If I get a "stamp of approval" to tamper with a voting machine, I could get to the point of being able to tamper, but not do anything. Or I could (if it was safe to do so) have it add 30,000 votes to a false candidate. It would be similar to how "white hat" hackers need to be able to show a POC but not actually do any harm.
Hell even having "false elections" could be a useful first step.
It wouldn't be perfect, but it could at least start figuring out where the weakness are.
Here's a 2012 paper from a team at the University of Michigan detailing a "mock election" gone wrong:
Title. Attacking the Washington, D.C. Internet Voting System
Abstract. In 2010, Washington, D.C. developed an Internet voting pilot project that was intended to allow overseas absentee voters to cast their ballots using a website. Prior to deploying the system in the general election, the District held a unique public trial: a mock election during which anyone was invited to test the system or attempt to compromise its security. This paper describes our experience participating in this trial. Within 48 hours of the system going live, we had gained near-complete control of the election server. We successfully changed every vote and revealed almost every secret ballot. Election officials did not detect our intrusion for nearly two business days—and might have remained unaware for far longer had we not deliberately left a prominent clue. This case study—the first (to our knowledge) to analyze the security of a government Internet voting system from the perspective of an attacker in a realistic pre-election deployment—attempts to illuminate the practical challenges of securing online voting as practiced today by a growing number of jurisdictions.
Thanks for the link! I look forward to reading the paper.
Yeah, from what I've read I really don't think any type of online voting system is the way to go. Interesting that they pretty much owned the server. Without reading, I suspect that has more to do with the system architecture than it being a voting application.
If I get a "stamp of approval" to tamper with a voting machine, I could get to the point of being able to tamper, but not do anything. Or I could (if it was safe to do so) have it add 30,000 votes to a false candidate. It would be similar to how "white hat" hackers need to be able to show a POC but not actually do any harm.
Hell even having "false elections" could be a useful first step.
It wouldn't be perfect, but it could at least start figuring out where the weakness are.