All bodies  ›  Office of Voting Systems Technology Assessment  ›  Source Code Report

OVSTA

Source Code Report

Hart System 6.2.1 (Conditional Reapproval following the Top-to-Bottom Review - December 6, 2007)

Office of Voting Systems Technology Assessment · oversight-ttbr-Hart-source-public · Document · Hart InterCivic

Read the report at Hart InterCivic ↗

Source Code Review of the Hart InterCivic Voting System1 SrinivasInguva StanfordUniversity2 EricRescorla NetworkResonance HovavShacham UniversityofCalifornia,SanDiego DanS.Wallach RiceUniversity July20,2007 1ThisreportwaspreparedattheUniversityofCalifornia,BerkeleyundercontracttotheCaliforniaSecre- taryofStateaspartofa“Top-to-Bottom”reviewofelectronicvotingsystemscertifiedforuseintheStateof California. 2Allauthoraffiliationsareforidentificationonly. Executive Summary ThisreportconsiderssecurityissuesinHartInterCivic’svotingsuite,version6.2.1.Thisreportwas preparedattherequestoftheCaliforniaSecretaryofState,aspartofa“top-to-bottom”reviewof thestate’selectronicvotingsystems. Thisdocumentisthefinalreportoftheteamthatexamined theHartvotingsystemsourcecode. Hart’s system consists of back-office election management components (SERVO, Rally, Tally, eCMManager, BOSS,BallotNow)whichareusedtoconfigureandcollectdatafromprecinctde- vices(eScan,eSlate,Judge’sBoothController).Theelectionmanagementsoftwarerunsonordinary Windowsmachineswhereastheprecinctdevicesareembeddedprogramsrunningonspecialized hardware. Component-to-component networks are pervasive in Hart’s architecture. A JBC and one or more eSlates are networked together at polling place for voting. JBCs, eSlates, and eScans are networkedwithSERVOforpre-andpost-electionsetup,auditing,andreset. RallyandTallycom- municateoveramodem(orleasedline)totransmitremotevotingrecords. Inaddition, theother componentscommunicateindirectlythroughPCMCIAmemorycardscalled“MobileBallotBoxes” (MBBs). Buildingasecurenetworkedsystemofthistyperequiresadoptinganattitudeofdefensein depth: itmustbedesignedandimplementedinsuchawaythatacompromisedcomponentcannot inducemisbehaviorinothercomponentsthatcommunicatewithit. OurexaminationindicatesthatHart’ssystemisnotdesignedalongtheselines. Instead,thede- signofthecomponentsmostlyassumesthatanyothercomponentoftheHartsystem(oranything thatappearstobeone)istrustable: Unsecurednetworkinterfaces NetworkinterfacesintheHartsystemarenotsecuredagainstdi- rectattack.VoterscanconnecttounsecurednetworklinksinapollingplacetosubverteSlates, aswellastoeavesdroponcastvotesandtoinjectnewvotes.PollworkerscanconnecttoJBCs or eScans over the management interfaces and perform back-office functions such as modi- fyingthedevicesoftware. Theimpactofthisisthatamaliciousvotercouldpotentiallytake overoneormoreeSlatesinaprecinctandamaliciouspollworkercouldpotentiallytakeover allthedevicesinaprecinct. Thesubvertedmachinescouldthenbeusedtoproduceanyre- sultsoftheattacker’schoice,regardlessofvoterinput. Weemphasizethatthesearenotbugs intheHartsoftware,butratherfeaturesintentionallydesignedintothesystemwhichcanbe usedinafashionforwhichtheywereneverintended. Vulnerabilitytomaliciousinputs Becausenetworkeddevicesmaybeconnectedtoother, poten- tiallymaliciousdevices,theymustbepreparedtoacceptrobustlyanyinputprovidedbysuch devices. TheHartsoftwareroutinelyfailstocheckthecorrectnessofinputsfromothercom- ponents,andthenproceedstousethoseinputsinunsafeways. Themostdamagingexample ofthisisthatSERVO,whichisusedtobackupandverifythecorrectnessofpollingplacede- vicescanitselfbecompromisedfromthosesamedevices. Thisimpliesthatanattackercould subvertasinglepollingplacedevice,throughitsubvertSERVO,andthenuseSERVOtore- programeverypollingplacedeviceinthecounty. Althoughwehavetestedsomeindividual componentsofthisattack,wedidnothavetimetoconfirmitinanend-to-endtest. Noorinsecureuseofcryptography The standard method for securing network communication ofthetypeinuseintheHartsystemistouseacryptographicsecurityprotocol. However,we i foundanotablelackofsuchtechniquesinHart’ssystem. Instead,communicationsbetween devicesgenerallyhappenintheclear,makingattackfareasier. CryptographyisusedforMBBs,butthekeymanagementinvolvesasinglecounty-widesym- metrickeythat,ifrevealed,wouldallowanattackertoforgeballotinformationandelection results. Thiskeyisstoredinsecurelyinvulnerablepolling-placedevices,withtheresultthat compromiseofasinglepollingplacedeviceenablesanattackertoforgeelectionMBBscarry- ingelectionresultsforanydeviceinthecounty. Failuretoprotectballotsecrecy Hart’s system fails to adequately protect ballot secrecy. A poll worker or election official with access to the raw ballot records can reconstruct the order in which those votes were cast. Combined with information about the order in which voters casttheirvotes,thiscanbeusedtoreconstructhoweachvotervoted. InthecaseoftheDRE, itisalsopossibletoreconstruct,foreachvote,theorderinwhichthevoteswereauthorized. Combinedwithinformationabouttheorderinwhichvoterswereauthorized, thiscanlike- wisebeusedtoreconstructhoweachvotervoted. Furthermore,avoterwhohastemporary access to an eSlate device can extract and reconstruct all the votes cast on that device up to thatpointintime. HemaybeabletosimilarlyreconstructallvotescastonanyothereSlate connectedtothesameJBC. Manyoftheseattackscanbemountedinamannerthatmakesthemextremelyhardtodetect andcorrect. Weexpectthatmanyofthemcouldbecarriedoutinthefieldbyasingleindividual, withoutextensiveeffort,andwithoutlong-termaccesstotheequipment. A manual examination of the paper trail would act as a defense against some of our attacks; othersmaybemitigatedbyneworexistingproceduralcontrolsbyelectionofficials,orbychanges totheHartsystem.Wherereasonable,weattemptedtoidentifysuchmitigationsandtoassesstheir effectiveness. Insomecases,theremaybenosimple,effectivefixes. We have deliberately avoided addressing the broader issue of whether or how this system should be used for voting in California. Making that judgement requires assessing not only the technicalissuesdescribedinthisreportbutalsotheproceduresandpolicieswithwhichthesystem isused. ii Table of Contents 1 Introduction 1 1.1 SystemOverview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 1.2 Methodology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 2 Limitations 4 3 ThreatModel 7 3.1 ReferenceModel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 3.1.1 Pre-Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 3.1.2 Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 3.1.3 Post-Voting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 3.2 AttackerGoals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 3.2.1 ProducingIncorrectVoteCounts . . . . . . . . . . . . . . . . . . . . . . . . . . 10 3.2.2 BlockingSomeorAllVotersfromVoting . . . . . . . . . . . . . . . . . . . . . 11 3.2.3 ViolatingBallotSecrecy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 3.3 AttackerTypes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 3.3.1 Outsiders . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 3.3.2 Voters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 3.3.3 PollWorkers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 3.3.4 ElectionOfficials . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 3.3.5 VendorEmployees . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 3.4 TypesofAttacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 3.5 MechanismsforTamperSealing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 4 OverviewofSystemArchitecture 19 4.1 Pre-Election . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 4.2 PreparingVotingDevices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 4.3 Election-DaySetup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 4.4 AuthorizingandCastingVotes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 4.5 VoteCollectionandTallying . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 4.6 Post-ElectionAuditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 5 ArchitecturalIssues 24 5.1 AuthenticationFailures. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 5.2 LeastPrivilegeViolations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25 5.3 InputValidation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 5.4 MisuseofCryptography . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 6 DetailedAnalysis 28 6.1 DeviceManagement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 6.2 eSlate-JBCCommunication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 6.2.1 DetailedDescription . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 6.2.2 TappingtheInterface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 iii 6.2.3 HijackingtheInterface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 6.3 SoftwareIntegrityChecks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42 6.4 BufferManagementVulnerabilitiesinBack-EndSystems . . . . . . . . . . . . . . . . 46 6.5 PrivilegeIssuesinBack-endSystems . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48 6.6 Windows-relatedVulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 6.7 CryptographicKeyManagement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 6.8 MBBVoteStorage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58 6.9 Rally/Tally’sUseofTLS/SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64 6.10 VerifiedBallotOptionIssues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67 6.11 CodeQualityandMiscellaneous . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69 7 AttacksontheFullSystem 72 7.1 CompromisingVoterPrivacy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72 7.1.1 VoteBuyingoneSlateSystems . . . . . . . . . . . . . . . . . . . . . . . . . . . 72 7.1.2 VoteBuyingoneScanSystems . . . . . . . . . . . . . . . . . . . . . . . . . . . 73 7.1.3 InformationGathering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73 7.2 AlteringtheFinalVoteCount . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74 7.2.1 eScan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74 7.2.2 eSlate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74 7.2.3 VotinginOtherPrecincts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76 7.2.4 DenialofService . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76 7.3 SubvertingallDREDevicesinaPrecinct . . . . . . . . . . . . . . . . . . . . . . . . . . 77 7.4 SubvertingalltheDevicesinaCounty . . . . . . . . . . . . . . . . . . . . . . . . . . . 77 8 DetectionandRecovery 79 8.1 Detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79 8.1.1 TheOnePercentManualRecount . . . . . . . . . . . . . . . . . . . . . . . . . 80 8.1.2 TotalVoterCounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80 8.1.3 MechanicalLogComparisons . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81 8.1.4 TamperSeals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81 8.1.5 ParallelTestingandLogicandAccuracyTesting . . . . . . . . . . . . . . . . . 81 8.1.6 FirmwareForensics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82 8.2 Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82 9 RecommendationsforFutureAnalysis 84 9.1 TimeLimitation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84 9.2 InadequateInformationaboutProcedures . . . . . . . . . . . . . . . . . . . . . . . . . 84 9.3 InsufficientAccesstoMaterials . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85 9.4 DifficultyinTestingHypothesesaboutSystemOperation . . . . . . . . . . . . . . . . 86 10 SummaryofFindings 87 Bibliography 88 A SystemComponentsandVersions 92 iv List of Issues Issue1 TheJBCismanagedviaanaccessibleparallelport. . . . . . . . . . . . . . . . . . . 30 Issue2 TheeSlateismanagedviaaserialportconnectedtotheJBC . . . . . . . . . . . . . 31 Issue3 TheeScanismanagedviaanaccessibleEthernetport . . . . . . . . . . . . . . . . . 32 Issue4 TheJBCvoterregistrationinterfacecanbeusedtogeneratevoteraccesscodes . . 32 Issue5 eSlate-JBCcommunicationisinsecure . . . . . . . . . . . . . . . . . . . . . . . . . . 37 Issue6 FormatstringvulnerabilitiesinJBCreportmode. . . . . . . . . . . . . . . . . . . . 39 Issue7 TheJBCaccesscodegeneratorisinsecure . . . . . . . . . . . . . . . . . . . . . . . . 40 Issue8 TheJBCwillacceptvotesfromeSlatesthatarenotinanauthorizedstate . . . . . 41 Issue9 eSlate/JBCinternalCRCchecksdonotdetectattacks . . . . . . . . . . . . . . . . . 42 Issue10 JBCinternalversioncheckingisbroken . . . . . . . . . . . . . . . . . . . . . . . . . 43 Issue11 SERVO-baseddevicefirmwarecheckingcanbespoofed . . . . . . . . . . . . . . . 43 Issue12 JBC-basedeSlatefirmwarecheckingcanbespoofed . . . . . . . . . . . . . . . . . . 45 Issue13 MultiplebufferoverflowsinSERVO . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 Issue14 AnimproperlyformattedMBBwillcauseRallyorTallytocrash. . . . . . . . . . . 47 Issue15 Databasepasswordsarestoredinsecurely . . . . . . . . . . . . . . . . . . . . . . . 48 Issue16 BallotNowcountersarestoredindatabase . . . . . . . . . . . . . . . . . . . . . . . 49 Issue 17 The Tally interface allows a Tally administrator to “adjust vote totals.” This can createinconsistenciesinthereportedvotetotals. . . . . . . . . . . . . . . . . . . . . 49 Issue18 Databasesarenotencrypted . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 Issue19 Newuserscanbeaddedviathedatabase . . . . . . . . . . . . . . . . . . . . . . . . 51 Issue20 Back-endWindowssystemsmaybeinsecure . . . . . . . . . . . . . . . . . . . . . . 52 Issue21 ManyHartsystemsareconnectedtointernalnetworksormodems,openingthem toattacksagainstWindows’vulnerabilities. . . . . . . . . . . . . . . . . . . . . . . . 53 Issue22 ThesamesymmetriceCMkeyisusedcounty-wide . . . . . . . . . . . . . . . . . . 55 Issue23 ECMkeysarestoredinsecurelyontheeCMmanager . . . . . . . . . . . . . . . . . 56 Issue24 eCMkeysareextractedandstoredinsecurely . . . . . . . . . . . . . . . . . . . . . 57 Issue25 Voteordercanbedetermined . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58 Issue26 MBBisnotprotectedduringvoting . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Issue27 HandlingofprecinctIDsinCVRs . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61 Issue28 UserscanreadunclosedMBBsorMBBswithinvalidMACs . . . . . . . . . . . . . 62 Issue29 Theprotectivecounterissubjecttotampering . . . . . . . . . . . . . . . . . . . . . 63 Issue30 IftwoMBBshavethesameID,Tallyonlyreadsthefirstone . . . . . . . . . . . . . 63 Issue31 RallyandTallyuseanoldversionofOpenSSLwithknownbugs. . . . . . . . . . . 64 Issue 32 Rally and Tally, when presented with an unknown certificate, will present the unauthenticatednameandorganizationtotheuserforverification. . . . . . . . . . 66 Issue33 VBOxprintingandscrollingiscontrolledbytheeSlate . . . . . . . . . . . . . . . . 67 Issue34 TheVBOxcodeindicatesareversefunction . . . . . . . . . . . . . . . . . . . . . . 68 Issue35 TheVBOxvotesaresequentialandsocompromisevoteprivacy . . . . . . . . . . 69 Issue36 Pervasivefailuretofollowcommonlyagreedsafecodingpractices . . . . . . . . . 69 v CHAPTER 1 Introduction ThisreportwaspreparedbytheUniversityofCalifornia,BerkeleyattherequestoftheCalifornia SecretaryofState,aspartofa“top-to-bottom”reviewofthestate’selectronicvotingsystems. This documentisthefinalreportoftheteamthatexaminedtheHartvotingsystemsourcecode. TheHartsystemsourcecodereviewteamwaslocatedatSRIInternationalinMenloParkand consisted of the four authors of this report: Srinivas Inguva, Eric Rescorla, Hovav Shacham, and DanWallach. WefrequentlyconsultedwiththeUCBerkeley-baseddocumentationteam1 andthe Sacramento-based“RedTeam”2. Allopinionsexpressedinthisreport,however,aresolelythoseof itsauthors. We started work on June 15, 2007 and received the Hart system source code on June 18, 2007. WorkendedonJuly20,2007withthedeliveryofthisreport. 1.1 System Overview TheHartsoftwarewereviewedispartofacomprehensivesystemthatincludesDirectRecording Electronic (DRE) voting machines and optical scan ballot collection equipment for use at polling places,aswellaselectiondefinition,managementandcountingsoftwareandhardwareforuseat acountyelectionsheadquarters. ThespecificsystemcomponentscertifiedforuseinCaliforniafor which we reviewed source code were from Hart system version 6.2.1, comprising the following components: • BallotNow,version3.3.11 • BOSS,version4.3.13 – BossUtil,version2.5.8 – TranslateDLL,version1.8.2 • eCMManager,version1.1.7 • eScan,version1.3.14 • eSlate,version4.2.13 • HartLib,version4.0 • JBC,version4.3.1 • Rally,version2.3.7 • SERVO,version4.2.10 1JosephLorenzoHallandLauraQuilter 2RobertAbbott,MarkDavis,JosephEdmonds,LukeFlorer,BrianPorter,ElliotProebstel,SujeetShenoi,andJacobStauf- fer 1 1. Introduction • Tally,version4.3.10 • VBOPrinterFirmware,version1.8.3 The centralized back-end processing functions (ballot preparation, voting machine configura- tion,andpost-electionvotecounting)areperformedbyBOSS,BallotNow,Tally,andSERVO,which are all software running on Windows-based PCs. Cryptographic keys are distributed on eSlate CryptographicModules(eCMs)whicharemanagedusingtheeCMManager, whichalsorunson Windows. Precinct polling stations can be equipped with DRE terminals, optical scan ballot readers or both. Normally, precinct-based optical ballot scanning is performed with Hart’s eScan systems while central optical ballot scanning is performed with Hart’s Ballot Now.3 DRE voting uses a networkofeSlatescontrolledbyasingleJBC.ResultsarereturnedtoElectionCentralusingMobile Ballot Boxes (MBBs), which are standard PCMCIA memory cards. Election results can also be returned using the Rally software, which transmits them to Tally via modem connections from regionalprocessingfacilities. The software comprises approximately 360K lines of source code, written primarily in C++, C, and PowerBuilder. The back-end software runs on Microsoft Windows. The eScan runs on WindowsCEoncustomembeddedhardware.TheeSlatesandJBCsrunonanembeddedoperating systemoncustomembeddedhardware. (Wewerenotprovidedwithsourcecodetoanyofthese operatingsystems.) AdetaileddescriptionofthesystemarchitectureandoperationcanbefoundinSection4. 1.2 Methodology Discovery of programming errors is a notoriously difficult problem in computer science, and no general methodology exists that is guaranteed to find all problems in even very small programs. The large size and complexity of the Hart InterCivic system makes a complete review an espe- ciallydauntingtaskundereventhebestconditions,butparticularlysoheregiventhelimitedtime availableandtheotherconstraintsimposedonusbythetermsofthereview. Our focus was on whether the software contains effective safeguards against error and abuse aimed at altering election results, changing votes, denying service, altering audit logs, and com- promisingvoters’ballotsecrecy. Morebroadly,weexploredissuesrelatedtoourconfidenceinthe securityandreliabilityofthearchitectureandimplementationasawhole.Ingeneral,inourreview weattemptedtoexplorequestionsofarchitecturalsoundness: • Doesthedesignandimplementationfollowsound,generallyacceptedengineeringpractices? Is code defensively written against bad data, errors in other modules, changes in environ- ment,andsoon? • Isthecryptographyandkeymanagementsound? Iscryptographycorrectlyusedtoprotect sensitivedataonuntrustedmedia? Doesthecryptographyemploystandardalgorithmsand protocols? Arekeysmanagedaccordingtogoodpractices? • Whatarethetrustedcomponentsofthesystem,whenaretheytrustedandforwhatpurposes? Whatpartiesaretrustedandforwhatpurposes? Whataretheimplicationsofacompromise oftrustedcomponents? • Aresecurityfailureslikelytobedetected?Areauditmechanismsreliableandtamper-resistant? Aredatathatmightbesubjecttotamperingproperlyvalidatedandauthenticated? Our review of the source code was focused on answering these questions, rather than exam- iningtheentirecodebase. Wewereparticularlyinterestedinissueswhichallowanuntrustedor 3“BallotNowistobeusedonlyascentralprocessingapplication[sic]andisnottobedeployedtoremotelocations outsideofcentraljurisdictionelectionheadquarters.”[21],page33. §1.2Methodology 2 1. Introduction minimallytrustedusertoescalatehiscapabilitiesbeyondthoseforwhichhewasauthorized. We alsoattemptedtofocusonissuesthatwouldrequiresubstantialrearchitectingtofixratherthanon individualvulnerabilitiesunlesstheywerereflectiveofsystematicdesignorarchitecturalissues. Weusedavarietyoftoolstosupportouranalysis. Weusedanopensourcewikionoursecure networktosummarizeandtrackthevarioussoftwareissuesunderinvestigationandtoprovidea commonknowledgebaseamongtheteammembers4. WeusedtheFortifySCAstaticanalysistool toidentifypotentialproblemareasinpartsoftheHartInterCivicsoftware. (WearegratefultoFor- tifySoftwareformakingthetoolavailabletous.)Variousdebuggers,programeditors,decompilers andothertoolswereusedtoexperimentwithandconfirmsoftwarestructureandbehavior. We have deliberately avoided addressing the broader issue of whether or how this system should be used for voting in California. Making that judgement requires assessing not only the technicalissuesdescribedinthisreportbutalsotheproceduresandpolicieswithwhichthesystem isused. 4Thecontentsofourwikiweresubmittedastheprivateannextothisreport. §1.2Methodology 3 CHAPTER 2 Limitations Ouranalysisfocusedonsystemdesignandarchitecture. Althoughsourcecodewasavailable,the largesizeofthecodebaseandthelimitedtimeavailableprecludedacomprehensivereviewofthe sourcecode. Nosecurityanalysiscanguaranteediscoveryofallsystemvulnerabilities;duetothe short timeframe, this analysis is even more limited. Therefore, no assertions can be made about nonexistenceofparticularvulnerabilitiesinthesource. Wemadeagood-faithefforttoidentifyand prioritizesecurityvulnerabilitiesbasedongenerallyknownandacceptedsecurityprinciples, but wecautionthatadditionalvulnerabilitiesmayexistthatarenotdocumentedinthisreport. Wedidnotattempttoverifythatthevotingsoftwareiscompletelyfreeofdefectsortoexhaus- tivelyenumeratealldefects,asthatexceedswhatisfeasiblewiththestateofart: • ThescaleoftheHartInterCivicsystemmakesacomprehensivereviewinfeasible. TheHart InterCivic system contains over 300,000 lines of code (See Appendix A for details), which wouldhavebeenimpracticaltoreviewinthetimeallowed. • Even thorough manual code review misses many problems. People are fallible; a code re- viewermightoverlookadefectinthecodethesamewaythatthedeveloperwhowrotethe codedid. Amanualreviewthatfoundhalfofallproblemsinthecodewouldbedoingpretty well, by industry standards, but that would still leave many undetected defects. Moreover, manualcodereviewoftenmissesarchitecturalflawsandotherissuesthatdonotclearlyman- ifestthemselvesattheimplementationlevel. • Manual source code inspection is laborious, time-intensive, and costly. A rough estimate is thatatrainedsoftwareengineercaninspectsomethinglike100linesofcodeperhour,under optimal conditions. If team members did nothing other than read source code for hours on end—somethingthatfewdeveloperscansustainforanylengthoftime—thenitwouldhave taken us a person-year or more of effort to read all of the source code. That would have significantlyexceededourbudgetandthetimeavailabletous. • We made no attempt to find all bugs or vulnerabilities in the code. Once we found several relatedvulnerabilitiesinthesameportionofthecode,westoppedlookingforothervulner- abilities of the same type. We made no attempt to catalog all bugs that might enable any particularkindofattack. Instead,westructuredouranalysisasanattempttofindevidence to confirm or refute the hypothesis that the voting system is secure from tampering. Once wefoundstrongevidencethatsomeaspectofthesystemwasvulnerabletoacertainkindof tampering,wemovedontoexaminesomeotheraspectofthesystem. Thismethodologywas selectedduetothelimitedtimeavailableforthisreviewandbecauseitseemstomakelittle differencewhetheranattackerhas3or30differentattackvariationsavailabletohimifallthe variationshavethesameimpact. As a consequence, the list of issues and defects in this report should not be taken as a compre- hensivelist. Inourreview,wesingledoutalimitedsubsetofthecodeasespeciallycritical,based onourarchitecturalanalysis,andthensubjectedthatportionofthesourcecodetointensivecode 4 2. Limitations inspection. Sincewedidfindsecurityvulnerabilitiesinthesourcecodethatwassubjecttoinspec- tion,onemightanticipatethattherestofthecodethatwedidnothavetimetoinspectmightalso containvulnerabilities. Forthisreason,itislikelythatthisreportunderestimatesthetruenumber ofvulnerabilitiesinthecode,anditispossiblethattheissuesidentifiedinthisreportmightrepre- sentonlythe“tipoftheiceberg.” However,becausewewereonlyabletoinspectasmallfraction ofthecode,wesimplydonotknowwhethertherestofthecodecontainssecurityvulnerabilities. Because the time available for this report was so short, we were unable to perform as com- plete testing for each issue as we would have liked. Instead, we prioritized issues based on our estimatesofpotentialseverityandourconfidenceinouranalysisofthecode. Thisallowedusto directly confirm some issues and to partially confirm others. However, this still leaves a number of issues which we did not have time to confirm and others for which we would have wished to perform more tests. For each issue we discuss, we also describe the experiments (if any) we per- formed to confirm it, allowing the reader to draw their own conclusions. In many cases, issues werediscoveredinthesourcecodewithoutconfirmationonactualHartsystems. Forsuchissues, wedescribeourrelativeconfidenceineachonebeingaviableattack. The analysis contained in this document is based on data gathered from documentation and sourcecodeprovidedbyHartInterCivic, theStateofCalifornia, andtheITAs(IndependentTest- ing Authorities). We made no attempt to validate the materials provided to us. Our conclusions depend on interpretation of those documents and source code. To the extent to which those ma- terials are incomplete, inaccurate, or do not reflect the systems and practices currently in use in California,thismayleadtomaterialinaccuraciesinthisreport. There was some software that we were not provided and thus did not review. The software whosesourcecodewebelievewasnotmadeavailabletousislistedinAppendixA.However,we donothaveacompletelistofthesoftwarethatisusedinthevotingsystembutwhosesourcecode wasnotprovidedtous. Weunderstandthatsomeofthissoftware,suchasthestandardClibraries, maybeclassifiedasunmodifiedCOTS(commercialoff-the-shelf)softwareunderthefederalvoting standards and thus may be exempt from scrutiny by the ITAs (Independent Testing Authorities). Other software was apparently written by Hart InterCivic but was not made available to us. In theabsenceofsourcecodetotheCOTSsoftware,wewerenotabletoverifywhetheritqualifiesas unmodifiedCOTSundertheprovisionsofthefederalvotingstandards. Itwasbeyondthescope of this review to evaluate whether any of the missing source code falls within the definition of unmodifiedCOTSsoftware,asdefinedinthefederalvotingstandards. Wemadenoattempttoverifythatthesourcecodeprovidedtousmatchesthebinarycodethat isexecutedonelectiondayintheHartInterCivicvotingequipment. Thatwasbeyondthescopeof this review. Also, while we were provided with binary executables for some of this software, we werenotprovidedwithafullbuildenvironmentthatwouldenableustocompilethesourcecode forourselvesandverifythattheresultswereidenticaltothebinaryexecutablesprovidedtous. Wemadenoattempttosearchforsecurityproblemsinthehardware. Thatworkwasdoneby aseparate“RedTeam.” Instead,ouranalysiswasbasedonanalyzingthesourcecodeprovidedto us. Wedidnotattempttosearchforconfigurationproblemsortoanalyzewhetherthevotingsys- tem, as installed in California counties, is configured correctly. This was out of the scope of this workandwedidnothaveaccesstoanycounty’sHartinstallationsinanycase. We did not attempt to analyze the procedures, processes, or practices used by local election officialsforpotentialsecurityproblems. Weweregivenoperator’smanualsfortheHartInterCivic equipment,andwefrequentlyusedthemtogaininsighthowthesystemmightbeusedinpractice. However,wewerenotprovidedwithinformationabouttypicalcounty-levelpractices,limitingour abilitytoexaminehowthevotingsystemisusedinthefieldandhowthosepracticesmayenable orhindersecurityattacks. Thesecurityofavotingsystemdependsuponboththetechnology(e.g., thesoftware)aswell asuponhowitisused(e.g.,theprocessesandproceduresinplace). Wewereaskedtofocusinthis reviewprimarilyonthesoftwareandaccompanyingdocumentation,notonhowitisused. There- fore, any potential issues we identify in this report might or might be relevant to any particular useroftheequipment,dependinguponthepracticesinplaceinthatjurisdiction. Itwouldrequire 5 2. Limitations aseparate,follow-onstudytoevaluatetheimpactoftheseissuesonindividualCaliforniacounties andotherusersofthisvotingsystem. ThescopeofthisworkwaslimitedtoanalysisoftheHartInterCivicvotingsystem,notthatof California’sentireelectionsystem. Forinstance, voterregistrationsystems, countypractices, and electionlawwereoutsidethescopeofthisstudy. Our analysis was limited to a particular version of the Hart InterCivic voting system. This reportisnotintendedasanendorsementorrepudiationofelectronicvotingingeneral. 6 CHAPTER 3 Threat Model The first step in security analysis of a system is to define the threat model. The threat model for a systemisintendedtodescribethegoalsanattackermighthave(e.g.,tomanipulatethevotecount) andthetypesofattackersthatmightattempttoattackthesystem(e.g., voters, pollworkers, etc.) aswellasthecapabilitiesavailabletoeachtypeofattacker. Itisequallyimportanttodescribethe threats that are out of scope for the analysis. This study was chartered to consider the security of voting systems proper only, not that of California’s entire election system, and therefore many possibleattacksareoutofscopeforthisreport. 3.1 Reference Model In order to simplify the analysis, we assume a common reference model, which distills what are hopefully the essential features of all of the voting systems involved in this study. The system consistsofthefollowingcomponents. Inthepollingplace: • Managementstations(MS) • Direct recording electronic (DRE) voting machines, attached to Voter Verified Paper Audit Trail(VVPAT)printers • Paperballotopticalscanners(opscan) AtElectionCentral: • Anelectionmanagementsystem(EMS) • High-speedpaperballotopticalscanners(e.g.,forabsenteevotes) Theelectioncanbethoughtofasproceedinginthreestages(forsimplicity, weareignoringearly votingcenters): Pre-voting: Beforeelectionday,electionofficialsusetheEMStosetuptheelection. Theygenerate theballotdefinition(s)andrecordthemontomediafordistribution. Duringthisstage,voting machinesarealsopreparedanddistributedtopollingplaces. Voting: Onelectionday,votersarriveatthepollingplace,areverifiedasbeingpermittedtovote, andcasttheirballots. Post-voting: Afterthepollsareclosed,thevotesaretallied,theofficialcanvass(includingtheone percentmanualrecount)isperformed,andtheresultsarecertified. TherelationshipbetweenthesecomponentsisshowninFigure3.1. 7 3. ThreatModel EMS n o B Results Results fi niti allot D Results all ot d e efi nition B VVPAT DRE MS OPSCAN Token/ Marked Token Votes Ballot DRE Token Poll Ballot Opscan Voter Worker Voter Figure3.1: Referencearchitecture 3.1.1 Pre-Voting Inthepre-votingphase,electionofficialsneedto: • Createtheelectiondefinition. • Printthepaperballotsusedforopticalscansystems. • Resetthelocalvotingequipmentandpotentiallyloadtheelectiondefinitions. • Distributethelocalvotingequipmenttothepollingplaces. There is some variation among voting system vendors, but in general the EMS is used to cre- ate the ballot definition files. These are then loaded onto some memory card/cartridge and/or directlyontothevotingmachines. Thevotecountersinthemachinesarereset,theinternalclocks are set to the correct time, and the machines are then shipped out to the local polling places or provided to poll workers to be hand-carried to the polling place. The ballot definition files must beprotectedfromtamperingandsomemorycard/cartridgesaregenerallydistributedwithsome physicalsecuritymeasures,eitherbysealingthemintothelocalequipmentatthecentralofficeor bydistributingtheminasealedpackage. Sealsmaytaketheformoftamper-evidenttapeormay take the form of metal or plastic loops, individually numbered, which once installed can only be removedbycuttingthem. 