
Tuesday's
Brad Blog brought my attention to the famed Princeton Diebold (NYSE: DBD) Virus Hack, last summer's break-in of Princeton University's Diebold touch-screen voting system. Princeton's study found that to steal an election, all someone had to do was gain access to the system and slip a vote-swapping virus onto a single machine, which then had the potential to affect every other machine in the country and -- Ta da! Election stolen, game over.
After discovering the hack, Diebold, which specializes in technology that people use to access their services whenever and wherever they may choose, posted a picture of "the key" on their Web site -- the same key that opens every single voting touch-screen machine in the system. Of course, J. Alex Halderman, one of the people involved in the Princeton Hack, had a friend who discovered the Web page and realized that he could very easily and cheaply make a working copy of that same key right from the photo. Voting security? Not so much.
While Diebold eventually removed the photo of the key from its Web site, it remains to be seen how many saw it and had the same thoughts as Mr. Halderman's friend and how many other voting machines, file cabinets and office supplies are at risk.
Even more frightening, it was announced that Diebold "recently earned certification from the General Services Administration to deliver security integration services that meet the requirements of the Homeland Security Presidential Directive." In addition, Diebold was hired to secure the founding documents of America: the U.S. Constitution, the Declaration of Independence and the Bill of Rights. Maybe it's just me, but the Virus Hack debacle highlights holes not only in Diebold's machines' securities, but Diebold itself. I for one, wouldn't want them working on matters of national security -- if their machines are so easily hacked into, what would that say about our country? I'd like to think that at the very least, our country's security leaders learned a few things from this incident, but I'm going to have to assume that they didn't.