . . . . . . . . . . 43
Issue12 JBC-basedeSlatefirmwarecheckingcanbespoofed . . . . . . . . . . . . . . . . . . 45
Issue13 MultiplebufferoverflowsinSERVO . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
Issue14 AnimproperlyformattedMBBwillcauseRallyorTallytocrash. . . . . . . . . . . 47
Issue15 Databasepasswordsarestoredinsecurely . . . . . . . . . . . . . . . . . . . . . . . 48
Issue16 BallotNowcountersarestoredindatabase . . . . . . . . . . . . . . . . . . . . . . . 49
Issue 17 The Tally interface allows a Tally administrator to “adjust vote totals.” This can
createinconsistenciesinthereportedvotetotals. . . . . . . . . . . . . . . . . . . . . 49
Issue18 Databasesarenotencrypted . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
Issue19 Newuserscanbeaddedviathedatabase . . . . . . . . . . . . . . . . . . . . . . . . 51
Issue20 Back-endWindowssystemsmaybeinsecure . . . . . . . . . . . . . . . . . . . . . . 52
Issue21 ManyHartsystemsareconnectedtointernalnetworksormodems,openingthem
toattacksagainstWindows’vulnerabilities. . . . . . . . . . . . . . . . . . . . . . . . 53
Issue22 ThesamesymmetriceCMkeyisusedcounty-wide . . . . . . . . . . . . . . . . . . 55
Issue23 ECMkeysarestoredinsecurelyontheeCMmanager . . . . . . . . . . . . . . . . . 56
Issue24 eCMkeysareextractedandstoredinsecurely . . . . . . . . . . . . . . . . . . . . . 57
Issue25 Voteordercanbedetermined . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
Issue26 MBBisnotprotectedduringvoting . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
Issue27 HandlingofprecinctIDsinCVRs . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61
Issue28 UserscanreadunclosedMBBsorMBBswithinvalidMACs . . . . . . . . . . . . . 62
Issue29 Theprotectivecounterissubjecttotampering . . . . . . . . . . . . . . . . . . . . . 63
Issue30 IftwoMBBshavethesameID,Tallyonlyreadsthefirstone . . . . . . . . . . . . . 63
Issue31 RallyandTallyuseanoldversionofOpenSSLwithknownbugs. . . . . . . . . . . 64
Issue 32 Rally and Tally, when presented with an unknown certificate, will present the
unauthenticatednameandorganizationtotheuserforverification. . . . . . . . . . 66
Issue33 VBOxprintingandscrollingiscontrolledbytheeSlate . . . . . . . . . . . . . . . . 67
Issue34 TheVBOxcodeindicatesareversefunction . . . . . . . . . . . . . . . . . . . . . . 68
Issue35 TheVBOxvotesaresequentialandsocompromisevoteprivacy . . . . . . . . . . 69
Issue36 Pervasivefailuretofollowcommonlyagreedsafecodingpractices . . . . . . . . . 69
v
CHAPTER 1
Introduction
ThisreportwaspreparedbytheUniversityofCalifornia,BerkeleyattherequestoftheCalifornia
SecretaryofState,aspartofa“top-to-bottom”reviewofthestate’selectronicvotingsystems. This
documentisthefinalreportoftheteamthatexaminedtheHartvotingsystemsourcecode.
TheHartsystemsourcecodereviewteamwaslocatedatSRIInternationalinMenloParkand
consisted of the four authors of this report: Srinivas Inguva, Eric Rescorla, Hovav Shacham, and
DanWallach. WefrequentlyconsultedwiththeUCBerkeley-baseddocumentationteam1 andthe
Sacramento-based“RedTeam”2. Allopinionsexpressedinthisreport,however,aresolelythoseof
itsauthors.
We started work on June 15, 2007 and received the Hart system source code on June 18, 2007.
WorkendedonJuly20,2007withthedeliveryofthisreport.
1.1 System Overview
TheHartsoftwarewereviewedispartofacomprehensivesystemthatincludesDirectRecording
Electronic (DRE) voting machines and optical scan ballot collection equipment for use at polling
places,aswellaselectiondefinition,managementandcountingsoftwareandhardwareforuseat
acountyelectionsheadquarters. ThespecificsystemcomponentscertifiedforuseinCaliforniafor
which we reviewed source code were from Hart system version 6.2.1, comprising the following
components:
• BallotNow,version3.3.11
• BOSS,version4.3.13
– BossUtil,version2.5.8
– TranslateDLL,version1.8.2
• eCMManager,version1.1.7
• eScan,version1.3.14
• eSlate,version4.2.13
• HartLib,version4.0
• JBC,version4.3.1
• Rally,version2.3.7
• SERVO,version4.2.10
1JosephLorenzoHallandLauraQuilter
2RobertAbbott,MarkDavis,JosephEdmonds,LukeFlorer,BrianPorter,ElliotProebstel,SujeetShenoi,andJacobStauf-
fer
1
1. Introduction
• Tally,version4.3.10
• VBOPrinterFirmware,version1.8.3
The centralized back-end processing functions (ballot preparation, voting machine configura-
tion,andpost-electionvotecounting)areperformedbyBOSS,BallotNow,Tally,andSERVO,which
are all software running on Windows-based PCs. Cryptographic keys are distributed on eSlate
CryptographicModules(eCMs)whicharemanagedusingtheeCMManager, whichalsorunson
Windows.
Precinct polling stations can be equipped with DRE terminals, optical scan ballot readers or
both. Normally, precinct-based optical ballot scanning is performed with Hart’s eScan systems
while central optical ballot scanning is performed with Hart’s Ballot Now.3 DRE voting uses a
networkofeSlatescontrolledbyasingleJBC.ResultsarereturnedtoElectionCentralusingMobile
Ballot Boxes (MBBs), which are standard PCMCIA memory cards. Election results can also be
returned using the Rally software, which transmits them to Tally via modem connections from
regionalprocessingfacilities.
The software comprises approximately 360K lines of source code, written primarily in C++,
C, and PowerBuilder. The back-end software runs on Microsoft Windows. The eScan runs on
WindowsCEoncustomembeddedhardware.TheeSlatesandJBCsrunonanembeddedoperating
systemoncustomembeddedhardware. (Wewerenotprovidedwithsourcecodetoanyofthese
operatingsystems.)
AdetaileddescriptionofthesystemarchitectureandoperationcanbefoundinSection4.
1.2 Methodology
Discovery of programming errors is a notoriously difficult problem in computer science, and no
general methodology exists that is guaranteed to find all problems in even very small programs.
The large size and complexity of the Hart InterCivic system makes a complete review an espe-
ciallydauntingtaskundereventhebestconditions,butparticularlysoheregiventhelimitedtime
availableandtheotherconstraintsimposedonusbythetermsofthereview.
Our focus was on whether the software contains effective safeguards against error and abuse
aimed at altering election results, changing votes, denying service, altering audit logs, and com-
promisingvoters’ballotsecrecy. Morebroadly,weexploredissuesrelatedtoourconfidenceinthe
securityandreliabilityofthearchitectureandimplementationasawhole.Ingeneral,inourreview
weattemptedtoexplorequestionsofarchitecturalsoundness:
• Doesthedesignandimplementationfollowsound,generallyacceptedengineeringpractices?
Is code defensively written against bad data, errors in other modules, changes in environ-
ment,andsoon?
• Isthecryptographyandkeymanagementsound? Iscryptographycorrectlyusedtoprotect
sensitivedataonuntrustedmedia? Doesthecryptographyemploystandardalgorithmsand
protocols? Arekeysmanagedaccordingtogoodpractices?
• Whatarethetrustedcomponentsofthesystem,whenaretheytrustedandforwhatpurposes?
Whatpartiesaretrustedandforwhatpurposes? Whataretheimplicationsofacompromise
oftrustedcomponents?
• Aresecurityfailureslikelytobedetected?Areauditmechanismsreliableandtamper-resistant?
Aredatathatmightbesubjecttotamperingproperlyvalidatedandauthenticated?
Our review of the source code was focused on answering these questions, rather than exam-
iningtheentirecodebase. Wewereparticularlyinterestedinissueswhichallowanuntrustedor
3“BallotNowistobeusedonlyascentralprocessingapplication[sic]andisnottobedeployedtoremotelocations
outsideofcentraljurisdictionelectionheadquarters.”[21],page33.
§1.2Methodology 2
1. Introduction
minimallytrustedusertoescalatehiscapabilitiesbeyondthoseforwhichhewasauthorized. We
alsoattemptedtofocusonissuesthatwouldrequiresubstantialrearchitectingtofixratherthanon
individualvulnerabilitiesunlesstheywerereflectiveofsystematicdesignorarchitecturalissues.
Weusedavarietyoftoolstosupportouranalysis. Weusedanopensourcewikionoursecure
networktosummarizeandtrackthevarioussoftwareissuesunderinvestigationandtoprovidea
commonknowledgebaseamongtheteammembers4. WeusedtheFortifySCAstaticanalysistool
toidentifypotentialproblemareasinpartsoftheHartInterCivicsoftware. (WearegratefultoFor-
tifySoftwareformakingthetoolavailabletous.)Variousdebuggers,programeditors,decompilers
andothertoolswereusedtoexperimentwithandconfirmsoftwarestructureandbehavior.
We have deliberately avoided addressing the broader issue of whether or how this system
should be used for voting in California. Making that judgement requires assessing not only the
technicalissuesdescribedinthisreportbutalsotheproceduresandpolicieswithwhichthesystem
isused.
4Thecontentsofourwikiweresubmittedastheprivateannextothisreport.
§1.2Methodology 3
CHAPTER 2
Limitations
Ouranalysisfocusedonsystemdesignandarchitecture. Althoughsourcecodewasavailable,the
largesizeofthecodebaseandthelimitedtimeavailableprecludedacomprehensivereviewofthe
sourcecode. Nosecurityanalysiscanguaranteediscoveryofallsystemvulnerabilities;duetothe
short timeframe, this analysis is even more limited. Therefore, no assertions can be made about
nonexistenceofparticularvulnerabilitiesinthesource. Wemadeagood-faithefforttoidentifyand
prioritizesecurityvulnerabilitiesbasedongenerallyknownandacceptedsecurityprinciples, but
wecautionthatadditionalvulnerabilitiesmayexistthatarenotdocumentedinthisreport.
Wedidnotattempttoverifythatthevotingsoftwareiscompletelyfreeofdefectsortoexhaus-
tivelyenumeratealldefects,asthatexceedswhatisfeasiblewiththestateofart:
• ThescaleoftheHartInterCivicsystemmakesacomprehensivereviewinfeasible. TheHart
InterCivic system contains over 300,000 lines of code (See Appendix A for details), which
wouldhavebeenimpracticaltoreviewinthetimeallowed.
• Even thorough manual code review misses many problems. People are fallible; a code re-
viewermightoverlookadefectinthecodethesamewaythatthedeveloperwhowrotethe
codedid. Amanualreviewthatfoundhalfofallproblemsinthecodewouldbedoingpretty
well, by industry standards, but that would still leave many undetected defects. Moreover,
manualcodereviewoftenmissesarchitecturalflawsandotherissuesthatdonotclearlyman-
ifestthemselvesattheimplementationlevel.
• Manual source code inspection is laborious, time-intensive, and costly. A rough estimate is
thatatrainedsoftwareengineercaninspectsomethinglike100linesofcodeperhour,under
optimal conditions. If team members did nothing other than read source code for hours on
end—somethingthatfewdeveloperscansustainforanylengthoftime—thenitwouldhave
taken us a person-year or more of effort to read all of the source code. That would have
significantlyexceededourbudgetandthetimeavailabletous.
• We made no attempt to find all bugs or vulnerabilities in the code. Once we found several
relatedvulnerabilitiesinthesameportionofthecode,westoppedlookingforothervulner-
abilities of the same type. We made no attempt to catalog all bugs that might enable any
particularkindofattack. Instead,westructuredouranalysisasanattempttofindevidence
to confirm or refute the hypothesis that the voting system is secure from tampering. Once
wefoundstrongevidencethatsomeaspectofthesystemwasvulnerabletoacertainkindof
tampering,wemovedontoexaminesomeotheraspectofthesystem. Thismethodologywas
selectedduetothelimitedtimeavailableforthisreviewandbecauseitseemstomakelittle
differencewhetheranattackerhas3or30differentattackvariationsavailabletohimifallthe
variationshavethesameimpact.
As a consequence, the list of issues and defects in this report should not be taken as a compre-
hensivelist. Inourreview,wesingledoutalimitedsubsetofthecodeasespeciallycritical,based
onourarchitecturalanalysis,andthensubjectedthatportionofthesourcecodetointensivecode
4
2. Limitations
inspection. Sincewedidfindsecurityvulnerabilitiesinthesourcecodethatwassubjecttoinspec-
tion,onemightanticipatethattherestofthecodethatwedidnothavetimetoinspectmightalso
containvulnerabilities. Forthisreason,itislikelythatthisreportunderestimatesthetruenumber
ofvulnerabilitiesinthecode,anditispossiblethattheissuesidentifiedinthisreportmightrepre-
sentonlythe“tipoftheiceberg.” However,becausewewereonlyabletoinspectasmallfraction
ofthecode,wesimplydonotknowwhethertherestofthecodecontainssecurityvulnerabilities.
Because the time available for this report was so short, we were unable to perform as com-
plete testing for each issue as we would have liked. Instead, we prioritized issues based on our
estimatesofpotentialseverityandourconfidenceinouranalysisofthecode. Thisallowedusto
directly confirm some issues and to partially confirm others. However, this still leaves a number
of issues which we did not have time to confirm and others for which we would have wished to
perform more tests. For each issue we discuss, we also describe the experiments (if any) we per-
formed to confirm it, allowing the reader to draw their own conclusions. In many cases, issues
werediscoveredinthesourcecodewithoutconfirmationonactualHartsystems. Forsuchissues,
wedescribeourrelativeconfidenceineachonebeingaviableattack.
The analysis contained in this document is based on data gathered from documentation and
sourcecodeprovidedbyHartInterCivic, theStateofCalifornia, andtheITAs(IndependentTest-
ing Authorities). We made no attempt to validate the materials provided to us. Our conclusions
depend on interpretation of those documents and source code. To the extent to which those ma-
terials are incomplete, inaccurate, or do not reflect the systems and practices currently in use in
California,thismayleadtomaterialinaccuraciesinthisreport.
There was some software that we were not provided and thus did not review. The software
whosesourcecodewebelievewasnotmadeavailabletousislistedinAppendixA.However,we
donothaveacompletelistofthesoftwarethatisusedinthevotingsystembutwhosesourcecode
wasnotprovidedtous. Weunderstandthatsomeofthissoftware,suchasthestandardClibraries,
maybeclassifiedasunmodifiedCOTS(commercialoff-the-shelf)softwareunderthefederalvoting
standards and thus may be exempt from scrutiny by the ITAs (Independent Testing Authorities).
Other software was apparently written by Hart InterCivic but was not made available to us. In
theabsenceofsourcecodetotheCOTSsoftware,wewerenotabletoverifywhetheritqualifiesas
unmodifiedCOTSundertheprovisionsofthefederalvotingstandards. Itwasbeyondthescope
of this review to evaluate whether any of the missing source code falls within the definition of
unmodifiedCOTSsoftware,asdefinedinthefederalvotingstandards.
Wemadenoattempttoverifythatthesourcecodeprovidedtousmatchesthebinarycodethat
isexecutedonelectiondayintheHartInterCivicvotingequipment. Thatwasbeyondthescopeof
this review. Also, while we were provided with binary executables for some of this software, we
werenotprovidedwithafullbuildenvironmentthatwouldenableustocompilethesourcecode
forourselvesandverifythattheresultswereidenticaltothebinaryexecutablesprovidedtous.
Wemadenoattempttosearchforsecurityproblemsinthehardware. Thatworkwasdoneby
aseparate“RedTeam.” Instead,ouranalysiswasbasedonanalyzingthesourcecodeprovidedto
us.
Wedidnotattempttosearchforconfigurationproblemsortoanalyzewhetherthevotingsys-
tem, as installed in California counties, is configured correctly. This was out of the scope of this
workandwedidnothaveaccesstoanycounty’sHartinstallationsinanycase.
We did not attempt to analyze the procedures, processes, or practices used by local election
officialsforpotentialsecurityproblems. Weweregivenoperator’smanualsfortheHartInterCivic
equipment,andwefrequentlyusedthemtogaininsighthowthesystemmightbeusedinpractice.
However,wewerenotprovidedwithinformationabouttypicalcounty-levelpractices,limitingour
abilitytoexaminehowthevotingsystemisusedinthefieldandhowthosepracticesmayenable
orhindersecurityattacks.
Thesecurityofavotingsystemdependsuponboththetechnology(e.g., thesoftware)aswell
asuponhowitisused(e.g.,theprocessesandproceduresinplace). Wewereaskedtofocusinthis
reviewprimarilyonthesoftwareandaccompanyingdocumentation,notonhowitisused. There-
fore, any potential issues we identify in this report might or might be relevant to any particular
useroftheequipment,dependinguponthepracticesinplaceinthatjurisdiction. Itwouldrequire
5
2. Limitations
aseparate,follow-onstudytoevaluatetheimpactoftheseissuesonindividualCaliforniacounties
andotherusersofthisvotingsystem.
ThescopeofthisworkwaslimitedtoanalysisoftheHartInterCivicvotingsystem,notthatof
California’sentireelectionsystem. Forinstance, voterregistrationsystems, countypractices, and
electionlawwereoutsidethescopeofthisstudy.
Our analysis was limited to a particular version of the Hart InterCivic voting system. This
reportisnotintendedasanendorsementorrepudiationofelectronicvotingingeneral.
6
CHAPTER 3
Threat Model
The first step in security analysis of a system is to define the threat model. The threat model for a
systemisintendedtodescribethegoalsanattackermighthave(e.g.,tomanipulatethevotecount)
andthetypesofattackersthatmightattempttoattackthesystem(e.g., voters, pollworkers, etc.)
aswellasthecapabilitiesavailabletoeachtypeofattacker. Itisequallyimportanttodescribethe
threats that are out of scope for the analysis. This study was chartered to consider the security
of voting systems proper only, not that of California’s entire election system, and therefore many
possibleattacksareoutofscopeforthisreport.
3.1 Reference Model
In order to simplify the analysis, we assume a common reference model, which distills what are
hopefully the essential features of all of the voting systems involved in this study. The system
consistsofthefollowingcomponents.
Inthepollingplace:
• Managementstations(MS)
• Direct recording electronic (DRE) voting machines, attached to Voter Verified Paper Audit
Trail(VVPAT)printers
• Paperballotopticalscanners(opscan)
AtElectionCentral:
• Anelectionmanagementsystem(EMS)
• High-speedpaperballotopticalscanners(e.g.,forabsenteevotes)
Theelectioncanbethoughtofasproceedinginthreestages(forsimplicity, weareignoringearly
votingcenters):
Pre-voting: Beforeelectionday,electionofficialsusetheEMStosetuptheelection. Theygenerate
theballotdefinition(s)andrecordthemontomediafordistribution. Duringthisstage,voting
machinesarealsopreparedanddistributedtopollingplaces.
Voting: Onelectionday,votersarriveatthepollingplace,areverifiedasbeingpermittedtovote,
andcasttheirballots.
Post-voting: Afterthepollsareclosed,thevotesaretallied,theofficialcanvass(includingtheone
percentmanualrecount)isperformed,andtheresultsarecertified.
TherelationshipbetweenthesecomponentsisshowninFigure3.1.
7
3. ThreatModel
EMS
n
o B
Results Results
fi
niti allot
D
Results
all
ot
d
e efi
nition
B
VVPAT DRE MS OPSCAN
Token/ Marked
Token
Votes Ballot
DRE Token Poll Ballot Opscan
Voter Worker Voter
Figure3.1: Referencearchitecture
3.1.1 Pre-Voting
Inthepre-votingphase,electionofficialsneedto:
• Createtheelectiondefinition.
• Printthepaperballotsusedforopticalscansystems.
• Resetthelocalvotingequipmentandpotentiallyloadtheelectiondefinitions.
• Distributethelocalvotingequipmenttothepollingplaces.
There is some variation among voting system vendors, but in general the EMS is used to cre-
ate the ballot definition files. These are then loaded onto some memory card/cartridge and/or
directlyontothevotingmachines. Thevotecountersinthemachinesarereset,theinternalclocks
are set to the correct time, and the machines are then shipped out to the local polling places or
provided to poll workers to be hand-carried to the polling place. The ballot definition files must
beprotectedfromtamperingandsomemorycard/cartridgesaregenerallydistributedwithsome
physicalsecuritymeasures,eitherbysealingthemintothelocalequipmentatthecentralofficeor
bydistributingtheminasealedpackage. Sealsmaytaketheformoftamper-evidenttapeormay
take the form of metal or plastic loops, individually numbered, which once installed can only be
removedbycuttingthem.
3.1.2 Voting
Oncethepollsopenonelectionday,votingcanbegin. Theexactdetailsofthevotingphasediffer
with the technology and manufacturer in use, but there is a fair amount of commonality across
manufacturerswithinagiventechnology(DRE,opscan).
§3.1ReferenceModel 8
3. ThreatModel
Opticalscanmachines. Opscanvotingcanmosteasilybethoughtofasmachine-countedpaper
ballots. Alltheproceduresherecouldbereplicatedbyhumanswithappropriateauditcontrols.
When an opscan voter enters the polling place, and is verified as permitted to vote, he or she
is given a blank paper ballot. He or she marks the ballot with a pen or pencil and the ballot is
thenmechanicallycountedwithanopticalscanner. Thiscanbedoneeitherlocallyorcentrally. In
thelocalcase,theprecincthasascannerwhichcountstheballotsastheyareinserted. Ingeneral,
thevoterpersonallyinsertstheballotintothescanner. Precinct-basedopticalscannerscandetect
“overvoting” and reject such ballots, giving the voter an opportunity to correct the error. At the
end of the day, the scanner’s electronic records are then sent back to the county for aggregation
withrecordsfromotherprecincts. Thepaperballotsarealsosentback,forauditingandrecounts.
Withcentralcounting,untabulatedballotsintheiroriginalballotboxaresentbacktoElection
Central(i.e.,thecounty’selectionheadquarters)wheretheyaretabulatedwithahigh-speedscan-
nerundersupervisionoftheelectionofficials.Centralandprecinct-basedtabulationmaybemixed
inavarietyofways. Centraltabulationisnaturallyusedforabsenteeballotsandcanalsobeused
forauditsandrecountsofprecinct-castballots,whetherornottheywereoriginallytabulatedinthe
precinct.
DREmachines. DREvotingisfundamentallydifferentfromopscanvoting. Insteadofentering
their vote on paper, the voter uses a computer-based graphical user interface (GUI). Once the vote
has been “cast,” an electronic records of the vote is stored locally, in the DRE machine (and, in
the case of the Hart system, a copy is also stored in the management station). At the end of the
day,theseelectronicrecordsmayeitherbeextractedfromtheDREmachinesonmemorycards,or
maybetransmittedviamodems,ortheDREsthemselvesmaybetransportedtoElectionCentral.
In any case, the EMS will collect the electronic records from each precinct and will tabulate them
electronically.
Aswithopscanvoting,inDREvoting,thevoterentersthepollingplaceandfirstestablisheshis
orhereligibilitytovote. However,somemethodmustbeusedtolimitauthorizedvoterstocasting
onlyonevote. InalltheDREsystemsinthisstudy,thepollworkerusesanadministrativedevice
toissuethevoteratokenofsomesort. Thevotermaythentakethistokentoanyvotingmachine
and vote once. With Diebold and Sequoia, the token is a smartcard. With Hart, it is a four-digit
“AccessCode.”
Oncethevotingmachineisactivated,ittakesthevoterthrougheachcontestandallowshimor
her to select candidates. DRE machines automatically forbid overvotes (too many votes cast in a
contest)butnotundervotes(toofewchoicescastinacontest). Thevoteristhenpresentedwithan
opportunitytoreviewhisballotandthencommitstoit(“casts”it),atwhichpointitisrecordedto
localstorage.
In California, a voter-verified paper audit trail (VVPAT) is required. On all the machines under
study,thistakestheformofasealedprinterwithacontinuousspoolofpaperattachedtotheDRE.
Beforethevoterconfirmshisballot,asummaryisprintedoutontheprinteranddisplayedthrough
a glass window. Once the voter accepts or rejects the ballot, an appropriate indication is printed
on the VVPAT record. When the voter casts the ballot, the VVPAT record is marked as accepted
and scrolled out of sight. Because the paper scroll is held behind glass, it becomes more difficult
for a voter to “stuff” additional ballots into the machine or to take the record of their vote home,
incorrectly,as“receipt.”
Once the election is over, the local results are transmitted to the Election Central, typically by
shipping some form of removable memory device from the voting machine. The VVPAT paper
rolls, perhaps still sealed in their printers, are also sent to the Election Central to be used in the
legallyrequired1%audit.
In larger counties, many vendors offer the ability to establish “regional processing centers.”
Election results are delivered by courier from the precincts to the centers, aggregated, and then
communicatedbacktoElectionCentralviaelectronicmeans(modems,Internetconnections)orvia
courier.
§3.1ReferenceModel 9
3. ThreatModel
Typicaldeployments. Therearetwocommonmodelsfordeployingthisequipmentinthepolling
place. In the DRE-only model, every polling place contains some number of DREs, most or all
votersvoteontheDREs,andtherearenoopticalscanmachinesinthepollingplace. Inthehybrid
model, everypollingplacecontainsoneopticalscanmachineandoneormoreDREs; votersmay
have the option whether to vote on paper ballots or using the DRE, or the DRE may be reserved
for voters with disabilities and all others may vote on paper ballots. In California, each county
determineswhichmodelismostappropriatefortheirneeds.
3.1.3 Post-Voting
Aftertheelectionisovertheelectionofficersneedtodo(atleast)threethings:
1. Tabulatetheuncountedopscanandabsenteeballots.
2. Producecombinedtalliesforeachcontestbasedontherecordsreceivedfromtheindividual
precinctsandthetalliesofcentrallycountedballots.
3. Perform the official canvass. This may involve reconciling the number of voters who have
signed in against the number of ballots cast, performing the statutory 1% manual recount,
andothertasks.
Thefirsttwotasksarerelativelystraightforward,thoughit’simportanttonotethatthesecond
task is typically performed based on electronic records. In the most common case, the precincts
sendbackmemorycardscontainingtheelectionresultsandthosecardsareaddeddirectlytothe
tallywithoutanyreferencetothepapertrail(except,ofcourse,forcentrallytabulatedopscanand
absenteeballots).
The1%manualrecountcomparesthepaperrecordsforagivensetofvotestothereportedvote
totals. Inthecaseofopscanballots,thismeansmanuallyassessingeachopscanballot. Inthecase
ofDREs,itmeansmanuallyassessingthevotesontheVVPATrecords. Notethatwhileinprinciple
theopscantallymaydifferslightlyfromthepaperballotsduetovariationinthesensitivityofthe
mark/sensescanner,theVVPATrecordsshouldexactlymatchtheDRErecords.
3.2 Attacker Goals
Atahighlevel,anattackermightwishtopursueanyofthefollowinggoalsorsomecombination
thereof:
• Produceincorrectvotecounts.
• Blocksomeorallvotersfromvoting.
• Violatethesecrecyoftheballot.
An attacker might wish to pursue any of these goals either generally or selectively. For example,
anattackermighttargetacertainsubsetofvoters(e.g.,registeredRepublicans,orvoterswholive
withinacertaingeographicarea)toattack. Also,theabilitytodeterminehowanindividualvoted
canbeusedtoenablevotebuyingorvotercoercion,eitherindividuallyorenmasse.
3.2.1 ProducingIncorrectVoteCounts
Themostobviousattackonavotingsystemistoproduceincorrectvotecounts. Anattackerwho
cancausethevotestoberecordedorcountedinawaythatisdifferentfromhowpeopleactually
votedcanaltertheoutcomeoftheelection. Thereareanumberofdifferentwaystoinfluencevote
counts,including:
• Confusevotersintovotingdifferentlythantheirintent.
§3.2AttackerGoals 10
3. ThreatModel
• Alterthevotes,withinthecomputer,beforetheyarerecorded.
• Altervotesinthevotestoragemedium,aftertheywereoriginallyrecorded.
• Corruptthevotetabulationprocess.
Whichattacksarefeasibledependsontheattackercapabilities.
3.2.2 BlockingSomeorAllVotersfromVoting
Twoclassicaltechniquestoinfluenceelectionoutcomes, regardlessoftheelectiontechnologiesin
use,arevotereducation/encouragement(i.e.,“getoutthevote”)orvotersuppression. Ifwelimit
the context to attacks specifically on voting systems, an attacker might mount a similar attack by
makingitverydifficultforcertainclassesofvoterstovote. Forexample,anattackermight:
• Arrange for some subset of machines to malfunction, possibly those in precincts in which
votersoftheoppositepartyareoverrepresented.
• Arrangeformachinestoselectivelymalfunctionwhenvotersattempttovoteinacertainway.
• Arrangeforallthemachinesinanelectiontomalfunction.
Thefirsttwooftheseattacksareselectiveattacksandcouldbeusedtoinfluencetheoutcome
of an election. A more global attack is primarily useful for denial-of-service or to invalidate an
election,butcouldpotentiallybeusedforextortionaswell. Theseattackswouldgenerallyrequire
tamperingwiththesoftwarewithinthevotingmachines.
3.2.3 ViolatingBallotSecrecy
Anattackerwhocannotinfluencevotingdirectlymightstillbeabletodeterminehowindividuals
orgroupsvoted. Therearetwonaturalapplicationsforthiskindofattack:
• Votebuying/votercoercion
• Informationgathering
Inavotebuyingorvotercoercionattack,theattackerpaysindividualvoterstovoteinaspecific
wayorthreatensretributioniftheydonot. However,inorderforsuchanattacktobesuccessful,
theattackerneedstobeabletoverifythatthevoterinfactvotedthewayheagreedto. Notethat
the buyer does not need to be able to determine with absolute certainty how a voter voted, but
merelyneedsahighenoughconfidencethatdefectionbybribedvotersbecomesunattractive. The
primary benefit of traditional secret-ballot voting is that that it allows the voter to cast a vote in
completesecrecy, defeatingtheattacker’sabilitytovalidateavoter’scastballotandthusmaking
votebuyingorcoercionunattractive.
Another possible reason to violate voter secrecy is to gather information on a large group of
people. Forexample,anattackermightwishtodeterminewhichvotersweresympathetictoapar-
ticularpoliticalparty(buthadnotregisteredwithit)andtargetthemforinvestigation,surveillance,
or even targeted mail or telephone solicitations. Alternately, an attacker might wish to publish a
given voter’s votes in an attempt to influence public opinion about them. In either case, ballot
secrecyisrequiredtoblocktheseattacks.
3.3 Attacker Types
Avotingsystemcanbesubjecttoattackbyanumberofdifferenttypesofattackerswithdifferent
capabilities and who will therefore be able to mount different kinds of attacks. We consider the
followingbroadclassesofattackers,listedroughlyinorderofincreasingcapability.
§3.3AttackerTypes 11
3. ThreatModel
Outsiders have no special access to any of the voting equipment. To the extent that voting or
tabulation equipment is connected to the Internet, modems, wireless technologies, and so
forth,anattackercanmountnetworkormalware-basedattacks. Outsidersmayalsobeable
to break into locations where voting equipment is stored unattended and tamper with the
equipment.
Voters havelimitedandpartiallysupervisedaccesstovotingsystemsduringtheprocessofcasting
theirvotes.
Pollworkers haveextensiveaccesstopollingplaceequipment,includingmanagementterminals,
before,during,andaftervoting.
Electionofficials haveextensiveaccessbothtotheback-endelectionmanagementsystemsaswell
astothevotingequipmentthatwillbesenttoeachprecinct.
Vendoremployees have access to the hardware and source code of the system during develop-
ment and may also be called upon during the election process to assist poll workers and
electionofficials.
Note that these categories are not intended to be mutually exclusive—a given attacker might
havethecapabilitiesofmorethanonecategory. Forexample,itmightbepossibletocombinethe
limitedphysicalaccessavailabletoavoterwithanetworkattacksuchasanoutsiderwouldmount.
Inaddition,notallmembersofagivenclasshaveidenticalcapabilities;anon-sitevendoremployee
hasadifferentlevelofaccessthananemployeewhoonlyworkswiththesourcecode.However,the
purposeofthisclassificationistoguideanalysis,nottoprovideacompletetaxonomyofattackers.
A particular focus of security analysis is privilege escalation. In many cases, one participant in
thesystemisforbiddentoperformactionswhicharenormalforanotherparticipantinthesystem.
A key feature of a secure design is enforcing such restrictions. For example, a voter should only
be allowed to vote once, but poll workers are in charge of allowing people to vote and therefore
mustbeabletoauthorizenewvoterstoaccessthesystem. Avoterwhowasabletouselegitimate
access to the voting terminal to acquire the ability to authorize new voters would be an example
ofprivilegeescalation. Similarly,pollworkersareentrustedwithmaintainingtheintegrityoftheir
pollingplace. Ifapollworkerwasabletouseauthorizedaccesstoonepollingplacetoinfluence
ordisruptthevotingequipmentlocatedinotherpollingplaces,thatwouldbeanotherexampleof
privilegeescalation.
3.3.1 Outsiders
Anoutsidertothesystemhasnoauthorizedaccesstoanypieceofvotingequipment. Theymaybe
completelyoutsidethesystemormaybephysicallypresent(perhapsasanobserver)butnotable
tophysicallytouchtheequipment. Suchanattackerhaslimitedcapabilitiesinthecontextofthis
review. Theymight,forexample,enterthepollingplacewithgunsandforcefullymanipulatethe
voting systems (at least, until the police arrive). This sort of attack is explicitly out of our scope,
althoughthe“boothcapture”problemisverymucharealconcernoutsidetheU.S.[27].
Outsiders may have the power to mount network- or malware-based attacks. Both election
management systems and the development systems used by the voting vendors typically run on
generalpurposeoperatingsystems—Windowsinthecaseofallthesystemsinthisreview. Ifthose
machinesareconnectedtotheInternetorconnectedtomachineswhichareoccasionallyconnected
totheInternetortheoutsideworldinanyway(laptopsareapopularchannel),anattackermight
managetoinfectthesystemsandtherebyalterthesoftwarerunningontheelectionmanagement
systems or even the polling place systems. In that case, individuals anywhere in the world may
havetheopportunitytoattackthevotingsystem.
Outsiders may also have the power to physically tamper with voting equipment. In many
counties,votingequipmentisstoredunattendedatthepollingplaceovernightbeforetheelection.
Whilepollingplacesmaybelockedovernight,mostpollingplacesarelow-securitylocations;they
may be located at a school or church or public building or a citizen’s garage. Consequently, an
§3.3AttackerTypes 12
3. ThreatModel
attackerwhoiswillingandabletobreakintothepollingplace,eitherbysurreptitiouslypickingthe
lockorbyforciblyentering,canlikelyobtainunsupervisedphysicalaccesstothevoterequipment
foratleastseveralhours. Thiskindofattackdoesrequiretheoutsidertobephysicallypresentand
takeonsomeriskofdiscovery.