3.1.2 Voting Oncethepollsopenonelectionday,votingcanbegin. Theexactdetailsofthevotingphasediffer with the technology and manufacturer in use, but there is a fair amount of commonality across manufacturerswithinagiventechnology(DRE,opscan). §3.1ReferenceModel 8 3. ThreatModel Opticalscanmachines. Opscanvotingcanmosteasilybethoughtofasmachine-countedpaper ballots. Alltheproceduresherecouldbereplicatedbyhumanswithappropriateauditcontrols. When an opscan voter enters the polling place, and is verified as permitted to vote, he or she is given a blank paper ballot. He or she marks the ballot with a pen or pencil and the ballot is thenmechanicallycountedwithanopticalscanner. Thiscanbedoneeitherlocallyorcentrally. In thelocalcase,theprecincthasascannerwhichcountstheballotsastheyareinserted. Ingeneral, thevoterpersonallyinsertstheballotintothescanner. Precinct-basedopticalscannerscandetect “overvoting” and reject such ballots, giving the voter an opportunity to correct the error. At the end of the day, the scanner’s electronic records are then sent back to the county for aggregation withrecordsfromotherprecincts. Thepaperballotsarealsosentback,forauditingandrecounts. Withcentralcounting,untabulatedballotsintheiroriginalballotboxaresentbacktoElection Central(i.e.,thecounty’selectionheadquarters)wheretheyaretabulatedwithahigh-speedscan- nerundersupervisionoftheelectionofficials.Centralandprecinct-basedtabulationmaybemixed inavarietyofways. Centraltabulationisnaturallyusedforabsenteeballotsandcanalsobeused forauditsandrecountsofprecinct-castballots,whetherornottheywereoriginallytabulatedinthe precinct. DREmachines. DREvotingisfundamentallydifferentfromopscanvoting. Insteadofentering their vote on paper, the voter uses a computer-based graphical user interface (GUI). Once the vote has been “cast,” an electronic records of the vote is stored locally, in the DRE machine (and, in the case of the Hart system, a copy is also stored in the management station). At the end of the day,theseelectronicrecordsmayeitherbeextractedfromtheDREmachinesonmemorycards,or maybetransmittedviamodems,ortheDREsthemselvesmaybetransportedtoElectionCentral. In any case, the EMS will collect the electronic records from each precinct and will tabulate them electronically. Aswithopscanvoting,inDREvoting,thevoterentersthepollingplaceandfirstestablisheshis orhereligibilitytovote. However,somemethodmustbeusedtolimitauthorizedvoterstocasting onlyonevote. InalltheDREsystemsinthisstudy,thepollworkerusesanadministrativedevice toissuethevoteratokenofsomesort. Thevotermaythentakethistokentoanyvotingmachine and vote once. With Diebold and Sequoia, the token is a smartcard. With Hart, it is a four-digit “AccessCode.” Oncethevotingmachineisactivated,ittakesthevoterthrougheachcontestandallowshimor her to select candidates. DRE machines automatically forbid overvotes (too many votes cast in a contest)butnotundervotes(toofewchoicescastinacontest). Thevoteristhenpresentedwithan opportunitytoreviewhisballotandthencommitstoit(“casts”it),atwhichpointitisrecordedto localstorage. In California, a voter-verified paper audit trail (VVPAT) is required. On all the machines under study,thistakestheformofasealedprinterwithacontinuousspoolofpaperattachedtotheDRE. Beforethevoterconfirmshisballot,asummaryisprintedoutontheprinteranddisplayedthrough a glass window. Once the voter accepts or rejects the ballot, an appropriate indication is printed on the VVPAT record. When the voter casts the ballot, the VVPAT record is marked as accepted and scrolled out of sight. Because the paper scroll is held behind glass, it becomes more difficult for a voter to “stuff” additional ballots into the machine or to take the record of their vote home, incorrectly,as“receipt.” Once the election is over, the local results are transmitted to the Election Central, typically by shipping some form of removable memory device from the voting machine. The VVPAT paper rolls, perhaps still sealed in their printers, are also sent to the Election Central to be used in the legallyrequired1%audit. In larger counties, many vendors offer the ability to establish “regional processing centers.” Election results are delivered by courier from the precincts to the centers, aggregated, and then communicatedbacktoElectionCentralviaelectronicmeans(modems,Internetconnections)orvia courier. §3.1ReferenceModel 9 3. ThreatModel Typicaldeployments. Therearetwocommonmodelsfordeployingthisequipmentinthepolling place. In the DRE-only model, every polling place contains some number of DREs, most or all votersvoteontheDREs,andtherearenoopticalscanmachinesinthepollingplace. Inthehybrid model, everypollingplacecontainsoneopticalscanmachineandoneormoreDREs; votersmay have the option whether to vote on paper ballots or using the DRE, or the DRE may be reserved for voters with disabilities and all others may vote on paper ballots. In California, each county determineswhichmodelismostappropriatefortheirneeds. 3.1.3 Post-Voting Aftertheelectionisovertheelectionofficersneedtodo(atleast)threethings: 1. Tabulatetheuncountedopscanandabsenteeballots. 2. Producecombinedtalliesforeachcontestbasedontherecordsreceivedfromtheindividual precinctsandthetalliesofcentrallycountedballots. 3. Perform the official canvass. This may involve reconciling the number of voters who have signed in against the number of ballots cast, performing the statutory 1% manual recount, andothertasks. Thefirsttwotasksarerelativelystraightforward,thoughit’simportanttonotethatthesecond task is typically performed based on electronic records. In the most common case, the precincts sendbackmemorycardscontainingtheelectionresultsandthosecardsareaddeddirectlytothe tallywithoutanyreferencetothepapertrail(except,ofcourse,forcentrallytabulatedopscanand absenteeballots). The1%manualrecountcomparesthepaperrecordsforagivensetofvotestothereportedvote totals. Inthecaseofopscanballots,thismeansmanuallyassessingeachopscanballot. Inthecase ofDREs,itmeansmanuallyassessingthevotesontheVVPATrecords. Notethatwhileinprinciple theopscantallymaydifferslightlyfromthepaperballotsduetovariationinthesensitivityofthe mark/sensescanner,theVVPATrecordsshouldexactlymatchtheDRErecords. 3.2 Attacker Goals Atahighlevel,anattackermightwishtopursueanyofthefollowinggoalsorsomecombination thereof: • Produceincorrectvotecounts. • Blocksomeorallvotersfromvoting. • Violatethesecrecyoftheballot. An attacker might wish to pursue any of these goals either generally or selectively. For example, anattackermighttargetacertainsubsetofvoters(e.g.,registeredRepublicans,orvoterswholive withinacertaingeographicarea)toattack. Also,theabilitytodeterminehowanindividualvoted canbeusedtoenablevotebuyingorvotercoercion,eitherindividuallyorenmasse. 3.2.1 ProducingIncorrectVoteCounts Themostobviousattackonavotingsystemistoproduceincorrectvotecounts. Anattackerwho cancausethevotestoberecordedorcountedinawaythatisdifferentfromhowpeopleactually votedcanaltertheoutcomeoftheelection. Thereareanumberofdifferentwaystoinfluencevote counts,including: • Confusevotersintovotingdifferentlythantheirintent. §3.2AttackerGoals 10 3. ThreatModel • Alterthevotes,withinthecomputer,beforetheyarerecorded. • Altervotesinthevotestoragemedium,aftertheywereoriginallyrecorded. • Corruptthevotetabulationprocess. Whichattacksarefeasibledependsontheattackercapabilities. 3.2.2 BlockingSomeorAllVotersfromVoting Twoclassicaltechniquestoinfluenceelectionoutcomes, regardlessoftheelectiontechnologiesin use,arevotereducation/encouragement(i.e.,“getoutthevote”)orvotersuppression. Ifwelimit the context to attacks specifically on voting systems, an attacker might mount a similar attack by makingitverydifficultforcertainclassesofvoterstovote. Forexample,anattackermight: • Arrange for some subset of machines to malfunction, possibly those in precincts in which votersoftheoppositepartyareoverrepresented. • Arrangeformachinestoselectivelymalfunctionwhenvotersattempttovoteinacertainway. • Arrangeforallthemachinesinanelectiontomalfunction. Thefirsttwooftheseattacksareselectiveattacksandcouldbeusedtoinfluencetheoutcome of an election. A more global attack is primarily useful for denial-of-service or to invalidate an election,butcouldpotentiallybeusedforextortionaswell. Theseattackswouldgenerallyrequire tamperingwiththesoftwarewithinthevotingmachines. 3.2.3 ViolatingBallotSecrecy Anattackerwhocannotinfluencevotingdirectlymightstillbeabletodeterminehowindividuals orgroupsvoted. Therearetwonaturalapplicationsforthiskindofattack: • Votebuying/votercoercion • Informationgathering Inavotebuyingorvotercoercionattack,theattackerpaysindividualvoterstovoteinaspecific wayorthreatensretributioniftheydonot. However,inorderforsuchanattacktobesuccessful, theattackerneedstobeabletoverifythatthevoterinfactvotedthewayheagreedto. Notethat the buyer does not need to be able to determine with absolute certainty how a voter voted, but merelyneedsahighenoughconfidencethatdefectionbybribedvotersbecomesunattractive. The primary benefit of traditional secret-ballot voting is that that it allows the voter to cast a vote in completesecrecy, defeatingtheattacker’sabilitytovalidateavoter’scastballotandthusmaking votebuyingorcoercionunattractive. Another possible reason to violate voter secrecy is to gather information on a large group of people. Forexample,anattackermightwishtodeterminewhichvotersweresympathetictoapar- ticularpoliticalparty(buthadnotregisteredwithit)andtargetthemforinvestigation,surveillance, or even targeted mail or telephone solicitations. Alternately, an attacker might wish to publish a given voter’s votes in an attempt to influence public opinion about them. In either case, ballot secrecyisrequiredtoblocktheseattacks. 3.3 Attacker Types Avotingsystemcanbesubjecttoattackbyanumberofdifferenttypesofattackerswithdifferent capabilities and who will therefore be able to mount different kinds of attacks. We consider the followingbroadclassesofattackers,listedroughlyinorderofincreasingcapability. §3.3AttackerTypes 11 3. ThreatModel Outsiders have no special access to any of the voting equipment. To the extent that voting or tabulation equipment is connected to the Internet, modems, wireless technologies, and so forth,anattackercanmountnetworkormalware-basedattacks. Outsidersmayalsobeable to break into locations where voting equipment is stored unattended and tamper with the equipment. Voters havelimitedandpartiallysupervisedaccesstovotingsystemsduringtheprocessofcasting theirvotes. Pollworkers haveextensiveaccesstopollingplaceequipment,includingmanagementterminals, before,during,andaftervoting. Electionofficials haveextensiveaccessbothtotheback-endelectionmanagementsystemsaswell astothevotingequipmentthatwillbesenttoeachprecinct. Vendoremployees have access to the hardware and source code of the system during develop- ment and may also be called upon during the election process to assist poll workers and electionofficials. Note that these categories are not intended to be mutually exclusive—a given attacker might havethecapabilitiesofmorethanonecategory. Forexample,itmightbepossibletocombinethe limitedphysicalaccessavailabletoavoterwithanetworkattacksuchasanoutsiderwouldmount. Inaddition,notallmembersofagivenclasshaveidenticalcapabilities;anon-sitevendoremployee hasadifferentlevelofaccessthananemployeewhoonlyworkswiththesourcecode.However,the purposeofthisclassificationistoguideanalysis,nottoprovideacompletetaxonomyofattackers. A particular focus of security analysis is privilege escalation. In many cases, one participant in thesystemisforbiddentoperformactionswhicharenormalforanotherparticipantinthesystem. A key feature of a secure design is enforcing such restrictions. For example, a voter should only be allowed to vote once, but poll workers are in charge of allowing people to vote and therefore mustbeabletoauthorizenewvoterstoaccessthesystem. Avoterwhowasabletouselegitimate access to the voting terminal to acquire the ability to authorize new voters would be an example ofprivilegeescalation. Similarly,pollworkersareentrustedwithmaintainingtheintegrityoftheir pollingplace. Ifapollworkerwasabletouseauthorizedaccesstoonepollingplacetoinfluence ordisruptthevotingequipmentlocatedinotherpollingplaces,thatwouldbeanotherexampleof privilegeescalation. 3.3.1 Outsiders Anoutsidertothesystemhasnoauthorizedaccesstoanypieceofvotingequipment. Theymaybe completelyoutsidethesystemormaybephysicallypresent(perhapsasanobserver)butnotable tophysicallytouchtheequipment. Suchanattackerhaslimitedcapabilitiesinthecontextofthis review. Theymight,forexample,enterthepollingplacewithgunsandforcefullymanipulatethe voting systems (at least, until the police arrive). This sort of attack is explicitly out of our scope, althoughthe“boothcapture”problemisverymucharealconcernoutsidetheU.S.[27]. Outsiders may have the power to mount network- or malware-based attacks. Both election management systems and the development systems used by the voting vendors typically run on generalpurposeoperatingsystems—Windowsinthecaseofallthesystemsinthisreview. Ifthose machinesareconnectedtotheInternetorconnectedtomachineswhichareoccasionallyconnected totheInternetortheoutsideworldinanyway(laptopsareapopularchannel),anattackermight managetoinfectthesystemsandtherebyalterthesoftwarerunningontheelectionmanagement systems or even the polling place systems. In that case, individuals anywhere in the world may havetheopportunitytoattackthevotingsystem. Outsiders may also have the power to physically tamper with voting equipment. In many counties,votingequipmentisstoredunattendedatthepollingplaceovernightbeforetheelection. Whilepollingplacesmaybelockedovernight,mostpollingplacesarelow-securitylocations;they may be located at a school or church or public building or a citizen’s garage. Consequently, an §3.3AttackerTypes 12 3. ThreatModel attackerwhoiswillingandabletobreakintothepollingplace,eitherbysurreptitiouslypickingthe lockorbyforciblyentering,canlikelyobtainunsupervisedphysicalaccesstothevoterequipment foratleastseveralhours. Thiskindofattackdoesrequiretheoutsidertobephysicallypresentand takeonsomeriskofdiscovery. Wenotethatanoutsidermaybeabletoimpersonateotherrolesinthesystem,suchasavendor representative or an election official. As an example, an outsider might mail CDs containing a malicioussoftwareupgradetotheelectionofficialinpackagingthatcloselyresemblestheofficial packagingfromthevendor. 3.3.2 Voters ItisveryeasytobecomeavoterinCaliforniaandsoitisexpectedthatanyattackerwhowantsto canacquireavoter’scapabilitiesinatleastoneprecinct. Unlikeanoutsider, avoterhasphysical access to a voting machine for a short period of time. That access is partially supervised, so that wewouldnotexpectavotertobeabletocompletelydisassemblethevotingmachine. However, in order to preserve the secrecy of the ballot, it is also partially unsupervised. The details of the levelofsupervisionvarytosomeextentfrommachinetomachineandfromcountytocounty. In particular,thedifferencebetweenopticalscanandDREisrelevanthere. Opticalscanmachines. Inopticalscanvoting,thevotermarkstheballothimselfbuttheballotis simplyaspecialpieceofpaper. Thevotertheninsertstheballotintotheopticalscanequipment, typically under the supervision of the poll worker. Ordinarily, poll workers would be observing voters as they feed their ballots into the scanner. Therefore, the voter probably cannot tamper withthescannerwithoutbeingdetected. ThisdoesnotentirelyprecludevoteraccesstoopenI/O portsonthescannerbutdoesmakeitmoredifficult. Themostlikelyavenueofvoterattackisby the ballot itself. For example, a voter might attempt to have multiple ballots recorded or might markmaliciouspatternsontheballotintendedtosubvertthescanner. Suchspecificpatternscould also be used to trigger a dormant “Trojan horse” (i.e., activate pre-installed malicious software) to induce the machine to begin cheating. Such a compromised machine might otherwise behave correctly. DREmachines. InDREvoting,bycontrast,thevoterhasmostlyunsupervisedaccesstothevot- ing terminal for a significant period of time. The front of the terminal is deliberately hidden by aprivacyscreeninordertoprotectvoters’secrecyandthereforethevoterhastheopportunityto mountavarietyofattacks.Anysectionofthemachinethatisaccessibletoavoterinsidetheprivacy screen,includingbuttons,cardslotsandopenI/Oports,mustbeassumedtobeapotentialpoint ofattack. Thevoteralsohasanopportunitytoinputsubstantialamountsofdatatothesystemvia theofficialuserinterface. Itmaybepossibletousethisinterfacetocompromisethemachine. In all the systems studied here, the voter is also provided with some kind of token used to authorizeaccesstotheDREterminaltoacceptthevoter’svote.IntheSequoiaandDieboldsystems thisisasmartcardandintheHartsystemitisafour-digitaccesscode. Asthevoterhasaccessto thesetokens,theyarealsoapotentialtargetofattackandthevotermightattempttosubstitutehis orherowntokenorsubvertthem(inthecaseofsmartcards). It’simportanttonotethattheprivacyaffordedtovotersbyvotinginapollingplaceisintended tobemandatory,buttherearemanystepsavotermaytake,whilebeingbribedorcoerced,tovi- olate this privacy. This may include the use of cell-phone cameras, the placement of identifying marks on paper ballots, or the placement of unusual voting patterns or specific write-in votes on anyvotingsystem. Votersmayalsobeabletotakeadvantageof“curb-sidevoting,”whereavail- able, tohave privateaccessto avotingmachineinside theircar(wherethey maythenhave tools thatwouldbeinfeasibletobringintoapollingplaceandtheprivacytousethem). BecauseanyUnitedStatescitizenandCaliforniaresidentispotentiallyavoterinCalifornia,it mustbeassumedthatanyattackwhichrequiresonlyvoteraccessispractical. §3.3AttackerTypes 13 3. ThreatModel 3.3.3 PollWorkers Local poll workers have a significant capability that voters do not have: they have legitimate ac- cesstothemanagementcapabilitiesoftheequipment. Forexample,thepollworkerhastheability toauthorizevoterstovote. Notethatalthoughinprinciplethismaygivethepollworkeroppor- tunities for malfeasance, this risk may be mitigated by procedural controls. For example, a poll workerwhocontrolsthemanagementstationcaninprincipleauthorizeavotertovoteanarbitrary numberoftimessimplybyissuingmultipletokens. However,pollingplaceswouldnormallyhave procedures in place to block or at least detect such attacks: because poll workers must perform theirdutiesinpublicview,suchmalfeasancemightbenoticedbyotherpollworkersorothervot- ers;moreover,ifattheendofthedaythereweremorevotescastthanregisteredvoterswhosigned in, that would indicate a problem. Purely technical means may, alone, be insufficient to prevent suchattacks,whileproceduralmechanismsmaybesufficienttoaddresssuchrisks. Dependinguponcountypractices,pollworkersmayalsohavelong-termunsupervisedaccess to voting equipment. In some counties, voting equipment is stored in the houses or cars of in- dividual poll workers prior to the election. For example, some counties provide the chief poll worker at each polling place with DREs or opscan machines to store and deliver to the polling place. Even counties that deliver DREs and opscan machines by commercial transport may pro- vide the chief poll worker with other equipment (smartcards, smartcard activation devices, man- agement consoles, etc.) before the election. And even if equipment is stored in a secured polling place, dual controls may not be in place to prevent individual poll workers from accessing the areaontheirown. Thisprovidesanumberofopportunitiesfortamperingwithequipment. Many piecesofequipmentincludesealstodetectsuchtampering,buteachsystemmustbeindividually analyzed to determine whether these seals are effective and whether they protect all the relevant accesspoints(seeSection3.5). Itmustbenotedthatpollworkersareprimarilyvolunteersandaresubjecttoextremelyminimal securityscreening,ifanyisperformedatall. Inmanycountiestheneedforpollworkersissogreat thatanyregisteredvoterwhocallsandofferstoservesufficientlyfarinadvanceisalmostsureto behired,andpollworkersareoftenallowedtorequesttoserveataparticularprecinct. Inpractice, we must assume that any attacker who wants to be a poll worker can do so. Therefore an attack whichrequirespollworkeraccesstoaparticularprecinctisquitepractical. 3.3.4 ElectionOfficials County election officials and county staff have three significant capabilities that poll workers do nothave: • Accesstofunctionalityoflocalvotingequipmentwhichmayberestrictedfrompollworkers. • Accesstolargeamountsoflocalvotingequipmentbetweenelections. • Accesstotheback-endelectionmanagementsystemusedforequipmentmanagement,ballot creationandtabulation. Forreasonsofadministrativeefficiency, thisaccessmightbeunsupervisedoronlylooselysuper- vised,dependinguponcountypractices. The first two capabilities imply greater ability to mount the sort of attacks that poll workers can mount. An election official with access to the warehouse where voting machines are stored mightbeabletocompromisealltheequipmentinacountyratherthanmerelyallthemachinesina precinct.Inaddition,theproceduresforsomeequipmentrequirethattheybesealed—forexample, thememorycardsorresultscartridgesmaybesealedinsidethemachine—beforetheyaresentto theprecincts.Becausethissealinghappensunderthesupervisionofelectionofficials,thoseofficials mightbeabletobypassorsubvertthatprocess. Thethirdcapabilityiswhollyunavailabletothelocalpollworker. Theback-endelectionman- agementsystemstypicallyrunongeneralpurposecomputerswhichareusedbytheelectionoffi- cials. Ifthosesystemsaresubvertedtheycouldbeusedtomismanage(compromise)pollingplace §3.3AttackerTypes 14 3. ThreatModel voting equipment, create fake or incorrect ballots, and to miscount votes. This subversion could happen in at least three ways. First, many attacks can be mounted using only the attacker’s au- thorizedaccessandwithinthecontextofthetechnicalcontrolswhichthesystemsareexpectedto enforce. Forexample,thesoftwaremayofferanopportunityforelectionofficialtomake“correc- tions”tovotetallies. Such“corrections”mightbeincorrect. Second,anelectionofficialmightfind awaytodefeatthetechnicalaccesscontrolsintheelectionmanagementsoftwareandtamperwith itsvoterecords. Third,theofficialcoulddirectlysubvertthecomputersonwhichthesoftwareruns.Itisatruism incomputersecuritythatifanattackerhasphysicalaccesstoageneralpurposecomputerhecan eventually gain control of it. This may be achieved in a number of ways ranging from software attackstodirectlycompromisingthesystemhardware,butinmostcasesisquitestraightforward. Theclearimplicationofthisfactisthatifelectionofficialshaveunsupervisedaccesstotheelection managementsystems,theintegrityofthosesystemsisprovidedpurelybytheintegrityandhonesty ofthoseofficials,notbyanytechnicalmeasures. 3.3.5 VendorEmployees Finally,weconsiderattackersintheemployofthevendors. Suchattackersfallintotwocategories: those involved in the production of the hardware and software, prior to the election, and those present at the polling place or Election Central warehouse during an election. An individual at- tackermightofcoursefallintobothcategories. An attacker involved in the development or production of the software and hardware for the election system has ample opportunity for subverting the system. He or she might, for example, deliberately insert malicious code into the election software, insert exploitable vulnerabilities or back doors into the system, or deliberately design the hardware in such a way that it is easily tamperedwith. Suchattacksareextremelyhardtodetect,especiallywhentheycanbepassedoff assimplemistakes,sincemistakesandbugsareextremelycommoninlargesoftwareprojectsand good-faithmistakesmaybeverydifficulttodistinguishfromdeliberatesubversion. Notethatfor suchanattacktosucceeditisnotnecessaryfortheattackertoarrangeforuncertifiedsoftwareor hardwaretobeacceptedbyelectionofficialsorpollworkers. Rather,thevulnerabilitieswouldbe inthecertifiedversions.Neitherthecurrentcertificationprocessnorthisreviewisintendedorable todetectallsuchvulnerabilities. Avendoremployeemayalsobepresentinthecountytoassistelectionofficialsorpollworkers. For example, the employee might be present at Election Central during or after the election to helpelectionofficials,eitheransweringquestionsorhelpingtofixorworkaroundmalfunctioning equipment.AvendoremployeemightalsobepresentatElectionCentraltohelpinstallormaintain the voting system or to train county staff or poll workers. A vendor employee might even be presentatthepollingplaceoravailablebyphonetoassistpollworkersoranswerquestions. Such anattackerwouldhaveaccesstoequipmentcomparabletothatofpollworkersorelectionofficials, but would also have substantial freedom of movement. Because they are being asked to correct malfunctionsandinstallandconfiguresoftware,activitieswhichareactuallyintendedtosubvert theequipmentaremuchlesslikelytobenoticed. Totheextenttowhichthesystemshavehidden administrative interfaces they would presumably have access to those as well. Finally, vendor employees pose a heightened risk because they may have access to multiple counties which use thevendor’sequipment,andtheabilityofoneindividualtoabletotamperwithvotingequipment inmultiplecountiesincreasesthescopeofanypotentialsubversion. 3.4 Types of Attacks Wecancategorizeattacksalongseveraldimensions: • Detectablevsundetectable. Someattacksareundetectable: theycannotbedetected,nomatter whatpracticesarefollowed.Othersaredetectableinprinciple,butareunlikelytobedetected by the routine practices currently in place; they might be detected by an in-depth forensic §3.4TypesofAttacks 15 3. ThreatModel audit or a 100% recount, for example, but not by ordinary processes. Still other attacks are both detectable and likely to be detected by the practices and processes that are routinely followed. The potential harm caused by the former two classes of attacks surpasses what one might expect by estimating their likelihood of occurrence. The mere existence of vulnerabilities that make likely-to-be-undetected attacks possible poses a threat to election confidence. If an election system is subject to such attacks, then we can never be certain that the election resultswere notcorruptedby undetectedtampering. This opensevery election upto ques- tion and undercuts the finality and perceived fairness of elections. Therefore, we consider undetectableorlikely-to-be-undetectedattackstobeespeciallysevereandanespeciallyhigh priority. • Recoverable vs unrecoverable. In some cases, if an attack is detected, there is an easy way to recover. Incontrast,otherattackscanbedetected,buttheremaybenogoodrecoverystrat- egy short of holding a new election. In intermediate cases, recovery may be possible but expensive(e.g., recoverystrategiesthatinvolvea100%manualrecountimposeaheavyad- ministrativeandfinancialburden). Attacks that are detectable but not recoverable are serious. Holding a new election is an extremeremedy,oftenrequiringcontentiouslitigation. Therearescenarioswhereanewelec- tioncannotfairlybeheld:forexample,redoingonecounty’spartofastatewideraceoncethe othercounties’resultsbecomeknownwouldbeunfairtotheothercounties. In addition, unofficial election results, once announced, tend to take on certain inertia and there may be a presumption against abandoning them. When errors are detected, attempts to overturn election results can potentially lead to heated partisan disputes. Even if errors are detected and corrected, the failure has the potential to diminish public confidence, de- pending upon the circumstances. At the same time, detectable-but-not-recoverable attacks arearguablynotasseriousasundetectableattacks: wecanpresumethatmostelectionswill notbesubjecttoattack,andtheabilitytoverifythatanyparticularelectionwasnotattacked isvaluable. • Preventionvsdetection. Often,thereisatradeoffbetweendifferentstrategiesfordealingwith attacks. Onestrategyistodesignmechanismstopreventtheattackentirely,closingthevul- nerability and rendering attack impossible. When prevention is not possible or too costly, anattractivealternativestrategyistodesignmechanismstodetectattacksandrecoverfrom them. Most election systems combine both strategies, using prevention as the first line of defense alongwithdetectionasafallbackincasethepreventivebarrierisbreached. Forexample,we attempttopreventordeterballotboxstuffingbyplacingtheballotboxintheopenwhereit canbeobservedandchargepollworkerswithkeepinganeyeontheballotbox. Atthesame time, we track the number of signed-in voters, account for all blank ballots, and count the numberofballotsintheboxattheendofthedaytoensurethatanyballotboxstuffingthat somehowescapesnoticewillstillbedetected. Thiscombinationcanprovidearobustdefense againstattack. • Wholesale vs retail. One can distinguish attacks that attempt to tamper with many ballots or affectmanyvoter’svotes(“wholesale”attacks)fromattacksthatattempttotamperwithonly a few votes (“retail” attacks). For example, attacks that affect an entire county or a large fractionoftheprecinctswithinacountyaretypicallyclassifiedaswholesaleattacks,whereas attacksthataffectonlyonevoteroroneprecinctaretypicallyclassifiedasretailattacks. This is a useful distinction because, in most contests, retail fraud is not enough to change the outcomeoftheelection. Becausewholesalefraudhasamoresignificantimpact,wefocused especiallyonanalyzingwhetherthesystemsarevulnerabletowholesalefraud. • Casual vs sophisticated. Some attacks require little technical knowledge, sophisticated, ad- vance planning, resources, or access. For example, stealing an absentee ballot out of some- §3.4TypesofAttacks 16 3. ThreatModel one’smailboxisaclassiclow-techattack: anyonecanexecutesuchanattack,andnospecial qualificationsorskillsororganizationisneeded. Incontrast,otherattacksmayrequiredeep technical knowledge, specialized skills or expertise, considerable advance planning, a great deal of time, money, or other resources, and/or insider access. This study examines both sophisticatedtechnicalattacksaswellascasuallow-techattacks. WhendiscussingvulnerabilitiesandpotentialattacksontheHartInterCivicvotingsystem,where possible we identify these distinctions to enable readers to form their own judgments about the severityandimpactofthoseattacks. 3.5 Mechanisms for Tamper Sealing Virtuallyeveryelectionsystemmakesextensiveuseoftampersealsasapartofitssecuritydesign. Thissectionpresentsabriefsummaryofhowthesemechanismsworkandthelevelofsophistica- tionanattackermusthavetoviolatethem. Tamper resistance refers to the ability of a system to deter an attacker from gaining access to the system. This could take the form of software controls (e.g., careful limits on the protocols spoken across networks) to procedural controls (e.g., the use of strong passwords) to hardware mechanisms (e.g., strong locks). Tamper resistance generally refers to the amount of time, effort, and/orsophisticationrequiredtoovercomeasecuritymechanism. Tamperevidenceistheflip-sideofthecointotamperresistance,representingtheextenttowhich anattacker’sattempttoovercomeatamper-resistancemechanismleavesbehindevidenceofthat tampering. For example, in a typical home, a burglar could easily break in by putting a brick through a window. A plate-glass window offers little tamper resistance, but strong tamper evi- dence(i.e., theeffortthatwouldberequiredbyaburglartoreinstallabrokenwindowandclean upthebrokenglassisquitesignificant). Forcontrast,atypicaldoorlockisfarmoretamperresis- tantthantheglasswindow. However,ifaskilledburglarcanpickthelock,therewillbelittleorno evidencethatithadbeenpicked. Inthecontextofvotingsystems,thereareanumberoftampersealingmechanismscommonly used: Keylocks Topreventaccesstomemorycardsorsensitivemachineports, manyvotingmachines place a plastic or metal door in front of these ports, using a key lock. Assuming the keys aresuitablycontrolled(andunauthorizedduplicationisprevented),attackerswouldbepre- vented from accessing the protected ports. Of course, if bypassable lock mechanisms are used, or if access to the locked compartment can be gained without opening the lock, then thelockswillofferneithertamperresistancenortamperevidenceashasbeenobservedwith bothDiebold[11]andNedap/Groenendaal[14]votingsystems. Wireloops Many voting machines have adopted a mechanism commonly used with traditional ballot boxes—the use of holes through which a metal or plastic wires loops may be fitted. These seals have much in common with standard “tie wraps;” once fitted, the wire loop cannotbeloosened;itcanonlybephysicallycutoff. Likekeylocks,theloops,whensealed, lockaphysicaldoorinplace. Incommonelectionpractice,thesesealsarestampedorprinted withindividualserialnumbers. Thosenumbersarethenloggedwhenthesealsareinstalled andagainwhentheyarecuttodetectthesubstitutionofanalternateseal. Anattackerwith simpletoolsmaybeabletoclonetheserialnumbersfromoldwireloopstonewoneswithout detection[31]. Tamper-evidenttape Adhesive tape can be printed with numbered labels in the same fashion as wire loops. Typically, two different adhesives are used, such that if/when the tape is re- moved,partofthelabelwillremainstucktothelowersurfacewhilepartofthelabelwillbe removedwiththetape. Technologyofthissortiscommonlyusedforautomobileregistration andinspectionstickers. Anecdotalevidencesuggeststhatitmaybepossibletopeelbackthe tapeandreplaceitwithoutthisbeingeasilyobservable[28]. §3.5MechanismsforTamperSealing 17 3. ThreatModel A recent study of tamper seals considered 244 different seal designs and found that “the ma- joritycouldbedefeated—removedandreplacedwithoutevidence—byonepersonworkingalone withinabouttwominutesandallofthesedevicescouldbethwartedwithinabout30minutes”[22]. Needlesstosay,suchsealscannotbecountedon,alone,toprovidesignificantsecurityprotections forelectronicvotingsystems. Of course, these mechanisms can be augmented through other procedural means, including requiringmultiplepeopletobepresentwhenmachinesarehandledormaintainingvideocameras and other locks on the storage areas of the elections warehouse. Johnston also recommends that officialshavegenuinesealsintheirhandstocompareagainstthesealsbeinginspected[22]. Theuseoftamper-evidentortamper-resistanttechnologies, assuch, mustbeevaluatedinthe broadercontextofproceduresandpoliciesusedtomanageanelection. Weaknessesinthesepro- cedures cannot be overcome by the application of tamper-resistant / tamper-evident seals. Also, theattacker’smotivationmustalsobeconsidered. Perhapstheattackerdoesnotcareifanattackis evident,solongasitcannotberecoveredfrom. §3.5MechanismsforTamperSealing 18 CHAPTER 4 Overview of System Architecture We now present a brief overview of the various components of the Hart InterCivic architecture. Wewillconsiderallthemajorcomponents,intheroughorderinwhichtheyareusedinanactual election. Notethatnotallcountiesuseallofthecomponentsdescribedhere. 4.1 Pre-Election eCM Manager e C M eC M Election Ms Ballot Now Ballot DB BOSS C Data e MBB Now Ballot MBBs Images To warehouse To printer Figure4.1: HartElectionSetup Figure4.1showsanoverviewofsettingupanelectionwiththeHartsystem. ThefirststepincreatingaHartelectionistocreateacryptographic“masterkey”thatisused todetectattacksagainsttheintegrityofdatathroughouttheelection. ThiskeyisstoredoneSlate Cryptographic Modules (eCMs), which are PKCS#11 USB cryptographic tokens, about the size of a pack of gum. The master key is generated using the eCM Manager software, which runs on a standardWindows-basedPC.TheeCMManagerloadsthekeyontoeacheCM. A Hart election is set up with the Ballot Origination Software System (BOSS) application, run- ningonastandardWindows-basedPC.BOSSisusedtodefinetheelection,i.e.,tocreatethelistof candidates running for each office, and to define how precincts and party primaries create many differentvariantsoneachballot. Whencomplete,thisproducesan“electiondatabase.” Theunder- lyingdatabaseissourcedfromSybase,oneofthemajorcommercialdatabasevendors. Inordertoexportelectioninformationtotheprecinctvotingdevices,BOSSwritestheelection definition to a Mobile Ballot Box (MBB), which is a standard PCMCIA type-1 flash memory card. 19 4. OverviewofSystemArchitecture Theballotdefinitionisdigitallysigned1usingthecryptographicmasterkey. Hartsupportsbothopticalscananddirectrecordingelectronic(DRE)voting. Theopticalscan ballotsarepreparedusingtheBallotNowprogram,whichrunsonastandardWindows-basedPC. BallotNowexportstheballotimageinelectronicformforexporttoanexternalballotprinter.2 The electiondefinitionistransferredbetweenBOSSandBallotNowonanMBB. 4.2 Preparing Voting Devices TheHartprecinctvotingsystemconsistsofthreeseparatedevices: eScan. aself-containedopticalscanningvotecounter eSlate. aDREvotingdevice Judge’sBoothController(JBC). thecontrolterminalfortheeSlate. All of these must be prepared before the election can take place. Preparation is performed at the central warehouse and consists at minimum of zeroing the vote counters and installing the per-electionmasterkey. ItmayalsoinvolveverifyingthedevicefirmwareandinstallingtheMBBs. DevicepreparationandmanagementisperformedwiththeSystemforElectionRecordsandVer- ification of Operations (SERVO), which is a program running on a standard PC. In the warehouse, SERVOisconnectedtothedevicesasshowninFigure4.2. eCM SERVO R M es A e C t Key + M A R C e s K et + ey Reset eScan JBC eSlate Figure4.2: HartDeviceSetup SERVO is connected to the eScan by means of an Ethernet cable and to the JBC by way of a parallel data cable. SERVO cannotdirectly talkto an eSlateand must use a JBCas a go-between. AneCMcontainingthemasterkeyispluggedintoSERVO,whichinstallsthekeyontheJBCsand eScans(butnottheeSlates)andzeroesthevotecounters. SERVOalsoservesaninventory-control function, tracking the serial numbers of every device owned by the county and can be used to verifydevicefirmware. At this time, MBBs may also be installed into the JBCs and eScans, in which case they are tamper-sealedatthewarehouse. Alternately,theMBBmaybeshippedseparatelytotheprecinct. Ineithercase,theprepareddevicesarethenshippedtotheprecinctsorthelocalpollworkers. 1Hart’sterminology.Moreprecisely,it’sashared-keymessageauthenticationcode,withthesamekeyusedthroughout theelection. 2BallotNowcanalsobeusedforon-demandin-precinctballotproductionandscanning,buttheCaliforniauseproce- dures[21]specificallyprohibitBallotNowoperationoutsideofthecentraloffice,sowedonotconsiderin-pollingplace applicationsofBallotNow. §4.2PreparingVotingDevices 20 4. OverviewofSystemArchitecture 4.3 Election-Day Setup Hart supports two varieties of in-precinct voting: optical scan voting using the eScan and DRE votingusingtheeSlate/JBC.Figure4.3showsthesetup. Access Check MBB MBB VBO eSlate JBC eScan Votes Access Code/ Access Marked Votes Code Ballot DRE Access Poll Ballot Opscan Voter Code Worker Voter Figure4.3: HartPollingPlaceSetup Once an eScan is loaded with an MBB it operates as an island unto itself. When ballots are inserted,itcanvalidateandtabulatethevotes,oritmayrejectmalformed(e.g.,over-voted)ballots. Thecastvoterecords(CVRs)arerecordedontheMBB. DREvotingissupportedusingoneormoreeSlatesystemsconnectedwithalocalareanetwork toasingleJBC.LargerprecinctsorvotingcentersmaywellhavemultipleJBCs,eachwithitsown groupofeSlatemachines.AswiththeeScan,theJBCmustbepre-loadedwithanappropriateMBB. 4.4 Authorizing and Casting Votes Unlike the eScan, the eSlates rely on their communications with the JBC that controls them. In a typical scenario, a voter is first validated as being a legitimate voter for the local precinct. Then, they enter a queue that leads to the poll worker operating the JBC. This poll worker selects the proper ballot definition, where appropriate (e.g., giving the voter the Democratic or Republican primary ballot), and then the JBC will use its built-in thermal paper printer to output a random four-digit access code. The voter takes this printed code and approaches any open eSlate. The voterisgrantedaccessbytheeSlatetocasthisvotebyenteringtheaccesscode. Whenthevoterhascompletedvoting, theeSlateprintsoutasummaryofhisselectionsusing the Verified Ballot Option (VBO) printer (the VBOx). The voter then has an opportunity to accept or reject the ballot. Once the voter has accepted his ballot, the VBOx marks the paper “BALLOT ACCEPTED”andtheballot(CVR)isstoredinsidetheeSlate,insidetheJBC,andontheMBBstored withintheJBC. 4.5 Vote Collection and Tallying At the end of the election day, results need to be collected and tallied. Hart systems allow for a numberofdifferentprocedures,asshowninFigure4.4. Wewilldescribeseveralofthepossibilities. First,theJBCand/ortheMBBfromwithinitmust becarriedviacouriertoaprocessingfacility. ThismightbeElectionCentral,orinlargercountiesit mightbearegionalprocessingcenter. Similarly,aneScanmightbecourieredinitsentirety,orthe eScanmightbeshippedseparatelywhiletheMBBissenttobeprocessed. Either way, the MBBs are loaded into a Windows PC running Rally or Tally. The software extractsthecontentsoftheMBB,verifiesthattheyhavenotbeenseenbefore,andstoresthemina §4.3Election-DaySetup 21 4. OverviewofSystemArchitecture Precinct Paper MBBs Voting Rally Ballots Devices M B Vote B s Data Ballot MBB Tally Now Election Central Figure4.4: HartVoteCollectionandCounting local(Sybase)database. Inthecaseofregionalprocessingcenters,theywillberunningRallyand theircomputersmusteitherbeconnectedtoanetworkorbeconnectedtomodemsandconfigured toacceptphonecalls. ElectionCentral,runningTally,willmakephonecallstoeachregionalcenter, runningRally. TallywillauthenticateitselftoRallyandthen,overanSSL-encryptedsession,will downloadalltheMBBsstoredwithinRally. AbsenteevotesarescannedusingtheBallotNowsoftwareandaCOTSscanner,whichprovides detailedprocedurestoallowtheoperatortodisambiguateballots. Oncethisprocessiscomplete, BallotNowwritesoutanMBBwhichcanthenbeaccumulatedalongsidetheotherMBBs. Insome counties,theeScanisnotusedandallballotsarescannedwithBallotNow. OncealltheMBBsarepresentwithinTally,eitherbecausetheywereloadedlocallyorbecause theywerecopiedfromremoteRallysystems,Tallycanthencomputethevotetotalsandproducea widevarietyofreports. WenotethatbothRallyandTallyrequirethepresenceofaneCM,inorder toobtainacopyoftheelection’scryptographicmasterkey,sothatanytamperingwithMBBs(or, anyinadvertentuseofMBBsfromotherelections)canbedetected. 4.6 Post-Election Auditing SERVO Ba + c V ku er p ify + V B e a r c if k y up Backup eScan JBC eSlate +Verify Figure4.5: HartPost-ElectionAuditing §4.6Post-ElectionAuditing 22 4. OverviewofSystemArchitecture OncetheeSlate,eScan,andJBCmachineshavebeenreturnedtoElectionCentral,theymaybe againconnectedtoSERVO,asshowninFigure4.5. SERVOcanextracttheirinternalcopiesofthe vote data and store backup copies. These copies can subsequently be used to produce a recount MBBwhichcanbefedtoTallytoperformamachinerecountwhichcanbecomparedagainstthe official totals. This process is optional and may not take place until well after the official election resultshavebeencertified. Likewise,thepaperballotsthathadbeenoriginallyscannedusingthe precinct-based eScan system can be rescanned with Ballot Now. There do not appear to be any proceduresforautomaticallyperforminganaudit. Rather, theauditsareperformedandthenthe resultsmanuallycompared. AtthistimeSERVOcanalsobeusedtoverifythedevicefirmware.However,therecommended procedureisthatthedevicesnotbezeroedincaseasubsequentauditisrequired. §4.6Post-ElectionAuditing 23 CHAPTER 5 Architectural Issues As discussed in Section 1.2, the focus of this review was on architectural issues. Unlike simple programmingerrors,architecturalerrorspervadetheentiresystemandthereforecanbedifficultto eradicate. OurreviewidentifiedfourmajorarchitecturalerrorsthataremadethroughouttheHart system: AuthenticationFailures. Components of the Hart system routinely assume that any input they receive from an entity speaking the Hart protocol is authorized and will act on it without question. LeastPrivilegeViolations. InmanycasestheHartprotocolallowspeeragentstoperformactions thatareunnecessarilypowerful. LackofInputValidation. The Hart software frequently fails to check input values before using theminternally. MisuseofCryptography. Cryptographyisnotusedinplaceswhereitshouldbe;whereitisused, itisusedinbrittleways. All of the issues described above can be viewed as aspects of a single larger architectural issue: theHartsystemfailstoexhibitdefenseindepth. Securesystemsshouldbedesignedinsuchaway thatcompromiseofsingleelementsdoesnotleadtocompromiseoftheentiresystem. Rather,the systemshouldbedesignedinsuchawaythatotherelementsacttocontaincompromiseofasingle element,sothatthelargersystemcontinuestofunctioncorrectly. Inmanyrespects,Hart’ssystemexhibitstheoppositeproperty:adistributedsinglepointoffailure. Anattackerwhocompromisesanyofalargenumberofelementscanleveragethatattacktocause other elements of the system to misbehave, in many cases even when those other elements are functioningasdesigned. Thisisinconsistentwithgoodsecuritydesign. Therestofthissectiondiscussesthesegeneralissuesatanarchitecturallevel. Thenextsection providesadetaileddescriptionoftheissueswehavefound. 5.1 Authentication Failures The various components of the Hart system routinely communicate between each other over a varietyofnetworkinterfaces,including: • SERVOtoeScan(Ethernet) • SERVOtoJBC(Parallel) • JBCtoeSlate(EIA-485) • VoterRegistrationComputertoJBC(RS-232) • RallytoTally(Internetormodem) 24 5. ArchitecturalIssues Becausethesechannelsareusedforimportantcommunications, suchasuploadingfirmware, au- thorizingvotes,andreturningvotestheyconstituteanattractiveattacktarget. Thefundamentalstartingpointfordesigningasecurenetworkedsystemistoassumethatthe attackerhascontrolofthecommunicationschannel. Thisisparticularlyimportantinthecaseofa systemlikeHart’swheretheattackerhasphysicalaccesstothecommunicatingdevices. Therefore, anycommunicationmustbeassumedtobeoriginatedbyormodifiedbytheattackeruntildemon- stratedotherwise.Thestandardtechniqueforestablishingtheidentityofthecommunicatingparty andtheintegrityofitsmessagesistouseasecurecommunicationsprotocolsuchasSSL/TLS[8]. WiththeexceptionoftheRally/Tallycommunications,whichdouseSSL/TLS1,theseremain- ingcommunicationschannelsarecompletelyunsecured. Theunderlyingassumptionhereappears tobethatbecausetheinterfacespecificationsandprotocolareproprietary,anynodewhichspeaks that protocol must be legitimate. This is only true to the extent to which the protocol remains secret. An attacker who has access to either the source code or the equipment can, with only a modestamountofeffort,deciphertheprotocolandcreatehisownimplementation. Weourselves havedevelopedapartialimplementationoftheprotocolanduseditinattacksontheHartsystem. Vendorsofproprietarynetworksystemsoftenassumethatbecausetheydonotpublishprotocol specifications or source code, no attacker will be able to reverse engineer their protocols. This assumption is largely untrue. With enough effort and access to a system, it is generally possible for an attacker to reverse engineer most protocols. Probably the most famous example of such an effort is Samba2, an independent reimplementation of Microsoft’s SMB server which was to a greatdegree(thoughnotexclusively)developedviathiskindofanalysis. TheprotocolHartusesis especiallysusceptibletothiskindofattackbecausemanymessagescansimplybereplayedwithout modificationandstillhavethedesiredeffect. Therefore,reverseengineeringtheprotocolmaynot evenbenecessaryifwhatisdesiredistosimplyrepeatanactionthatwasobservedinthepast. Repairingthisissuemostlikelyrequiresaddingcryptographicauthenticationandencryptionto allinter-devicecommunication, whichlikelywouldentailreworkingHart’sentireauthentication model. 5.2 Least Privilege Violations Oneofthefundamentalprinciplesofsecuresystemsdesigniswhat’stermedthe“principleofleast privilege”: anagentshouldbegivenonlytheminimalcapabilitiesrequiredtocompletethetasksit isexpectedtoperform. Hart’ssystemsviolatethisprincipleintwoways: • The commands used to implement a given task are often significantly more powerful than required. • Thecapabilitiesrequiredtoexecutecommandsareoftennotlimitedtotheagentsandtimes whentheyareneeded. Asanexampleoftheformerissue,Hartprovidesageneralmemoryreadingcommandthatallows SERVO—or anyone pretending to be SERVO—to read arbitrary portions of the eScan permanent storage or of JBC/eSlate memory. SERVO uses this mechanism in an attempt to verify the de- vice firmware (see Issue 11), however it can also be used to extract cryptographic keys and other sensitive information. This command could be limited to specific sections of firmware without sacrificingthedesiredfunctionality. Asanexampleofthelatterissue,Hartprovidesasetofcommandswhichcanbeusedtoupdate the firmware. These commands are only ever legitimately used by Hart representatives under tightly controlled conditions. However, our analysis suggests that these commands are available atalltimestoanyagentwhichcanaccesstotherequiredinterface. Asuperiordesignwouldbeto lockdownthesecommandsentirelywhenthedevicesareinthefield,withtheunlockingrequiring 1Thoughwehaveconcernsaboutthisusageaswell,asdescribedinSection6.9. 2http://www.samba.org/ §5.2LeastPrivilegeViolations 25 5. ArchitecturalIssues explicit action by an election official or Hart representative. It would of course be necessary to ensurethatthatunlockingcouldnotbespoofed,whichcanbeaccomplishedinavarietyofways. Addressing this design issue would likely involve an analysis of the entire command set to determiningtherequiredscopeandfunctionalityofeachoperation. 5.3 Input Validation WefoundnumerousinstancesintheHartsystemoffailuretocheckinputsthatarereceivedfrom otherentities. Theseinputsarethenusedinavarietyofunsafeways,suchascopiedintoafixed- size memory buffer or passed as a format string argument to printf. This violates the basic secure programming practice of assuming that any input received from outside is malicious and usingitonlyafterithasbeenrigorouslychecked.InthecaseofHart’ssystem,thisleadstomultiple remotelyexploitablevulnerabilities,discussedinIssue13andelsewhere. Wewishtoemphasizethatthesearenotcomplicatederrorswhereatainteddataitemfollows a tortuous path to the point of exploitation—though we identified this type of issue as well. The Hartsystemrepeatedlytakesdatadirectlyoffthenetworkandusesitinunsafeoperationswithin afewlinesofthepointwhereitisread. Thispracticeistotallyunsafeandtriviallyexploitablewith techniquestaughtinintroductorysecurityengineeringclasses. Arelatederroristheimplicitassumptionthatpeersarewellbehaved. Forinstance,wefound errors where Hart would query a peer for the length of a value, allocate a buffer of that length, thenqueryagainforthelengthandusethesecondanswerwithoutcheckingthatitwasthesame asthefirst. This, too, isinconsistentwiththeassumptionthatthepeercanbemalicious, andisa well-knowntypeoferror,knownintheliteratureasatime-of-check-to-time-of-use(TOCTTOU)bug. AddressingthisissuerequiresthatHartperformacompleteauditofeverysectionofthecode which reads and processes data from the outside world and in each case ensure that the data is thoroughly checked before any other operations are performed on it. This will require pervasive changesthroughoutthecode. 5.4 Misuse of Cryptography AlthoughHartdoesnotusecryptographyinanumberofplaceswhereitwouldbehelpful, they douseitinatleastthreecases: • ToprotectcommunicationbetweenRallyandTally • ToprovideintegrityprotectionfortheMBBand • Torandomizevotedata. In the latter two cases, the techniques provide a far lower level of security than is desirable. The twomajordataitemsontheMBBwhichneedtobeprotectedare: • TheballotdataintransitfromBOSStothepollingplace. • VotedataintransitfromthepollingplacetoRally/Tally. Logicallyspeaking,theseoperationsarequiteseparate. Thefirstcategoryofdataisgeneratedby ElectionCentralandverifiedbythepollingplace. Thesecondcategoryofdataisgeneratedbythe pollingplaceandverifiedbyElectionCentral. Basiccryptographicprinciplesdictatethatseparate types of data should be protected with separate keys. Hart, however, uses a symmetric message authenticationcode(MAC),whichrequiresthatbothsideshavethesamekey. Moreover,thesame keyisusedcountywide. Theimpactofthischoiceisthatanattackerwhohasaccesstothissinglekeycan: • Forgeballotdatawhichwillbeacceptedbyanyprecinct. §5.3InputValidation 26 5. ArchitecturalIssues • ForgevotedatafromanyprecinctwhichwillbeacceptedbyElectionCentral. Thischoiceisexacerbatedfurtherbypoorkeyhygiene. Keysarecentrallygeneratedinsoftware, thentransferredtoahardwaretoken,thentransferredviaanunsecurednetworkinterfacetomem- oryontheJBCsandeScans. Thisviolatesstandardcryptographicpracticewithhardwaresecurity tokens, which is to use the key exclusively on the token. (Modern cryptographic tokens can per- form a variety of cryptographic operations internally without ever divulging the keys used for theseoperations.) Theresultisthatthereisalargenumberofsofttargets,compromiseofanyone ofwhichsufficestocompromisetheentirecryptographicscheme. Even without the device management issues described in Section 6.1, extracting these keys would not be particularly difficult. An attacker with physical access, such as a poll worker, can simplyopenthecaseofasingleeScanorJBCanddirectlyreadthekeyfromitsinternalmemory card. Eveniftheviolationofthetampersealsisdetected,hecansimplyclaimthatthesealswere broken when he received the device. According to Hart’s suggested procedures, this would re- quirenotifyingthechiefelectionofficial, butatmostwouldrequiretakingthecompromisedunit outofservice ([21],page26,seealsopage45),whichdoesnotpreventtheattackerfromusingthe extractedkey. Amorerobustdesignwouldusepublickeycryptography,witheachdeviceissueditsownkey. This would stop a compromised polling place device from impersonating either Election Central oranotherpollingdevice. Thisdesigncouldbefurtherhardenedbydistributingallkeysonsecure tokenswiththekeysneverexportedandallcryptographiccomputationsperformedonthetoken. Hart also uses cryptographic-style techniques in the pseudorandom number generator which generatesthevotercodes.Designofcryptographicallystrongpseudorandomnumbergeneratorsis awell-studiedproblemintheliterature,buthome-growntechniquesaretypicallyquiteweakand Hart’sisnoexception,asdiscussedinIssue7. Thisissuecanberelativelyeasilyfixedbyreplacing thePRNGwithastrongonefromtheliterature. §5.4MisuseofCryptography 27 CHAPTER 6 Detailed Analysis WenowconsiderindividualattacksthatwehavediscoveredontheHartInterCivicvotingsystem. Foreachattack,wedescribe,briefly,howtheattackworks,andwhatcapabilitiesarenecessaryfor anattackertoperformtheattack. Wealsodiscusstheimpacttheattacksmayhaveandwhatmiti- gationsmaybeavailable. Becausethetermsofthereviewforbidpublishingfulldetailsofattacks on the Hart system, some of the descriptions below are incomplete. More complete descriptions, including,whererelevant,thetoolsrequiredtoexploittheissues,weremadeavailabletotheState inaprivateannextothisreport. 6.1 Device Management Thepollingplacedevices(eScan,JBC,eSlate)arealldesignedtobemanagedbyprogramsrunning onordinarycomputers: • Hartusesaspecialprogramtoupdatethefirmwareonthesemachines.1 • SERVOisusedtobackupelectionresultsandauditlogs,verifyfirmware,andresettheballot countersinpreparationforthenextelection. Inbothcases, managementisperformedbyconnectingthedevicetobemanagedtotheman- agementstationviaaphysicalcable. Innocasedidthereappeartobeanysecuritymeasuresap- pliedtopreventunauthorizedpersonnelfrommanagingthedevicesthemselves. Thisrepresentsa significantsecurityissueinthatanattackercoulduseittocompromisevotingequipment. All network communications between Hart’s devices, whether over TCP/IP, Parallel, or EIA- 485 serial interfaces, use a common data protocol. Understanding this protocol is the key to suc- cessful analysis and exploitation of the Hart system. A large number of our attacks depend on beingabletoreadand/orwriteprotocolmessages. Wedescribetheprotocolhereinordertogive readersasenseofhowtheprotocolworksandofthetypesofcapabilitiesweuseinimplementing ourattacks. Atthelinklayer,eachmessageisframedwithalinklayerheaderandachecksum: • Commandbyte(fixed) • Length • Payload • Checksum 1WewerenotprovidedwithacopyofHart’sfirmwareupgradingtools,butwewereabletoreconstructsomeoftheir functionalityfromaprotocoltracecapturedbytheRedTeamandbyanalyzingthesourcecode. 28 6. DetailedAnalysis Thelinklayerstripsoffthatframingtorevealtheapplicationlayermessage.2 Above the link layer, the Hart protocol is a reasonably conventional datagram protocol. Each node on the network is assigned an identification number. In the case of the JBCs, eScans, and managementstationsthisisfixed. InthecaseofeSlates,eacheSlatereceivesanidentifierfromone totwelve,denotingtheeSlate’svotingboothID. Everymessagesharesacommonheader,whichcontains:3 • Sourceaddress • Destinationaddress • Responseaddress • FrameID • Length One somewhat unusual feature is the response address, which indicates the node to which a re- sponseshouldbesent. Manyprotocolssimplyreplytothefromaddress. Wehavenotinvestigated thisindetail,butitappearstobemostlyusedtoindicatenoresponseisneeded. TheFrameIDcontainsthecommandbeingexecutedorrespondedto. Therestofthemessage isatype-specificpayload. Describingallthecommandsisoutofthescopeofthisreport,butafew ofparticularinterestinclude: Fileaccess direct read and write to arbitrary portions of the eScan file system. We used this ca- pability in the firmware replacement attack described in Issue 3. which could be used to completelytakeoverthedevice. Readaccesstoarbitrarymemorylocations which could be used to read cryptographic keys or voterecordsfromthedevice. FortheeScanthisonlyappliestostaticstorage. FortheeSlate andJBCthisappearstoapplytoallofmainmemory. Writeaccesstoarbitrarymemorylocations which could be used to write MBB data and, in the caseoftheeSlate/JBC,takeoverprogramexecution.Itcouldalsobeusedtotamperwithany auditlogscurrentlyonthedevice. Aswithreadaccess,writeaccessappliestostaticstorage ontheeScanandtoallofmainmemoryontheeSlateandJBC. Resetvotecounters whichcouldbeusedtoresettheprivateprotectivecounterinflashmemory. Generateasystemerror whichcouldbeusedtoresetthedevice. Reset usedtorestartdevices. Allthreedevicesspeakvariantsofthissamebinaryprotocol, althoughsomecommandshave differentbehaviordependingonwhichdevicetheyareaddressedtoordonotexistonsometypes of devices. The same basic protocol is also used for ordinary communication between the eSlate andtheJBC,asdescribedinSection6.2. Becausewehadsourcecode,wedidnotneedtoreverseengineertheprotocolbutwereableto buildencodersanddecodersbasedonthesourcecode. However,cursorybinaryanalysissuggests that an attacker with access to a device, a copy of the management software, and an appropriate sniffercouldreverseengineersubstantialportionsoftheprotocol. Ifweconsiderbrieflythecaseof anattackerwhoobservesafirmwareinstall,werealizethatheobserves: • Thecommandsnecessarytoinstallthefirmwareimage. • Thefirmwareimageitself. 2ThecontrolchannelforthetheeSlateEIA-485interfaceusesthesamelinklayerframingbutadifferentupperlayer protocol. 3Note:notallfieldsareshown §6.1DeviceManagement 29 6. DetailedAnalysis It’srelativelystraightforwardtodeterminewhichpartsofthecommunicationarethefirmwareand whicharetheprotocolwrapper.Atthispoint,theattackerbothhasaccesstoadeliverymechanism and to the binary which decodes it in one convenient package. It’s straightforward (though time consuming) able to disassemble that to reverse engineer the binary and recover the rest of the protocol. Accesstothemanagementinterfaceisthereforeextremelypowerfulandinthecurrentdesign appearstoleadtocompletecontrolofthedevicebeingaccessed. Issue1:TheJBCismanagedviaanaccessibleparallelport TheJBCismanagedviaaparallelinterface: aDB-25connectorontherearofthedevicelabeled “Printer.” Thisinterfacedoesnotappeartobeprotectedbyanykindofdoorandwewerenotable to determine whether there is any requirement that it be tamper sealed or taped. Protecting this interfaceinthefieldwouldlikelybefairlydifficultbecauseitisveryclosetotheDE-9portusedto talktotheeSlates,whichisusedinthefield. Anattackerwhocanaccessthisportcanimpersonate amanagementstationandpotentiallysubverttheJBC. Detailed Description When the JBC boots up it installs an interrupt service routine (ISR) on the parallelinterface. WhendatacomesinonthatinterfacetheISRreadsafullmessageandthenputs itinamessagequeueforthe“servicetask”.Theservicetaskdetermineswhetherthemessageisfor theJBCorforaconnecteddevice(aneSlate). IfitisforaneSlateitsendsitouttheserialinterface totheeSlate. IfitisfortheJBCitisprocessedlocally. The JBC service task will process—without any authentication—any message it receives via the parallel interface. Thus, an attacker who understands the protocol can simply connect to the parallelportandstartissuinginstructionswhichtheJBCwillobey. Theseinstructionsincludethe managementcommandsindicatedabove. Prerequisites Inordertoexploitthisissuetheattackerwouldneed: • TohavedecodedtheprotocolusedbyHart. • AccesstotheparallelportontheJBC. Asindicatedatthebeginningofthissection,webelievethatanattackerwhohadanopportunity toobservearunningsystemcoulddecodesubstantialportionsoftheprotocol. Currently, any poll worker has access to the parallel port on the JBC. The amount of time re- quiredisquitesmall. WehaveobservedJBCsoftwareupgrades(reflashing)inthefieldandthey appeartotakelessthanaminute. Othercommandswouldpresumablybeevenfastersincelittle datatransferisrequired. Inaddition,theattackermayneedtoresettheJBCtoloadthenewcode. Thiscanlikelybedoneremotelybutcanalsobedonebysimplypullingtheplug. Hownoticeable thisisdependsonhowoftensuchfailuresoccurinnormalusage. NotethattheJBCwillrecover gracefullyfromapowerfailureofthistype. Itmayalsobepossibletopatchtherunningimagein memory. Impact An attacker who took control of a JBC would have direct control of every eSlate in the precinct. Inparticular,theeSlatesgettheirinformationaboutballotsandvoteauthorizationfrom the JBC. Moreover, as described in the next section, we believe the JBC can use the management interfacetosubverttheeSlates. SeeSection7forarangeofpossibleattacksusingthisaccess. Mitigations The primary JBC-specific mitigation is to somehow secure the parallel port. There doesnotappeartobeanylegitimateuseforthisportinthepollingplace. Generalmitigationsfor alloftheissuesdiscussedinthissectionarediscussedinSection6.1. FutureversionsoftheHarthardwaremightadddoorswithlocksorothersuitablemechanisms toprotecttheparallelportfromtamperingwhiletheJBCisinthefield. §6.1DeviceManagement 30 6. DetailedAnalysis Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Anincompleteunderstand- ingofthehardwareinterfacehasstoppedusfromreplicatingitwitharealJBC. Issue2:TheeSlateismanagedviaaserialportconnectedtotheJBC The eSlate is managed via a serial interface on the rear of the device. In order to manage the eSlate,oneplugstheeSlateintotheJBCandconnectsthemanagementstationtotheJBC.Allmes- sages between the management station and the eSlate are sent through the JBC. This interface is not protected by any kind of door, nor is it tamper sealed. In fact, Hart’s curbside voting feature explicitlycontemplatesthattheeSlateswillbeunplugged. An attacker who can access the eSlate interface can impersonate a management station to the eSlate and potentially subvert the eSlate. Mounting this attack would be extremely quick, on the orderofseconds. DetailedDescription TheeSlateisconnectedtotheJBCviaaserialinterface(seeSection6.2for details). Onstartup,theeSlate“networktask”beginsandwaitsforinstructionsoverthisinterface, eitherfromtheJBCorfromamanagementstationroutedthroughtheJBC.Ineithercase,theeSlate obeysthoseinstructionswithoutquestion. By design, all communication to the eSlate is via the JBC. However, an attacker who had the specificationstothisinterfacecouldconnectdirectlyandimpersonatetheJBC(andhencetheman- agementsystem)totheeSlate. Thus,controllingthisinterfacewouldallowanattackertomanage theeSlate,asdiscussedabove. Prerequisites Inordertoexploitthisissuetheattackerwouldneed: • TohavedecodedtheprotocolusedbyHart. • AccesstotheserialportontheeSlate. Asindicatedatthebeginningofthissection,webelievethatanattackerwhohadanopportunity toobservearunningsystemcoulddecodesubstantialportionsoftheprotocol. Currently,anyvoterhasaccesstotheserialportontheJBCandcaneasilyremovetheconnector. TheeSlateisdesignedtobedisconnectedtoenablecurbsidevotingandthereforeitispossibleto removethelasteSlateinthechain. (SeeSection6.2.3). InordertoinstallnewfirmwareontheeSlate,itwouldprobablyneedtoberebooted,however this could likely be done without disturbing the JBC. It may also be possible to use the memory commandstopatchtherunningmemoryimage. Anyoftheseattackscouldplausiblybemounted byavoterandcouldcertainlybemountedbyapollworker. Impact A successful attack of this type would likely lead to complete control of the eSlate. An attackerwhocontrolledaneSlatewouldbeabletoaccessorcontroleveryvoteperformedonthat eSlate. He might also be able to leverage this access into control of the rest of the eSlates in the system,asdescribedinSections7.3and6.2. Mitigations ThenaturalmitigationistosecuretheconnectionbetweentheeSlateandthestand via some kind of seal. However, we saw no obvious sealing points. In addition, the red team informs us that the eSlates need to be demountable in order to install potential disabled access devices such as sip-puff devices. In addition, each eSlate is connected to the next eSlate, which providesanadditionalcableattachmentpoint. SeeSection6.2formoredetailsonthedifficultiesof securingthisinterface. §6.1DeviceManagement 31 6. DetailedAnalysis Status This issue was discovered by examination of the source code. We have verified that we canobservecommunicationsbetweentheJBCandeSlateandwereabletoverifythelackofcrypto- graphicsecurity. WehavenotattemptedtoimpersonateaJBCormanagementstationtoaneSlate. Issue3:TheeScanismanagedviaanaccessibleEthernetport TheeScan,liketheotherdevicesisremotelymanageable. TheeScanisequippedwithanRJ-45 EthernetjackandautomaticallyadoptsafixedIPaddress. ItcanberemotelymanagedviaTCP/IP. DetailedDescription WhentheeScanbootsitautomaticallystartsa“servicetask”whichlistens on TCP port 4600. The eScan seems to have fixed IP address of 192.168.0.1. The eScan ser- vice handler treats any TCP connection on this port as the management console and will process commandsissuedviatheTCPconnectionwithoutquestion. Prerequisites Inordertoexploitthisissuetheattackerwouldneed: • TohavedecodedtheprotocolusedbyHart. • AccesstotheEthernetportontheeScan. Asindicatedatthebeginningofthissection,webelievethatanattackerwhohadanopportunity toobservearunningsystemcoulddecodesubstantialportionsoftheprotocol. Thisisparticularly easy with TCP/IP connections because tools such as Wireshark and tcpdump for analyzing TCP connectionsarereadilyavailableandwidelyusedforpreciselythissortofanalysis. CurrentlyanypollworkerhasaccesstotheEthernetinterfaceontheeScan. Wedonotknowif voterswouldbeabletoaccesstheinterfaceinthefield. Thisdependsonthephysicalmountingof theeScanonitscartaswellaswhatsortofsupervisionvotersareunder. Impact A successful attack of this type would likely lead to complete control of the eScan. The attackercouldcauseanyvotecountshechosetoappearaswellasrejecting“invalid”ballotsofhis choice. SeeSection7forotherattacksbasedoncontrollinganeScan. Mitigations ThenaturaleScan-specificmitigationistosecureaccesstotheEthernetportonthe eScan. There does not appear to be any need to have it available in the polling place. General mitigationsforalloftheissuesdiscussedinthissectionarediscussedattheendofSection6.1. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavesuccessfullyused acomputerunderourcontroltocommunicatewiththeeScanandextractedthememoryinforma- tion,theinitializationfile,andthecryptographickeys. ThischannelisusedbyHarttomanagethe firmware on the eScan and based on the source code and a capture of a firmware upgrade trans- action(providedbytheredteam)wewereabletowriteourowntooltoupdatethefirmware. We workedwiththeredteamtotestedthistoolwiththeredteam’seScanandweresuccessfullyable toloadourownfirmware,whichdisplayedarevisedHartlogo. Issue4:The JBC voter registration interface can be used to generate voter access codes TheJBCcontainsaDE-9maleconnectorontherearofthedevicelabeled“Modem”. Thisisa serialinterfacewhichisinternallyreferredtoasa“VoterRegistrationInterface”(hereafterVRI)4.A VRIdevicecansendinstructionstotheJBCtoissuevoteraccesscodes. AswiththeJBC’sparallel interface,thisserialinterfacedoesnotappeartobeprotectedbyanykindofdoorandwewerenot 4WhilethereisnocertifiedHartInterCivicproductinCaliforniathatconnectstothisport,thesupportforitisclearly presentintheJBCsourcecode. §6.1DeviceManagement 32 6. DetailedAnalysis abletodeterminewhetherthereisanyrequirementthatitbetampersealedortaped. Anattacker whocanaccessthisportcanimpersonatetheVRIdeviceandgeneratevoteraccesscodesthatcan beusedforvotingononeoftheeSlatesmanagedbythisJBC.Further,iftheJBCisinEarlyVoting mode, access codes can be obtained by an attacker without causing records to be printed to the JBC’sprinter. DetailedDescription AftertheJBCbootsuptheandlowlevelinitializationisfinished,the“main task”isstarted. Themaintasklistensontheserialinterface(labeled“Modem”onthebackofthe JBC,referredtoastheVRIinthesourcecode)forvoteraccesscoderequests. IftheJBCisinEarly Voting mode, then access code requests can include an instruction to not print any records to the JBCprinter. Otherwise,accesscoderequeststriggerareceiptbeingprinted. TheJBC“maintask”willprocess—withoutanyauthenticationorcryptographicintegritychecking— any message it receives via the VRI. Thus, an attacker who understands this protocol can simply connecttotheserialportandstartissuingvoteraccesscoderequests. Prerequisites Inordertoexploitthisissuetheattackerwouldneed: • TohavedecodedthevoterregistrationprotocolusedbyHart. • AccesstotheVRI(i.e.,theserialportlabeled“Modem”)ontheJBC. Similartothecasewithafirmwareupgrade,anattackerwhohadanopportunitytoobservedata exchangedbetweenaVRIdeviceandaJBCcoulddecodesubstantialportionsoftheprotocol. This protocolisalsopartiallydescribedintheJBCFunctionalSpecification[15]. Onequestionworthaskingisthedurationofrequiredaccess.TheRedTeamwasabletoconnect toaJBCinEarlyVotingmodeandextractseveralvoteraccesscodesinaveryshortamountoftime. Impact Anattackerwhocouldgeneratevalidvoteraccesscodescouldvoteasmanytimesasthe numberofaccesscodesgenerated. Thedocumentationindicatesalimitof150outstandingaccess codesbutwehavenotverifiedhowwellthisisenforced. IfaJBCwasusedwithabarcodereader,thenanattackerwouldnotneedtoconnectanexternal computertotheserialport.Instead,theattackercouldpre-printsuitablebarcodesandexposethem tothereader. Mitigations TheprimaryJBC-specificmitigationistosomehowsecurethisserialport. Ifnocom- puterorbarcodereaderisintendedtobeconnectedtotheVRI(and,wearenotawareofanyreason whyoneshouldbe),thentheserialportshouldbesuitablysealedtopreventaccesstoitduringthe election. GeneralmitigationsfortheissuesdiscussedinthissectionarealsodiscussedinSection6.1. Status Thisissuewasdiscoveredbyexaminationofthedocumentationandsourcecode.TheRed TeamwasabletosuccessfullyconnecttoarealJBC’sVRIandgeneratevoteraccesscodes. Mitigations Alloftheissuesdiscussedabovestemfromthesameunderlyingarchitecturalissue: allthreede- vices assume that any device which talks to them and issues management-style commands is a legitimate management console. This assumption is incorrect and the failure to authenticate at- temptsatmanagementallowsanyattackerwhocanspeaktheprotocoltomanagethedevice. As noted above, it is conceivable to secure the ports on the eScan and the JBC but perhaps not the eSlate. To the extent that the seals are secure (see Section 3.5), this provides protection againstvotersandpollworkers,butnotelectionofficialswithaccesstounsealeddevices.Asealing strategyimpliesthatnoonewhoisnotcompletelytrustedcaneverbeallowedunsupervisedaccess toadevicewhichdoesnothaveitsportssealed. Thisisdifficultoperationalbartoclear. However, §6.1DeviceManagement 33 6. DetailedAnalysis asealingstrategymaybeusefulinadditiontootherhardeningstrategiesasabackupforpotential programmingerrorsinthesoftwaredoingaccesscontrol. Thereareanumberofmodificationstothesoftwarearchitecturethatwouldmitigatetheseis- sues. First,ifmanagementconsoleswererequiredtoauthenticatecryptographicallytothedevices theymanagedthiswouldsubstantiallyreducetheriskoffakemanagementconsoles. Note,how- ever, that the existing keying material management strategy (see Section 6.7) makes this difficult becausecompromiseofanysingledevicewouldallowtheattackertorecoverthekeyandmakea fakemanagementconsole. Publickeyauthenticationoftheconsoleswouldbesaferbutwouldbe asignificantarchitecturalshift. Evenifthemanagementconsolesweretobeauthenticated,therewouldbesubstantialresidual risk from an attacker who compromised a management console. This risk could be mitigated by substantiallyreducingtherangeofoperationstheconsolecouldmount. Inparticular,theconsole cancurrentlyloadarbitraryfirmware.IffirmwareneededtobesignedbyHartorathirdparty(and thiswasenforcedbythedevice)thenevenaroguemanagementconsolewouldnotbeabletoload maliciousfirmware. Inaddition,anumberoftheoperations(genericmemoryreadingandwriting inparticular)appeartobestrongerthanrequiredforamanagementsystem. Strictlytrimmingthis listtotheoperationswhichareabsolutelynecessaryformanagementwouldmitigatetherisk. Finally, the command set could be partitioned into commands which were accessible in the warehouseandcommandswhichwereaccessibleinthefield. Itisnotclearthatthereisanyactual need for field management, Special access (e.g., a PIN entered on the console) could be required toputtheunitintowarehousemode, andperhapstoreactivateit. Thiswouldlimittheexposure fromunauthorizedfieldmanagement. 6.2 eSlate-JBC Communication TheeSlatehasnoMBBofitsown. ThismeansthatitmustgetelectioninformationfromtheJBC towhichitisconnectedandmustreturnvotingresultstotheJBCforstorage. Thiscommunication that occurs over the eSlate-JBC interface using the standard Hart protocol (See Section 6.1). As discussedearlier,thisprotocolhasnosecurityfeatures,whichleadstoanumberofissues. In the Hart voting system a number of eSlates are connected to a single JBC in a daisy chain configuration, with the first eSlate connected to the JBC and each subsequent eSlate connected to the one before it, as shown in Figure 6.1. This network is used by the JBC both to communicate withandsupplypowertotheeSlates. eSlate 3 eSlate 2 eSlate 1 JBC Figure6.1: JBC/eSlateNetwork This broadcast network. All of the devices are electrically connected and any message sent fromanydevicetoanyotherdevicecanbeseenbyalltheotherdevicesinthenetwork. Theway that devices know which messages are intended for them is that there is additional addressing information (again, visible to all). This is a fairly common network design. Classic Ethernet, for instance,hassomesimilarproperties. 6.2.1 DetailedDescription Physically,thecablingisasfollows: §6.2eSlate-JBCCommunication 34 6. DetailedAnalysis • TheJBChasafemaleDE-9connectorontheback. • AcablewithamaleDE-9ononeendandafemaleHD-15ontheotherendrunstotheback oftheeSlatestandforthefirsteSlate. • TheeSlatestandhasamaleHD-15connectoronthebackandaninternalcablethatterminates inafemaleHD-15,whichplugsintotheeSlate. • TheeSlatehasamaleHD-15fortheabovecable. • AcableterminatinginafemaleHD-15comesoutoftheeSlateandisruntothebackofthe nexteSlatestand. • InthelasteSlate,thecableiscurledupandstuffedintoacompartmentinthestand. Electrically,thenetworkcontains: • OnepairofwiresforanEIA-485[9]controlchannel5 • OnepairofwiresforanEIA-485datachannel • +24Vpowerwires • Groundwires • Awireusedtosignal“lasteSlate” Onethingthatisconfusinghereisthatthenetworkissuperficiallyadaisychain: wirescomeinto aneSlateandthencomeout. It’snaturaltosuspectthateSlateOneforwardspacketstoeSlateTwo. Thisisnotthecase. Rather, allthedevicesareelectricallyconnected,itissimplythattheconnec- tiontakesplaceinsideeacheSlateratherthanexternallyasisthecasewith, forinstance, 10Base2 (Thinnet). Effectively,thisisapairofbroadcastnetworks,withonenetworkusedforcontroland theothernetworkusedfordata. Access to the network is mediated by the JBC which serves as the network master. The JBC uses the control network to tell the other nodes when to read and write. Only the JBC writes to the control channel and other nodes write to the data channel only when told to over the control channel. Signalingonbothchannelsisclockedatanonstandard938kbps. NotethatthefactthattheJBCisthenetworkmastermeansthatnoeSlatecaneversayanything that’s unsolicited. Since eSlates do sometimes need to initiate communication with the JBC—for instancetorecordCVRs—theJBCpollseacheSlateperiodicallytoseeifithasanythingtosay. Ifit does,itsendsitaquerytogetthedata. 6.2.2 TappingtheInterface Because this is a broadcast network, tapping it is straightforward. We were successfully able to connecttothisinterfaceusinganAaxeonMSC-102Bdual-portEIA-485card. Usingapinoutsup- plied by Hart and supplemented by our own analysis of the interface we built a cable to bridge the HD-15 output of an eSlate to our own PCI EIA-485 card. The maximum rated clock speed of thecardisat921.6kbps,butthisisapparentlywithinerrorlimitsbecauseclockingourcardatthis rate enabled us to capture both the control and data channels. Because we were able to capture messagesbetweentheeSlateandtheJBCwhilesniffingafterthefinaleSlateinthechain, thisex- perimentconfirmsthatallnodesreceiveeachmessage. NotethatthecablefromthefinaleSlateis exposedandthereforecanbetappedwithoutunplugginganydevices. 5EIA-485isadifferentiallysignaledmultipointserialinterface(hencetheneedfortwowires). §6.2eSlate-JBCCommunication 35 6. DetailedAnalysis 6.2.3 HijackingtheInterface Tapping the network allows the attacker to have access to the contents of messages flowing over it, but this only allows a small number of attacks. More attractive to the attacker is to hijack the network. I.e.,wewouldliketo: • PretendtobeanextraeSlate • PretendtobeanexistingeSlatetotheJBC • PretendtobetheJBCtotheeSlate This would allow you to send messages and affect the behavior of other nodes, rather than just broadcasting. The difficulty here is that because messages are broadcast, the attacker has to compete with whatever node he is impersonating. So, for instance, if he is pretending to be eSlate Two, he has to worry that messages that are coming back to him are also read by eSlate Two and that it gets confusedbytheunexpectedmessages.EvenmoredifficultisthatthetheeSlatebeingimpersonated istryingtotransmitattheexactsametimetheattackeris,whichcausesconflicts. Therearetwomajorapproachestoattackingsuchanetwork. UsingaProxy Because what makes attacks difficult is that the network is broadcast, the natural approach is to removethatproperty. Attacker eSlate 3 eSlate 2 eSlate 1 JBC Figure6.2: JBC/eSlateNetworkProxy InFigure6.2,theattackerinterposeshimselfbetweeneSlatesTwoandThreeandseparatesthe networkintotwonetworks6 HereceivesallmessagesdirectedtoandfromeSlateThreefromand totherestofthenetworkandcanpasson,change,ordropanymessageshechooses. Asfarasthe restofthenetworkisconcernedheiseSlateThreeandasfaraseSlateThreeisconcerned,heisthe restofthenetwork. This allows complete control of all transmissions crossing the Attacker’s device, but has two disadvantages from the perspective of the attacker. First, it cannot be mounted purely from a compromisedeSlate. Theattackermustleaveadeviceinplacefortheentiredurationoftheperiod he wishes to mount his attack. The device could probably be fairly small (about the size of a matchbox) and could easily be put in place on the input port of an eSlate. Nevertheless, it might stillbenoticed. Second,theattackercanonlyimpersonatetheJBCtodevicestotheleftofhisdevice(andvice versa). This limits his control and motivates placing the device between the JBC and eSlate One, whichmaybemorenoticeablesinceeSlateOneisclosesttothepollworkers. InstallingsuchaproxyalsorequiresdisconnectingthecableleadingintotheeSlate,whichmight benoticeable. TheHartcurbsidevotingfeatureappearstomakethispractical: onceavotercode has been entered into an eSlate, if the JBC loses contact with that eSlate, it assumes that it is in curbsidevotingmode,logsthefact,andwaitsforitsreturn. EveniftheJBCdoesnoticethatanode hasfailedanddisablesit,theattackercanprobablyconvincepollworkersitwasaninnocentfailure and have them correct it, possibly by rebooting the entire system. The Hart documentation [16] 6Technically,fournetworks,withtwoEIA-485networksoneachside. §6.2eSlate-JBCCommunication 36 6. DetailedAnalysis describeshowtoclearsucherrorsanddoesnottreatthemassecuritycritical. Notethatoncethe attackerhascompromisedtheeSlatehecancauseittodisplayanyerrormessageofhischoice. SharingtheNetwork Fromattacker’sperspective,amoreattractivealternativewouldbetotakeoverasingleeSlateand thenuseittoimpersonateothereSlatestotheJBCandtoeachother. Thisavoidstheneedforany long-termdevicewhichmightbedetected. Arelatedtechniquewouldbetoplugintothedangling endofthecablefromthefinaleSlateandpretendtobeoneoftheexistingnodes. Technically,however,thisisamoredifficultproblem. Themostlikelyavenuewouldbeto“co- master” the network, i.e., pretend to be the JBC. The general idea would be to issue one’s own network control messages at times when the JBC was silent (most of the time). Analysis of the sourcecodesuggeststhattheJBCignorescontrolchannelmessagesnotdirectedtoit, thereforeit should be fairly oblivious to attempts to control the network. More difficult is stopping the JBC fromreceivingdatamessagesfromtheeSlatesdirectedtoit(recallthatweareimpersonatingthe JBC)ordatamessageswhichweareusingtoimpersonateit. Webelievethatthiscanbedealtwithbytheattacker.First,theJBCappearsonlytopayattention toresponsesfromnodesitexpectstoreceivedatafrom,sowithcarefultimingitmaybepossibleto minimizeexceptionsontheJBC(whichisreasonablyresilientinanycase). Second,First,inmany casesitispossibletosendmessageswitharesponseaddressof0,whichmeansthatthereshouldbe noresponse. InsuchcasesthereisnoneedtosuppresstheJBCfromreadingtheresponses. Third, theattackercouldtransmitajammingsignalintimewiththeresponseinordertogenerateabogus message checksum, which will cause it to be ignored by the JBC. This works best with messages whichweplantoignoreinanycasebutwhichmightconfuseotherunits. Clearly,allofthesetechniquesaremorecomplicatedthanthesimpleproxyapproachdescribed in Section 6.2.3. The advantage is that they can be mounted from a compromised eSlate without anyspecialhardware. Issue5:eSlate-JBCcommunicationisinsecure The JBC and the eSlate are in constant communication. This communications channel is used foranumberofpurposes,including: • ManagementoftheeSlate(seeIssue2). • TransmittingballotinformationtotheeSlate. • AllowingtheeSlatetocheckthevalidityofavoteraccesscode. • TransmittingCVRstotheJBCfromtheeSlate. Thischannelisnotcryptographicallysecuredinanyway,thusallowinganattackerwhocanaccess theinterfacetoimpersonateaneSlatetoaJBCorvice-versa. Detailed Description There is no cryptographic protection for messages on the eSlate-JBC net- work and therefore there is no authentication, message integrity, or confidentiality. Any attacker who can access the network can transmit any message he wishes on the interface and have it ac- ceptedascomingfromanysourceaddresshechooses. Hecanalsoviewanymessageswhichare transmittedonthenetwork. Inparticular,anattackerwhocontrolledthisnetworkcould: • PretendtobeaJBCand“accept”aCVR,thuspreventingitfrombeingrecordedbytheJBC. • PretendtobeaJBCandlietotheeSlateaboutthevalidityofavotercode,thusallowingan illegitimatevotertovoteorblockingalegitimatevoterfromvoting. §6.2eSlate-JBCCommunication 37 6. DetailedAnalysis • Pretend to be an eSlate and send spurious votes to the JBC (this is potentially enhanced by Issue8). • Watcheachvoteasitiscast. As an example, consider the first attack. The JBC periodically polls every eSlate to see if it has a CVRtodeliver. WhenitgetsapositiveresponseitsendsamessagetoretrievetheCVRandthen resetstheeSlate’sstate. AnattackerwhocontrolledthenetworkcouldpretendtobetheJBCandretrievethevote,thus leavingtheeSlatethinkingithaddeliveredthevotewhilethetrueJBChasnotinfactstoredacopy. ItcouldsimultaneouslypretendtobetheeSlatetotheJBCandstorevotesofitschoice,replacing therealeSlatevotes. Theotherattacksproceedinasimilarfashion,withtheattackerpretendingto beonesideortheother. Notethatvoteobservationcanbedonepurelypassively,i.e.,bysnooping on the shared communication network. Any eSlate can observe all the communication from any othereSlateconnectedtothesameJBC. Onedifficultyhereisthatbecausethisisabroadcastnetwork,andthereforeimpersonatingan existingnodemaycauseproblemsforothernodes.Earlierinthissectionweoutlinesomepotential waystobypassthisobstacle.Anattackerwhoispresentatthebeginningoftheelectioncansimply pretendtobeanonexistenteSlate,providedthatfewerthan12eSlatesareinuse.Thisavoidsissues abouthijackingforeSlateimpersonation. Prerequisites Inordertoexploitthisissuetheattackerwouldneed: • TohavedecodedtheprotocolusedbyHart. • AccesstotheserialportontheeSlateduringanelection. AsindicatedinSection6.1webelievethatanattackerwhohadanopportunitytoobservearunning systemcoulddecodesubstantialportionsoftheprotocol. Currently,anyvoterhasaccesstotheserialportontheeSlateandcaneasilyremovetheconnec- tor. TheeSlateisdesignedtobedisconnectedtoenablecurbsidevotingandthereforeitispossible toremovethelasteSlateinthechainwithoutgeneratingalerts. Inaddition,anattackercouldpo- tentiallyconnecttotheoutgoingcableonthelasteSlateinthedaisychain,whichissimplystored inacompartmentintheeSlatestand. Theattackerhastohavesomesortofaccesstotheserialportfortheentireperiodoftheattack. Thisdoesnotimplythattheattackerisphysicallypresentthewholetime,merelythathisdeviceis attached. Weanticipatethatthedevicecouldbemaderelativelysmall,ontheorderofamatchbox. Nevertheless,thispresentssomeriskofdiscovery. Impact Theimpactoftheseattacksdependsonwhichdeviceisbeingimpersonated.However,in generalitwouldbepossibletoinjectfalsevotesintotheJBC(whichwouldnotmatchtheVVPAT ortheeSlatememory),removevotesfromtheeSlate(butnotfromtheVVPATorJBCmemory),or allowanattackertoappeartovotemultipletimes. Thisfinalattackwouldcreatematchingentries intheVVPAT,eSlatememory,andJBC,thoughthelogsofhowmanyindividualshadvotedwould notmatchthenumberofvotescast. Mitigations OnepotentialmitigationistoseverelyrestrictaccesstotheeSlateserialport. How- ever,thisisdifficultforanumberofreasons,includingthedesiretoenablecurbsidevoting. Itmay be possible to restrict voter access, but because the poll workers assemble the eSlate/JBC daisy chain at the polling place, it is likely to be extremely difficult to secure their access. Note that a small device placed between the eSlate serial cable and the connector is sufficient to mount this attack. Another mitigation would be to cryptographically authenticate the eSlate to the JBC and vice versa. Thiscouldbedoneinanumberofways. OnepossibilityisfortheeSlateandJBCtousethe globaleCMkeytoauthenticateeachother. Thishasseveraldifficulties. First,thateCMkeyneeds §6.2eSlate-JBCCommunication 38 6. DetailedAnalysis tobeinstalledintheeSlate,whichcurrentlywouldhavetobedoneoverthisinterface. However, it might be possible to do that installation securely in the warehouse and then set the eSlate to use cryptographic protocols from there on. Second, compromise of any unit in the entire county potentiallyleakstheeCMkeyandwouldallowthisattacktoproceed. AnotherpossibilitywouldbeusepublickeycryptographytoauthenticatetheeSlateandJBCto eachother.Aswithsymmetriccryptography,onewouldsecurelyinstallknowledgeoftheexpected peer’spublickeyoneachdeviceandtheywouldrefusetoconnecttoanyotherdevice. Onediffi- cultyhereisthatthisseverelyreducestheflexibilitytomix-and-matchdeviceswithinandbetween precincts. Anadditionalproblemwithanycryptographicsolutionisthatitrequiressomemechanismto reprogramthekeyingmaterialonthedevice. Thatmechanismthenbecomesapotentialtargetof attackandsomustbedesignedcarefully. Status This issue was discovered by examination of the source code. We have verified that we canobservecommunicationsbetweentheJBCandeSlateandwereabletoverifythelackofcryp- tographicsecurity. Wehavenotattemptedtoimpersonateeithersideofthecommunication. Issue6:FormatstringvulnerabilitiesinJBCreportmode AformatstringvulnerabilityintheJBC’swrite-insummaryreportmayallowanattackerwho hadcausedtheJBCtorecordspecially-formattedvotestocompromisetheJBCafterpollsareclosed. DetailedDescription Attheendofvoting,pollworkersinstructtheJBCtoclosethepolls,after whichnofurthervotesareaccepted.Oncepollsareclosed,theJBCallowspollworkerstoproduce, ontheJBC’sinternalprinter,anyofthreereports:avotercodesummary;avotetally;andawrite-in report. For each precinct, for each party, and for each contest, the write-in report lists the candidate namesincludedinwrite-infieldsandhowmanyvoteseachreceived. TheJBCproducesthisreport byexaminingthevotesinitsinternalCVRlog. While write-in candidate names are massaged, for example to remove leading and trailing whitespace, it appears that no attempt is made to filter out printf format specifiers (such as “ %d”). What’smore, thePrintWriteInsroutine, whichiscalledforprintingeachwrite-inentry inthesummary,passesthecandidatenametoprintf7 astheformatstring,ratherthanusingan idiomsuchasprintf("%s",str). ThismakestheJBCvulnerabletoaformat-stringattack[13]: aspeciallycraftedwrite-incandidatenamerecordedintheJBCCVRlog, whenprocessedaspart ofthewrite-inreport,allowsmemoryoverwritesarbitrarycodeexecution. Prerequisites Inordertoexploitthisissuetheattackerwouldneed: • Tocauseavotecontainingaspeciallycraftedwrite-incandidatenametoberecordedinthe JBC’sCVRlog. • Tocauseapollworkertorequestawrite-inreport. It is not normally possible to input format specifiers using the eSlate on-screen keyboard. An attackercouldneverthelesscausevotescontainingtheappropriatespecifierstoberecordedeither by compromising an eSlate (Issue 2) or by tapping the JBC-eSlate communication network and impersonatinganeSlate(Issue5). 7Moreprecisely,topprintf,whichpassesittovsnprintf §6.2eSlate-JBCCommunication 39 6. DetailedAnalysis Impact A JBC can only be compromised using this vulnerability once polls have closed. This is, of course, too late to have an effect on the system’s behavior towards voters. Nonetheless, a compromisedJBCcanstilldoanyofthefollowing: • modifyitsinternalauditandCVRlogs; • modifytheauditandCVRlogsontheMBB,eithertomatchthemodifiedlogsontheJBCor toexploitavulnerabilityinTally(cf.Issue14); • leakthecryptographickey(cf.Section6.7);and • usetheJBC-eSlateinterfacetomodifythelogsontheeSlatesorinstallnewsoftwareonthem (cf.Issue2). AcompromisedJBCcanalsobeusedtomountattacksonback-endsystems,forexampleonSERVO (cf.Issue13). Mitigations Until Hart fixes this vulnerability, poll workers could disconnect eSlates from the JBCbeforerequestinganyJBCreports;thisensuresthataJBCcompromisedthroughvulnerabilities relatedtoitsCVRparsingcannotmodifytheauditandCVRlogsstoredontheeSlates. Thisdoes not, however, mitigate the risk of SERVO being compromised through a compromised JBC (see Issue13). Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenotattemptedto verifyit. Issue7:TheJBCaccesscodegeneratorisinsecure Voter codes, printed at the JBC, are intended to prevent voters from registering unauthorized votesataneSlate. Thesecodesarepredictable: anyonewhoseesasinglevotercodecancompute thesequenceofallsubsequentvotercodes. DetailedDescription TopreventunauthorizedvotersfromusinganeSlate,Hartemploysvoter codes—four-digitpseudorandomnumbersprintedontheJBCthatthevotertypesintotheeSlate. AvoterentershisvotercodeonaneSlatetobeginvoting. TheeSlatecheckswiththeJBCthat thecodehasbeenissuedandisunused. Ifthisisthecase,theJBCmarksthecodeasused,andthe eSlateallowsthevotertomakehisselections. Castingaballotinvalidatesthevotercode. The algorithm that generates these voter codes uses a poor design that makes it possible to predictcodes. TheJBCpicksarandominitialindex,between0and9999. TheJBCgeneratesavoter codebyapplyinganunkeyedpermutationtothecurrentindex;itthenincrementstheindex. Permutations, of course, can be inverted. Applying the inverse permutation to a voter code givesthecurrentindex.Allsubsequentvotercodescanbedeterminedbyapplyingthepermutation tothecomputedindexplusone,plustwo,andsoon. (ThisissuewasfirstdiscoveredbyProebsteletal.[26]inananalysisofHartsystemswherethey didnothaveaccesstoanysourcecode.) Prerequisites Inordertoexploitthisissuetheattackerwouldneedtoobserveasinglevotercode, forexamplebyvoting. Also,theattackerwouldneedtoknowthepermutation,whichisfixedfor theentireHartsystem. Impact Anattackercouldpredictvotercodes. Usingthese,hevoteinplaceofanothervoter: He mustwaitfortheothervotertobegivenavotercodefromapollworker. Beforethatvoterreaches aneSlateandsignsinusingthecode,theattackersignsinonanothereSlates.Theattackercannow vote as he pleases, whereas the legitimate voter will receive an error message indicating that his votercodeisalreadyinuse. §6.2eSlate-JBCCommunication 40 6. DetailedAnalysis Mitigations Pollworkersshouldbevigilantforinstanceswherenewlyissuedcodesappeartobe alreadybeingused.Theseoccurrencescouldbeindicativeofthisattackorofvoterswhoattemptto double-votebyusingthesamecodetwice. Pollworkersshouldalsobeawareofvoterswhospend anunusuallylongtimeinthevotingarea. Hart could revise the software running on JBCs to produce cryptographically unpredictable votercodes. Asimplewaytodothisisasfollows. Startanindexat0,andincrementitwitheach vote. To produce a voter code, apply a keyed function to the index, where the key is chosen at random at startup. A good choice is to apply AES (with a randomly-chosen 128-bit key) to the index,andoutputtheresultmodulo10,000. Thekeyshouldbegeneratedusingasourceofstrong randomness;theClibrary’srandfunctionisinsufficient. Status This issue was discovered by examination of the source code. We have developed an access code predictor and verified it against a real access code sequence from a JBC, provided by Proebstel. Issue8:TheJBCwillacceptvotesfromeSlatesthatarenotinanauthorizedstate Votercodes,printedattheJBC,preventvotersfromregisteringunauthorizedvotesataneSlate. As currently engineered, they do not prevent a compromised, malicious eSlate from registering arbitrarilymanyvoteswithoutavotercodeandwithoutavoterpresent. DetailedDescription TopreventvotersfromregisteringunauthorizedvotesusinganeSlate,Hart employsvotercodes—four-digitpseudorandomnumbersprintedbytheJBCthatthevotertypes intotheeSlate. TheeSlatessendtotheJBCtheirmostrecentvotercodeaspartofeachstatusmessage; status messagesaresolicitedbytheJBConceeverysecond. The JBC keeps a list of valid voter codes. When a voter types a voter code into an eSlate, the eSlatecheckswiththeJBCthatthecodeisvalidbysettingaflaginitsstatusmessagerequestfield, whichpromptstheJBCtoverifythatthecodeisvalidandnotyetassignedtoassignedtoanother eSlate. The JBC then logs the code as assigned to the eSlate and communicates to the eSlate to proceedwithvoting. Oncethevoterhasfinishedvoting,theeSlatesignalsthatithasavotereadybysettingasecond flag in its status message request field, which prompts the JBC to ask the eSlate for the CVR and torecordtheCVRinitsCVRandauditlogs. TheJBCthenremovesthevotercodeassociatedwith thateSlate(thecodethatwastransmittedwiththateSlate’smostrecentstatusmessage)fromthe activecodelist. Ifthecodeisnotnotfoundontheactivecodelist,noerrorisraised,andthevote isstillrecorded. TheJBChasenoughinformationintodetermine(1)whetherthevotercodewasgeneratedby theJBC;(2)whetherthevotercodewasalreadyusedbytheeSlatevotingusingit;and(3)whether thisisthefirstandonlyvotebeingrecordedbythiseSlateusingthisvotercode. Ourinspectionof thesourcecodesuggeststhattheJBCdoesnotperformanyofthesechecks. Acompromised,maliciouseSlatecanthusrecordarbitrarilymanyvotes,eachwithanarbitrary votercode. (NotethatvotercodesareincludedintheauditlogsbutnotinCVRlogs;however,the twologscanbecorrelated. SeeIssue25.) Prerequisites Inordertoexploitthisissuetheattackerwouldneedtohavesubvertedorbeim- personatinganeSlate. Impact ThesubvertedorfakeeSlatecanrecordarbitrarilymanyvotesandthusengageinballot- stuffing. §6.2eSlate-JBCCommunication 41 6. DetailedAnalysis Mitigations Electionofficialscananalyzetheauditlogstoverifythateachgeneratedvotercode corresponds to at most one recorded vote, and that the eSlate to which the code was assigned is theonethatrecordsthevote. Thisanalysiswouldallowofficialstodetecttheattack,butitwould beimpossibleforthemtodistinguishwhichofseveralvotesrecordedfromasingleeSlateusinga singlevotercodeisvalid;seeSection7.2.2. Hart could revise the software running on JBCs to automatically perform the checks recom- mendedabove,andtowarnpollworkersofattemptstoregisterunauthorizedvotes. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenotattemptedto verifyitbyimpersonatinganeSlate. 6.3 Software Integrity Checks Hartappearstohavebeenawareofthepossibilityofmaliciousfirmwarereplacementandtohave takenstepsdesignedtopreventit. Inparticular,thefollowingfourmechanismsareused: • The eSlate and the JBC both run internal memory consistency checks designed to detect changesintherunningfirmware. • TheJBCchecksitsownversion. • SERVOcanbeusedtoverifythefirmwareimageontheJBC,eSlate,andeScan. • TheJBCcheckstheversionofconnectedeSlates. Allofthesemechanismsappeartofunctioncorrectlyfordamagedfirmware;however,theyappear tobevulnerabletoattackbymaliciousfirmware. Issue9:eSlate/JBCinternalCRCchecksdonotdetectattacks eSlateandtheJBCruna“backgroundtask”whosejobistocheckmemoryintegrity. Thistask starts with a list of memory regions and their expected CRC-16 values and compares the actual CRCsoftheregionstotheexpectedCRC.Thischeckingislikelytobeeasilybypassed. DetailedDescription TheeSlateandtheJBCbothrunabackgroundtaskwhichperformsmem- ory checking. It is provided with a list of code sections to check8 and their CRCs, presumably computed during the binary build process. Every ten seconds it walks through the list and com- parestheCRCsoftheregionstotheexpectedCRCs. Webelievethereareanumberofavenuesforbypassingorotherwiseavoidingthischeck.These include: • InsertingnewcodewiththesameCRC-16value. Thisiseasytodoifyouhaveevenasmall amount of control over the instructions generated, as CRC-16 is not a secure hash function. Approximately16locationswheretherearetwoalternativeinstructionsareenough. • Overwriting the check list. This is likely to be possible in the 10-second interval between checks. • Patchingthecodethatrunsthecheckssothattheyarenolongerrun. • Patching the firmware and section list in firmware and not in memory. Once the error is caughtitcausesasystemcrash. Whenthesystemrestartsitwillhavethenewfirmwareand sectionlist,soit’snotclearthiscanbedistinguishedfromasimplecrash. We emphasize that we have not attempted any of these approaches because we did not have an opportunitytouseadevelopmentkittogeneratenewfirmwarefortheJBCoreSlateandonlyhad limitedaccesstobothdevices. However,thesearestandardtechniquesandseemlikelytowork. 8Wedonothavealistofthosesections. §6.3SoftwareIntegrityChecks 42 6. DetailedAnalysis Prerequisites Anyattackerwhohastheabilitytoloadanewbinaryimageononeofthesedevices couldexploitthisissue. Impact Thisissuedoesnotitselfallowcompromiseofasystem. However, itallowsanattacker whohascompromisedavotingdevicetoavoiddetection. Hart’stamperdetectionroutinesarenot themselvestamperresistant. Mitigations Theproblemofhavingaprogramverifyitsownintegrityisverydifficultagainsta cleverattacker. The“matchingCRC”approachcouldbemitigatedbyusingasuperiorhashsuch asSHA-1,butthiswouldnotpreventtheotheravenuesofattack. Avarietyoftechnologies,such asTrustedPlatformModulechips[25,33],arenowcommerciallyavailable. Futureversionsofthe Hartsystemcouldinvestigatetheuseofsuchhardwarefeatures. Likewise,Hartcouldinvestigate softwareattestationtechniquessuchasPIONEER[30,12]. WiththepresentHartsoftwareandhardware,therearenoeffectivemitigationsagainstthisat- tack,beyondproceduralmeasuresaimingtolimitanattacker’sabilitytoinstallmalicioussoftware. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenottesteditona runningsystem. Issue10:JBCinternalversioncheckingisbroken The JBC has some internal version checking, but it is unclear how it is intended to work. It appears to only check two compiled-in numbers against each other and then log an error rather thanexitingifthereisafailure. DetailedDescription Onbootup,theJBCattemptstoverifyitssoftwareversion,ultimatelyfetch- ing a a compiled-in value. This value is then logged and “success” is indicated as a return code. Iffailurewereeverindicated,thesystemwouldexit,butsinceitcannot,thisfunctionalwayssuc- ceeds. Perhapstheimplementationofthisfeatureisincomplete. Impact We don’t understand the purpose of this set of checks. An attacker can compile in any versionnumbertheywantandit’snotclearthattheauditlogsarecheckedforversionnumbersin anycase. However,whateverbehaviorthischeckissupposedtoprevent,itseemsunlikelythatit doesso. Mitigations Unknown. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenottesteditona runningsystemtoseeifwemisunderstanditsfunction. Issue11:SERVO-baseddevicefirmwarecheckingcanbespoofed SERVO can be used to verify the firmware of voting devices against an official firmware in- tegrity file provided by Hart. This file contains SHA-1 digests of the firmware images. SERVO downloads the firmware images from the target device and then computes the digest and com- paresitwiththerecordedhash. Iftheydonotmatch,SERVOsignalsanerror. However,because the firmware image is provided by the running program, a malicious image can simply provide datathatfoolsthecheck(e.g.,bymaintainingabackupcopyofthelegitimatefirmwareimagefor purposesofcomputingtheseSHA-1digests). §6.3SoftwareIntegrityChecks 43 6. DetailedAnalysis Detailed Description SERVO maintains a database of all known devices owned by the county, partly for inventory control purposes. When a new device is introduced into the system (this is determinedbythe32-bitdeviceID),itoffersanoptionto“Verify”thatthedevicecontainstheex- pectedfirmwareimage. Verificationisdonebycomparingthehashofthedevice’sactualfirmware totheknown-goodhash. SERVOstoresknown-goodhashesforeachtypeofdeviceinitsdatabase; theseareloadedfromanXMLfilesuppliedbyHartusingSERVO’s“ImportFirmwareDataFile...” menuitem. Theverificationprocessisasfollows: 1. InterrogatethedeviceforitsdeviceID. 2. Ifthedeviceisalreadyinthedatabase,exit. 3. Retrievethedeviceversionnumberandcompareittotheexpectedversion. 4. Ifthedeviceisn’tinthedatabase,downloaditsfirmware.OntheeScanthisisdonebyreading thefileeScan.exeusingtheFILE_CMD_GETcommand. OntheJBC/eSlatethisisdoneby usingtheMEM_READcommandtoreadtheappropriatememoryblock. 5. Oncetheentirefirmwareimageisrecovered,itishashedwithSHA-19 andthehashiscom- paredtotheexpectedvalue. Thistechniquehasseveralproblems. Thefirstisthatthefirmwareisonlycheckedthefirsttimea deviceisloaded. Wedonotknowifthedatabaseiszeroedbetweenelections,butifitisnotthen subsequent compromises will not be detected. Second, it is dependent on the device’s providing the correct device ID. It is unclear what happens if the device provides the device ID of another, alreadychecked,device. Theseissuescouldpresumablybedealtwithbyforcingacheckeverytime. However,themore seriousissueisthatthecommandsthatSERVOusestodownloadthefirmwareimageareexecuted bytheprogramrunningontheeScan,JBC,oreSlate. Ifthatprogramhasbeencompromiseditcan simplyhandbackthecontentsofavalidbinaryeventhoughthosedonotreflecttheprogramthat isactuallyrunning.Anotherwaytobypassthischeckwouldbetohavethelastactofthemalicious imageuponelectionclosebetocopythecorrectimagebackontothemachine. ThecurrentimplementationoffirmwarecheckingalsoleavesSERVOvulnerabletocompromise byamaliciouseScan;seeIssue13. Prerequisites Anyattackerwhohastheabilitytoloadanewbinaryimageononeofthesedevices couldexploitthisissue. Impact Thisissuedoesnotitselfallowcompromiseofasystem(see,however,Issue13).However, itallowsanattackerwhohascompromisedavotingdevicetoavoiddetection. Mitigations Theproblemofverifyingthataparticularpieceofsoftwareisrunningonaremote system (attestation) is known to be extremely difficult. The obstacle is exactly as seen here—you needtocommunicatewiththesystembutyouaredoingsothroughapieceofsoftwareyoudonot yet trust. One commonly suggested strategy is to have a supervisor process which intercepts the communication and vouches for the binary. The supervisor itself is not field replaceable. This is difficultinthissettingfortworeasons. First,theJBCandeSlatehavenosuchsupervisorprocesssoimplementingthisapproachwould requireverysignificantrearchitecture.eScanrunsWindowsCEandsoitmightbepossibletoinstall suchasupervisor. However,thehistoryofoperatingsystemsecuritysuggeststhatonceattackers are able to run code at all on a target system they are typically able to escalate their privileges to supervisorstatus. 9Thefileformatallowssomeflexibilityinthis,butSHA-1appearstobewhat’sused. §6.3SoftwareIntegrityChecks 44 6. DetailedAnalysis Second,thisdoesnotsolvetheproblemofanattacker’scompletelyreplacingallthesoftwareon themachine,includingthesupervisor.Dependingonthearchitecture,thismightinvolvehardware hackingbutisgenerallynotimpossible.Inthelimit,theattackercansimplygutthemachine,install hisownprocessor,andrunavirtualizedversionoftheHartsoftware. Anothersuggestedapproachwouldbetomovethefirmwarecheckingtothedevicebyrestrict- ingittoloadingonlytrustedfirmware. Thiswouldrequiresuperiormemorycheckingtothatused by Hart (see Issue 9), which may or may not be practical. It would also not provide resistance to completereplacementattacks. Thehistoryofattemptstobuildrestrictedloadersisnotparticularly good[32]. The only known workable strategies for remote attestation involve trusted hardware on the targetsystem(seeIssue9). Thathardwarecanverifytherunningmemoryimageandcryptograph- ically signs the results for consumption by the verifier. This approach would require extensive modification of Hart’s devices, both from a hardware perspective and in order to introduce the cryptographicinfrastructureusedforverification. Analternativetoremoteattestationislocalattestation,byhavingSERVOreadthefirmwareof thetargetdevicedirectlyratherthanthroughthedevice’ssoftwarestack.Thiswouldeitherrequire interfacing the device non-volatile memory to a new external port (a potential source of security holes)orphysicallyremovingthenon-volatilememoryinthewarehouseandverifyingitdirectly. TheHartdevicesdonotappeartobedesignedtomakeeitherapproacheasy. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedatool which runs on an ordinary Linux PC and will accept a connection from SERVO, pretend to be aneScan,andreturnabinarytakenfromarealeScan. Thisbinaryproducesthesamehashasthat providedbyarealeScan.Wehavenotrunthroughtheentirebackupandresetprocessbecausethis wouldinvolvewritinghandlersforothereScancommands. However,webelievethisispractical todogivenmodestlymoretime. Issue12:JBC-basedeSlatefirmwarecheckingcanbespoofed The JBC attempts to check the integrity of the eSlate firmware. As with Issue 11, this check dependsonthetargetdevice’stellingthetruth,whereasacompromiseddevicecanandwilllie. Detailed Description When a JBC connects to an eSlate, it gets the eSlate device information. TheresponsecontainstheeSlate’ssoftwareversionandthe“privateID”whichappearstobesome sort of CRC value. It then compares the major version of the eSlate software (ignoring the minor version) against its own version, which is hardcoded. If that matches, the eSlate is judged to be acceptable. Because this value is under the control of the eSlate software, this may be useful as a compatibilitycheckbutisuselessagainstamaliciouseSlate. Inaddition,thischeckisonlydoneat startup,soaneSlatecompromisedduringanelectionwouldgoundetected. Prerequisites Anyattackerwhohastheabilitytoloadanewbinaryimageononeofthesedevices couldexploitthisissue. Impact Thisissuedoesnotitselfallowcompromiseofasystem. However,itallowsanattacker whohascompromisedavotingdevicetoavoiddetection. Mitigation SeethemitigationdiscussionforIssue11. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenottesteditona runningsystem. §6.3SoftwareIntegrityChecks 45 6. DetailedAnalysis 6.4 Buffer Management Vulnerabilities in Back-End Systems Theback-endelectionmanagementsystems(BOSS,SERVO,Tally,BallotNow)areprogramsrun- ningonstandardWindows-basedPCs. Itisexpectedthatphysicalaccesstothesesystemswillbe restrictedtoauthorizedpersonnel. Despitethis,therestillremainseveralavenuesthroughwhich attackscanbemounted,including: MBBstransportedfrompollingplaces areconnectedtoback-endelectionsystems. TheseMBBs couldhavebeentamperedwith,asdescribedinSection6.8. Pollingplaceequipment couldbeconnectedtotheSERVOsystempost-election. Thisequipment couldhavebeentamperedwith(asdescribedinSection6.1). ConnectionsfromaTallysystem toaRallysystemcouldbemadeforthepurposesoftransferring electiondata. IftheRallysystemwerecompromised,itcouldbeusedtopropagateattacksto Tally. (SeealsoSections6.9and6.6.) Malicioususeofelectionmanagementsystems byauthorizedpersonnel. As a result, great care should be taken to secure the back-end systems at the points where they interactwithotherelectionsystems. Issue13:MultiplebufferoverflowsinSERVO Afteranelection,SERVOisusedbyelectionofficialsforverificationandbackupofthepolling placedevices. Inparticular,itisusedto: • VerifythefirmwareontheJBC,eSlates,andeScan • BackuptheCastVoteRecordlogsfromtheJBC,eSlates,andeScan • BackuptheauditlogsfromtheJBC,eSlates,andeScan Each of these routines contains buffer overflows which we believe to be exploitable, allowing an attacker who has compromised the connected device to execute arbitrary code on the machine runningSERVO. DetailedDescription Alloftheseoverflowsfollowroughlythesamepattern: SERVOallocatesa bufferofagivensizetoreaddatafromthedevice. Itthenreadsablockofdatafromthedevicebut allowsthedevicetospecifythesizeofthedata,withoutcheckingwhetheritwillfitinthebuffer. This allows an overflow which corrupts the malloc arena, which can be exploited using known techniques[23,2]. As a specific example, consider an overflow in the firmware verification routine. SERVO in- vokes FILE_CMD_GET to read 1000 byte extents of the eScan executable10 (stored as a file on the eScan flash memory) into a local buffer. However, it allows the eScan to tell it the length of the returned buffer (likely in order to detect the end of file by a short read). The eScan can cause an overflowofthebufferbyreturningalengthgreaterthan1000. Thebufferisallocatedontheheap andispromptlyfreed,whichiseasilyexploitableduetothedetailsofthemallocimplementation used. ThisparticularattackappearstoworkonlywiththeeScanbecauseadifferentcommandisused toreadtheeSlateandJBCfirmware;however,theCVRlogandauditlogbackupissuesappearto applytoallthreedevices. Weareawareofotherpotentialissuesthatappeartobesomewhathardertoexploit. 10Strangely,thecommentforthissizedefinitionreads16k bytes. §6.4BufferManagementVulnerabilitiesinBack-EndSystems 46 6. DetailedAnalysis Prerequisites Inordertoexploitthisissue,anattackerneedstotakecontrolofadevicewhichwill laterbeverifiedorbackedupwithSERVO.Wehavealreadydescribedanumberofissueswhich shouldallowthis(seeSection6.1). Note that the exploit described above requires that the device appear to be a “new” device in order to activate the verification routine. However, as the eScan can provide a device ID of its choosing, this should be easy to do even with a pre-verified device. The other routines do not sufferfromthislimitation. Notealsothatwhilerunningtheverificationandbackupproceduresisnotrequiredforcorrect functioningoftheHartsystem,itappearstobeHart’srecommendedprocedureandcheckingthe “verify” checkbox is simply treated as part of the backup procedure in the SERVO documenta- tion[19]. Impact The immediate impact of this attack is to allow the attacker to run arbitrary code in the SERVO process. This will generally also allow the attacker to run a program on the SERVO ma- chineastheSERVOuser,aswellastomodifySERVOasdesired. Itisnotnecessarytoescalateto Administratorprivileges;nevertheless,techniquesfordoingsoarewell-known. Forthelong-termimpactofthisattackseeSection7.4. Mitigations Theseattackscouldbedirectlymitigatedbyfixingthespecificoverflows. However, thefactthatwewereabletoreadilydiscoverthreesimpleoverflowsinaverysmallsectionofthe SERVOcodebasesuggeststhatSERVOisinsufficientlycarefulaboutcheckingtheinputitreceives fromdevicesitissupposedtobechecking. Itwouldnotbesurprisingtodiscoverotherremotely exploitablevulnerabilitiesofthesametype. SeeSections5.3and6.11formoreonthispoint. Status These issues were discovered by examination of the source code. We have directly ex- ploited the first of the three attacks (through the firmware verification routines) against our own copyofSERVOinstalledonWindows2000SP4inaVMWareimagerunningononeofourLinux machines. OurexploitinstalledaWindows“bindshell”thatwewereabletoremotelyaccess. We havenotyetattemptedtoexploititagainstaHart-suppliedmachine. Issue14:AnimproperlyformattedMBBwillcauseRallyorTallytocrash. A mobile ballot box (MBB) can be carefully crafted to cause the Rally or Tally applications to crashwhenanMBBisreadintothesystem. IfacompromisedRallyfeedsthisinformationtoTally, Tallywilllikewisecrash. Detailed Description The MBB file format makes extensive use of 16-bit CRCs, which serve to detectminorcorruptionwithinthefile. (16-bitCRCsdonotserveanysecurityfunctiontoprotect against tampering. The MBB format separately uses HMAC for that purpose, as describe in Sec- tion6.8.) Thelow-levelroutinethatverifiestheseCRCsusesa32-bitlengthfieldthatcomesfrom theheaderoftheMBB.Whilethetruelengthofthebuffermightbequitesmall,theheaderofthe MBBcanspecifyamuchlargerbuffer.SuchamalformedMBBwillcausethecrc16routinetoread memorybeyondtheendofthebuffer. Given a large-enough length field, crc16 will eventually attempt to read a virtual memory addresswherenophysicalpagehasbeenmapped. Thiswillresultinasegmentationfault,causing Tally to crash. Every time Tally is restarted and asked to process the MBBs, it will consistently crash. Impact Thisattackwillnotdestroyanydata,butitcancauseeitherRallytoTallytocrashwhen readinganMBB.IfaRallymachinehasbeencompromisedthroughothermeans,thenthecommu- nicationspathbetweenRallyandTallywouldallowforRallytodeliveracorruptMBBtoTallyand causeTallytocrash. WhilethecorruptMBBwouldneverbewrittentothedatabaseondisk,thiscouldcauseafair amountofconfusionfortheelectionadministrators. §6.4BufferManagementVulnerabilitiesinBack-EndSystems 47 6. DetailedAnalysis Prerequisites An attacker must be able to introduce a corrupt MBB into the legitimate flow of MBBsfromtheprecinctsbacktoElectionCentral. Thisattackcouldbeperformedbyamalicious pollworker(orgroupofpollworkers, dependingonlocalprocedures). Thisattackcouldalsobe performed if any individual eScan, JBC, or Rally server had been corrupted at some point in the process,asallofthemultimatelyfeedMBBstotheTallyserver. Mitigations AnattackofthisformmightnotcorrupteveryMBBbutonlyasubsetofthem. Elec- tionofficialswouldbeabletodetermineaspecificMBB(orsetofMBBs)whichcausethecrashing condition. This would allow the election officials to tally the non-corrupt subset of MBBs; votes fromtheeffectedprecinctswouldneedtobehand-talliedfrompaperrecords. FutureversionsoftheHartsoftwarecouldbeengineeredtomorecarefullytrackthetruesizeof anygivenbuffer,ratherthantrustingthelengthfieldsinpotentiallyuntrusteddatatobetruthful (seeSection5.3andIssue36formoredetails). Status Thisissuewasdiscoveredbyexaminationofthesourcecodeprovidedtothecodeanalysis team. IthasnotbeendirectlyverifiedagainstRallyandTallyservers. 6.5 Privilege Issues in Back-end Systems AlloftheHartback-endsoftwarerunsonageneral-purposeoperatingsystem(Windows)withits own security mechanisms intended to force users to only use the official applications and block direct access to the underlying data, even by an election administrator. However, in many cases we find that the Hart applications are designed in such a way that allows such direct access. A particularpointofconcernisthesecurityofthedatabasesthatstoremuchofthedataontheHart system. Issue15:Databasepasswordsarestoredinsecurely The user names and passwords used by the back-end election management systems to access databases containing election data are stored in configuration files. The configuration files, as a whole, are not protected using any cryptographic techniques. Within the files, the password is obfuscated,butthemethodofobfuscationiseasilyinvertedtorecoverthepassword. Detailed Description When one of these systems (Boss, SERVO, Ballot Now, Tally) is started, a user name and password is read from a configuration file and used to connect to the database server. The password value contained in the configuration file is the characters of the original passwordXOR’dwiththecharacter‘x’. Anyonewhohasaccesstotheconfigurationfilecaneasily recover the database password and use it to connect directly to the database server containing electiondata,readinganydatapresent,aswellasmakingarbitrarychangestothedatabase. Prerequisites AnyattackerwhohasaccesstothefilesystemofthePCrunningaback-endelection managementsystemcouldexploitthisissue. Impact Since the username and password contained in this configuration file are used by the election management system code to read, modify, and delete election data, possession of this passwordconfigurationfileallowsthesameprivileges. Mitigations One of the most common reasons to store passwords in a file is to avoid requiring userinputuponprogramstartuporhavingtheusertypemultiplepasswords. Ifthisisanecessary productfeature, thenthereareanumberofwaystopartiallymitigatetheriskofpasswordexpo- sure. Oneofthemostcommonisrequiringmorereadandwritepermissionsontheconfiguration §6.5PrivilegeIssuesinBack-endSystems 48 6. DetailedAnalysis filethantheuserloggedintothePCowns. Theelectionmanagementapplicationsarethenconfig- uredtoRunAs11 auserthathastheappropriatereadandwritepermissionsontheconfiguration files. The reason that this can only be considered a partial mitigation is that if the normal user isabletoescalatehisprivileges, thenthepasswordscanberecovered. Alternatively, anadminis- trative user could still recover the database password. See Section 6.6 for more issues related to Windowssecurity. Amoreaggressiveapproachwouldbetohavethedatabaseencryptedunderapasswordthat theusertypedin,avoidingtheentireissueoffileaccess. Thispasswordcanbeintegratedwiththe generalHartloginsystemtoavoidmultiplepasswordmanagementissues. Status We discovered this issue by examining the source code. We then developed tooling to extractthepasswordandwereabletousethepasswordtoconnectdirectlytothedatabase. Issue16:BallotNowcountersarestoredindatabase The Ballot Now system is designed to maintain a private counter of all ballots processed by a given Ballot Now installation as well as a public counter of the number of ballots written to a particularMBB.WhenBallotNowisinstalled,theprivatecounterisexpectedtobezero. Further, only the Ballot Now system is supposed to have the ability to increment the private counter. We foundthattheabilitytoaccessandmodifytheBallotNowdatabasesufficesforchangingthevalues ofthepublicandprivatecounters. DetailedDescription Theprivateandprivatecountersareimplementedasdatabasetableentries in the database used by Ballot Now. Anyone who can connect to the Ballot Now database with theprivilegetoupdatethetablecontainingtheprivatecountercanchangethecountervalue. As described above, the username and password of an account that has such privileges is stored on thefilesystemofthePCrunningBallotNow. Prerequisites AnyattackerwhohasaccesstotheBallotNowdatabasecouldexploitthisissue. Impact ModifyingthepublicorprivatecountersofaBallotNowsystemcouldbringintoquestion thenumberofballotsthatitprocessed,eitherinagivenbatchofMBBsorforitslifetime,potentially requiringmanualexaminationofelectiondatatoresolvediscrepancies. Mitigations This problem can be partially mitigated by requiring more read and write permis- sionsonthecounterfiles(andthedatabasefiles)thantheuserloggedintothePCpossesses. Ballot NowwouldthenbeconfiguredtoRunAs12auserthathastheappropriatereadandwritepermis- sionsonthecounterfiles. Thereasonthatthiscanonlybeconsideredapartialmitigationisthatif thenormaluserisabletoescalatehisprivileges,thenthecounterscanbemodified. Alternatively, an administrative user could still modify the counters. See Section 6.6 for more issues related to Windowssecurity. Future Hart software could be designed to leverage the hardware counters featured in TPM chips[33]thatareincreasinglyinstalledinstandardPCs. Thiswouldallowcounterstobestored inatamper-resistantchipratherthanontheaccessiblefilesystem. Status Wediscoveredthisissuebyexaminingthesourcecode. Issue17:The Tally interface allows a Tally administrator to “adjust vote totals.” Thiscancreateinconsistenciesinthereportedvotetotals. 11http://support.microsoft.com/kb/294676 12http://support.microsoft.com/kb/294676 §6.5PrivilegeIssuesinBack-endSystems 49 6. DetailedAnalysis DetailedDescription Inthecourseofrunninganelection,theremaybeavarietyofreasonsfor anelectionadministratortoneedtoadjustthetotalsbeingreportedbyTally. Onereason,citedin theTallyUserManual,isthattheremaybeanadditionalvotingsysteminuse,entirelyoutsideof Hart’svotingsystem,whosevotesneedtobeincludedinthefinaltally. The “adjust votes” feature allows the election administrator to select a specific precinct, race, and/orparty(forprimaryelections),andtomakechangestothebottom-linetotalsforthatpartic- ularrace. Theimplementationofthisfeaturejustchangestherelevant“total”fieldsintheunderly- ingdatabasewithoutaddinganycorrespondingrecordsthattheadjustmentshadbeenmade. This couldresultinvotetotalsinconsistentwiththenumberofcastvotes. Thisalsodoesnotallowan administratortoeasilyundoormodifysuchchangesaftertheyhavebeenperformed.Ifanelection administratoradjuststhevotetotalsthenrealizestherewasanerror,theoriginaladjustmentscan onlybefoundintheauditlog. The“adjustvotes”dialogboxwillnotshowpreviouschanges,nor isthereaneasywaytobackoutchangesaftertheyhavebeenmade. Inadditiontotheopportunitiesforanadministratortomakelegitimatemistakes,thisfunction- alitycouldalsobeusedtotamperwiththeelectionresults. Prerequisite The user of the “adjust votes” dialog must have “administrator” privileges on the Tally application. Users may either be “administrators” or “operators” and operators are not al- lowedtoadjustvotetotals. Anyuserwhoeitherknowsorcanguesstheadministratorusername andpasswordandhadbriefphysicalaccesstotheTallymachinecouldperformtheattack. Impact The reported vote totals could be inconsistent with the genuine cast ballot totals. The votetotaladjustmentsareincludedintheauditlogs, whichwouldallowtheseadjustmentstobe observed. Mitigations Users of Hart election systems could be discouraged from using the “adjust vote totals”featureofTally. Tally offers a variety of report formats, including some which are intended to be easy to load into tools like Microsoft Excel. California could require that a standard set of reports, including a complete report of the audit log, be produced in machine- and human-readable formats. This wouldsimplifytheprocessofdetectingabusesofthisfeature. Infuturesoftwarereleases,Hartcouldchangethisfeaturetofollowbasicaccountingprinciples, explicitlyreportingtheadjustmentsalongsidethetotalsratherthansimplyoverwritingthetotals. Status ThisissuewasdiscoveredbyexaminationofthesourcecodeandverifiedbytheRedTeam onactualTallysystems. Issue18:Databasesarenotencrypted Election-relateddata,storedinthedatabasesusedbytheseback-endelectionmanagementsystems, isstoredinplaintext.Asaresult,electiondatacanbereadoffwithoutknowingthedatabaseaccess password. Detailed Description The election-related data stored by these systems (Boss, SERVO, Ballot Now,Tally)arestoredinSybasedatabases. Thesedatabasesmakeuseofthefilesystemforpersis- tentstorage. EventhoughloggingintothedatabaseandissuingSQLcommandsrequiresknowl- edge of the database password, the database entries can be recovered by simply opening the databasefiledirectlywithabinaryeditingtool. Withalittleextraeffort,thedatabaseentriesthem- selvescanbealteredbydirectlymodifyingthedatabasefile. Prerequisites AnyattackerwhohasaccesstothefilesystemofthePCrunningaback-endelection managementsystemcouldexploitthisissue. §6.5PrivilegeIssuesinBack-endSystems 50 6. DetailedAnalysis Impact Sensitiveelectiondatacanbeobtainedorpotentiallymodified. Mitigations Onenaturalmitigationistoemployadatabaseencryptionscheme. Alternatively,a partialmitigationwouldbetorestrictreadandwriteaccesstothedatabasefile,inafashionsimilar tothatdescribedinIssue15. Status We discovered this issue by examining the source code. The absence of encryption was verifiedbyexaminingdatabasefilesgeneratedduringasimulatedelection. Issue19:Newuserscanbeaddedviathedatabase An operator of one of the back-end election management systems, who has restricted access, can create a new account for herself with higher privileges. In general, being able to access the databasesforoneofthesesystemspermitsthecreationofnewuseraccounts. DetailedDescription Thedistinctionneedstobedrawnbetweenthepasswordusedforlogging intoasystemdatabaseversusthepasswordsusedforloggingintoaHartapplication.Thedatabase password, in addition to being stored within the database, is also stored by the application (see Issue15). Theapplicationsalsomaintainuserpasswords,forusersoftheapplications. Thesepass- wordsarealsostoredinsidethedatabaseand,unlikethedatabaseaccesspasswords,arenotstored intheclearbutareinsteadhashedwitharandomsalt(afairlystandardtechnique, usedbyUnix andmanyothersystems;anattackerwhocanreadthesalted/hashedpasswordswillnotbeeasily abletolearnthepasswords). While an attacker cannot directly read the plaintext passwords, the attacker can either reuse existingpasswordsorcomputenewonesifhehastheabilitytowritetothefile. Likewise, anat- tackercanprogramacomputertomethodicallytrycommonpasswords(e.g.,wordsindictionaries) againstthehashedpasswordsinthedatabase. Ifauserchoseorwasgivenaweakpassword,the attackercoulddiscoverthis. Prerequisites Anyattackerwhohasread-onlyaccesstothefilesystemofthePCrunningaback- endelectionmanagementsystemcouldextractthepasswordfileandreverse-engineerpoorlycho- senpasswords. Anattackerwhohasread-writeaccesstothefilesystem(particularlythedatabase) couldinstallhisownusersandgivethemadministrativeprivileges. Impact Privilegeescalationforoperatorsofback-endelectionmanagementsystems. Mitigations As with other database-related issues, the root issue is that normal users will have sufficientprivilegestoaccessthedatabasewithoutgoingthroughtheHartapplications. Thesame mitigations,asdescribedabove,applyhere. Status Wediscoveredthisissuebyexaminingthesourcecode. WemanuallystarteduptheTally databaseserver,loggedin,andissuedSQLcommandstoaddnewTallyuserswiththesamepass- wordasexistingusers. Wewerethenabletosuccessfullyloginusingtheseaccounts. 6.6 Windows-related Vulnerabilities ManyofthecomponentsoftheHartelectionsystemrunonstandardWindows-basedPCs,includ- ingBOSS,Servo,Rally,Tally,andBallotNow. TheHartdocumentationprovidesonlyminimalguidanceinhowtheirWindowsinstallations shouldbeconfigured. ThereareawidevarietyofsecurityissuesthatoccurwithanyuseofWin- dowsmachines. ThissectionfocusesonissuesthatmayapplywithWindowsasusedinatypical Hartcustomerinstallation. §6.6Windows-relatedVulnerabilities 51 6. DetailedAnalysis Issue20:Back-endWindowssystemsmaybeinsecure Because all of the Hart back-end components run on Windows-based PCs, an attacker who is able to subvert Windows may be able to subvert the Hart components. The user need not start outwithadministratorlevelaccessbecausestandardconfigurationsofWindows-basedcomputers oftenaresusceptibletoprivilegeescalationattacks, especiallyiftheyhavenotbeenlockeddown orkeptuptodate. Therefore,thesecurityoftheWindowsenvironmentiscritical. Detailed Description Hart provides only minimal guidance for securing these machines. They do not provide detailed instructions on how to lock them down. Moreover, they encourage or requirepracticesthatarelikelytocompromisesecurity. Section3.5oftheHartuseprocedures[21] state: OperatingsystemupgradestothecomputersonwhichtheHartVotingSystemapplica- tionsareonlyperformedbyHartInterCivicpersonnel,andonlythen,aftercertification bytheSecretaryofState. Weareunsureifthisisacertificationrequirement,butinanycase,unpatchedversionsofWindows aregenerallyinsecureandbecomeincreasinglysoasnewvulnerabilitiesarediscovered. It is likely that an attacker with even short-term physical access to one of the back-office ma- chinescouldsubvertitandescalatetoadministratorprivileges. Thiswouldnotbealongprocess sincehecouldloadmalwareonaUSBstick,setitoff,andthenleave. Prerequisites AnattackerneedsphysicalaccesstooneoftheWindows-basedcomputersusedin ElectionCentralforatmostaminute. Theattackercoulduseausernameandpasswordtologinto theWindowsmachine;orobtainaccesstoamachinethatisalreadyloggedin,perhapsleftalone; or,withmoretime,accessthechassisandaccessthemachine’shardwaredirectly. Impact Election insiders with physical access to any of the Windows-based back-end machines couldmostlikelysubvertthem. Mitigation First and foremost, all Windows systems should be regularly updated with security patchesfromMicrosoft.13 Thiswillreduceexposurestowidelyunderstoodvulnerabilities. Another important mitigation is to “lock down” Windows so that the user accounts used to operate the Hart systems have limited privileges rather than the full privileges of the Windows administrator. A suitably-configured user account would be unable to run any programs beyond the official ones necessary to operate the Hart software. Microsoft offers some advice for how to best configure Windows XP with least-privilege user accounts14 and has added a variety of fea- turesalongtheselinestoWindowsVista. ForWindows2000,whichseemstobecommonforHart servers,Microsofthasextensiveresourcesonlinetodescribehowtolockdownsuchamachine15. There are also good guides elsewhere online16. This will not necessarily stop privilege escalation butmaydelayit. Finally,physicalaccesstothesemachinesshouldbehighlylimited. Itshouldnotbeassumed, merelybecauseauserdoesnothavealogintoamachine,thatitissecureinhispresence. Status This issue was discovered by examination of the Hart manuals. Red team analysis of the systems provided by Hart determined that they were running Windows 2000 SP4, with the “LicensedUser”grantedfulladministrativeprivileges. 13InstallingupdatestoWindowsandtoanti-virussystemsmayhaveimplicationsforthecertificationprocess, which typicallyconsidersaspecificversionofeveryelementofthesoftwarestack,includingCOTScomponents. 14http://technet.microsoft.com/en-us/library/bb456992.aspx 15http://www.microsoft.com/technet/security/prodtech/windows2000/secwin2k/default.mspx 16See,e.g.,http://www.cites.uiuc.edu/security/byos/win2000.html §6.6Windows-relatedVulnerabilities 52 6. DetailedAnalysis Issue21:ManyHartsystemsareconnectedtointernalnetworksormodems,open- ingthemtoattacksagainstWindows’vulnerabilities. Detailed Information Windows systems, particularly those which do not have Microsoft’s se- curity patches regularly installed, are well-known for having network-exploitable security holes. WhilenoneoftheHartWindows-basedsystemsshouldeverbedirectlyconnectedtotheInternet, thesevulnerabilitiesmaystillbeexploitable. Anattackerwishingtoexploitoneofthesevulnerabilitiesneedstoconnecthisowncomputer to the same network as one of the Windows machines running Hart software. The attack would onlytakesecondstoperform,perhapsinstallinga“backdoor”accountontheWindowsmachines, allowing them to be accessed later in an arbitrary fashion. Such attacks would likely override any locking down of user account privileges (as described above), since many of the vulnerable Windowssystemservicesrunwithfulladministrativeprivileges. An attack such as this could be mounted against Rally (when used at Election Central), Tally, BOSS, Servo, and eScan machines. In addition to launching an attack from an unofficial laptop computer, the attacker could possibly have compromised an eScan machine while it was in the field; eScanmachinesareconnectedtothelocalnetworkatElectionCentraltoextracttheirvotes, providing an opportunity for the eScan machine to mount attacks against other machines on the samenetwork. WhenRallyandTallycommunicateusingmodems(seealso, Section6.9), anattackercanalso dialthephonenumberusedbytheRallymachine. IftheRallymachineisconfiguredinthefashion specifiedintheRallyUser’sManual[18],thennousernameorpasswordwillberequiredbeforethe Rallymachinegivestheattackera“local”networkaddress(i.e.,192.168.x.x)allowingtheattacker to communicate with any service on the Rally machine, not just the Rally application itself. This meansthatanynetwork-exploitablevulnerabilityinWindowsisnowamodem-exploitablevulner- abilityinaRallymachine. WhenTallyconnectstoRally,acompromisedRallycanthenattackthe Tallysystem,whichinturncanattackotherWindows-basedsystemsatElectionCentral. Hartdoesrecommendthatanti-virussoftwaresoftwarebeinstalledonitsWindows-basedsys- tems(seetheHartProductDescription[17],pages27-30),howeversuchsoftwaretypicallyrequires an active Internet connection to download the latest updates, as does Microsoft’s own Windows Update system. As Hart’s Windows-based systems should never be connected to the Internet, this presents some practical complications to keeping both the anti-virus software and the neces- sary Windows security patches up to date. Hart’s System 6.2 Use Procedures [21] (Sections 10.2.3 and10.2.4)statesthat“anti-virussoftwareisonlyinstalledandconfiguredbyHartInterCivicper- sonnel” and that “installation of software and firmware upgrades is performed only by Hart In- terCivicpersonneliforwhennecessary.” ThisrequiresHart’scustomerstorelyonthevendorfor a variety of services. As a major election approaches, the vendor may be unable to provide this servicetoallitscustomersinatimelymanner. Furthermore,mostanti-virussoftwarefocusesonsearchingforwell-knownviruses(“signature matching”);securitycompromisingsoftware,engineeredspecificallytoattackHartsystems,would mostlikelynotmatchthesignatureofanyknownvirus. Hartsuggeststhatsuchupdatesshould beperformedthroughremovablemedia[21](Section10.2.3). Prerequisites Anattackermusteitherhaveaccesswithalaptopcomputertothelocalnetworkat ElectionCentralforatmostaminute,ortheattackermusthavepreviouslycompromisedanyone computerusedinthelocalnetwork, includingtheeScanmachine. Onceonemachineisinfected, the infection can spread to every other machine without the direct involvement of the attacker. Infections from traditional computer worms and viruses might also spread, inadvertently, in the samefashion,forexample,ifanelectionadministrator’spersonal,Internet-using,laptopwasacci- dentallyconnectedtotheinternalnetworkatElectionCentral. Impact OnceanyoneWindows-basedsysteminaHartelection,includinganeScansystem,has been compromised in any fashion, it can then use well-known Windows vulnerabilities to attack §6.6Windows-relatedVulnerabilities 53 6. DetailedAnalysis alloftheothernetworkedHartsystems. Suchattackswouldhavefullsystemprivileges,allowing them to modify or delete votes and other records. Likewise, the attack can spread either directly fromtheinitialcompromisedmachine,oritmightspreadviaviralpropagation. Mitigations Windows XP and Vista have a built-in firewall tool.17 This should be configured to block all ports except those required for the Hart system to function. For example, Rally and Tallymachinescommunicateonport4500. Nootherportsshouldbenecessary,althoughthiswill require careful testing to determine whether there are unexpected dependencies. Regardless, the firewall can be configured to allow connections on only this handful of ports while dropping all othertraffic. Hart can and should develop a step-by-step checklist for installing its systems on Windows andforconfiguringWindowstominimizeexposurestonetwork-basedvulnerabilities. Thiscould be applied to the current, certified versions of Hart software. Likewise, the California Secretary of State’s office could create such a Windows checklist and require Hart customers in the state to follow it. (A complete guide to Windows configuration is beyond the scope of this report.) Thechecklistshouldbemandatory,andmustnamethespecificversion(s)ofWindowstowhichit applies. AmoreaggressivemitigationwouldbetoplaceeachHartsystemonaseparatenetwork,with airgaps between them. This would significantly reduce the risk that compromise of one system would affect others. This would be useful against attacks even if the machines were in the same room,sinceitwouldmakeviralspreadsignificantlymoredifficult. ThemodemvulnerabilitieswithRallysystemscanbemitigatedbybanningtheuseofmodems. Ifregionalvoteprocessingcentersarestilldesirable,Rallycanstillbeusedinadisconnectedfash- ion,withatraditionalcouriertransportingtheRallymachinesbacktoElectionCentralonceallof theprecincts’voteshavebeencollected. eScanrunsWindowsCE,anembeddedversionoftheWindowsoperatingsystem. Thismakes itdifficultorimpossibleforanend-usertochangetheconfigurationofeScantoequivalentlycon- figurea firewallto disableconnectionsto unnecessaryservices. When aneScan isin thefield, its Ethernet interface already provides extensive capabilities to an attacker (see Section 6.1), and the mitigationstakentoprotectagainstthoseattackswouldalsoapplyagainsttheseones. Itisunclear thatthereisanyreasonforthisporttobeliveinthefieldatall. In future versions of their software, Hart could design the installers for its various software packagestolockdowntheWindowscomputer,configurethefirewall,anddeleteunnecessaryand unused elements of the Windows system, making the above checklist an automatic aspect of the softwareinstallation. ForRally’smodemissue,Hartcouldmodifythewaythatmodemsareused suchthatdialingintotheRallysystemyieldsadirectconnectiontotheRallysoftwareratherthan ageneral-purposenetworkconnectiontotheRallymachine(i.e.,Rally’sdesignshouldfollowthe principleofleastprivilegetoreducethepowerofanattackerwhomightconnectviathemodem). Status This issue was discovered by examination of the source code and other documents pro- vided to the source code analysis team. Red Team analysis has determined that a number of un- necessarynetworkservicesareenabledontheWindows2000machinesprovidedbyHart.TheRed Team did not discover any vulnerabilities in these services, implying that the machines given by Harthadallofthelatestsecuritypatchesinstalled. ThismightormightnotbethecasewithHart’s customersusingthesesystems. Microsoftcurrentlyonlyprovides“extendedsupport”toWindows2000,meaningtheyarepro- vidingsecurityfixesbutarenotaddingnewfunctionality. Microsofthasstatedthatthisextended support will end in 2010. Hart customers using Windows 2000 must migrate to newer versions MicrosoftbeforeMicrosoftceasesmaintenanceofWindows2000securitypatches. 