MCU-in-the-middle attack on Diebold voting machine

Posted on Thursday, September 29th, 2011 in hacks, Prototypes, techniques by the machinegeek

Computerized voting machine vulnerabilities are nothing new, but this video demonstrating a man-in-the-middle wireless attack on a Diebold voting machine takes a different tact than most others. A vulnerability assessment team at Argonne National Laboratories was able to compromise the security of the Diebold machine, rendering it vulnerable by using a homemade MCU board at a total parts cost of less than $12. Adding the remote wireless capability would increase total cost to around $26.

The technique requires initial physical access to the target voting machine in order to install the board on the bus between the touchscreen and the mainboard. (The difficulty of achieving this would be relative to the amount of physical security surrounding the machine.) Once installed, the added hardware can intercept data from the touchscreen and alter input according to a preprogrammed routine, or according to instructions from the remote.

The researchers in this video are simply remotely pressing buttons on the machine’s 0-9 password keypad. It would appear to us that in order to perform an effective, undetectable hack on an election would require additional detailed knowledge about the progression of screens, choices and options available to the voter. This could be more effectively performed if voter’s button presses were transmitted for viewing by the attacker on a remote screen. This would require additional coding and hardware on the remote side, but would really turn this into a killer hack!

We’d be interested in seeing the hardware/software details. Looks like a (very) Dangerous Prototype!

Via Brad Friedman at Salon.

This entry was posted on Thursday, September 29th, 2011 at 3:18 pm and is filed under hacks, Prototypes, techniques. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

One Response to “MCU-in-the-middle attack on Diebold voting machine”

  1. Eddie says:

    Gahh.. . so voting becomes evn less secure. .. Bring back those steampunky mechanical units!

Leave a Reply

Notify me of followup comments via e-mail. You can also subscribe without commenting.

Recent Comments

  • KH: TPS62200 will get him to under 15uA, a bit better than the 20-30uA he mentioned. I would try the same thing. Switch some resistors in...
  • KH: Yeah, it's an end-user thing. Very few people would spend hundreds of hours on this kind of project and sustain it. It's more or less...
  • Max: Not quite a dinosaur if you've seen Big Hero 6 though... wait. You've watched it with your kids, didn't you? That's cheating...! ;) One of...
  • Edward Mallon: A visiting researcher dropped by our humble basement workshop with questions about the physical skill level students would need if they added one of our...
  • KH: And that looks really expensive... Only browsed the vid though, I'm an dinosaur so I had the sound off too. Nice of him to open-source...