Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] Bad Protocol - Freedom to Tinker |
|---|---|
| Date: | Thu, 14 Oct 2004 03:52:42 -0500 (CDT) |
http://www.freedom-to-tinker.com/archives/000699.html Edward W. Felten October 13, 2004 Dan Wallach from Rice University was here on Monday and gave a talk on e-voting. One of the examples in his talk was interesting enough that I thought I would share it with you, both as an introductory example of how security analysts think, and as an illustration of how badly Diebold botched the design of their voting system. One of the problems in voting system design is making sure that each voter who signs in is allowed to vote only once. In the Diebold AccuVote-TS system, this is done using smartcards. (Smartcards are the size and shape of credit cards, but they have tiny computers inside.) After signing in, a voter would be given a smartcard -- the "voter card" -- that had been activated by a poll worker. The voter would slide the voter card into a voting machine. The voting machine would let the voter cast one vote, and would then cause the voter card to deactivate itself so that the voter couldn't vote again. The voter would return the deactivated voter card after leaving the voting booth. This sounds like a decent plan, but Diebold botched the design of the protocol that the voting terminal used to talk to the voter card. The protocol involved a series of six messages, as follows: terminal to card: "My password is [8 byte value]" card to terminal: "Okay" terminal to card: "Are you a valid card?" card to terminal: "Yes." terminal to card: "Please deactivate yourself." card to terminal: "Okay." Can you spot the problem here? (Hint: anybody can make their own smartcard that sends whatever messages they like.) As most of you probably noticed -- and Diebold's engineers apparently did not -- the smartcard doesn't actually do anything surprising in this protocol. Anybody can make a smartcard that sends the three messages "Okay; Yes; Okay" and use it to cast an extra vote. (Do-it-yourself smartcard kits cost less than $50.) Indeed, anybody can make a smartcard that sends the three-message sequence "Okay; Yes; Okay" over and over, and can thereby vote as many times as desired, at least until a poll worker asks why the voter is spending so long in the booth. One problem with the Diebold protocol is that rather than asking the card to prove that it is valid, the terminal simply asks the card whether it is valid, and accepts whatever answer the card gives. If a man calls you on the phone and says he is me, you can't just ask him "Are you really Ed Felten?" and accept the answer at face value. But that's the equivalent of what Diebold is doing here. This system was apparently used in a real election in Georgia in 2002. Yikes. _________________________________________ Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - http://www.osvdb.org/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Enterprise security is worst ever, experts say, InfoSec News |
|---|---|
| Next by Date: | [ISN] NSA: Global grid will have data assurance baked in, InfoSec News |
| Previous by Thread: | [ISN] Enterprise security is worst ever, experts say, InfoSec News |
| Next by Thread: | [ISN] NSA: Global grid will have data assurance baked in, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |