OVSTA
County of Los Angeles Vsap Tally 1.0 Staff Report
VSAP Tally Version 1.0
Read the report at Los Angeles County VSAP ↗
A P
LEX ADILLA | SECRETARY OF STATE | STATE OF CALIFORNIA
OFFICE OF VOTING SYSTEMS TECHNOLOGY ASSESSMENT
1500 11th Street | Sacramento, CA 95814 | Tel 916.695.1680 | Fax 916.653.4620 | www.sos.ca.gov
County of Los Angeles
Voting Solutions for All People (VSAP) Tally 1.0
Staff Report
Prepared by:
Secretary of State’s
Office of Voting Systems Technology Assessment
July 13, 2018
Table of Contents
I. Introduction ......................................................................................... 1
1. Scope ................................................................................... 1
2. Summary of the Application ................................................. 1
3. Contracting and Outsourcing ............................................... 1
II. Summary of the System .................................................................... 2
1. VSAP Tally System, v. 1.1.2.2 ............................................. 2
2. IBML ImageTrac Scanner, v. 6400 ....................................... 2
III. Testing Information and Results ........................................................ 2
1. Background .......................................................................... 2
2. Functional Testing Summary ............................................... 3
3. Software (Source Code) Testing Summary .......................... 5
4. Security and Telecommunications Testing Summary .......... 5
5. Volume Testing Summary .................................................... 18
IV. Compliance with State and Federal Laws and Regulations ............... 20
V. Conclusion .......................................................................................... 26
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 2 | Page
A P
LEX ADILLA | SECRETARY OF STATE | STATE OF CALIFORNIA
OFFICE OF VOTING SYSTEMS TECHNOLOGY ASSESSMENT
1500 11th Street | Sacramento, CA 95814 | Tel 916.695.1680 | Fax 916.653.4620 | www.sos.ca.gov
I. INTRODUCTION
1. Scope
This report presents the test results for all phases of the certification test of the
County of Los Angeles’ VSAP Tally 1.0. The purpose of the testing is to test the
compliance of the voting system with California and Federal laws, including the
California Voting System Standards (CVSS). Testing also uncovers other
findings, which do not constitute non-compliance, and those findings are reported
to the voting system vendor to address the issues procedurally. The procedures
for mitigating any additional findings are made to the documentation, specifically
the County of Los Angeles Use Procedures.
2. Summary of the Application
The County of Los Angeles submitted an application for the VSAP Tally 1.0
central tabulation system on September 19, 2017. The system is comprised of
the following major components:
Voting Solutions for All People (VSAP) Tally software, version 1.1.2.2;
IBML ImageTrac Scanner, version 6400
In addition to these two components, which includes the executable code and the
source code, the County of Los Angeles was required to submit the following: 1)
the technical documentation package (TDP); 2) all the hardware components to
including all peripheral devices needed for the Functional Test Phase the
Security and Telecommunications Test Phase; 3) and the VSAP Tally Blended
Use Procedures.
3. Contracting and Consulting
Upon receipt of a complete application, the Secretary of State released a
Request for Quote (RFQ) for assistance with the Software Testing (Source Code
Review) and Security and Telecommunications testing.
Through the formal California contracting process, the Secretary of State
awarded a contract to SLI Compliance (SLI), a division of Gaming Laboratories
International, LLC.
II. SUMMARY OF THE SYSTEM
The VSAP Tally 1.0 solution is solely used for scanning and tabulating ballots.
The intent of use for this iteration is to process vote by mail (VBM) ballots. The
system will be used in a blended environment, with the County of Los Angeles’
legacy system Microcomputer Tally System (MTS) version 1.3.1 using InkaVote
ballots, which will tabulate precinct ballots.
The system consists of two components:
1. Voting Solutions for All People (VSAP) Tally software, version 1.1.2.2
The VSAP Tally is a central tabulation software solution. The VSAP Tally system
as described in the Los Angeles County 2018 Blended Use Procedures is a
transition to scanning technology of digital image that then processes the ballot
into Cast Vote Records (CVR).
2. IBML ImageTrac Scanner, version 6400
The IBML ImageTrac is a commercial off-the-shelf (COTS) document scanner.
The scanner provides the following functionality for the system:
Scans 10,000 ballots per hour
Out stacks documents that do not have or are unable to read QR codes
and 1d Barcodes.
Pre-Print ballot id, name the digital image with the ballot id and scan in the
same process.
III. TESTING INFORMATION AND RESULTS
1. Background
Functional and Volume testing of this system was conducted by Secretary of
State Staff, in Norwalk, California, from May 23 to May 25, 2018. The
configuration of the equipment, including a build from the ground up, was
witnessed by Secretary of State Staff on May 23, 2018, using the configuration
procedures provided by the County of Los Angeles. Software testing (Source
Code Review) was performed by SLI Compliance June 11 to July 12, 2018.
