Security Evaluation of ES&S Voting Machines and Election Management System Adam Aviv Pavol Cernˇ y´ Sandy Clark Eric Cronin Gaurav Shah Micah Sherr Matt Blaze faviv,cernyp,saender,ecronin,gauravsh,msherr,
[email protected] Department of Computer and Information Science University of Pennsylvania Abstract EVEREST was the first major study of ES&S voting sys- tems, despite the system’s popularity (ES&S claims to be This paper summarizes a security analysis of the DRE the world’s largest e-voting systems vendor [1], support- and optical scan voting systems manufactured by Election ing more than 67 million voter registrations with 97,000 Systems and Software (ES&S), as used in Ohio (and many touchscreen voting machines installed in 20 states and other jurisdictions inside and outside the US). We found 30,000 optical ballot readers present in 43 states [4]), and numerous exploitable vulnerabilities in nearly every com- only the second comprehensive study that examined all ponent of the ES&S system. These vulnerabilities enable components – from backend registration systems to fron- attacks that could alter or forge precinct results, install tend ballot casting – of any electronic voting system. In a corrupt firmware, and erase audit records. Our analysis ten week period, our seven-member team was tasked with focused on architectural issues in which the interactions analyzing the nearly 670,000 lines of source code that between various software and hardware modules leads to comprise the ES&S system, encompassing twelve pro- systemic vulnerabilities that do not appear to be easily gramming languages and five hardware platforms1.