Wenotethatanoutsidermaybeabletoimpersonateotherrolesinthesystem,suchasavendor
representative or an election official. As an example, an outsider might mail CDs containing a
malicioussoftwareupgradetotheelectionofficialinpackagingthatcloselyresemblestheofficial
packagingfromthevendor.
3.3.2 Voters
ItisveryeasytobecomeavoterinCaliforniaandsoitisexpectedthatanyattackerwhowantsto
canacquireavoter’scapabilitiesinatleastoneprecinct. Unlikeanoutsider, avoterhasphysical
access to a voting machine for a short period of time. That access is partially supervised, so that
wewouldnotexpectavotertobeabletocompletelydisassemblethevotingmachine. However,
in order to preserve the secrecy of the ballot, it is also partially unsupervised. The details of the
levelofsupervisionvarytosomeextentfrommachinetomachineandfromcountytocounty. In
particular,thedifferencebetweenopticalscanandDREisrelevanthere.
Opticalscanmachines. Inopticalscanvoting,thevotermarkstheballothimselfbuttheballotis
simplyaspecialpieceofpaper. Thevotertheninsertstheballotintotheopticalscanequipment,
typically under the supervision of the poll worker. Ordinarily, poll workers would be observing
voters as they feed their ballots into the scanner. Therefore, the voter probably cannot tamper
withthescannerwithoutbeingdetected. ThisdoesnotentirelyprecludevoteraccesstoopenI/O
portsonthescannerbutdoesmakeitmoredifficult. Themostlikelyavenueofvoterattackisby
the ballot itself. For example, a voter might attempt to have multiple ballots recorded or might
markmaliciouspatternsontheballotintendedtosubvertthescanner. Suchspecificpatternscould
also be used to trigger a dormant “Trojan horse” (i.e., activate pre-installed malicious software)
to induce the machine to begin cheating. Such a compromised machine might otherwise behave
correctly.
DREmachines. InDREvoting,bycontrast,thevoterhasmostlyunsupervisedaccesstothevot-
ing terminal for a significant period of time. The front of the terminal is deliberately hidden by
aprivacyscreeninordertoprotectvoters’secrecyandthereforethevoterhastheopportunityto
mountavarietyofattacks.Anysectionofthemachinethatisaccessibletoavoterinsidetheprivacy
screen,includingbuttons,cardslotsandopenI/Oports,mustbeassumedtobeapotentialpoint
ofattack. Thevoteralsohasanopportunitytoinputsubstantialamountsofdatatothesystemvia
theofficialuserinterface. Itmaybepossibletousethisinterfacetocompromisethemachine.
In all the systems studied here, the voter is also provided with some kind of token used to
authorizeaccesstotheDREterminaltoacceptthevoter’svote.IntheSequoiaandDieboldsystems
thisisasmartcardandintheHartsystemitisafour-digitaccesscode. Asthevoterhasaccessto
thesetokens,theyarealsoapotentialtargetofattackandthevotermightattempttosubstitutehis
orherowntokenorsubvertthem(inthecaseofsmartcards).
It’simportanttonotethattheprivacyaffordedtovotersbyvotinginapollingplaceisintended
tobemandatory,buttherearemanystepsavotermaytake,whilebeingbribedorcoerced,tovi-
olate this privacy. This may include the use of cell-phone cameras, the placement of identifying
marks on paper ballots, or the placement of unusual voting patterns or specific write-in votes on
anyvotingsystem. Votersmayalsobeabletotakeadvantageof“curb-sidevoting,”whereavail-
able, tohave privateaccessto avotingmachineinside theircar(wherethey maythenhave tools
thatwouldbeinfeasibletobringintoapollingplaceandtheprivacytousethem).
BecauseanyUnitedStatescitizenandCaliforniaresidentispotentiallyavoterinCalifornia,it
mustbeassumedthatanyattackwhichrequiresonlyvoteraccessispractical.
§3.3AttackerTypes 13
3. ThreatModel
3.3.3 PollWorkers
Local poll workers have a significant capability that voters do not have: they have legitimate ac-
cesstothemanagementcapabilitiesoftheequipment. Forexample,thepollworkerhastheability
toauthorizevoterstovote. Notethatalthoughinprinciplethismaygivethepollworkeroppor-
tunities for malfeasance, this risk may be mitigated by procedural controls. For example, a poll
workerwhocontrolsthemanagementstationcaninprincipleauthorizeavotertovoteanarbitrary
numberoftimessimplybyissuingmultipletokens. However,pollingplaceswouldnormallyhave
procedures in place to block or at least detect such attacks: because poll workers must perform
theirdutiesinpublicview,suchmalfeasancemightbenoticedbyotherpollworkersorothervot-
ers;moreover,ifattheendofthedaythereweremorevotescastthanregisteredvoterswhosigned
in, that would indicate a problem. Purely technical means may, alone, be insufficient to prevent
suchattacks,whileproceduralmechanismsmaybesufficienttoaddresssuchrisks.
Dependinguponcountypractices,pollworkersmayalsohavelong-termunsupervisedaccess
to voting equipment. In some counties, voting equipment is stored in the houses or cars of in-
dividual poll workers prior to the election. For example, some counties provide the chief poll
worker at each polling place with DREs or opscan machines to store and deliver to the polling
place. Even counties that deliver DREs and opscan machines by commercial transport may pro-
vide the chief poll worker with other equipment (smartcards, smartcard activation devices, man-
agement consoles, etc.) before the election. And even if equipment is stored in a secured polling
place, dual controls may not be in place to prevent individual poll workers from accessing the
areaontheirown. Thisprovidesanumberofopportunitiesfortamperingwithequipment. Many
piecesofequipmentincludesealstodetectsuchtampering,buteachsystemmustbeindividually
analyzed to determine whether these seals are effective and whether they protect all the relevant
accesspoints(seeSection3.5).
Itmustbenotedthatpollworkersareprimarilyvolunteersandaresubjecttoextremelyminimal
securityscreening,ifanyisperformedatall. Inmanycountiestheneedforpollworkersissogreat
thatanyregisteredvoterwhocallsandofferstoservesufficientlyfarinadvanceisalmostsureto
behired,andpollworkersareoftenallowedtorequesttoserveataparticularprecinct. Inpractice,
we must assume that any attacker who wants to be a poll worker can do so. Therefore an attack
whichrequirespollworkeraccesstoaparticularprecinctisquitepractical.
3.3.4 ElectionOfficials
County election officials and county staff have three significant capabilities that poll workers do
nothave:
• Accesstofunctionalityoflocalvotingequipmentwhichmayberestrictedfrompollworkers.
• Accesstolargeamountsoflocalvotingequipmentbetweenelections.
• Accesstotheback-endelectionmanagementsystemusedforequipmentmanagement,ballot
creationandtabulation.
Forreasonsofadministrativeefficiency, thisaccessmightbeunsupervisedoronlylooselysuper-
vised,dependinguponcountypractices.
The first two capabilities imply greater ability to mount the sort of attacks that poll workers
can mount. An election official with access to the warehouse where voting machines are stored
mightbeabletocompromisealltheequipmentinacountyratherthanmerelyallthemachinesina
precinct.Inaddition,theproceduresforsomeequipmentrequirethattheybesealed—forexample,
thememorycardsorresultscartridgesmaybesealedinsidethemachine—beforetheyaresentto
theprecincts.Becausethissealinghappensunderthesupervisionofelectionofficials,thoseofficials
mightbeabletobypassorsubvertthatprocess.
Thethirdcapabilityiswhollyunavailabletothelocalpollworker. Theback-endelectionman-
agementsystemstypicallyrunongeneralpurposecomputerswhichareusedbytheelectionoffi-
cials. Ifthosesystemsaresubvertedtheycouldbeusedtomismanage(compromise)pollingplace
§3.3AttackerTypes 14
3. ThreatModel
voting equipment, create fake or incorrect ballots, and to miscount votes. This subversion could
happen in at least three ways. First, many attacks can be mounted using only the attacker’s au-
thorizedaccessandwithinthecontextofthetechnicalcontrolswhichthesystemsareexpectedto
enforce. Forexample,thesoftwaremayofferanopportunityforelectionofficialtomake“correc-
tions”tovotetallies. Such“corrections”mightbeincorrect. Second,anelectionofficialmightfind
awaytodefeatthetechnicalaccesscontrolsintheelectionmanagementsoftwareandtamperwith
itsvoterecords.
Third,theofficialcoulddirectlysubvertthecomputersonwhichthesoftwareruns.Itisatruism
incomputersecuritythatifanattackerhasphysicalaccesstoageneralpurposecomputerhecan
eventually gain control of it. This may be achieved in a number of ways ranging from software
attackstodirectlycompromisingthesystemhardware,butinmostcasesisquitestraightforward.
Theclearimplicationofthisfactisthatifelectionofficialshaveunsupervisedaccesstotheelection
managementsystems,theintegrityofthosesystemsisprovidedpurelybytheintegrityandhonesty
ofthoseofficials,notbyanytechnicalmeasures.
3.3.5 VendorEmployees
Finally,weconsiderattackersintheemployofthevendors. Suchattackersfallintotwocategories:
those involved in the production of the hardware and software, prior to the election, and those
present at the polling place or Election Central warehouse during an election. An individual at-
tackermightofcoursefallintobothcategories.
An attacker involved in the development or production of the software and hardware for the
election system has ample opportunity for subverting the system. He or she might, for example,
deliberately insert malicious code into the election software, insert exploitable vulnerabilities or
back doors into the system, or deliberately design the hardware in such a way that it is easily
tamperedwith. Suchattacksareextremelyhardtodetect,especiallywhentheycanbepassedoff
assimplemistakes,sincemistakesandbugsareextremelycommoninlargesoftwareprojectsand
good-faithmistakesmaybeverydifficulttodistinguishfromdeliberatesubversion. Notethatfor
suchanattacktosucceeditisnotnecessaryfortheattackertoarrangeforuncertifiedsoftwareor
hardwaretobeacceptedbyelectionofficialsorpollworkers. Rather,thevulnerabilitieswouldbe
inthecertifiedversions.Neitherthecurrentcertificationprocessnorthisreviewisintendedorable
todetectallsuchvulnerabilities.
Avendoremployeemayalsobepresentinthecountytoassistelectionofficialsorpollworkers.
For example, the employee might be present at Election Central during or after the election to
helpelectionofficials,eitheransweringquestionsorhelpingtofixorworkaroundmalfunctioning
equipment.AvendoremployeemightalsobepresentatElectionCentraltohelpinstallormaintain
the voting system or to train county staff or poll workers. A vendor employee might even be
presentatthepollingplaceoravailablebyphonetoassistpollworkersoranswerquestions. Such
anattackerwouldhaveaccesstoequipmentcomparabletothatofpollworkersorelectionofficials,
but would also have substantial freedom of movement. Because they are being asked to correct
malfunctionsandinstallandconfiguresoftware,activitieswhichareactuallyintendedtosubvert
theequipmentaremuchlesslikelytobenoticed. Totheextenttowhichthesystemshavehidden
administrative interfaces they would presumably have access to those as well. Finally, vendor
employees pose a heightened risk because they may have access to multiple counties which use
thevendor’sequipment,andtheabilityofoneindividualtoabletotamperwithvotingequipment
inmultiplecountiesincreasesthescopeofanypotentialsubversion.
3.4 Types of Attacks
Wecancategorizeattacksalongseveraldimensions:
• Detectablevsundetectable. Someattacksareundetectable: theycannotbedetected,nomatter
whatpracticesarefollowed.Othersaredetectableinprinciple,butareunlikelytobedetected
by the routine practices currently in place; they might be detected by an in-depth forensic
§3.4TypesofAttacks 15
3. ThreatModel
audit or a 100% recount, for example, but not by ordinary processes. Still other attacks are
both detectable and likely to be detected by the practices and processes that are routinely
followed.
The potential harm caused by the former two classes of attacks surpasses what one might
expect by estimating their likelihood of occurrence. The mere existence of vulnerabilities
that make likely-to-be-undetected attacks possible poses a threat to election confidence. If
an election system is subject to such attacks, then we can never be certain that the election
resultswere notcorruptedby undetectedtampering. This opensevery election upto ques-
tion and undercuts the finality and perceived fairness of elections. Therefore, we consider
undetectableorlikely-to-be-undetectedattackstobeespeciallysevereandanespeciallyhigh
priority.
• Recoverable vs unrecoverable. In some cases, if an attack is detected, there is an easy way to
recover. Incontrast,otherattackscanbedetected,buttheremaybenogoodrecoverystrat-
egy short of holding a new election. In intermediate cases, recovery may be possible but
expensive(e.g., recoverystrategiesthatinvolvea100%manualrecountimposeaheavyad-
ministrativeandfinancialburden).
Attacks that are detectable but not recoverable are serious. Holding a new election is an
extremeremedy,oftenrequiringcontentiouslitigation. Therearescenarioswhereanewelec-
tioncannotfairlybeheld:forexample,redoingonecounty’spartofastatewideraceoncethe
othercounties’resultsbecomeknownwouldbeunfairtotheothercounties.
In addition, unofficial election results, once announced, tend to take on certain inertia and
there may be a presumption against abandoning them. When errors are detected, attempts
to overturn election results can potentially lead to heated partisan disputes. Even if errors
are detected and corrected, the failure has the potential to diminish public confidence, de-
pending upon the circumstances. At the same time, detectable-but-not-recoverable attacks
arearguablynotasseriousasundetectableattacks: wecanpresumethatmostelectionswill
notbesubjecttoattack,andtheabilitytoverifythatanyparticularelectionwasnotattacked
isvaluable.
• Preventionvsdetection. Often,thereisatradeoffbetweendifferentstrategiesfordealingwith
attacks. Onestrategyistodesignmechanismstopreventtheattackentirely,closingthevul-
nerability and rendering attack impossible. When prevention is not possible or too costly,
anattractivealternativestrategyistodesignmechanismstodetectattacksandrecoverfrom
them.
Most election systems combine both strategies, using prevention as the first line of defense
alongwithdetectionasafallbackincasethepreventivebarrierisbreached. Forexample,we
attempttopreventordeterballotboxstuffingbyplacingtheballotboxintheopenwhereit
canbeobservedandchargepollworkerswithkeepinganeyeontheballotbox. Atthesame
time, we track the number of signed-in voters, account for all blank ballots, and count the
numberofballotsintheboxattheendofthedaytoensurethatanyballotboxstuffingthat
somehowescapesnoticewillstillbedetected. Thiscombinationcanprovidearobustdefense
againstattack.
• Wholesale vs retail. One can distinguish attacks that attempt to tamper with many ballots or
affectmanyvoter’svotes(“wholesale”attacks)fromattacksthatattempttotamperwithonly
a few votes (“retail” attacks). For example, attacks that affect an entire county or a large
fractionoftheprecinctswithinacountyaretypicallyclassifiedaswholesaleattacks,whereas
attacksthataffectonlyonevoteroroneprecinctaretypicallyclassifiedasretailattacks. This
is a useful distinction because, in most contests, retail fraud is not enough to change the
outcomeoftheelection. Becausewholesalefraudhasamoresignificantimpact,wefocused
especiallyonanalyzingwhetherthesystemsarevulnerabletowholesalefraud.
• Casual vs sophisticated. Some attacks require little technical knowledge, sophisticated, ad-
vance planning, resources, or access. For example, stealing an absentee ballot out of some-
§3.4TypesofAttacks 16
3. ThreatModel
one’smailboxisaclassiclow-techattack: anyonecanexecutesuchanattack,andnospecial
qualificationsorskillsororganizationisneeded. Incontrast,otherattacksmayrequiredeep
technical knowledge, specialized skills or expertise, considerable advance planning, a great
deal of time, money, or other resources, and/or insider access. This study examines both
sophisticatedtechnicalattacksaswellascasuallow-techattacks.
WhendiscussingvulnerabilitiesandpotentialattacksontheHartInterCivicvotingsystem,where
possible we identify these distinctions to enable readers to form their own judgments about the
severityandimpactofthoseattacks.
3.5 Mechanisms for Tamper Sealing
Virtuallyeveryelectionsystemmakesextensiveuseoftampersealsasapartofitssecuritydesign.
Thissectionpresentsabriefsummaryofhowthesemechanismsworkandthelevelofsophistica-
tionanattackermusthavetoviolatethem.
Tamper resistance refers to the ability of a system to deter an attacker from gaining access to
the system. This could take the form of software controls (e.g., careful limits on the protocols
spoken across networks) to procedural controls (e.g., the use of strong passwords) to hardware
mechanisms (e.g., strong locks). Tamper resistance generally refers to the amount of time, effort,
and/orsophisticationrequiredtoovercomeasecuritymechanism.
Tamperevidenceistheflip-sideofthecointotamperresistance,representingtheextenttowhich
anattacker’sattempttoovercomeatamper-resistancemechanismleavesbehindevidenceofthat
tampering. For example, in a typical home, a burglar could easily break in by putting a brick
through a window. A plate-glass window offers little tamper resistance, but strong tamper evi-
dence(i.e., theeffortthatwouldberequiredbyaburglartoreinstallabrokenwindowandclean
upthebrokenglassisquitesignificant). Forcontrast,atypicaldoorlockisfarmoretamperresis-
tantthantheglasswindow. However,ifaskilledburglarcanpickthelock,therewillbelittleorno
evidencethatithadbeenpicked.
Inthecontextofvotingsystems,thereareanumberoftampersealingmechanismscommonly
used:
Keylocks Topreventaccesstomemorycardsorsensitivemachineports, manyvotingmachines
place a plastic or metal door in front of these ports, using a key lock. Assuming the keys
aresuitablycontrolled(andunauthorizedduplicationisprevented),attackerswouldbepre-
vented from accessing the protected ports. Of course, if bypassable lock mechanisms are
used, or if access to the locked compartment can be gained without opening the lock, then
thelockswillofferneithertamperresistancenortamperevidenceashasbeenobservedwith
bothDiebold[11]andNedap/Groenendaal[14]votingsystems.
Wireloops Many voting machines have adopted a mechanism commonly used with traditional
ballot boxes—the use of holes through which a metal or plastic wires loops may be fitted.
These seals have much in common with standard “tie wraps;” once fitted, the wire loop
cannotbeloosened;itcanonlybephysicallycutoff. Likekeylocks,theloops,whensealed,
lockaphysicaldoorinplace. Incommonelectionpractice,thesesealsarestampedorprinted
withindividualserialnumbers. Thosenumbersarethenloggedwhenthesealsareinstalled
andagainwhentheyarecuttodetectthesubstitutionofanalternateseal. Anattackerwith
simpletoolsmaybeabletoclonetheserialnumbersfromoldwireloopstonewoneswithout
detection[31].
Tamper-evidenttape Adhesive tape can be printed with numbered labels in the same fashion as
wire loops. Typically, two different adhesives are used, such that if/when the tape is re-
moved,partofthelabelwillremainstucktothelowersurfacewhilepartofthelabelwillbe
removedwiththetape. Technologyofthissortiscommonlyusedforautomobileregistration
andinspectionstickers. Anecdotalevidencesuggeststhatitmaybepossibletopeelbackthe
tapeandreplaceitwithoutthisbeingeasilyobservable[28].
§3.5MechanismsforTamperSealing 17
3. ThreatModel
A recent study of tamper seals considered 244 different seal designs and found that “the ma-
joritycouldbedefeated—removedandreplacedwithoutevidence—byonepersonworkingalone
withinabouttwominutesandallofthesedevicescouldbethwartedwithinabout30minutes”[22].
Needlesstosay,suchsealscannotbecountedon,alone,toprovidesignificantsecurityprotections
forelectronicvotingsystems.
Of course, these mechanisms can be augmented through other procedural means, including
requiringmultiplepeopletobepresentwhenmachinesarehandledormaintainingvideocameras
and other locks on the storage areas of the elections warehouse. Johnston also recommends that
officialshavegenuinesealsintheirhandstocompareagainstthesealsbeinginspected[22].
Theuseoftamper-evidentortamper-resistanttechnologies, assuch, mustbeevaluatedinthe
broadercontextofproceduresandpoliciesusedtomanageanelection. Weaknessesinthesepro-
cedures cannot be overcome by the application of tamper-resistant / tamper-evident seals. Also,
theattacker’smotivationmustalsobeconsidered. Perhapstheattackerdoesnotcareifanattackis
evident,solongasitcannotberecoveredfrom.
§3.5MechanismsforTamperSealing 18
CHAPTER 4
Overview of System Architecture
We now present a brief overview of the various components of the Hart InterCivic architecture.
Wewillconsiderallthemajorcomponents,intheroughorderinwhichtheyareusedinanactual
election. Notethatnotallcountiesuseallofthecomponentsdescribedhere.
4.1 Pre-Election
eCM
Manager
e C
M eC
M
Election Ms Ballot Now Ballot
DB BOSS C
Data e MBB Now
Ballot
MBBs
Images
To warehouse To printer
Figure4.1: HartElectionSetup
Figure4.1showsanoverviewofsettingupanelectionwiththeHartsystem.
ThefirststepincreatingaHartelectionistocreateacryptographic“masterkey”thatisused
todetectattacksagainsttheintegrityofdatathroughouttheelection. ThiskeyisstoredoneSlate
Cryptographic Modules (eCMs), which are PKCS#11 USB cryptographic tokens, about the size of
a pack of gum. The master key is generated using the eCM Manager software, which runs on a
standardWindows-basedPC.TheeCMManagerloadsthekeyontoeacheCM.
A Hart election is set up with the Ballot Origination Software System (BOSS) application, run-
ningonastandardWindows-basedPC.BOSSisusedtodefinetheelection,i.e.,tocreatethelistof
candidates running for each office, and to define how precincts and party primaries create many
differentvariantsoneachballot. Whencomplete,thisproducesan“electiondatabase.” Theunder-
lyingdatabaseissourcedfromSybase,oneofthemajorcommercialdatabasevendors.
Inordertoexportelectioninformationtotheprecinctvotingdevices,BOSSwritestheelection
definition to a Mobile Ballot Box (MBB), which is a standard PCMCIA type-1 flash memory card.
19
4. OverviewofSystemArchitecture
Theballotdefinitionisdigitallysigned1usingthecryptographicmasterkey.
Hartsupportsbothopticalscananddirectrecordingelectronic(DRE)voting. Theopticalscan
ballotsarepreparedusingtheBallotNowprogram,whichrunsonastandardWindows-basedPC.
BallotNowexportstheballotimageinelectronicformforexporttoanexternalballotprinter.2 The
electiondefinitionistransferredbetweenBOSSandBallotNowonanMBB.
4.2 Preparing Voting Devices
TheHartprecinctvotingsystemconsistsofthreeseparatedevices:
eScan. aself-containedopticalscanningvotecounter
eSlate. aDREvotingdevice
Judge’sBoothController(JBC). thecontrolterminalfortheeSlate.
All of these must be prepared before the election can take place. Preparation is performed at
the central warehouse and consists at minimum of zeroing the vote counters and installing the
per-electionmasterkey. ItmayalsoinvolveverifyingthedevicefirmwareandinstallingtheMBBs.
DevicepreparationandmanagementisperformedwiththeSystemforElectionRecordsandVer-
ification of Operations (SERVO), which is a program running on a standard PC. In the warehouse,
SERVOisconnectedtothedevicesasshowninFigure4.2.
eCM
SERVO
R
M
es
A
e
C
t Key + M
A
R
C
e s
K
et
+ ey
Reset
eScan JBC eSlate
Figure4.2: HartDeviceSetup
SERVO is connected to the eScan by means of an Ethernet cable and to the JBC by way of a
parallel data cable. SERVO cannotdirectly talkto an eSlateand must use a JBCas a go-between.
AneCMcontainingthemasterkeyispluggedintoSERVO,whichinstallsthekeyontheJBCsand
eScans(butnottheeSlates)andzeroesthevotecounters. SERVOalsoservesaninventory-control
function, tracking the serial numbers of every device owned by the county and can be used to
verifydevicefirmware.
At this time, MBBs may also be installed into the JBCs and eScans, in which case they are
tamper-sealedatthewarehouse. Alternately,theMBBmaybeshippedseparatelytotheprecinct.
Ineithercase,theprepareddevicesarethenshippedtotheprecinctsorthelocalpollworkers.
1Hart’sterminology.Moreprecisely,it’sashared-keymessageauthenticationcode,withthesamekeyusedthroughout
theelection.
2BallotNowcanalsobeusedforon-demandin-precinctballotproductionandscanning,buttheCaliforniauseproce-
dures[21]specificallyprohibitBallotNowoperationoutsideofthecentraloffice,sowedonotconsiderin-pollingplace
applicationsofBallotNow.
§4.2PreparingVotingDevices 20
4. OverviewofSystemArchitecture
4.3 Election-Day Setup
Hart supports two varieties of in-precinct voting: optical scan voting using the eScan and DRE
votingusingtheeSlate/JBC.Figure4.3showsthesetup.
Access
Check MBB MBB
VBO eSlate JBC eScan
Votes
Access Code/ Access Marked
Votes Code Ballot
DRE Access Poll Ballot Opscan
Voter Code Worker Voter
Figure4.3: HartPollingPlaceSetup
Once an eScan is loaded with an MBB it operates as an island unto itself. When ballots are
inserted,itcanvalidateandtabulatethevotes,oritmayrejectmalformed(e.g.,over-voted)ballots.
Thecastvoterecords(CVRs)arerecordedontheMBB.
DREvotingissupportedusingoneormoreeSlatesystemsconnectedwithalocalareanetwork
toasingleJBC.LargerprecinctsorvotingcentersmaywellhavemultipleJBCs,eachwithitsown
groupofeSlatemachines.AswiththeeScan,theJBCmustbepre-loadedwithanappropriateMBB.
4.4 Authorizing and Casting Votes
Unlike the eScan, the eSlates rely on their communications with the JBC that controls them. In a
typical scenario, a voter is first validated as being a legitimate voter for the local precinct. Then,
they enter a queue that leads to the poll worker operating the JBC. This poll worker selects the
proper ballot definition, where appropriate (e.g., giving the voter the Democratic or Republican
primary ballot), and then the JBC will use its built-in thermal paper printer to output a random
four-digit access code. The voter takes this printed code and approaches any open eSlate. The
voterisgrantedaccessbytheeSlatetocasthisvotebyenteringtheaccesscode.
Whenthevoterhascompletedvoting, theeSlateprintsoutasummaryofhisselectionsusing
the Verified Ballot Option (VBO) printer (the VBOx). The voter then has an opportunity to accept
or reject the ballot. Once the voter has accepted his ballot, the VBOx marks the paper “BALLOT
ACCEPTED”andtheballot(CVR)isstoredinsidetheeSlate,insidetheJBC,andontheMBBstored
withintheJBC.
4.5 Vote Collection and Tallying
At the end of the election day, results need to be collected and tallied. Hart systems allow for a
numberofdifferentprocedures,asshowninFigure4.4.
Wewilldescribeseveralofthepossibilities. First,theJBCand/ortheMBBfromwithinitmust
becarriedviacouriertoaprocessingfacility. ThismightbeElectionCentral,orinlargercountiesit
mightbearegionalprocessingcenter. Similarly,aneScanmightbecourieredinitsentirety,orthe
eScanmightbeshippedseparatelywhiletheMBBissenttobeprocessed.
Either way, the MBBs are loaded into a Windows PC running Rally or Tally. The software
extractsthecontentsoftheMBB,verifiesthattheyhavenotbeenseenbefore,andstoresthemina
§4.3Election-DaySetup 21
4. OverviewofSystemArchitecture
Precinct
Paper MBBs
Voting Rally
Ballots
Devices
M
B Vote
B
s Data
Ballot MBB
Tally
Now
Election Central
Figure4.4: HartVoteCollectionandCounting
local(Sybase)database. Inthecaseofregionalprocessingcenters,theywillberunningRallyand
theircomputersmusteitherbeconnectedtoanetworkorbeconnectedtomodemsandconfigured
toacceptphonecalls. ElectionCentral,runningTally,willmakephonecallstoeachregionalcenter,
runningRally. TallywillauthenticateitselftoRallyandthen,overanSSL-encryptedsession,will
downloadalltheMBBsstoredwithinRally.
AbsenteevotesarescannedusingtheBallotNowsoftwareandaCOTSscanner,whichprovides
detailedprocedurestoallowtheoperatortodisambiguateballots. Oncethisprocessiscomplete,
BallotNowwritesoutanMBBwhichcanthenbeaccumulatedalongsidetheotherMBBs. Insome
counties,theeScanisnotusedandallballotsarescannedwithBallotNow.
OncealltheMBBsarepresentwithinTally,eitherbecausetheywereloadedlocallyorbecause
theywerecopiedfromremoteRallysystems,Tallycanthencomputethevotetotalsandproducea
widevarietyofreports. WenotethatbothRallyandTallyrequirethepresenceofaneCM,inorder
toobtainacopyoftheelection’scryptographicmasterkey,sothatanytamperingwithMBBs(or,
anyinadvertentuseofMBBsfromotherelections)canbedetected.
4.6 Post-Election Auditing
SERVO
Ba
+
c V ku er p ify + V B e a r c if k
y
up
Backup
eScan JBC eSlate
+Verify
Figure4.5: HartPost-ElectionAuditing
§4.6Post-ElectionAuditing 22
4. OverviewofSystemArchitecture
OncetheeSlate,eScan,andJBCmachineshavebeenreturnedtoElectionCentral,theymaybe
againconnectedtoSERVO,asshowninFigure4.5. SERVOcanextracttheirinternalcopiesofthe
vote data and store backup copies. These copies can subsequently be used to produce a recount
MBBwhichcanbefedtoTallytoperformamachinerecountwhichcanbecomparedagainstthe
official totals. This process is optional and may not take place until well after the official election
resultshavebeencertified. Likewise,thepaperballotsthathadbeenoriginallyscannedusingthe
precinct-based eScan system can be rescanned with Ballot Now. There do not appear to be any
proceduresforautomaticallyperforminganaudit. Rather, theauditsareperformedandthenthe
resultsmanuallycompared.
AtthistimeSERVOcanalsobeusedtoverifythedevicefirmware.However,therecommended
procedureisthatthedevicesnotbezeroedincaseasubsequentauditisrequired.
§4.6Post-ElectionAuditing 23
CHAPTER 5
Architectural Issues
As discussed in Section 1.2, the focus of this review was on architectural issues. Unlike simple
programmingerrors,architecturalerrorspervadetheentiresystemandthereforecanbedifficultto
eradicate. OurreviewidentifiedfourmajorarchitecturalerrorsthataremadethroughouttheHart
system:
AuthenticationFailures. Components of the Hart system routinely assume that any input they
receive from an entity speaking the Hart protocol is authorized and will act on it without
question.
LeastPrivilegeViolations. InmanycasestheHartprotocolallowspeeragentstoperformactions
thatareunnecessarilypowerful.
LackofInputValidation. The Hart software frequently fails to check input values before using
theminternally.
MisuseofCryptography. Cryptographyisnotusedinplaceswhereitshouldbe;whereitisused,
itisusedinbrittleways.
All of the issues described above can be viewed as aspects of a single larger architectural issue:
theHartsystemfailstoexhibitdefenseindepth. Securesystemsshouldbedesignedinsuchaway
thatcompromiseofsingleelementsdoesnotleadtocompromiseoftheentiresystem. Rather,the
systemshouldbedesignedinsuchawaythatotherelementsacttocontaincompromiseofasingle
element,sothatthelargersystemcontinuestofunctioncorrectly.
Inmanyrespects,Hart’ssystemexhibitstheoppositeproperty:adistributedsinglepointoffailure.
Anattackerwhocompromisesanyofalargenumberofelementscanleveragethatattacktocause
other elements of the system to misbehave, in many cases even when those other elements are
functioningasdesigned. Thisisinconsistentwithgoodsecuritydesign.
Therestofthissectiondiscussesthesegeneralissuesatanarchitecturallevel. Thenextsection
providesadetaileddescriptionoftheissueswehavefound.
5.1 Authentication Failures
The various components of the Hart system routinely communicate between each other over a
varietyofnetworkinterfaces,including:
• SERVOtoeScan(Ethernet)
• SERVOtoJBC(Parallel)
• JBCtoeSlate(EIA-485)
• VoterRegistrationComputertoJBC(RS-232)
• RallytoTally(Internetormodem)
24
5. ArchitecturalIssues
Becausethesechannelsareusedforimportantcommunications, suchasuploadingfirmware, au-
thorizingvotes,andreturningvotestheyconstituteanattractiveattacktarget.
Thefundamentalstartingpointfordesigningasecurenetworkedsystemistoassumethatthe
attackerhascontrolofthecommunicationschannel. Thisisparticularlyimportantinthecaseofa
systemlikeHart’swheretheattackerhasphysicalaccesstothecommunicatingdevices. Therefore,
anycommunicationmustbeassumedtobeoriginatedbyormodifiedbytheattackeruntildemon-
stratedotherwise.Thestandardtechniqueforestablishingtheidentityofthecommunicatingparty
andtheintegrityofitsmessagesistouseasecurecommunicationsprotocolsuchasSSL/TLS[8].
WiththeexceptionoftheRally/Tallycommunications,whichdouseSSL/TLS1,theseremain-
ingcommunicationschannelsarecompletelyunsecured. Theunderlyingassumptionhereappears
tobethatbecausetheinterfacespecificationsandprotocolareproprietary,anynodewhichspeaks
that protocol must be legitimate. This is only true to the extent to which the protocol remains
secret. An attacker who has access to either the source code or the equipment can, with only a
modestamountofeffort,deciphertheprotocolandcreatehisownimplementation. Weourselves
havedevelopedapartialimplementationoftheprotocolanduseditinattacksontheHartsystem.
Vendorsofproprietarynetworksystemsoftenassumethatbecausetheydonotpublishprotocol
specifications or source code, no attacker will be able to reverse engineer their protocols. This
assumption is largely untrue. With enough effort and access to a system, it is generally possible
for an attacker to reverse engineer most protocols. Probably the most famous example of such
an effort is Samba2, an independent reimplementation of Microsoft’s SMB server which was to a
greatdegree(thoughnotexclusively)developedviathiskindofanalysis. TheprotocolHartusesis
especiallysusceptibletothiskindofattackbecausemanymessagescansimplybereplayedwithout
modificationandstillhavethedesiredeffect. Therefore,reverseengineeringtheprotocolmaynot
evenbenecessaryifwhatisdesiredistosimplyrepeatanactionthatwasobservedinthepast.
Repairingthisissuemostlikelyrequiresaddingcryptographicauthenticationandencryptionto
allinter-devicecommunication, whichlikelywouldentailreworkingHart’sentireauthentication
model.