17Windows 2000 also has firewall functionality. See, e.g., http://homepages.wmich.edu/∼mchugha/ w2kfirewall.htm §6.6Windows-relatedVulnerabilities 54 6. DetailedAnalysis 6.7 Cryptographic Key Management HartmakesextensiveuseofcryptographytoprotectdataontheirMBBs. Inparticular,ballotdata and CVR data are both cryptographically integrity protected. Although the Hart documentation andsourceaswellastheSymantecreport[4]refertothisasa“signature”itisactuallyasymmetric MessageAuthenticationCode(MAC),specificallyHMAC-SHA1[5]. Throughoutthisdocumentwe willrefertothisasaMACratherthanasignature. BecauseMACsareasymmetrictechnique,thegeneratorandtheverifierofaMACmustshare aMACkey. Thisimpliesthatifthreeparties,Alice,Bob,andCarol,allwishtousethesameMAC key,thenthereisnocryptographicwayforAlicetodistinguishaMACgeneratedbyBobfromone generatedbyCarol. BobcanimpersonateCaroltoAlice,andindeedanymemberofthegroupcan impersonateanyother. InHart’ssystem,asingleMACkeyisusedforeverymachine/deviceina singleadministrativedomain,andsocompromiseofanyentityallowstheattackertoimpersonate anyotherentity. This key is distributed on eSlate Cryptographic Modules (eCMs) and is generated by the eCM Manager application. The eCMs are USB-based Spyrus cryptographic tokens about the size of a typical USB flash drive. The eCM manager uses the Windows cryptographic random number generatortocreateasecret128-bitkeyandaGloballyUniqueIdentifier(GUID)identifyingthatkey. ThekeyisthenstoredoneachindividualeCM.TheseeCMsarethenusedtoprogramtheJBCsand eScansusingSERVO. Itshouldbenotedthatstandardpracticefortheuseofcryptographicmodulesisthatthekeys shouldbegeneratedonthemoduleandneverleaveit. Hartviolatesthispracticeintworespects, firstbygeneratingthekeyoutsidethemoduleandsecondbyexportingthekeyfromthemodule. Thisleadstoanumberofissues,asdetailedbelow. Issue22:ThesamesymmetriceCMkeyisusedcounty-wide In the Hart system, all message integrity is performed using a single county-wide MAC key. Thiskeyismadeavailabletotheback-officeapplicationssuchasTallyandSERVObypluggingan eCMcontainingthekeyintothemachinesrunningthem. ItismadeavailabletoJBCsandeScans byprogrammingthemusingSERVO.ThiskeydoesnotappeartobeusedbyeSlates. Thispractice impliesthatanattackerwhocompromisesanysinglekeyeddevice(mostlikelyaJBCoraneScan) orhasaccesstoaneCManditsPINwillbeabletoforgeMBBsthatwillbeacceptedbyanyother deviceinthesystem. DetailedDescription Therearethreemajorwaystorecoverthesecretkey • ExtractitfromtheeCMdirectly(whichprobablyrequirestheeCMPIN). • ExtractitfromtheeCMmanager(seeIssue23). • ExtractitfromaneScanorJBC(seeIssue24). Once an attacker has the key, he can mount a number of attacks. The two most interesting are: forging incorrect ballot information on MBBs that are consumed by eScans and JBC/eSlates, and forgingMBBscontainingfakevotes(ormodifyingthevotesonrealMBBs)andsendingthemback tothecentralofficefortallying. NotethatalthoughHart’sproceduresindicatethatoneshouldnotreusekeysbetweenelections, wedidnotfindanytechnicalcontrolspreventingit. Prerequisites Avoterisunlikelytobeabletoaccessthesecretkey. Apollworkerwouldbeable to extract it (see Issue 24) if he had temporary unattended access to an eScan or JBC. An election officialresponsibleforrunningSERVOorTallycouldextractthekeydirectlyfromtheeCM.Though aPINisrequiredtoaccesstheeCM,thisPINalsoallowsextractionoftheeCMsecretkey,because extractionisnecessarytoexportittotheeScan/JBC. §6.7CryptographicKeyManagement 55 6. DetailedAnalysis TheattackerwouldalsoneedphysicalaccesstothetargetMBB.Itappearsthatthepollworkers havesuchaccessatleastinsomeenvironmentsandthatelectionofficialsgenerallydo. Impact An attacker who forged MBBs for consumption by the eScan/JBC would be able to im- poseaballotofhischoice. Thismightallowhimtoaffectelectionresults,forinstancebyremoving candidates,flippingtheorderofcandidates,orbreakingthebindingbetweencandidatesandop- scanmarkingsorvoterecords. Itisunclearwhetherthiswouldbedetectedbythosefamiliarwith thecorrectorderoftheelection. An attacker who forged MBBs for consumption by Tally would be able to modify votes for thatMBB.ThosevoteswouldbeacceptedbyTally. Thisattackwouldbedetectedifadirectaudit (via SERVO) were performed or a manual paper recount—such as is done with the one percent recount—wereperformed. Mitigations Anumberofmitigationstothisthreatarepossible. Insomecasesforgedballotdata could be detected by visually comparing the election interface to the expected UI. Forged MBBs senttoTallycouldbedetectedbydoingacompleterecountbasedontheonboardmemoryofthe JBCs, eSlates, and eScans. We do not know if this is standard practice. More extensive use of paper-basedrecountswouldalsoaidindetectionofthistypeofattack. Restrictingmasterkeystoasingleelection, asHart’sproceduresrequire(thoughthesoftware does not appear to enforce) would reduce the risk level somewhat. More severe restrictions on access to the secret keys, such as those proposed as mitigations to Issues 23 and 24, would make thisattackmoredifficulttomount. Movingfrom aMAC-basedsystemto adigitalsignature-based system withseparatekeys for everydevicewouldsignificantlymitigatethisvulnerabilitybyseparatingtheabilitytoverifyfrom the ability to sign. The effect would be that compromise of an eScan or JBC would no longer allowforgeryofMBBsthatwouldbeacceptedbyothereScans/JBCs. Similarly,itwouldnotallow forgery of MBBs that were accepted as from other eScans/JBCs, provided that Issue 27 were also addressed. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedatool thatwillchecksignaturesonMBBsusinganextractedkey. Wehavemadesomeinitialattemptsto forgeMBBsbutdonotyethaveaworkingtool; duetotimeconstraintshavenotyetbeenableto completethis. Issue23:ECMkeysarestoredinsecurelyontheeCMmanager TheeCMmanagercreatesakeyinsoftwareusingtheWindowsCryptGenRandomcall,which isastandardWindowscallandappearstogeneratehighqualityrandomness. Thegeneratedkey is128bitslong,whichisadequate. TheeCMofferstheusertheoptiontosavethemoduledatato afile. Whenthatdataissaveditissaved“obfuscated,”whichmeansthateachbyteofthedatais XOR’edwiththeletter‘x’. Anattackerwhocontrolsthecomputeronwhichthishasbeendonecan triviallyextractthesecretkey. Detailed Description An attacker who has access to the computer running eCM manager can simplyfindthe.eCMfileandXORthecontentswith’x’torecoverthekey. Prerequisites Theattackersimplyneedsaccesstothecomputer. Impact OncetheattackerhasaccesstotheeCMkeyhecanmountanyoftheattacksdescribedin Issue22. §6.7CryptographicKeyManagement 56 6. DetailedAnalysis Mitigations OnemitigationwouldsimplybenottostoretheMACkeytoafileatall. Thiswould requireinitializingalltheeCMsatonceorhavingeCMswithdifferentkeys,whichwouldbenec- essaryinanycaseifpublickeycryptographywerebeingused. Anothermitigationwouldbetoreplacetheobfuscationwithencryptionunderauser-supplied PIN or passphrase [24]. This would still potentially be susceptible to dictionary attacks if the at- tacker also had access to an MBB protected with that key or if the encryption were done poorly. However,thisisasignificantlymoredifficultattack,especiallyifagoodpassphraseischosen. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedatool toextractthekeyfroman.eCMfileandhaveusedittoverifyanMBB. Issue24:eCMkeysareextractedandstoredinsecurely Although the keys are transported on the eCM, they are then copied (over the management channel) to the JBC and the eScan, where they are stored on the onboard memory. Any attacker whocontrolledeitherofthesedeviceswouldbeabletoextractthekeys. Detailed Description SERVO is used to program MAC keys onto the eScans and JBCs via the usualmanagementinterface(seeSections6.1and6.2).Thisinvolvespassingthecryptographickey intheclearovertheEthernetorparallelcableusingtheNET_CMD_SET_SIGNING_KEYcommand, whichstoresitunprotectedtheflashonthedevice. Itcanthenbeextractedinanumberofways, including: • ReadingthekeydirectlyoutofmemorywithMEM_READ. • Loadingnewfirmwareontothedevicewhichallowskeyexport. • Openingthecaseandreadingtheflashdirectly. Wehavetestedthefirstoftheseapproaches. Prerequisites Readingthekeydirectlyoutofmemorywouldrequireonlydirectphysicalaccess tothedevice. Loadingnewfirmwarewouldrequiresimilaraccess,thoughiffirmwareweremade more difficult to load (see Section 6.1), then this attack would be much harder. Opening the case requiresextensivephysicalaccesstothemachine. Impact All of these methods would allow raw access to the MAC key and enable the attacks described in Issue 22. Note that even if asymmetric keys were used, it would still be possible to forgeMBBsfromthecompromiseddevice. Mitigations The first avenue of attack (reading the key directly out of memory) could be miti- gatedbyremovingMEM_READaccesstothatportionofmemory. Loadingnewfirmwarecouldbe mademoredifficult,asdescribedinSection6.1. Thecaseopeningattackissubstantiallyharderto thwart,buttheuseofatamper-resistantcryptographicmodulesuchastheeCMontheeScansand JBCswouldmakethisattacksignificantlymoredifficult. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavesuccessfullyused acomputerunderourcontroltocommunicatewiththeeScanandextractthecryptographickeys. Wehavenotattemptedtheothertwoavenuesofattack. §6.7CryptographicKeyManagement 57 6. DetailedAnalysis 6.8 MBB Vote Storage Both the eSlate and the eScan store their vote records in Mobile Ballot Boxes (MBBs), which are generic PCMCIA memory cards. Each eScan has an MBB and each JBC has a single MBB which serves all the eSlates under its control. Integrity for MBB data is intended to be provided by an HMAC-based [5] message authentication code over some of the contents. As discussed in Sec- tion6.7,theMACiskeyedwithakeycommontoalltheprecinctsinacounty. Issue25:Voteordercanbedetermined In order to preserve voter privacy, it is necessary that an attacker who has access to the MBB not be able to determine how individual voters cast their votes. Although the votes recorded on theMBBdonotcontaintheidentityofthevoter,itispossibletodetermineboththeorderinwhich voteswerecast, andinthecaseoftheeSlate, theorderinwhichvoterswereissuedaccesscodes. Because the order in which voters vote is fairly easy to determine, being able to determine the order in which votes are cast provides a large amount of information about how any individual votervotes,evenwithouttheMBBexplicitlycontainingvoteridentities. DetailedDescription EachvoteisstoredonanMBBintwoways: • The vote itself is stored in a cast vote record (CVR) which is stored in a randomly selected locationinalargememoryblock. • Anentryrepresentingthevoteisappendedtotheauditlog. Thismethodhastwoproblems. ThefirstisthattherandomizationoftheCVRlocationispoorand leaks a significant amount of sequence information. The second is that the in-sequence audit log leakstheorderoftheCVRs. CVR Randomization Before any votes are cast, the eScan or JBC allocates a large random block on the MBB. It then selects a random point approximately in the middle of that block and initialized two pointers, start and end with the start pointing at the selected point and end = start+1. Whenever a CVR needs to be stored, the device selects a random 1-bit value and uses thattoselectwhethertostoreatthebeginningorendofthelog. Ifthebeginning,theCVRisstored justbeforestart. Iftheend,itisstoredatend. Theappropriatepointeristhenmovedawayfrom thecenterofthebufferandtheprocessisrepeatedforanynewvote. Giventhisalgorithm,iftheinitialvalueofstart(referredtohereasstart )isknown,itiseasyto 0 deriveapartialvoteorderingfortwoCVRsatpositionsp andp providedthateitherp <start 1 2 1 0 and p < start or p > start and p > start . In either case, the CVR closer to start must 2 0 1 0 2 0 0 havebeencastfirst. Evenforvotesondifferentsidesofstart itispossibletodeterminearough 0 orderingiftheirdistancesfromstart aresufficientlylarge. 0 The above algorithm requires determining start . This can be approximately determined by 0 taking the center of the used portion of the buffer. However, a more precise estimate may be possible by observing that that algorithm for selecting start selects a random position from a 0 100byteregioncenteredonthemiddleofthebuffer. Theendofthefirstprependedvotemustfall withinthisregion,asmostthebeginningofthefirstappendedvote.BecausetheCVRheaderalone is17octetslong,thisnarrowsstart downtowithinatmost6values,andinfactlessbecausethe 0 CVRdatamustalsobestored. InonesampleelectionrunbytheRedTeam,thesmallestCVR(with nowrite-ins)was32bytes. Derandomization via Audit Log Although the audit log does not contain CVRs, each audit entrycontainsaCRC-16oftheCVRdata. ThisallowstheattackertodetermineasmallsetofCVRs (mostlikelyallcontainingthesamevotes)whichcorrespondtoagivenauditlogentry.Becausethe auditlogentriesareinsequence,thisallowsanattackertocompletelyrecoverthesequenceofcast §6.8MBBVoteStorage 58 6. DetailedAnalysis votes. Inaddition,whenvotersvotebyeSlate,thevoteraccesscodeappearsintheauditlogand itisthereforepossibletodeterminehowvotersvotedbytheorderinwhichtheywereauthorized, particularlyifvoterskeeptheiraccesscodeprintouts,whichareproducedbytheJBC. TheSERVODeviceAuditLogreportalsoappearstodisplaytheauditlogdata,containingthe CRCandthevotercode,whichmayallowmappingofvoterstovotedata. Whetherthisispossible dependsonwhethertheCRCscanbecompletelypredictedfromthevoter’schoices,withoutaccess totheCVRlogdata. Wehavenotdeterminedwhetherthatisthecase. Prerequisites Inordertoexploitthisissue, anattackerwouldneedreadaccesstoanMBBorto thecontentsoftheMBB.BecauseMBBsarenotencrypted,noaccesstokeyingmaterialisrequired. Election officials are likely to have access to MBBs or MBB contents. Whether poll workers have accesstoMBBcontentsdependsonwhethertheMBBsaresealedintotheeScan/JBCatthecentral warehouse and then shipped back to the warehouse inside the JBC or whether they are removed priortoshipping. Ifthelatter,thenpollworkerswouldalsobeabletomountthisattack. Poll workers could also access the CVR and audit logs internal to the eSlate, JBC, and eScan usingthemanagementinterfaces;seeSection6.1. If the SERVOaudit logs can be mappedback to vote results, thenthis attack may be practical withonlypublicinformation. Impact The result of this attack is that anyone who has access to the contents of an MBB can determine which votes were cast in which order. If the attacker also has access to the order in whichvotersenteredthepollingplace,theorderinwhichtheycasttheirvotes,oraccesstovoters’ accesscodeprintouts,thisleaksasignificantamountofinformationabouthowindividualvoters voted. Mitigations Pollworkerscanbeblockedfromexploitingthisissuebyrestrictingtheiraccessto MBBs and to the network/management interfaces on polling place devices. In particular, if the MBB is sealed in the JBC/eSlate whenever the unit is in the poll worker’s possession, then this attackbecomesmoredifficulttomountwithoutbeingdetected. FutureversionsofHartsoftware could routinely encrypting the MBB contents, which would also block poll worker attacks. The contentscouldbeencryptedunderapublickeyownedbyElectionCentral,thuspreventingleakage ofthekeybydevicecompromise. BecauseMBBCVRinformationisroutinelystoredbytheback-endelectionsystems,itismore difficulttorestrictaccessbyelectionofficials. MerelyimprovingtheCVRrandomizationalgorithmdoesnotsignificantlymitigatethisissue because the CVRs can still be derandomized by examining the audit log. Future versions of the Hartsoftwarecouldremovetheauditlogvectorbyeitherfurtherrestrictingaccesstotheauditlog ormakingitsignificantlymoredifficulttotieauditlogentriestoCVRs,mostlikelybyremovingthe CRC-16hashoftheCVRfromtheauditlog. WehavenotdeterminedwhethertheCRC-16isused byanyofHart’sauditingmechanisms,butasit’snotcryptographicallystrong,itisonlyusefulas acheckfordatacorruption,notmaliciouschanges. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavedevelopedtoolsto reconstructthevoteorderandusedthemwithanMBBimageprovidedbytheredteamtoextract thevoteorderinagivenelection.Wealsoverifiedthatthefirstvote(representinglocationofstart ) 0 wasintheexpectedlocation. Issue26:MBBisnotprotectedduringvoting Inordertoprotectagainsttampering,Hart’sMBBsarecryptographicallyprotectedusingHMAC[5].18 Intheory,thisprotectstherelevantstructuresontheMBBfromtamperingbyanyonewhodoesnot 18Thematerialprovidedtousreferstothisasa“signature”butit’sactuallyasymmetricmessageauthenticationcode (MAC). §6.8MBBVoteStorage 59 6. DetailedAnalysis have the relevant MAC key. However, the HMAC is not present on the vote data on MBB dur- ingtheelection,butiscomputedandrecordedeitherwhentheelectionislockedtoaccommodate a pause in early voting or when the election is closed. Therefore, it may be possible to remove, modify,andreinserttheMBBwithoutbeingdetected. DetailedDescription TheeScanandJBCbothmaintainvotedataintwolocations: • Ininternalstaticstorage. • OntheMBB. Asindicatedabove,eachlocationhastwodatastructures,theCVRdataandtheauditlog. ThisdataismaintainedunprotecteduptothepointwhereMBBisclosedorlocked.Theinternal memorydoesnotappeartobeaccessiblewithoutopeningthecaseoftheJBCoreScan. Assessing thedifficultyofthisisoutsidethescopeofthiswork. TheMBB,however,isreadilyaccessible,but tampersealsareintendedtodetectremoval. IfanMBBisremoved,modified,andreinserted,theresultisthattheinternalandexternaldata structureswillnotmatch.However,theJBCandeScandonotappeartoverifythattheinternaland externalauditandCVRlogsmatchandthereforevotingproceedsasnormal. JBCs and eScans both run a watchdog task that triggers an audit log message and halts the device if the MBB is removed. The attacker can power down the device, remove, modify, and reinserttheMBB,thenpowerthedevicebackup. TherebootwillcausetheJBC,atleast,tocheck that the inserted MBB is the same as the one it originally read the election information from, but thischeckdoesnotappeartoextendtocomparingtheinternalCVRandauditlogstothosestored ontheMBB. Whenitistimeto“sign”theMBB,thefollowingstepsareperformed: 1. GenerateanunkeyedhashfortheinternalCVRdataandlogittoboththeinternalandexter- nalauditlogs. 2. Generated a keyed MAC (HMAC-SHA1) of the external CVR data and log it to both audit logs. 3. Generateanunkeyedhashoftheinternalauditlogandlogittobothauditlogs. 4. GenerateakeyedMAC(HMAC-SHA1)oftheexternalauditlogandlogittobothauditlogs. WhentheMBBisverifiedbyTally,itverifiestheMACsbutdoesnothaveaccesstotheinternal auditorCVRdataanddoesnotattempttocomparethemtothedataontheMBB. Prerequisites Themajorobstaclestothisattackareobtainingaccesstothedevicelongenoughto remove and reinsert the MBB and the tamper sealing on the MBB insertion point. A poll worker would have appropriate access to the devices though a voter would not. See Section 3.5 for a discussiononthelimitationsoftampersealing. Impact AnattackerwhowasabletoobtainaccesstotheMBBwouldbeabletochangeexisting votesonitandthenreinsertitintotheJBCoreScanandhavethatunitproceedasnormal,includ- ing inserting the MAC. This MBB would have votes partly of the attacker’s choice and would be acceptedbythecentraltabulationsystem. Mitigations Severalpossibilitiesformitigatingthisattackexist. Electionadministratorscouldverifytheinternalauditlogs(collectedviaSERVO)againsteach MBB to verify that they match. We have no information as to whether this is currently routinely done,butitcouldbedonewiththecurrentHartsoftware. InfutureversionsofHartsoftware,theJBC/eScancouldcheckoneachMBBinsertionthatthe contentsoftheMBBmatchtheinternalmemoryandfailiftheydidnot.Oneminordifficultyhereis §6.8MBBVoteStorage 60 6. DetailedAnalysis thattherandomizationoftheCVRsontheMBBandtheinternalmemoryisnotthesame;19however, thiscouldbefixedbylexicallysortingtheCVRspriortoverification. Status ThisissuewasdiscoveredbytheRedTeamagainstalivesystemandverifiedbyreference tothesourcecode. Issue27:HandlingofprecinctIDsinCVRs EachCVRcontainsaprecinctIDfieldindicatingtheprecinctforwhichtheCVRwasvoted.This allowsasingleMBBtocontainconsolidatedrecordsforanumberofdifferentprecincts. Itmaybe possibletogenerateanMBBwhichcontainsvotesforunauthorizedprecincts. Inaddition,itmay be possible for an attacker who has access to the election database on Tally to silently suppress votes. DetailedDescription EachCVRinanMBBisanindependentrecord,withadescriptiveheader containingmeta-informationaboutthevotesintheCVR.Thismeta-informationincludes: • A16-bitballottypeidentifier • A16-bitprecincttypeidentifier • A16-bitpartyidentifier In theory, any given piece of equipment is only relevant to a small number (most commonly one) of precincts, and under ordinary circumstances when Tally converts votes into the internal storageitreferstotheelectiondatabasetodeterminewhatprecinctsandpartiesareauthorizedfor agivenMBB.Itthencyclesthrougheachvalidprecinct/partycombinationinordertocountvotes. ThispreventsanMBBfromprecinctX frominjectingvotesinprecinctY. However,ithastheside effectthatitispossibleforvotestogetignoredifthedatabaseonTallyisinconsistentwiththeMBB. The one exception to this rule appears to be that SERVO is allowed to create recount MBBs, which contain records from multiple polling places. If Tally thinks it is processing such an MBB, itexecutestallyCvrLogForServo()whichappearstoiteratethroughallpossibleprecinctsand parties. TallymakesthisdecisionbasedontheMBBheader,whichisundercontroloftheprecinct polling devices. Thus, it may be possible for an attacker to forge a SERVO MBB which contains arbitraryprecinctIDs. Prerequisites MountingasuppressionattackwouldrequireaccesstotheTallydatabaseinorder tomodifytheprecinctsassignedtoagivenpollingplace. Thisiselectionworkerstyleaccess. MountingthisattackrequirestheabilitytoforgeMBBs. Thiscouldeitherbedonebyextracting themasterMACkey(seeSection6.7)orbyusingtheattackdescribedinIssue26. Anattackerwho hadarrangedtoreplacethefirmwareonaneScanorJBCcouldalsomountthisattack. In any case, the attacker would need access to the MBB, such as may be available to a poll worker. Impact Theimpactofasuppressionattackwouldbetoallowsomeonewithtemporaryaccessto theelectiondatabasetosuppressvotesfromagivenprecinct/pollingplacepair. The impact of an injection attack would be to allow an attacker who had partial control of equipmentinoneprecincttoaffecttheoutcomeofvotinginanotherprecinctbyinjectinghisvotes intothatprecinct’sdata. 19Thisisalsosuboptimalbecauseitleaksadditionalorderinginformation. §6.8MBBVoteStorage 61 6. DetailedAnalysis Mitigations One might attempt to mitigate this issue in a number of ways. First, one might attempt to restrict physical access to the MBB, perhaps with extensive tamper sealing, thus pre- ventingitfrombeingrewritten. Thesecuritylevelofthisdefensedependsontheattackvector. If theattackerwantstowritetheMBBwithhisowncomputer, thisprovidessomelevelofsecurity. If the attacker has compromised the JBC/eScan, then he can arbitrarily rewrite the MBB without removingitfromtheJBC/eScan. Auditing the MBB contents against JBC/eScan internal memory might also detect this attack if the attacker has only altered the MBB. However, it will not detect the attack if the attacker has compromisedtheJBCoreScanandthereforecanmodifytheinternalmemory. Finally, one might attempt to enforce this on the Tally side. This could be done in two ways. First, one could compare the number of recorded votes in each precinct against the number of voters signed into the precinct and flag discrepancies. Second, one could keep records of which MBBswereassignedtoeachprecinctandflageventswhereprecinctswhichshouldnotappearon agivenMBBinfactdo. However,thismightinterferewithconsolidationfeaturesandthecreation ofrecountMBBsbySERVO. InfutureversionsofHartsoftware,theserecordscouldnaturallybestoredintheMBBheader. However,becausetheheaderisintegrityprotectedwithakeyavailabletotheJBC/eScan,thiswill notdefendagainstanattackerwhohascompromisedthemwithoutastrongercryptographickey infrastructure(seeSection6.7). Status This issue was discovered by examination of the source code. The MBB-reading code is extremelycomplicatedandmayincludesanitychecksthatpreventeitheroftheseattacks,although wedidnotseeanysuchchecks. Testingonarealsystemwouldberequiredtoconfirmorrejectthis issue. Issue28:UserscanreadunclosedMBBsorMBBswithinvalidMACs AlthoughthedataontheMBBisintegrityprotectedwithHMAC,thisHMACisonlyapplied when the election is closed. When Tally is asked to read an MBB which isn’t closed or when the cryptographic check fails it shows a dialog allowing the user to accept the MBB anyway. This providesapotentialwaytobypasstheMACcheck. DetailedDescription WhenTallyreadsinanMBBitcheckstheMACvalue. Basedonthedoc- umentation, if the MAC check fails, it complains that the MBB is corrupt and allows the user to acceptitanyway. Similarly,iftheelectionisnotclosed(andthereforethereisnoMAC),Tallypops up a dialog giving the user the option to accept the MBB anyway. This provides an easier attack target for an attacker who has possession of an MBB but cannot forge the MAC: they send in the MBB with a bogus MAC or simply don’t close the election or strip off the closure information in the audit log. There is no guarantee that the MBB will be accepted, but experience in other envi- ronments,whereusersareaskedtoenforcesecurityrules[29,34],suggeststhattherewillbeahigh rateofusersacceptinginvalidMBBs. NotethattheconcernherewithrespecttoTallyusersisinattention,notmalice,sinceasophis- ticatedTallyusercanforgeMBBs. Prerequisites ToexploitthisanattackerwouldneedtobeabletoeithermodifyanexistingMBB orsubstitute/addhisown. Thisprobablymeansapollworkerorelectionofficial. Impact Thisattackwouldpotentiallyallowanattackertoinjectfalsevotes. Mitigations OnepotentialmitigationforfutureHartsoftwareversionswouldbetosimplyrefuse toeveracceptun-closedMBBs. However,thiswouldhavetheeffectthatifpollworkersmakeany mistakes, perhaps forgetting to close a precinct before shipping off the MBB, recovery would be difficult. §6.8MBBVoteStorage 62 6. DetailedAnalysis ThiscouldperhapsbeaddressedwithaseparatetoolthatHartwouldsupplytoelectionadmin- istrators which could be used to sign unclosed MBBs. This tool would require supervisor access and produce extensivepaper logging. Such MBBsshould perhapsbe flaggedfor ahigher proba- bilityofpost-electioninvestigationsincetheyaremorelikelytobecorrupt. Status This issue was discovered in the source code and verified in the documentation but we havenottesteditourselves. Issue29:Theprotectivecounterissubjecttotampering A voting machine are required to keep a private protective counter that is incremented with eachvotecastandthatreflectsthetotalnumberofvotesevercastonthatmachine. However, on the JBC, eSlate, and eScan, the private counter can be tampered with by software running on the machineandthroughthemanagementinterface. Detailed Description Each of the JBC, eSlate, and eScan keeps the private counter in memory asa32-bitinteger(alongwitha16-bitCRC,whichisineffectiveatdetectingtampering). Oneach ofthesedevices,thecounteriskeptstoredinflashmemory. TheeScanusesits“estoremanager,” which keeps two copies at location STORE_VOTE_COUNTERS. This flash copy appears to be up- datedonlywhenthelogsarecleared;thecurrentprivatecounteristhesumofthecounterinflash andthevotesrecordedintheauditlog. TheJBCandeSlatestoretwocopiesinterleaveddirectlyin flash,atADDR_PRIVATE_COUNTER,i.e.,0x0000c000. SincethesoftwareontheJBC,eSlate,andeScancanmodifythestoredprivatecountersdirectly, anymalicioussoftwareloadedontothesedevicescanmodifytheprotectivecounter. What’smore, itispossibletousethemanagementinterfacetomodifytheprotectivecounterwithoutreplacing thesoftware. Forexample,theJBCprocessesaNET_CMD_CLR_PRIVATE_CNTmessagethatresets the private counter. In addition, an attacker can rewrite the private counter directly using the MEM_WRITEoptiontotheNET_CMD_MEMORYmessage. Prerequisites Toexploitthisanattackerwouldneedeithertoreplacethesoftwarerunningona JBC,eSlate,oreScan,ortobeabletoconnecttothedevice’smanagementinterface. Impact Thisattackwouldallowtheattackertomodifytheprotectivecounter. Mitigations Implementingacounterthatcanbeincrementedbutnotresetorotherwisemodified requiresspecializedhardwaresupport,whichHartwouldhavetoaddtotheJBC,eSlate,andeScan. Status Thisissuewasdiscoveredinthesourcecode,butwehavenotattemptedtoverifyit. Issue30:IftwoMBBshavethesameID,Tallyonlyreadsthefirstone TallymaintainsadatabasewhichstoreseachMBB.IfanattackercanloadabogusMBBthathas thesameIDasarealone,beforethatrealMBBwasloaded,therealMBBwillberejectedbyTally. DetailedDescription EveryMBBhasanidentifierthatshouldbeuniquewithinthecounty. Be- fore a new MBB is inserted into the database, the database is first queried to see if the MBB ID is already present. MBBValidateCls::InsertSubLog is responsible for this process, ultimately callingintoMbbDBInfoCls::AlreadyProcessedwhichdoestheSQLquery. NowhereintheprocessisthereanychecktomakesurethatthegivenMBBIDistheproperID foragivenprecinct. Asaresult,anattackercouldproduceamaliciousMBBforatargetprecinct, perhapsasaresultofcompromisingaRallyserveroraJBC,andthenTallywouldloadthatMBB. §6.8MBBVoteStorage 63 6. DetailedAnalysis So long as the attacker’s malicious MBB goes first, it will prevent the legitimate MBB from being loaded. Asuitableerrormessagewillbelogged,butelectionofficialswouldhavenoeasywaytoresolve the errorcondition. Even thoughthe log indicatesthe identifierof the conflictingMBB, Tally has noMBBremovalmechanismavailablefromitsuserinterface. Impact This is an example of a “denial of service” attack, which will slow down the tallying process, possibly requiring assistance from the vendor in order to resolve the issue. This could delayelectionreportingforseveraldays. Prerequisites AnattackerneedstheabilitytointroducebogusMBBsintotheRally/Tallysystem. This could be accomplished through attacks against eScan or JBC systems, in the polling place, through attacks against Rally, perhaps via modem, or through attacks against SERVO, if it were usedtoextractMBBsdirectlyfromthevotingmachines. AnattackeralsoneedstoknowtheMBBidentifiersforanyparticularprecinctsthathewishes to suppress. BOSS, which writes out MBBs, generates these identifiers sequentially as it writes thecards, startingoutfromoneandworkingitswayup. Thismeansthatanattackercansimply use small numbers for MBBs to perform the attack, if he has no particular preference for which precincts he wishes to suppress. If he wants to suppress a particular precinct, he would need to knowtheexactorderinwhichtheMBBsarewrittenbyBOSS. Mitigations This attack must be performed after the ability to inject a bogus MBB has been ac- complished.Assuch,themitigationswhichmightprotectagainstthoseattackswouldalsomitigate againstthisattack. Shouldanattackofthisformsucceed,noactualvotedatawouldbelost. Avendortechnician couldpotentiallyissuerawSQLcommandstocleanupthedatabase. Likewise,VVPATprintouts andpaperballotscouldbetabulatedbyhandfortheaffectedprecincts. Status Thisissuewasdiscoveredbyexaminationofthesourcecode. Wehavenotattemptedto verifyitwitharealTallyinstallation. 