All bodies  ›  Office of Voting Systems Technology Assessment  ›  Hart Verity Voting 3.0.1 Voting System Security and Telecommunications Supplemental Report

OVSTA

Hart Verity Voting 3.0.1 Voting System Security and Telecommunications Supplemental Report

Hart Verity Voting 3.0.1 Voting System

Office of Voting Systems Technology Assessment · vendors-hart-intercivic-verity-verity-sectel-supp · Testing report · Hart InterCivic

Read the report at Hart InterCivic ↗

California Secretary of State Consultant’s Report on: Functional Regression Testing, Supplemental Security and Telecommunications Testing of the Hart Verity 3.0.1 Voting System Prepared for the California Secretary of State by: Freeman, Craft, McGregor Group September 6, 2018 Revision history Version Change date Author(s) Changes to previous version 1.0 8-23-18 Paul Craft Initial Draft Craft, McGregor, Draft 1.1 9-3-18 Weingart and Bullock 1.2 9-6-18 McGregor and Craft Final Edits FCMG: Functional Regression and Supplemental Security Test Report Table of Contents Introduction and Background ..................................................................................................................... 4 Scope of Work and Reporting .................................................................................................................... 4 Description of System Submitted for Certification ................................................................................... 5 Approach to Testing ..................................................................................................................................... 5 Witnessed Build of Software and Creation of Trusted Install ......................................................... 5 Functional Regression Testing ........................................................................................................... 5 Supplemental Security Testing ........................................................................................................... 8 Functional Findings ...................................................................................................................................... 8 Supplemental Security Test Findings ........................................................................................................ 9 Attachment A – Inventory of Items Tested ............................................................................................. 13 Attachment B – Marginal Marks Ballot .................................................................................................... 15 Last update: 9/6/18 Status: Public Version: 1.2 Page 3 of 15 FCMG: Functional Regression and Supplemental Security Test Report Introduction and Background The Freeman, Craft, McGregor Group, (FCMG) and atsec information security corporation (atsec) conducted Security and Telecommunications Testing and Software Testing for the California Secretary of State (SOS) that found multiple vulnerabilities in the Hart InterCivic, Inc. (Hart) Verity 3.0 voting system (the system). In response to these findings, Hart modified the system to mitigate the vulnerabilities. Making such changes to a system submitted for certification warrants a change to the version number. Hart revised their application for certification to include their changes to the system and updated the version number to Verity 3.0.1. To verify the effectiveness of the changes and ensure that the changes did not degrade the system’s functionality, the SOS issued a work order to FCMG to conduct a Supplemental Security and Telecommunications Test, Supplemental Software Test and Functional Regression Test. Scope of Work and Reporting This report covers the work completed during the Functional Regression Test and Supplemental Security and Telecommunications Test. Narratives describing our initial Software Test and Security and Telecommunications Test are presented in separate reports. SOS staff conducted the initial Functional Test. We reviewed these test records prior to determining the scope of our Functional Regression Test. The results of the Supplemental Software Test are provided in a separate report. We are not attorneys and do not offer legal advice. We have assisted the SOS with collecting facts and evidence in order for them to make certification decisions. However, to advise the SOS on the determination of whether the system complies with California’s certification requirements would require an interpretation of law. Accordingly we do not provide recommendations or offer any opinion as to whether the system can be certified. The work we performed and our findings are strictly limited to the specific serial numbered hardware elements and specific software elements exercised during this test. An inventory of those items is included as Attachment A to this report. Last update: 9/6/18 Status: Public Version: 1.2 Page 4 of 15 FCMG: Functional Regression and Supplemental Security Test Report Description of System Submitted for Certification The Verity 3.0.1 voting system utilizes paper ballots. The system is comprised of a suite of software applications and hardware devices that provide end-to-end election management and operational functions. These functions include generating election definitions, creating ballot layout, programming voting devices, allowing voters to mark and cast ballots, collecting and consolidating tabulation data, reporting results and producing audit logs. The applications may be installed on a freestanding workstation or in client/server configurations. A complete description of the system may be found in our report titled “California Secretary of State Consultant’s Public Report on: Security and Telecommunications Testing of the Hart InterCivic Verity 3.0 Voting System,” pages 8 through 11. Approach to Testing Witnessed Build of Software and Creation of Trusted Install CA SOS provided the source code for the system and personnel from FCMG witnessed as the source code was compiled into the trusted build. When the build was complete, the source code was sent to atsec for source code analysis. Hart provided workstations that had been wiped of all previous programs. The operating system, supporting COTS utilities and the compiled system were installed on the workstation that would later become the Count/Server. An image of the newly built system was taken and installed on the remaining workstations. Next, each workstation was configured for its function. An image was taken of each workstation and server, and these images were filed with the SOS. Functional Regression Testing FCMG and SOS jointly managed the Functional Regression Test. Hart staff provided technical support and witnessed the test. The system was exercised by staging test elections in accordance with the California Use Procedures and documenting the results of those elections. The test elections staged during the Functional Regression Test were: A Primary election based on a Sacramento County election that included both precinct voting and a countywide vote center. Last update: 9/6/18 Status: Public Version: 1.2 Page 5 of 15 FCMG: Functional Regression and Supplemental Security Test Report A General election based on a Contra Costa County election. A Recall election. A Ranked Choice (RCV) election. The Primary election, based on the June 5, 2012 Sacramento Presidential Primary, was defined on the Data/Build Client and Server using manual data entry. FCMG modified the original election definition to include five polling places, a countywide, all poll early vote center and centrally counted absentee ballots. The election included ballots in English, Spanish and Chinese. All of the ballots were produced from the Data/Build application and reproduced on a COTS printer. The test decks were assembled and hand marked following a marking pattern developed by FCMG. In order to cast and record the ballots, the test decks were processed through Verity Scan devices and the Verity Central scanner. In order to test the functionality of the Verity Touch Writer, both the touch screen interface and the audio ballot were exercised to produce ballots in each of the three languages. Verity Reader was used to review a previously marked ballot, including audio and video output, in each of the three languages. Verity Print was used to simulate printing ballots on demand in a manner similar to that which would be used in either a polling place or vote center. Test decks were proofed against expected results during a simulated Logic and Accuracy (L&A) test. For any results that did not match, the results and decks were audited. All of the mismatches were found to be the result of mismarked ballots. These mismatches were handled by either correcting mismarked ballots or, in some cases, by modifying the expected results. When the L&A test was completed, the decks were rerun and re-tabulated on Verity Count to simulate an election. All reports were run and audited and the results matched the expected totals. The election was created and run following the California Use Procedures and no anomalies were encountered. The definition for the General election was based on the election held in Contra Costa County on November 6, 2012. We used the same election definition that Hart provided for the original functional test conducted by the SOS. The backup files for the test election were restored on the Data/Build Standalone, and modified to only use English language ballots. The election was structured to reflect how ballots are cast in precincts on Election Day and how absentee ballots are normally handled. Ballots were printed, hand marked and assembled into test decks. During this election the system’s ability to print marked ballots for use in test decks was exercised. However, only a small number of ballots were printed. When all of the