[Talk] Hotel Minibar Keys Open Diebold Voting Machines

talk@flux.org talk@flux.org
Tue, 19 Sep 2006 16:09:44 -0400 (EDT)


http://www.freedom-to-tinker.com/?p=1064

Hotel Minibar Keys Open Diebold Voting Machines
Monday September 18, 2006 by Ed Felten

Like other computer scientists who have studied Diebold voting machines, we 
were surprised at the apparent carelessness of Diebolds security design. It can 
be hard to convey this to nonexperts, because the examples are technical. To 
security practitioners, the use of a fixed, unchangeable encryption key and the 
blind acceptance of every software update offered on removable storage are 
rookie mistakes; but nonexperts have trouble appreciating this. Here is an 
example that anybody, expert or not, can appreciate:

The access panel door on a Diebold AccuVote-TS voting machine the door 
that protects the memory card that stores the votes, and is the main 
barrier to the injection of a virus can be opened with a standard key that 
is widely available on the Internet...