Halderman's findings: (emphasis mine)
I show that the ICX suffers from critical vulnerabilities that can be exploited to subvert all of its security mechanisms, including: user authentication, data integrity protection, access control, privilege separation, audit logs, protective counters, hash validation, and external firmware validation. I demonstrate that these vulnerabilities provide multiple routes by which attackers can install malicious software on Georgia’s BMDs, either with temporary physical access or remotely from election management systems (EMSs).
I explain how such malware can alter voters’ votes while subverting all of the procedural protections practiced by the State, including acceptance testing, hash validation, logic and accuracy testing, external firmware validation, and risk-limiting audits (RLAs).
The most serious vulnerabilities I discovered include the following:
1. Attackers can alter the QR codes on printed ballots to modify voters’ selections. Critically, voters have no practical way to confirm that the QR codes match their intent, but they are the only part of the ballot that the scanners count. I demonstrate how the QR codes can be modified by compromising the BMD printer (Section 5) or by installing malware on the BMD (Section 7).
2. The software update that Georgia installed in October 2020 left Georgia’s BMDs in a state where anyone can install malware with only brief physical access to the machines. I show that this problem can potentially be exploited in the polling place even by non-technical voters (Section 8).
3. Attackers can forge or manipulate the smart cards that the ICX uses to authenticate technicians, poll workers, and voters. Without needing any secret information, I created a counterfeit technician card that can unlock any ICX in Georgia, allowing anyone with physical access to install malware
(Section 6).
4. I demonstrate that attackers can execute arbitrary code with root (super- visory) privileges by altering the election definition file that county workers copy to every BMD before each election. Attackers could exploit this to spread malware to all BMDs across a county or the entire state (Section 9).
5. The ICX contains numerous unnecessary Android applications, including a Terminal Emulator that provides a “root shell” (a supervisory command inter- face that overrides access controls). An attacker can alter the BMD’s audit logs simply by opening them in the on-screen Text Editor application (Section 10).
6. In a given election, all BMDs and scanners in a county share the same set of cryptographic keys, which are used for authentication and to protect election results on scanner memory cards. An attacker with brief access to a single ICX or a single Poll Worker Card and PIN can obtain the county-wide keys.
7. The ImageCast Precinct (ICP) scanner stores ballot scans in the order they were cast. A dishonest election worker (like that emphasized by the Defen- dants and their expert Michael Shamos) with just brief access to the scanner’s memory card could violate ballot secrecy and determine how individual voters voted (Section 11).
I show that the ICX suffers from critical vulnerabilities that can be exploited to subvert all of its security mechanisms, including: user authentication, data integrity protection, access control, privilege separation, audit logs, protective counters, hash validation, and external firmware validation. I demonstrate that these vulnerabilities provide multiple routes by which attackers can install malicious software on Georgia’s BMDs, either with temporary physical access or remotely from election management systems (EMSs).
I explain how such malware can alter voters’ votes while subverting all of the procedural protections practiced by the State, including acceptance testing, hash validation, logic and accuracy testing, external firmware validation, and risk-limiting audits (RLAs).
The most serious vulnerabilities I discovered include the following:
1. Attackers can alter the QR codes on printed ballots to modify voters’ selections. Critically, voters have no practical way to confirm that the QR codes match their intent, but they are the only part of the ballot that the scanners count. I demonstrate how the QR codes can be modified by compromising the BMD printer (Section 5) or by installing malware on the BMD (Section 7).
2. The software update that Georgia installed in October 2020 left Georgia’s BMDs in a state where anyone can install malware with only brief physical access to the machines. I show that this problem can potentially be exploited in the polling place even by non-technical voters (Section 8).
3. Attackers can forge or manipulate the smart cards that the ICX uses to authenticate technicians, poll workers, and voters. Without needing any secret information, I created a counterfeit technician card that can unlock any ICX in Georgia, allowing anyone with physical access to install malware
(Section 6).
4. I demonstrate that attackers can execute arbitrary code with root (super- visory) privileges by altering the election definition file that county workers copy to every BMD before each election. Attackers could exploit this to spread malware to all BMDs across a county or the entire state (Section 9).