Security and Telecommunications testing was performed in Norwalk, California
from July 2 to July 3, 2018. Accessibility for this iteration of the VSAP Tally
system will be addressed by the County of Los Angeles internal procedures for
employee accessibility. This version is solely for the tabulation of vote-by-mail
ballots and exclusively for the use of Los Angeles County election employees.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 2 | Page
2. Functional Testing Summary
System Configuration:
Preparation for Functional Testing and all subsequent testing began on May 23,
2018. The system is self-contained on an air gapped network, per the CVSS
requirements. Secretary of State staff witnessed the build of the test environment
utilizing the vendor provided Use Procedures, which included installation of the
operating system, commercial-off-the-shelf (COTS) software, tabulation software,
and hardening of the system.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 3 | Page
Issues & Observations
During the configuration build, each time the system is built it requires installing
the latest updates for the operating system.
a. Documentation
The documentation was subsequently modified and the changes verified by
the Secretary of State staff.
Phase I - Functional Testing
The first phase of Functional Testing consisted of following the Use Procedures
to configure test elections. The testing included defining three (3) different test
election definitions.
The election type definitions, jurisdictions, and any anomalies noted are listed in
the table below:
Table 2A: Election Definitions
Election Type Jurisdiction Anomaly Identified Resolution
General Los Angeles None N/A
County
Primary – Los Angeles Reports – Sensitivity settings
Countywide County Treasurer Contest were adjusted in
Vote Center count came out 2/4, the configuration
Model instead of 4/4. file. The ballot was
rerun five (5) times,
Ballot Out Stack – and each time it
Superintendent of came out clear after
Education and making the
Measure I. One adjustment.
ballot had debris
that could not be
seen with naked
eye, but the
scanner picked it
up a valid count.
Recall Election Los Angeles None N/A
- Fictional County
Contest with
72 Candidates
and Yes/No
Recall
Question
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 4 | Page
3. Software Testing (Source Code) Review Summary
The review was conducted at the SLI Compliance offices located in Wheat Ridge,
Colorado. SLI evaluated the security and integrity of the voting system, by identifying
any security vulnerabilities that could be exploited to:
Alter vote recording,
Alter vote results,
Alter critical data (such as audit logs), or
Conduct a “denial of service” attack on the voting system.
There were no discrepancy findings or vulnerabilities identified within the VSAP Tally
1.1.2.2 code base.
4. Security and Telecommunications Testing
Security and Telecommunications testing of the VSAP Tally system was conducted
from July 2 to July 3, 2018, by SLI Compliance. The security and telecommunications
testing was conducted in four phases as follows:
Phase I – Security Documentation Review
Phase II – Functional Security Testing
Phase III – Telecommunications and Data Transmission Testing
Phase IV – Onsite Security Testing
Phase I – Security Documentation Review
SLI Compliance reviewed the security documentation supplied by Los Angeles County,
and determined there were no vulnerabilities with the documentation. SLI did note that
there were some improvements, five (5) minor findings with vague or partially missing
documentation.
Table 4A: Security Documentation Review
Test Results Vendor Mitigation/Response
CVSS 7.4.6 – The Following locations must exist and be
writable by the system:
Documentation is only present to validate /opt/mounts (mounted into docker)
VSAP Tally Containers and Trusted Build /opt/tally (scripts, configuration)
outputs, and base package installation of /mount/ballots
COTS software. Detailed documentation
for validation of all storage locations The following must exist but should not be
associated with election specific writeable:
information was missing. /var/lib/docker
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 5 | Page
Table 4A: Security Documentation Review
Test Results Vendor Mitigation/Response
/mount/ballots should also have sufficient
room for all the ballot images that will be
generated in the election with sufficient
safety margin.
CVSS 7.4.5 – VSAP Tally System Version 1.1.2.2 is
designed for internal use by Los Angeles
Documentation was present for creation of County only. It will only be installed in the
a build environment for the VSAP Tally County’s secure central count facility and
solution as well as building the will not be distributed to any other
environment; however, the documentation locations.
has limited references as to how software
is distributed and where the certified copy Prior to installation in the central count
of the software will be stored. There is facility, a copy of the software will be
mention in the documentation that the obtained from a software escrow company
solution will only be used by LA County. certified with the California Secretary of
State and the security hashes for the
download will be validated.
CVSS 7.4.4.b – A more complete list of files will be
compiled and provided.
There is reference to parts of the system
being considered static, dynamic or a mix
of both, the list of files was not complete or
extensive.
CVSS 7.4.2 – County will perform malware/anti-virus and
vulnerability scanning after system
Documentation was present indicating that installation in the air-gapped
due to performance requirements the environment. In addition, an offline scan
solution will not actively utilize COTS anti- will be performed prior to each batch
virus software during operation of the processing of production ballots for every
solution. There are, however, election.
supplemental mitigation steps including
anti-virus and vulnerability scanning of the
environment systems prior to being
introduced to an air gapped network.