5.2 Least Privilege Violations
Oneofthefundamentalprinciplesofsecuresystemsdesigniswhat’stermedthe“principleofleast
privilege”: anagentshouldbegivenonlytheminimalcapabilitiesrequiredtocompletethetasksit
isexpectedtoperform. Hart’ssystemsviolatethisprincipleintwoways:
• The commands used to implement a given task are often significantly more powerful than
required.
• Thecapabilitiesrequiredtoexecutecommandsareoftennotlimitedtotheagentsandtimes
whentheyareneeded.
Asanexampleoftheformerissue,Hartprovidesageneralmemoryreadingcommandthatallows
SERVO—or anyone pretending to be SERVO—to read arbitrary portions of the eScan permanent
storage or of JBC/eSlate memory. SERVO uses this mechanism in an attempt to verify the de-
vice firmware (see Issue 11), however it can also be used to extract cryptographic keys and other
sensitive information. This command could be limited to specific sections of firmware without
sacrificingthedesiredfunctionality.
Asanexampleofthelatterissue,Hartprovidesasetofcommandswhichcanbeusedtoupdate
the firmware. These commands are only ever legitimately used by Hart representatives under
tightly controlled conditions. However, our analysis suggests that these commands are available
atalltimestoanyagentwhichcanaccesstotherequiredinterface. Asuperiordesignwouldbeto
lockdownthesecommandsentirelywhenthedevicesareinthefield,withtheunlockingrequiring
1Thoughwehaveconcernsaboutthisusageaswell,asdescribedinSection6.9.
2http://www.samba.org/
§5.2LeastPrivilegeViolations 25
5. ArchitecturalIssues
explicit action by an election official or Hart representative. It would of course be necessary to
ensurethatthatunlockingcouldnotbespoofed,whichcanbeaccomplishedinavarietyofways.
Addressing this design issue would likely involve an analysis of the entire command set to
determiningtherequiredscopeandfunctionalityofeachoperation.
5.3 Input Validation
WefoundnumerousinstancesintheHartsystemoffailuretocheckinputsthatarereceivedfrom
otherentities. Theseinputsarethenusedinavarietyofunsafeways,suchascopiedintoafixed-
size memory buffer or passed as a format string argument to printf. This violates the basic
secure programming practice of assuming that any input received from outside is malicious and
usingitonlyafterithasbeenrigorouslychecked.InthecaseofHart’ssystem,thisleadstomultiple
remotelyexploitablevulnerabilities,discussedinIssue13andelsewhere.
Wewishtoemphasizethatthesearenotcomplicatederrorswhereatainteddataitemfollows
a tortuous path to the point of exploitation—though we identified this type of issue as well. The
Hartsystemrepeatedlytakesdatadirectlyoffthenetworkandusesitinunsafeoperationswithin
afewlinesofthepointwhereitisread. Thispracticeistotallyunsafeandtriviallyexploitablewith
techniquestaughtinintroductorysecurityengineeringclasses.
Arelatederroristheimplicitassumptionthatpeersarewellbehaved. Forinstance,wefound
errors where Hart would query a peer for the length of a value, allocate a buffer of that length,
thenqueryagainforthelengthandusethesecondanswerwithoutcheckingthatitwasthesame
asthefirst. This, too, isinconsistentwiththeassumptionthatthepeercanbemalicious, andisa
well-knowntypeoferror,knownintheliteratureasatime-of-check-to-time-of-use(TOCTTOU)bug.
AddressingthisissuerequiresthatHartperformacompleteauditofeverysectionofthecode
which reads and processes data from the outside world and in each case ensure that the data is
thoroughly checked before any other operations are performed on it. This will require pervasive
changesthroughoutthecode.
5.4 Misuse of Cryptography
AlthoughHartdoesnotusecryptographyinanumberofplaceswhereitwouldbehelpful, they
douseitinatleastthreecases:
• ToprotectcommunicationbetweenRallyandTally
• ToprovideintegrityprotectionfortheMBBand
• Torandomizevotedata.
In the latter two cases, the techniques provide a far lower level of security than is desirable. The
twomajordataitemsontheMBBwhichneedtobeprotectedare:
• TheballotdataintransitfromBOSStothepollingplace.
• VotedataintransitfromthepollingplacetoRally/Tally.
Logicallyspeaking,theseoperationsarequiteseparate. Thefirstcategoryofdataisgeneratedby
ElectionCentralandverifiedbythepollingplace. Thesecondcategoryofdataisgeneratedbythe
pollingplaceandverifiedbyElectionCentral. Basiccryptographicprinciplesdictatethatseparate
types of data should be protected with separate keys. Hart, however, uses a symmetric message
authenticationcode(MAC),whichrequiresthatbothsideshavethesamekey. Moreover,thesame
keyisusedcountywide.
Theimpactofthischoiceisthatanattackerwhohasaccesstothissinglekeycan:
• Forgeballotdatawhichwillbeacceptedbyanyprecinct.
§5.3InputValidation 26
5. ArchitecturalIssues
• ForgevotedatafromanyprecinctwhichwillbeacceptedbyElectionCentral.
Thischoiceisexacerbatedfurtherbypoorkeyhygiene. Keysarecentrallygeneratedinsoftware,
thentransferredtoahardwaretoken,thentransferredviaanunsecurednetworkinterfacetomem-
oryontheJBCsandeScans. Thisviolatesstandardcryptographicpracticewithhardwaresecurity
tokens, which is to use the key exclusively on the token. (Modern cryptographic tokens can per-
form a variety of cryptographic operations internally without ever divulging the keys used for
theseoperations.) Theresultisthatthereisalargenumberofsofttargets,compromiseofanyone
ofwhichsufficestocompromisetheentirecryptographicscheme.
Even without the device management issues described in Section 6.1, extracting these keys
would not be particularly difficult. An attacker with physical access, such as a poll worker, can
simplyopenthecaseofasingleeScanorJBCanddirectlyreadthekeyfromitsinternalmemory
card. Eveniftheviolationofthetampersealsisdetected,hecansimplyclaimthatthesealswere
broken when he received the device. According to Hart’s suggested procedures, this would re-
quirenotifyingthechiefelectionofficial, butatmostwouldrequiretakingthecompromisedunit
outofservice ([21],page26,seealsopage45),whichdoesnotpreventtheattackerfromusingthe
extractedkey.
Amorerobustdesignwouldusepublickeycryptography,witheachdeviceissueditsownkey.
This would stop a compromised polling place device from impersonating either Election Central
oranotherpollingdevice. Thisdesigncouldbefurtherhardenedbydistributingallkeysonsecure
tokenswiththekeysneverexportedandallcryptographiccomputationsperformedonthetoken.
Hart also uses cryptographic-style techniques in the pseudorandom number generator which
generatesthevotercodes.Designofcryptographicallystrongpseudorandomnumbergeneratorsis
awell-studiedproblemintheliterature,buthome-growntechniquesaretypicallyquiteweakand
Hart’sisnoexception,asdiscussedinIssue7. Thisissuecanberelativelyeasilyfixedbyreplacing
thePRNGwithastrongonefromtheliterature.
§5.4MisuseofCryptography 27
CHAPTER 6
Detailed Analysis
WenowconsiderindividualattacksthatwehavediscoveredontheHartInterCivicvotingsystem.
Foreachattack,wedescribe,briefly,howtheattackworks,andwhatcapabilitiesarenecessaryfor
anattackertoperformtheattack. Wealsodiscusstheimpacttheattacksmayhaveandwhatmiti-
gationsmaybeavailable. Becausethetermsofthereviewforbidpublishingfulldetailsofattacks
on the Hart system, some of the descriptions below are incomplete. More complete descriptions,
including,whererelevant,thetoolsrequiredtoexploittheissues,weremadeavailabletotheState
inaprivateannextothisreport.
6.1 Device Management
Thepollingplacedevices(eScan,JBC,eSlate)arealldesignedtobemanagedbyprogramsrunning
onordinarycomputers:
• Hartusesaspecialprogramtoupdatethefirmwareonthesemachines.1
• SERVOisusedtobackupelectionresultsandauditlogs,verifyfirmware,andresettheballot
countersinpreparationforthenextelection.
Inbothcases, managementisperformedbyconnectingthedevicetobemanagedtotheman-
agementstationviaaphysicalcable. Innocasedidthereappeartobeanysecuritymeasuresap-
pliedtopreventunauthorizedpersonnelfrommanagingthedevicesthemselves. Thisrepresentsa
significantsecurityissueinthatanattackercoulduseittocompromisevotingequipment.
All network communications between Hart’s devices, whether over TCP/IP, Parallel, or EIA-
485 serial interfaces, use a common data protocol. Understanding this protocol is the key to suc-
cessful analysis and exploitation of the Hart system. A large number of our attacks depend on
beingabletoreadand/orwriteprotocolmessages. Wedescribetheprotocolhereinordertogive
readersasenseofhowtheprotocolworksandofthetypesofcapabilitiesweuseinimplementing
ourattacks.
Atthelinklayer,eachmessageisframedwithalinklayerheaderandachecksum:
• Commandbyte(fixed)
• Length
• Payload
• Checksum
1WewerenotprovidedwithacopyofHart’sfirmwareupgradingtools,butwewereabletoreconstructsomeoftheir
functionalityfromaprotocoltracecapturedbytheRedTeamandbyanalyzingthesourcecode.
28
6. DetailedAnalysis
Thelinklayerstripsoffthatframingtorevealtheapplicationlayermessage.2
Above the link layer, the Hart protocol is a reasonably conventional datagram protocol. Each
node on the network is assigned an identification number. In the case of the JBCs, eScans, and
managementstationsthisisfixed. InthecaseofeSlates,eacheSlatereceivesanidentifierfromone
totwelve,denotingtheeSlate’svotingboothID.
Everymessagesharesacommonheader,whichcontains:3
• Sourceaddress
• Destinationaddress
• Responseaddress
• FrameID
• Length
One somewhat unusual feature is the response address, which indicates the node to which a re-
sponseshouldbesent. Manyprotocolssimplyreplytothefromaddress. Wehavenotinvestigated
thisindetail,butitappearstobemostlyusedtoindicatenoresponseisneeded.
TheFrameIDcontainsthecommandbeingexecutedorrespondedto. Therestofthemessage
isatype-specificpayload. Describingallthecommandsisoutofthescopeofthisreport,butafew
ofparticularinterestinclude:
Fileaccess direct read and write to arbitrary portions of the eScan file system. We used this ca-
pability in the firmware replacement attack described in Issue 3. which could be used to
completelytakeoverthedevice.
Readaccesstoarbitrarymemorylocations which could be used to read cryptographic keys or
voterecordsfromthedevice. FortheeScanthisonlyappliestostaticstorage. FortheeSlate
andJBCthisappearstoapplytoallofmainmemory.
Writeaccesstoarbitrarymemorylocations which could be used to write MBB data and, in the
caseoftheeSlate/JBC,takeoverprogramexecution.Itcouldalsobeusedtotamperwithany
auditlogscurrentlyonthedevice. Aswithreadaccess,writeaccessappliestostaticstorage
ontheeScanandtoallofmainmemoryontheeSlateandJBC.
Resetvotecounters whichcouldbeusedtoresettheprivateprotectivecounterinflashmemory.
Generateasystemerror whichcouldbeusedtoresetthedevice.
Reset usedtorestartdevices.
Allthreedevicesspeakvariantsofthissamebinaryprotocol, althoughsomecommandshave
differentbehaviordependingonwhichdevicetheyareaddressedtoordonotexistonsometypes
of devices. The same basic protocol is also used for ordinary communication between the eSlate
andtheJBC,asdescribedinSection6.2.
Becausewehadsourcecode,wedidnotneedtoreverseengineertheprotocolbutwereableto
buildencodersanddecodersbasedonthesourcecode. However,cursorybinaryanalysissuggests
that an attacker with access to a device, a copy of the management software, and an appropriate
sniffercouldreverseengineersubstantialportionsoftheprotocol. Ifweconsiderbrieflythecaseof
anattackerwhoobservesafirmwareinstall,werealizethatheobserves:
• Thecommandsnecessarytoinstallthefirmwareimage.
• Thefirmwareimageitself.
2ThecontrolchannelforthetheeSlateEIA-485interfaceusesthesamelinklayerframingbutadifferentupperlayer
protocol.
3Note:notallfieldsareshown
§6.1DeviceManagement 29
6. DetailedAnalysis
It’srelativelystraightforwardtodeterminewhichpartsofthecommunicationarethefirmwareand
whicharetheprotocolwrapper.Atthispoint,theattackerbothhasaccesstoadeliverymechanism
and to the binary which decodes it in one convenient package. It’s straightforward (though time
consuming) able to disassemble that to reverse engineer the binary and recover the rest of the
protocol.
Accesstothemanagementinterfaceisthereforeextremelypowerfulandinthecurrentdesign
appearstoleadtocompletecontrolofthedevicebeingaccessed.
Issue1:TheJBCismanagedviaanaccessibleparallelport
TheJBCismanagedviaaparallelinterface: aDB-25connectorontherearofthedevicelabeled
“Printer.” Thisinterfacedoesnotappeartobeprotectedbyanykindofdoorandwewerenotable
to determine whether there is any requirement that it be tamper sealed or taped. Protecting this
interfaceinthefieldwouldlikelybefairlydifficultbecauseitisveryclosetotheDE-9portusedto
talktotheeSlates,whichisusedinthefield. Anattackerwhocanaccessthisportcanimpersonate
amanagementstationandpotentiallysubverttheJBC.
Detailed Description When the JBC boots up it installs an interrupt service routine (ISR) on the
parallelinterface. WhendatacomesinonthatinterfacetheISRreadsafullmessageandthenputs
itinamessagequeueforthe“servicetask”.Theservicetaskdetermineswhetherthemessageisfor
theJBCorforaconnecteddevice(aneSlate). IfitisforaneSlateitsendsitouttheserialinterface
totheeSlate. IfitisfortheJBCitisprocessedlocally.
The JBC service task will process—without any authentication—any message it receives via
the parallel interface. Thus, an attacker who understands the protocol can simply connect to the
parallelportandstartissuinginstructionswhichtheJBCwillobey. Theseinstructionsincludethe
managementcommandsindicatedabove.
Prerequisites Inordertoexploitthisissuetheattackerwouldneed:
• TohavedecodedtheprotocolusedbyHart.
• AccesstotheparallelportontheJBC.
Asindicatedatthebeginningofthissection,webelievethatanattackerwhohadanopportunity
toobservearunningsystemcoulddecodesubstantialportionsoftheprotocol.
Currently, any poll worker has access to the parallel port on the JBC. The amount of time re-
quiredisquitesmall. WehaveobservedJBCsoftwareupgrades(reflashing)inthefieldandthey
appeartotakelessthanaminute. Othercommandswouldpresumablybeevenfastersincelittle
datatransferisrequired. Inaddition,theattackermayneedtoresettheJBCtoloadthenewcode.
Thiscanlikelybedoneremotelybutcanalsobedonebysimplypullingtheplug. Hownoticeable
thisisdependsonhowoftensuchfailuresoccurinnormalusage. NotethattheJBCwillrecover
gracefullyfromapowerfailureofthistype. Itmayalsobepossibletopatchtherunningimagein
memory.
Impact An attacker who took control of a JBC would have direct control of every eSlate in the
precinct. Inparticular,theeSlatesgettheirinformationaboutballotsandvoteauthorizationfrom
the JBC. Moreover, as described in the next section, we believe the JBC can use the management
interfacetosubverttheeSlates. SeeSection7forarangeofpossibleattacksusingthisaccess.
Mitigations The primary JBC-specific mitigation is to somehow secure the parallel port. There
doesnotappeartobeanylegitimateuseforthisportinthepollingplace. Generalmitigationsfor
alloftheissuesdiscussedinthissectionarediscussedinSection6.1.
FutureversionsoftheHarthardwaremightadddoorswithlocksorothersuitablemechanisms
toprotecttheparallelportfromtamperingwhiletheJBCisinthefield.
§6.1DeviceManagement 30
6. DetailedAnalysis
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Anincompleteunderstand-
ingofthehardwareinterfacehasstoppedusfromreplicatingitwitharealJBC.
Issue2:TheeSlateismanagedviaaserialportconnectedtotheJBC
The eSlate is managed via a serial interface on the rear of the device. In order to manage the
eSlate,oneplugstheeSlateintotheJBCandconnectsthemanagementstationtotheJBC.Allmes-
sages between the management station and the eSlate are sent through the JBC. This interface is
not protected by any kind of door, nor is it tamper sealed. In fact, Hart’s curbside voting feature
explicitlycontemplatesthattheeSlateswillbeunplugged.
An attacker who can access the eSlate interface can impersonate a management station to the
eSlate and potentially subvert the eSlate. Mounting this attack would be extremely quick, on the
orderofseconds.
DetailedDescription TheeSlateisconnectedtotheJBCviaaserialinterface(seeSection6.2for
details). Onstartup,theeSlate“networktask”beginsandwaitsforinstructionsoverthisinterface,
eitherfromtheJBCorfromamanagementstationroutedthroughtheJBC.Ineithercase,theeSlate
obeysthoseinstructionswithoutquestion.
By design, all communication to the eSlate is via the JBC. However, an attacker who had the
specificationstothisinterfacecouldconnectdirectlyandimpersonatetheJBC(andhencetheman-
agementsystem)totheeSlate. Thus,controllingthisinterfacewouldallowanattackertomanage
theeSlate,asdiscussedabove.
Prerequisites Inordertoexploitthisissuetheattackerwouldneed:
• TohavedecodedtheprotocolusedbyHart.
• AccesstotheserialportontheeSlate.
Asindicatedatthebeginningofthissection,webelievethatanattackerwhohadanopportunity
toobservearunningsystemcoulddecodesubstantialportionsoftheprotocol.
Currently,anyvoterhasaccesstotheserialportontheJBCandcaneasilyremovetheconnector.
TheeSlateisdesignedtobedisconnectedtoenablecurbsidevotingandthereforeitispossibleto
removethelasteSlateinthechain. (SeeSection6.2.3).
InordertoinstallnewfirmwareontheeSlate,itwouldprobablyneedtoberebooted,however
this could likely be done without disturbing the JBC. It may also be possible to use the memory
commandstopatchtherunningmemoryimage. Anyoftheseattackscouldplausiblybemounted
byavoterandcouldcertainlybemountedbyapollworker.
Impact A successful attack of this type would likely lead to complete control of the eSlate. An
attackerwhocontrolledaneSlatewouldbeabletoaccessorcontroleveryvoteperformedonthat
eSlate. He might also be able to leverage this access into control of the rest of the eSlates in the
system,asdescribedinSections7.3and6.2.
Mitigations ThenaturalmitigationistosecuretheconnectionbetweentheeSlateandthestand
via some kind of seal. However, we saw no obvious sealing points. In addition, the red team
informs us that the eSlates need to be demountable in order to install potential disabled access
devices such as sip-puff devices. In addition, each eSlate is connected to the next eSlate, which
providesanadditionalcableattachmentpoint. SeeSection6.2formoredetailsonthedifficultiesof
securingthisinterface.
§6.1DeviceManagement 31
6. DetailedAnalysis
Status This issue was discovered by examination of the source code. We have verified that we
canobservecommunicationsbetweentheJBCandeSlateandwereabletoverifythelackofcrypto-
graphicsecurity. WehavenotattemptedtoimpersonateaJBCormanagementstationtoaneSlate.
Issue3:TheeScanismanagedviaanaccessibleEthernetport
TheeScan,liketheotherdevicesisremotelymanageable. TheeScanisequippedwithanRJ-45
EthernetjackandautomaticallyadoptsafixedIPaddress. ItcanberemotelymanagedviaTCP/IP.
DetailedDescription WhentheeScanbootsitautomaticallystartsa“servicetask”whichlistens
on TCP port 4600. The eScan seems to have fixed IP address of 192.168.0.1. The eScan ser-
vice handler treats any TCP connection on this port as the management console and will process
commandsissuedviatheTCPconnectionwithoutquestion.
Prerequisites Inordertoexploitthisissuetheattackerwouldneed:
• TohavedecodedtheprotocolusedbyHart.
• AccesstotheEthernetportontheeScan.
Asindicatedatthebeginningofthissection,webelievethatanattackerwhohadanopportunity
toobservearunningsystemcoulddecodesubstantialportionsoftheprotocol. Thisisparticularly
easy with TCP/IP connections because tools such as Wireshark and tcpdump for analyzing TCP
connectionsarereadilyavailableandwidelyusedforpreciselythissortofanalysis.
CurrentlyanypollworkerhasaccesstotheEthernetinterfaceontheeScan. Wedonotknowif
voterswouldbeabletoaccesstheinterfaceinthefield. Thisdependsonthephysicalmountingof
theeScanonitscartaswellaswhatsortofsupervisionvotersareunder.
Impact A successful attack of this type would likely lead to complete control of the eScan. The
attackercouldcauseanyvotecountshechosetoappearaswellasrejecting“invalid”ballotsofhis
choice. SeeSection7forotherattacksbasedoncontrollinganeScan.
Mitigations ThenaturaleScan-specificmitigationistosecureaccesstotheEthernetportonthe
eScan. There does not appear to be any need to have it available in the polling place. General
mitigationsforalloftheissuesdiscussedinthissectionarediscussedattheendofSection6.1.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavesuccessfullyused
acomputerunderourcontroltocommunicatewiththeeScanandextractedthememoryinforma-
tion,theinitializationfile,andthecryptographickeys. ThischannelisusedbyHarttomanagethe
firmware on the eScan and based on the source code and a capture of a firmware upgrade trans-
action(providedbytheredteam)wewereabletowriteourowntooltoupdatethefirmware. We
workedwiththeredteamtotestedthistoolwiththeredteam’seScanandweresuccessfullyable
toloadourownfirmware,whichdisplayedarevisedHartlogo.
Issue4:The JBC voter registration interface can be used to generate voter access
codes
TheJBCcontainsaDE-9maleconnectorontherearofthedevicelabeled“Modem”. Thisisa
serialinterfacewhichisinternallyreferredtoasa“VoterRegistrationInterface”(hereafterVRI)4.A
VRIdevicecansendinstructionstotheJBCtoissuevoteraccesscodes. AswiththeJBC’sparallel
interface,thisserialinterfacedoesnotappeartobeprotectedbyanykindofdoorandwewerenot
4WhilethereisnocertifiedHartInterCivicproductinCaliforniathatconnectstothisport,thesupportforitisclearly
presentintheJBCsourcecode.
§6.1DeviceManagement 32
6. DetailedAnalysis
abletodeterminewhetherthereisanyrequirementthatitbetampersealedortaped. Anattacker
whocanaccessthisportcanimpersonatetheVRIdeviceandgeneratevoteraccesscodesthatcan
beusedforvotingononeoftheeSlatesmanagedbythisJBC.Further,iftheJBCisinEarlyVoting
mode, access codes can be obtained by an attacker without causing records to be printed to the
JBC’sprinter.
DetailedDescription AftertheJBCbootsuptheandlowlevelinitializationisfinished,the“main
task”isstarted. Themaintasklistensontheserialinterface(labeled“Modem”onthebackofthe
JBC,referredtoastheVRIinthesourcecode)forvoteraccesscoderequests. IftheJBCisinEarly
Voting mode, then access code requests can include an instruction to not print any records to the
JBCprinter. Otherwise,accesscoderequeststriggerareceiptbeingprinted.
TheJBC“maintask”willprocess—withoutanyauthenticationorcryptographicintegritychecking—
any message it receives via the VRI. Thus, an attacker who understands this protocol can simply
connecttotheserialportandstartissuingvoteraccesscoderequests.
Prerequisites Inordertoexploitthisissuetheattackerwouldneed:
• TohavedecodedthevoterregistrationprotocolusedbyHart.
• AccesstotheVRI(i.e.,theserialportlabeled“Modem”)ontheJBC.
Similartothecasewithafirmwareupgrade,anattackerwhohadanopportunitytoobservedata
exchangedbetweenaVRIdeviceandaJBCcoulddecodesubstantialportionsoftheprotocol. This
protocolisalsopartiallydescribedintheJBCFunctionalSpecification[15].
Onequestionworthaskingisthedurationofrequiredaccess.TheRedTeamwasabletoconnect
toaJBCinEarlyVotingmodeandextractseveralvoteraccesscodesinaveryshortamountoftime.
Impact Anattackerwhocouldgeneratevalidvoteraccesscodescouldvoteasmanytimesasthe
numberofaccesscodesgenerated. Thedocumentationindicatesalimitof150outstandingaccess
codesbutwehavenotverifiedhowwellthisisenforced.
IfaJBCwasusedwithabarcodereader,thenanattackerwouldnotneedtoconnectanexternal
computertotheserialport.Instead,theattackercouldpre-printsuitablebarcodesandexposethem
tothereader.
Mitigations TheprimaryJBC-specificmitigationistosomehowsecurethisserialport. Ifnocom-
puterorbarcodereaderisintendedtobeconnectedtotheVRI(and,wearenotawareofanyreason
whyoneshouldbe),thentheserialportshouldbesuitablysealedtopreventaccesstoitduringthe
election.
GeneralmitigationsfortheissuesdiscussedinthissectionarealsodiscussedinSection6.1.
Status Thisissuewasdiscoveredbyexaminationofthedocumentationandsourcecode.TheRed
TeamwasabletosuccessfullyconnecttoarealJBC’sVRIandgeneratevoteraccesscodes.
Mitigations
Alloftheissuesdiscussedabovestemfromthesameunderlyingarchitecturalissue: allthreede-
vices assume that any device which talks to them and issues management-style commands is a
legitimate management console. This assumption is incorrect and the failure to authenticate at-
temptsatmanagementallowsanyattackerwhocanspeaktheprotocoltomanagethedevice.
As noted above, it is conceivable to secure the ports on the eScan and the JBC but perhaps
not the eSlate. To the extent that the seals are secure (see Section 3.5), this provides protection
againstvotersandpollworkers,butnotelectionofficialswithaccesstounsealeddevices.Asealing
strategyimpliesthatnoonewhoisnotcompletelytrustedcaneverbeallowedunsupervisedaccess
toadevicewhichdoesnothaveitsportssealed. Thisisdifficultoperationalbartoclear. However,
§6.1DeviceManagement 33
6. DetailedAnalysis
asealingstrategymaybeusefulinadditiontootherhardeningstrategiesasabackupforpotential
programmingerrorsinthesoftwaredoingaccesscontrol.
Thereareanumberofmodificationstothesoftwarearchitecturethatwouldmitigatetheseis-
sues. First,ifmanagementconsoleswererequiredtoauthenticatecryptographicallytothedevices
theymanagedthiswouldsubstantiallyreducetheriskoffakemanagementconsoles. Note,how-
ever, that the existing keying material management strategy (see Section 6.7) makes this difficult
becausecompromiseofanysingledevicewouldallowtheattackertorecoverthekeyandmakea
fakemanagementconsole. Publickeyauthenticationoftheconsoleswouldbesaferbutwouldbe
asignificantarchitecturalshift.
Evenifthemanagementconsolesweretobeauthenticated,therewouldbesubstantialresidual
risk from an attacker who compromised a management console. This risk could be mitigated by
substantiallyreducingtherangeofoperationstheconsolecouldmount. Inparticular,theconsole
cancurrentlyloadarbitraryfirmware.IffirmwareneededtobesignedbyHartorathirdparty(and
thiswasenforcedbythedevice)thenevenaroguemanagementconsolewouldnotbeabletoload
maliciousfirmware. Inaddition,anumberoftheoperations(genericmemoryreadingandwriting
inparticular)appeartobestrongerthanrequiredforamanagementsystem. Strictlytrimmingthis
listtotheoperationswhichareabsolutelynecessaryformanagementwouldmitigatetherisk.
Finally, the command set could be partitioned into commands which were accessible in the
warehouseandcommandswhichwereaccessibleinthefield. Itisnotclearthatthereisanyactual
need for field management, Special access (e.g., a PIN entered on the console) could be required
toputtheunitintowarehousemode, andperhapstoreactivateit. Thiswouldlimittheexposure
fromunauthorizedfieldmanagement.
6.2 eSlate-JBC Communication
TheeSlatehasnoMBBofitsown. ThismeansthatitmustgetelectioninformationfromtheJBC
towhichitisconnectedandmustreturnvotingresultstotheJBCforstorage. Thiscommunication
that occurs over the eSlate-JBC interface using the standard Hart protocol (See Section 6.1). As
discussedearlier,thisprotocolhasnosecurityfeatures,whichleadstoanumberofissues.
In the Hart voting system a number of eSlates are connected to a single JBC in a daisy chain
configuration, with the first eSlate connected to the JBC and each subsequent eSlate connected to
the one before it, as shown in Figure 6.1. This network is used by the JBC both to communicate
withandsupplypowertotheeSlates.
eSlate 3 eSlate 2 eSlate 1 JBC
Figure6.1: JBC/eSlateNetwork
This broadcast network. All of the devices are electrically connected and any message sent
fromanydevicetoanyotherdevicecanbeseenbyalltheotherdevicesinthenetwork. Theway
that devices know which messages are intended for them is that there is additional addressing
information (again, visible to all). This is a fairly common network design. Classic Ethernet, for
instance,hassomesimilarproperties.
6.2.1 DetailedDescription
Physically,thecablingisasfollows:
§6.2eSlate-JBCCommunication 34
6. DetailedAnalysis
• TheJBChasafemaleDE-9connectorontheback.
• AcablewithamaleDE-9ononeendandafemaleHD-15ontheotherendrunstotheback
oftheeSlatestandforthefirsteSlate.
• TheeSlatestandhasamaleHD-15connectoronthebackandaninternalcablethatterminates
inafemaleHD-15,whichplugsintotheeSlate.
• TheeSlatehasamaleHD-15fortheabovecable.
• AcableterminatinginafemaleHD-15comesoutoftheeSlateandisruntothebackofthe
nexteSlatestand.
• InthelasteSlate,thecableiscurledupandstuffedintoacompartmentinthestand.
Electrically,thenetworkcontains:
• OnepairofwiresforanEIA-485[9]controlchannel5
• OnepairofwiresforanEIA-485datachannel
• +24Vpowerwires
• Groundwires
• Awireusedtosignal“lasteSlate”
Onethingthatisconfusinghereisthatthenetworkissuperficiallyadaisychain: wirescomeinto
aneSlateandthencomeout. It’snaturaltosuspectthateSlateOneforwardspacketstoeSlateTwo.
Thisisnotthecase. Rather, allthedevicesareelectricallyconnected,itissimplythattheconnec-
tiontakesplaceinsideeacheSlateratherthanexternallyasisthecasewith, forinstance, 10Base2
(Thinnet). Effectively,thisisapairofbroadcastnetworks,withonenetworkusedforcontroland
theothernetworkusedfordata.
Access to the network is mediated by the JBC which serves as the network master. The JBC
uses the control network to tell the other nodes when to read and write. Only the JBC writes to
the control channel and other nodes write to the data channel only when told to over the control
channel. Signalingonbothchannelsisclockedatanonstandard938kbps.
NotethatthefactthattheJBCisthenetworkmastermeansthatnoeSlatecaneversayanything
that’s unsolicited. Since eSlates do sometimes need to initiate communication with the JBC—for
instancetorecordCVRs—theJBCpollseacheSlateperiodicallytoseeifithasanythingtosay. Ifit
does,itsendsitaquerytogetthedata.
6.2.2 TappingtheInterface
Because this is a broadcast network, tapping it is straightforward. We were successfully able to
connecttothisinterfaceusinganAaxeonMSC-102Bdual-portEIA-485card. Usingapinoutsup-
plied by Hart and supplemented by our own analysis of the interface we built a cable to bridge
the HD-15 output of an eSlate to our own PCI EIA-485 card. The maximum rated clock speed of
thecardisat921.6kbps,butthisisapparentlywithinerrorlimitsbecauseclockingourcardatthis
rate enabled us to capture both the control and data channels. Because we were able to capture
messagesbetweentheeSlateandtheJBCwhilesniffingafterthefinaleSlateinthechain, thisex-
perimentconfirmsthatallnodesreceiveeachmessage. NotethatthecablefromthefinaleSlateis
exposedandthereforecanbetappedwithoutunplugginganydevices.
5EIA-485isadifferentiallysignaledmultipointserialinterface(hencetheneedfortwowires).
§6.2eSlate-JBCCommunication 35
6. DetailedAnalysis
6.2.3 HijackingtheInterface
Tapping the network allows the attacker to have access to the contents of messages flowing over
it, but this only allows a small number of attacks. More attractive to the attacker is to hijack the
network. I.e.,wewouldliketo:
• PretendtobeanextraeSlate
• PretendtobeanexistingeSlatetotheJBC
• PretendtobetheJBCtotheeSlate
This would allow you to send messages and affect the behavior of other nodes, rather than just
broadcasting.
The difficulty here is that because messages are broadcast, the attacker has to compete with
whatever node he is impersonating. So, for instance, if he is pretending to be eSlate Two, he has
to worry that messages that are coming back to him are also read by eSlate Two and that it gets
confusedbytheunexpectedmessages.EvenmoredifficultisthatthetheeSlatebeingimpersonated
istryingtotransmitattheexactsametimetheattackeris,whichcausesconflicts.
Therearetwomajorapproachestoattackingsuchanetwork.
UsingaProxy
Because what makes attacks difficult is that the network is broadcast, the natural approach is to
removethatproperty.
Attacker
eSlate 3 eSlate 2 eSlate 1 JBC
Figure6.2: JBC/eSlateNetworkProxy
InFigure6.2,theattackerinterposeshimselfbetweeneSlatesTwoandThreeandseparatesthe
networkintotwonetworks6 HereceivesallmessagesdirectedtoandfromeSlateThreefromand
totherestofthenetworkandcanpasson,change,ordropanymessageshechooses. Asfarasthe
restofthenetworkisconcernedheiseSlateThreeandasfaraseSlateThreeisconcerned,heisthe
restofthenetwork.
This allows complete control of all transmissions crossing the Attacker’s device, but has two
disadvantages from the perspective of the attacker. First, it cannot be mounted purely from a
compromisedeSlate. Theattackermustleaveadeviceinplacefortheentiredurationoftheperiod
he wishes to mount his attack. The device could probably be fairly small (about the size of a
matchbox) and could easily be put in place on the input port of an eSlate. Nevertheless, it might
stillbenoticed.
Second,theattackercanonlyimpersonatetheJBCtodevicestotheleftofhisdevice(andvice
versa). This limits his control and motivates placing the device between the JBC and eSlate One,
whichmaybemorenoticeablesinceeSlateOneisclosesttothepollworkers.
InstallingsuchaproxyalsorequiresdisconnectingthecableleadingintotheeSlate,whichmight
benoticeable. TheHartcurbsidevotingfeatureappearstomakethispractical: onceavotercode
has been entered into an eSlate, if the JBC loses contact with that eSlate, it assumes that it is in
curbsidevotingmode,logsthefact,andwaitsforitsreturn. EveniftheJBCdoesnoticethatanode
hasfailedanddisablesit,theattackercanprobablyconvincepollworkersitwasaninnocentfailure
and have them correct it, possibly by rebooting the entire system. The Hart documentation [16]
6Technically,fournetworks,withtwoEIA-485networksoneachside.