ballots were marked, the expected results were determined by a hand count of the ballots. The test decks were run through two Verity Last update: 9/6/18 Status: Public Version: 1.2 Page 6 of 15 FCMG: Functional Regression and Supplemental Security Test Report Central devices and a Verity Scan in a simulated L&A test and the results were audited. The decks were put through the devices a second time and re-tabulated to simulate an election. Reports were run and the results were compared to the expected results. This election was created and run following the California Use Procedures and no anomalies were encountered. The Recall election was based on the October 7, 2003 California Gubernatorial Recall election. We used the same election definition that Hart had provided for the original functional test conducted by the SOS. The election used by the SOS was structured so a voter could only vote for a candidate if they voted “yes” on the recall question. The election definition was modified and that dependency was removed in order to make the test consistent with California law. It was modified further to allow votes to be cast for up to ninety candidates so the election could be used to test the system’s ability to consistently read marginal marks. As modified, this election tested the system’s capacity to handle a contest with one hundred thirty-five candidates, the hardware’s ability to read marginal marks and the consistency of the point at which marginal marks are not read. Three ballots were printed. One of the ballots was marked with a range of mark density using a variety of inks and a pencil. The ballot was scanned ten times on a Verity Scan and ten times on Verity Central. An image of the ballot can be found in Attachment B. The results were printed from both devices. Marks were read consistently at a mark density far below those recommended for use in an election. In addition, the point at which marks could not be read by either device was consistent. The definition for an RCV election used in the original functional test conducted by the SOS was loaded; ballots were printed, voted and tabulated. Ballots were also cast using a Verity Touch Writer. The Touch Writer is capable of warning the voter if they are about to under vote a race and can prevent both types of over votes. (Over votes in RCV can occur either when a voter assigns a candidate two different rankings or they assign the same ranking to two different candidates). The system does not perform RCV tabulation. Rather, it tabulates the number of votes for each candidate in each ranking and produces a “cast vote record” in an XML file for each ballot. This file shows the ranking assigned to each candidate and can be used either to tabulate the vote manually or to process the cast vote record through applications outside of the system. This election definition was created with no anomalies. Ballots were run through the Verity Scan and Verity Central devices and the results were tabulated on Verity Count. The cast vote files were audited against the cast ballots and found to match. The cast vote records were printed as reports and used to conduct a hand counted tabulation. Last update: 9/6/18 Status: Public Version: 1.2 Page 7 of 15 FCMG: Functional Regression and Supplemental Security Test Report Supplemental Security Testing The Supplemental Security Test was performed by FCMG consultants and witnessed by the representative from the CA SOS. Hart staff provided technical support and also witnessed the test. FCMG reviewed the updated Technical Data Package and change logs provided by Hart with respect to updates made in response to earlier security findings. For each of the previous findings it was determined whether the finding had been addressed, how it had been addressed and if the stated update met the requirements proscribed by the California Voting System Standards. The system was retested, both physically and logically, to verify that the updates had been applied and to confirm that the function and improvements performed as documented. Functional Findings Within the test, the system performed as described in the documentation with no tabulation or reporting errors. Despite the modifications to the system and subsequent change to the version number, when it was compared to the results recorded by the SOS in the initial functional test, we found no evidence that the system performance was degraded. There were a small number of errors found in the system documentation. The errors and suggested edits were provided to Hart and they were asked to make the necessary corrections and provide the revised documents to the SOS. The system does not perform RCV tabulation, but it creates a “cast vote record” XML file for each cast ballot. These files can be used to manually tabulate the results or incorporate other software products outside of the system to determine the results. The system’s RCV capabilities are limited. It allows a maximum of six candidates and one write-in for each RCV contest. There must be a ranking for each candidate and the system does not accommodate a multiple vote for RCV contest. Accordingly coding a RCV contest with three rankings and five candidates is not possible. The Verity Touch Writer device provides a warning to the voter prior to them under voting a race and prevents over votes on Primary, General, and RCV ballots. Last update: 9/6/18 Status: Public Version: 1.2 Page 8 of 15 FCMG: Functional Regression and Supplemental Security Test Report The system has been designed so a Verity Scan device cannot be cleared of counts or re-opened for tabulation after an election has been closed and the results printed. The only way results can be cleared is by removing the vDrive from the unit, taking it back to the Build application and re-writing it. As a result, after an L&A test is conducted on a Verity Scan device the vDrive used in that test must be replaced before the machine can be sealed and secured for use in the election. An additional security enhancement will lock out either a user or administrator account after three unsuccessful attempts to log into the system. In order to prevent an accidental lockout from interfering with the normal course of business, the California Use Procedures should include steps to establish a separate administrative account that is only used for such a contingency and that the password and the administrator ID for that account be kept in a highly secured area. Supplemental Security Test Findings Updated Security Findings The measures taken to ensure the physical security for the COTS PC cases used with the Verity Client, Server and Standalone have been revamped. A 4-dial combination lock was added to the cover of the rear case. In order to restrict access to the lock, an improved tamper evident label was wrapped around the hasp of the lock. A second of these labels was wrapped around the body of the lock to cover the combination dials. The hard disks, which were previously accessed via the front of the case, are now covered with a hard plastic bezel that is held in place by a metal bar anchored inside of the case and held secure by this lock. An identical lock with the same configuration of tamper evident labels is used on the rear case. These changes prevented access to the interior of the case and the components within. The seals on the Verity Scan with a ballot box, Verity Touch Writer and Verity Reader have been replaced with a wire seal and a heavy gauge plastic seal, both of which are serialized. These seals are far more complex and difficult to defeat, resulting in significant improvements to the overall physical security of the system. Full disk encryption via Bitlocker has been added to the Verity Client, Server and Standalone workstations but not on the Verity devices. The firewall configurations for the Verity Client and Server have been updated to require encryption on all incoming and outgoing connections. This resolves the vulnerability regarding server spoofing credential disclosure, as only machines with access to the Last update: 9/6/18 Status: Public Version: 1.2 Page 9 of 15 FCMG: Functional Regression and Supplemental Security Test Report private key for the Verity Server are able to negotiate IPSEC and communicate with the networked Verity systems. On Verity Server, any application that is not required to operate the voting system has been removed. This resolves the finding regarding the Unnecessary Applications Available. In order to increase its complexity and make it harder to break, the Verity password has been increased from six numeric characters to a minimum of eight alphanumeric characters. This remediates the issue, as it greatly increases the potential bruteforce time and/or computational power needed to guess the password. However, the appropriate solution to prevent bruteforce is to replace the use of a plain SHA256 as a Key-Derivation Function (KDF) and using a PBKDF instead, such as PBKDF2, SCRYPT, or ARGON. The serialization code used to transfer key material from the Verity Key devices has been enhanced and uses a more secure method that precludes any potential command execution. This completely remediates the instance identified in the finding regarding code execution via untrusted deserialization. During review of the fix, additional instances of the vulnerable BinaryFormatter serialization class were found referenced within the code. While they may be vulnerable to code execution, it is unlikely that they are exploitable. These instances were not reviewed, and Hart should analyze the code and work towards implementing any serialization using BinaryFormatter with a secure alternative. The finding regarding shared secrets remains open. Changing the configuration of each deployed system will mitigate this issue, however; it will increase the