All systems have been decertified and will be replaced

Apr 17, 2015 09:08 GMT  ·  By

One would expect the government and authorities responsible for state elections to pay much more attention to the security of voting machines than anyone else, but in Virginia, it turns out that those in charge of the whole system forgot how easy it has become to crack a password.

A study conducted by the Virginia Information Technology Agency and published by The Guardian reveals that the AVS WinVote systems used in no more, no less than 24 elections are running copies of Windows XP Embedded 2002 that haven’t been updated since 2004.

Some machines still have bugs and security vulnerabilities that were first spotted more than 10 years ago, the report says, but the company in charge of deploying updates and making them fully secure apparently forgot about this.

Passwords? What passwords?

And if you’re simply amazed at how little they actually care about the election system, it gets worse.

The AVS WinVote machines were obviously protected with an admin password to block unauthorized access. But what’s shocking is that the admin password was… “admin.” What’s more, the wireless network that these machines were connected to was also protected with a password, this time “abcde.”

While there’s no evidence that any of these systems got hacked over the years, the study claims that attacks would have only needed basic tools to do it. And with a password such as “admin,” that’s pretty obvious. But what does basic tools actually mean? Fingers?

It appears that the very same machines were also used for state elections in Mississippi and Pennsylvania, but they eventually arrived in Virginia, where they served for elections in the last years.

The only good news is that Virginia has already decertified the machines and is now looking to buy new ones that would be more effective and more secure.

And yet, no one says anything about the company that built these devices or the one that was responsible for their security and maintenance. Who’s responsible for handling systems that were used in three presidential elections with so much ignorance?