| Not a member? Register | Lost your password?

The Autormated Election System - Is it hackable?

by uncleangidpogi on » Sep 25 2009 » (Angel's Realm)
Viewed 1039 times, 1 so far today » 3 Comments » « previous article | next article »

The Automated Election System – Is it Hackable?

For the past few months, since the consortium of Smartmatic-TIM won the Philippines election automation project, doubts and fears about the system as well as the machines have been raised and discussed everywhere. While many already concluded that the machines are vulnerable to hacking and vote modifications, Smartmatic-TIM in defense have continuously denied such allegations and shouted to the whole world saying their system and machines are not prone to hacking.
So the unanswered question still lingers…is it really hackable?

The PROBLEM…

In the world of cyber security, it is presumed that nothing is impossible and everything is hackable. The only question is, WHEN? A system could be hacked tomorrow, next week, next month or next year, all these depends on the security measures implemented and the knowledge or the stupidity of those responsible in the field of cyber security.
Smartmatic-TIM has continuously failed to demonstrate the level of security their system has or the level of security they are planning to implement to prevent possible election fraud and/or election failure. They however successfully ignited the wrath of malicious hackers (http://www.tribune.net.ph/headlines/20090820hed5.html ) and crackers to attack the election automation system by irresponsibly screaming to the whole world claiming their system is unhackable and even offering a 10M PHP reward to those who can successfully hack the system. The thing is, there are hackers who hack not for money, but for fame and personal satisfaction, but definitely there are those who do it for money, and 10M PHP is more than enough to give a free invite to these people.
The ignorance of Smartmatic-TIM in terms of information security is obviously bottomless otherwise they wouldn’t have done that. Almost all those who dared hackers and irresponsibly advertised to the whole world that their system is secure have been hacked and humiliated.

As a Filipino, this is scaring me, not because I am a Smartmatic-TIM sympathizer but because this would mean a failure to the 2010 national election.

The QUESTIONS…
Although it is very valid to raise our doubts and fears on the security of these machines, I don’t think we are asking the right questions. A lot of experts have given their point of views and the Government has been talking about conducting a source code review (which is good) but all of them did not satisfy my own doubts and fears.

As far as I know, this is how data is going to be sent to the different levels (I could be wrong):

From Poll precincts —— Upload from PCOS machines located in poll precincts to Central
Server, Municipal level and Political Party Server

From Municipal level —– Upload from Municipal to Central Server, Provincial level, and to
Political Party Server

From Provincial level —– Upload from Provincial level to Central Server, NBOC and Political
Party Server

From National level  ——- Upload from NBOC to Central Server and Political Party Server

1st: How will you secure the physical level access of the machines?
2nd: How will you secure the logical level access of the machines?
3rd: How will you protect the votes stored inside the machines?
4th: How will you secure the votes sent from the machines to the different levels (municipal, provincial, national, etc) during transmission to prevent information sniffing and hijacking?
5th: How will you secure the data when it arrives at the municipal level, provincial level, national level, etc?

6th: How will you make sure that the integrity of the data sent or received was not compromised and that the person who sent the data and the person who opened and received the data are the persons authorized to process the data?

7th: If in case the data is hijacked, how will you make sure that data will be unusable to the person who hijacked the data.

8th: If the data has been compromised, how long will it take for the hacker to read and modify the data?

9th: If the data has been successfully modified, how will you prevent the hacker from uploading the data to all levels and make it look it was sent by an authorized person?
10th: On the municipal level, how will you ensure that the data sent to the provincial level, national level, etc. are authentic and came from the authorized person in the municipal level?

11th: How will you prevent a massive Denial of Service of Distributed Denial of Service Attacks from happening?

12th: How will you ensure the integrity of the data sent and received as well as the person who sent and received the data?
These are just some of the valid questions that Smartmatic-TIM so far failed to address and demonstrate.

