All bodies  ›  Office of Voting Systems Technology Assessment  ›  Consultant Report: Item 4A

OVSTA

Consultant Report: Item 4A

Hart System 3.4 (Prior Conditional Approval - September 17, 2004)

Office of Voting Systems Technology Assessment · vendors-hart-intercivic-091404-4a-c-redact · Document · Hart InterCivic

Read the report at Hart InterCivic ↗

Mr. John Mott-Smith 7 September 2004 Director of Voting Systems Office of the Secretary of State 1500 11th Street Sacramento, CA Subject: Certification of Hart InterCivic’s System Release 3.4. Executive Summary State certification testing was conducted 30-31 August 2004], at the California Secretary Of State, Election Division offices in Sacramento, CA, to certify the Sequoia Hart InterCivic System Rel. 3.4. This release incorporates changes to Ballot Origination Software System (BOSS) Version 3.5.4, Ballot Now (BN) Version 2.3.0, Precinct Voting System (PVS) Version 2.3.8, and Judges Booth Controller (JBC 1000) Version 2.3.8. The Ballot Now application was only tested in the Stand-Alone configuration. References: 1. [Wyle1] Wyle Report #50178-01, Change Release Report of the Hart InterCivic eSlate/JBC DRE Precinct Voting System Hardware (Firmware Release eSlate 2.0.13/JBC 2.2.1), 25 June 2004 2. [Wyle2] Wyle Report #50178-02, Change Release Report of the Hart InterCivic eSlate/JBC DRE Precinct Voting System Hardware (Firmware Release eSlate 2.3.8/JBC 2.3.8), 23 July 2004 3. [Ciber1] Ciber Report, Hart InterCivic Software Qualification Test Report Amendment 4 : 5-5-04 Ballot Now 2.3.0 : Hart System Version 3.3, 5 May 2004 4. [Ciber2] Ciber Report, Hart InterCivic Software Qualification Test Report Amendment 5 : 8-02-04 BOSS 3.5.4 : Hart System Version 3.4, 2 Aug 2004 5. [SVF031211] Steve Freeman, Report on the Certification Test for Hart InterCivic System 3.0, 11 Dec 2003. 6. [Hart/SOS] Hart, State of California Procedures Required for Use of eSlate Electronic Voting System, Rev. D, 9 Dec 2003 Introduction In compliance with California Elections Code 19200 and 19205, Diebold Election Systems applied for certification for the following revisions: 1. Hart InterCivic, System 3.4, NASED#: N-1-04-12-12-005 (1990), Date: 2 Aug 2004 a. Ballot Now 2.3.0 (System 3.3 change) b. Servo 2.0.10 c. BOSS 3.5.4 i. BossUtil (sub component of BOSS) 1.11.2* d. Rally 1.2.0 e. Tally 3.2.0 2. Precinct Voting System (PVS) Firmware consisting of: a. eSlate Firmware 2.3.8* b. JBC Firmware 2.3.8* (JBC also changed in System 3.3) The Hart InterCivic System was last certified in California on 11 Feb 2004 for System 3.2 with JBC 2.0.13. Although the changes in each release has been functionally relatively minor, a review of the ITA reports and state certification history indicated that integrated system testing verifying compatible operation between the BOSS/Ballot Now/Tally software components and the PVS hardware based DRE components has not been performed since System 3.0 in Dec 2003 (ref Page 1 of 8 [SVF031211]). The test schedule and setup would not allow a full system integration test but the test did touch major features, checked a range of reports required under the California Significant Change 1. BOSS a. Repaired audio data validation issue with respect to contest instructions, proposition texts, and ballot instructions. b. Added validation to Ballot Instruction interface to function the same way as other instruction texts behave, in that there must be an English string for Ballot Instructions if a Spanish string is defined. c. Other changes with no direct functional impact on California elections. 2. PVS a. Support for a barcode scanner used in issuing voter access codes. Supports a request from Orange County to improve poll worker conditions. b. Enhanced support for large ballots c. Other changes with no significant functional impact on California elections. Outstanding Issues from Prior Test 1. BOSS locks out update users if the administrative user logs in. This was considered not significant in the [SVF031211] report due to usage in most California client jurisdiction typically is run only at the administrative level. Greater concern about security access weaknesses which has developed over the last year makes this less acceptable. This problem has not been corrected in BOSS. 2. Ballot Now was reported as having a problem with a preview screen not correctly showing the Precinct identification. This has since been identified as a misunderstanding of the function for the preview screen which is previewing the ballot styles before the styles are assigned to precincts. This issue has been cleared. 3. If a race is positioned so that a write-in wraps around into the top of the next column of a ballot, the write-in is not recognized. BOSS prevents this from happening for the DRE; 4. The Ballot Now audit log did not report all reports requested. 5. The [Hart/SOS] procedures recommend passwords be eight characters or better and replaced before each election or every six months. The passwords resetting screens, however, allowed the passwords to be disabled (for the JBC) or reset to a new password with a zero length (‘empty’ or NULL password). 