I don't know about you, but I couldn't believe these systems were certified. Check out the
Security Access Controls and
Other Known Problems sections, they will shock you!
<<SNIP>>
http://www.ss.ca.gov/elections/consultant_report_item_5c.pdfState certification testing was conducted 19-22 July, 2004, at Diebold offices in Coppell, TX, to certify two versions of the AccuVote Optical Scan (AV-OS), versions 1.94W and 1.96.4, with the
new GEMS 1.18.19. The AV-OS, version 1.94W, was previously certified in California under an earlier version of GEMS. This testing was to ensure continued compliance with California election code and rules under the new GEMS 1.18.19 and for the newer AV-OS Version 1.96.4.
The testing for this version configuration showed compliance with the California Election Code but
has broadly published security weaknesses similar to those reported earlier in reports
about the Diebold DREs. In spite of these weaknesses, the tested configuration provides
better security and functional support than the currently certified version and is recommended
for certification in replace of the current version, with suitable Technical Security Plan
procedures compatible with those suggested earlier for the Touch Screen DREs.
The following security weaknesses were noted in testing:
Item GEMS TS OS
1. Weak security of the basic server and operating system Yes n/a n/a
2. GEMS database is accessible by DAO-supported programs Yes n/a n/a
3. GEMS passwords are too weak Yes n/a n/a
4. SSL/TLS encryption may be disabled Yes uses n/a
5. Default encryption keys published (but may be changed) Yes uses n/a
6. Default passwords/pins are hardcode Yes Yes n/a
7. Some passwords/pins restricted to four digits. Yes Yes Yes
8. Key locks on access panels are not secure Yes Yes
a. Memory card not secure Yes Sealable
b. Serial/Parallel ports not secure Yes Yes
9. PS/2 Keyboard port not secure Yes n/a
10. (new) Modem not secure Unused Yes
The election procedures for the AV-TS and AV-OS are being rewritten to address some
of these items but are not finished at in time to be included in this report.
<</SNIP>>