Magazine

US Election 2020: ‘Why I Bought a Voting Machine on eBay’

Posted on the 04 October 2020 by Thiruvenkatam Chinnagounder @tipsclear
US election 2020: ‘Why I bought a voting machine on eBay’ US election 2020: ‘Why I bought a voting machine on eBay’ US election 2020: ‘Why I bought a voting machine on eBay’

"Earlier this year, I attended a conference and was shocked to find that you could actually buy voting machines on eBay. So I bought one two months ago and was able to open it and look at the chips ".

Beatrice Atobatele is attempting to hack one of the most commonly used voting machines in the United States to search for security vulnerabilities, but not with criminal intent.

Beatrice is actually one of over 200 people who signed up for a volunteer group of security experts and hackers called the Election Cyber ​​Surge.

And by understanding how this machine works, he hopes he can ensure that any vulnerabilities are fixed.

"I ignored the authentication itself," he says.

"I'm still learning and trying to find new vulnerabilities that may not yet be known."

The problem with the American elections, Beatrice and others say, is how disjointed they are.

Most estimates suggest there are around 8,000 separate electoral jurisdictions.

The equipment and voting methods vary greatly.

And every step of the process is vulnerable to hackers and human error.

In the voting booth, there are many different systems, from direct-recording electronic voting machines to voting devices and paper-based systems.

And the more a system is digitized and connected, the greater the risk of some sort of computer interference.

Like all volunteers, Beatrice's research is conducted outside of her daily work.

And as a passionate soccer player and mother of two football-obsessed daughters in New York City, she must adapt volunteering to a busy schedule.

He had no intention of getting into cybersecurity at all.

But 17 years ago, he lost more than $ 1,000 (£ 775) after hackers used his account to buy five pairs of Nike sneakers.

It spurred her on a new career path.

And now he is a security specialist for the state and local government.

Despite the pressure she is under, Beatrice is desperate to help the elections run smoothly.

"Every vote cast should count," he says.

"The thing that worries me is some kind of ransomware attack on these machines on the same day, which would prevent people from voting.

"This is my worst case scenario."

A ransomware attack occurs when hackers take control of a computer system or encrypt data until victims have paid a ransom.

Beatrice and the rest of the Election Cyber ​​Surge group know that time is running out.

It is too late to upgrade the physical equipment for the vote.

But it's still on the lookout for critical software flaws and offers to help election officials better understand their machines and any potential problems.

The group is led by the University of Chicago Cyber ​​Policy Institute, which seeks to "open a line of communication between election officials and a network of volunteers for direct communication on cyber security issues" until the vote on November 3. .

Hackers across the United States have signed up to help secure elections or deal with any attacks that could derail an already complicated process.

"It's not just voting machines on voting day that could be vulnerable to cyberattacks," said Christopher Budd, another Washington state volunteer.

"With my hacker hat on, going after registration lists are compiled right now in the US would be a great way to break an election.

"If I'm not registered or if my registration record is altered in some way, even if the voting system is completely secure, my vote may not count."

And again, the disconnected nature of the electoral system adds risks.

The security and even the actual structure of voter registration databases vary.

And an FBI notice ahead of the 2016 election warned that foreign actors had had access to some of these databases.

With the further complication this time of electoral officials working remotely trying to plan for restrictions on Covid-19, Christopher is concerned.

"I always try to reduce the escalation of things in my work

"But there is no doubt that the threats in this election are more intense.

"Everyone is focused on the vulnerability of this election.

"I am willing to give all the time necessary to help out."

Christopher's experience is in communication and crisis management.

As a consultant, he deals with cyber attacks that bring large companies to their knees.

He deals with everything from panicked CEOs to angry IT managers from his rural office overlooking the woods.

And when he has to pull the nights, the only company he has is the local deer peeking out of his window, wondering what it is.

Over the course of his 20 years of experience, Christopher has developed a secret weapon for when things really hit fans.

"I'm a huge fan of classical music," he says.

"When I really need to focus and work fast, there's only one place I turn to: Camille Saint-Saëns Symphony No. 3."

Christopher hopes he won't have to "get the Camille out" in the next month, but he's ready.

The group is also devoting enormous efforts to data protection.

The latest elections in the United States and the United Kingdom were hit by high-profile "hacking and leaking" operations.

In 2016, the email accounts of the Democratic National Committee and some of the top Democrats were hacked and then leaked.

And in the 2019 UK general election, documents on the UK-US trade talks were stolen from a parliamentarian's email account and leaked online.

Jason Kirkland specializes in securing "endpoints": computers and phones.

But he's less concerned with highly sophisticated zero-day attacks than basic techniques.

"I don't think we'll see attackers burn precious zero days where they can get into important networks with much simpler methods," he says.

"It will likely be things like malicious software that infiltrates everyday office applications that really pose the threat.

"I want to help people get the foundation right.

"For example, don't download malicious files or click malicious links."

US and British security services have publicly blamed Russian hackers for "hacking and leaking" operations and numerous other disinformation campaigns to influence voters and sow discord on social media.

Russia denies the accusation.

And other countries are also accused of cyber activities that damage democracy.

Earlier this week, Twitter removed about 130 accounts linked to Iran, according to which it had tried to interrupt the public conversation during the first presidential debate.

Disinformation campaigns are a major concern that volunteer hackers say they don't have the time or the ability to address.

But Jason is committed to helping keep the bad guys out the best he can.

Before turning to hacking and cybersecurity, he was a dispatcher for local state troops.

And his time in law enforcement is what forced him to get involved.

"I'm definitely a follower of the rules," he says.

"And my wife teases me all the time.

"But the rules and the laws are very important.

"And we have to support these things.

"Right now I feel uncomfortable.

"Electoral officials have so much to expect.

"So I really hope I can help you."


Back to Featured Articles on Logo Paperblog