§6.2eSlate-JBCCommunication 36
6. DetailedAnalysis
describeshowtoclearsucherrorsanddoesnottreatthemassecuritycritical. Notethatoncethe
attackerhascompromisedtheeSlatehecancauseittodisplayanyerrormessageofhischoice.
SharingtheNetwork
Fromattacker’sperspective,amoreattractivealternativewouldbetotakeoverasingleeSlateand
thenuseittoimpersonateothereSlatestotheJBCandtoeachother. Thisavoidstheneedforany
long-termdevicewhichmightbedetected. Arelatedtechniquewouldbetoplugintothedangling
endofthecablefromthefinaleSlateandpretendtobeoneoftheexistingnodes.
Technically,however,thisisamoredifficultproblem. Themostlikelyavenuewouldbeto“co-
master” the network, i.e., pretend to be the JBC. The general idea would be to issue one’s own
network control messages at times when the JBC was silent (most of the time). Analysis of the
sourcecodesuggeststhattheJBCignorescontrolchannelmessagesnotdirectedtoit, thereforeit
should be fairly oblivious to attempts to control the network. More difficult is stopping the JBC
fromreceivingdatamessagesfromtheeSlatesdirectedtoit(recallthatweareimpersonatingthe
JBC)ordatamessageswhichweareusingtoimpersonateit.
Webelievethatthiscanbedealtwithbytheattacker.First,theJBCappearsonlytopayattention
toresponsesfromnodesitexpectstoreceivedatafrom,sowithcarefultimingitmaybepossibleto
minimizeexceptionsontheJBC(whichisreasonablyresilientinanycase). Second,First,inmany
casesitispossibletosendmessageswitharesponseaddressof0,whichmeansthatthereshouldbe
noresponse. InsuchcasesthereisnoneedtosuppresstheJBCfromreadingtheresponses. Third,
theattackercouldtransmitajammingsignalintimewiththeresponseinordertogenerateabogus
message checksum, which will cause it to be ignored by the JBC. This works best with messages
whichweplantoignoreinanycasebutwhichmightconfuseotherunits.
Clearly,allofthesetechniquesaremorecomplicatedthanthesimpleproxyapproachdescribed
in Section 6.2.3. The advantage is that they can be mounted from a compromised eSlate without
anyspecialhardware.
Issue5:eSlate-JBCcommunicationisinsecure
The JBC and the eSlate are in constant communication. This communications channel is used
foranumberofpurposes,including:
• ManagementoftheeSlate(seeIssue2).
• TransmittingballotinformationtotheeSlate.
• AllowingtheeSlatetocheckthevalidityofavoteraccesscode.
• TransmittingCVRstotheJBCfromtheeSlate.
Thischannelisnotcryptographicallysecuredinanyway,thusallowinganattackerwhocanaccess
theinterfacetoimpersonateaneSlatetoaJBCorvice-versa.
Detailed Description There is no cryptographic protection for messages on the eSlate-JBC net-
work and therefore there is no authentication, message integrity, or confidentiality. Any attacker
who can access the network can transmit any message he wishes on the interface and have it ac-
ceptedascomingfromanysourceaddresshechooses. Hecanalsoviewanymessageswhichare
transmittedonthenetwork.
Inparticular,anattackerwhocontrolledthisnetworkcould:
• PretendtobeaJBCand“accept”aCVR,thuspreventingitfrombeingrecordedbytheJBC.
• PretendtobeaJBCandlietotheeSlateaboutthevalidityofavotercode,thusallowingan
illegitimatevotertovoteorblockingalegitimatevoterfromvoting.
§6.2eSlate-JBCCommunication 37
6. DetailedAnalysis
• Pretend to be an eSlate and send spurious votes to the JBC (this is potentially enhanced by
Issue8).
• Watcheachvoteasitiscast.
As an example, consider the first attack. The JBC periodically polls every eSlate to see if it has a
CVRtodeliver. WhenitgetsapositiveresponseitsendsamessagetoretrievetheCVRandthen
resetstheeSlate’sstate.
AnattackerwhocontrolledthenetworkcouldpretendtobetheJBCandretrievethevote,thus
leavingtheeSlatethinkingithaddeliveredthevotewhilethetrueJBChasnotinfactstoredacopy.
ItcouldsimultaneouslypretendtobetheeSlatetotheJBCandstorevotesofitschoice,replacing
therealeSlatevotes. Theotherattacksproceedinasimilarfashion,withtheattackerpretendingto
beonesideortheother. Notethatvoteobservationcanbedonepurelypassively,i.e.,bysnooping
on the shared communication network. Any eSlate can observe all the communication from any
othereSlateconnectedtothesameJBC.
Onedifficultyhereisthatbecausethisisabroadcastnetwork,andthereforeimpersonatingan
existingnodemaycauseproblemsforothernodes.Earlierinthissectionweoutlinesomepotential
waystobypassthisobstacle.Anattackerwhoispresentatthebeginningoftheelectioncansimply
pretendtobeanonexistenteSlate,providedthatfewerthan12eSlatesareinuse.Thisavoidsissues
abouthijackingforeSlateimpersonation.
Prerequisites Inordertoexploitthisissuetheattackerwouldneed:
• TohavedecodedtheprotocolusedbyHart.
• AccesstotheserialportontheeSlateduringanelection.
AsindicatedinSection6.1webelievethatanattackerwhohadanopportunitytoobservearunning
systemcoulddecodesubstantialportionsoftheprotocol.
Currently,anyvoterhasaccesstotheserialportontheeSlateandcaneasilyremovetheconnec-
tor. TheeSlateisdesignedtobedisconnectedtoenablecurbsidevotingandthereforeitispossible
toremovethelasteSlateinthechainwithoutgeneratingalerts. Inaddition,anattackercouldpo-
tentiallyconnecttotheoutgoingcableonthelasteSlateinthedaisychain,whichissimplystored
inacompartmentintheeSlatestand.
Theattackerhastohavesomesortofaccesstotheserialportfortheentireperiodoftheattack.
Thisdoesnotimplythattheattackerisphysicallypresentthewholetime,merelythathisdeviceis
attached. Weanticipatethatthedevicecouldbemaderelativelysmall,ontheorderofamatchbox.
Nevertheless,thispresentssomeriskofdiscovery.
Impact Theimpactoftheseattacksdependsonwhichdeviceisbeingimpersonated.However,in
generalitwouldbepossibletoinjectfalsevotesintotheJBC(whichwouldnotmatchtheVVPAT
ortheeSlatememory),removevotesfromtheeSlate(butnotfromtheVVPATorJBCmemory),or
allowanattackertoappeartovotemultipletimes. Thisfinalattackwouldcreatematchingentries
intheVVPAT,eSlatememory,andJBC,thoughthelogsofhowmanyindividualshadvotedwould
notmatchthenumberofvotescast.
Mitigations OnepotentialmitigationistoseverelyrestrictaccesstotheeSlateserialport. How-
ever,thisisdifficultforanumberofreasons,includingthedesiretoenablecurbsidevoting. Itmay
be possible to restrict voter access, but because the poll workers assemble the eSlate/JBC daisy
chain at the polling place, it is likely to be extremely difficult to secure their access. Note that a
small device placed between the eSlate serial cable and the connector is sufficient to mount this
attack.
Another mitigation would be to cryptographically authenticate the eSlate to the JBC and vice
versa. Thiscouldbedoneinanumberofways. OnepossibilityisfortheeSlateandJBCtousethe
globaleCMkeytoauthenticateeachother. Thishasseveraldifficulties. First,thateCMkeyneeds
§6.2eSlate-JBCCommunication 38
6. DetailedAnalysis
tobeinstalledintheeSlate,whichcurrentlywouldhavetobedoneoverthisinterface. However,
it might be possible to do that installation securely in the warehouse and then set the eSlate to
use cryptographic protocols from there on. Second, compromise of any unit in the entire county
potentiallyleakstheeCMkeyandwouldallowthisattacktoproceed.
AnotherpossibilitywouldbeusepublickeycryptographytoauthenticatetheeSlateandJBCto
eachother.Aswithsymmetriccryptography,onewouldsecurelyinstallknowledgeoftheexpected
peer’spublickeyoneachdeviceandtheywouldrefusetoconnecttoanyotherdevice. Onediffi-
cultyhereisthatthisseverelyreducestheflexibilitytomix-and-matchdeviceswithinandbetween
precincts.
Anadditionalproblemwithanycryptographicsolutionisthatitrequiressomemechanismto
reprogramthekeyingmaterialonthedevice. Thatmechanismthenbecomesapotentialtargetof
attackandsomustbedesignedcarefully.
Status This issue was discovered by examination of the source code. We have verified that we
canobservecommunicationsbetweentheJBCandeSlateandwereabletoverifythelackofcryp-
tographicsecurity. Wehavenotattemptedtoimpersonateeithersideofthecommunication.
Issue6:FormatstringvulnerabilitiesinJBCreportmode
AformatstringvulnerabilityintheJBC’swrite-insummaryreportmayallowanattackerwho
hadcausedtheJBCtorecordspecially-formattedvotestocompromisetheJBCafterpollsareclosed.
DetailedDescription Attheendofvoting,pollworkersinstructtheJBCtoclosethepolls,after
whichnofurthervotesareaccepted.Oncepollsareclosed,theJBCallowspollworkerstoproduce,
ontheJBC’sinternalprinter,anyofthreereports:avotercodesummary;avotetally;andawrite-in
report.
For each precinct, for each party, and for each contest, the write-in report lists the candidate
namesincludedinwrite-infieldsandhowmanyvoteseachreceived. TheJBCproducesthisreport
byexaminingthevotesinitsinternalCVRlog.
While write-in candidate names are massaged, for example to remove leading and trailing
whitespace, it appears that no attempt is made to filter out printf format specifiers (such as “
%d”). What’smore, thePrintWriteInsroutine, whichiscalledforprintingeachwrite-inentry
inthesummary,passesthecandidatenametoprintf7 astheformatstring,ratherthanusingan
idiomsuchasprintf("%s",str). ThismakestheJBCvulnerabletoaformat-stringattack[13]:
aspeciallycraftedwrite-incandidatenamerecordedintheJBCCVRlog, whenprocessedaspart
ofthewrite-inreport,allowsmemoryoverwritesarbitrarycodeexecution.
Prerequisites Inordertoexploitthisissuetheattackerwouldneed:
• Tocauseavotecontainingaspeciallycraftedwrite-incandidatenametoberecordedinthe
JBC’sCVRlog.
• Tocauseapollworkertorequestawrite-inreport.
It is not normally possible to input format specifiers using the eSlate on-screen keyboard. An
attackercouldneverthelesscausevotescontainingtheappropriatespecifierstoberecordedeither
by compromising an eSlate (Issue 2) or by tapping the JBC-eSlate communication network and
impersonatinganeSlate(Issue5).
7Moreprecisely,topprintf,whichpassesittovsnprintf
§6.2eSlate-JBCCommunication 39
6. DetailedAnalysis
Impact A JBC can only be compromised using this vulnerability once polls have closed. This
is, of course, too late to have an effect on the system’s behavior towards voters. Nonetheless, a
compromisedJBCcanstilldoanyofthefollowing:
• modifyitsinternalauditandCVRlogs;
• modifytheauditandCVRlogsontheMBB,eithertomatchthemodifiedlogsontheJBCor
toexploitavulnerabilityinTally(cf.Issue14);
• leakthecryptographickey(cf.Section6.7);and
• usetheJBC-eSlateinterfacetomodifythelogsontheeSlatesorinstallnewsoftwareonthem
(cf.Issue2).
AcompromisedJBCcanalsobeusedtomountattacksonback-endsystems,forexampleonSERVO
(cf.Issue13).
Mitigations Until Hart fixes this vulnerability, poll workers could disconnect eSlates from the
JBCbeforerequestinganyJBCreports;thisensuresthataJBCcompromisedthroughvulnerabilities
relatedtoitsCVRparsingcannotmodifytheauditandCVRlogsstoredontheeSlates. Thisdoes
not, however, mitigate the risk of SERVO being compromised through a compromised JBC (see
Issue13).
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenotattemptedto
verifyit.
Issue7:TheJBCaccesscodegeneratorisinsecure
Voter codes, printed at the JBC, are intended to prevent voters from registering unauthorized
votesataneSlate. Thesecodesarepredictable: anyonewhoseesasinglevotercodecancompute
thesequenceofallsubsequentvotercodes.
DetailedDescription TopreventunauthorizedvotersfromusinganeSlate,Hartemploysvoter
codes—four-digitpseudorandomnumbersprintedontheJBCthatthevotertypesintotheeSlate.
AvoterentershisvotercodeonaneSlatetobeginvoting. TheeSlatecheckswiththeJBCthat
thecodehasbeenissuedandisunused. Ifthisisthecase,theJBCmarksthecodeasused,andthe
eSlateallowsthevotertomakehisselections. Castingaballotinvalidatesthevotercode.
The algorithm that generates these voter codes uses a poor design that makes it possible to
predictcodes. TheJBCpicksarandominitialindex,between0and9999. TheJBCgeneratesavoter
codebyapplyinganunkeyedpermutationtothecurrentindex;itthenincrementstheindex.
Permutations, of course, can be inverted. Applying the inverse permutation to a voter code
givesthecurrentindex.Allsubsequentvotercodescanbedeterminedbyapplyingthepermutation
tothecomputedindexplusone,plustwo,andsoon.
(ThisissuewasfirstdiscoveredbyProebsteletal.[26]inananalysisofHartsystemswherethey
didnothaveaccesstoanysourcecode.)
Prerequisites Inordertoexploitthisissuetheattackerwouldneedtoobserveasinglevotercode,
forexamplebyvoting. Also,theattackerwouldneedtoknowthepermutation,whichisfixedfor
theentireHartsystem.
Impact Anattackercouldpredictvotercodes. Usingthese,hevoteinplaceofanothervoter: He
mustwaitfortheothervotertobegivenavotercodefromapollworker. Beforethatvoterreaches
aneSlateandsignsinusingthecode,theattackersignsinonanothereSlates.Theattackercannow
vote as he pleases, whereas the legitimate voter will receive an error message indicating that his
votercodeisalreadyinuse.
§6.2eSlate-JBCCommunication 40
6. DetailedAnalysis
Mitigations Pollworkersshouldbevigilantforinstanceswherenewlyissuedcodesappeartobe
alreadybeingused.Theseoccurrencescouldbeindicativeofthisattackorofvoterswhoattemptto
double-votebyusingthesamecodetwice. Pollworkersshouldalsobeawareofvoterswhospend
anunusuallylongtimeinthevotingarea.
Hart could revise the software running on JBCs to produce cryptographically unpredictable
votercodes. Asimplewaytodothisisasfollows. Startanindexat0,andincrementitwitheach
vote. To produce a voter code, apply a keyed function to the index, where the key is chosen at
random at startup. A good choice is to apply AES (with a randomly-chosen 128-bit key) to the
index,andoutputtheresultmodulo10,000. Thekeyshouldbegeneratedusingasourceofstrong
randomness;theClibrary’srandfunctionisinsufficient.
Status This issue was discovered by examination of the source code. We have developed an
access code predictor and verified it against a real access code sequence from a JBC, provided by
Proebstel.
Issue8:TheJBCwillacceptvotesfromeSlatesthatarenotinanauthorizedstate
Votercodes,printedattheJBC,preventvotersfromregisteringunauthorizedvotesataneSlate.
As currently engineered, they do not prevent a compromised, malicious eSlate from registering
arbitrarilymanyvoteswithoutavotercodeandwithoutavoterpresent.
DetailedDescription TopreventvotersfromregisteringunauthorizedvotesusinganeSlate,Hart
employsvotercodes—four-digitpseudorandomnumbersprintedbytheJBCthatthevotertypes
intotheeSlate.
TheeSlatessendtotheJBCtheirmostrecentvotercodeaspartofeachstatusmessage; status
messagesaresolicitedbytheJBConceeverysecond.
The JBC keeps a list of valid voter codes. When a voter types a voter code into an eSlate, the
eSlatecheckswiththeJBCthatthecodeisvalidbysettingaflaginitsstatusmessagerequestfield,
whichpromptstheJBCtoverifythatthecodeisvalidandnotyetassignedtoassignedtoanother
eSlate. The JBC then logs the code as assigned to the eSlate and communicates to the eSlate to
proceedwithvoting.
Oncethevoterhasfinishedvoting,theeSlatesignalsthatithasavotereadybysettingasecond
flag in its status message request field, which prompts the JBC to ask the eSlate for the CVR and
torecordtheCVRinitsCVRandauditlogs. TheJBCthenremovesthevotercodeassociatedwith
thateSlate(thecodethatwastransmittedwiththateSlate’smostrecentstatusmessage)fromthe
activecodelist. Ifthecodeisnotnotfoundontheactivecodelist,noerrorisraised,andthevote
isstillrecorded.
TheJBChasenoughinformationintodetermine(1)whetherthevotercodewasgeneratedby
theJBC;(2)whetherthevotercodewasalreadyusedbytheeSlatevotingusingit;and(3)whether
thisisthefirstandonlyvotebeingrecordedbythiseSlateusingthisvotercode. Ourinspectionof
thesourcecodesuggeststhattheJBCdoesnotperformanyofthesechecks.
Acompromised,maliciouseSlatecanthusrecordarbitrarilymanyvotes,eachwithanarbitrary
votercode. (NotethatvotercodesareincludedintheauditlogsbutnotinCVRlogs;however,the
twologscanbecorrelated. SeeIssue25.)
Prerequisites Inordertoexploitthisissuetheattackerwouldneedtohavesubvertedorbeim-
personatinganeSlate.
Impact ThesubvertedorfakeeSlatecanrecordarbitrarilymanyvotesandthusengageinballot-
stuffing.
§6.2eSlate-JBCCommunication 41
6. DetailedAnalysis
Mitigations Electionofficialscananalyzetheauditlogstoverifythateachgeneratedvotercode
corresponds to at most one recorded vote, and that the eSlate to which the code was assigned is
theonethatrecordsthevote. Thisanalysiswouldallowofficialstodetecttheattack,butitwould
beimpossibleforthemtodistinguishwhichofseveralvotesrecordedfromasingleeSlateusinga
singlevotercodeisvalid;seeSection7.2.2.
Hart could revise the software running on JBCs to automatically perform the checks recom-
mendedabove,andtowarnpollworkersofattemptstoregisterunauthorizedvotes.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenotattemptedto
verifyitbyimpersonatinganeSlate.
6.3 Software Integrity Checks
Hartappearstohavebeenawareofthepossibilityofmaliciousfirmwarereplacementandtohave
takenstepsdesignedtopreventit. Inparticular,thefollowingfourmechanismsareused:
• The eSlate and the JBC both run internal memory consistency checks designed to detect
changesintherunningfirmware.
• TheJBCchecksitsownversion.
• SERVOcanbeusedtoverifythefirmwareimageontheJBC,eSlate,andeScan.
• TheJBCcheckstheversionofconnectedeSlates.
Allofthesemechanismsappeartofunctioncorrectlyfordamagedfirmware;however,theyappear
tobevulnerabletoattackbymaliciousfirmware.
Issue9:eSlate/JBCinternalCRCchecksdonotdetectattacks
eSlateandtheJBCruna“backgroundtask”whosejobistocheckmemoryintegrity. Thistask
starts with a list of memory regions and their expected CRC-16 values and compares the actual
CRCsoftheregionstotheexpectedCRC.Thischeckingislikelytobeeasilybypassed.
DetailedDescription TheeSlateandtheJBCbothrunabackgroundtaskwhichperformsmem-
ory checking. It is provided with a list of code sections to check8 and their CRCs, presumably
computed during the binary build process. Every ten seconds it walks through the list and com-
parestheCRCsoftheregionstotheexpectedCRCs.
Webelievethereareanumberofavenuesforbypassingorotherwiseavoidingthischeck.These
include:
• InsertingnewcodewiththesameCRC-16value. Thisiseasytodoifyouhaveevenasmall
amount of control over the instructions generated, as CRC-16 is not a secure hash function.
Approximately16locationswheretherearetwoalternativeinstructionsareenough.
• Overwriting the check list. This is likely to be possible in the 10-second interval between
checks.
• Patchingthecodethatrunsthecheckssothattheyarenolongerrun.
• Patching the firmware and section list in firmware and not in memory. Once the error is
caughtitcausesasystemcrash. Whenthesystemrestartsitwillhavethenewfirmwareand
sectionlist,soit’snotclearthiscanbedistinguishedfromasimplecrash.
We emphasize that we have not attempted any of these approaches because we did not have an
opportunitytouseadevelopmentkittogeneratenewfirmwarefortheJBCoreSlateandonlyhad
limitedaccesstobothdevices. However,thesearestandardtechniquesandseemlikelytowork.
8Wedonothavealistofthosesections.
§6.3SoftwareIntegrityChecks 42
6. DetailedAnalysis
Prerequisites Anyattackerwhohastheabilitytoloadanewbinaryimageononeofthesedevices
couldexploitthisissue.
Impact Thisissuedoesnotitselfallowcompromiseofasystem. However, itallowsanattacker
whohascompromisedavotingdevicetoavoiddetection. Hart’stamperdetectionroutinesarenot
themselvestamperresistant.
Mitigations Theproblemofhavingaprogramverifyitsownintegrityisverydifficultagainsta
cleverattacker. The“matchingCRC”approachcouldbemitigatedbyusingasuperiorhashsuch
asSHA-1,butthiswouldnotpreventtheotheravenuesofattack. Avarietyoftechnologies,such
asTrustedPlatformModulechips[25,33],arenowcommerciallyavailable. Futureversionsofthe
Hartsystemcouldinvestigatetheuseofsuchhardwarefeatures. Likewise,Hartcouldinvestigate
softwareattestationtechniquessuchasPIONEER[30,12].
WiththepresentHartsoftwareandhardware,therearenoeffectivemitigationsagainstthisat-
tack,beyondproceduralmeasuresaimingtolimitanattacker’sabilitytoinstallmalicioussoftware.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenottesteditona
runningsystem.
Issue10:JBCinternalversioncheckingisbroken
The JBC has some internal version checking, but it is unclear how it is intended to work. It
appears to only check two compiled-in numbers against each other and then log an error rather
thanexitingifthereisafailure.
DetailedDescription Onbootup,theJBCattemptstoverifyitssoftwareversion,ultimatelyfetch-
ing a a compiled-in value. This value is then logged and “success” is indicated as a return code.
Iffailurewereeverindicated,thesystemwouldexit,butsinceitcannot,thisfunctionalwayssuc-
ceeds. Perhapstheimplementationofthisfeatureisincomplete.
Impact We don’t understand the purpose of this set of checks. An attacker can compile in any
versionnumbertheywantandit’snotclearthattheauditlogsarecheckedforversionnumbersin
anycase. However,whateverbehaviorthischeckissupposedtoprevent,itseemsunlikelythatit
doesso.
Mitigations Unknown.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenottesteditona
runningsystemtoseeifwemisunderstanditsfunction.
Issue11:SERVO-baseddevicefirmwarecheckingcanbespoofed
SERVO can be used to verify the firmware of voting devices against an official firmware in-
tegrity file provided by Hart. This file contains SHA-1 digests of the firmware images. SERVO
downloads the firmware images from the target device and then computes the digest and com-
paresitwiththerecordedhash. Iftheydonotmatch,SERVOsignalsanerror. However,because
the firmware image is provided by the running program, a malicious image can simply provide
datathatfoolsthecheck(e.g.,bymaintainingabackupcopyofthelegitimatefirmwareimagefor
purposesofcomputingtheseSHA-1digests).
§6.3SoftwareIntegrityChecks 43
6. DetailedAnalysis
Detailed Description SERVO maintains a database of all known devices owned by the county,
partly for inventory control purposes. When a new device is introduced into the system (this is
determinedbythe32-bitdeviceID),itoffersanoptionto“Verify”thatthedevicecontainstheex-
pectedfirmwareimage. Verificationisdonebycomparingthehashofthedevice’sactualfirmware
totheknown-goodhash. SERVOstoresknown-goodhashesforeachtypeofdeviceinitsdatabase;
theseareloadedfromanXMLfilesuppliedbyHartusingSERVO’s“ImportFirmwareDataFile...”
menuitem.
Theverificationprocessisasfollows:
1. InterrogatethedeviceforitsdeviceID.
2. Ifthedeviceisalreadyinthedatabase,exit.
3. Retrievethedeviceversionnumberandcompareittotheexpectedversion.
4. Ifthedeviceisn’tinthedatabase,downloaditsfirmware.OntheeScanthisisdonebyreading
thefileeScan.exeusingtheFILE_CMD_GETcommand. OntheJBC/eSlatethisisdoneby
usingtheMEM_READcommandtoreadtheappropriatememoryblock.
5. Oncetheentirefirmwareimageisrecovered,itishashedwithSHA-19 andthehashiscom-
paredtotheexpectedvalue.
Thistechniquehasseveralproblems. Thefirstisthatthefirmwareisonlycheckedthefirsttimea
deviceisloaded. Wedonotknowifthedatabaseiszeroedbetweenelections,butifitisnotthen
subsequent compromises will not be detected. Second, it is dependent on the device’s providing
the correct device ID. It is unclear what happens if the device provides the device ID of another,
alreadychecked,device.
Theseissuescouldpresumablybedealtwithbyforcingacheckeverytime. However,themore
seriousissueisthatthecommandsthatSERVOusestodownloadthefirmwareimageareexecuted
bytheprogramrunningontheeScan,JBC,oreSlate. Ifthatprogramhasbeencompromiseditcan
simplyhandbackthecontentsofavalidbinaryeventhoughthosedonotreflecttheprogramthat
isactuallyrunning.Anotherwaytobypassthischeckwouldbetohavethelastactofthemalicious
imageuponelectionclosebetocopythecorrectimagebackontothemachine.
ThecurrentimplementationoffirmwarecheckingalsoleavesSERVOvulnerabletocompromise
byamaliciouseScan;seeIssue13.
Prerequisites Anyattackerwhohastheabilitytoloadanewbinaryimageononeofthesedevices
couldexploitthisissue.
Impact Thisissuedoesnotitselfallowcompromiseofasystem(see,however,Issue13).However,
itallowsanattackerwhohascompromisedavotingdevicetoavoiddetection.
Mitigations Theproblemofverifyingthataparticularpieceofsoftwareisrunningonaremote
system (attestation) is known to be extremely difficult. The obstacle is exactly as seen here—you
needtocommunicatewiththesystembutyouaredoingsothroughapieceofsoftwareyoudonot
yet trust. One commonly suggested strategy is to have a supervisor process which intercepts the
communication and vouches for the binary. The supervisor itself is not field replaceable. This is
difficultinthissettingfortworeasons.
First,theJBCandeSlatehavenosuchsupervisorprocesssoimplementingthisapproachwould
requireverysignificantrearchitecture.eScanrunsWindowsCEandsoitmightbepossibletoinstall
suchasupervisor. However,thehistoryofoperatingsystemsecuritysuggeststhatonceattackers
are able to run code at all on a target system they are typically able to escalate their privileges to
supervisorstatus.
9Thefileformatallowssomeflexibilityinthis,butSHA-1appearstobewhat’sused.
§6.3SoftwareIntegrityChecks 44
6. DetailedAnalysis
Second,thisdoesnotsolvetheproblemofanattacker’scompletelyreplacingallthesoftwareon
themachine,includingthesupervisor.Dependingonthearchitecture,thismightinvolvehardware
hackingbutisgenerallynotimpossible.Inthelimit,theattackercansimplygutthemachine,install
hisownprocessor,andrunavirtualizedversionoftheHartsoftware.
Anothersuggestedapproachwouldbetomovethefirmwarecheckingtothedevicebyrestrict-
ingittoloadingonlytrustedfirmware. Thiswouldrequiresuperiormemorycheckingtothatused
by Hart (see Issue 9), which may or may not be practical. It would also not provide resistance to
completereplacementattacks. Thehistoryofattemptstobuildrestrictedloadersisnotparticularly
good[32].
The only known workable strategies for remote attestation involve trusted hardware on the
targetsystem(seeIssue9). Thathardwarecanverifytherunningmemoryimageandcryptograph-
ically signs the results for consumption by the verifier. This approach would require extensive
modification of Hart’s devices, both from a hardware perspective and in order to introduce the
cryptographicinfrastructureusedforverification.
Analternativetoremoteattestationislocalattestation,byhavingSERVOreadthefirmwareof
thetargetdevicedirectlyratherthanthroughthedevice’ssoftwarestack.Thiswouldeitherrequire
interfacing the device non-volatile memory to a new external port (a potential source of security
holes)orphysicallyremovingthenon-volatilememoryinthewarehouseandverifyingitdirectly.
TheHartdevicesdonotappeartobedesignedtomakeeitherapproacheasy.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedatool
which runs on an ordinary Linux PC and will accept a connection from SERVO, pretend to be
aneScan,andreturnabinarytakenfromarealeScan. Thisbinaryproducesthesamehashasthat
providedbyarealeScan.Wehavenotrunthroughtheentirebackupandresetprocessbecausethis
wouldinvolvewritinghandlersforothereScancommands. However,webelievethisispractical
todogivenmodestlymoretime.
Issue12:JBC-basedeSlatefirmwarecheckingcanbespoofed
The JBC attempts to check the integrity of the eSlate firmware. As with Issue 11, this check
dependsonthetargetdevice’stellingthetruth,whereasacompromiseddevicecanandwilllie.
Detailed Description When a JBC connects to an eSlate, it gets the eSlate device information.
TheresponsecontainstheeSlate’ssoftwareversionandthe“privateID”whichappearstobesome
sort of CRC value. It then compares the major version of the eSlate software (ignoring the minor
version) against its own version, which is hardcoded. If that matches, the eSlate is judged to be
acceptable. Because this value is under the control of the eSlate software, this may be useful as a
compatibilitycheckbutisuselessagainstamaliciouseSlate. Inaddition,thischeckisonlydoneat
startup,soaneSlatecompromisedduringanelectionwouldgoundetected.
Prerequisites Anyattackerwhohastheabilitytoloadanewbinaryimageononeofthesedevices
couldexploitthisissue.
Impact Thisissuedoesnotitselfallowcompromiseofasystem. However,itallowsanattacker
whohascompromisedavotingdevicetoavoiddetection.
Mitigation SeethemitigationdiscussionforIssue11.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenottesteditona
runningsystem.
§6.3SoftwareIntegrityChecks 45
6. DetailedAnalysis
6.4 Buffer Management Vulnerabilities in Back-End Systems
Theback-endelectionmanagementsystems(BOSS,SERVO,Tally,BallotNow)areprogramsrun-
ningonstandardWindows-basedPCs. Itisexpectedthatphysicalaccesstothesesystemswillbe
restrictedtoauthorizedpersonnel. Despitethis,therestillremainseveralavenuesthroughwhich
attackscanbemounted,including:
MBBstransportedfrompollingplaces areconnectedtoback-endelectionsystems. TheseMBBs
couldhavebeentamperedwith,asdescribedinSection6.8.
Pollingplaceequipment couldbeconnectedtotheSERVOsystempost-election. Thisequipment
couldhavebeentamperedwith(asdescribedinSection6.1).
ConnectionsfromaTallysystem toaRallysystemcouldbemadeforthepurposesoftransferring
electiondata. IftheRallysystemwerecompromised,itcouldbeusedtopropagateattacksto
Tally. (SeealsoSections6.9and6.6.)
Malicioususeofelectionmanagementsystems byauthorizedpersonnel.
As a result, great care should be taken to secure the back-end systems at the points where they
interactwithotherelectionsystems.
Issue13:MultiplebufferoverflowsinSERVO
Afteranelection,SERVOisusedbyelectionofficialsforverificationandbackupofthepolling
placedevices. Inparticular,itisusedto:
• VerifythefirmwareontheJBC,eSlates,andeScan
• BackuptheCastVoteRecordlogsfromtheJBC,eSlates,andeScan
• BackuptheauditlogsfromtheJBC,eSlates,andeScan
Each of these routines contains buffer overflows which we believe to be exploitable, allowing an
attacker who has compromised the connected device to execute arbitrary code on the machine
runningSERVO.
DetailedDescription Alloftheseoverflowsfollowroughlythesamepattern: SERVOallocatesa
bufferofagivensizetoreaddatafromthedevice. Itthenreadsablockofdatafromthedevicebut
allowsthedevicetospecifythesizeofthedata,withoutcheckingwhetheritwillfitinthebuffer.
This allows an overflow which corrupts the malloc arena, which can be exploited using known
techniques[23,2].
As a specific example, consider an overflow in the firmware verification routine. SERVO in-
vokes FILE_CMD_GET to read 1000 byte extents of the eScan executable10 (stored as a file on the
eScan flash memory) into a local buffer. However, it allows the eScan to tell it the length of the
returned buffer (likely in order to detect the end of file by a short read). The eScan can cause an
overflowofthebufferbyreturningalengthgreaterthan1000. Thebufferisallocatedontheheap
andispromptlyfreed,whichiseasilyexploitableduetothedetailsofthemallocimplementation
used.
ThisparticularattackappearstoworkonlywiththeeScanbecauseadifferentcommandisused
toreadtheeSlateandJBCfirmware;however,theCVRlogandauditlogbackupissuesappearto
applytoallthreedevices.
Weareawareofotherpotentialissuesthatappeartobesomewhathardertoexploit.
10Strangely,thecommentforthissizedefinitionreads16k bytes.
§6.4BufferManagementVulnerabilitiesinBack-EndSystems 46
6. DetailedAnalysis
Prerequisites Inordertoexploitthisissue,anattackerneedstotakecontrolofadevicewhichwill
laterbeverifiedorbackedupwithSERVO.Wehavealreadydescribedanumberofissueswhich
shouldallowthis(seeSection6.1).
Note that the exploit described above requires that the device appear to be a “new” device in
order to activate the verification routine. However, as the eScan can provide a device ID of its
choosing, this should be easy to do even with a pre-verified device. The other routines do not
sufferfromthislimitation.
Notealsothatwhilerunningtheverificationandbackupproceduresisnotrequiredforcorrect
functioningoftheHartsystem,itappearstobeHart’srecommendedprocedureandcheckingthe
“verify” checkbox is simply treated as part of the backup procedure in the SERVO documenta-
tion[19].
Impact The immediate impact of this attack is to allow the attacker to run arbitrary code in the
SERVO process. This will generally also allow the attacker to run a program on the SERVO ma-
chineastheSERVOuser,aswellastomodifySERVOasdesired. Itisnotnecessarytoescalateto
Administratorprivileges;nevertheless,techniquesfordoingsoarewell-known.
Forthelong-termimpactofthisattackseeSection7.4.
Mitigations Theseattackscouldbedirectlymitigatedbyfixingthespecificoverflows. However,
thefactthatwewereabletoreadilydiscoverthreesimpleoverflowsinaverysmallsectionofthe
SERVOcodebasesuggeststhatSERVOisinsufficientlycarefulaboutcheckingtheinputitreceives
fromdevicesitissupposedtobechecking. Itwouldnotbesurprisingtodiscoverotherremotely
exploitablevulnerabilitiesofthesametype. SeeSections5.3and6.11formoreonthispoint.