The INVISIBLE THREAT
There is an ongoing war right now, it’s called Cyber War. Unlike the conventional type of war, cyber warfare is invisible, and you can be attacked by anyone from anywhere and you wouldn’t even know where the source of the attacks came from. There are also cyber mercenaries, those who get paid by successfully attacking a target, and no doubt these mercenaries would be more than happy to accommodate our corrupt politicians. How are you going to arrest or preempt an invisible threat or attacks? How are you going to pinpoint the location and source of these possible attacks?
A million dollar question that can only be answered by those who truly understand these invisible threats, as well as the invisible threat catalysts, not by those who pretend to be experts in cyber security and not by those who read a lot about cyber security but haven’t really done it.

The Filipino people deserves more, let us not put our trust to these pretenders, let us not put our future to these incompetent people, because protecting our votes this coming 2010 elections is protecting the future of our children and our children’s children.

So, going back to the first question…IS IT HACKABLE?

As an information security enthusiast and practitioner, my answer would be…WHO KNOWS? But I can surely say that Smartmatic-TIM guys are not that good and knowledgeable when it comes to information security and cyber attacks, they don’t understand how hackers think and they’ve got no freaking idea how they work. This makes it very scary. Unlike the saying ¨What you don’t know won’t hurt you¨, in cyber security, what you don’t know will definitely hurt you…BIG TIME!!!

3 Comments »

  1. didi didi says:

    Angel, how do other countries protect the sanctity of the ballot? First world countries have adopted automation long time ago and the results of elections have never been contested (except the Bush-Gore toss up which ended up in the US Supreme Court, but the contested portion is statistically insignificant, considering data dating back to the start of automation). Redundancy in transmission of the data could probably help. Also, simultaneous and redundant transmission is probably better than laddered transmission (send simultaneously to local, provincial, national and media rather than precinct to municipal to provincial, etc). At this time of the technological evolution, ensuring a credible automated election should be a walk in the park.

    Quote

  2. Angel Redoble uncleangidpogi says:

    I don’t know how others secure their automated election system…and this is exactly the idea…nobody knows and no one should know. In cyber warfare, if you know how to hide your system, even if you are vulnerable to some attacks, but you make it so hard for your enemy to find your system…your system can be considered secure, because if I were the enemy I wouldn’t know where to launch the attack.

    Security by obscurity is the secret. The more you say something about your system, the more vulnerable you become..

    Never shout to the whole world that your system is secure and unhackable…be paranoid always, always bear in mind that there is someone out there much better than you..and that someone surely has the capability to break into your system…

    And Never challenge a hacker…

    These 3 points are the most basic but very effective in information security. And samtmatic-tim failed in these points so far. They have continuously claimed through the media that their system is unhackable and they are even offering 10M php to those who can successfully hack the system..this so far is the most stupid thing.

    And Comelec, who’s ignorance to cyber security is also bottomless like smartmatic-tim..they have become the “bash-brothers” in causing the possible failure of the 2010 automated election. This is like “The blind leading the blind” hehehe

    Quote

  3. Primo Redoble Tats says:

    We should know our politicians better. They will find a way to rig the election no matter what. Anything not hackable or riggable they will never buy!