6. Additional, third-party software was noticed in the server/client environments in earlier testing. All third party software used and required by the system is expected to be identified or removed. Again, additional software was found Test Results The test election was based on the San Diego 2002 Primary and General with the addition of Presidential race (with semi-fictional candidates to complete the General election) in seven political parties. Three parties, American Independent, Democratic, and Republican, were defined as allowing DTS voter participation and reporting with the Republican DTS not permitting participation in Presidential nominations (See details in Attachment B). Only limited testing was done on the PVS to test the bar-code reader operation and provisional ballot resolution. Full counts were run using a pre-marked Logic and Accuracy deck to verify correct interpretation of all ballot logic variations. Audio ballots were not tested. . The new barcode reader is a simple commercial wand type bar code reader used to read barcodes imprinted on a list available to the poll worker. The barcode may be imprinted in the poll book next on the line with each registered voter indicating the eligible ballot selection or printed on a separate page which the poll worker can cross-reference. The barcode reader is connected to the Page 2 of 8 JBC and takes the place of searching through and finding the right precinct and, in a primary, party option to select the correct ballot for the voter. The barcode uses the commercial standard Code 39. The barcode reader was tested on seven different primary party choices involving three different parties, both declared and decline-to-state voter options, and split precincts. The test included trying to pass the barcode reader over the printed barcode strip in every direction with halts pauses and changed directions trying to confuse the reader. The reader either correctly read the value or reported no value if the code was not completely read. Procedures are needed for using and checking the barcode values in an actual election. Outstanding Issues from Test 1. Several additional programs and utilities were discovered or described during testing: a. ------ b. ---------------------------------------------------------- c. ------- d. ----------- e. C:\Program Files\Hart InterCivic\Shared. When these files were deleted after being identified as unused, access was hampered. They had to be replaced to continue operations.. This subdirectory contains license for Sybase SQL AnyWhere. 2. Ballot Now was only tested in the Stand-alone configuration. Prior to use in a jurisdiction of the networked configuration, a formal Acceptance test should be performed exercising multiple stations performing resolution tasks at the same time. 3. Ballot Now and Tally are allegedly installed in separate workstations with the operating system configured for “secure desktop”. This testing was conducted at a lesser level of security and may, therefore, not be complete. None of documentation provided described the criteria for a secure desktop. Future testing should, at least in part, be conducted in the operational configuration proposed for actual elections. 4. In BOSS, users assigned the View and Update roles were not able to print any reports which may be needed for system proofing. 5. The number of registered voters is ‘locked’ at the point the election definition is finalized for ballot printing. The Registration numbers and turn-out reports may not show correct values when initially producing the canvas directly from Tally due to late registrations. ------------------- --------------------------------------------------------------------------------------------- 6. A provisional DRE ballot can be resolved within the same precinct/style as it was submitted but can not be viewed for reproducing if the voter belongs to another district. Security Issues This release includes a proposal that each application would be placed in separate workstations with the workstation configured as a “secure” desktop. Otherwise, the security issues remain the same as in the [SVF031211] report. The documentation I reviewed does not specify how the desktops will be made more secure and the test environment for this session was inadequate to evaluate the effectiveness of that approach. Physical security limiting direct access is still the primary protection. . Conclusion Review and testing of this proposed configuration showed compliance with the California Election Code except for: a. provisional ballots on the DRE. The current practice of submitting all provisional as paper ballots would need to continue. b. the registered voter totals can not be updated within System 3.4 once the database is locked. Corrected voter turnout reports must be compiled outside of the certified system. Page 3 of 8 c. There is no single report for reporting aggregate totals and the separate break out totals for the decline to state and declared party members in a primary election. A report can be generated based on separate reports. Sincerely, Steven V. Freeman Two Attachments: A. Hardware Description with a list of the test configuration components. B. Test Election Design Page 4 of 8 Attachment A. Hardware Descriptions Hart InterCivic System 3.4 The election management system component subsystems consisting of BOSS, Ballot Now, Rally, and Tally may be placed in one or more server/workstations consisting of PC-compatible units supported with appropriate printers and peripherals. BOSS supports the election definition management and provides support for programming the eSlate PVS. It requires a MBB reader/writer as a peripheral as well as access to printer for various review