Status These issues were discovered by examination of the source code. We have directly ex-
ploited the first of the three attacks (through the firmware verification routines) against our own
copyofSERVOinstalledonWindows2000SP4inaVMWareimagerunningononeofourLinux
machines. OurexploitinstalledaWindows“bindshell”thatwewereabletoremotelyaccess. We
havenotyetattemptedtoexploititagainstaHart-suppliedmachine.
Issue14:AnimproperlyformattedMBBwillcauseRallyorTallytocrash.
A mobile ballot box (MBB) can be carefully crafted to cause the Rally or Tally applications to
crashwhenanMBBisreadintothesystem. IfacompromisedRallyfeedsthisinformationtoTally,
Tallywilllikewisecrash.
Detailed Description The MBB file format makes extensive use of 16-bit CRCs, which serve to
detectminorcorruptionwithinthefile. (16-bitCRCsdonotserveanysecurityfunctiontoprotect
against tampering. The MBB format separately uses HMAC for that purpose, as describe in Sec-
tion6.8.) Thelow-levelroutinethatverifiestheseCRCsusesa32-bitlengthfieldthatcomesfrom
theheaderoftheMBB.Whilethetruelengthofthebuffermightbequitesmall,theheaderofthe
MBBcanspecifyamuchlargerbuffer.SuchamalformedMBBwillcausethecrc16routinetoread
memorybeyondtheendofthebuffer.
Given a large-enough length field, crc16 will eventually attempt to read a virtual memory
addresswherenophysicalpagehasbeenmapped. Thiswillresultinasegmentationfault,causing
Tally to crash. Every time Tally is restarted and asked to process the MBBs, it will consistently
crash.
Impact Thisattackwillnotdestroyanydata,butitcancauseeitherRallytoTallytocrashwhen
readinganMBB.IfaRallymachinehasbeencompromisedthroughothermeans,thenthecommu-
nicationspathbetweenRallyandTallywouldallowforRallytodeliveracorruptMBBtoTallyand
causeTallytocrash.
WhilethecorruptMBBwouldneverbewrittentothedatabaseondisk,thiscouldcauseafair
amountofconfusionfortheelectionadministrators.
§6.4BufferManagementVulnerabilitiesinBack-EndSystems 47
6. DetailedAnalysis
Prerequisites An attacker must be able to introduce a corrupt MBB into the legitimate flow of
MBBsfromtheprecinctsbacktoElectionCentral. Thisattackcouldbeperformedbyamalicious
pollworker(orgroupofpollworkers, dependingonlocalprocedures). Thisattackcouldalsobe
performed if any individual eScan, JBC, or Rally server had been corrupted at some point in the
process,asallofthemultimatelyfeedMBBstotheTallyserver.
Mitigations AnattackofthisformmightnotcorrupteveryMBBbutonlyasubsetofthem. Elec-
tionofficialswouldbeabletodetermineaspecificMBB(orsetofMBBs)whichcausethecrashing
condition. This would allow the election officials to tally the non-corrupt subset of MBBs; votes
fromtheeffectedprecinctswouldneedtobehand-talliedfrompaperrecords.
FutureversionsoftheHartsoftwarecouldbeengineeredtomorecarefullytrackthetruesizeof
anygivenbuffer,ratherthantrustingthelengthfieldsinpotentiallyuntrusteddatatobetruthful
(seeSection5.3andIssue36formoredetails).
Status Thisissuewasdiscoveredbyexaminationofthesourcecodeprovidedtothecodeanalysis
team. IthasnotbeendirectlyverifiedagainstRallyandTallyservers.
6.5 Privilege Issues in Back-end Systems
AlloftheHartback-endsoftwarerunsonageneral-purposeoperatingsystem(Windows)withits
own security mechanisms intended to force users to only use the official applications and block
direct access to the underlying data, even by an election administrator. However, in many cases
we find that the Hart applications are designed in such a way that allows such direct access. A
particularpointofconcernisthesecurityofthedatabasesthatstoremuchofthedataontheHart
system.
Issue15:Databasepasswordsarestoredinsecurely
The user names and passwords used by the back-end election management systems to access
databases containing election data are stored in configuration files. The configuration files, as a
whole, are not protected using any cryptographic techniques. Within the files, the password is
obfuscated,butthemethodofobfuscationiseasilyinvertedtorecoverthepassword.
Detailed Description When one of these systems (Boss, SERVO, Ballot Now, Tally) is started,
a user name and password is read from a configuration file and used to connect to the database
server. The password value contained in the configuration file is the characters of the original
passwordXOR’dwiththecharacter‘x’. Anyonewhohasaccesstotheconfigurationfilecaneasily
recover the database password and use it to connect directly to the database server containing
electiondata,readinganydatapresent,aswellasmakingarbitrarychangestothedatabase.
Prerequisites AnyattackerwhohasaccesstothefilesystemofthePCrunningaback-endelection
managementsystemcouldexploitthisissue.
Impact Since the username and password contained in this configuration file are used by the
election management system code to read, modify, and delete election data, possession of this
passwordconfigurationfileallowsthesameprivileges.
Mitigations One of the most common reasons to store passwords in a file is to avoid requiring
userinputuponprogramstartuporhavingtheusertypemultiplepasswords. Ifthisisanecessary
productfeature, thenthereareanumberofwaystopartiallymitigatetheriskofpasswordexpo-
sure. Oneofthemostcommonisrequiringmorereadandwritepermissionsontheconfiguration
§6.5PrivilegeIssuesinBack-endSystems 48
6. DetailedAnalysis
filethantheuserloggedintothePCowns. Theelectionmanagementapplicationsarethenconfig-
uredtoRunAs11 auserthathastheappropriatereadandwritepermissionsontheconfiguration
files. The reason that this can only be considered a partial mitigation is that if the normal user
isabletoescalatehisprivileges, thenthepasswordscanberecovered. Alternatively, anadminis-
trative user could still recover the database password. See Section 6.6 for more issues related to
Windowssecurity.
Amoreaggressiveapproachwouldbetohavethedatabaseencryptedunderapasswordthat
theusertypedin,avoidingtheentireissueoffileaccess. Thispasswordcanbeintegratedwiththe
generalHartloginsystemtoavoidmultiplepasswordmanagementissues.
Status We discovered this issue by examining the source code. We then developed tooling to
extractthepasswordandwereabletousethepasswordtoconnectdirectlytothedatabase.
Issue16:BallotNowcountersarestoredindatabase
The Ballot Now system is designed to maintain a private counter of all ballots processed by
a given Ballot Now installation as well as a public counter of the number of ballots written to a
particularMBB.WhenBallotNowisinstalled,theprivatecounterisexpectedtobezero. Further,
only the Ballot Now system is supposed to have the ability to increment the private counter. We
foundthattheabilitytoaccessandmodifytheBallotNowdatabasesufficesforchangingthevalues
ofthepublicandprivatecounters.
DetailedDescription Theprivateandprivatecountersareimplementedasdatabasetableentries
in the database used by Ballot Now. Anyone who can connect to the Ballot Now database with
theprivilegetoupdatethetablecontainingtheprivatecountercanchangethecountervalue. As
described above, the username and password of an account that has such privileges is stored on
thefilesystemofthePCrunningBallotNow.
Prerequisites AnyattackerwhohasaccesstotheBallotNowdatabasecouldexploitthisissue.
Impact ModifyingthepublicorprivatecountersofaBallotNowsystemcouldbringintoquestion
thenumberofballotsthatitprocessed,eitherinagivenbatchofMBBsorforitslifetime,potentially
requiringmanualexaminationofelectiondatatoresolvediscrepancies.
Mitigations This problem can be partially mitigated by requiring more read and write permis-
sionsonthecounterfiles(andthedatabasefiles)thantheuserloggedintothePCpossesses. Ballot
NowwouldthenbeconfiguredtoRunAs12auserthathastheappropriatereadandwritepermis-
sionsonthecounterfiles. Thereasonthatthiscanonlybeconsideredapartialmitigationisthatif
thenormaluserisabletoescalatehisprivileges,thenthecounterscanbemodified. Alternatively,
an administrative user could still modify the counters. See Section 6.6 for more issues related to
Windowssecurity.
Future Hart software could be designed to leverage the hardware counters featured in TPM
chips[33]thatareincreasinglyinstalledinstandardPCs. Thiswouldallowcounterstobestored
inatamper-resistantchipratherthanontheaccessiblefilesystem.
Status Wediscoveredthisissuebyexaminingthesourcecode.
Issue17:The Tally interface allows a Tally administrator to “adjust vote totals.”
Thiscancreateinconsistenciesinthereportedvotetotals.
11http://support.microsoft.com/kb/294676
12http://support.microsoft.com/kb/294676
§6.5PrivilegeIssuesinBack-endSystems 49
6. DetailedAnalysis
DetailedDescription Inthecourseofrunninganelection,theremaybeavarietyofreasonsfor
anelectionadministratortoneedtoadjustthetotalsbeingreportedbyTally. Onereason,citedin
theTallyUserManual,isthattheremaybeanadditionalvotingsysteminuse,entirelyoutsideof
Hart’svotingsystem,whosevotesneedtobeincludedinthefinaltally.
The “adjust votes” feature allows the election administrator to select a specific precinct, race,
and/orparty(forprimaryelections),andtomakechangestothebottom-linetotalsforthatpartic-
ularrace. Theimplementationofthisfeaturejustchangestherelevant“total”fieldsintheunderly-
ingdatabasewithoutaddinganycorrespondingrecordsthattheadjustmentshadbeenmade. This
couldresultinvotetotalsinconsistentwiththenumberofcastvotes. Thisalsodoesnotallowan
administratortoeasilyundoormodifysuchchangesaftertheyhavebeenperformed.Ifanelection
administratoradjuststhevotetotalsthenrealizestherewasanerror,theoriginaladjustmentscan
onlybefoundintheauditlog. The“adjustvotes”dialogboxwillnotshowpreviouschanges,nor
isthereaneasywaytobackoutchangesaftertheyhavebeenmade.
Inadditiontotheopportunitiesforanadministratortomakelegitimatemistakes,thisfunction-
alitycouldalsobeusedtotamperwiththeelectionresults.
Prerequisite The user of the “adjust votes” dialog must have “administrator” privileges on the
Tally application. Users may either be “administrators” or “operators” and operators are not al-
lowedtoadjustvotetotals. Anyuserwhoeitherknowsorcanguesstheadministratorusername
andpasswordandhadbriefphysicalaccesstotheTallymachinecouldperformtheattack.
Impact The reported vote totals could be inconsistent with the genuine cast ballot totals. The
votetotaladjustmentsareincludedintheauditlogs, whichwouldallowtheseadjustmentstobe
observed.
Mitigations Users of Hart election systems could be discouraged from using the “adjust vote
totals”featureofTally.
Tally offers a variety of report formats, including some which are intended to be easy to load
into tools like Microsoft Excel. California could require that a standard set of reports, including
a complete report of the audit log, be produced in machine- and human-readable formats. This
wouldsimplifytheprocessofdetectingabusesofthisfeature.
Infuturesoftwarereleases,Hartcouldchangethisfeaturetofollowbasicaccountingprinciples,
explicitlyreportingtheadjustmentsalongsidethetotalsratherthansimplyoverwritingthetotals.
Status ThisissuewasdiscoveredbyexaminationofthesourcecodeandverifiedbytheRedTeam
onactualTallysystems.
Issue18:Databasesarenotencrypted
Election-relateddata,storedinthedatabasesusedbytheseback-endelectionmanagementsystems,
isstoredinplaintext.Asaresult,electiondatacanbereadoffwithoutknowingthedatabaseaccess
password.
Detailed Description The election-related data stored by these systems (Boss, SERVO, Ballot
Now,Tally)arestoredinSybasedatabases. Thesedatabasesmakeuseofthefilesystemforpersis-
tentstorage. EventhoughloggingintothedatabaseandissuingSQLcommandsrequiresknowl-
edge of the database password, the database entries can be recovered by simply opening the
databasefiledirectlywithabinaryeditingtool. Withalittleextraeffort,thedatabaseentriesthem-
selvescanbealteredbydirectlymodifyingthedatabasefile.
Prerequisites AnyattackerwhohasaccesstothefilesystemofthePCrunningaback-endelection
managementsystemcouldexploitthisissue.
§6.5PrivilegeIssuesinBack-endSystems 50
6. DetailedAnalysis
Impact Sensitiveelectiondatacanbeobtainedorpotentiallymodified.
Mitigations Onenaturalmitigationistoemployadatabaseencryptionscheme. Alternatively,a
partialmitigationwouldbetorestrictreadandwriteaccesstothedatabasefile,inafashionsimilar
tothatdescribedinIssue15.
Status We discovered this issue by examining the source code. The absence of encryption was
verifiedbyexaminingdatabasefilesgeneratedduringasimulatedelection.
Issue19:Newuserscanbeaddedviathedatabase
An operator of one of the back-end election management systems, who has restricted access,
can create a new account for herself with higher privileges. In general, being able to access the
databasesforoneofthesesystemspermitsthecreationofnewuseraccounts.
DetailedDescription Thedistinctionneedstobedrawnbetweenthepasswordusedforlogging
intoasystemdatabaseversusthepasswordsusedforloggingintoaHartapplication.Thedatabase
password, in addition to being stored within the database, is also stored by the application (see
Issue15). Theapplicationsalsomaintainuserpasswords,forusersoftheapplications. Thesepass-
wordsarealsostoredinsidethedatabaseand,unlikethedatabaseaccesspasswords,arenotstored
intheclearbutareinsteadhashedwitharandomsalt(afairlystandardtechnique, usedbyUnix
andmanyothersystems;anattackerwhocanreadthesalted/hashedpasswordswillnotbeeasily
abletolearnthepasswords).
While an attacker cannot directly read the plaintext passwords, the attacker can either reuse
existingpasswordsorcomputenewonesifhehastheabilitytowritetothefile. Likewise, anat-
tackercanprogramacomputertomethodicallytrycommonpasswords(e.g.,wordsindictionaries)
againstthehashedpasswordsinthedatabase. Ifauserchoseorwasgivenaweakpassword,the
attackercoulddiscoverthis.
Prerequisites Anyattackerwhohasread-onlyaccesstothefilesystemofthePCrunningaback-
endelectionmanagementsystemcouldextractthepasswordfileandreverse-engineerpoorlycho-
senpasswords. Anattackerwhohasread-writeaccesstothefilesystem(particularlythedatabase)
couldinstallhisownusersandgivethemadministrativeprivileges.
Impact Privilegeescalationforoperatorsofback-endelectionmanagementsystems.
Mitigations As with other database-related issues, the root issue is that normal users will have
sufficientprivilegestoaccessthedatabasewithoutgoingthroughtheHartapplications. Thesame
mitigations,asdescribedabove,applyhere.
Status Wediscoveredthisissuebyexaminingthesourcecode. WemanuallystarteduptheTally
databaseserver,loggedin,andissuedSQLcommandstoaddnewTallyuserswiththesamepass-
wordasexistingusers. Wewerethenabletosuccessfullyloginusingtheseaccounts.
6.6 Windows-related Vulnerabilities
ManyofthecomponentsoftheHartelectionsystemrunonstandardWindows-basedPCs,includ-
ingBOSS,Servo,Rally,Tally,andBallotNow.
TheHartdocumentationprovidesonlyminimalguidanceinhowtheirWindowsinstallations
shouldbeconfigured. ThereareawidevarietyofsecurityissuesthatoccurwithanyuseofWin-
dowsmachines. ThissectionfocusesonissuesthatmayapplywithWindowsasusedinatypical
Hartcustomerinstallation.
§6.6Windows-relatedVulnerabilities 51
6. DetailedAnalysis
Issue20:Back-endWindowssystemsmaybeinsecure
Because all of the Hart back-end components run on Windows-based PCs, an attacker who is
able to subvert Windows may be able to subvert the Hart components. The user need not start
outwithadministratorlevelaccessbecausestandardconfigurationsofWindows-basedcomputers
oftenaresusceptibletoprivilegeescalationattacks, especiallyiftheyhavenotbeenlockeddown
orkeptuptodate. Therefore,thesecurityoftheWindowsenvironmentiscritical.
Detailed Description Hart provides only minimal guidance for securing these machines. They
do not provide detailed instructions on how to lock them down. Moreover, they encourage or
requirepracticesthatarelikelytocompromisesecurity. Section3.5oftheHartuseprocedures[21]
state:
OperatingsystemupgradestothecomputersonwhichtheHartVotingSystemapplica-
tionsareonlyperformedbyHartInterCivicpersonnel,andonlythen,aftercertification
bytheSecretaryofState.
Weareunsureifthisisacertificationrequirement,butinanycase,unpatchedversionsofWindows
aregenerallyinsecureandbecomeincreasinglysoasnewvulnerabilitiesarediscovered.
It is likely that an attacker with even short-term physical access to one of the back-office ma-
chinescouldsubvertitandescalatetoadministratorprivileges. Thiswouldnotbealongprocess
sincehecouldloadmalwareonaUSBstick,setitoff,andthenleave.
Prerequisites AnattackerneedsphysicalaccesstooneoftheWindows-basedcomputersusedin
ElectionCentralforatmostaminute. Theattackercoulduseausernameandpasswordtologinto
theWindowsmachine;orobtainaccesstoamachinethatisalreadyloggedin,perhapsleftalone;
or,withmoretime,accessthechassisandaccessthemachine’shardwaredirectly.
Impact Election insiders with physical access to any of the Windows-based back-end machines
couldmostlikelysubvertthem.
Mitigation First and foremost, all Windows systems should be regularly updated with security
patchesfromMicrosoft.13 Thiswillreduceexposurestowidelyunderstoodvulnerabilities.
Another important mitigation is to “lock down” Windows so that the user accounts used to
operate the Hart systems have limited privileges rather than the full privileges of the Windows
administrator. A suitably-configured user account would be unable to run any programs beyond
the official ones necessary to operate the Hart software. Microsoft offers some advice for how to
best configure Windows XP with least-privilege user accounts14 and has added a variety of fea-
turesalongtheselinestoWindowsVista. ForWindows2000,whichseemstobecommonforHart
servers,Microsofthasextensiveresourcesonlinetodescribehowtolockdownsuchamachine15.
There are also good guides elsewhere online16. This will not necessarily stop privilege escalation
butmaydelayit.
Finally,physicalaccesstothesemachinesshouldbehighlylimited. Itshouldnotbeassumed,
merelybecauseauserdoesnothavealogintoamachine,thatitissecureinhispresence.
Status This issue was discovered by examination of the Hart manuals. Red team analysis of
the systems provided by Hart determined that they were running Windows 2000 SP4, with the
“LicensedUser”grantedfulladministrativeprivileges.
13InstallingupdatestoWindowsandtoanti-virussystemsmayhaveimplicationsforthecertificationprocess, which
typicallyconsidersaspecificversionofeveryelementofthesoftwarestack,includingCOTScomponents.
14http://technet.microsoft.com/en-us/library/bb456992.aspx
15http://www.microsoft.com/technet/security/prodtech/windows2000/secwin2k/default.mspx
16See,e.g.,http://www.cites.uiuc.edu/security/byos/win2000.html
§6.6Windows-relatedVulnerabilities 52
6. DetailedAnalysis
Issue21:ManyHartsystemsareconnectedtointernalnetworksormodems,open-
ingthemtoattacksagainstWindows’vulnerabilities.
Detailed Information Windows systems, particularly those which do not have Microsoft’s se-
curity patches regularly installed, are well-known for having network-exploitable security holes.
WhilenoneoftheHartWindows-basedsystemsshouldeverbedirectlyconnectedtotheInternet,
thesevulnerabilitiesmaystillbeexploitable.
Anattackerwishingtoexploitoneofthesevulnerabilitiesneedstoconnecthisowncomputer
to the same network as one of the Windows machines running Hart software. The attack would
onlytakesecondstoperform,perhapsinstallinga“backdoor”accountontheWindowsmachines,
allowing them to be accessed later in an arbitrary fashion. Such attacks would likely override
any locking down of user account privileges (as described above), since many of the vulnerable
Windowssystemservicesrunwithfulladministrativeprivileges.
An attack such as this could be mounted against Rally (when used at Election Central), Tally,
BOSS, Servo, and eScan machines. In addition to launching an attack from an unofficial laptop
computer, the attacker could possibly have compromised an eScan machine while it was in the
field; eScanmachinesareconnectedtothelocalnetworkatElectionCentraltoextracttheirvotes,
providing an opportunity for the eScan machine to mount attacks against other machines on the
samenetwork.
WhenRallyandTallycommunicateusingmodems(seealso, Section6.9), anattackercanalso
dialthephonenumberusedbytheRallymachine. IftheRallymachineisconfiguredinthefashion
specifiedintheRallyUser’sManual[18],thennousernameorpasswordwillberequiredbeforethe
Rallymachinegivestheattackera“local”networkaddress(i.e.,192.168.x.x)allowingtheattacker
to communicate with any service on the Rally machine, not just the Rally application itself. This
meansthatanynetwork-exploitablevulnerabilityinWindowsisnowamodem-exploitablevulner-
abilityinaRallymachine. WhenTallyconnectstoRally,acompromisedRallycanthenattackthe
Tallysystem,whichinturncanattackotherWindows-basedsystemsatElectionCentral.
Hartdoesrecommendthatanti-virussoftwaresoftwarebeinstalledonitsWindows-basedsys-
tems(seetheHartProductDescription[17],pages27-30),howeversuchsoftwaretypicallyrequires
an active Internet connection to download the latest updates, as does Microsoft’s own Windows
Update system. As Hart’s Windows-based systems should never be connected to the Internet,
this presents some practical complications to keeping both the anti-virus software and the neces-
sary Windows security patches up to date. Hart’s System 6.2 Use Procedures [21] (Sections 10.2.3
and10.2.4)statesthat“anti-virussoftwareisonlyinstalledandconfiguredbyHartInterCivicper-
sonnel” and that “installation of software and firmware upgrades is performed only by Hart In-
terCivicpersonneliforwhennecessary.” ThisrequiresHart’scustomerstorelyonthevendorfor
a variety of services. As a major election approaches, the vendor may be unable to provide this
servicetoallitscustomersinatimelymanner.
Furthermore,mostanti-virussoftwarefocusesonsearchingforwell-knownviruses(“signature
matching”);securitycompromisingsoftware,engineeredspecificallytoattackHartsystems,would
mostlikelynotmatchthesignatureofanyknownvirus. Hartsuggeststhatsuchupdatesshould
beperformedthroughremovablemedia[21](Section10.2.3).
Prerequisites Anattackermusteitherhaveaccesswithalaptopcomputertothelocalnetworkat
ElectionCentralforatmostaminute,ortheattackermusthavepreviouslycompromisedanyone
computerusedinthelocalnetwork, includingtheeScanmachine. Onceonemachineisinfected,
the infection can spread to every other machine without the direct involvement of the attacker.
Infections from traditional computer worms and viruses might also spread, inadvertently, in the
samefashion,forexample,ifanelectionadministrator’spersonal,Internet-using,laptopwasacci-
dentallyconnectedtotheinternalnetworkatElectionCentral.
Impact OnceanyoneWindows-basedsysteminaHartelection,includinganeScansystem,has
been compromised in any fashion, it can then use well-known Windows vulnerabilities to attack
§6.6Windows-relatedVulnerabilities 53
6. DetailedAnalysis
alloftheothernetworkedHartsystems. Suchattackswouldhavefullsystemprivileges,allowing
them to modify or delete votes and other records. Likewise, the attack can spread either directly
fromtheinitialcompromisedmachine,oritmightspreadviaviralpropagation.
Mitigations Windows XP and Vista have a built-in firewall tool.17 This should be configured
to block all ports except those required for the Hart system to function. For example, Rally and
Tallymachinescommunicateonport4500. Nootherportsshouldbenecessary,althoughthiswill
require careful testing to determine whether there are unexpected dependencies. Regardless, the
firewall can be configured to allow connections on only this handful of ports while dropping all
othertraffic.
Hart can and should develop a step-by-step checklist for installing its systems on Windows
andforconfiguringWindowstominimizeexposurestonetwork-basedvulnerabilities. Thiscould
be applied to the current, certified versions of Hart software. Likewise, the California Secretary
of State’s office could create such a Windows checklist and require Hart customers in the state
to follow it. (A complete guide to Windows configuration is beyond the scope of this report.)
Thechecklistshouldbemandatory,andmustnamethespecificversion(s)ofWindowstowhichit
applies.
AmoreaggressivemitigationwouldbetoplaceeachHartsystemonaseparatenetwork,with
airgaps between them. This would significantly reduce the risk that compromise of one system
would affect others. This would be useful against attacks even if the machines were in the same
room,sinceitwouldmakeviralspreadsignificantlymoredifficult.
ThemodemvulnerabilitieswithRallysystemscanbemitigatedbybanningtheuseofmodems.
Ifregionalvoteprocessingcentersarestilldesirable,Rallycanstillbeusedinadisconnectedfash-
ion,withatraditionalcouriertransportingtheRallymachinesbacktoElectionCentralonceallof
theprecincts’voteshavebeencollected.
eScanrunsWindowsCE,anembeddedversionoftheWindowsoperatingsystem. Thismakes
itdifficultorimpossibleforanend-usertochangetheconfigurationofeScantoequivalentlycon-
figurea firewallto disableconnectionsto unnecessaryservices. When aneScan isin thefield, its
Ethernet interface already provides extensive capabilities to an attacker (see Section 6.1), and the
mitigationstakentoprotectagainstthoseattackswouldalsoapplyagainsttheseones. Itisunclear
thatthereisanyreasonforthisporttobeliveinthefieldatall.
In future versions of their software, Hart could design the installers for its various software
packagestolockdowntheWindowscomputer,configurethefirewall,anddeleteunnecessaryand
unused elements of the Windows system, making the above checklist an automatic aspect of the
softwareinstallation. ForRally’smodemissue,Hartcouldmodifythewaythatmodemsareused
suchthatdialingintotheRallysystemyieldsadirectconnectiontotheRallysoftwareratherthan
ageneral-purposenetworkconnectiontotheRallymachine(i.e.,Rally’sdesignshouldfollowthe
principleofleastprivilegetoreducethepowerofanattackerwhomightconnectviathemodem).
Status This issue was discovered by examination of the source code and other documents pro-
vided to the source code analysis team. Red Team analysis has determined that a number of un-
necessarynetworkservicesareenabledontheWindows2000machinesprovidedbyHart.TheRed
Team did not discover any vulnerabilities in these services, implying that the machines given by
Harthadallofthelatestsecuritypatchesinstalled. ThismightormightnotbethecasewithHart’s
customersusingthesesystems.
Microsoftcurrentlyonlyprovides“extendedsupport”toWindows2000,meaningtheyarepro-
vidingsecurityfixesbutarenotaddingnewfunctionality. Microsofthasstatedthatthisextended
support will end in 2010. Hart customers using Windows 2000 must migrate to newer versions
MicrosoftbeforeMicrosoftceasesmaintenanceofWindows2000securitypatches.
17Windows 2000 also has firewall functionality. See, e.g., http://homepages.wmich.edu/∼mchugha/
w2kfirewall.htm
§6.6Windows-relatedVulnerabilities 54
6. DetailedAnalysis
6.7 Cryptographic Key Management
HartmakesextensiveuseofcryptographytoprotectdataontheirMBBs. Inparticular,ballotdata
and CVR data are both cryptographically integrity protected. Although the Hart documentation
andsourceaswellastheSymantecreport[4]refertothisasa“signature”itisactuallyasymmetric
MessageAuthenticationCode(MAC),specificallyHMAC-SHA1[5]. Throughoutthisdocumentwe
willrefertothisasaMACratherthanasignature.
BecauseMACsareasymmetrictechnique,thegeneratorandtheverifierofaMACmustshare
aMACkey. Thisimpliesthatifthreeparties,Alice,Bob,andCarol,allwishtousethesameMAC
key,thenthereisnocryptographicwayforAlicetodistinguishaMACgeneratedbyBobfromone
generatedbyCarol. BobcanimpersonateCaroltoAlice,andindeedanymemberofthegroupcan
impersonateanyother. InHart’ssystem,asingleMACkeyisusedforeverymachine/deviceina
singleadministrativedomain,andsocompromiseofanyentityallowstheattackertoimpersonate
anyotherentity.
This key is distributed on eSlate Cryptographic Modules (eCMs) and is generated by the eCM
Manager application. The eCMs are USB-based Spyrus cryptographic tokens about the size of
a typical USB flash drive. The eCM manager uses the Windows cryptographic random number
generatortocreateasecret128-bitkeyandaGloballyUniqueIdentifier(GUID)identifyingthatkey.
ThekeyisthenstoredoneachindividualeCM.TheseeCMsarethenusedtoprogramtheJBCsand
eScansusingSERVO.
Itshouldbenotedthatstandardpracticefortheuseofcryptographicmodulesisthatthekeys
shouldbegeneratedonthemoduleandneverleaveit. Hartviolatesthispracticeintworespects,
firstbygeneratingthekeyoutsidethemoduleandsecondbyexportingthekeyfromthemodule.
Thisleadstoanumberofissues,asdetailedbelow.
Issue22:ThesamesymmetriceCMkeyisusedcounty-wide
In the Hart system, all message integrity is performed using a single county-wide MAC key.
Thiskeyismadeavailabletotheback-officeapplicationssuchasTallyandSERVObypluggingan
eCMcontainingthekeyintothemachinesrunningthem. ItismadeavailabletoJBCsandeScans
byprogrammingthemusingSERVO.ThiskeydoesnotappeartobeusedbyeSlates. Thispractice
impliesthatanattackerwhocompromisesanysinglekeyeddevice(mostlikelyaJBCoraneScan)
orhasaccesstoaneCManditsPINwillbeabletoforgeMBBsthatwillbeacceptedbyanyother
deviceinthesystem.
DetailedDescription Therearethreemajorwaystorecoverthesecretkey
• ExtractitfromtheeCMdirectly(whichprobablyrequirestheeCMPIN).
• ExtractitfromtheeCMmanager(seeIssue23).
• ExtractitfromaneScanorJBC(seeIssue24).
Once an attacker has the key, he can mount a number of attacks. The two most interesting are:
forging incorrect ballot information on MBBs that are consumed by eScans and JBC/eSlates, and
forgingMBBscontainingfakevotes(ormodifyingthevotesonrealMBBs)andsendingthemback
tothecentralofficefortallying.
NotethatalthoughHart’sproceduresindicatethatoneshouldnotreusekeysbetweenelections,
wedidnotfindanytechnicalcontrolspreventingit.
Prerequisites Avoterisunlikelytobeabletoaccessthesecretkey. Apollworkerwouldbeable
to extract it (see Issue 24) if he had temporary unattended access to an eScan or JBC. An election
officialresponsibleforrunningSERVOorTallycouldextractthekeydirectlyfromtheeCM.Though
aPINisrequiredtoaccesstheeCM,thisPINalsoallowsextractionoftheeCMsecretkey,because
extractionisnecessarytoexportittotheeScan/JBC.
§6.7CryptographicKeyManagement 55
6. DetailedAnalysis
TheattackerwouldalsoneedphysicalaccesstothetargetMBB.Itappearsthatthepollworkers
havesuchaccessatleastinsomeenvironmentsandthatelectionofficialsgenerallydo.
Impact An attacker who forged MBBs for consumption by the eScan/JBC would be able to im-
poseaballotofhischoice. Thismightallowhimtoaffectelectionresults,forinstancebyremoving
candidates,flippingtheorderofcandidates,orbreakingthebindingbetweencandidatesandop-
scanmarkingsorvoterecords. Itisunclearwhetherthiswouldbedetectedbythosefamiliarwith
thecorrectorderoftheelection.
An attacker who forged MBBs for consumption by Tally would be able to modify votes for
thatMBB.ThosevoteswouldbeacceptedbyTally. Thisattackwouldbedetectedifadirectaudit
(via SERVO) were performed or a manual paper recount—such as is done with the one percent
recount—wereperformed.
Mitigations Anumberofmitigationstothisthreatarepossible. Insomecasesforgedballotdata
could be detected by visually comparing the election interface to the expected UI. Forged MBBs
senttoTallycouldbedetectedbydoingacompleterecountbasedontheonboardmemoryofthe
JBCs, eSlates, and eScans. We do not know if this is standard practice. More extensive use of
paper-basedrecountswouldalsoaidindetectionofthistypeofattack.
Restrictingmasterkeystoasingleelection, asHart’sproceduresrequire(thoughthesoftware
does not appear to enforce) would reduce the risk level somewhat. More severe restrictions on
access to the secret keys, such as those proposed as mitigations to Issues 23 and 24, would make
thisattackmoredifficulttomount.
Movingfrom aMAC-basedsystemto adigitalsignature-based system withseparatekeys for
everydevicewouldsignificantlymitigatethisvulnerabilitybyseparatingtheabilitytoverifyfrom
the ability to sign. The effect would be that compromise of an eScan or JBC would no longer
allowforgeryofMBBsthatwouldbeacceptedbyothereScans/JBCs. Similarly,itwouldnotallow
forgery of MBBs that were accepted as from other eScans/JBCs, provided that Issue 27 were also
addressed.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedatool
thatwillchecksignaturesonMBBsusinganextractedkey. Wehavemadesomeinitialattemptsto
forgeMBBsbutdonotyethaveaworkingtool; duetotimeconstraintshavenotyetbeenableto
completethis.
Issue23:ECMkeysarestoredinsecurelyontheeCMmanager
TheeCMmanagercreatesakeyinsoftwareusingtheWindowsCryptGenRandomcall,which
isastandardWindowscallandappearstogeneratehighqualityrandomness. Thegeneratedkey
is128bitslong,whichisadequate. TheeCMofferstheusertheoptiontosavethemoduledatato
afile. Whenthatdataissaveditissaved“obfuscated,”whichmeansthateachbyteofthedatais
XOR’edwiththeletter‘x’. Anattackerwhocontrolsthecomputeronwhichthishasbeendonecan
triviallyextractthesecretkey.
Detailed Description An attacker who has access to the computer running eCM manager can
simplyfindthe.eCMfileandXORthecontentswith’x’torecoverthekey.
Prerequisites Theattackersimplyneedsaccesstothecomputer.
Impact OncetheattackerhasaccesstotheeCMkeyhecanmountanyoftheattacksdescribedin
Issue22.
§6.7CryptographicKeyManagement 56
6. DetailedAnalysis
Mitigations OnemitigationwouldsimplybenottostoretheMACkeytoafileatall. Thiswould
requireinitializingalltheeCMsatonceorhavingeCMswithdifferentkeys,whichwouldbenec-
essaryinanycaseifpublickeycryptographywerebeingused.