CVSS 7.4.1 – In the VSAP Tally System Air-Gap Setup
document provided, Los Angeles County
Documentation was provided that has documented the procedure to setup an
describes the basic overall features air-gap network and configure all
requirements and processes for creation connected devices in the County central
and management of an air gapped facility.
network. In some cases it is detailed, such
has how to update software or firmware on
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 6 | Page
Table 4A: Security Documentation Review
Test Results Vendor Mitigation/Response
the air gapped systems and software
without internet connectivity. No full
procedure for a start to finish air gapped
network implementation including
hardware connectivity is available.
Phase II – Functional Security Testing
Functional Security Testing includes testing the relevant software and operating system
configuration for vulnerabilities, and testing of the hardware, including examination of
unused hardware ports and security measures applied to those ports. Functional
Security Testing also included verifying the VSAP Tally system meets the applicable
requirements of the CVSS.
Table 4B: Functional Security Testing Findings lists the applicable sections of the
CVSS, in addition to the findings of the testing conducted by SLI. A response to those
findings is also included by the County of Los Angeles.
Table 4B: Functional Security Testing Findings
Test Results Vendor Mitigation/Response
CVSS 7.4.2 – County will perform malware/anti-virus and
vulnerability scanning after system
The actual outcome for this review was a installation in the air gapped environment.
determination that during operations, the In addition, an offline scan will be performed
systems within the Scanner environment prior to each batch processing of production
as well as the systems within the VSAP ballots for every election.
Tally environment do not actively use
COTS anti-virus protection. The system
instead utilizes initial malware/anti-virus
and vulnerability scanning prior to the
systems being introduced to the air
gapped network. These are mitigation
steps that are being relied upon instead
of active malicious software protection.
CVSS 7.4.6 – VSAP Tally System Version 1.1.2.2 is
designed to be installed and operated in an
The actual outcome for this review environment with tight physical controls.
was a determination that there are There is no external network connection to
validation methods to verify the allow processes to access external
VSAP Tally 1.0 trusted build software.
output as well as a JSON file
created with a list of every VSAP Tally System Version 1.1.2.2 is not
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 7 | Page
Table 4B: Functional Security Testing Findings
Test Results Vendor Mitigation/Response
container generated by the build designed for distribution and will only be
process and a corresponding hash used by Los Angeles County in a tightly-
value. Each of the COTS products controlled environment. Physical,
contain a hash of the single COTS administrative, and management controls
file installation file(s). This that include strict supervision and
indicates that the software monitoring of staff activity while operating
validation is done prior to the the Tally System and the prohibition of
installation of the system. wireless phones\devices and unverified
removable media in the secure Tally room
The actual outcome for this review
are some of the mitigation measures that
was a determination that there are
will be implemented to ensure integrity of
processes and procedures for
the air gapped network.
creation of SHA512 Hash codes
during the trusted build for both
the system build outputs and
SHA256 hashes of each of the
Docker service containers. All
COTS Software contains verifiable
HASH values to validate that the
correct version of the software is
installed.
The system has no protections to
prevent processes from installing
software except for manual
processes and procedures and
physical security and access
controls to prevent unauthorized
installation.
The VSAP Tally 1.0 system
utilizes processes and procedures
and physical security and access
controls to prevent previous
versions of the system from being
installed.
The software update package is
not digitally signed.
The Solution doesn’t currently
utilize an automated process to
prevent unwanted installations
The system doesn’t have a way to
provide a verification method of all
system storage locations, only the
VSAP Tally 1.0 solution, and the
COTS products installers.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 8 | Page
Table 4B: Functional Security Testing Findings
Test Results Vendor Mitigation/Response
CVSS 7.6.1 – Ballot security and accountability is critically
important for the County. Each ballot has a
QR Code with election-specific information
The actual outcome for this review
encoded, which VSAP Tally reads to ensure
was a determination that portions
the ballot is valid in the current election.
of this requirement are not
applicable. The system scans
Additionally, controls are implemented as
already marked ballots which are
part of the Use Procedures to inspect all
then processed by the VSAP Tally
ballots prior to tabulation and to ensure only
system.
valid official ballots are sent to VSAP Tally
No checksums or message
for processing.
digests are used to validate
scanned ballot images.
Manual recount procedures,
California State required one
percent manual recount
procedures, physical security
measures and a tightly controlled
air gapped network are all
mitigating measures in place.
CVSS 7.8.2 - Physical, administrative, and management
controls that include strict supervision and
The actual outcome for this review monitoring of staff activity while operating
was a determination that the the Tally System and the prohibition of
solution sufficiently protects wireless phones\devices and unverified
against data interception and removable media in the secure Tally room
disruption. are some of the mitigation measures that
will be implemented to ensure integrity of
The solution currently does not
the air gapped network. A major feature of
provide end to end transmission
this network is that the network switch being
security. The VSAP Tally 1.0
used is configured to only allow one device
solution utilizes encryption of data
per port and locks that port to the device’s
transmissions between Application
mac address.
containers for image processing
and reporting. The connection
between the IBML Scanner and
the CIFS file share, however, is
not transmitted using encryption.