5. The ICX contains numerous unnecessary Android applications, including a Terminal Emulator that provides a “root shell” (a supervisory command inter- face that overrides access controls). An attacker can alter the BMD’s audit logs simply by opening them in the on-screen Text Editor application (Section 10).
6. In a given election, all BMDs and scanners in a county share the same set of cryptographic keys, which are used for authentication and to protect election results on scanner memory cards. An attacker with brief access to a single ICX or a single Poll Worker Card and PIN can obtain the county-wide keys.
7. The ImageCast Precinct (ICP) scanner stores ballot scans in the order they were cast. A dishonest election worker (like that emphasized by the Defen- dants and their expert Michael Shamos) with just brief access to the scanner’s memory card could violate ballot secrecy and determine how individual voters voted (Section 11).
In case you're wondering about ES&S - check this out: https://www.vice.com/en/article/mb4ezy/top-voting-machine-vendor-admits-it-installed-remote-access-software-on-systems-sold-to-states
Vice
Top Voting Machine Vendor Admits It Installed Remote-Access Software on Systems Sold to States
Remote-access software and modems on election equipment 'is the worst decision for security short of leaving ballot boxes on a Moscow street corner.'
Now it’s no longer a top secret… my question is why was this information released?
👍1
Wars and rumors of wars...Russia is starting a civil war and it's repeating almost the same pattern as their own in 1919-1921. A Fourth Turning?
Forwarded from Amir Tsarfati
This media is not supported in your browser
VIEW IN TELEGRAM
Footage from the attack on the Wagner convoy on the M4 motorway on the way to Voronezh. Dozens of casualties reported!
Unless you are tracking international media, few are discussing this. Expect this to ratchet up over the next few days. Amir Tsarfati is an Israeli evangelist who was an officer in the Israeli military. He's tracking the events and reposting with observations.
An interesting thing happens when a civil war starts. Soon others may want to join the parade.
I've been attempting to verify what is happening in Russia. Although some footage shows advances in the Russian M4 highway, multiple images that are supposed to indicate a specific location do not match what Google earth shows. For instance, the M4 bridge over the Don or Oka Rivers are not split as a video is supposed to indicate. The video could have been taken earlier in the advance or it could be fake. More specific reports from multiple sources are needed.
👍3
The real problem machines may pose: No reasonable, viable means of authentication. https://petapixel.com/2023/06/29/artist-banned-by-midjourney-over-fake-photos-of-cheating-politicians/
Peta Pixel
Artist Banned by Midjourney Over Fake ‘Photos’ of Cheating Politicians
"I feel every possible way about it. I'd rather not be banned."
Happy Independence Day! Looks like our Creator is providing the fireworks right now!!🧨🎆🎇
🔥4❤1
"You can't have a democracy because it's a faith-based system" - Tucker Carlson. Serious question: can there be a distinct neutral civil government, or does government itself become a "god" - i.e. religious faith? Is the idea of worship been constrained by government? Doesn't true worship require assuring justice righteousness without compelling state-secular impositions upon others? For instance, demanding taxes from others when those funds will be used for abortions?
Forwarded from ULTRA Pepe Lives Matter 🐸 (Pepe Lives Matter)
Media is too big
VIEW IN TELEGRAM
Tucker doubles down on electronic voting machines and the lies the establishment repeats about January 6th:
"The lying about it was immediate. These are people who thought the election was stolen from them... There was no effort at all to convince people electronic voting machines are secure. Any country that has electronic voting machines by definition at risk of having its election stolen. No country that cared about Democracy would have electronic voting machines. There was no effort to reassure anybody. They immediately used it to make their political opponents shut up and send them to jail. They were just immediately lying about it with maximum aggression. That's the key for me. It's like an infection. They immediately recoiled when you asked any questions about January 6th."
Twitter
"The lying about it was immediate. These are people who thought the election was stolen from them... There was no effort at all to convince people electronic voting machines are secure. Any country that has electronic voting machines by definition at risk of having its election stolen. No country that cared about Democracy would have electronic voting machines. There was no effort to reassure anybody. They immediately used it to make their political opponents shut up and send them to jail. They were just immediately lying about it with maximum aggression. That's the key for me. It's like an infection. They immediately recoiled when you asked any questions about January 6th."