6.9 Rally/Tally’s Use of TLS/SSL Whencommunicatingoveramodem(seeSection6.6), RallyandTallyencrypttheirconversation usingOpenSSL(theSecureSocketsLibrary),which,whenusedproperly,couldbothpreventtam- peringandeavesdroppingonthecommunication. Issue31:RallyandTallyuseanoldversionofOpenSSLwithknownbugs. Rally/TallyuseOpenSSLversion0.9.7d, circaMarch2004. ThisopensRallyandTallyservers toattacksagainstdocumentedOpenSSLbugs. Background Whenyouvisitasecurewebsite(i.e.,anywebsitewhoseURLbeginswith“https”) thewebsiteandyourbrowsercommunicatewiththeTransportLayerSecurity(TLS)protocol[8], oftenreferredtobyitsearliername,theSecureSocketsLayer(SSL,whichwewillusehere). SSLis mostcommonlyusedforsecurewebpages,butthisgeneral-purposetechnologyandcanbeused foravarietyofothertasks,asitisused,forexample,byRallyandTally. SSLuseencryptiontechnologiestoprovideavarietyofusefulproperties: Integrity SSLusesmessageauthenticationcodes(MACs)toensurethatthedatareceivedbyone side of the conversation is precisely the same data that was sent by the other side of the conversation. §6.9Rally/Tally’sUseofTLS/SSL 64 6. DetailedAnalysis Privacy SSL provides optional encryption, using a variety of different algorithms, to ensure that eavesdropperscannotlearntheplaintextoftheconversation. Authentication SSLcanvalidatethatthepartyontheothersidehasaspecificidentity.Thisisdone usingcertificates,whicharedigitallysignedstatementsmadebyacertificateauthority(CA)who is trusted by both parties. When the two parties start their SSL conversation, they will use cryptographic techniques to prove that they are the holder of a particular secret key which corresponds to a public key. Likewise, they will prove that the CA agrees that the public keycorrespondstotheirname,organization,emailaddress,orotheridentifyinginformation specifiedinthecertificate. OpenSSLisafree,open-sourceimplementationoftheSSLprotocolthatiswidelyused,partic- ularly by the Apache web server. Hart InterCivic has adopted OpenSSL to use for protecting the conversationsbetweenRallyandTallywhentheyareperformedoveramodem. Detailed Description One of the supported configurations for Rally and Tally is to create “re- gional” centers, where poll workers would bring their MBBs at the end of the day. The regional centers would have PCs running Rally, which would be used to collect the MBBs together. Tally, running at Election Central, would make a phone call to each regional center, connecting to the computerrunningRally,andwouldthendownloadtheMBBs. Thisconnectionisprotectedbythe useofSSLandbytheuseofausernameandpassword. Alternately,RallymachinesmaybeinstalledalongsideTallymachinesatElectionCentral. This wouldallowtheretobemultiple“processingdesks”tohandleincomingMBBs,speedingthepro- cess. In this configuration, the Rally and Tally machines are connected by a local area network (i.e., standard Ethernet), which Tally uses to copy the MBBs from each Rally machine. SSL and username/passwordsarealsousedinthisconfiguration. WhilewewerenotgiventhesourcecodetotheversionofOpenSSLusedbyHartInterCivic,we weregiventheDLLs(compiledbinarylibraries)thatcontainOpenSSL.ByexaminingtheDLLs,we determined that Hart is using OpenSSL 0.9.7d, which was released in March 2004. The OpenSSL maintainers’ vulnerabilities web page20 documents seven known issues that apply to OpenSSL 0.9.7d. These issues include one attack which can be used to crash the remote system and an- other which allows a buffer overflow attack. The buffer overflow attack relies on a flaw within SSL_get_shared_ciphers(),whichispresentlyunusedbyRallyandTally. Theotherrelevant OpenSSLflawsallowanattackertocrashtheprogramortoinduceaninfiniteloop(renderingthe programunresponsive). WhenRallyandTallyareusedwithmodemstoconnectthem(seeSection6.6),anattackermay alsoconnecttotheRallymachineviamodemandcanthenusetheseknownOpenSSLvulnerability toattackRally. Prerequisites Rallyand Tallyhavetwo usemodes: communicatingovermodems orcommuni- cating over a network21. This attack mode functions in any context where an attacker can access thenetworktowhichTallyorRallyisconnected—inparticular,ifRallyisconnectedtoamodem. If, forwhateverreason, aRallysystemwasconnectedviaitsnetworkporttotheInternetthis vulnerabilitywouldalsobeexploitablebyaremoteattackerovertheInternet. Impact When Rally and Tally are used with modems, an attacker can cause an arbitrary Rally system to crash or become unresponsive, simply by dialing its phone number. Such an attack couldbeusedtoslowdownorinconvenienceelectionofficials. Mitigations One obvious mitigation to the risks posed by outsiders connecting to Rally/Tally modemsistoavoidanyuseofmodems. Rallyserverscanoperateoffline,collectingvoteswithout 20http://www.openssl.org/news/vulnerabilities.html 21Theuseprocedures[21]specifyanintranet,butthereisnotechnicalreasonitcouldnotbetheInternet §6.9Rally/Tally’sUseofTLS/SSL 65 6. DetailedAnalysis transmittingthemtoTally.Onceallthevoteshavebeencollected,theRallyservercanbephysically transportedfromtheregionalvotecollectionfacilitytoElectionCentral. Another possible mitigation is to train election officials how to respond to these attacks (e.g., how to kill and restart the Rally application) or to switch to physical transportation of the Rally machinesifthemodemsarenotworkingproperlyorareunderattack. Of course, future software releases from Hart could be engineered to address these concerns, mostlikelybyupgradingtothecurrentversionofOpenSSL(andfollowingsubsequentOpenSSL upgradesastheybecomeavailable). Status Thisissuewasdiscoveredby examination ofthesourcecodeandotherfiles provided to thesourcecodeanalysisteam. IthasnotbeendirectlyverifiedagainstRallyandTallyservers. Issue32:RallyandTally,whenpresentedwithanunknowncertificate,willpresent theunauthenticatednameandorganizationtotheuserforverification. DetailedDescription WithRallyandTally,thereisnocertificateauthority(CA)inuse. Instead, Rally and Tally have a memory of the certificate used “last time” and will present a dialog box to the user if the certificate changes. This dialog box presents the name, organization, city, state, and country from the remote machine’s certificate. However, because no CA was used to sign the certificate, its contents may be set arbitrarily by an attacker. If a user is convinced to press the “okay” button to this dialog (on either side: Rally or Tally), then an attacker can potentially impersonateonesidetotheother. Once the SSL connection is initialized, Tally authenticates itself to Rally by presenting a user- name and password inside the SSL connection. This username and password are configured in advance, before the Rally machines are deployed. This process is analogous, in some fashion, to how users authenticate themselves to secure commerce web sites, but it’s not very good for use whentwocomputersareconnectingtooneanotheronaregularbasis. Theuseofhuman-chosen passwordsisanunnecessaryopportunityforpoorpasswordstobechosen. AsidefromtheSSLcertificateauthentication,thereisnoothermechanismforRallytoauthenti- cateitselftoTally. ThismeansthatanattackerwhocanintercepttheconnectionbetweenRallyand Tally, perhaps by climbing a telephone pole and clipping into the appropriate wires, may be able toimpersonateaRallyservertoTally. Theonlymechanismpreventingsuchanattackisthedialog boxthatwillappearontheTallymachineaskingtheusertoapproveofthenewcertificate(which, asdescribedabove,canpresentseeminglycorrectinformation). Prerequisites Rally and Tally must be configured to communicate over a modem or other net- work connection. The user of Rally or Tally (whichever machine is being attacked) must press okaytoadialogboxthat,byallappearances,ispresentinggoodinformation. Inthecaseofattacks against Rally, the attacker must know the phone number of Rally and must know the username andpassword. InthecaseofattacksagainstTally,theattackermustbeabletointerceptthephone callfromTallytoRally. If,forwhateverreason,aRallyorTallysystemwasconnectedviaitsnetworkporttotheInter- net,thenthisvulnerabilitywouldalsobeexploitablebyaremoteattackerovertheInternet. Impact If modems are used to connect Rally and Tally and if the usernames and passwords are chosenpoorly,anattackerwillbeabletoconnecttoRallyanddownloadallofthevotesstoredin it. Likewise,ifanattackerisabletointercepttheoutgoingphonecallsfromElectionCentral(e.g., by climbing a nearby telephone pole and attaching alligator clips to the appropriate wires), then theattackerwouldbeabletoinserthisowncomputerinplaceofthetrueRallymachine,feeding backarbitraryvoteinformationtotheTallyserver. §6.9Rally/Tally’sUseofTLS/SSL 66 6. DetailedAnalysis Mitigations OnepossiblemitigationistoensurethatallRallyandTallysystemsare“preloaded” withthenecessarycryptographiccertificates. ThiscanbeperformedintheElectionCentralware- house, prior to deploying the Rally systems to the field. This would allow for poll workers and electionofficialstobeinstructed,underallcircumstance,torejectrequeststhatRallyorTallymight pop-uponthescreentoapproveanyneworpreviouslyunseencertificate,regardlessofthecertifi- catecontentspresentedon-screen. The use of strong usernames and passwords also mitigates against this threat, as an attacker who does not and cannot guess the username and password will be unable to make any further progress attacking Rally, but would remain unhindered in presenting a false Rally to spoof Tally. HemightbeabletoleveragethatattacktocapturetheTallypasswordandthenimpersonateTally toRally. TheusernameandpasswordchosenwithinRallyandTallytoauthenticatethesystemstoone anothermustbecarefullychosentohaveahighdegreeofrandomness. Anumberofcommercial and free software tools are available that can generate suitable passwords. Likewise, passwords couldbeselectedbyrollingdice. EveryRallymachinecanandshouldhaveadifferentusername andpassword. ThisissuecouldalsobemitigatedaspartofabroaderredesignofHart’skeymanagementar- chitecture(seeSection6.7),inwhichkeysaremanagedcentrallyandlesssubjecttouserdiscretion. Status Thisissuewasdiscoveredbyexaminationofthesourcecodeprovidedtothecodeanalysis teamaswellasreadingtheRallyandTallyusermanuals[18,20]. Ithasnotbeendirectlyverified againstRallyandTallyservers. 6.10 Verified Ballot Option Issues AsrequiredbyCalifornialaw,Hart’sDREsystemhasaVoterVerifiedPaperAuditTrail(VVPAT), whichHartcallstheVerifiedBallotOption(VBO),whichusestheVBOx,areel-to-reelprinterwhich attaches to the eSlate. Once the voter has indicated that he wishes to cast his ballot, the ballot information is printed by the VBOx and presented to the user. The voter can then indicate either acceptanceorrejectionoftheballot. If the voter accepts the ballot, the VBOx prints an “BALLOT ACCEPTED” message and a bar code and then scrolls to a blank page. If the voter rejects the ballot, the VBOx prints a “BALLOT REJECTED”messageandtheeSlateallowstheusertoadjusthisvote. TheVBOxisintendedtoprovideevidenceofthevoter’sintentinawaythatisnotamenableto tamperingbycompromisedsoftwareontheDRE.However,wefoundanumberofimplementation decisions that might allow an attacker who controlled the eSlate to construct bogus paper audit trails. Issue33:VBOxprintingandscrollingiscontrolledbytheeSlate TheVBOxitselfisanextremelysimpleprinter.ThecommandsitreceivesfromtheeSlatejusttell ittoprintarbitrarydatatothepaperand/orscrollthepaperforward. Thisenablesacompromised eSlatetoexertalargeamountofcontrolovertheVBOx. Detailed Description The eSlate communicates with the VBOx by sending it a variety of com- mands. The two most relevant here are Print and FormFeed. These allow the eSlate to print arbitrarybytesandtoscrollthepaperforward. However,thegeneralflexibilityofferedhereplus thefactthatthereisnoexternalusercontrolontheVBOx, allowacompromisedeSlateflexibility tomountattacks. Thesimplestsuchattackwouldbeforgingvotes.AsdescribedinIssue8,acompromisedeSlate cansendvotestotheJBCevenifnoacceptablevotercodehasbeenenteredintotheeSlate. How- ever, this potentially produces an inconsistency between the recorded votes and the VVPAT. Be- §6.10VerifiedBallotOptionIssues 67 6. DetailedAnalysis causetheeSlatecontrolstheVVPAT,itcansimplyissueitsowninstructionstotheVVPATtoprint thevotealongwiththeacceptedbanner. Other attacks are also possible, such as waiting for a voter to confirm his vote, then printing “BALLOTREJECTED”,printinganew,corruptvotewiththe“BALLOTACCEPTED”bannerand thenscrollingtoablankpage. YetanotherpossibilitywouldbetosimulateVBOxfailures(e.g.,formfeedthroughallthepaper) toforcethepollingplacetofallbacktoelectroniconlyvoting. Wedonotknowhowpollingplaces dealwithfailuresoftheVVPAT. Prerequisites Toexploitthisissue,anattackerwouldneedtocontroltheeSlateorsomehowgain control of the serial connection between the eSlate and the VBOx. There are two points of attack here: theconnectionbetweentheeSlatestandandtheVBOx, whichappearstobeasimpleserial cable, and the contacts in the eSlate stand which mate to contacts on the bottom of the eSlate. It is not clear that either are well sealed and the eSlate stand contacts are voter accessible, though clumsilynonstandardtoaccess. Impact An attacker can maintain consistency between tampered electronic vote records and a tamperedVVPAT,thusdecreasingtheriskofdetection. Mitigations ApartialmitigationwouldbetoprovidetheVBOxwithseparatehardwarecontrols so that the voter had to operate the VBOx in order to accept their ballot. This would prevent attacks where the eSlate ran off incorrect ballots. One approach that has been suggested in the past but would require somewhat extensive re-engineering would be to have the VBOx have a mechanicalswitchthatwhendepressedcutofftheballotanddroppeditintoahopper,thusboth requiring manual engagement in the voting process and providing some measure of privacy for thesequenceofvotes(seeIssue35.) Status Thisissuewasdiscoveredthroughexaminationofthesourcecode. Ithasnotbeentested ontheVBOxPrinterhardware,whichmaynotinfactsupportarewindfeature. Issue34:TheVBOxcodeindicatesareversefunction A VBOx printer is connected to an eSlate device, which issues it commands to print data. It appears to be possible for the VBOx printer to be run backwards, thereby overwriting previous ballot records. While there are not commands implemented in the source code to perform this action,ifanattackerweretogaincontrolofaVBOxPrinter(forexampleviaacompromisedeSlate) theymightbeabletocausetheVBOxPrintertorunbackwards. Detailed Description When a VBOx Printer receives a command from an eSlate, code on the printerisexecutedthatinstructsthehardwaretoperformtheprinting. WithinthisVBOxPrinter sourcecode,wefoundseveralcommentedoutlinesofcodethatseemedtoindicateitwaspossible toinstructtheprinterhardwaretoruninreverse. Soundernormaloperatingconditions,running inreversewouldnotoccur. However,ifanattackerwereabletotakecontrolofaVBOxPrinter,e.g. byexploitingabufferoverflow,itseemshecouldinstructtheprinterhardwaretorunbackwards. Prerequisites An attacker who is able to execute code on the VBOx printer could be able cause theVBOxPrintertorunbackwards. Impact RunningtheVBOxPrinterbackwardswouldoverwritepreviouslywrittenballotrecords, therebycorruptingasourceofdataforperformingmanualrecountsofballots.Itwouldalsoenable anobservertoseepreviously-castvotes,violatingtheprivacyofthosevoters. §6.10VerifiedBallotOptionIssues 68 6. DetailedAnalysis Mitigations The natural mitigation for this issue is to disable backwards feeding in the VBOx Printer hardware. If this change were made, even a complete compromise of the VBOx Printer softwarewouldnotresultintheoverwritingofballotrecords. Status Thisissuewasdiscoveredthroughexaminationofthesourcecode. Ithasnotbeentested ontheVBOxPrinterhardware. Issue35:TheVBOxvotesaresequentialandsocompromisevoteprivacy TheVBOxisareel-to-reelprinterwithvotesprintedsequentially. Therefore,anyattackerwho hadaccesstothepapercoulddeterminethesequenceofvotesandhowanyindividualvotervoted. DetailedDescription CastvotesareprintedoutontheVBOxinsequencebothinhuman-readable mode and as machine-readable bar codes. This allows an attacker who has access to the tape to determine the order of votes. With access to the order in which voters voted, this allows recon- structionofindividualvotes. Evenifthepapertapehasbeencut,itmaybepossiblewithenough worktolineupcutedges. Thisattackismademoreusefulbythepredictabilityofvotercodes(Issue7),becauseanattacker canidentifywhereaparticularvotercodeoccurredtothesequenceofvoters. Prerequisites TheattackerwouldneedaccesstotheVBOxpapertape. Thiscouldpotentiallybe available to a poll worker who violated the VBOx tamper seals, if any. It would be available to a numberofelectionofficials. Impact Thisissueallowsviolationofvotesecrecy. Mitigation The primary mitigation here is to ensure that nobody ever has access to the paper tapeincompleteform. IfaVBOxauditisperformed,somemechanismshouldbeusedtoblindly cutthepaperapart,perhapsmechanically. ThisappearstobeanissueforallcurrentVVPAT-based e-votingsystems. Status Thisissuewasdiscoveredbyinspectionofthesystemandisgenerictoreel-to-reelVVPATs ofthistype. 6.11 Code Quality and Miscellaneous In addition to the specific issues discussed above, we identified a number of problems related to theimplementationoftheHartInterCivicvotingsuitethatbeardiscussion. Issue36:Pervasivefailuretofollowcommonlyagreedsafecodingpractices Writingsecurecodeisanextremelydifficultproblem,especiallyinCandC++,whichgivethe programmer an extraordinary amount of control over memory, and thus a large number of ways tomakeseriousmistakes. §6.11CodeQualityandMiscellaneous 69 6. DetailedAnalysis DetailedDescription Specificclassesofproblemsinclude: Failuretocheckarraybounds. In addition to the exploitable buffer overflows listed previously, wediscoverednumerousplacesinthesourcecodewherememorybufferswereusedwithout appropriateboundschecking. Insomecasessystemcrashescouldpotentiallybetriggeredby anattackertakingadvantageoftheseoverflows. Throughacombinationofmanualandautomatedsourcecodeexamination—usingFortify— wefoundanumberofbufferoverflowsintheHartsourcecode. Whilemostofthemdidnot openthesystemstocontrolbyanattacker,theseoverflowsweresuggestiveofafragilecode- baseandofasoftwaredevelopmentprocessthathasroomforimprovement. Formatstringvulnerabilities. Thecorrectwaytoprintastringusingtheprintffamilyoffunc- tionsisprintf("%s", str), notprintf(str). Thisbecausethelatterformcanleadto unexpectedresultsifstrcontainsformatspecifierssuchas%d.Infact,acarefullycraftedma- liciousformatstring,wheninterpretedbyprintf,canallowtheattackertoexecutearbitrary code. TheHartsourcecontainsmultipleinstanceswhereprintfisusedwithanon-constantfor- mat specifier. One example is the JBC’s report mode, which uses printf to print write-in candidatenames;seeIssue6. Signednessandintegeroverflowerrors. It is important to watch out for arithmetic operations whose result is outside the range of values that can be represented by the result type. For example,30,000+30,000asasigned16-bitintegeris−5536,not60,000. Wraparoundofthis sortcanleadtoincorrectresults.Itcanalsoleadtosecurityvulnerabilitiesofaclassknownas integeroverflows[6]. Acommonvarietyofintegeroverflowarisesfromcarelessnessabout the signedness of values, leading to (implicit) integer overflow when a signed quantity is type-castasunsignedorviceversa. TheHartsourcecodeweexaminedcontainsmultipleintegeroverflows. Itmakesextensive use of 16- and 32-bit signed and unsigned integers, and frequently converts between these. Thissometimesleadstoexploitablevulnerabilities. Forexample, considerTally’sMBBprocessing. ForeachMBB,Tallyreadstheextentsofthe CVR log from the MBB header, then computes the size of this log by subtracting the end offsetfromthestart offset—asa32-bitsigned integer. Ifthedifferencebetweentheseoffsets exceeds2,147,483,647,itisrepresentedasanegativenumber,whichmeansthatTally’scheck that the size is less than the maximum allowed size is satisfied. The log is then read into a buffer,whichcausesmemcpytobeinvokedwiththecomputedsizeasitssizeargument. But memcpytreatsitssizeargumentasanunsignedinteger,whichmeansitcopiesmorebytesthan areallocatedfortheinputandoutputbuffers,leadingtomemorycorruption. Failuretocheckandpropagateerrorconditions. Detectingandappropriatelyactingonunexpected error conditions is important for secure programming. Attackers compromise systems by causing them to deviate from their intended behavior, and this deviation will be character- ized by an error condition. Software modules should check that each of their assumptions about their environment is satisfied before acting. Having discovered an anomalous condi- tion,modulesshouldpropagateanalerttohigher-levelcodethatcantakeappropriateaction inresponse. The Hart source code we examined follows neither of these recommendations. This some- timesleadstoexploitablevulnerabilities. Forexample,whenaJBCrecordsavotereceivedfromaneSlate,theJBCcallsafunctiontore- movetheeSlate’sclaimedvotercodefromthelistofactivecodes. Ifthisfunctiondetermines that supplied the voter code is not a valid voter code, it takes no corrective action. It does notloganalert, itdoesnotalerttheoperator, anditdoesnotpropagatetheerrorcondition up—infact,thefunctionisoftypevoid. (Evenifthefunctiondidpropagatetheerrorup,it §6.11CodeQualityandMiscellaneous 70 6. DetailedAnalysis isalreadytoolatetoremovethevotefromtheCVRlog.) Thelackoferrorcheckingiscrucial inenablingtheattackdescribedinIssue8. Failuretominimizetrustbetweencomponents. Softwaremodulesshouldbewrittentominimize relianceonthecorrectnessofothermodules. Thisisnotonlyusefulforrobustnessbutcrucial for security. If this principle is not followed, a compromise of one module can lead to a compromiseofanotherthattrustsittobehavereasonably. The Hart source code we examined does not follow this principle. This sometimes leads to exploitablevulnerabilities. Forexample,whenSERVOisbackinguptheauditlogofaneScan,JBC,oreSlate,itasksthe devicewhattheextentsofthedevice’sauditlogareandusestheanswertosizeabufferforits copyofthelog. Then,aspartoftheactuallogdumping,SERVOagainasksthedeviceforthe auditlogextentstodecidehowmanybytestotransfer. Ifthethetwoanswersarethesame, thecopyproceedsasexpected. If,however,theconnecteddevicehasbeencompromisedand claims a different (larger) log size on the second query than on the first, SERVO’s allocated bufferisoverwritten,leadingtoaheapoverflow,asdescribedinIssue13. Poorlyunifieddesign. Any time a piece of software has multiple implementations of the same typeoffunctionality,thereisanopportunityforerror. TheHartsoftwareincludesanumber ofsuchcases,including: Multiplecopiesofpiecesofcode in particular, between the HartLib library and the eScan. In many cases the files seem identical, in others they appear to be system-dependent, andinyetothercasestheyappeartobebranchedversionswhichhavediverged. This programming practice substantially increases the risk that the files will diverge in im- portant ways, for instance fixes get applied in inconsistent ways, or that programmers getconfusedaboutthebehaviorofthesubroutinebeinginvoked. Multipleerrorreturnhandlingmechanisms between different sections of code. In some places, the Hart code uses exceptions, in others, they use explicit return values, and inotherstheysimplyignorethereturnvalues. Thismakesithardforoneimplementor tobesureoftheerrorconventionusedbyanothersectionofcode,whichcanleadtoer- rorsbeinginappropriatelyignored. Wehavefoundcaseswhereerrorsshouldnothave beenignoredbutwere,thoughwedonotknowthecause. Inconsistentmemoryallocation. Hart uses both malloc and new. There is nothing inher- entlyunsafeaboutthisinC++code,butitrunstheriskofmisusingdatamanagedwith onemethodwiththeothermethod,whichcancreateseriousproblems. Theseissuesmakethecodehardtomaintainaswellastoreview,sinceonemustfrequently ask“whatsection(orsections)ofcodeisinplayhere?” Aunifiedsystemwouldbeeasierto workon. Prerequisites Theprerequisitesforanattackbasedonaninstanceoftheissuesdescribedabove dependonthespecificsettinginthesystemwherethatinstanceisfound. Theknowledgerequired toexploitstandardC-languagevulnerabilitieslikebufferoverflowsiswidelydisseminated. Mitigations Hart could rework its codebase, using some combination of: following commonly- agreed safe coding practices; auditing the code base by hand or with automated static analysis tools;andrewritinginasaferlanguagesuchasJava. Status Thisissuewasdiscoveredthroughbothmanualandautomatedexaminationofthesource code. §6.11CodeQualityandMiscellaneous 71 CHAPTER 7 Attacks on the Full System The previous section described a number of attacks on individual components of the Hart Inter- Civic voting system. However, an attacker would not be limited to mounting individual attacks, butwouldmostlikelywanttostringthemtogetherintoanattackplanwhichaccomplishesasetof real-worldobjectives. In the rest of this section, we consider attacks designed to accomplish a number of common objectives: • Compromisingvoterprivacy • Alteringthefinalvotecount • SubvertingallDREdevicesinaprecinct • Subvertingallthedevicesinacounty It’simportanttonotethatinmanycaseswewillonlypresentoneorahandfulofavenuestowards achieving the desired goal. This should not be taken to imply that there are no other ways to achieve these goals or even that we do not know of others. Rather, this section is intended as an illustrationofhowanattackermightchoosetoattackthesystem. 7.1 Compromising Voter Privacy AsdiscussedinSection3.2.3,therearetwomajorapplicationsforattacksonvoterprivacy: • Votebuying/votercoercion • Informationgathering Theattacksdescribedinthissectionworkforbothapplications. 7.1.1 VoteBuyingoneSlateSystems In a vote buying attack, the attacker needs to be able to verify that the voter voted the way that hewasinstructed. Theattackercanreadilyverifythatthevoterenteredthepollingplaceandwas authorizedtovotebecauseHartissuesareceiptcontainingthevoteraccesscode. Whilethisdoes notdemonstratethatthevotervotedatallorthathevotedthewayhewasinstructedto,itisuseful incombinationwithotherissuestoformacompletevotebuyingattack. Thewaythatthisworksisthatthevotebuyerinstructsthevotertovoteacertainway. When thevoterexitsthepollingplaceheprovideshisaccesscodeprintoutreceipttothevotebuyer. The vote buyer can then use this access code as a lookup key into vote records stored on the MBBs, eSlate,orJBCtoverifythevoter’sactions(seeSection6.8fordetailsonvotestorage). Theproblem thenbecomesobtainingacopyofthatvotedata. Thisiseasiesttodoiftheattackerisamaliciouspollworker,usingthefollowingsteps: 72 7. AttacksontheFullSystem 1. AftertheelectionisclosedandtheMBBhasbeenunsealedheplacestheMBBintoaPCMCIA card reader (e.g., a laptop) and obtains an image. This is the only part of the process that requiresaccesstoprotectedmaterials. 2. He searches through the audit log for an access code entry that matches the voter’s access code. 3. HesearchesthroughtheCVRdataforanentrywithaCRCthatmatchestheentryintheaudit log(seeIssue25). 4. Heexaminestheentrytoseeifitmatchestheexpectedvotes. Thisallowstheattackerwithhighprobabilitytodeterminethatthevoterhasvotedasinstructed. Anelectionofficialcouldofcoursemountthesametypeofattack. Naturally, oncetheMBBdata hasbeenobtainedanddecoded,theattackercanverifyhowanynumberofvotersvoted. AnotherapproachwouldbetoreadtheinternalauditlogsoftheeSlateorJBCviatheparallel managementinterface(Issue1). Thesamederandomizationprocedurecanbeused. Avotercanalsomountthisattack. Inordertodoso,heplacesamonitoringdeviceontheserial port of any of the eSlates of the system, either in between the eSlate and the stand or on the free connectorofthefinaleSlate(seeSection6.2formoredetailsonwhatsuchadevicemightlooklike). ThisdevicewouldbeabletoobserveeverycastvotefromeveryeSlateinorderandwouldsimply recordthem. BecausetheaccesscodesaretransmittedbytheeSlatetotheJBCpriortovoting,itis veryeasytotietheaccesscodestotheCVR.Alternatively,avotercouldpotentiallyattachadevice attheveryendoftheelection,impersonatetheJBC,andsimplysuckoutthecontentsoftheJBC’s memory. Notethatthisdoesnotrequiretheattackertobepresentattheprecinct,hemerelyneeds toobtainthereceiptfromthevoter. 7.1.2 VoteBuyingoneScanSystems Vote buying attacks on eScan systems are more difficult because the voter is not issued with a linkable receipt. However, because the audit log is created sequentially and can be linked to the CVRlog,apollworkerwhohasaccesstotheMBBcanstillmountavotebuyingorcoercionattack. TheattackerobservestheorderinwhichpeoplefeedtheirballotsintotheeScan. Hethenlooksup theentryfortheappropriatevoterintheauditlogandusesthetechniquesdescribedinIssue25to findtherelevantCVR.Thistellshimhoweachvotervoted,intheordertheirballotswerecast. 7.1.3 InformationGathering Extendingthisattackbeyondasinglevotertoagenericinformationgatheringattackisrelatively straightforward.AgainsttheeScan,theattacklooksexactlylikethatdescribedinSection7.1.2.This allowsustomatchvotestotheorderinwhichvotersvoted. AgainsttheeSlate,theattackercandothesamethingaswiththeeScan,butobservingtheorder in which voters voted may not be simple because there are a large number of eSlates. However, becausetheeSlateauditlogscontaintheaccesscodeshecandosomethingmoreconvenient:match votestotheorderinwhichvotersenteredtheprecinctandreceivedaccesscodes. Inordertomountthisattack,theobservestheorderinwhichvotersapproachtheJBC.Hethen extractstheauditlogsfromtheJBC,eSlate,orMBB,whichcontaineachaccesscodeinorder,and thenusesIssue25tomatchtheaccesscodestothecastvotes. Thisallowshimtoreconstructhow each voter voted. Note also that even if the access code issuance were not in the logs, it would stillbepossibletoreconstructvoteorderbytakingadvantageofthepredictabilityofaccesscodes (Issue7.) Thisattackrequireshavingacollaboratorineveryprecincttoobservetheorderinwhichpeople voted—providedthatpollingplacesdonotkeepsuchrecords—whichmakeslargescaleinforma- tiongatheringdifficult. However,itwouldbepracticalforsmall-scaleattacks. §7.1CompromisingVoterPrivacy 73 7. AttacksontheFullSystem 7.2 Altering the Final Vote Count Anotherimportantattackistomodifythefinalvotecount.Inthissectionweconsiderattackswhere an attacker who controls a single device can modify the vote count. These attacks are obviously more powerful if the attacker controls multiple devices. We consider those issues in subsequent sections. 7.2.1 eScan The most obvious attack is to subvert an eScan, which can be done via the attack described in Issue 3. This would most likely require either poll worker or election official access, or that the attacker break into the location where the eScan is stored. An attacker who subverted the eScan couldmountatleasttwoattacks: • ExtractthesharedMACkeyanduseittowriteafakeMBB(seeSection6.7). • Installhisownfirmwareimagewhichcountsvotesinanarbitraryfashion(seeIssue3). The second attack is more powerful because it would result in the eScan internal vote data, the MBB,andthesummarytape,allhavingidentical(wrong)results. AsnotedinIssue12,itiseasyto subverttheexternalintegritycheckingandsoelectronicauditprocedureswouldnotdetectthisas longasthetotalnumberofvotesremainsthesame. Theonepercentmanualrecountwoulddetect thisformofattack,providedthatthevictimeScanwasrandomlyselectedforrecount. 7.2.2 eSlate WhileattackinganeScanismostlikelyoutsidethereachofavoter, webelievethatavotercould subvertaneSlate,asdescribedinIssue2.SuchanattackercouldinstallnewfirmwareontheeSlate, whichwouldactinanarbitraryfashion. The difficulty with the eSlate is that there are four types of records which one wishes to have agree: • CVRs/AuditlogsontheMBB • CVRs/AuditlogsintheJBC’sinternalmemory • CVRs/AuditlogsontheeSlate’sinternalmemory • TheVVPATrecords TheMBBdataiswhatisordinarilyusedfortallying,somodifyingthatisattractive,butourattacker maywishtosurviveanaudit, inwhichcasehemustarrangetotamperwiththeotherrecordsas well. IfweassumethattheJBCisuncompromised,thenthefirsttwotypesofrecordsagreebydefi- nition. Thedifficultyisgettingthefirsttwotypestoagreewiththethirdandfourthtypes. Weconsidertwoexampleattacks.Inthefirst,theattackerchangesavoter’svotebeforeitleaves theeSlate. Inthesecond,theattackerintroducesfalsevotesintothesystemfromtheeSlate. ChangingVotes Thebasicvotechangingattackissimple:the(compromised)eSlatesimplysends whateverCVRdataitwishestotheJBC.ThisproducesconsistentelectronicrecordsbuttheVVPAT willnotmatch. Itisnotclearhowseriousaproblemthisisfromtheattacker’sperspective,because inCaliforniatheVVPATisnotroutinelyverified,exceptduringthe1%manualtally. However,an attacker might wish to change votes in such a way that he could not be detected even in a 100% manualrecount. ThisrequiressomesocialengineeringtoproduceaVVPATrecordthatisincorrect butnotnoticedbytheuser. Anumberoftechniquesarepossiblehere: §7.2AlteringtheFinalVoteCount 74 7. AttacksontheFullSystem • The simplest approach is for the eSlate to print out a VVPAT entry that matches the wrong candidate. Ifthevoterdoesnotnotice,thentheattackerhaswon. Ifthevoterdoesnotice,the eSlatesimplyallowsthemtochangetheirvote,asiftheyhadsimplymadeanerror,thistime allowingthevotetogothrough. Everett’sresultsindicatingthatfewpeopledetectchanges inDREconfirmationscreens[10]suggestthatthisattackhasahighsuccessprobability. • Anotherapproachistopresentthecorrectvotedataonthescreen,waitfortheusertoaccept their ballot, and then display the UI indicator that shows their vote was accepted but not print “BALLOT ACCEPTED” on the VVPAT. Once the voter walks away, the VBOx prints “BALLOTREJECTED”indicatingthattheballotwasspoiledandthenprintsanewballotof theattacker’schoice. TheinstructionsforusingtheHartsystemonlytellthevotertowaitfor thedisplaytoindicatedone,nottowaitfortheVVPATtoscrollforward. • The converse of this approach is to present the correct vote data in the VBOx, but when the user accepts the ballot, print “BALLOT REJECTED” instead and then quickly scroll the paper forward. Once the voter is likely gone the eSlate prints a new VBOx record with the candidatesoftheirchoiceandmarkthat“BALLOTACCEPTED”.Thisisclearlypossiblein principlebutwehavenodataonwhethervotersorpollworkerswillnoticeit. Evenifthey did, it would be hard for a voter to prove the problem to a pollworker because the VVPAT wouldhavescrolledpast. In any case, the data recorded on the VVPAT would match the data recorded in the electronic records, with the result that the attack would not be detected by an audit. As with the eScan, SERVOsintegritycheckswouldnotdetectthecompromiseoftheeSlate(seeIssue11). ElectronicBallotStuffing Anattackerwhowasnotconcernedwithalteringthetotalnumberof castvotescouldalsouseacompromisedeSlatetointroducefalsevotes,asdescribedinIssue8or byusingthemodemporttointroduceaccesscodes,asdescribedinIssue4. Asdiscussedabove,wepresumetheattackerwouldwanttominimizehisvulnerabilitytode- tection. Therearethreeissueshere: • ArrangingthattheVVPATmatchestheelectronicrecords. • Avoidingdetectionbyvotersorpollworkers. • Makingitdifficultforanauditortodeterminewhichvoteswerefake. Inordertosatisfythefirstrequirement,theeSlatemustprintouttheattacker’schosenballotresult ontheVBOprinter. Otherwise, theonepercentmanualrecountmightdetectthecheating. How- ever,becausetheVBOxiscompletelycontrolledbytheeSlatesoftware(Issue33),thisisstraightfor- ward. Thisleavesuswiththesecondrequirement,avoidingvoterorpollworkerdetectionofthe attack. Thegeneralprinciplehereistoprintoutthefakevotedataaspartoftheprocessofclearing theVBOxscreenafterthevoterleaves. Thisminimizesthechanceofdetection. Note that this attack produces a situation in which the total number of votes in a precinct ex- ceeds the total number of voters. This is easy to detect during the official canvass, provided that countiescomparethenumberofvotescasttothenumberofvoters. Ifitisdetected,someattempts mightbemadetorepairthedamagebyremovingthefakevotes. Ifthevotercodesaregenerated using the modem technique of Issue 4, then they will presumably all be next to each other in the auditlogandeasytotosuppress.However,ifthecompromisedeSlatesometimesswapstheaccess codesforlegitimateandfakevotes,thentherepairproblembecomesquitechallenging. ThesituationismorecomplicatedifonlytheeSlateiscompromised.However,itisstillpossible tomakeitverydifficultforaninvestigationtodeterminewhichvoteswerethefakeones.Theattack isasfollows. 1. TheeSlatewaitsforavotertofinishvoting. 2. TheeSlategeneratesafakeCVR. §7.2AlteringtheFinalVoteCount 75 7. AttacksontheFullSystem 3. TheeSlategeneratesarandomnumberr,either0or1. 4. Ifr =0,theeSlateprintsthefakeCVRentrytotheVVPAT.immediatelyfollowingthevoter’s genuinevote. Otherwise,itwillbeprintedlater. 5. TheeSlatewaitsforasecondvotertocome,callthatvoter’saccesscodeX. 6. Ifr = 0,theeSlateimmediatelysendsthefakeCVRtotheJBCwiththenewaccesscodeX. Otherwise,itwillbesentlater. 7. The voter votes and the eSlate sends the correct CVR to the JBC and prints out the correct CVRentrytotheVVPAT. 8. Ifr =1,theeSlatesendsthefakeCVRtotheJBCwithaccesscodeX andthenprintsoutthe fakeCVRentrytotheVVPAT. Theresultisthatthereisapairofvotes,bothofwhichhaveaccesscodeX,buttheorderwillvary. Halfwillhavethelegitimatevotefirstwhiletheotherhalfwillhavethefakevotefirst. Thiswillbe consistentbetweentheVVPATandtheelectronicrecords. This attack could be detected by examining the electronic records, although we found no evi- dencethattheTallycodemakesanyattempttodetectmultipleusesofthesameaccesscode.Evenif thiscaseweredetectedandeveniftheelectionofficialsknewexactlyhowtheattackwasdesigned, they would be unable to distinguish between the legitimate votes and the fake votes that could occurineitherorder. Theelectionofficialwouldbeforcedtoeitheracceptbothvotesordisregard both votes, either of which could disenfranchise the voter whose access code was abused in this fashion. 7.2.3 VotinginOtherPrecincts If we assume that an attacker is not concerned with producing a set of electronic records which can survive auditing, other attacks are practical. If an attacker controls either a JBC or an eScan he can simply add CVRs of his choice to the MBB. Because each CVR contains its own precinct ID(Issue27),theattackermaybeabletoinjectMBBsintothesystemwhichcontainvotesforany precinctofhischoice,thusaffectingawiderareathanhisownprecinct. The difficulty with this attack is that it creates an inconsistency between the vote counts for eachprecinctandthenumberofrecordedvoters. Totheextenttowhichrecordsarekeptofwhich MBBsanddevicesareassignedtoeachprecinct, itshouldbepossibletodeterminetheroguede- vices/MBBsandsuppressthebogusvotes. Wedonotknowtheextenttowhichsuchchecksarein factdone. 