Risk Assessment of Danaher Controls DRE Electronic
Total Page:16
File Type:pdf, Size:1020Kb
Voter Verification of Accurate Ballot Tabulation http://www.seventy.org/electioninfo/DREReceipts2004.html Philadelphia City Commissioners Office Report on Proposed "Ballot Receipts" Risk Assessment of Danaher Controls DRE Electronic Voting System and Philadelphia Procedures Prepared by: Bob Lee, Voter Registration Administrator March 28,2001; Revised – March 9, 2004 A. Receipt Proposal There numerous news articles about a small number of individuals who assert that existing Direct Recording Electronic (DRE) voting systems are not reliable because they lack a paper ballot or paper audit trail to verify each voter's individual ballot selections. These individuals have suggested that DRE voting systems should provide a printed receipt of voter selections that each voter can view either before, or after, executing and recording their ballot. The proponents assert that a system that provides receipts would provide the following security advantages over current DRE systems: 1. It would allow a voter to view a printed record of all of their candidate selections to ensure that the DRE device is accurately recording their ballot selections. 2. The ballot receipts could be used after an election to provide a paper audit trail to conduct a recount to verify the electronic results reported by the voting device. These individuals claim that computerized systems require these receipts because a person intent on corrupting the voting process, or programming errors, could result in a DRE device indicating to the voter that it was accurately recording the voter's selections, while actually altering the selections and recording votes for candidates not selected. A superficial glance by a layperson might find the receipt suggestion attractive and based upon reasonable concerns. However, the proponents have not explained how an individual intent on fraudulently altering results would obtain access to the electronic voting system and voting devices in light of the security features of the system or procedures in place to prevent such events. They have also failed to explain how this activity would go undetected. This paper attempts to highlight issues related to these proposed ballot receipts, including: · The standards for testing and using existing DRE systems; · The capabilities and functionality of existing full-face ballot DRE systems; · The questionable value of these proposed receipts: · The pragmatic issues related to receipts; and · The impact of receipt production and review on the voting process. This review evidences the fact that the addition of ballot receipts will not provide the outcome desired by proponents, that they are not necessary, not feasible and could be detrimental to the voting process. B. Existing DRE Voting Systems After numerous and extensive constituent needs assessments Philadelphia decided to procure a DRE voting machine that provides a full face ballot sheet, allowing voters to view and vote all candidates and issues on the ballot without the need for scrolling or viewing numerous pages or screens. The full face DRE voting devices have provided a smooth transition for voters as Philadelphians had voted on full face ballot mechanical lever machines for more than fifty years. After a comprehensive procurement and proposal evaluation process Philadelphia selected the Danaher Control's 1 of 17 10/29/04 13:28 Voter Verification of Accurate Ballot Tabulation http://www.seventy.org/electioninfo/DREReceipts2004.html Guardian Voting System which includes 3526 ELECTronic 1242 DRE voting machines and Guardian, Danaher’s Election Management Software. 1. Independent Testing & Qualification The Danaher Controls Electronic Voting System, both the ELECTronic 1242 DRE Voting Machine and Guardian Election Management Software, have been tested, and listed as qualified, for Federal Elections Commission standards by an Independent Testing Authority designated by the National Association of State Election Directors. The NASED designated ITAs for testing the Danaher EVS were Wyle Labs for EVMs, and Nichols Labs for EMS. The ITAs test for FEC standards that include technical specifications to be used consistently as guidelines to ensure that systems are accurate and secure. The standards include functional criteria along with technical requirements for hardware, software, quality assurance, and documentation. The standards also include testing procedures to ensure that systems meet the requirements. Qualification tests encompass a selectively in-depth examination of the software; an inspection and evaluation of the system documentation; tests of hardware under conditions simulating the intended storage, operation, transportation, and maintenance environments; and operational tests verifying system performance and function under normal and abnormal conditions. The ITA evaluates the completeness of the vendor's developmental test program including sufficiency of vendor tests and sample tests of the vendor's test modules. The FEC standards and testing by designated ITAs is designed to reduce risks of failure by helping State and local election officials ensure that the system they buy, and that the public vote on, work accurately and reliably. 2. Examination & Certification for Pennsylvania The ELECTronic 1242 EVM and Guardian EMS were last examined by the Secretary of the Commonwealth in 1998 and certified for use in Pennsylvania. Pennsylvania election laws require that voting systems be examined and approved for use in conducting elections. The Secretary of the Commonwealth designates an examination team to conduct tests on voting equipment to insure compliance with the Pennsylvania Election Code. This testing reduces risk by helping local election officials in ensuring that systems they buy have work in accordance with state law. City Commissioners personnel will perform conditional and final acceptance tests on the EVM that include voting scripts to verify compliance with Pennsylvania laws. 3. Proven Usage Approximately 43,000 Sequoia Pacific AVC Advantage or Danaher Electronic 1242 DRE, full face ballot, Electronic Voting Machines (EVM) are currently used across the country in conducting elections for Federal, State, and local offices. Both the Danaher and Sequoia full face DRE voting devices have been used extensively to conduct elections. These devices have proven track records. The City Commissioners Office conducted research of DRE EVM usage and contacted 26 jurisdictions using over 23,000 DRE voting machines to assess experience with DRE system accuracy, reliability, durability, security, ease of use, and suitability for Philadelphia. Approximately 20,000 Danaher ELECTronic 1242 EVMs are in use in 13 states. Various models of these 1242 EVMs have been used by some jurisdictions for more than 17 years. In 1998 Delaware selected these 1242 EVMs for its' statewide voting system. Team members visited four jurisdictions to observe the use of two proposed full-face DRE systems in use to conduct official elections. The City Commissioners observed the use of the selected Danaher Controls EVS in Franklin County, (Columbus), Ohio consisting of 2800 ELECTronic 1242 DRE EVMs, 7 RTCs and 734 Election Districts. 2 of 17 10/29/04 13:28 Voter Verification of Accurate Ballot Tabulation http://www.seventy.org/electioninfo/DREReceipts2004.html The minor problems discovered during our review have been almost exclusively caused by human error and most relate to timeliness in returning cartridges used to report unofficial election results. These EVMs have proven through almost two decades of use to be durable, accurate, reliable, and easy to use. 4. Security The EVS is secure from unauthorized outside access, provides backup power, backup of data and is designed with redundancy to insure retention of data. 4.a ELECTronic 1242 Electronic Voting Machine Security Each DRE voting device contains all required general-purpose election logic and capabilities in its firmware on circuit chips. However, it does not in itself have any knowledge of the specific election that is being conducted. The EVM firmware is not modified for the conduct of an election. The machine firmware resides on integrated circuit chips, which are sealed into the machines. The machines cannot execute instructions not residing in the chips, and the changing of the chips is very difficult to accomplish and very easy to detect. Any attempt to fraudulently alter or switch voter selections would require that the fraudulent switching programs be contained in the circuit chips within each DRE voting device. Such an effort would require that chips in each DRE voting device be changed. Additionally any potential manufacturer of the fraudulent chips would need to know the candidates to be placed on the ballot and which positions on the DRE voting device would be assigned to each candidate. Only City election personnel have access to the DRE voting devices. However, City personnel do not have access to the encrypted firmware, or replacement chips required for any alteration. Only Danaher Controls and the escrow agent have access to the source code. Only Danaher Controls, through its proprietary hardware processes, can provide firmware on circuit chips. However, Danaher Controls does not have access to City DRE voting devices so they would be unable to change the chips without City knowledge. Any firmware upgrades provided by the vendor to be installed on the City's voting devices would be installed by City civil service EVM technicians and would be followed by extensive conditional and final