Anothermitigationwouldbetoreplacetheobfuscationwithencryptionunderauser-supplied
PIN or passphrase [24]. This would still potentially be susceptible to dictionary attacks if the at-
tacker also had access to an MBB protected with that key or if the encryption were done poorly.
However,thisisasignificantlymoredifficultattack,especiallyifagoodpassphraseischosen.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedatool
toextractthekeyfroman.eCMfileandhaveusedittoverifyanMBB.
Issue24:eCMkeysareextractedandstoredinsecurely
Although the keys are transported on the eCM, they are then copied (over the management
channel) to the JBC and the eScan, where they are stored on the onboard memory. Any attacker
whocontrolledeitherofthesedeviceswouldbeabletoextractthekeys.
Detailed Description SERVO is used to program MAC keys onto the eScans and JBCs via the
usualmanagementinterface(seeSections6.1and6.2).Thisinvolvespassingthecryptographickey
intheclearovertheEthernetorparallelcableusingtheNET_CMD_SET_SIGNING_KEYcommand,
whichstoresitunprotectedtheflashonthedevice. Itcanthenbeextractedinanumberofways,
including:
• ReadingthekeydirectlyoutofmemorywithMEM_READ.
• Loadingnewfirmwareontothedevicewhichallowskeyexport.
• Openingthecaseandreadingtheflashdirectly.
Wehavetestedthefirstoftheseapproaches.
Prerequisites Readingthekeydirectlyoutofmemorywouldrequireonlydirectphysicalaccess
tothedevice. Loadingnewfirmwarewouldrequiresimilaraccess,thoughiffirmwareweremade
more difficult to load (see Section 6.1), then this attack would be much harder. Opening the case
requiresextensivephysicalaccesstothemachine.
Impact All of these methods would allow raw access to the MAC key and enable the attacks
described in Issue 22. Note that even if asymmetric keys were used, it would still be possible to
forgeMBBsfromthecompromiseddevice.
Mitigations The first avenue of attack (reading the key directly out of memory) could be miti-
gatedbyremovingMEM_READaccesstothatportionofmemory. Loadingnewfirmwarecouldbe
mademoredifficult,asdescribedinSection6.1. Thecaseopeningattackissubstantiallyharderto
thwart,buttheuseofatamper-resistantcryptographicmodulesuchastheeCMontheeScansand
JBCswouldmakethisattacksignificantlymoredifficult.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavesuccessfullyused
acomputerunderourcontroltocommunicatewiththeeScanandextractthecryptographickeys.
Wehavenotattemptedtheothertwoavenuesofattack.
§6.7CryptographicKeyManagement 57
6. DetailedAnalysis
6.8 MBB Vote Storage
Both the eSlate and the eScan store their vote records in Mobile Ballot Boxes (MBBs), which are
generic PCMCIA memory cards. Each eScan has an MBB and each JBC has a single MBB which
serves all the eSlates under its control. Integrity for MBB data is intended to be provided by an
HMAC-based [5] message authentication code over some of the contents. As discussed in Sec-
tion6.7,theMACiskeyedwithakeycommontoalltheprecinctsinacounty.
Issue25:Voteordercanbedetermined
In order to preserve voter privacy, it is necessary that an attacker who has access to the MBB
not be able to determine how individual voters cast their votes. Although the votes recorded on
theMBBdonotcontaintheidentityofthevoter,itispossibletodetermineboththeorderinwhich
voteswerecast, andinthecaseoftheeSlate, theorderinwhichvoterswereissuedaccesscodes.
Because the order in which voters vote is fairly easy to determine, being able to determine the
order in which votes are cast provides a large amount of information about how any individual
votervotes,evenwithouttheMBBexplicitlycontainingvoteridentities.
DetailedDescription EachvoteisstoredonanMBBintwoways:
• The vote itself is stored in a cast vote record (CVR) which is stored in a randomly selected
locationinalargememoryblock.
• Anentryrepresentingthevoteisappendedtotheauditlog.
Thismethodhastwoproblems. ThefirstisthattherandomizationoftheCVRlocationispoorand
leaks a significant amount of sequence information. The second is that the in-sequence audit log
leakstheorderoftheCVRs.
CVR Randomization Before any votes are cast, the eScan or JBC allocates a large random
block on the MBB. It then selects a random point approximately in the middle of that block and
initialized two pointers, start and end with the start pointing at the selected point and end =
start+1. Whenever a CVR needs to be stored, the device selects a random 1-bit value and uses
thattoselectwhethertostoreatthebeginningorendofthelog. Ifthebeginning,theCVRisstored
justbeforestart. Iftheend,itisstoredatend. Theappropriatepointeristhenmovedawayfrom
thecenterofthebufferandtheprocessisrepeatedforanynewvote.
Giventhisalgorithm,iftheinitialvalueofstart(referredtohereasstart )isknown,itiseasyto
0
deriveapartialvoteorderingfortwoCVRsatpositionsp andp providedthateitherp <start
1 2 1 0
and p < start or p > start and p > start . In either case, the CVR closer to start must
2 0 1 0 2 0 0
havebeencastfirst. Evenforvotesondifferentsidesofstart itispossibletodeterminearough
0
orderingiftheirdistancesfromstart aresufficientlylarge.
0
The above algorithm requires determining start . This can be approximately determined by
0
taking the center of the used portion of the buffer. However, a more precise estimate may be
possible by observing that that algorithm for selecting start selects a random position from a
0
100byteregioncenteredonthemiddleofthebuffer. Theendofthefirstprependedvotemustfall
withinthisregion,asmostthebeginningofthefirstappendedvote.BecausetheCVRheaderalone
is17octetslong,thisnarrowsstart downtowithinatmost6values,andinfactlessbecausethe
0
CVRdatamustalsobestored. InonesampleelectionrunbytheRedTeam,thesmallestCVR(with
nowrite-ins)was32bytes.
Derandomization via Audit Log Although the audit log does not contain CVRs, each audit
entrycontainsaCRC-16oftheCVRdata. ThisallowstheattackertodetermineasmallsetofCVRs
(mostlikelyallcontainingthesamevotes)whichcorrespondtoagivenauditlogentry.Becausethe
auditlogentriesareinsequence,thisallowsanattackertocompletelyrecoverthesequenceofcast
§6.8MBBVoteStorage 58
6. DetailedAnalysis
votes. Inaddition,whenvotersvotebyeSlate,thevoteraccesscodeappearsintheauditlogand
itisthereforepossibletodeterminehowvotersvotedbytheorderinwhichtheywereauthorized,
particularlyifvoterskeeptheiraccesscodeprintouts,whichareproducedbytheJBC.
TheSERVODeviceAuditLogreportalsoappearstodisplaytheauditlogdata,containingthe
CRCandthevotercode,whichmayallowmappingofvoterstovotedata. Whetherthisispossible
dependsonwhethertheCRCscanbecompletelypredictedfromthevoter’schoices,withoutaccess
totheCVRlogdata. Wehavenotdeterminedwhetherthatisthecase.
Prerequisites Inordertoexploitthisissue, anattackerwouldneedreadaccesstoanMBBorto
thecontentsoftheMBB.BecauseMBBsarenotencrypted,noaccesstokeyingmaterialisrequired.
Election officials are likely to have access to MBBs or MBB contents. Whether poll workers have
accesstoMBBcontentsdependsonwhethertheMBBsaresealedintotheeScan/JBCatthecentral
warehouse and then shipped back to the warehouse inside the JBC or whether they are removed
priortoshipping. Ifthelatter,thenpollworkerswouldalsobeabletomountthisattack.
Poll workers could also access the CVR and audit logs internal to the eSlate, JBC, and eScan
usingthemanagementinterfaces;seeSection6.1.
If the SERVOaudit logs can be mappedback to vote results, thenthis attack may be practical
withonlypublicinformation.
Impact The result of this attack is that anyone who has access to the contents of an MBB can
determine which votes were cast in which order. If the attacker also has access to the order in
whichvotersenteredthepollingplace,theorderinwhichtheycasttheirvotes,oraccesstovoters’
accesscodeprintouts,thisleaksasignificantamountofinformationabouthowindividualvoters
voted.
Mitigations Pollworkerscanbeblockedfromexploitingthisissuebyrestrictingtheiraccessto
MBBs and to the network/management interfaces on polling place devices. In particular, if the
MBB is sealed in the JBC/eSlate whenever the unit is in the poll worker’s possession, then this
attackbecomesmoredifficulttomountwithoutbeingdetected. FutureversionsofHartsoftware
could routinely encrypting the MBB contents, which would also block poll worker attacks. The
contentscouldbeencryptedunderapublickeyownedbyElectionCentral,thuspreventingleakage
ofthekeybydevicecompromise.
BecauseMBBCVRinformationisroutinelystoredbytheback-endelectionsystems,itismore
difficulttorestrictaccessbyelectionofficials.
MerelyimprovingtheCVRrandomizationalgorithmdoesnotsignificantlymitigatethisissue
because the CVRs can still be derandomized by examining the audit log. Future versions of the
Hartsoftwarecouldremovetheauditlogvectorbyeitherfurtherrestrictingaccesstotheauditlog
ormakingitsignificantlymoredifficulttotieauditlogentriestoCVRs,mostlikelybyremovingthe
CRC-16hashoftheCVRfromtheauditlog. WehavenotdeterminedwhethertheCRC-16isused
byanyofHart’sauditingmechanisms,butasit’snotcryptographicallystrong,itisonlyusefulas
acheckfordatacorruption,notmaliciouschanges.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedtoolsto
reconstructthevoteorderandusedthemwithanMBBimageprovidedbytheredteamtoextract
thevoteorderinagivenelection.Wealsoverifiedthatthefirstvote(representinglocationofstart )
0
wasintheexpectedlocation.
Issue26:MBBisnotprotectedduringvoting
Inordertoprotectagainsttampering,Hart’sMBBsarecryptographicallyprotectedusingHMAC[5].18
Intheory,thisprotectstherelevantstructuresontheMBBfromtamperingbyanyonewhodoesnot
18Thematerialprovidedtousreferstothisasa“signature”butit’sactuallyasymmetricmessageauthenticationcode
(MAC).
§6.8MBBVoteStorage 59
6. DetailedAnalysis
have the relevant MAC key. However, the HMAC is not present on the vote data on MBB dur-
ingtheelection,butiscomputedandrecordedeitherwhentheelectionislockedtoaccommodate
a pause in early voting or when the election is closed. Therefore, it may be possible to remove,
modify,andreinserttheMBBwithoutbeingdetected.
DetailedDescription TheeScanandJBCbothmaintainvotedataintwolocations:
• Ininternalstaticstorage.
• OntheMBB.
Asindicatedabove,eachlocationhastwodatastructures,theCVRdataandtheauditlog.
ThisdataismaintainedunprotecteduptothepointwhereMBBisclosedorlocked.Theinternal
memorydoesnotappeartobeaccessiblewithoutopeningthecaseoftheJBCoreScan. Assessing
thedifficultyofthisisoutsidethescopeofthiswork. TheMBB,however,isreadilyaccessible,but
tampersealsareintendedtodetectremoval.
IfanMBBisremoved,modified,andreinserted,theresultisthattheinternalandexternaldata
structureswillnotmatch.However,theJBCandeScandonotappeartoverifythattheinternaland
externalauditandCVRlogsmatchandthereforevotingproceedsasnormal.
JBCs and eScans both run a watchdog task that triggers an audit log message and halts the
device if the MBB is removed. The attacker can power down the device, remove, modify, and
reinserttheMBB,thenpowerthedevicebackup. TherebootwillcausetheJBC,atleast,tocheck
that the inserted MBB is the same as the one it originally read the election information from, but
thischeckdoesnotappeartoextendtocomparingtheinternalCVRandauditlogstothosestored
ontheMBB.
Whenitistimeto“sign”theMBB,thefollowingstepsareperformed:
1. GenerateanunkeyedhashfortheinternalCVRdataandlogittoboththeinternalandexter-
nalauditlogs.
2. Generated a keyed MAC (HMAC-SHA1) of the external CVR data and log it to both audit
logs.
3. Generateanunkeyedhashoftheinternalauditlogandlogittobothauditlogs.
4. GenerateakeyedMAC(HMAC-SHA1)oftheexternalauditlogandlogittobothauditlogs.
WhentheMBBisverifiedbyTally,itverifiestheMACsbutdoesnothaveaccesstotheinternal
auditorCVRdataanddoesnotattempttocomparethemtothedataontheMBB.
Prerequisites Themajorobstaclestothisattackareobtainingaccesstothedevicelongenoughto
remove and reinsert the MBB and the tamper sealing on the MBB insertion point. A poll worker
would have appropriate access to the devices though a voter would not. See Section 3.5 for a
discussiononthelimitationsoftampersealing.
Impact AnattackerwhowasabletoobtainaccesstotheMBBwouldbeabletochangeexisting
votesonitandthenreinsertitintotheJBCoreScanandhavethatunitproceedasnormal,includ-
ing inserting the MAC. This MBB would have votes partly of the attacker’s choice and would be
acceptedbythecentraltabulationsystem.
Mitigations Severalpossibilitiesformitigatingthisattackexist.
Electionadministratorscouldverifytheinternalauditlogs(collectedviaSERVO)againsteach
MBB to verify that they match. We have no information as to whether this is currently routinely
done,butitcouldbedonewiththecurrentHartsoftware.
InfutureversionsofHartsoftware,theJBC/eScancouldcheckoneachMBBinsertionthatthe
contentsoftheMBBmatchtheinternalmemoryandfailiftheydidnot.Oneminordifficultyhereis
§6.8MBBVoteStorage 60
6. DetailedAnalysis
thattherandomizationoftheCVRsontheMBBandtheinternalmemoryisnotthesame;19however,
thiscouldbefixedbylexicallysortingtheCVRspriortoverification.
Status ThisissuewasdiscoveredbytheRedTeamagainstalivesystemandverifiedbyreference
tothesourcecode.
Issue27:HandlingofprecinctIDsinCVRs
EachCVRcontainsaprecinctIDfieldindicatingtheprecinctforwhichtheCVRwasvoted.This
allowsasingleMBBtocontainconsolidatedrecordsforanumberofdifferentprecincts. Itmaybe
possibletogenerateanMBBwhichcontainsvotesforunauthorizedprecincts. Inaddition,itmay
be possible for an attacker who has access to the election database on Tally to silently suppress
votes.
DetailedDescription EachCVRinanMBBisanindependentrecord,withadescriptiveheader
containingmeta-informationaboutthevotesintheCVR.Thismeta-informationincludes:
• A16-bitballottypeidentifier
• A16-bitprecincttypeidentifier
• A16-bitpartyidentifier
In theory, any given piece of equipment is only relevant to a small number (most commonly
one) of precincts, and under ordinary circumstances when Tally converts votes into the internal
storageitreferstotheelectiondatabasetodeterminewhatprecinctsandpartiesareauthorizedfor
agivenMBB.Itthencyclesthrougheachvalidprecinct/partycombinationinordertocountvotes.
ThispreventsanMBBfromprecinctX frominjectingvotesinprecinctY. However,ithastheside
effectthatitispossibleforvotestogetignoredifthedatabaseonTallyisinconsistentwiththeMBB.
The one exception to this rule appears to be that SERVO is allowed to create recount MBBs,
which contain records from multiple polling places. If Tally thinks it is processing such an MBB,
itexecutestallyCvrLogForServo()whichappearstoiteratethroughallpossibleprecinctsand
parties. TallymakesthisdecisionbasedontheMBBheader,whichisundercontroloftheprecinct
polling devices. Thus, it may be possible for an attacker to forge a SERVO MBB which contains
arbitraryprecinctIDs.
Prerequisites MountingasuppressionattackwouldrequireaccesstotheTallydatabaseinorder
tomodifytheprecinctsassignedtoagivenpollingplace. Thisiselectionworkerstyleaccess.
MountingthisattackrequirestheabilitytoforgeMBBs. Thiscouldeitherbedonebyextracting
themasterMACkey(seeSection6.7)orbyusingtheattackdescribedinIssue26. Anattackerwho
hadarrangedtoreplacethefirmwareonaneScanorJBCcouldalsomountthisattack.
In any case, the attacker would need access to the MBB, such as may be available to a poll
worker.
Impact Theimpactofasuppressionattackwouldbetoallowsomeonewithtemporaryaccessto
theelectiondatabasetosuppressvotesfromagivenprecinct/pollingplacepair.
The impact of an injection attack would be to allow an attacker who had partial control of
equipmentinoneprecincttoaffecttheoutcomeofvotinginanotherprecinctbyinjectinghisvotes
intothatprecinct’sdata.
19Thisisalsosuboptimalbecauseitleaksadditionalorderinginformation.
§6.8MBBVoteStorage 61
6. DetailedAnalysis
Mitigations One might attempt to mitigate this issue in a number of ways. First, one might
attempt to restrict physical access to the MBB, perhaps with extensive tamper sealing, thus pre-
ventingitfrombeingrewritten. Thesecuritylevelofthisdefensedependsontheattackvector. If
theattackerwantstowritetheMBBwithhisowncomputer, thisprovidessomelevelofsecurity.
If the attacker has compromised the JBC/eScan, then he can arbitrarily rewrite the MBB without
removingitfromtheJBC/eScan.
Auditing the MBB contents against JBC/eScan internal memory might also detect this attack
if the attacker has only altered the MBB. However, it will not detect the attack if the attacker has
compromisedtheJBCoreScanandthereforecanmodifytheinternalmemory.
Finally, one might attempt to enforce this on the Tally side. This could be done in two ways.
First, one could compare the number of recorded votes in each precinct against the number of
voters signed into the precinct and flag discrepancies. Second, one could keep records of which
MBBswereassignedtoeachprecinctandflageventswhereprecinctswhichshouldnotappearon
agivenMBBinfactdo. However,thismightinterferewithconsolidationfeaturesandthecreation
ofrecountMBBsbySERVO.
InfutureversionsofHartsoftware,theserecordscouldnaturallybestoredintheMBBheader.
However,becausetheheaderisintegrityprotectedwithakeyavailabletotheJBC/eScan,thiswill
notdefendagainstanattackerwhohascompromisedthemwithoutastrongercryptographickey
infrastructure(seeSection6.7).
Status This issue was discovered by examination of the source code. The MBB-reading code is
extremelycomplicatedandmayincludesanitychecksthatpreventeitheroftheseattacks,although
wedidnotseeanysuchchecks. Testingonarealsystemwouldberequiredtoconfirmorrejectthis
issue.
Issue28:UserscanreadunclosedMBBsorMBBswithinvalidMACs
AlthoughthedataontheMBBisintegrityprotectedwithHMAC,thisHMACisonlyapplied
when the election is closed. When Tally is asked to read an MBB which isn’t closed or when the
cryptographic check fails it shows a dialog allowing the user to accept the MBB anyway. This
providesapotentialwaytobypasstheMACcheck.
DetailedDescription WhenTallyreadsinanMBBitcheckstheMACvalue. Basedonthedoc-
umentation, if the MAC check fails, it complains that the MBB is corrupt and allows the user to
acceptitanyway. Similarly,iftheelectionisnotclosed(andthereforethereisnoMAC),Tallypops
up a dialog giving the user the option to accept the MBB anyway. This provides an easier attack
target for an attacker who has possession of an MBB but cannot forge the MAC: they send in the
MBB with a bogus MAC or simply don’t close the election or strip off the closure information in
the audit log. There is no guarantee that the MBB will be accepted, but experience in other envi-
ronments,whereusersareaskedtoenforcesecurityrules[29,34],suggeststhattherewillbeahigh
rateofusersacceptinginvalidMBBs.
NotethattheconcernherewithrespecttoTallyusersisinattention,notmalice,sinceasophis-
ticatedTallyusercanforgeMBBs.
Prerequisites ToexploitthisanattackerwouldneedtobeabletoeithermodifyanexistingMBB
orsubstitute/addhisown. Thisprobablymeansapollworkerorelectionofficial.
Impact Thisattackwouldpotentiallyallowanattackertoinjectfalsevotes.
Mitigations OnepotentialmitigationforfutureHartsoftwareversionswouldbetosimplyrefuse
toeveracceptun-closedMBBs. However,thiswouldhavetheeffectthatifpollworkersmakeany
mistakes, perhaps forgetting to close a precinct before shipping off the MBB, recovery would be
difficult.
§6.8MBBVoteStorage 62
6. DetailedAnalysis
ThiscouldperhapsbeaddressedwithaseparatetoolthatHartwouldsupplytoelectionadmin-
istrators which could be used to sign unclosed MBBs. This tool would require supervisor access
and produce extensivepaper logging. Such MBBsshould perhapsbe flaggedfor ahigher proba-
bilityofpost-electioninvestigationsincetheyaremorelikelytobecorrupt.
Status This issue was discovered in the source code and verified in the documentation but we
havenottesteditourselves.
Issue29:Theprotectivecounterissubjecttotampering
A voting machine are required to keep a private protective counter that is incremented with
eachvotecastandthatreflectsthetotalnumberofvotesevercastonthatmachine. However, on
the JBC, eSlate, and eScan, the private counter can be tampered with by software running on the
machineandthroughthemanagementinterface.
Detailed Description Each of the JBC, eSlate, and eScan keeps the private counter in memory
asa32-bitinteger(alongwitha16-bitCRC,whichisineffectiveatdetectingtampering). Oneach
ofthesedevices,thecounteriskeptstoredinflashmemory. TheeScanusesits“estoremanager,”
which keeps two copies at location STORE_VOTE_COUNTERS. This flash copy appears to be up-
datedonlywhenthelogsarecleared;thecurrentprivatecounteristhesumofthecounterinflash
andthevotesrecordedintheauditlog. TheJBCandeSlatestoretwocopiesinterleaveddirectlyin
flash,atADDR_PRIVATE_COUNTER,i.e.,0x0000c000.
SincethesoftwareontheJBC,eSlate,andeScancanmodifythestoredprivatecountersdirectly,
anymalicioussoftwareloadedontothesedevicescanmodifytheprotectivecounter. What’smore,
itispossibletousethemanagementinterfacetomodifytheprotectivecounterwithoutreplacing
thesoftware. Forexample,theJBCprocessesaNET_CMD_CLR_PRIVATE_CNTmessagethatresets
the private counter. In addition, an attacker can rewrite the private counter directly using the
MEM_WRITEoptiontotheNET_CMD_MEMORYmessage.
Prerequisites Toexploitthisanattackerwouldneedeithertoreplacethesoftwarerunningona
JBC,eSlate,oreScan,ortobeabletoconnecttothedevice’smanagementinterface.
Impact Thisattackwouldallowtheattackertomodifytheprotectivecounter.
Mitigations Implementingacounterthatcanbeincrementedbutnotresetorotherwisemodified
requiresspecializedhardwaresupport,whichHartwouldhavetoaddtotheJBC,eSlate,andeScan.
Status Thisissuewasdiscoveredinthesourcecode,butwehavenotattemptedtoverifyit.
Issue30:IftwoMBBshavethesameID,Tallyonlyreadsthefirstone
TallymaintainsadatabasewhichstoreseachMBB.IfanattackercanloadabogusMBBthathas
thesameIDasarealone,beforethatrealMBBwasloaded,therealMBBwillberejectedbyTally.
DetailedDescription EveryMBBhasanidentifierthatshouldbeuniquewithinthecounty. Be-
fore a new MBB is inserted into the database, the database is first queried to see if the MBB ID is
already present. MBBValidateCls::InsertSubLog is responsible for this process, ultimately
callingintoMbbDBInfoCls::AlreadyProcessedwhichdoestheSQLquery.
NowhereintheprocessisthereanychecktomakesurethatthegivenMBBIDistheproperID
foragivenprecinct. Asaresult,anattackercouldproduceamaliciousMBBforatargetprecinct,
perhapsasaresultofcompromisingaRallyserveroraJBC,andthenTallywouldloadthatMBB.
§6.8MBBVoteStorage 63
6. DetailedAnalysis
So long as the attacker’s malicious MBB goes first, it will prevent the legitimate MBB from being
loaded.
Asuitableerrormessagewillbelogged,butelectionofficialswouldhavenoeasywaytoresolve
the errorcondition. Even thoughthe log indicatesthe identifierof the conflictingMBB, Tally has
noMBBremovalmechanismavailablefromitsuserinterface.
Impact This is an example of a “denial of service” attack, which will slow down the tallying
process, possibly requiring assistance from the vendor in order to resolve the issue. This could
delayelectionreportingforseveraldays.
Prerequisites AnattackerneedstheabilitytointroducebogusMBBsintotheRally/Tallysystem.
This could be accomplished through attacks against eScan or JBC systems, in the polling place,
through attacks against Rally, perhaps via modem, or through attacks against SERVO, if it were
usedtoextractMBBsdirectlyfromthevotingmachines.
AnattackeralsoneedstoknowtheMBBidentifiersforanyparticularprecinctsthathewishes
to suppress. BOSS, which writes out MBBs, generates these identifiers sequentially as it writes
thecards, startingoutfromoneandworkingitswayup. Thismeansthatanattackercansimply
use small numbers for MBBs to perform the attack, if he has no particular preference for which
precincts he wishes to suppress. If he wants to suppress a particular precinct, he would need to
knowtheexactorderinwhichtheMBBsarewrittenbyBOSS.
Mitigations This attack must be performed after the ability to inject a bogus MBB has been ac-
complished.Assuch,themitigationswhichmightprotectagainstthoseattackswouldalsomitigate
againstthisattack.
Shouldanattackofthisformsucceed,noactualvotedatawouldbelost. Avendortechnician
couldpotentiallyissuerawSQLcommandstocleanupthedatabase. Likewise,VVPATprintouts
andpaperballotscouldbetabulatedbyhandfortheaffectedprecincts.
Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenotattemptedto
verifyitwitharealTallyinstallation.
6.9 Rally/Tally’s Use of TLS/SSL
Whencommunicatingoveramodem(seeSection6.6), RallyandTallyencrypttheirconversation
usingOpenSSL(theSecureSocketsLibrary),which,whenusedproperly,couldbothpreventtam-
peringandeavesdroppingonthecommunication.
Issue31:RallyandTallyuseanoldversionofOpenSSLwithknownbugs.
Rally/TallyuseOpenSSLversion0.9.7d, circaMarch2004. ThisopensRallyandTallyservers
toattacksagainstdocumentedOpenSSLbugs.
Background Whenyouvisitasecurewebsite(i.e.,anywebsitewhoseURLbeginswith“https”)
thewebsiteandyourbrowsercommunicatewiththeTransportLayerSecurity(TLS)protocol[8],
oftenreferredtobyitsearliername,theSecureSocketsLayer(SSL,whichwewillusehere). SSLis
mostcommonlyusedforsecurewebpages,butthisgeneral-purposetechnologyandcanbeused
foravarietyofothertasks,asitisused,forexample,byRallyandTally.
SSLuseencryptiontechnologiestoprovideavarietyofusefulproperties:
Integrity SSLusesmessageauthenticationcodes(MACs)toensurethatthedatareceivedbyone
side of the conversation is precisely the same data that was sent by the other side of the
conversation.
§6.9Rally/Tally’sUseofTLS/SSL 64
6. DetailedAnalysis
Privacy SSL provides optional encryption, using a variety of different algorithms, to ensure that
eavesdropperscannotlearntheplaintextoftheconversation.
Authentication SSLcanvalidatethatthepartyontheothersidehasaspecificidentity.Thisisdone
usingcertificates,whicharedigitallysignedstatementsmadebyacertificateauthority(CA)who
is trusted by both parties. When the two parties start their SSL conversation, they will use
cryptographic techniques to prove that they are the holder of a particular secret key which
corresponds to a public key. Likewise, they will prove that the CA agrees that the public
keycorrespondstotheirname,organization,emailaddress,orotheridentifyinginformation
specifiedinthecertificate.
OpenSSLisafree,open-sourceimplementationoftheSSLprotocolthatiswidelyused,partic-
ularly by the Apache web server. Hart InterCivic has adopted OpenSSL to use for protecting the
conversationsbetweenRallyandTallywhentheyareperformedoveramodem.
Detailed Description One of the supported configurations for Rally and Tally is to create “re-
gional” centers, where poll workers would bring their MBBs at the end of the day. The regional
centers would have PCs running Rally, which would be used to collect the MBBs together. Tally,
running at Election Central, would make a phone call to each regional center, connecting to the
computerrunningRally,andwouldthendownloadtheMBBs. Thisconnectionisprotectedbythe
useofSSLandbytheuseofausernameandpassword.
Alternately,RallymachinesmaybeinstalledalongsideTallymachinesatElectionCentral. This
wouldallowtheretobemultiple“processingdesks”tohandleincomingMBBs,speedingthepro-
cess. In this configuration, the Rally and Tally machines are connected by a local area network
(i.e., standard Ethernet), which Tally uses to copy the MBBs from each Rally machine. SSL and
username/passwordsarealsousedinthisconfiguration.
WhilewewerenotgiventhesourcecodetotheversionofOpenSSLusedbyHartInterCivic,we
weregiventheDLLs(compiledbinarylibraries)thatcontainOpenSSL.ByexaminingtheDLLs,we
determined that Hart is using OpenSSL 0.9.7d, which was released in March 2004. The OpenSSL
maintainers’ vulnerabilities web page20 documents seven known issues that apply to OpenSSL
0.9.7d. These issues include one attack which can be used to crash the remote system and an-
other which allows a buffer overflow attack. The buffer overflow attack relies on a flaw within
SSL_get_shared_ciphers(),whichispresentlyunusedbyRallyandTally. Theotherrelevant
OpenSSLflawsallowanattackertocrashtheprogramortoinduceaninfiniteloop(renderingthe
programunresponsive).
WhenRallyandTallyareusedwithmodemstoconnectthem(seeSection6.6),anattackermay
alsoconnecttotheRallymachineviamodemandcanthenusetheseknownOpenSSLvulnerability
toattackRally.
Prerequisites Rallyand Tallyhavetwo usemodes: communicatingovermodems orcommuni-
cating over a network21. This attack mode functions in any context where an attacker can access
thenetworktowhichTallyorRallyisconnected—inparticular,ifRallyisconnectedtoamodem.
If, forwhateverreason, aRallysystemwasconnectedviaitsnetworkporttotheInternetthis
vulnerabilitywouldalsobeexploitablebyaremoteattackerovertheInternet.
Impact When Rally and Tally are used with modems, an attacker can cause an arbitrary Rally
system to crash or become unresponsive, simply by dialing its phone number. Such an attack
couldbeusedtoslowdownorinconvenienceelectionofficials.
Mitigations One obvious mitigation to the risks posed by outsiders connecting to Rally/Tally
modemsistoavoidanyuseofmodems. Rallyserverscanoperateoffline,collectingvoteswithout
20http://www.openssl.org/news/vulnerabilities.html
21Theuseprocedures[21]specifyanintranet,butthereisnotechnicalreasonitcouldnotbetheInternet
§6.9Rally/Tally’sUseofTLS/SSL 65
6. DetailedAnalysis
transmittingthemtoTally.Onceallthevoteshavebeencollected,theRallyservercanbephysically
transportedfromtheregionalvotecollectionfacilitytoElectionCentral.
Another possible mitigation is to train election officials how to respond to these attacks (e.g.,
how to kill and restart the Rally application) or to switch to physical transportation of the Rally
machinesifthemodemsarenotworkingproperlyorareunderattack.
Of course, future software releases from Hart could be engineered to address these concerns,
mostlikelybyupgradingtothecurrentversionofOpenSSL(andfollowingsubsequentOpenSSL
upgradesastheybecomeavailable).
Status Thisissuewasdiscoveredby examination ofthesourcecodeandotherfiles provided to
thesourcecodeanalysisteam. IthasnotbeendirectlyverifiedagainstRallyandTallyservers.
Issue32:RallyandTally,whenpresentedwithanunknowncertificate,willpresent
theunauthenticatednameandorganizationtotheuserforverification.
DetailedDescription WithRallyandTally,thereisnocertificateauthority(CA)inuse. Instead,
Rally and Tally have a memory of the certificate used “last time” and will present a dialog box
to the user if the certificate changes. This dialog box presents the name, organization, city, state,
and country from the remote machine’s certificate. However, because no CA was used to sign
the certificate, its contents may be set arbitrarily by an attacker. If a user is convinced to press
the “okay” button to this dialog (on either side: Rally or Tally), then an attacker can potentially
impersonateonesidetotheother.
Once the SSL connection is initialized, Tally authenticates itself to Rally by presenting a user-
name and password inside the SSL connection. This username and password are configured in
advance, before the Rally machines are deployed. This process is analogous, in some fashion, to
how users authenticate themselves to secure commerce web sites, but it’s not very good for use
whentwocomputersareconnectingtooneanotheronaregularbasis. Theuseofhuman-chosen
passwordsisanunnecessaryopportunityforpoorpasswordstobechosen.
AsidefromtheSSLcertificateauthentication,thereisnoothermechanismforRallytoauthenti-
cateitselftoTally. ThismeansthatanattackerwhocanintercepttheconnectionbetweenRallyand
Tally, perhaps by climbing a telephone pole and clipping into the appropriate wires, may be able
toimpersonateaRallyservertoTally. Theonlymechanismpreventingsuchanattackisthedialog
boxthatwillappearontheTallymachineaskingtheusertoapproveofthenewcertificate(which,
asdescribedabove,canpresentseeminglycorrectinformation).
Prerequisites Rally and Tally must be configured to communicate over a modem or other net-
work connection. The user of Rally or Tally (whichever machine is being attacked) must press
okaytoadialogboxthat,byallappearances,ispresentinggoodinformation. Inthecaseofattacks
against Rally, the attacker must know the phone number of Rally and must know the username
andpassword. InthecaseofattacksagainstTally,theattackermustbeabletointerceptthephone
callfromTallytoRally.
If,forwhateverreason,aRallyorTallysystemwasconnectedviaitsnetworkporttotheInter-
net,thenthisvulnerabilitywouldalsobeexploitablebyaremoteattackerovertheInternet.
Impact If modems are used to connect Rally and Tally and if the usernames and passwords are
chosenpoorly,anattackerwillbeabletoconnecttoRallyanddownloadallofthevotesstoredin
it. Likewise,ifanattackerisabletointercepttheoutgoingphonecallsfromElectionCentral(e.g.,
by climbing a nearby telephone pole and attaching alligator clips to the appropriate wires), then
theattackerwouldbeabletoinserthisowncomputerinplaceofthetrueRallymachine,feeding
backarbitraryvoteinformationtotheTallyserver.
§6.9Rally/Tally’sUseofTLS/SSL 66
6. DetailedAnalysis
Mitigations OnepossiblemitigationistoensurethatallRallyandTallysystemsare“preloaded”
withthenecessarycryptographiccertificates. ThiscanbeperformedintheElectionCentralware-
house, prior to deploying the Rally systems to the field. This would allow for poll workers and
electionofficialstobeinstructed,underallcircumstance,torejectrequeststhatRallyorTallymight
pop-uponthescreentoapproveanyneworpreviouslyunseencertificate,regardlessofthecertifi-
catecontentspresentedon-screen.