    Quote


Leave a Reply

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

Subscribe without commenting

  • search 32
  • bengals cheerleaders tryouts 2011
  • connecticut 97.7connecticut attorney general
  • zara phillips royal wedding picture
  • mtv 30 years
  • nestle
  • hp support contact number
  • c span shelby foote
  • la ink tattoos
  • chicago bears jewish players
  • freida pinto glamour 2011
  • cspan government shutdown
  • gprs
  • cspan facebook
  • entrepreneurs
  • bea 2011 map
  • zara phillips tongue
  • new england patriots 98.5
  • bea zuberbühler
  • tea party table settings
  • libbey
  • searchbugsearch engines
  • randy moss wonderlic
  • hp support assistant review
  • connecticut quarry
  • charitable
  • jorgensen
  • new england patriots rumors
  • mtv dougie
  • freida pinto zac posen
  • battleship texas hours
  • clio
  • chad ochocinco quits football
  • connecticut 5th district
  • zara phillips facebookzara phillips gossip
  • randy moss bio
  • lemon
  • bengals history
  • chicago bears expo
  • bengals 09 record
  • la ink yahoo answers
  • connecticut 5 star resorts
  • bengals images
  • la ink games online
  • bengals forum
  • greg olsen twitter
  • search engines compared
  • bea taylor
  • crimping
  • mizuno
  • quarts
  • chun
  • bea diy
  • chicago bears expo 2011
  • cspan ap government review
  • chicago bears donation request
  • chicago bears 4th phase
  • capoeira
  • search 78search 800 numbers
  • chicago bears 1985
  • framed
  • beamerbea france
  • modified
  • search engines 9
  • dis v44
  • la ink season 6
  • search protocol host
  • battleship aurora
  • mtv kings of leon
  • connecticut limo
  • dove
  • bengals 80's
  • bengals undraftedbengals vs steelers
  • beau coup
  • la ink 3rd season
  • mtv jams
  • hp support 2133
  • chicago bears 61
  • new england patriots 65
  • chad ochocinco quickstep
  • overs
  • karachi
  • chad ochocinco height and weight
  • randy moss arrested
  • search engines no follow
  • tomatoes
  • battleship layout
  • mtv true life
  • search with image
  • chicago bears posters
  • connecticut secretary of state
  • search engines other than google
  • cspan michelle bachmann
  • hp support error 1005
  • vince young dadvince young eagles
  • randy moss wallpaper
  • search google cache
  • connecticut football
  • search engines usage statistics 2010
  • sweeping
  • search cfisd.net
  • la ink 04x01
  • tea party young people
  • dis windsor wi
  • battleship galactica
  • thinkpad
  • macau
  • c span yesterdayc span zelaya
  • bea 71 16
  • attack
  • search xml file
  • westminster
  • zara phillips fascinator
  • dis unplugged show notes
  • mummy
  • chicago bears 2009 roster
  • connecticut 104.1
  • bea nipa
  • new england patriots 1997 roster
  • bea exhibitors
  • battleship ipad
  • vince young endorsementsvince young foundation
  • greg olsen website
  • hp support center
  • freida pinto jeansfreida pinto kissing
  • 4pm cspancspan area 51cspan 90.1
  • mtv overdrive
  • sandman
  • cspan washington correspondents dinner 2011
  • chicago bears 96
  • bengals usa
  • la ink phone number
  • la ink 105
  • freida pinto plastic surgery
  • vince young released
  • mtv oddities
  • randy moss vikings 2011
  • greg olsen combine
  • wetsuit
  • tea party agenda
  • connecticut law tribune
  • bea luna
  • disassembledis boards
  • new england patriots 1996 roster
  • cspan goldman sachs hearingcspan history
  • hp support 6310hp support 7200
  • cheney
  • movers
  • bengals tryouts
  • hp support quick test pro
  • randy moss football cards
  • bengals youth jerseys
  • greg olsen puzzles
  • la ink price list
  • freida pinto miral
  • tea party birthday
  • awareness
  • chad ochocinco 15
  • tea party for kids
  • zara phillips baby
  • xanadu bengals
  • louvers
  • hp support chat
  • new england patriots espn blog
  • tea party obama
  • vince young jay cutler
  • gallbladder
  • morse
  • dis systems
  • new england patriots 07
  • battleship yamato 2010
  • mtv 2 schedule
  • battleship hacked
  • zara phillips engagement ring
  • impression
  • rojas
  • tea party lies
  • chad ochocinco and cheryl burke
  • vince young football camp
  • freida pinto green dress
  • la ink jabberwocky
  • webhosting
  • chad ochocinco stats
  • zara phillips kids
  • dis lyrics
  • hp support englandhp support forum
  • search 990 finder
  • romania
  • cspan question timecspan radio