Stringent attention to maintaining
the air gapped scanner and Tally
environment removes the ability to
intercept or modify results as they
are being scanned and processed.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 9 | Page
Phase III – Telecommunications and Data Transmission Testing
Telecommunications and Data Testing included testing of system communications,
including encryption of data, as well as protocols and procedures for access
authorization. Table 4C list the results of that testing.
Table 4C: Telecommunications and Data Transmission Vulnerabilities
Issue Consultant Assessment Vendor Mitigation/Response
Cross Site (High Severity) (Tentative Cross Site Scripting requires
Scripting confidence) Potentially a false having another (malicious) site
(DOM-based) positive as the confidence is set accessible on the network. This is
to tentative. prevented by strict enforcement of
the air gapped network
environment and security
protocols.
SSL Certificate (Medium severity) (Certain As noted, this issue is mitigated
confidence). Server’s certificate is by the strict enforcement of the air
not valid for the server’s gapped network environment and
hostname, and the server security protocols.
certificate is not trusted. This
error has little to no impact to the
overall security of the solution
due to the nature of the air
gapped trusted network.
Client-side (Low Severity) (Firm Confidence). Strict enforcement of the air
JSON injection DOM-based JSON injection may gapped network environment and
(DOM-based) happen when a script includes security protocols should provide
controllable data into a string that sufficient protection against DOM-
is parsed as a JSON data based attacks.
structure and then processed by
the application.
Transport (Low Severity) (Certain Strict enforcement of the air
security confidence). This allows a gapped network environment and
potential attacker to modify security protocols should provide
legitimate user network traffic to sufficient protection against these
bypass application use of types of attacks.
SSL/TLS encryption.
Informational These vulnerabilities are of an Although as noted these
Vulnerabilities informational nature and include vulnerabilities are believed to be
recon information that helps to negligible, they are mitigated by
identify the system, including open the strict enforcement of the air
ports, OS type and version and gapped network environment and
services detected. The security protocols.
vulnerabilities explored and
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 10 | Page
detected are believed to be
negligible and have little or no
impact on the overall security of
the system.
SLI reported three (3) categorical findings during the Telecommunications and Data
Transmission Testing of the VSAP Tally 1.0 system. SLI’s determination was that, the
overall security posture of the system as a whole is minimal. The findings are listed
below in Table 4D.
Table 4D: Telecommunications and Data Transmission Categorical
Issue Consultant Assessment Vendor Mitigation/Response
Six (6) medium 1. SMB signing not required VSAP Tally operates in an air
severity gapped network. Strict access
2. SSL Certificate cannot be
vulnerabilities trusted controls and physical security
mitigation measures are
3. SSL Certificate signed using
implemented to ensure the
weak hashing algorithm
integrity of the air gapped
4. SSL certificate with wrong host
environment.
name
5. SSL medium strength cipher
suites supported
6. SSL Self-signed Certificate
Two (2) low 1. SSH Server CBC mode ciphers VSAP Tally operates in an air
severity enabled gapped network. Strict access
vulnerabilities 2. SSL RC4 cipher suites controls and physical security
supported. mitigation measures are
implemented to ensure the
integrity of the air gapped
environment.
Fifty (50) These vulnerabilities are of an Although as noted these
informational informational nature and include vulnerabilities are believed to be
severity recon information that helps to negligible, they are mitigated by
vulnerabilities. identify the system, including open the strict enforcement of the air
ports, OS type and version and gapped network environment and
services detected. The security protocols.
vulnerabilities explored and
detected are believed to be
negligible and have little or no
impact on the overall security of
the system.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 11 | Page
Phase IV – Onsite Security Testing
The Onsite Security Testing consisted of testing for relevant software and operating
system configuration for vulnerabilities, testing of hardware, including the examination of
unused ports and the security measures applied to the ports, in addition to examination
of the physical environment. The applicable portions of CVSS and the results of the
Onsite Security Testing are listed in Table 4E.
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
CVSS 5.4.3 - The actual outcome for N/A
this review was a
a. Machine generated error and determination that the
exception messages to system generates and
demonstrate successful contains sufficient
recovery. auditing capability. This
includes VSAP Tally 1.0
iv. Notification of system logs, Centos Operating
login or access errors, System logs, Windows
file access errors, and OS logs, ImageTrac logs.
physical violations of
security as they occur,
and a summary record of
these events after
processing
CVSS 7.2.1 – The actual outcome for N/A
this review was a
a. Voting system equipment determination that the
shall provide access control system sufficiently
mechanisms designed to permit provides access controls
authorized access to the voting for the VSAP Tally 1.0
system and to prevent solution, as well as the
unauthorized access to the systems that are
voting system. associated with the
solution. The system has
i. Access control processes and
mechanisms on the procedures in place to
Election Management prevent
System (EMS) shall be modification/tampering
capable of identifying with software/firmware, as
and authenticating well as physical security
individuals permitted to including an air gapped
perform operations on network.
the EMS.
b. Voting system equipment
shall provide controls that
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 12 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
permit or deny access to the
device’s software and files.
c. The default access control
permissions shall implement
the minimum permissions
needed for each role or group
identified by a device.
d. The voting device shall
prevent a lower-privileged
process from modifying a
higher-privileged process.
e. An administrator of voting
system equipment shall
authorize privileged operations.
f. Voting system equipment
shall prevent modification to or
tampering with software or
firmware through any means
other than the documented
procedure for software
upgrades.
CVSS 7.2.2 – The actual outcome for N/A
this review was a
a. The voting system shall determination that the
identify users and processes to access controls are
which access is granted and sufficient for all portions of
the specific functions and data the VSAP Tally 1.0
to which each entity holds environment, including
authorized access. Scanner environment.
b. Voting system equipment
that implements role-based
access control shall support
the recommendations for Core
RBAC in the ANSI INCITS 359-
2004 American National
Standard for Information
Technology- Role Based
Access Control document.
c. Voting system equipment
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 13 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
shall allow the administrator
group or role to configure the
permissions and functionality
for each identity, group, or role
to include account and
group/role creation,
modification, and deletion.
CVSS 7.3 – The actual outcome for N/A
this review was a
a. Voting system equipment determination that all
shall authenticate users prior to username password
granting them access to system functionality is maintained
functions or data. by an administrative
source. Complex
b. When private or secret passwords, lockout
authentication data is stored in history, complexity
voting system equipment, the requirements, and
data shall be protected to expiration of passwords
ensure that the confidentiality can all be enforced at the
and integrity of the data is not operating system level
violated. and at the ImageTrac
scanning software which
c. Voting system equipment sufficiently meets the
shall allow the administrator requirements.
group or role to set and change
passwords, pass phrases, and
keys.
d. Voting system equipment
shall allow privileged groups or
roles to be disabled and allow
new individual privileged
groups or roles to be created.
e. Voting system equipment
shall lock out groups, roles, or
individuals after a specified
number of consecutive failed
authentication attempts within a
predefined time period.
f. Voting systems shall allow
the administrator group or role
to configure the account lock
out policy, including the time
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 14 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
period within which failed
attempts must occur, the
number of consecutive failed
access attempts allowed before
lock out, and the length of time
the account is locked out.
g. If the voting system uses a
user name and password
authentication method, the
voting system shall allow the
administrator to enforce
password strength, histories,
and expiration.
h. The voting system shall
allow the administrator group or
role to specify password
strength for all accounts,
including minimum password
length, use of capitalized
letters, use of numeric
characters, and use of non-
alphanumeric characters.
i. The voting system shall
enforce password histories, and
allow the administrator to
configure the history length.
j. Voting system equipment
shall ensure that the username
is not used in the password.
k. Voting systems shall provide
a means to automatically expire
passwords in accordance with
the voting jurisdiction’s policies.
l. Manufacturers shall develop
and document in detail the
measures to be taken in a
central counting environment.
These measures shall include
physical and procedural
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 15 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
controls related to the handling
of ballot boxes, preparing of
ballots for counting, counting
operations and reporting data.
CVSS 7.3.2 – The actual outcome for In the VSAP Tally
this review was a System Air-Gap Setup
Manufacturers shall develop determination that the document provided, Los
and document in detail the solution fully documents Angeles County has
measures to be taken in a and implements documented the
central counting environment. processes and procedure to setup an
These measures shall include procedures for securing air-gap network and
physical and procedural the central count location. configure all connected
controls related to the handling These include physical devices in the County
of ballot boxes, preparing of security measures, central facility.
ballots for counting, counting procedural controls for
operations and reporting data. maintaining the Air Gap In the VSAP Tally
network, protection and System Tamper-Evident
handling of ballots, and Seals Procedures
reporting of data. document provided, Los
Angeles County has
Observation: No specific
documented how it
details pertaining to the
intends to log the use
security measures to
tamper-evident seals as
network switching
a security measure.
equipment. Security
practices for the air
gapped network were
observed that help to
enhance the overall
security of the solution but
were not documented
anywhere in the
requirements.
Observation: There is
reference to maintaining
tamper-evident seal
numbers multiple times
throughout the
documentation; however,
there is no direct
reference to the tamper
evident seal log that was
in use. Documentation of
the procedures for
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 16 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
maintaining such a log
including where it’s stored
and who has access to
the log is needed.
