Election Data Analyzer
Закритий канал
Without election integrity we do not have a nation.
Показати більшеКраїна не вказанаКатегорія не вказана
997
Підписники
Немає даних24 години
Немає даних7 днів
Немає даних30 днів
Архів дописів
This quote from Defcon 2017 was so choice, I am just going to put it here without further comment. Page 20 for those of you reading the report for your self.
This is a funny (not so funny) picture of a CF slot safe guarded with a “secure screw” found at Defcon 2017. The problem is that you can go to your local hardware store and buy the screwdriver for it.
I had to look up what CF meant (because I am a dummy). Turns out the acronym shows up in the NIST System and Network Security Abbreviations dictionary.
This dummy thinks it must be really important to protect the magical CF thingamajig with a better whatchamacallit if it show up on a NIST standard, right?
But there again, that is not the machine companies problem, it is on the local government to provide the physical security…..but I am sure our local officials understand all of that?
https://www.nsi.org/pdf/reports/NIST%20Network%20Security%20Acronyms.pdf
Defcon 2017 hacker conference was able to boot up one of the machines from a disk and use it as an entertainment device with "Nyan Cat".
Apparently Chris Krebbs attended the conference too.
The most secure kitty ever.
https://archive.org/details/6432002-Voting-Village-Report-defcon27/page/n17/mode/2up
Routers and Splunk Logs, we have all heard of them, but what does it mean for a non-IT expert (like me) and or our election supervisors. Here is an answer “for dummies” written by a dummy.
These machine companies state that their equipment is “not designed” to be connected to the internet. But, they are connected to an internal private network and each machine has it’s own private internal address on the network. A private address begins with 192.168.XXX.XXX and is not accessible from the internet. So far so good. The PROBLEM is that using a Network Address Translator (NAT), you CAN connect devices on a private network to the public internet. The NAT is a ROUTER that internally converts the private address into a PUBLIC address.
Suppose you are careless about setting such a network up? Suppose as a machine vendor you say, “Gee, the NAT Router is not part of MY system, it is YOUR problem local government. If it is wrong, that is on YOU”. See how they deflect and push down the responsibility to the local folks who are left holding the BAG of $%#!? Now suppose you have something called SPLUNK running. This is the LOGGER of LOGS on a network (for dummies like me). If you had the SPLUNK logs, you could examine all of the LOGS on your private network for nefarious behavior, like, which outside IP address accessed the local machines through the NAT.
As an IT dummy, I want to ask this DUMB question.
Why do these machines have a NAT if they are not supposed to be connected to the internet?
http://www.faqs.org/rfcs/rfc1631.html
Routers and Splunk Logs, we have all heard of them, but what does it mean for a non-IT expert (like me) and or our election supervisors who are supposed to safeguard of election infrastructure? Here is my best really simple answer “for dummies”.
These machine companies state that their equipment is “not designed” to be connected to the internet. But, they are connected to an internal private network and each machine has it’s own private internal address on the network. A private address begins with 192.168.XXX.XXX and is not accessible from the internet. So far so good. The PROBLEM is that using a Network Address Translator (NAT), you CAN connect devices on a private network to the public internet. The NAT is simply a ROUTER that internally converts the private address (which is likely not a unique address in the world) into a unique PUBLIC address. Now, you have the gateway to the world opened up.
Suppose you are really careless about setting such a network up? Suppose as a machine vendor you say, “Gee, the NAT Router is not part of MY system, it is YOUR problem local government. If it is wrong, that is on YOU”. See how they deflect and push down the responsibility to the local folks who are left holding the BAG of $%#!? Now suppose you have something called SPLUNK running. This is the LOGGER of LOGS on a network (for dummies like me). If you had the SPLUNK logs, you could examine all of the LOGS on your private network for nefarious behavior, like, which outside IP address accessed the local machines through the NAT.
As an IT dummy, I want to ask this DUMB question.
Why do these machines have a NAT if they are not supposed to be connected to the internet?
And here is what they do in France. Paper voter roll book that you sign with ID, paper ballot dropped in a clear glass box. Apparently the ballots are mailed to you but you have to drop them off in person. What a travesty we have been brainwashed into accepting these machines.
I hope Mr. Gould does not mind me posting a snippet of the report (Appendix A) here for those of you who don't want to read the entire report. These are non-compliance items related to the Voluntary Voting System Guideline (VVSG). His conclusions in RED.
