Security News > 2021 > March > On the Insecurity of ES&S Voting Machines’ Hash Code

On the Insecurity of ES&S Voting Machines’ Hash Code
2021-03-16 11:36

It turns out that ES&S has bugs in their hash-code checker: if the "Reference hashcode" is completely missing, then it'll say "Yes, boss, everything is fine" instead of reporting an error.

It's simultaneously shocking and unsurprising that ES&S's hashcode checker could contain such a blunder and that it would go unnoticed by the U.S. Election Assistance Commission's federal certification process.

It's unsurprising because testing naturally tends to focus on "Does the system work right when used as intended?" Using the system in unintended ways is not something anyone will notice.

Another gem in Mr. Mechler's report is in Section 7.1, in which he reveals that acceptance testing of voting systems is done by the vendor, not by the customer.

Acceptance testing is the process by which a customer checks a delivered product to make sure it satisfies requirements.

To have the vendor do acceptance testing pretty much defeats the purpose.


News URL

https://www.schneier.com/blog/archives/2021/03/on-the-insecurity-of-ess-voting-machines-hash-code.html