Categories

MCU-in-the-middle attack on Diebold voting machine

Posted on Thursday, September 29th, 2011 in hacks, Prototypes, techniques by the machinegeek


Computerized voting machine vulnerabilities are nothing new, but this video demonstrating a man-in-the-middle wireless attack on a Diebold voting machine takes a different tact than most others. A vulnerability assessment team at Argonne National Laboratories was able to compromise the security of the Diebold machine, rendering it vulnerable by using a homemade MCU board at a total parts cost of less than $12. Adding the remote wireless capability would increase total cost to around $26.

The technique requires initial physical access to the target voting machine in order to install the board on the bus between the touchscreen and the mainboard. (The difficulty of achieving this would be relative to the amount of physical security surrounding the machine.) Once installed, the added hardware can intercept data from the touchscreen and alter input according to a preprogrammed routine, or according to instructions from the remote.

The researchers in this video are simply remotely pressing buttons on the machine’s 0-9 password keypad. It would appear to us that in order to perform an effective, undetectable hack on an election would require additional detailed knowledge about the progression of screens, choices and options available to the voter. This could be more effectively performed if voter’s button presses were transmitted for viewing by the attacker on a remote screen. This would require additional coding and hardware on the remote side, but would really turn this into a killer hack!

We’d be interested in seeing the hardware/software details. Looks like a (very) Dangerous Prototype!

Via Brad Friedman at Salon.

This entry was posted on Thursday, September 29th, 2011 at 3:18 pm and is filed under hacks, Prototypes, techniques. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

One Response to “MCU-in-the-middle attack on Diebold voting machine”

  1. Eddie says:

    Gahh.. . so voting becomes evn less secure. .. Bring back those steampunky mechanical units!

Leave a Reply

Notify me of followup comments via e-mail. You can also subscribe without commenting.

Recent Comments

  • T.O.: For $29 I can get 10 STM32F1 mini boards plus external debugger, free shipping. $0.99 would get me bare microcontroller if I need own board....
  • KH: However innocent it may be, I'm not impressed by the choice made by the creator of the image. Now, I'm not the most politically correct...
  • cyk: A simple google search for "free arm ide" lists CooCox on the first page: http://www.coocox.org/index.html Supports a ton of different ARM M0/3/4 micros and all...
  • Stennly: Despite the popularity of STM32s, it may not be the best place to start. As mentioned already, the Silicon Labs gecko family is cheap to...
  • Pete Juliano: Since this posting on my blog I have received an excellent suggestion on how to quickly disconnect the 48 VDC from the amp so you...