Mr. Doug Gould concludes (p 103) the Mesa County forensic report with this warning: “With elections beginning on a large scale very soon, with the massive security vulnerabilities, the weakness presented by this uncertifiable Voting System, the abject failure of the Voting System testing laboratory with the expired accreditation and lack of proper oversight by authorities, remediation of these issues before pending election IS NOT POSSIBLE.” (my emphasis)
So, what are we to DO to fix it? Do we really need to AUDIT and CANVASS to make the point? If the goal is to VOTE differently, this analysis is conclusive enough. I have spent 100s of hours analyzing voter rolls and built and distributed a free tool to help others do the same. But, at this point, we need to focus on the machines. PERIOD.
After you know the port, then you can download this other FREE app to your phone and start flipping vote totals. https://apps.apple.com/us/app/sql-server-mssql-by-sqlpro/id1176218536
Feel like scanning your area for open ports to your voting machine MS SQL databases? No problem. Just download this app to your phone. Makes it real convenient to find that Port 1433. And the app is FREE!! https://apps.apple.com/us/app/fing-network-scanner/id430921107
What a joke. Telnet was used to access the machine server. "The commonly-known default SQL Service, TCP Port 1433 is specifically ALLOWED by this firewall rule." This is so bad in my opinion, it HAD to be done on purpose. Imagine leaving home with the key in the lock to your front door front door left in the lock. And these are certified based on RLAs?
Imagine you have two records in your machine database of “1 - Trump 56,894 votes” and “2 - Biden 31,536 votes”. Then imagine you right click on those records and change “1” to “2” and “2” to “1”. You have just flipped the election in the machine database. No warnings, no passwords, nothing to stop you. Actually, you don’t need to imagine it because it can be done with the terrible way these machine databases have been designed. Read the report. There are even screen shots for the doubters.
Here is a quote directly form the Mesa forensic report #2: The presence of prior election databases on the EMS Server also offers an extensive and convenient repository for copy and paste modification of election data, not only for the 2020 election but for any prior listed election as well."
If you are familiar with the work of Garland Favarito at https://voterga.org/ his team has found EXACTLY that which is evidence of cutting and pasting in the CVR in Fulton County GA. This is called “Simultaneous Discovery”.
USB flash drive attack vectors also exist on these machines. How many machines are out there? 10,000 or more in the US? Each machine can have, what 2-3 ports? So, there are at least 30,000+ USB ports out there to protect. Here is a list of 29 attack vectors from research done 4 years ago….and the list grows. How much time and tax dollars are wasted just protecting USB ports through procedural and physical security measures? Let’s redirect that energy to paper hand counts.
https://www.bleepingcomputer.com/news/security/heres-a-list-of-29-different-types-of-usb-attacks/
Wouldn't it be interesting to survey how many of the vendor employees and other folks involved in maintaining our election machine infrastructure are properly qualified with industry standard certifications like CISSP, for example? Maybe We The People should start asking questions like this to our Counties? Those of us in private industry need professional credentials...just asking.
https://www.isc2.org/Certifications/CISSP
One line of thinking keeps popping out in reading the Mesa County forensic report #2. The author states that (paraphrasing) in some cases it is not possible to prove that a device was or was not connected to the internet even though the capability is there, due to the lack of log files which were deleted. So, the MSM latches on to the “not possible to prove” part while ignoring that it SHOULD be possible to prove the machines were NOT connected to the internet by reviewing the logs. That is the purpose of the logs, to prove the NEGATIVE. Beware of this MSM propaganda.
It is bad that MS SQL server is installed on the election machines when it is not needed to run an election. It is worse when MS SQL server is configured to ENABLE three different types of network configuration protocols (Shared Memory, Named Pipes, TCP/IP). But it is beyond belief to me that we are using machines that have EXPLICIT CUSTOM firewall rules that might permit backdoor access to these servers from anywhere in the world. It is not as if someone forgot to disable of enable something…no…a firewall rule was created to permit backdoor access!
Here is a DoD reference public servants who manage election machines should be aware of….unless of course they are working with a Trusted Vendor in which case never mind. Maybe a better idea is to create a new department in every SoS office called “The Department for Cutting Edge Cyber Security Research for Tax Payer Funded Election Machines (DCECSRTPFEM)”. They can use our tax dollars to stay current on all the latest cyber threats in perpetuity. It should be easy to find qualified people to fill these new government jobs. I “vote” for that.
https://public.cyber.mil/stigs/
Secure voter registration databases?....NOT. Let me ask a "stupid" question. Instead of moving towards more and more centralization of voter registration, why don't we use "local control" or 100% air gapped registration rolls controlled by the County? Wouldn't it be much more difficult to hack the entire US registration database if it was widely distributed? It seems to me tech folks are incapable of thinking of a solution which doesn't involve MORE and MORE tech.
https://www.whitehatsec.com/blog/2020-election-security-the-urgent-need-to-address-vulnerabilities-in-voting-systems/