CVSS 6.1.2 – The actual outcome for N/A
this review was a
These requirements apply to determination that the
the use of telecommunications system sufficiently meets
to transmit data for the the requirements for data
preparation of the system for an transmission. Testing
election, the execution of an included Nessus®
election, and the preservation Vulnerability scans
of the system data and audit against all connected
trails during and following an equipment, as well as
election. While this section physical inspection of the
does not assume a specific networking equipment
model of voting system connected to the air
operations and does not gapped network.
assume a specific model for the
use of telecommunications to
support such operations, it
does address the following
types of data, where applicable:
Voter Authentication: Coded
information that confirms the
identity of a voter for security
purposes for a system that
transmits votes individually
Ballot Definition: Information
that describes to a voting
machine the content and
appearance of the ballots to be
used in an election
Vote Count: Information
representing the tabulation of
votes at any level within the
control of the jurisdiction, such
as the polling place, precinct or
central count
List of Voters: A listing of the
individual voters who have cast
ballots in a specific election
CVSS 7.8.1– The actual outcome for N/A
this review was a
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 17 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
For those access control determination that the
features built in as components solution successfully
of the voting system, the S-ATA meets the requirements
shall design tests to confirm for access control.
that these security elements
work as specified.
Specific activities to be
conducted by the S-ATA shall
include:
b. Specific tests
designed by the S-ATA
to verify the correct
operation of all
documented access
control procedures and
capabilities, including
tests designed to
circumvent controls
provided by the
manufacturer. These
tests shall include:
i. Performing the
activities that the
jurisdiction will
perform in specific
accordance with
the
manufacturer’s
access control
policy and
procedures to
create a secure
system, including
procedures for
software and
firmware
installation
ii. Performing
tests intended to
bypass or
otherwise defeat
the resulting
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 18 | Page
Table 4E: Onsite Security Testing
CVSS Standard Result Vendor
Mitigation/Response
security
environment.
These tests shall
include simulation
of attempts to
physically destroy
components of
the voting system
in order to
validate the
correct operation
of system
redundancy and
backup
capabilities
CVSS 7.8.2 – The actual outcome for Physical, administrative,
this review was a and management
For systems that use determination that the controls that include strict
telecommunications, as solution sufficiently supervision and
provided for in section 6 of the protects against data monitoring of staff activity
Standards and consistent with interception and while operating the Tally
California law, to transmit disruption. The utilization System and the
official voting data, the SATA of a physically protected prohibition of wireless
shall review, and conduct tests air gapped network helps phones\devices and
of, the data interception and improve a solution that unverified removable
prevention safeguards specified only employs encryption media in the secure Tally
by the manufacturer in its TDP. of data transmissions room are some of the
The S-ATA shall evaluate between application mitigation measures that
safeguards provided by the containers for image will be implemented to
manufacturer to ensure their processing and reporting ensure integrity of the air
proper operation, including the and not all gapped network. A
proper response to the communications. The major feature of this
detection of efforts to monitor connection between the network is that the
data or otherwise compromise IBML Scanner and the network switch being
the system. CIFS file share is not used is configured to only
currently encrypted. allow one device per port
Stringent attention to and locks that port to the
maintaining the air device’s mac address.
gapped scanner and Tally
environment removes the
ability to intercept or
modify results as they are
being scanned and
processed.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 19 | Page
SLI determined there were three (3) findings and two (2) observations during the Onsite
Security Testing Phase. SLI concluded the impact to the overall security posture of the
solution as a whole is minimal.
5. Volume Testing Summary
The Volume Test simulates conditions in which the system components would be used
on Election Day. Volume Testing of the VSAP Tally system took place in Los Angeles
County, on May 24, 2018. Test ballots from the California 2014 General Election were
scanned for over seven (7) hours. The use of this election required an edit of the
configuration file within the Tally system.
Table 5A: Machine and Ballot Count
Hardware Number of Number of Ballot Pages Total for All
Component Machines Ballots per Machines
Machine
IBML Scanner 1 2,998 Two (2) 5,996
Table 5B: Error Log
Hardware Component Error Type Error Occurrence Mitigation
Frequency
IBML Scanner “Gap Violation” – The Ten (10) The use
scanner is sensitive procedures and
to the amount of operator cards
spacing between at the scanner
ballots in the feeder. will remind
operators of the
scanner that
adequate
spacing
between the
ballots in the
feeder is
necessary.
IBML Scanner “Double Feed Error” One (1) IBML
– Two ballots were suggested
stuck together. adjustments to
the scanner to
alleviate gap
and double
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 20 | Page
Table 5B: Error Log
Hardware Component Error Type Error Occurrence Mitigation
Frequency
feed errors.
Those
suggestions
were
incorporated
into the daily
maintenance
routine;
operators will
follow during
the tally
process.
Additionally,
operators
should utilize a
“ballot jogger”.
Use
procedures will
address this
issue.
IBML Scanner “Document too long One (1) Ballot was
error” pulled off of
track and
delicately hand
fed into the
scanner.