difficulty of providing support to users. The best short-term solution is to implement procedures to ensure the Verity Keys are not lost and to have a plan in place if a Verity Key or Verity Device is stolen. Last update: 9/6/18 Status: Public Version: 1.2 Page 10 of 15 FCMG: Functional Regression and Supplemental Security Test Report The following table summarizes the original findings, Hart’s mitigations and our supplemental findings. Original Finding Description Mitigation Reported by Hart Supplemental Findings Locks and tamper seals are Physical security has been As described above, subject to picking and revamped to include new, workstation cases have removal more effective, locks and been modified and new, seals. more effective, locks and tamper evident labels applied. The Verity devices, including the door that provides access to the cFast drive in the tablet, and ballot boxes have new seals that have been tested and are effective. Unrestricted access to Physical security applied to As described above, workstation cases workstation cases. workstation cases have been modified and new, more effective locks, a bezel to restrict access to the hard disks, and improved tamper evident labels have been applied. Lack of Full Disk Encryption BitLocker added to Verified on Client/Server workstation O/S image. and Freestanding BitLocker whole disk Workstations. encryption mode (AES-128) Not implemented on Verity enabled. Print, Scan, Reader and Touch Writer devices. Server Spoofing Credential Firewall configuration Verified. Disclosure allowed by lack settings updated. of authentication on outgoing connections. Last update: 9/6/18 Status: Public Version: 1.2 Page 11 of 15 FCMG: Functional Regression and Supplemental Security Test Report Original Finding Description Mitigation Reported by Hart Supplemental Findings Shared Static Secrets Procedural Recommend procedures to ensure that the Verity Keys are not lost and a plan in place for the event that a Verity Key or Device is stolen. Unnecessary Applications The applications have been Verified. Available on System removed. Weak Authentication The device password for Verified. Encryption for Verity Key Verity Key is now required to be 8-10 alphanumeric allowed unauthorized characters. modification of election results Code Execution via Verity Key security has Verified. Untrusted Deserialization been increased by updating how the data on the Verity Key is written and read. Last update: 9/6/18 Status: Public Version: 1.2 Page 12 of 15 FCMG: Functional Regression and Supplemental Security Test Report Attachment A – Inventory of Items Tested Verity 3.0.1 Inventory Device Manufacturer Serial Number Verity Devices Verity Touch Writer Hart InterCivic W1701426111 Verity Print Hart InterCivic P1701428611 Verity Scan Hart InterCivic S1701422011 Verity Scan Hart InterCivic S1701422311 Verity Reader Hart InterCivic R1701438712 Workstations Hewlett- HP Z240 Packard 2UA74526WM Count Client Hewlett- HP Z240 Packard 2UA74526WD Count Server Hewlett- HP Z240 Packard 2UA74526WR Count Standalone Hewlett- HP Z240 Packard 2UA74526WW Central Client Hewlett- HP Z240 Packard 2UA74526WV Central Standalone/Server Hewlett- HP Z240 Packard 2UA74222WS Data/Build Client Hewlett- HP Z240 Packard 2UA74526WZ Data/Build Server Hewlett- HP Z240 Packard 2UA74222WL Data/Build Standalone Monitors Hewlett- HP P232 Packard 6CM7250RSH Count Client Hewlett- HP P232 Packard 6CM7250RWB Count Server Hewlett- HP P232 Packard 6CM7250RWT Count Standalone Hewlett- HP P232 Packard 6CM7250RX8 Central Client Hewlett- HP P232 Packard 6CM7250SBG Central Standalone Hewlett- HP P232 Packard 6CM7130KPQ Data/Build Client Last update: 9/6/18 Status: Public Version: 1.2 Page 13 of 15 FCMG: Functional Regression and Supplemental Security Test Report Hewlett- HP P232 Packard 6CM7250RWD Data/Build Server Hewlett- HP P232 Packard 6CM7250RVX Data/Build Standalone Printers B432dn OKI Data AK77024680 Count Printer B432dn OKI Data AK77024674 Touch Writer Printer B432dn OKI Data AK77024670 Touch Writer Printer C831dn OKI Data AL31045014 Data/Build Printer Scanner DR-G1130 Canon GF301966 Client/Server Central Scanner DR-G1110 Canon GG307770 Standalone Central Scanner Network Switches Hewlett- HPE 1405 8G Packard CN71HZN2W0 Count Hewlett- HPE 1405 8G Packard CN71HZN2KM Central Hewlett- HPE 1405 8G Packard CN71HZN3N7 Data/Build Verity Software Application Name Manufacturer Version Verity Print Hart InterCivic 3.0.1 Verity Reader Hart InterCivic 3.0.1 Verity Scan Hart InterCivic 3.0.1 Verity Touch Writer Hart InterCivic 3.0.1 Verity Data Hart InterCivic 3.0.1 Verity Build Hart InterCivic 3.0.1 Verity Central Hart InterCivic 3.0.1 Verity Count Hart InterCivic 3.0.1 Last update: 9/6/18 Status: Public Version: 1.2 Page 14 of 15 FCMG: Functional Regression and Supplemental Security Test Report Attachment B – Marginal Marks Ballot Last update: 9/6/18 Status: Public Version: 1.2 Page 15 of 15