The use of strong usernames and passwords also mitigates against this threat, as an attacker
who does not and cannot guess the username and password will be unable to make any further
progress attacking Rally, but would remain unhindered in presenting a false Rally to spoof Tally.
HemightbeabletoleveragethatattacktocapturetheTallypasswordandthenimpersonateTally
toRally.
TheusernameandpasswordchosenwithinRallyandTallytoauthenticatethesystemstoone
anothermustbecarefullychosentohaveahighdegreeofrandomness. Anumberofcommercial
and free software tools are available that can generate suitable passwords. Likewise, passwords
couldbeselectedbyrollingdice. EveryRallymachinecanandshouldhaveadifferentusername
andpassword.
ThisissuecouldalsobemitigatedaspartofabroaderredesignofHart’skeymanagementar-
chitecture(seeSection6.7),inwhichkeysaremanagedcentrallyandlesssubjecttouserdiscretion.
Status Thisissuewasdiscoveredbyexaminationofthesourcecodeprovidedtothecodeanalysis
teamaswellasreadingtheRallyandTallyusermanuals[18,20]. Ithasnotbeendirectlyverified
againstRallyandTallyservers.
6.10 Verified Ballot Option Issues
AsrequiredbyCalifornialaw,Hart’sDREsystemhasaVoterVerifiedPaperAuditTrail(VVPAT),
whichHartcallstheVerifiedBallotOption(VBO),whichusestheVBOx,areel-to-reelprinterwhich
attaches to the eSlate. Once the voter has indicated that he wishes to cast his ballot, the ballot
information is printed by the VBOx and presented to the user. The voter can then indicate either
acceptanceorrejectionoftheballot.
If the voter accepts the ballot, the VBOx prints an “BALLOT ACCEPTED” message and a bar
code and then scrolls to a blank page. If the voter rejects the ballot, the VBOx prints a “BALLOT
REJECTED”messageandtheeSlateallowstheusertoadjusthisvote.
TheVBOxisintendedtoprovideevidenceofthevoter’sintentinawaythatisnotamenableto
tamperingbycompromisedsoftwareontheDRE.However,wefoundanumberofimplementation
decisions that might allow an attacker who controlled the eSlate to construct bogus paper audit
trails.
Issue33:VBOxprintingandscrollingiscontrolledbytheeSlate
TheVBOxitselfisanextremelysimpleprinter.ThecommandsitreceivesfromtheeSlatejusttell
ittoprintarbitrarydatatothepaperand/orscrollthepaperforward. Thisenablesacompromised
eSlatetoexertalargeamountofcontrolovertheVBOx.
Detailed Description The eSlate communicates with the VBOx by sending it a variety of com-
mands. The two most relevant here are Print and FormFeed. These allow the eSlate to print
arbitrarybytesandtoscrollthepaperforward. However,thegeneralflexibilityofferedhereplus
thefactthatthereisnoexternalusercontrolontheVBOx, allowacompromisedeSlateflexibility
tomountattacks.
Thesimplestsuchattackwouldbeforgingvotes.AsdescribedinIssue8,acompromisedeSlate
cansendvotestotheJBCevenifnoacceptablevotercodehasbeenenteredintotheeSlate. How-
ever, this potentially produces an inconsistency between the recorded votes and the VVPAT. Be-
§6.10VerifiedBallotOptionIssues 67
6. DetailedAnalysis
causetheeSlatecontrolstheVVPAT,itcansimplyissueitsowninstructionstotheVVPATtoprint
thevotealongwiththeacceptedbanner.
Other attacks are also possible, such as waiting for a voter to confirm his vote, then printing
“BALLOTREJECTED”,printinganew,corruptvotewiththe“BALLOTACCEPTED”bannerand
thenscrollingtoablankpage.
YetanotherpossibilitywouldbetosimulateVBOxfailures(e.g.,formfeedthroughallthepaper)
toforcethepollingplacetofallbacktoelectroniconlyvoting. Wedonotknowhowpollingplaces
dealwithfailuresoftheVVPAT.
Prerequisites Toexploitthisissue,anattackerwouldneedtocontroltheeSlateorsomehowgain
control of the serial connection between the eSlate and the VBOx. There are two points of attack
here: theconnectionbetweentheeSlatestandandtheVBOx, whichappearstobeasimpleserial
cable, and the contacts in the eSlate stand which mate to contacts on the bottom of the eSlate. It
is not clear that either are well sealed and the eSlate stand contacts are voter accessible, though
clumsilynonstandardtoaccess.
Impact An attacker can maintain consistency between tampered electronic vote records and a
tamperedVVPAT,thusdecreasingtheriskofdetection.
Mitigations ApartialmitigationwouldbetoprovidetheVBOxwithseparatehardwarecontrols
so that the voter had to operate the VBOx in order to accept their ballot. This would prevent
attacks where the eSlate ran off incorrect ballots. One approach that has been suggested in the
past but would require somewhat extensive re-engineering would be to have the VBOx have a
mechanicalswitchthatwhendepressedcutofftheballotanddroppeditintoahopper,thusboth
requiring manual engagement in the voting process and providing some measure of privacy for
thesequenceofvotes(seeIssue35.)
Status Thisissuewasdiscoveredthroughexaminationofthesourcecode. Ithasnotbeentested
ontheVBOxPrinterhardware,whichmaynotinfactsupportarewindfeature.
Issue34:TheVBOxcodeindicatesareversefunction
A VBOx printer is connected to an eSlate device, which issues it commands to print data. It
appears to be possible for the VBOx printer to be run backwards, thereby overwriting previous
ballot records. While there are not commands implemented in the source code to perform this
action,ifanattackerweretogaincontrolofaVBOxPrinter(forexampleviaacompromisedeSlate)
theymightbeabletocausetheVBOxPrintertorunbackwards.
Detailed Description When a VBOx Printer receives a command from an eSlate, code on the
printerisexecutedthatinstructsthehardwaretoperformtheprinting. WithinthisVBOxPrinter
sourcecode,wefoundseveralcommentedoutlinesofcodethatseemedtoindicateitwaspossible
toinstructtheprinterhardwaretoruninreverse. Soundernormaloperatingconditions,running
inreversewouldnotoccur. However,ifanattackerwereabletotakecontrolofaVBOxPrinter,e.g.
byexploitingabufferoverflow,itseemshecouldinstructtheprinterhardwaretorunbackwards.
Prerequisites An attacker who is able to execute code on the VBOx printer could be able cause
theVBOxPrintertorunbackwards.
Impact RunningtheVBOxPrinterbackwardswouldoverwritepreviouslywrittenballotrecords,
therebycorruptingasourceofdataforperformingmanualrecountsofballots.Itwouldalsoenable
anobservertoseepreviously-castvotes,violatingtheprivacyofthosevoters.
§6.10VerifiedBallotOptionIssues 68
6. DetailedAnalysis
Mitigations The natural mitigation for this issue is to disable backwards feeding in the VBOx
Printer hardware. If this change were made, even a complete compromise of the VBOx Printer
softwarewouldnotresultintheoverwritingofballotrecords.
Status Thisissuewasdiscoveredthroughexaminationofthesourcecode. Ithasnotbeentested
ontheVBOxPrinterhardware.
Issue35:TheVBOxvotesaresequentialandsocompromisevoteprivacy
TheVBOxisareel-to-reelprinterwithvotesprintedsequentially. Therefore,anyattackerwho
hadaccesstothepapercoulddeterminethesequenceofvotesandhowanyindividualvotervoted.
DetailedDescription CastvotesareprintedoutontheVBOxinsequencebothinhuman-readable
mode and as machine-readable bar codes. This allows an attacker who has access to the tape to
determine the order of votes. With access to the order in which voters voted, this allows recon-
structionofindividualvotes. Evenifthepapertapehasbeencut,itmaybepossiblewithenough
worktolineupcutedges.
Thisattackismademoreusefulbythepredictabilityofvotercodes(Issue7),becauseanattacker
canidentifywhereaparticularvotercodeoccurredtothesequenceofvoters.
Prerequisites TheattackerwouldneedaccesstotheVBOxpapertape. Thiscouldpotentiallybe
available to a poll worker who violated the VBOx tamper seals, if any. It would be available to a
numberofelectionofficials.
Impact Thisissueallowsviolationofvotesecrecy.
Mitigation The primary mitigation here is to ensure that nobody ever has access to the paper
tapeincompleteform. IfaVBOxauditisperformed,somemechanismshouldbeusedtoblindly
cutthepaperapart,perhapsmechanically. ThisappearstobeanissueforallcurrentVVPAT-based
e-votingsystems.
Status Thisissuewasdiscoveredbyinspectionofthesystemandisgenerictoreel-to-reelVVPATs
ofthistype.
6.11 Code Quality and Miscellaneous
In addition to the specific issues discussed above, we identified a number of problems related to
theimplementationoftheHartInterCivicvotingsuitethatbeardiscussion.
Issue36:Pervasivefailuretofollowcommonlyagreedsafecodingpractices
Writingsecurecodeisanextremelydifficultproblem,especiallyinCandC++,whichgivethe
programmer an extraordinary amount of control over memory, and thus a large number of ways
tomakeseriousmistakes.
§6.11CodeQualityandMiscellaneous 69
6. DetailedAnalysis
DetailedDescription Specificclassesofproblemsinclude:
Failuretocheckarraybounds. In addition to the exploitable buffer overflows listed previously,
wediscoverednumerousplacesinthesourcecodewherememorybufferswereusedwithout
appropriateboundschecking. Insomecasessystemcrashescouldpotentiallybetriggeredby
anattackertakingadvantageoftheseoverflows.
Throughacombinationofmanualandautomatedsourcecodeexamination—usingFortify—
wefoundanumberofbufferoverflowsintheHartsourcecode. Whilemostofthemdidnot
openthesystemstocontrolbyanattacker,theseoverflowsweresuggestiveofafragilecode-
baseandofasoftwaredevelopmentprocessthathasroomforimprovement.
Formatstringvulnerabilities. Thecorrectwaytoprintastringusingtheprintffamilyoffunc-
tionsisprintf("%s", str), notprintf(str). Thisbecausethelatterformcanleadto
unexpectedresultsifstrcontainsformatspecifierssuchas%d.Infact,acarefullycraftedma-
liciousformatstring,wheninterpretedbyprintf,canallowtheattackertoexecutearbitrary
code.
TheHartsourcecontainsmultipleinstanceswhereprintfisusedwithanon-constantfor-
mat specifier. One example is the JBC’s report mode, which uses printf to print write-in
candidatenames;seeIssue6.
Signednessandintegeroverflowerrors. It is important to watch out for arithmetic operations
whose result is outside the range of values that can be represented by the result type. For
example,30,000+30,000asasigned16-bitintegeris−5536,not60,000. Wraparoundofthis
sortcanleadtoincorrectresults.Itcanalsoleadtosecurityvulnerabilitiesofaclassknownas
integeroverflows[6]. Acommonvarietyofintegeroverflowarisesfromcarelessnessabout
the signedness of values, leading to (implicit) integer overflow when a signed quantity is
type-castasunsignedorviceversa.
TheHartsourcecodeweexaminedcontainsmultipleintegeroverflows. Itmakesextensive
use of 16- and 32-bit signed and unsigned integers, and frequently converts between these.
Thissometimesleadstoexploitablevulnerabilities.
Forexample, considerTally’sMBBprocessing. ForeachMBB,Tallyreadstheextentsofthe
CVR log from the MBB header, then computes the size of this log by subtracting the end
offsetfromthestart offset—asa32-bitsigned integer. Ifthedifferencebetweentheseoffsets
exceeds2,147,483,647,itisrepresentedasanegativenumber,whichmeansthatTally’scheck
that the size is less than the maximum allowed size is satisfied. The log is then read into a
buffer,whichcausesmemcpytobeinvokedwiththecomputedsizeasitssizeargument. But
memcpytreatsitssizeargumentasanunsignedinteger,whichmeansitcopiesmorebytesthan
areallocatedfortheinputandoutputbuffers,leadingtomemorycorruption.
Failuretocheckandpropagateerrorconditions. Detectingandappropriatelyactingonunexpected
error conditions is important for secure programming. Attackers compromise systems by
causing them to deviate from their intended behavior, and this deviation will be character-
ized by an error condition. Software modules should check that each of their assumptions
about their environment is satisfied before acting. Having discovered an anomalous condi-
tion,modulesshouldpropagateanalerttohigher-levelcodethatcantakeappropriateaction
inresponse.
The Hart source code we examined follows neither of these recommendations. This some-
timesleadstoexploitablevulnerabilities.
Forexample,whenaJBCrecordsavotereceivedfromaneSlate,theJBCcallsafunctiontore-
movetheeSlate’sclaimedvotercodefromthelistofactivecodes. Ifthisfunctiondetermines
that supplied the voter code is not a valid voter code, it takes no corrective action. It does
notloganalert, itdoesnotalerttheoperator, anditdoesnotpropagatetheerrorcondition
up—infact,thefunctionisoftypevoid. (Evenifthefunctiondidpropagatetheerrorup,it
§6.11CodeQualityandMiscellaneous 70
6. DetailedAnalysis
isalreadytoolatetoremovethevotefromtheCVRlog.) Thelackoferrorcheckingiscrucial
inenablingtheattackdescribedinIssue8.
Failuretominimizetrustbetweencomponents. Softwaremodulesshouldbewrittentominimize
relianceonthecorrectnessofothermodules. Thisisnotonlyusefulforrobustnessbutcrucial
for security. If this principle is not followed, a compromise of one module can lead to a
compromiseofanotherthattrustsittobehavereasonably.
The Hart source code we examined does not follow this principle. This sometimes leads to
exploitablevulnerabilities.
Forexample,whenSERVOisbackinguptheauditlogofaneScan,JBC,oreSlate,itasksthe
devicewhattheextentsofthedevice’sauditlogareandusestheanswertosizeabufferforits
copyofthelog. Then,aspartoftheactuallogdumping,SERVOagainasksthedeviceforthe
auditlogextentstodecidehowmanybytestotransfer. Ifthethetwoanswersarethesame,
thecopyproceedsasexpected. If,however,theconnecteddevicehasbeencompromisedand
claims a different (larger) log size on the second query than on the first, SERVO’s allocated
bufferisoverwritten,leadingtoaheapoverflow,asdescribedinIssue13.
Poorlyunifieddesign. Any time a piece of software has multiple implementations of the same
typeoffunctionality,thereisanopportunityforerror. TheHartsoftwareincludesanumber
ofsuchcases,including:
Multiplecopiesofpiecesofcode in particular, between the HartLib library and the eScan.
In many cases the files seem identical, in others they appear to be system-dependent,
andinyetothercasestheyappeartobebranchedversionswhichhavediverged. This
programming practice substantially increases the risk that the files will diverge in im-
portant ways, for instance fixes get applied in inconsistent ways, or that programmers
getconfusedaboutthebehaviorofthesubroutinebeinginvoked.
Multipleerrorreturnhandlingmechanisms between different sections of code. In some
places, the Hart code uses exceptions, in others, they use explicit return values, and
inotherstheysimplyignorethereturnvalues. Thismakesithardforoneimplementor
tobesureoftheerrorconventionusedbyanothersectionofcode,whichcanleadtoer-
rorsbeinginappropriatelyignored. Wehavefoundcaseswhereerrorsshouldnothave
beenignoredbutwere,thoughwedonotknowthecause.
Inconsistentmemoryallocation. Hart uses both malloc and new. There is nothing inher-
entlyunsafeaboutthisinC++code,butitrunstheriskofmisusingdatamanagedwith
onemethodwiththeothermethod,whichcancreateseriousproblems.
Theseissuesmakethecodehardtomaintainaswellastoreview,sinceonemustfrequently
ask“whatsection(orsections)ofcodeisinplayhere?” Aunifiedsystemwouldbeeasierto
workon.
Prerequisites Theprerequisitesforanattackbasedonaninstanceoftheissuesdescribedabove
dependonthespecificsettinginthesystemwherethatinstanceisfound. Theknowledgerequired
toexploitstandardC-languagevulnerabilitieslikebufferoverflowsiswidelydisseminated.
Mitigations Hart could rework its codebase, using some combination of: following commonly-
agreed safe coding practices; auditing the code base by hand or with automated static analysis
tools;andrewritinginasaferlanguagesuchasJava.
Status Thisissuewasdiscoveredthroughbothmanualandautomatedexaminationofthesource
code.
§6.11CodeQualityandMiscellaneous 71
CHAPTER 7
Attacks on the Full System
The previous section described a number of attacks on individual components of the Hart Inter-
Civic voting system. However, an attacker would not be limited to mounting individual attacks,
butwouldmostlikelywanttostringthemtogetherintoanattackplanwhichaccomplishesasetof
real-worldobjectives.
In the rest of this section, we consider attacks designed to accomplish a number of common
objectives:
• Compromisingvoterprivacy
• Alteringthefinalvotecount
• SubvertingallDREdevicesinaprecinct
• Subvertingallthedevicesinacounty
It’simportanttonotethatinmanycaseswewillonlypresentoneorahandfulofavenuestowards
achieving the desired goal. This should not be taken to imply that there are no other ways to
achieve these goals or even that we do not know of others. Rather, this section is intended as an
illustrationofhowanattackermightchoosetoattackthesystem.
7.1 Compromising Voter Privacy
AsdiscussedinSection3.2.3,therearetwomajorapplicationsforattacksonvoterprivacy:
• Votebuying/votercoercion
• Informationgathering
Theattacksdescribedinthissectionworkforbothapplications.
7.1.1 VoteBuyingoneSlateSystems
In a vote buying attack, the attacker needs to be able to verify that the voter voted the way that
hewasinstructed. Theattackercanreadilyverifythatthevoterenteredthepollingplaceandwas
authorizedtovotebecauseHartissuesareceiptcontainingthevoteraccesscode. Whilethisdoes
notdemonstratethatthevotervotedatallorthathevotedthewayhewasinstructedto,itisuseful
incombinationwithotherissuestoformacompletevotebuyingattack.
Thewaythatthisworksisthatthevotebuyerinstructsthevotertovoteacertainway. When
thevoterexitsthepollingplaceheprovideshisaccesscodeprintoutreceipttothevotebuyer. The
vote buyer can then use this access code as a lookup key into vote records stored on the MBBs,
eSlate,orJBCtoverifythevoter’sactions(seeSection6.8fordetailsonvotestorage). Theproblem
thenbecomesobtainingacopyofthatvotedata.
Thisiseasiesttodoiftheattackerisamaliciouspollworker,usingthefollowingsteps:
72
7. AttacksontheFullSystem
1. AftertheelectionisclosedandtheMBBhasbeenunsealedheplacestheMBBintoaPCMCIA
card reader (e.g., a laptop) and obtains an image. This is the only part of the process that
requiresaccesstoprotectedmaterials.
2. He searches through the audit log for an access code entry that matches the voter’s access
code.
3. HesearchesthroughtheCVRdataforanentrywithaCRCthatmatchestheentryintheaudit
log(seeIssue25).
4. Heexaminestheentrytoseeifitmatchestheexpectedvotes.
Thisallowstheattackerwithhighprobabilitytodeterminethatthevoterhasvotedasinstructed.
Anelectionofficialcouldofcoursemountthesametypeofattack. Naturally, oncetheMBBdata
hasbeenobtainedanddecoded,theattackercanverifyhowanynumberofvotersvoted.
AnotherapproachwouldbetoreadtheinternalauditlogsoftheeSlateorJBCviatheparallel
managementinterface(Issue1). Thesamederandomizationprocedurecanbeused.
Avotercanalsomountthisattack. Inordertodoso,heplacesamonitoringdeviceontheserial
port of any of the eSlates of the system, either in between the eSlate and the stand or on the free
connectorofthefinaleSlate(seeSection6.2formoredetailsonwhatsuchadevicemightlooklike).
ThisdevicewouldbeabletoobserveeverycastvotefromeveryeSlateinorderandwouldsimply
recordthem. BecausetheaccesscodesaretransmittedbytheeSlatetotheJBCpriortovoting,itis
veryeasytotietheaccesscodestotheCVR.Alternatively,avotercouldpotentiallyattachadevice
attheveryendoftheelection,impersonatetheJBC,andsimplysuckoutthecontentsoftheJBC’s
memory. Notethatthisdoesnotrequiretheattackertobepresentattheprecinct,hemerelyneeds
toobtainthereceiptfromthevoter.
7.1.2 VoteBuyingoneScanSystems
Vote buying attacks on eScan systems are more difficult because the voter is not issued with a
linkable receipt. However, because the audit log is created sequentially and can be linked to the
CVRlog,apollworkerwhohasaccesstotheMBBcanstillmountavotebuyingorcoercionattack.
TheattackerobservestheorderinwhichpeoplefeedtheirballotsintotheeScan. Hethenlooksup
theentryfortheappropriatevoterintheauditlogandusesthetechniquesdescribedinIssue25to
findtherelevantCVR.Thistellshimhoweachvotervoted,intheordertheirballotswerecast.
7.1.3 InformationGathering
Extendingthisattackbeyondasinglevotertoagenericinformationgatheringattackisrelatively
straightforward.AgainsttheeScan,theattacklooksexactlylikethatdescribedinSection7.1.2.This
allowsustomatchvotestotheorderinwhichvotersvoted.
AgainsttheeSlate,theattackercandothesamethingaswiththeeScan,butobservingtheorder
in which voters voted may not be simple because there are a large number of eSlates. However,
becausetheeSlateauditlogscontaintheaccesscodeshecandosomethingmoreconvenient:match
votestotheorderinwhichvotersenteredtheprecinctandreceivedaccesscodes.
Inordertomountthisattack,theobservestheorderinwhichvotersapproachtheJBC.Hethen
extractstheauditlogsfromtheJBC,eSlate,orMBB,whichcontaineachaccesscodeinorder,and
thenusesIssue25tomatchtheaccesscodestothecastvotes. Thisallowshimtoreconstructhow
each voter voted. Note also that even if the access code issuance were not in the logs, it would
stillbepossibletoreconstructvoteorderbytakingadvantageofthepredictabilityofaccesscodes
(Issue7.)
Thisattackrequireshavingacollaboratorineveryprecincttoobservetheorderinwhichpeople
voted—providedthatpollingplacesdonotkeepsuchrecords—whichmakeslargescaleinforma-
tiongatheringdifficult. However,itwouldbepracticalforsmall-scaleattacks.
§7.1CompromisingVoterPrivacy 73
7. AttacksontheFullSystem
7.2 Altering the Final Vote Count
Anotherimportantattackistomodifythefinalvotecount.Inthissectionweconsiderattackswhere
an attacker who controls a single device can modify the vote count. These attacks are obviously
more powerful if the attacker controls multiple devices. We consider those issues in subsequent
sections.
7.2.1 eScan
The most obvious attack is to subvert an eScan, which can be done via the attack described in
Issue 3. This would most likely require either poll worker or election official access, or that the
attacker break into the location where the eScan is stored. An attacker who subverted the eScan
couldmountatleasttwoattacks:
• ExtractthesharedMACkeyanduseittowriteafakeMBB(seeSection6.7).
• Installhisownfirmwareimagewhichcountsvotesinanarbitraryfashion(seeIssue3).
The second attack is more powerful because it would result in the eScan internal vote data, the
MBB,andthesummarytape,allhavingidentical(wrong)results. AsnotedinIssue12,itiseasyto
subverttheexternalintegritycheckingandsoelectronicauditprocedureswouldnotdetectthisas
longasthetotalnumberofvotesremainsthesame. Theonepercentmanualrecountwoulddetect
thisformofattack,providedthatthevictimeScanwasrandomlyselectedforrecount.
7.2.2 eSlate
WhileattackinganeScanismostlikelyoutsidethereachofavoter, webelievethatavotercould
subvertaneSlate,asdescribedinIssue2.SuchanattackercouldinstallnewfirmwareontheeSlate,
whichwouldactinanarbitraryfashion.
The difficulty with the eSlate is that there are four types of records which one wishes to have
agree:
• CVRs/AuditlogsontheMBB
• CVRs/AuditlogsintheJBC’sinternalmemory
• CVRs/AuditlogsontheeSlate’sinternalmemory
• TheVVPATrecords
TheMBBdataiswhatisordinarilyusedfortallying,somodifyingthatisattractive,butourattacker
maywishtosurviveanaudit, inwhichcasehemustarrangetotamperwiththeotherrecordsas
well.
IfweassumethattheJBCisuncompromised,thenthefirsttwotypesofrecordsagreebydefi-
nition. Thedifficultyisgettingthefirsttwotypestoagreewiththethirdandfourthtypes.
Weconsidertwoexampleattacks.Inthefirst,theattackerchangesavoter’svotebeforeitleaves
theeSlate. Inthesecond,theattackerintroducesfalsevotesintothesystemfromtheeSlate.
ChangingVotes Thebasicvotechangingattackissimple:the(compromised)eSlatesimplysends
whateverCVRdataitwishestotheJBC.ThisproducesconsistentelectronicrecordsbuttheVVPAT
willnotmatch. Itisnotclearhowseriousaproblemthisisfromtheattacker’sperspective,because
inCaliforniatheVVPATisnotroutinelyverified,exceptduringthe1%manualtally. However,an
attacker might wish to change votes in such a way that he could not be detected even in a 100%
manualrecount. ThisrequiressomesocialengineeringtoproduceaVVPATrecordthatisincorrect
butnotnoticedbytheuser.
Anumberoftechniquesarepossiblehere:
§7.2AlteringtheFinalVoteCount 74
7. AttacksontheFullSystem
• The simplest approach is for the eSlate to print out a VVPAT entry that matches the wrong
candidate. Ifthevoterdoesnotnotice,thentheattackerhaswon. Ifthevoterdoesnotice,the
eSlatesimplyallowsthemtochangetheirvote,asiftheyhadsimplymadeanerror,thistime
allowingthevotetogothrough. Everett’sresultsindicatingthatfewpeopledetectchanges
inDREconfirmationscreens[10]suggestthatthisattackhasahighsuccessprobability.
• Anotherapproachistopresentthecorrectvotedataonthescreen,waitfortheusertoaccept
their ballot, and then display the UI indicator that shows their vote was accepted but not
print “BALLOT ACCEPTED” on the VVPAT. Once the voter walks away, the VBOx prints
“BALLOTREJECTED”indicatingthattheballotwasspoiledandthenprintsanewballotof
theattacker’schoice. TheinstructionsforusingtheHartsystemonlytellthevotertowaitfor
thedisplaytoindicatedone,nottowaitfortheVVPATtoscrollforward.
• The converse of this approach is to present the correct vote data in the VBOx, but when
the user accepts the ballot, print “BALLOT REJECTED” instead and then quickly scroll the
paper forward. Once the voter is likely gone the eSlate prints a new VBOx record with the
candidatesoftheirchoiceandmarkthat“BALLOTACCEPTED”.Thisisclearlypossiblein
principlebutwehavenodataonwhethervotersorpollworkerswillnoticeit. Evenifthey
did, it would be hard for a voter to prove the problem to a pollworker because the VVPAT
wouldhavescrolledpast.
In any case, the data recorded on the VVPAT would match the data recorded in the electronic
records, with the result that the attack would not be detected by an audit. As with the eScan,
SERVOsintegritycheckswouldnotdetectthecompromiseoftheeSlate(seeIssue11).
ElectronicBallotStuffing Anattackerwhowasnotconcernedwithalteringthetotalnumberof
castvotescouldalsouseacompromisedeSlatetointroducefalsevotes,asdescribedinIssue8or
byusingthemodemporttointroduceaccesscodes,asdescribedinIssue4.
Asdiscussedabove,wepresumetheattackerwouldwanttominimizehisvulnerabilitytode-
tection. Therearethreeissueshere:
• ArrangingthattheVVPATmatchestheelectronicrecords.
• Avoidingdetectionbyvotersorpollworkers.
• Makingitdifficultforanauditortodeterminewhichvoteswerefake.
Inordertosatisfythefirstrequirement,theeSlatemustprintouttheattacker’schosenballotresult
ontheVBOprinter. Otherwise, theonepercentmanualrecountmightdetectthecheating. How-
ever,becausetheVBOxiscompletelycontrolledbytheeSlatesoftware(Issue33),thisisstraightfor-
ward. Thisleavesuswiththesecondrequirement,avoidingvoterorpollworkerdetectionofthe
attack. Thegeneralprinciplehereistoprintoutthefakevotedataaspartoftheprocessofclearing
theVBOxscreenafterthevoterleaves. Thisminimizesthechanceofdetection.
Note that this attack produces a situation in which the total number of votes in a precinct ex-
ceeds the total number of voters. This is easy to detect during the official canvass, provided that
countiescomparethenumberofvotescasttothenumberofvoters. Ifitisdetected,someattempts
mightbemadetorepairthedamagebyremovingthefakevotes. Ifthevotercodesaregenerated
using the modem technique of Issue 4, then they will presumably all be next to each other in the
auditlogandeasytotosuppress.However,ifthecompromisedeSlatesometimesswapstheaccess
codesforlegitimateandfakevotes,thentherepairproblembecomesquitechallenging.
ThesituationismorecomplicatedifonlytheeSlateiscompromised.However,itisstillpossible
tomakeitverydifficultforaninvestigationtodeterminewhichvoteswerethefakeones.Theattack
isasfollows.
1. TheeSlatewaitsforavotertofinishvoting.
2. TheeSlategeneratesafakeCVR.
§7.2AlteringtheFinalVoteCount 75
7. AttacksontheFullSystem
3. TheeSlategeneratesarandomnumberr,either0or1.
4. Ifr =0,theeSlateprintsthefakeCVRentrytotheVVPAT.immediatelyfollowingthevoter’s
genuinevote. Otherwise,itwillbeprintedlater.
5. TheeSlatewaitsforasecondvotertocome,callthatvoter’saccesscodeX.
6. Ifr = 0,theeSlateimmediatelysendsthefakeCVRtotheJBCwiththenewaccesscodeX.
Otherwise,itwillbesentlater.
7. The voter votes and the eSlate sends the correct CVR to the JBC and prints out the correct
CVRentrytotheVVPAT.
8. Ifr =1,theeSlatesendsthefakeCVRtotheJBCwithaccesscodeX andthenprintsoutthe
fakeCVRentrytotheVVPAT.
Theresultisthatthereisapairofvotes,bothofwhichhaveaccesscodeX,buttheorderwillvary.
Halfwillhavethelegitimatevotefirstwhiletheotherhalfwillhavethefakevotefirst. Thiswillbe
consistentbetweentheVVPATandtheelectronicrecords.
This attack could be detected by examining the electronic records, although we found no evi-
dencethattheTallycodemakesanyattempttodetectmultipleusesofthesameaccesscode.Evenif
thiscaseweredetectedandeveniftheelectionofficialsknewexactlyhowtheattackwasdesigned,
they would be unable to distinguish between the legitimate votes and the fake votes that could
occurineitherorder. Theelectionofficialwouldbeforcedtoeitheracceptbothvotesordisregard
both votes, either of which could disenfranchise the voter whose access code was abused in this
fashion.
7.2.3 VotinginOtherPrecincts
If we assume that an attacker is not concerned with producing a set of electronic records which
can survive auditing, other attacks are practical. If an attacker controls either a JBC or an eScan
he can simply add CVRs of his choice to the MBB. Because each CVR contains its own precinct
ID(Issue27),theattackermaybeabletoinjectMBBsintothesystemwhichcontainvotesforany
precinctofhischoice,thusaffectingawiderareathanhisownprecinct.
The difficulty with this attack is that it creates an inconsistency between the vote counts for
eachprecinctandthenumberofrecordedvoters. Totheextenttowhichrecordsarekeptofwhich
MBBsanddevicesareassignedtoeachprecinct, itshouldbepossibletodeterminetheroguede-
vices/MBBsandsuppressthebogusvotes. Wedonotknowtheextenttowhichsuchchecksarein
factdone.
7.2.4 DenialofService
Subvertedmachinescanalsobeusedtomountavarietyofdenialofserviceattacks.Inthesimplest
suchattack,themachinecouldsimplybeprogrammedtocrash,misbehaveinconfusingways,or
operate extremely slowly. The scope of this attack depends on the number of machines compro-
mised(seebelowfordiscussionofcompromisingmultiplemachines). Thiscouldblockoratleast
severelyimpedeanentireelection.
More sophisticated attacks are also possible. Machines could be programmed to detect the
votingpatternsofvotersintheprecinctinwhichtheyareinstalledandmalfunctionifthevoting
patternsareunfavorabletotheattacker. Machinescouldalsobeprogrammedtoselectivelyfailfor
voters who voted a certain way, thus potentially causing them to give up. Once the machine is
subverted,itisrunningsoftwareoftheattacker’schoiceandsoanyofthesebehaviorsaresimply
amatterofprogramming.
§7.2AlteringtheFinalVoteCount 76
7. AttacksontheFullSystem
7.3 Subverting all DRE Devices in a Precinct
BecauseHart’spollingplacearchitectureinvolvesmultiplemachinesconnectedinanetwork, we
shouldasktheextenttowhichitispossibleforanattackerwhohassubvertedonemachineinthe
pollingplacetosubvertothers.1
Thisattackistrivialforapollworkeroranattackerwhobreaksintothepollingplace(orother
storage area) the night before the election. It is also trivial for an election official working in the
warehouse. First,heislikelytohaveunattendedaccesstoallthemachines. Second,hecansubvert
theJBC(usingIssue1)andthenusethattotakeoveralltheremainingeSlates(usingIssue2).
Theproblemismoredifficultforavoter,becauseheonlyhasaccesstoasingleeSlate.However,
iftheattackercancausetheeSlatetoimpersonateaJBC(seeSection6.2),thenhecanusetheeSlate
tosubverttheothereSlatesintheprecinct. ThisismadesomewhatdifficultbytheJBC’sbeingthe
busmaster;however,webelieveitispotentiallypossible,asdescribedinSection6.2.3.
Using the JBC write-in report vulnerability of Issue 6 it is possible to escalate access from an
eSlatetotheJBC,butonlyattheendofanelection,potentiallycompromisingthefinalMBBdata
orfutureelections.
7.4 Subverting all the Devices in a County
Whilesubvertingthedevicesinasingleprecinctisattractivefortheattacker,itisalsolimitedfor
reasonsindicatedinSection7.2.3.Amorepowerfulattackistotakeoverallthedevicesinanentire
county. Webelievethatsuchanattackcanbemountedbyapollworker,voter,oranattackerwho
hasbrokenintothepollingplace/storageareabeforetheelection.
1. Subvertasinglepollingplacedevice,whethereSlate,JBC,oreScan(seeSection6.1).
2. Installnewfirmwareonthatdevice. Thisfirmwareoperatesliketheoriginalsoftwareexcept
thatitcontainsanexploitforoneoftheSERVOissuesdescribedinIssue13.
3. WhenSERVOconnectstothecompromiseddeviceaftertheelection(tobackupand/orver-
ify),ourfirmwareattacksSERVOandinstallsnewsoftwareontheSERVOmachine.