IBML Scanner Ballot Out stacked One (1) Slight fold in
the corner of
ballot, covering
the registration
mark. Use
procedures will
address this
issue.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 21 | Page
IV. COMPLIANCE WITH STATE AND FEDERAL LAWS AND
REGULATIONS
The following are the applicable California Elections Code sections that the Secretary of
State tested the County of Los Angeles’ VSAP Tally 1.0 central tabulation voting system
against. The list is broken down by Elections Code Section, language quoted from the
section and how the system complies with the section.
10264 - As soon as the result of the election is declared, the elections official of the
governing body shall enter on its records a statement of the result. The statement shall
show: (a) The whole number of votes cast in the city. (b) The names of the persons
voted for. (c) The measures voted upon. (d) For what office each person was voted for.
(e) The number of votes given at each precinct to each person and for and against each
measure. (f) The number of votes given in the city to each person and for and against
each measure.
The central tabulation voting system has the capability to produce the required report(s).
10550 - As soon as the result of the canvass by the county elections official is declared,
the county elections official shall prepare and mail a statement of the result to the
secretary of each district participating in the general district election. The statement
shall be signed by the county elections official, authenticated by the seal of the county
and shall show: (a) The number of ballots cast for elective offices of that district and,
when directors of that district are elected by divisions, the number of ballots cast in each
division. (b) The name of each candidate for an elective office of that district voted for
and the office. (c) The number of votes cast in each precinct for each candidate. (d)
When directors are elected by divisions, the number of votes cast in each division for
each candidate for the office of director from that division. (e) The number of votes cast
in the district for all other elective offices of that district.
The central tabulation voting system has the capability to produce the required report(s).
15101(b) - Any jurisdiction having the necessary computer capability may start to
process vote by mail ballots on the seventh business day prior to the election.
Processing vote by mail ballots includes opening vote by mail ballot return envelopes,
removing ballots, duplicating any damaged ballots, and preparing the ballots to be
machine read, or machine reading them, but under no circumstances may a vote count
be accessed or released until 8 p.m. on the day of the election. All other jurisdictions
shall start to process vote by mail ballots at 5 p.m. on the day before the election.
The central tabulation voting system has the capability to meet this requirement.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 22 | Page
15101(c) - Results of any vote by mail ballot tabulation or count shall not be released
prior to the close of the polls on the day of the election.
The central tabulation voting system has the capability to scan, but not tabulate or
report the results prior to the close of polls on Election Day.
15109 - Except as otherwise provided in this chapter, the counting and canvassing of
vote by mail ballots shall be conducted in the same manner and under the same
regulations as used for ballots cast in a precinct polling place.
The central tabulation voting system has the capability to meet this requirement.
15110 - Reports to the Secretary of State of the findings of the canvass of vote by mail
ballots shall be made by the elections official pursuant to Chapter 3 (commencing with
Section 15150) and Chapter 4 (commencing with Section 15300).
The central tabulation voting system has the capability to produce the required report(s).
15150 - For every election, the elections official shall conduct a semifinal official
canvass by tabulating vote by mail and precinct ballots and compiling the results. The
semifinal official canvass shall commence immediately upon the close of the polls and
shall continue without adjournment until all precincts are accounted for.
The central tabulation voting system has the capability to meet this requirement.
15151(a) - The elections official shall transmit the semifinal official results to the
Secretary of State in the manner and according to the schedule prescribed by the
Secretary of State prior to each election, for the following: (1) All candidates voted for
statewide office. (2) All candidates voted for the following offices: (A) State Assembly.
(B) State Senate. (C) Member of the United States House of Representatives. (D)
Member of the State Board of Equalization. (E) Justice of the Court of Appeals. (3) All
persons voted for at the presidential primary or for electors of President and Vice
President of the United States. (4) Statewide ballot measures.
The central tabulation voting system has the capability to produce the required report(s).
15152 - Neither the elections official, any member of a precinct board, nor any other
person shall count any votes, either for a ballot proposition or candidate, until the close
of the polls in that county. After that time, the ballots for all candidates and ballot
propositions voted upon solely within the county shall be counted and the results of the
balloting made public. However, the results for any candidate or ballot proposition also
voted upon in another county or counties shall not be made public until after all the polls
in that county and the other county or counties have closed. This paragraph applies
regardless of whether the counting is done by manual tabulation or by a vote tabulating
device.
The central tabulation voting system has the capability to scan, but not tabulate or
report the results prior to the close of polls on Election Day.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 23 | Page
15153 - During the semifinal official canvass, write-in votes shall be counted in
accordance with Article 3 (commencing with Section 15340) of Chapter 4.
The central tabulation voting system has the capability to meet this requirement.