and audit reports Ballot Now provides ballot-on-demand service and supports the scanning of the paper ballots. It requires TWAIN32 compatible high speed scanner and laser printer. Ballot Now can be configured in two configurations: Stand-alone or Networked. In the Stand-alone mode, all the Ballot Now processing is done on a single processor. In the Networked configuration, one or more Ballot Now workstations can be attached to the Ballot Now server for multiple resolution workstations. In addition to the high-speed scanner, Ballot Now requires access to a PCMCIA reader/writer (to read and write to the MBB) and a large enough hard drive to store the ballot images captured by the scanner. Rally supports reading the MBBs produced by the JBC and transferring the ballot images, called Cast Voter Records (CVRs) to the Tally subsystem. Rally requires access to a PCMCIA SmartCard Reader/Writer and a connection to the Tally subsystem. Tally receives all the CSV results from MBBs or from Rally and consolidates the ballot counts for final counting and voting result reporting. Tally requires access to a MBB SmartCard reader/writer and a printer. In the test configuration, these applications were split between two workstations: the BOSS/BallotNow/Tally server and the Rally/SERVO server. eSlate Precinct Voting System The Precinct Voting System (PVS) consists of a Judge’s Booth Controller (JBC) (pictured to the left) connected with an RS485 multipoint cable to 1 to 12 eSlate 3000 DREs. The JBC is operated by the poll worker to configure the DREs, install the election database, save the CVRs from each of the eSlates connected. When the ballot style (based on precinct or other attributes ) the voter is eligible has been determined, the poll worker enters the ballot style on the JBC and receives a one-time, time-limited access code which the voter then uses to get access to his or her ballot. The JBC and the eSlate are based on Motorola processor using a proprietary operating system. Page 5 of 8 Test Configuration 1. BOSS/Ballot Now/Tally a. Dell Latitude D800 Service Tag: 7QSK741 i. Intel Pentium M 1.6 GHz processor ii. 512 MByte main memory iii. 40 GByte hard drive iv. PCMCIA CardBus v. USB 2.0 Controller b. HP LaserJet 2300 c. Fuji 4097 Scanner d. Application Software i. C:\boss ii. C:\Program Files\Hart InterCivic e. COTS Software i. Windows 2000 Professional, Service Pack 4 ii. Windows Internet Explorer Rel. 6.0.2800 iii. Imaging for Windows Ver. 5.0.2138 iv. Seagate Software\Report Designer ?? v. Sybase Powerbuilder 6.5.0.444 vi. Symantec Anti-Virus 8.00 vii. WinZip 8.0 2. Rally/SERVO a. Dell Latitude D800 Service Tag: B351P31 i. Intel Pentium M 1.4 GHz processor ii. 512 MByte main memory iii. 30 GByte hard drive iv. PCMCIA CardBus b. COTS Software i. Windows 2000 Professional, Service Pack 4 ii. Windows Internet Explorer Rel. 6.0.2800 iii. Imaging for Windows Ver. 5.0.2138 iv. Seagate Software: Sybase PowerBuilder 6.5.0.444 v. Symantec Anti-Virus 8.00 vi. WinZip 8.0 3. Precinct Voting System 2.3.8 a. Judge’s Booth Controller 1000B S/N:C0113A b. eSlate 3000, S/N: A05B28 4. Hart InterCivic System 3.4 a. Directories: i. C:\Boss ii. C:\Program Files\Hart InterCivic\ 1) Ballot Now 2) \Rally 3) \SERVO 4) \Shared\(Sybase SQL Anywhere) 5) \Tally iii. C:\Program Files\Seagate Software iv. C:\WINNT 1) \Crystal 2) \PIXTRAN 3) \System32\(32 added/replaced files Page 6 of 8 Attachment B. Test Election Design Precinct 1 2 2 3 4 5 6 7 8 9 10 Type Split 1 2 SW Federal, STATE x x x x x x x x x x x SD Board of Equal 3 x x x x x x x x x x x SD CONGRESS 49 x x x SD CONGRESS 50 x x SD CONGRESS 51 x x SD CONGRESS 52 x x SD CONGRESS 53 x x SD STATE SENATE 36 x x SD STATE SENATE 37 x x SD STATE SENATE 38 x x SD STATE SENATE 39 x x SD STATE SENATE 40 x x x SD ASSEMBLY 66 x x SD ASSEMBLY 74 x x SD ASSEMBLY 75 x x x SD ASSEMBLY 76 x x SD ASSEMBLY 77 x x COUNTY, U Unincorporated x x C CHULA VISTA x C LEMON GROVE x R PORTER VISTA x S Measure x x x x x x x x x x x C city, M Military, R unincorporated remainder of county, U Unincorporated place in a county. Further details on test election makeup and The test election was modified from the San Diego by combining various districts and races into a selection of ten precincts which concisely included samples of state, statewide district (State Senate and Assembly Districts), judicial, (See Test Design Matrix above Testing was completed using a pre-marked Logic and Accuracy deck. The test deck was used to verify basic election definition and verify the rotation was set up correctly on the DRE units. Additional ballots were marked to test response to common voter errors and some ballot tampering changes. All altered ballots were identified and rejected for operator action. Primary ballots were cast, exercising the following ballot logic and conditions: Primary party ballots with DTS voting and reporting Non-Partisan races Split precinct Page 7 of 8 Vote for 2 of 5, Write-in votes (including potential over-vote conditions) Blank ballots Rotation based on assembly district at state, state districts, and local levels Multiple languages. Turn-out statistics on final summary reports Measures Polls open, close, and report printing. Consolidating absentee and Election Day precinct voting. Rally was used to pass forward results from multiple sources and SERVO was used to recover election data from the JBC and eSlate. Audio ballots were not tested. Page 8 of 8