7.2.4 DenialofService Subvertedmachinescanalsobeusedtomountavarietyofdenialofserviceattacks.Inthesimplest suchattack,themachinecouldsimplybeprogrammedtocrash,misbehaveinconfusingways,or operate extremely slowly. The scope of this attack depends on the number of machines compro- mised(seebelowfordiscussionofcompromisingmultiplemachines). Thiscouldblockoratleast severelyimpedeanentireelection. More sophisticated attacks are also possible. Machines could be programmed to detect the votingpatternsofvotersintheprecinctinwhichtheyareinstalledandmalfunctionifthevoting patternsareunfavorabletotheattacker. Machinescouldalsobeprogrammedtoselectivelyfailfor voters who voted a certain way, thus potentially causing them to give up. Once the machine is subverted,itisrunningsoftwareoftheattacker’schoiceandsoanyofthesebehaviorsaresimply amatterofprogramming. §7.2AlteringtheFinalVoteCount 76 7. AttacksontheFullSystem 7.3 Subverting all DRE Devices in a Precinct BecauseHart’spollingplacearchitectureinvolvesmultiplemachinesconnectedinanetwork, we shouldasktheextenttowhichitispossibleforanattackerwhohassubvertedonemachineinthe pollingplacetosubvertothers.1 Thisattackistrivialforapollworkeroranattackerwhobreaksintothepollingplace(orother storage area) the night before the election. It is also trivial for an election official working in the warehouse. First,heislikelytohaveunattendedaccesstoallthemachines. Second,hecansubvert theJBC(usingIssue1)andthenusethattotakeoveralltheremainingeSlates(usingIssue2). Theproblemismoredifficultforavoter,becauseheonlyhasaccesstoasingleeSlate.However, iftheattackercancausetheeSlatetoimpersonateaJBC(seeSection6.2),thenhecanusetheeSlate tosubverttheothereSlatesintheprecinct. ThisismadesomewhatdifficultbytheJBC’sbeingthe busmaster;however,webelieveitispotentiallypossible,asdescribedinSection6.2.3. Using the JBC write-in report vulnerability of Issue 6 it is possible to escalate access from an eSlatetotheJBC,butonlyattheendofanelection,potentiallycompromisingthefinalMBBdata orfutureelections. 7.4 Subverting all the Devices in a County Whilesubvertingthedevicesinasingleprecinctisattractivefortheattacker,itisalsolimitedfor reasonsindicatedinSection7.2.3.Amorepowerfulattackistotakeoverallthedevicesinanentire county. Webelievethatsuchanattackcanbemountedbyapollworker,voter,oranattackerwho hasbrokenintothepollingplace/storageareabeforetheelection. 1. Subvertasinglepollingplacedevice,whethereSlate,JBC,oreScan(seeSection6.1). 2. Installnewfirmwareonthatdevice. Thisfirmwareoperatesliketheoriginalsoftwareexcept thatitcontainsanexploitforoneoftheSERVOissuesdescribedinIssue13. 3. WhenSERVOconnectstothecompromiseddeviceaftertheelection(tobackupand/orver- ify),ourfirmwareattacksSERVOandinstallsnewsoftwareontheSERVOmachine. 4. WheneachnewdeviceisconnectedtoSERVO,ourprograminstallscompromisedfirmware on that device (again, see Section 6.1). Note that this happens immediately prior the next electionwhenSERVOisusedtozerothecounters. Attheconclusionofthisattack,mostoralleSlates,JBCs,andeScansinthecountywouldcontain maliciousfirmwareunderthecontroloftheattacker. Effectively, this is a multi-stage, multi-platform worm, with the exploit for each stage being embeddedasapayloadinthestagebeforeit. Writingsuchawormiswellwithinthecapabilities oftheaveragemalwarewriter. Thisattackallowsanattackerwhocompromisesasingledeviceinone election toescalateup toanattackonallthedevicesinacountybythetimeofthenextelection. Forinstance,onecould compromiseadeviceintheprimaryelectionandhavecompletecontrolofalldevicesinthecounty intimeforthegeneralelection. Once the attacker has control of all the devices in the county, he can of course mount attacks onvoteintegrityandsecrecythataredifficulttodetectand/orrepair, includingalloftheattacks describedinSection7.2. Wehavetestedthefollowingportionsofthisattack: • InstallationofnewfirmwareonaneScantowhichwehavephysicalaccess. • RemotecompromiseofSERVOfromaneScanduringthefirmwareverificationprocess. 1Thisisn’tarelevantissuefortheeScanbecausethey’renotnetworkedinsidethepollingplaceandtherearelikelyonly oneortwoeScansperpollingplace. §7.3SubvertingallDREDevicesinaPrecinct 77 7. AttacksontheFullSystem Wehavenotproducedanend-to-enddemonstrationofthisattack,howeverdeliveringapayload ofone’schoiceinthetypeofattackwemountedonSERVOisawell-understoodproblem.Wehave notdemonstratedtheabilitytochangethesoftwareonaneSlateorJBC.However,theinstallationof newfirmwareontheothereScansinthecountyfromSERVOisessentiallysimilartothefirmware installationwehavealreadydemonstrated. In addition to this attack, note that if SERVO is installed in a network with the the other Hart back-office software, an attacker might employ Windows vulnerabilities to take over those ma- chinesfromSERVO,leadingtocompromiseofallcountymachines. §7.4SubvertingalltheDevicesinaCounty 78 CHAPTER 8 Detection and Recovery BecauseeachvoteintheHartsystemproducesrecordsinanumberoflocations,inprinciplemany ofthelesscompleteattackscanbedetectedandinsomecasesrepaired. Forinstancethevotein- jectionattackdescribedinSection7.2.2changestheaggregatevotecount,whichcouldbedetected simply by comparing the number of voters reported by a precinct against the number of votes reported by the precinct’s voting machines. However, the extent to which the measures that are availableareactuallyusedisunclearandmayvarydramatically. Thelistofpotentialindependentrecordswhichshouldbereconcilableincludes,fortheeScan: • Thevoterbookindicatingthenumberofvoterswhovoted. • Thenumberofpaperballotsissued • TheactualpaperballotsprocessedbytheeScan • TheeScan’sMBB • TheeScaninternallogs AndfortheDREsystemincludes: • Thevoterbookindicatingthenumberofvoterswhovoted. • TheJBCrecordsofthenumberofissuedvotercodes(DREonly) • TheJBC’sMBB • TheJBC’sinternallogs • TheeSlate’sinternallogs • TheVVPAT In principle, any inconsistency between any of these records can be detected and potentially cor- rected. Inpractice,inconsistenciescanbedifficulttodetect. 8.1 Detection Inthissectionweconsidermethodsofdetectingdiscrepancies. Inthenextweconsidermethodsof recovery. 79 8. DetectionandRecovery 8.1.1 TheOnePercentManualRecount Californiaelectionlawrequiresthatonepercentoftheballotsbemanuallyrecounted. Inthecase ofeScanorBallotNowcentrallycountedballots,thismeansmanuallyassessingeachopscanballot andcomparingthecountagainstthatreportedbytheopticalscanner. InthecaseofDREvotingit meanscomparingtheVVPATagainsttherecordsfromtheJBC’sMBB.Notethatwhileinprinciple theopscantallymaydifferslightlyfromthepaperballotsduetovariationinthesensitivityofthe mark/sensescanner,theVVPATrecordsshouldexactlymatchtheDRErecords. The effectiveness of the one percent recount is strongly dependent on how discrepancies are treated. Thereareatleastthreeplausiblepossibilities: • Treatthemanualresultsasthecorrectresultsanddiscardtheelectronicresults. • Investigatetheprecinctwheretheerrorsoccurred. • Doaninvestigationorarecountofalargerfractionofthevotes,escalatinguptoafullpaper recount. It appears that in at least some counties the first option is taken [1]. While this is potentially suf- ficienttodetectcheatingbytheprecinctvotingequipment,itislikelytobeinsufficienttorecover fromitoutsidetheprecinctswhichareactuallyrecounted. Consideranattackerwhoincreasesthe vote count for his candidate by 5% in 25% of precincts. Such an attacker has a .25 probability of havingoneofhisprecinctsaudited,butifthecheatingintheotherprecinctsremainsundetected,he willhavechangedthevotetotalsbynearly1.24%,havinglostonlyasmallfractionofhisinfluence fromtherecount. The other extreme is to take the 1% recount as a tripwire and follow up any discrepancies by escalatingtoamoresignificantrecount,possiblyuptoacompletemanualrecount.1 Thedifficultyis indecidinghowsensitivethetripwireandhowaggressivetheescalationshouldbe. Ifevenminor discrepancies trigger full manual recounts, it is fairly easy for an attacker with limited resources to force the county into a full recount some reasonable fraction of the time. Moreover, strategies which are effective in detecting fraud are also susceptible to being forced into full recounts. It should also be noted that attacks that produce discrepancies are generally easier to mount than those that do not—much of our effort went into figuring out how to conduct attacks that leave behindnoinconsistencies. Notethatintheopticalscancase,escalationissubstantiallyeasier:theballotssimplyneedtobe recountedwithascannerwhichistrustednottohavebeencompromised. Thisisinconvenientbut farlessinconvenientthanaDRErecount,whichrequiresmanualrecountingofthehuman-readable portionoftheVVPAT—thebarcodecannotbetrustedforthispurpose. Onemightimaginedoing opticalcharacterrecognitionoftheVVPAT,butthisisamuchmorecomplicatedproblem. Asfar asweknow,toolsforthisjobarenotpresentlycommerciallyavailable. 8.1.2 TotalVoterCounts Attackswhichsimplyinjectfalsevotesareinprinciplesusceptibletosimplycomparingthenumber of voters to the number of electronically recorded votes. In both the optical scan and DRE cases, thereisaphysicalrecordofthenumberofvoterswhosignedintothepools.InthecaseoftheeScan, one could count the actual number of paper ballots used. None of these records are susceptible to electronic tampering2 and they can therefore be used to detect vote injection, provided that thesecomparisonsareactuallydone. Wedonotknowhowregularlytheyareperformedorwhat the results of discrepancies are—as we expect that small-digit numbers of discrepancies will be common. Again, treating small discrepancies as a trigger for a recount creates an opening for a denialofserviceattack. 1Appel[3]providesagooddescriptionofthestatisticshere. 2Ifelectronicpollbooksareinuse,theymayalsobesubjecttoattack. §8.1Detection 80 8. DetectionandRecovery 8.1.3 MechanicalLogComparisons Wenotethatseveraloftheattackswedescribehereproducedistinctivesignaturesontheelectronic logs produced in the various components. For instance, the eSlate vote injection attacks produce more votes in the MBB than the number of access codes issued to voters. Careful comparison of theMBBandtheJBCaccesscoderecordswouldrevealthis. InprincipleSERVOprovidesreports thatwouldallowanauditortomakethesecomparisons,however,wedidnotseeanyevidenceit woulddosoautomatically. 8.1.4 TamperSeals Finally, wemaynothaveanyevidenceofactualcheatingotherthanthatatampersealisbroken. This is obviously a reason to suspect that the sealed device has been tampered with, but it could also be a case where the seal was mishandled in some way. Determining which has happened is a difficult problem. In the case of all three of the polling place devices, an attacker with physical accesscancompletelyreprogramthedeviceinawaythatrequiresextensiveforensicstoverify,as discussedinSection8.1.6. Theconverseofhowtorespondtocasesoftamperedsealsisthequestionofhoweffectivesuch sealsare. Anumberofdifferenttypesofseals(plastic,wire,tape,etc.) areinuseinCalifornia,and wehavenotmadeanysystematicinvestigationofthem;however,Johnston[22]reportssuccessful and straightforward attacks on seals of the general type used in California elections. Therefore wemustconsiderthepossibilitythatsealscanbebrokenwithoutanyobvioussignsoftampering, especiallywithminimallytrainedpollworkers. SeeSection3.5formoreonthispoint. 8.1.5 ParallelTestingandLogicandAccuracyTesting One natural way to detect whether systems have been compromised is to test them to determine whether they are behaving correctly. Parallel testing involves selecting a random sample of DRE machines, takingthemaside, andrunningamockelectiononElectionDayusingtheequipment. By preparing a known voting slate, one can compare the results from those machines against the inputs that mock voters entered. Typically, parallel tests are videotaped so that it is possible to gobackandreviewanydiscrepancies. ParalleltestsareonewaytodetectbugsormaliceinDRE software, if the faulty software is widespread enough that the random sample is likely to pick at least one DRE that exhibits incorrect behavior. It is natural to wonder whether parallel testing mightprovideawaytodetectlarge-scaleviralattacks. Thereliabilityofparalleltestingatdetectingmaliciouscodeappearstobeopentodebate. The effectiveness of parallel testing is heavily dependent upon the details of how the testing is done. Ifmalicioussoftwarecandistinguishwhenitisbeingtestedfromnormaloperations,forinstance bylookingformistakesthatinexperiencedvoterswouldmakebutofficialsperformingtestswould not, then the malicious software can evade detection by behaving correctly when it is under test. Analysisoftheeffectivenessofparalleltestingpracticeswasoutsideofthescopeofthisstudy. Ultimately, parallel testing becomes an arms race between attack designers and officials who plan realistic parallel tests. The defenders attempt to design testing procedures that mimic real electionsascloselyaspossible,whilewemustassumetheattackerswilltrytodesignmethodsto detectwhentheyarebeingtested. Itisnotclearwhohastheadvantageinthisrace. Theproblem with thiskind of arms race is that it is difficult to know whetherone is winning. Thus, there is a risk that an attacker might develop a secret way to defeat parallel testing, leaving the defenders withafalsesenseofsecurityaboutelectionintegrity. Anotherwaytothwartparalleltestingwouldbetouseasecretknock(aseriesofinputsknown onlytotheattackerthatwouldbeunlikelytohappenbychance)tocontrolactivationofthevote- stealing code. A secret knock could be used to activate the virus, though this would require the virus author to have conspirators who would need to access each of the voting machines where votes would be stolen. Alternatively, a secret knock might serve to deactivate the vote-stealing code,thoughthiswouldrequirethehelpofaninsiderintheparalleltestingprocess. §8.1Detection 81 8. DetectionandRecovery ParalleltestingonlydefendsagainstmalicioussoftwareontheDREsystem(eSlatesandJBCs). Itdoesnotdefendagainstmalicioussoftwareatcountyheadquarters. Paralleltestingismoreeffectiveatdetectingattacksthanatpreventingthemfromdisruptingthe election.Supposetestingrevealsthatasmallnumberofvotesarerecordedforthewrongcandidate. Ifthetestisconductedonorclosetoelectionday,theremaynotbeenoughtimetodeterminethe cause. Asdescribedbelow,itmaybedifficultorimpossibletodeterminethecorrectvotetotalsif attackcodeisrunningonthemachinesonelectionday. Denialofserviceattackspresentaneven harder challenge. Officials have few recovery options if they discover shortly before the election thatthemachineswillfailthenexttimetheyareused,andparalleltestingonelectiondayprovides nowarningofsuchafailure. Finally,unlessparalleltestingisperformedonaverylargenumberofmachines,itwillhavea lowprobabilityofuncoveringattacksthataredirectedonlyatspecificprecinctsorelectioncondi- tions. Othermitigationstrategiesmustbeappliedtocontroltheserisks. All in all, it is difficult to predict with any degree of certainty how effective parallel testing willbe. Wewouldpreferadefensethatwecanbeconfidentwilldetectproblemsoveronewhose efficacyisopentodebate.Despitetheselimitations,paralleltestingmaystillhavevalueatdetecting viral attacks. And, of course, we do not deny that parallel testing may have other benefits that are outside the scope of this study. We leave it to others to analyze the cost-effectiveness and appropriatenessofparalleltesting. 8.1.6 FirmwareForensics Incaseswhereaunitissuspectedofhavingbeentampered,itisnaturaltoattemptforensicexami- nationoftheunitinordertodeterminewhetheritisrunningthecorrectfirmware.Aswediscussed inSection6.3,Hartprovidestechniquesforrunningthesechecksremotelybuttheyareineffective. Theonlyplausibletechniqueforrunningsuchforensiccheckswouldbetodirectlyexaminethe memory cards on the device, thus bypassing the potentially compromised software. However, a clever attacker could defeat such checks as well. The approach would be to retain a copy of the original firmware. When the “close elections” routine is run, the compromised firmware would scrub itself off of permanent storage and then restore the original firmware. This would defeat evenfairlysophisticatedforensictechniques. Acountermeasuretothisattackistosetasidearandomsampleofdevicesbeforetheelection sothatanyattacksoftwarepresentwillbepreservedforanalysis.Notethatthistechniquedoesnot detectmalwareinstalledonElectionDay. 8.2 Recovery As noted above, recovering from a clear discrepancy with an optical scan system is straightfor- ward: rescanwithanewscanner. eScanMBBcompromisescanpotentiallyberecoveredsimplyby auditingtheeScandirectly,althoughitisn’tnecessarilystraightforwardtodeterminewhichofthe twoiswrong. Recovering from DRE compromises will be more complicated. If the VVPAT doesn’t match the electronic records, then it is natural (and perhaps legally required) to use the VVPAT as the definitiverecord—althoughittoomayinfactbeincorrect. However,iftheymatch,theproblemis moredifficult. Thechoicesareeffectivelytoabandonandreruntheelectionortotrytoforensically determinewhatreallyhappened. Theforensicsoptionisproblematicintworespects. First,itstartsfromthepremisethatthesys- temisunderattackfromanattackerwithlimitedcapabilitieswhoforsomereasoncannotcontrol allelectronicrecords.Inconsistenciesareevidenceofhislackofcontroloveroneortheotherdevice andsoreconstructingtherealhistoryisamatteroffiguringoutwhichdevicewascompromised. Thisisadifficultpropositionandbearswithittheinherentriskofidentifyingtheuncompromised deviceascompromisedandthereforeacceptingthebogussetofresultsratherthantherealones. §8.2Recovery 82 8. DetectionandRecovery Thisriskisenhancediftheforensicproceduresarepublishedinadvanceandtheattackertherefore hasanopportunitytotunehisattacktocounterthem. Thesecond issueis thatsucha forensicinvestigationdepends onmaintainingmore extensive andtamper-resistantrecordswhichtendtocompromisethesecrecyoftheballot. Toconsidertwo examplesfromthecurrentsystem: • TheVVPATisdesignedtobetamperresistantbutinherentlyprovidesalinearrecordofallof thevotes. Thisrecordcanbeeasilymappedtovotercodes(cf.Issue35). • In Issue 25 we observed that the votes are stored on the MBB in a way that allows recon- structingthevotercode–CVRmapping. Thisrepresentsaballotsecrecyissuebutisalsokey toallowingrecoveryfromtheattackdescribedinSection7.2.2. One can imagine even more aggressive record keeping measures, such as a separate hardware- basedtamper-resistantrecordofeverypieceofuserinput. Thiswouldofcourseallowmuchbetter recovery, but at the expense of severely compromising ballot secrecy if an attacker obtained the record. Thus,thereisaninherenttensionbetweentheabilitytorecoverfromcompromiseandthe secrecy of the ballot. It may not be possible to recover from any significant attacks purely on the basisofelectronicrecords. Thisisnottosay,however,thattheHartsystemrepresentsanoptimaltrade-offinthatdesign space,asithasbothissueswithballotsecrecyandminimalrecoverycapabilities. §8.2Recovery 83 CHAPTER 9 Recommendations for Future Analysis Themajordifficultieswefacedinthisworkwere: • Sharplylimitedtime • Inadequateinformationaboutprocedures • Insufficientaccesstomaterials • Difficultyintestinghypothesesaboutsystemoperation 9.1 Time Limitation Although the project started May 31, the delivery of the Hart source code was delayed. We first obtainedthesourcecodecodeonMondayJune18. Thisleftuswithjustoveramonthtoperform our analysis and complete our report, which was due July 20. This timeline was extremely tight andforcedustostrictlytriageourinvestigation. Inparticular,theshorttimecombinedwiththecoordinationdifficultiesdescribedinSection9.4 preventedusfromverifyingmostoftheissueswediscoveredinthecode. Thisisextremelyprob- lematicandshouldbeamajorfocusofanyadditionaleffort. AsexplainedinSection2,itisunrealistictobelievethatanyprojectofthistypewillproducean exhaustiveauditofallthevulnerabilitiesinasystem;webelievethatasignificantlymorethorough jobcouldhavebeendonewithmoretime. We recommend that future projects provide the teams with at least three months to complete theirwork. 9.2 Inadequate Information about Procedures The impact of anumber ofthe issueswe discovereddepends significantly on theprocedures fol- lowedinactualuseofthesystem. Forinstance,RallyandTallyclearlyhavethecapabilitytocom- municateresultsviatheInternetormodem;however,theextenttowhichthiscapabilityisusedin California—ifatall—isstilluncleartous. Itappearsthatmanyoftheproceduresvarysubstantiallybetweencounties,butweweregen- erallyinstructedthattheseprocedureswereoutofscope.1 Thismadeitveryhardtoassesswhich issuesweremostimportantandtofocustheappropriateamountofattentionaccordingly. Thislackofinformationaboutproceduresextendstoordinaryelectionprocedures. Werecom- mend that in the future teams be allowed to observe a real election using the chosen equipment 1WewereabletodirectlyobtainsomeanswersaboutproceduresinYoloCounty.WeappreciatetheassistanceofFreddie OakleyandTomStanionis. 84 9. RecommendationsforFutureAnalysis andthattheyhavedirectaccesstovendorrepresentativesandcountyelectionofficialstoanswer questionsaboutprocedures. 9.3 Insufficient Access to Materials This project was significantly hampered by incomplete materials. Materials we were missing in- clude: • Detailedspecificationsforthenetworkprotocolsusedbythesystem.2 • ThetoolingthatHartusestoupgradefirmwareontheirowndevices. • Aworkingbuildenvironmentthatwouldhaveallowedustobuildourownbinaryversions oftheHartsoftware.3 • Source code for significant portions of the system, such as the embedded MQX real-time operatingsystemusedbyeSlateandJBC.ItisourunderstandingthatHartownsandcontrols MQX[7]. • Windowssystemsconfiguredwiththeback-endHartapplicationsastheyshouldbeconfig- uredinagenuineelectionenvironment. Lackofaccesstobuildenvironmentswasparticularlyproblematicforanumberofreasons: • Readingsourcecodeisgenerallyafairlyinefficientmethodfordetermininghowaprogram works.Runningit,especiallyunderadebugger,ismoreconvenient,butonlyifyoucanbuild yourownbinariessoyoucandosourceratherthanbinarydebugging. • Anumberoftheissueswediscoveredinvolveddetailedmemoryexploitswhichwouldhave beeneasiertoinvestigatehadwehadbeenabletotobuildourownversionsofthesoftware. Eventuallywewereabletoacquireacopyofthebinariesandresortedtobinarylevelanalysis. • A number of our testing and attack tools required imitating one Hart component talking to another. Incaseswherethisdidnotworkitwasverydifficulttodiscoverwherethebugin our code was because the Hart component would generally just be silent. Were we able to buildourownbinariesandrunthemunderadebuggerwequicklywouldhavebeenableto determinetheissue. Inaddition,wecouldhaveusedtheHartsystemasabasisforourown tools,thusgreatlyreducingtherequiredeffortlevel. • SourcecodeanalysistoolslikeFortifySCAaredesignedtoprocessthecodeinthesamebuild environmentsthatthecompilerdoes. Inordertousethesetoolsatallwehadtomockupour ownbuildenvironments,whichwastimeconsumingandmaynothavebeenrepresentative oftherealenvironment. Inaddition,wewerenotabletodothisforallthecomponentsofthe Hartsystem. Someofourquestionsaboutthesystemstillremainunansweredduetolackoftheabilitytobuild ourownbinaries. We recommend that any future projects require that the teams be supplied with a full vendor developmentenvironmentaswellasalltoolsusedbythevendorformaintenance,eveniftheyare notsuppliedtoordinarycustomers. 2WefinallyreceivedasmallportionofthistheweekofJuly1st,butmostofourunderstandingcamefromreviewingthe source. 3WeunderstandthatthetoolingwerefinallysenttotheSecretaryofStateonJuly18,despiteourearlierrequestsfor theseresources.AsofthecompletionofthisreportonJuly20th,wehavenotreceivedthem. §9.3InsufficientAccesstoMaterials 85 9. RecommendationsforFutureAnalysis 9.4 Difficulty in Testing Hypotheses about System Operation Workoneachsystemunderstudywasdividedbetweenthreeteams: • Adocumentationteam • Asourcecodeteam • A“RedTeam”responsiblefortryingattacks FortheHartsystem,thedocumentationteamwaslocatedinBerkeley,thesourceteaminMenlo Park, and the Red Team in Sacramento. The geographical separation plus the necessary security restrictions made it very difficult to transfer information among the three teams. For example, when we wished to transfer our attack tools to and from Sacramento, they had to be encrypted, burnedontoaCD-ROMandshipped,withthekeytransferredviatelephone. This,plustheordi- narydifficultyofknowledgetransferacrossgeographicallyseparatedteams,unavoidablycreated significantdelaysintestinghypothesesaboutpotentialissues. Werecommendthatinthefuturetherebeoneteamwhichisresponsibleforbothanalysisofthe sourceandmountingattacksandthatalltheworkbedoneinasinglelocationwithaccesstoboth thesourceandthehardware. Thiswouldallowamuchtighterfeedbackloopbetweenhypothesis andtestandwouldaccelerateprogress. §9.4DifficultyinTestingHypothesesaboutSystemOperation 86 CHAPTER 10 Summary of Findings Althoughwehadonlylimitedtimetoreviewthesourcecodeofthesystem,ourreviewneverthe- less uncovered what we believe to be a number of significant security issues. In many cases the Hartsystemdoesnotincorporatedefense-in-depthprinciples,whichmayallowindividualattacks tobeescalateduptomuchbroaderattacks. The Hart software and devices appear to be susceptible to a variety of attacks which would allowanattackertogaincontrolofsomeorallofthesystemsinacounty: • The Hart eScan, eSlate, and JBC devices incorporate an unsecured management capability. WebelievethatgivenbriefphysicalaccesstoaneScan,eSlate,orJBCdevice,anattackercan subvertitandoverwritetheexistingsoftwarewithmalicioussoftwareofhischoice. • Theseattackscouldbemountedbyapollworkerorpossiblybyavoterwhileintheprocess ofvoting. Theeffectsofsuchanattackareessentiallypermanent;oncemalicioussoftwareis loadedontosuchadevice,thereisnorealisticwaytoremoveit. • Subversionofsinglepollingplacedevicescanbeusedtomountavarietyofvoteforgeryand ballotstuffingattacks. • ThemechanismsprovidedbyHartfordetectingdevicesubversionappeartobeeasytoby- passandthereforesystemsubversionislikelytogoundetected. • The Hart back-end SERVO software contains multiple buffer overflows which appear to be remotely exploitable by a single compromised polling place device. We have exploited one of these in our test environment and used it to install software of our choice on the SERVO machine. Bycombiningtheaboveattacks, amaliciouspollworkercouldsubvertaneScan, throughthat SERVO,andthroughSERVOallthemachinesinthecountyforthenextelection. Wehavetested what we believe to be the essential elements of this attack but not performed an end-to-end test. Furthermore, a malicious voter could subvert a single eSlate, through that SERVO, and through SERVO all the machines in a county for the next election. We have tested some but not all of the elementsofthisattack. Beyonddirectsystemcompromise,wefoundthatHart’smanagementofballotandvotedatais vulnerabletoseveralattacks: • Hart’scryptographickeymanagementrequiresacounty-widesymmetrickeywhichisstored onvulnerablefielddevices.Thiskeycanbeobtainedbyanattackerwithbriefphysicalaccess toaneScanorJBC. • Compromiseofthissinglekeywouldallowanattackertoforgebothballotinformationand voteresults. • Wefoundmultipleavenuesforcompromisingvoterprivacy,enablingbothvotebuying/coercion andwholesaleinformationgatheringattacks. 87 10. SummaryofFindings This list does not include all the issues discovered during our review and there may be other issuesthatwouldbeuncoveredwithfurtherreview. WeencouragetheSecretaryofStatetounder- takesuchareview. WestressthatduetolimitedtimeandaccesstoHartequipment,wedidnotattempttovalidate all of the above issues. In the body of the report we clearly indicate the validation status of each issue. WeencouragetheSecretaryofStateandHarttoattemptsuchvalidation. Some of these issues can be mitigated with stricter polling place procedures. Others may be repaired with minor modifications to Hart’s systems, while yet others may require significant re- design. Providingacompleteassessmentofmitigationstrategieswasoutofscopeofthisreview, butweencouragetheHartandtheSecretaryofStatetostudytheseissues. We have deliberately avoided addressing the broader issue of whether or how this system should be used for voting in California. Making that judgement requires assessing not only the technicalissuesdescribedinthisreportbutalsotheproceduresandpolicieswithwhichthesystem isused. 88 Bibliography [1] Judy Alter. Report on the 1% manual recount for special election, Nov. 2005 L.A. County, July 2006. http://www.bbvforums.org/forums/messages/2197/Manual recount report-33060.doc. [2] Anonymous. Once upon a free(). Phrack Magazine, 57(9), August 2001. http://www. phrack.org/archives/57/p57-0x09. [3] AndrewW.Appel.Effectiveauditpolicyforvoter-verifiedpaperballotsinNewJersey,March 2007. http://www.cs.princeton.edu/∼appel/papers/appel-nj-audits.pdf. [4] Brad Arkin. Securing the eSlate Electronic Voting System: Application Security Imple- mentation,January2005. http://www.hartic.com/files/HART SYMANTEC SECURITY REPORT White Paper.pdf. [5] MihirBellare,RanCanetti,andHugoKrawczyk. Keyinghashfunctionsformessageauthen- tication. InNealKoblitz,editor,ProceedingsofCrypto1996,volume1109ofLNCS,pages1–15. Springer-Verlag,August1996. [6] blexim. Basic integer overflows. Phrack Magazine, 60(10), December 2002. http://www. phrack.org/archives/60/p60-0x0a.txt. [7] Compuware Corporation, Columbus, OH. Direct Recording Electronic (DRE) Technical Se- curity Assessment Report, November 2003. http://www.sos.state.oh.us/sos/hava/ compuware112103.pdf. [8] Tim Dierks and Eric Rescorla. The transport layer security (TLS) protocol version 1.1. RFC 4346,April2006. http://www.ietf.org/rfc/rfc4346.txt. [9] Electronics Industry Association. Electrical Characteristics of Generators and Receivers for Use in Balanced Digital Multipoint Systems (ANSI/TIA/EIA-485-A-98) (R2003). EIA-485, March1998. [10] Sarah P. Everett. The Usability of Electronic Voting Machines and How Votes Can Be Changed WithoutDetection. PhDthesis,RiceUniversity,2007. [11] ArielJ.Feldman,J.AlexHalderman,andEdwardW.Felten. SecurityanalysisoftheDiebold AccuVote-TS voting machine. In 2007 Usenix/ACCURATE Electronic Voting Technology Work- shop,Boston,MA,August2007. [12] RyanGardner, SujataGarera, andAvielD.Rubin. Onthedifficultyofvalidatingvotingma- chine software with software. In 2007 Usenix/ACCURATE Electronic Voting Technology Work- shop,Boston,MA,August2007. [13] geraandriq. Advancesinformatstringexploiting. PhrackMagazine,59(7),July2001. http: //www.phrack.org/archives/59/p59-0x07.txt. 89 BIBLIOGRAPHY [14] Rop Gonggrijp and Willem-Jan Hengeveld. Studying the Nedap/Groenendaal ES3B voting computer:Acomputersecurityperspective.In2007Usenix/ACCURATEElectronicVotingTech- nologyWorkshop,Boston,MA,August2007. [15] HartInterCivic.Judge’sBoothController(JBC)FunctionalSpecification,2005.Document6000-050, Rev.42-62B. [16] HartInterCivic. eSlatePollingPlaceSystemElectionDayDeskReference,2006. [17] HartInterCivic. HartVotingSystem,ProductDescription,System6.2,2006. Document6000-060, Rev.62A. [18] HartInterCivic. RallyOperationsManual,2006. Document6100-114,Rev.23-62A. [19] Hart InterCivic. System for Election Records and Verification of Operations, Operations Manual, 2006. Document6100-102,Rev.42-62B. [20] HartInterCivic. TallyOperationsManual,2006. Document6100-049,Rev.43-62B. [21] Hart InterCivic. Voting System Use Procedures for California, Hart Voting System 6.2, July 2006. PartNumber000255,Rev.C. [22] Roger G. Johnston. Tamper-indicating seals. American Scientist, 94:515–523, November- December 2006. Reprint available at http://ephemer.al.cl.cam.ac.uk/∼rja14/ johnson/newpapers/American%20Scientist%20(2006).pdf. [23] Michel Kaempf. Vudo malloc tricks. Phrack Magazine, 57(8), August 2001. http://www. phrack.org/archives/57/p57-0x08. [24] Burt Kaliski. PKCS #5: Password-based cryptography specification version 2.0. RFC 2898, September2000. http://www.ietf.org/rfc/rfc2898.txt. [25] John Marchesini, Sean Smith, Omen Wild, and Rich MacDonald. Experimenting with TCPA/TCG Hardware, Or: How I Learned to Stop Worrying and Love The Bear. Technical ReportTR2003-476,DepartmentofComputerScience,DartmouthCollege,December2003. [26] Elliot Proebstel, Sean Riddle, Francis Hsu, Justin Cummins, Freddie Oakley, Tom Stanionis, andMattBishop. AnanalysisoftheHartInterCivicDAUeSlate. In2007Usenix/ACCURATE ElectronicVotingTechnologyWorkshop,Boston,MA,August2007. [27] DavidRohde.Onnewvotingmachine,thesameoldfraud.TheNewYorkTimes,April27,2004. http://www.nytimes.com/2004/04/27/international/asia/27indi.html. [28] Aviel D. Rubin. My day at the polls – Maryland primary ’06, September 2006. http:// avi-rubin.blogspot.com/2006/09/my-day-at-polls-maryland-primary-06. html. [29] StuartSchechter,RachnaDhamija,AndyOzment,andIanFischer.Theemperor’snewsecurity indicators. In Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, May 2007. [30] Arvind Seshadri, Mark Luk, Elaine Shi, Adrian Perrig, Leendert van Doorn, and Pradeep Khosla. Pioneer: Verifyingintegrityandguaranteeingexecutionofcodeonlegacyplatforms. InProceedingsofACMSymposiumonOperatingSystemsPrinciples(SOSP),pages1–15,October 2005. [31] Michael Shamos. Oral testimony, Technical Guidelines Development Committee (TGDC), public data gathering hearings, September 2004. http://vote.nist.gov/ PublicHearings/9-20-94%20Panel%202%20SHAMOS.doc. BIBLIOGRAPHY 90 BIBLIOGRAPHY [32] Michael Steil. 17 mistakes Microsoft made in the Xbox security system. In Proceedings of the 22ndChaosCommunicationCongress,December2005. [33] TrustedComputingGroup. TPMv1.2SpecificationChanges,October2003. https://www. trustedcomputinggroup.org/downloads/TPM 1 2 Changes final.pdf. [34] AlmaWhittenandJ.D.Tygar. Whyjohnnycan’tencrypt: AusabilityevaluationofPGP5.0. InProceedingsofthe8thUSENIXSecuritySymposium,Washington,D.C.,August1999. BIBLIOGRAPHY 91 APPENDIX A System Components and Versions SourcecodeforthefollowingcomponentswassubmittedbyHartInterCivicforreview: • BallotNow,version3.3.11 • BOSS,version4.3.13 – BossUtil,version2.5.8 – TranslateDLL,version1.8.2 • eCMManager,version1.1.7 • eScan,version1.3.14 • eSlate,version4.2.13 • HartLib,version4.0 • JBC,version4.3.1 • Rally,version2.3.7 • SERVO,version4.2.10 • Tally,version4.3.10 • VBOPrinterFirmware,version1.8.3 Wedidnotreceivesourcecodeforthefollowingcomponents: • TheversionoftheembeddedMQXreal-timeoperatingsystemmaintainedbyHartforusein theeSlateandJBCdevices. • ThesoftwaretoolsthatHartusestoupgradefirmwareontheirdevices. BreakdownofthenumberofSourceLinesofCode(SLOC)percomponent: 92 A.SystemComponentsandVersions Component SLOC Language(s) BallotNow3.3.11 64K (C++) Boss4.3.13(excludingPowerBuildercode) 35K (C++) eCMManager1.1.7 2K (C++) eScan1.3.14 79K (C++,C) eSlate4.2.13 22K (C++) HartLib4.0 56K (C++,asm) JBC 23K (C++) Rally2.3.7 7K (C++) SERVO4.2.10 24K (C++) Tally4.3.10 52K (C++) VBOPrinterFirmware1.8.3 2K (C++) (total) 366K Table A.1: The number of non-blank, non-comment source lines of code in each voting system component,ascountedbyDavidWheeler’ssloccount2.26. Allnumbershavebeenroundedto thenearestthousandlinesofcode. 93