5212 - If voting at all precincts within a county is not conducted using the same voting
system, the result as to the precincts not subject to this article shall be determined in
accordance with other provisions of this code and the result of the vote at precincts
subject to this article shall be determined as provided in this article. The statement of
the vote in that case shall represent the consolidation of all the results and the results of
the canvass of all vote by mail voter ballots.
The central tabulation voting system has the capability to produce the required report(s).
15302(e), (f), (g), (h) - The official canvass shall include, but not be limited to, the
following tasks: (e) Processing and counting any valid vote by mail and provisional
ballots not included in the semifinal official canvass. (f) Counting any valid write-in
votes. (g) Reproducing any damaged ballots, if necessary. (h) Reporting final results to
the governing board and the Secretary of State, as required.
The central tabulation voting system has the capability to produce the required report(s).
15342(a) - Any name written upon a ballot for a qualified write-in candidate, including a
reasonable facsimile of the spelling of a name, shall be counted for the office, if it is
written in the blank space provided and voted as specified below: (a) For voting systems
in which write-in spaces appear directly below the list of candidates for that office and
provide a voting space, no write-in vote shall be counted unless the voting space next to
the write-in space is marked or slotted as directed in the voting instructions, except as
provided in subdivision (f). (d) Neither a vote cast for a candidate whose name appears
on the ballot nor a vote cast for a write-in candidate shall be counted by a combination
of marking and writing, a choice of more names than there are candidates to be
nominated or elected to the office. (e) All valid write-in votes shall be tabulated and
certified to the elections official on forms provided for this purpose, and the write-in
votes shall be added to the results of the count of the ballots at the counting place and
be included in the official returns for the precinct.
The central tabulation voting system has the capability to meet this requirement.
15372(a) - The elections official shall prepare a certified statement of the results of the
election and submit it to the governing body within 28 days of the election or, in the case
of school district, community college district, county board of education, or special
district elections conducted on the first Tuesday after the first Monday in November of
odd numbered years, no later than the last Monday before the last Friday of that month.
(b) The elections official shall post the certified statement of the results of the election
on his or her Internet Web site in a downloadable spreadsheet format that may include,
but is not limited to, a comma-separated values file or a tab-separated values file and
that is compatible with a spreadsheet software application that is widely used at the time
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 24 | Page
of the posting. The certified statement of the election results shall be posted and
maintained on the elections official’s Internet Web site for a period of at least 10 years
following the election. This subdivision shall apply only to an elections official who uses
a computer system that has the capability of producing the election results in a
downloadable spreadsheet format without requiring modification of the computer
system.
The central tabulation voting system has the capability to produce the required report(s).
15374(a) - The statement of the result shall show all of the following: (1) The total
number of ballots cast. (2) The number of votes cast at each precinct for each candidate
and for and against each measure. (3) The total number of votes cast for each
candidate and for and against each measure. (b) The statement of the result shall also
show the number of votes cast in each city, Assembly district, congressional district,
senatorial district, State Board of Equalization district, and supervisorial district located
in whole or in part in the county, for each candidate for the offices of presidential elector
and all statewide offices, depending on the offices to be filled, and on each statewide
ballot proposition.
The central tabulation voting system has the capability to produce the required report(s).
19101(b)(1) - The machine or device and its software shall be suitable for the purpose
for which it is intended.
The central tabulation voting system meets this requirement.
19101(b)(2) - The system shall preserve the secrecy of the ballot.
The central tabulation voting system meets this requirement.
19101(b) (3) – The system shall be safe from fraud or manipulation.
The central tabulation voting system meets this requirement.
19203 - The Secretary of State shall not certify or conditionally approve a voting system
or a part of a voting system that uses paper ballots unless the paper used for the ballots
is of sufficient quality that it maintains its integrity and readability throughout the
retention period specified in Chapter 4 (commencing with Section 17300) of Division 17.
The ballots used for testing the central tabulation voting system have the capability to
meet this requirement.
19204 - The Secretary of State shall not certify or conditionally approve any voting
system that includes features that permit a voter to produce, and leave the polling place
with, a copy or facsimile of the ballot cast by the voter at that polling place.
The central tabulation voting system has the capability to meet this requirement.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 25 | Page
19205 - A voting system shall comply with all of the following: (a) No part of the voting
system shall be connected to the Internet at any time. (b) No part of the voting system
shall electronically receive or transmit election data through an exterior communication
network, including the public telephone system, if the communication originates from or
terminates at a polling place, satellite location, or counting center. (c) No part of the
voting system shall receive or transmit wireless communications or wireless data
transfers.
The central tabulation voting system has the capability to meet this requirement.
V. CONCLUSION
The VSAP Tally 1.0 voting system, in the configuration tested and documented
by the California Installation and the County of Los Angeles’ Use Procedures,
meets all applicable California and federal laws. The County of Los Angeles’
VSAP Tally 1.0 voting system is compliant with all applicable California and
federal laws.
SECRETARY OF STATE’S STAFF REPORT – LA VSAP TALLY 1.0 26 | Page