4. WheneachnewdeviceisconnectedtoSERVO,ourprograminstallscompromisedfirmware
on that device (again, see Section 6.1). Note that this happens immediately prior the next
electionwhenSERVOisusedtozerothecounters.
Attheconclusionofthisattack,mostoralleSlates,JBCs,andeScansinthecountywouldcontain
maliciousfirmwareunderthecontroloftheattacker.
Effectively, this is a multi-stage, multi-platform worm, with the exploit for each stage being
embeddedasapayloadinthestagebeforeit. Writingsuchawormiswellwithinthecapabilities
oftheaveragemalwarewriter.
Thisattackallowsanattackerwhocompromisesasingledeviceinone election toescalateup
toanattackonallthedevicesinacountybythetimeofthenextelection. Forinstance,onecould
compromiseadeviceintheprimaryelectionandhavecompletecontrolofalldevicesinthecounty
intimeforthegeneralelection.
Once the attacker has control of all the devices in the county, he can of course mount attacks
onvoteintegrityandsecrecythataredifficulttodetectand/orrepair, includingalloftheattacks
describedinSection7.2.
Wehavetestedthefollowingportionsofthisattack:
• InstallationofnewfirmwareonaneScantowhichwehavephysicalaccess.
• RemotecompromiseofSERVOfromaneScanduringthefirmwareverificationprocess.
1Thisisn’tarelevantissuefortheeScanbecausethey’renotnetworkedinsidethepollingplaceandtherearelikelyonly
oneortwoeScansperpollingplace.
§7.3SubvertingallDREDevicesinaPrecinct 77
7. AttacksontheFullSystem
Wehavenotproducedanend-to-enddemonstrationofthisattack,howeverdeliveringapayload
ofone’schoiceinthetypeofattackwemountedonSERVOisawell-understoodproblem.Wehave
notdemonstratedtheabilitytochangethesoftwareonaneSlateorJBC.However,theinstallationof
newfirmwareontheothereScansinthecountyfromSERVOisessentiallysimilartothefirmware
installationwehavealreadydemonstrated.
In addition to this attack, note that if SERVO is installed in a network with the the other Hart
back-office software, an attacker might employ Windows vulnerabilities to take over those ma-
chinesfromSERVO,leadingtocompromiseofallcountymachines.
§7.4SubvertingalltheDevicesinaCounty 78
CHAPTER 8
Detection and Recovery
BecauseeachvoteintheHartsystemproducesrecordsinanumberoflocations,inprinciplemany
ofthelesscompleteattackscanbedetectedandinsomecasesrepaired. Forinstancethevotein-
jectionattackdescribedinSection7.2.2changestheaggregatevotecount,whichcouldbedetected
simply by comparing the number of voters reported by a precinct against the number of votes
reported by the precinct’s voting machines. However, the extent to which the measures that are
availableareactuallyusedisunclearandmayvarydramatically.
Thelistofpotentialindependentrecordswhichshouldbereconcilableincludes,fortheeScan:
• Thevoterbookindicatingthenumberofvoterswhovoted.
• Thenumberofpaperballotsissued
• TheactualpaperballotsprocessedbytheeScan
• TheeScan’sMBB
• TheeScaninternallogs
AndfortheDREsystemincludes:
• Thevoterbookindicatingthenumberofvoterswhovoted.
• TheJBCrecordsofthenumberofissuedvotercodes(DREonly)
• TheJBC’sMBB
• TheJBC’sinternallogs
• TheeSlate’sinternallogs
• TheVVPAT
In principle, any inconsistency between any of these records can be detected and potentially cor-
rected. Inpractice,inconsistenciescanbedifficulttodetect.
8.1 Detection
Inthissectionweconsidermethodsofdetectingdiscrepancies. Inthenextweconsidermethodsof
recovery.
79
8. DetectionandRecovery
8.1.1 TheOnePercentManualRecount
Californiaelectionlawrequiresthatonepercentoftheballotsbemanuallyrecounted. Inthecase
ofeScanorBallotNowcentrallycountedballots,thismeansmanuallyassessingeachopscanballot
andcomparingthecountagainstthatreportedbytheopticalscanner. InthecaseofDREvotingit
meanscomparingtheVVPATagainsttherecordsfromtheJBC’sMBB.Notethatwhileinprinciple
theopscantallymaydifferslightlyfromthepaperballotsduetovariationinthesensitivityofthe
mark/sensescanner,theVVPATrecordsshouldexactlymatchtheDRErecords.
The effectiveness of the one percent recount is strongly dependent on how discrepancies are
treated. Thereareatleastthreeplausiblepossibilities:
• Treatthemanualresultsasthecorrectresultsanddiscardtheelectronicresults.
• Investigatetheprecinctwheretheerrorsoccurred.
• Doaninvestigationorarecountofalargerfractionofthevotes,escalatinguptoafullpaper
recount.
It appears that in at least some counties the first option is taken [1]. While this is potentially suf-
ficienttodetectcheatingbytheprecinctvotingequipment,itislikelytobeinsufficienttorecover
fromitoutsidetheprecinctswhichareactuallyrecounted. Consideranattackerwhoincreasesthe
vote count for his candidate by 5% in 25% of precincts. Such an attacker has a .25 probability of
havingoneofhisprecinctsaudited,butifthecheatingintheotherprecinctsremainsundetected,he
willhavechangedthevotetotalsbynearly1.24%,havinglostonlyasmallfractionofhisinfluence
fromtherecount.
The other extreme is to take the 1% recount as a tripwire and follow up any discrepancies by
escalatingtoamoresignificantrecount,possiblyuptoacompletemanualrecount.1 Thedifficultyis
indecidinghowsensitivethetripwireandhowaggressivetheescalationshouldbe. Ifevenminor
discrepancies trigger full manual recounts, it is fairly easy for an attacker with limited resources
to force the county into a full recount some reasonable fraction of the time. Moreover, strategies
which are effective in detecting fraud are also susceptible to being forced into full recounts. It
should also be noted that attacks that produce discrepancies are generally easier to mount than
those that do not—much of our effort went into figuring out how to conduct attacks that leave
behindnoinconsistencies.
Notethatintheopticalscancase,escalationissubstantiallyeasier:theballotssimplyneedtobe
recountedwithascannerwhichistrustednottohavebeencompromised. Thisisinconvenientbut
farlessinconvenientthanaDRErecount,whichrequiresmanualrecountingofthehuman-readable
portionoftheVVPAT—thebarcodecannotbetrustedforthispurpose. Onemightimaginedoing
opticalcharacterrecognitionoftheVVPAT,butthisisamuchmorecomplicatedproblem. Asfar
asweknow,toolsforthisjobarenotpresentlycommerciallyavailable.
8.1.2 TotalVoterCounts
Attackswhichsimplyinjectfalsevotesareinprinciplesusceptibletosimplycomparingthenumber
of voters to the number of electronically recorded votes. In both the optical scan and DRE cases,
thereisaphysicalrecordofthenumberofvoterswhosignedintothepools.InthecaseoftheeScan,
one could count the actual number of paper ballots used. None of these records are susceptible
to electronic tampering2 and they can therefore be used to detect vote injection, provided that
thesecomparisonsareactuallydone. Wedonotknowhowregularlytheyareperformedorwhat
the results of discrepancies are—as we expect that small-digit numbers of discrepancies will be
common. Again, treating small discrepancies as a trigger for a recount creates an opening for a
denialofserviceattack.
1Appel[3]providesagooddescriptionofthestatisticshere.
2Ifelectronicpollbooksareinuse,theymayalsobesubjecttoattack.
§8.1Detection 80
8. DetectionandRecovery
8.1.3 MechanicalLogComparisons
Wenotethatseveraloftheattackswedescribehereproducedistinctivesignaturesontheelectronic
logs produced in the various components. For instance, the eSlate vote injection attacks produce
more votes in the MBB than the number of access codes issued to voters. Careful comparison of
theMBBandtheJBCaccesscoderecordswouldrevealthis. InprincipleSERVOprovidesreports
thatwouldallowanauditortomakethesecomparisons,however,wedidnotseeanyevidenceit
woulddosoautomatically.
8.1.4 TamperSeals
Finally, wemaynothaveanyevidenceofactualcheatingotherthanthatatampersealisbroken.
This is obviously a reason to suspect that the sealed device has been tampered with, but it could
also be a case where the seal was mishandled in some way. Determining which has happened is
a difficult problem. In the case of all three of the polling place devices, an attacker with physical
accesscancompletelyreprogramthedeviceinawaythatrequiresextensiveforensicstoverify,as
discussedinSection8.1.6.
Theconverseofhowtorespondtocasesoftamperedsealsisthequestionofhoweffectivesuch
sealsare. Anumberofdifferenttypesofseals(plastic,wire,tape,etc.) areinuseinCalifornia,and
wehavenotmadeanysystematicinvestigationofthem;however,Johnston[22]reportssuccessful
and straightforward attacks on seals of the general type used in California elections. Therefore
wemustconsiderthepossibilitythatsealscanbebrokenwithoutanyobvioussignsoftampering,
especiallywithminimallytrainedpollworkers. SeeSection3.5formoreonthispoint.
8.1.5 ParallelTestingandLogicandAccuracyTesting
One natural way to detect whether systems have been compromised is to test them to determine
whether they are behaving correctly. Parallel testing involves selecting a random sample of DRE
machines, takingthemaside, andrunningamockelectiononElectionDayusingtheequipment.
By preparing a known voting slate, one can compare the results from those machines against the
inputs that mock voters entered. Typically, parallel tests are videotaped so that it is possible to
gobackandreviewanydiscrepancies. ParalleltestsareonewaytodetectbugsormaliceinDRE
software, if the faulty software is widespread enough that the random sample is likely to pick at
least one DRE that exhibits incorrect behavior. It is natural to wonder whether parallel testing
mightprovideawaytodetectlarge-scaleviralattacks.
Thereliabilityofparalleltestingatdetectingmaliciouscodeappearstobeopentodebate. The
effectiveness of parallel testing is heavily dependent upon the details of how the testing is done.
Ifmalicioussoftwarecandistinguishwhenitisbeingtestedfromnormaloperations,forinstance
bylookingformistakesthatinexperiencedvoterswouldmakebutofficialsperformingtestswould
not, then the malicious software can evade detection by behaving correctly when it is under test.
Analysisoftheeffectivenessofparalleltestingpracticeswasoutsideofthescopeofthisstudy.
Ultimately, parallel testing becomes an arms race between attack designers and officials who
plan realistic parallel tests. The defenders attempt to design testing procedures that mimic real
electionsascloselyaspossible,whilewemustassumetheattackerswilltrytodesignmethodsto
detectwhentheyarebeingtested. Itisnotclearwhohastheadvantageinthisrace. Theproblem
with thiskind of arms race is that it is difficult to know whetherone is winning. Thus, there is a
risk that an attacker might develop a secret way to defeat parallel testing, leaving the defenders
withafalsesenseofsecurityaboutelectionintegrity.
Anotherwaytothwartparalleltestingwouldbetouseasecretknock(aseriesofinputsknown
onlytotheattackerthatwouldbeunlikelytohappenbychance)tocontrolactivationofthevote-
stealing code. A secret knock could be used to activate the virus, though this would require the
virus author to have conspirators who would need to access each of the voting machines where
votes would be stolen. Alternatively, a secret knock might serve to deactivate the vote-stealing
code,thoughthiswouldrequirethehelpofaninsiderintheparalleltestingprocess.
§8.1Detection 81
8. DetectionandRecovery
ParalleltestingonlydefendsagainstmalicioussoftwareontheDREsystem(eSlatesandJBCs).
Itdoesnotdefendagainstmalicioussoftwareatcountyheadquarters.
Paralleltestingismoreeffectiveatdetectingattacksthanatpreventingthemfromdisruptingthe
election.Supposetestingrevealsthatasmallnumberofvotesarerecordedforthewrongcandidate.
Ifthetestisconductedonorclosetoelectionday,theremaynotbeenoughtimetodeterminethe
cause. Asdescribedbelow,itmaybedifficultorimpossibletodeterminethecorrectvotetotalsif
attackcodeisrunningonthemachinesonelectionday. Denialofserviceattackspresentaneven
harder challenge. Officials have few recovery options if they discover shortly before the election
thatthemachineswillfailthenexttimetheyareused,andparalleltestingonelectiondayprovides
nowarningofsuchafailure.
Finally,unlessparalleltestingisperformedonaverylargenumberofmachines,itwillhavea
lowprobabilityofuncoveringattacksthataredirectedonlyatspecificprecinctsorelectioncondi-
tions. Othermitigationstrategiesmustbeappliedtocontroltheserisks.
All in all, it is difficult to predict with any degree of certainty how effective parallel testing
willbe. Wewouldpreferadefensethatwecanbeconfidentwilldetectproblemsoveronewhose
efficacyisopentodebate.Despitetheselimitations,paralleltestingmaystillhavevalueatdetecting
viral attacks. And, of course, we do not deny that parallel testing may have other benefits that
are outside the scope of this study. We leave it to others to analyze the cost-effectiveness and
appropriatenessofparalleltesting.
8.1.6 FirmwareForensics
Incaseswhereaunitissuspectedofhavingbeentampered,itisnaturaltoattemptforensicexami-
nationoftheunitinordertodeterminewhetheritisrunningthecorrectfirmware.Aswediscussed
inSection6.3,Hartprovidestechniquesforrunningthesechecksremotelybuttheyareineffective.
Theonlyplausibletechniqueforrunningsuchforensiccheckswouldbetodirectlyexaminethe
memory cards on the device, thus bypassing the potentially compromised software. However, a
clever attacker could defeat such checks as well. The approach would be to retain a copy of the
original firmware. When the “close elections” routine is run, the compromised firmware would
scrub itself off of permanent storage and then restore the original firmware. This would defeat
evenfairlysophisticatedforensictechniques.
Acountermeasuretothisattackistosetasidearandomsampleofdevicesbeforetheelection
sothatanyattacksoftwarepresentwillbepreservedforanalysis.Notethatthistechniquedoesnot
detectmalwareinstalledonElectionDay.
8.2 Recovery
As noted above, recovering from a clear discrepancy with an optical scan system is straightfor-
ward: rescanwithanewscanner. eScanMBBcompromisescanpotentiallyberecoveredsimplyby
auditingtheeScandirectly,althoughitisn’tnecessarilystraightforwardtodeterminewhichofthe
twoiswrong.
Recovering from DRE compromises will be more complicated. If the VVPAT doesn’t match
the electronic records, then it is natural (and perhaps legally required) to use the VVPAT as the
definitiverecord—althoughittoomayinfactbeincorrect. However,iftheymatch,theproblemis
moredifficult. Thechoicesareeffectivelytoabandonandreruntheelectionortotrytoforensically
determinewhatreallyhappened.
Theforensicsoptionisproblematicintworespects. First,itstartsfromthepremisethatthesys-
temisunderattackfromanattackerwithlimitedcapabilitieswhoforsomereasoncannotcontrol
allelectronicrecords.Inconsistenciesareevidenceofhislackofcontroloveroneortheotherdevice
andsoreconstructingtherealhistoryisamatteroffiguringoutwhichdevicewascompromised.
Thisisadifficultpropositionandbearswithittheinherentriskofidentifyingtheuncompromised
deviceascompromisedandthereforeacceptingthebogussetofresultsratherthantherealones.
§8.2Recovery 82
8. DetectionandRecovery
Thisriskisenhancediftheforensicproceduresarepublishedinadvanceandtheattackertherefore
hasanopportunitytotunehisattacktocounterthem.
Thesecond issueis thatsucha forensicinvestigationdepends onmaintainingmore extensive
andtamper-resistantrecordswhichtendtocompromisethesecrecyoftheballot. Toconsidertwo
examplesfromthecurrentsystem:
• TheVVPATisdesignedtobetamperresistantbutinherentlyprovidesalinearrecordofallof
thevotes. Thisrecordcanbeeasilymappedtovotercodes(cf.Issue35).
• In Issue 25 we observed that the votes are stored on the MBB in a way that allows recon-
structingthevotercode–CVRmapping. Thisrepresentsaballotsecrecyissuebutisalsokey
toallowingrecoveryfromtheattackdescribedinSection7.2.2.
One can imagine even more aggressive record keeping measures, such as a separate hardware-
basedtamper-resistantrecordofeverypieceofuserinput. Thiswouldofcourseallowmuchbetter
recovery, but at the expense of severely compromising ballot secrecy if an attacker obtained the
record. Thus,thereisaninherenttensionbetweentheabilitytorecoverfromcompromiseandthe
secrecy of the ballot. It may not be possible to recover from any significant attacks purely on the
basisofelectronicrecords.
Thisisnottosay,however,thattheHartsystemrepresentsanoptimaltrade-offinthatdesign
space,asithasbothissueswithballotsecrecyandminimalrecoverycapabilities.
§8.2Recovery 83
CHAPTER 9
Recommendations for Future
Analysis
Themajordifficultieswefacedinthisworkwere:
• Sharplylimitedtime
• Inadequateinformationaboutprocedures
• Insufficientaccesstomaterials
• Difficultyintestinghypothesesaboutsystemoperation
9.1 Time Limitation
Although the project started May 31, the delivery of the Hart source code was delayed. We first
obtainedthesourcecodecodeonMondayJune18. Thisleftuswithjustoveramonthtoperform
our analysis and complete our report, which was due July 20. This timeline was extremely tight
andforcedustostrictlytriageourinvestigation.
Inparticular,theshorttimecombinedwiththecoordinationdifficultiesdescribedinSection9.4
preventedusfromverifyingmostoftheissueswediscoveredinthecode. Thisisextremelyprob-
lematicandshouldbeamajorfocusofanyadditionaleffort.
AsexplainedinSection2,itisunrealistictobelievethatanyprojectofthistypewillproducean
exhaustiveauditofallthevulnerabilitiesinasystem;webelievethatasignificantlymorethorough
jobcouldhavebeendonewithmoretime.
We recommend that future projects provide the teams with at least three months to complete
theirwork.
9.2 Inadequate Information about Procedures
The impact of anumber ofthe issueswe discovereddepends significantly on theprocedures fol-
lowedinactualuseofthesystem. Forinstance,RallyandTallyclearlyhavethecapabilitytocom-
municateresultsviatheInternetormodem;however,theextenttowhichthiscapabilityisusedin
California—ifatall—isstilluncleartous.
Itappearsthatmanyoftheproceduresvarysubstantiallybetweencounties,butweweregen-
erallyinstructedthattheseprocedureswereoutofscope.1 Thismadeitveryhardtoassesswhich
issuesweremostimportantandtofocustheappropriateamountofattentionaccordingly.
Thislackofinformationaboutproceduresextendstoordinaryelectionprocedures. Werecom-
mend that in the future teams be allowed to observe a real election using the chosen equipment
1WewereabletodirectlyobtainsomeanswersaboutproceduresinYoloCounty.WeappreciatetheassistanceofFreddie
OakleyandTomStanionis.
84
9. RecommendationsforFutureAnalysis
andthattheyhavedirectaccesstovendorrepresentativesandcountyelectionofficialstoanswer
questionsaboutprocedures.
9.3 Insufficient Access to Materials
This project was significantly hampered by incomplete materials. Materials we were missing in-
clude:
• Detailedspecificationsforthenetworkprotocolsusedbythesystem.2
• ThetoolingthatHartusestoupgradefirmwareontheirowndevices.
• Aworkingbuildenvironmentthatwouldhaveallowedustobuildourownbinaryversions
oftheHartsoftware.3
• Source code for significant portions of the system, such as the embedded MQX real-time
operatingsystemusedbyeSlateandJBC.ItisourunderstandingthatHartownsandcontrols
MQX[7].
• Windowssystemsconfiguredwiththeback-endHartapplicationsastheyshouldbeconfig-
uredinagenuineelectionenvironment.
Lackofaccesstobuildenvironmentswasparticularlyproblematicforanumberofreasons:
• Readingsourcecodeisgenerallyafairlyinefficientmethodfordetermininghowaprogram
works.Runningit,especiallyunderadebugger,ismoreconvenient,butonlyifyoucanbuild
yourownbinariessoyoucandosourceratherthanbinarydebugging.
• Anumberoftheissueswediscoveredinvolveddetailedmemoryexploitswhichwouldhave
beeneasiertoinvestigatehadwehadbeenabletotobuildourownversionsofthesoftware.
Eventuallywewereabletoacquireacopyofthebinariesandresortedtobinarylevelanalysis.
• A number of our testing and attack tools required imitating one Hart component talking to
another. Incaseswherethisdidnotworkitwasverydifficulttodiscoverwherethebugin
our code was because the Hart component would generally just be silent. Were we able to
buildourownbinariesandrunthemunderadebuggerwequicklywouldhavebeenableto
determinetheissue. Inaddition,wecouldhaveusedtheHartsystemasabasisforourown
tools,thusgreatlyreducingtherequiredeffortlevel.
• SourcecodeanalysistoolslikeFortifySCAaredesignedtoprocessthecodeinthesamebuild
environmentsthatthecompilerdoes. Inordertousethesetoolsatallwehadtomockupour
ownbuildenvironments,whichwastimeconsumingandmaynothavebeenrepresentative
oftherealenvironment. Inaddition,wewerenotabletodothisforallthecomponentsofthe
Hartsystem.
Someofourquestionsaboutthesystemstillremainunansweredduetolackoftheabilitytobuild
ourownbinaries.
We recommend that any future projects require that the teams be supplied with a full vendor
developmentenvironmentaswellasalltoolsusedbythevendorformaintenance,eveniftheyare
notsuppliedtoordinarycustomers.
2WefinallyreceivedasmallportionofthistheweekofJuly1st,butmostofourunderstandingcamefromreviewingthe
source.
3WeunderstandthatthetoolingwerefinallysenttotheSecretaryofStateonJuly18,despiteourearlierrequestsfor
theseresources.AsofthecompletionofthisreportonJuly20th,wehavenotreceivedthem.
§9.3InsufficientAccesstoMaterials 85
9. RecommendationsforFutureAnalysis
9.4 Difficulty in Testing Hypotheses about System Operation
Workoneachsystemunderstudywasdividedbetweenthreeteams:
• Adocumentationteam
• Asourcecodeteam
• A“RedTeam”responsiblefortryingattacks
FortheHartsystem,thedocumentationteamwaslocatedinBerkeley,thesourceteaminMenlo
Park, and the Red Team in Sacramento. The geographical separation plus the necessary security
restrictions made it very difficult to transfer information among the three teams. For example,
when we wished to transfer our attack tools to and from Sacramento, they had to be encrypted,
burnedontoaCD-ROMandshipped,withthekeytransferredviatelephone. This,plustheordi-
narydifficultyofknowledgetransferacrossgeographicallyseparatedteams,unavoidablycreated
significantdelaysintestinghypothesesaboutpotentialissues.
Werecommendthatinthefuturetherebeoneteamwhichisresponsibleforbothanalysisofthe
sourceandmountingattacksandthatalltheworkbedoneinasinglelocationwithaccesstoboth
thesourceandthehardware. Thiswouldallowamuchtighterfeedbackloopbetweenhypothesis
andtestandwouldaccelerateprogress.
§9.4DifficultyinTestingHypothesesaboutSystemOperation 86
CHAPTER 10
Summary of Findings
Althoughwehadonlylimitedtimetoreviewthesourcecodeofthesystem,ourreviewneverthe-
less uncovered what we believe to be a number of significant security issues. In many cases the
Hartsystemdoesnotincorporatedefense-in-depthprinciples,whichmayallowindividualattacks
tobeescalateduptomuchbroaderattacks.
The Hart software and devices appear to be susceptible to a variety of attacks which would
allowanattackertogaincontrolofsomeorallofthesystemsinacounty:
• The Hart eScan, eSlate, and JBC devices incorporate an unsecured management capability.
WebelievethatgivenbriefphysicalaccesstoaneScan,eSlate,orJBCdevice,anattackercan
subvertitandoverwritetheexistingsoftwarewithmalicioussoftwareofhischoice.
• Theseattackscouldbemountedbyapollworkerorpossiblybyavoterwhileintheprocess
ofvoting. Theeffectsofsuchanattackareessentiallypermanent;oncemalicioussoftwareis
loadedontosuchadevice,thereisnorealisticwaytoremoveit.
• Subversionofsinglepollingplacedevicescanbeusedtomountavarietyofvoteforgeryand
ballotstuffingattacks.
• ThemechanismsprovidedbyHartfordetectingdevicesubversionappeartobeeasytoby-
passandthereforesystemsubversionislikelytogoundetected.
• The Hart back-end SERVO software contains multiple buffer overflows which appear to be
remotely exploitable by a single compromised polling place device. We have exploited one
of these in our test environment and used it to install software of our choice on the SERVO
machine.
Bycombiningtheaboveattacks, amaliciouspollworkercouldsubvertaneScan, throughthat
SERVO,andthroughSERVOallthemachinesinthecountyforthenextelection. Wehavetested
what we believe to be the essential elements of this attack but not performed an end-to-end test.
Furthermore, a malicious voter could subvert a single eSlate, through that SERVO, and through
SERVO all the machines in a county for the next election. We have tested some but not all of the
elementsofthisattack.
Beyonddirectsystemcompromise,wefoundthatHart’smanagementofballotandvotedatais
vulnerabletoseveralattacks:
• Hart’scryptographickeymanagementrequiresacounty-widesymmetrickeywhichisstored
onvulnerablefielddevices.Thiskeycanbeobtainedbyanattackerwithbriefphysicalaccess
toaneScanorJBC.
• Compromiseofthissinglekeywouldallowanattackertoforgebothballotinformationand
voteresults.
• Wefoundmultipleavenuesforcompromisingvoterprivacy,enablingbothvotebuying/coercion
andwholesaleinformationgatheringattacks.
87
10. SummaryofFindings
This list does not include all the issues discovered during our review and there may be other
issuesthatwouldbeuncoveredwithfurtherreview. WeencouragetheSecretaryofStatetounder-
takesuchareview.
WestressthatduetolimitedtimeandaccesstoHartequipment,wedidnotattempttovalidate
all of the above issues. In the body of the report we clearly indicate the validation status of each
issue. WeencouragetheSecretaryofStateandHarttoattemptsuchvalidation.
Some of these issues can be mitigated with stricter polling place procedures. Others may be
repaired with minor modifications to Hart’s systems, while yet others may require significant re-
design. Providingacompleteassessmentofmitigationstrategieswasoutofscopeofthisreview,
butweencouragetheHartandtheSecretaryofStatetostudytheseissues.
We have deliberately avoided addressing the broader issue of whether or how this system
should be used for voting in California. Making that judgement requires assessing not only the
technicalissuesdescribedinthisreportbutalsotheproceduresandpolicieswithwhichthesystem
isused.
88
Bibliography
[1] Judy Alter. Report on the 1% manual recount for special election, Nov. 2005 L.A. County,
July 2006. http://www.bbvforums.org/forums/messages/2197/Manual recount
report-33060.doc.
[2] Anonymous. Once upon a free(). Phrack Magazine, 57(9), August 2001. http://www.
phrack.org/archives/57/p57-0x09.
[3] AndrewW.Appel.Effectiveauditpolicyforvoter-verifiedpaperballotsinNewJersey,March
2007. http://www.cs.princeton.edu/∼appel/papers/appel-nj-audits.pdf.
[4] Brad Arkin. Securing the eSlate Electronic Voting System: Application Security Imple-
mentation,January2005. http://www.hartic.com/files/HART SYMANTEC SECURITY
REPORT White Paper.pdf.
[5] MihirBellare,RanCanetti,andHugoKrawczyk. Keyinghashfunctionsformessageauthen-
tication. InNealKoblitz,editor,ProceedingsofCrypto1996,volume1109ofLNCS,pages1–15.
Springer-Verlag,August1996.
[6] blexim. Basic integer overflows. Phrack Magazine, 60(10), December 2002. http://www.
phrack.org/archives/60/p60-0x0a.txt.
[7] Compuware Corporation, Columbus, OH. Direct Recording Electronic (DRE) Technical Se-
curity Assessment Report, November 2003. http://www.sos.state.oh.us/sos/hava/
compuware112103.pdf.
[8] Tim Dierks and Eric Rescorla. The transport layer security (TLS) protocol version 1.1. RFC
4346,April2006. http://www.ietf.org/rfc/rfc4346.txt.
[9] Electronics Industry Association. Electrical Characteristics of Generators and Receivers for
Use in Balanced Digital Multipoint Systems (ANSI/TIA/EIA-485-A-98) (R2003). EIA-485,
March1998.
[10] Sarah P. Everett. The Usability of Electronic Voting Machines and How Votes Can Be Changed
WithoutDetection. PhDthesis,RiceUniversity,2007.
[11] ArielJ.Feldman,J.AlexHalderman,andEdwardW.Felten. SecurityanalysisoftheDiebold
AccuVote-TS voting machine. In 2007 Usenix/ACCURATE Electronic Voting Technology Work-
shop,Boston,MA,August2007.
[12] RyanGardner, SujataGarera, andAvielD.Rubin. Onthedifficultyofvalidatingvotingma-
chine software with software. In 2007 Usenix/ACCURATE Electronic Voting Technology Work-
shop,Boston,MA,August2007.
[13] geraandriq. Advancesinformatstringexploiting. PhrackMagazine,59(7),July2001. http:
//www.phrack.org/archives/59/p59-0x07.txt.
89
BIBLIOGRAPHY
[14] Rop Gonggrijp and Willem-Jan Hengeveld. Studying the Nedap/Groenendaal ES3B voting
computer:Acomputersecurityperspective.In2007Usenix/ACCURATEElectronicVotingTech-
nologyWorkshop,Boston,MA,August2007.
[15] HartInterCivic.Judge’sBoothController(JBC)FunctionalSpecification,2005.Document6000-050,
Rev.42-62B.
[16] HartInterCivic. eSlatePollingPlaceSystemElectionDayDeskReference,2006.
[17] HartInterCivic. HartVotingSystem,ProductDescription,System6.2,2006. Document6000-060,
Rev.62A.
[18] HartInterCivic. RallyOperationsManual,2006. Document6100-114,Rev.23-62A.
[19] Hart InterCivic. System for Election Records and Verification of Operations, Operations Manual,
2006. Document6100-102,Rev.42-62B.
[20] HartInterCivic. TallyOperationsManual,2006. Document6100-049,Rev.43-62B.
[21] Hart InterCivic. Voting System Use Procedures for California, Hart Voting System 6.2, July 2006.
PartNumber000255,Rev.C.
[22] Roger G. Johnston. Tamper-indicating seals. American Scientist, 94:515–523, November-
December 2006. Reprint available at http://ephemer.al.cl.cam.ac.uk/∼rja14/
johnson/newpapers/American%20Scientist%20(2006).pdf.
[23] Michel Kaempf. Vudo malloc tricks. Phrack Magazine, 57(8), August 2001. http://www.
phrack.org/archives/57/p57-0x08.
[24] Burt Kaliski. PKCS #5: Password-based cryptography specification version 2.0. RFC 2898,
September2000. http://www.ietf.org/rfc/rfc2898.txt.
[25] John Marchesini, Sean Smith, Omen Wild, and Rich MacDonald. Experimenting with
TCPA/TCG Hardware, Or: How I Learned to Stop Worrying and Love The Bear. Technical
ReportTR2003-476,DepartmentofComputerScience,DartmouthCollege,December2003.
[26] Elliot Proebstel, Sean Riddle, Francis Hsu, Justin Cummins, Freddie Oakley, Tom Stanionis,
andMattBishop. AnanalysisoftheHartInterCivicDAUeSlate. In2007Usenix/ACCURATE
ElectronicVotingTechnologyWorkshop,Boston,MA,August2007.
[27] DavidRohde.Onnewvotingmachine,thesameoldfraud.TheNewYorkTimes,April27,2004.
http://www.nytimes.com/2004/04/27/international/asia/27indi.html.
[28] Aviel D. Rubin. My day at the polls – Maryland primary ’06, September 2006. http://
avi-rubin.blogspot.com/2006/09/my-day-at-polls-maryland-primary-06.
html.
[29] StuartSchechter,RachnaDhamija,AndyOzment,andIanFischer.Theemperor’snewsecurity
indicators. In Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, May
2007.
[30] Arvind Seshadri, Mark Luk, Elaine Shi, Adrian Perrig, Leendert van Doorn, and Pradeep
Khosla. Pioneer: Verifyingintegrityandguaranteeingexecutionofcodeonlegacyplatforms.
InProceedingsofACMSymposiumonOperatingSystemsPrinciples(SOSP),pages1–15,October
2005.
[31] Michael Shamos. Oral testimony, Technical Guidelines Development Committee
(TGDC), public data gathering hearings, September 2004. http://vote.nist.gov/
PublicHearings/9-20-94%20Panel%202%20SHAMOS.doc.
BIBLIOGRAPHY 90
BIBLIOGRAPHY
[32] Michael Steil. 17 mistakes Microsoft made in the Xbox security system. In Proceedings of the
22ndChaosCommunicationCongress,December2005.
[33] TrustedComputingGroup. TPMv1.2SpecificationChanges,October2003. https://www.
trustedcomputinggroup.org/downloads/TPM 1 2 Changes final.pdf.
[34] AlmaWhittenandJ.D.Tygar. Whyjohnnycan’tencrypt: AusabilityevaluationofPGP5.0.
InProceedingsofthe8thUSENIXSecuritySymposium,Washington,D.C.,August1999.
BIBLIOGRAPHY 91
APPENDIX A
System Components and Versions
SourcecodeforthefollowingcomponentswassubmittedbyHartInterCivicforreview:
• BallotNow,version3.3.11
• BOSS,version4.3.13
– BossUtil,version2.5.8
– TranslateDLL,version1.8.2
• eCMManager,version1.1.7
• eScan,version1.3.14
• eSlate,version4.2.13
• HartLib,version4.0
• JBC,version4.3.1
• Rally,version2.3.7
• SERVO,version4.2.10
• Tally,version4.3.10
• VBOPrinterFirmware,version1.8.3
Wedidnotreceivesourcecodeforthefollowingcomponents:
• TheversionoftheembeddedMQXreal-timeoperatingsystemmaintainedbyHartforusein
theeSlateandJBCdevices.
• ThesoftwaretoolsthatHartusestoupgradefirmwareontheirdevices.
BreakdownofthenumberofSourceLinesofCode(SLOC)percomponent:
92
A.SystemComponentsandVersions
Component SLOC Language(s)
BallotNow3.3.11 64K (C++)
Boss4.3.13(excludingPowerBuildercode) 35K (C++)
eCMManager1.1.7 2K (C++)
eScan1.3.14 79K (C++,C)
eSlate4.2.13 22K (C++)
HartLib4.0 56K (C++,asm)
JBC 23K (C++)
Rally2.3.7 7K (C++)
SERVO4.2.10 24K (C++)
Tally4.3.10 52K (C++)
VBOPrinterFirmware1.8.3 2K (C++)
(total) 366K
Table A.1: The number of non-blank, non-comment source lines of code in each voting system
component,ascountedbyDavidWheeler’ssloccount2.26. Allnumbershavebeenroundedto
thenearestthousandlinesofcode.
93