Diebold, Die

It’s no surprise that there are plenty of ISVs and IT companies out there who hack together half-assed “solutions” instead of full-fledged products, but most of them aren’t responsible for mission-critical type things like, say, tallying votes to elect our next leaders.

So it’s really shocking to find out that Diebold—maker of ATMs and other banking equipment—implemented a voting system that is not only easy to hack, but relies on Microsoft Access as its database.

Claude Muncey’s comment is especially scary:

… not only were the Access .mdb files essentially unprotected by passwords … but that ability to easly [sic] read the data has been used to get around the operating problems—in other words some jurisdictions rely on it being insecure to get their work done. (Italics mine.)

(Link via Electrolite.)

2003.10.22 · permalink