Aug 07

The Diebold saga continues

Wired is reporting that Diebold was hacked:

Following an embarrassing leak of its proprietary software over a file transfer protocol site last January, the inner workings of Diebold Election Systems have again been laid bare.

A hacker has come forward with evidence that he broke the security of a private Web server operated by the embattled e-vote vendor, and made off last spring with Diebold's internal discussion-list archives, a software bug database and more software.

...

The hacker did not reveal how he subsequently breached the security of the Diebold staff site, which used SSL encryption. The file archive included source code to a login page that included a March 2 welcome message to one of the firm's election support specialists, suggesting the attacker may have compromised the employee's account.

Judging from internal mailing list discussions, Diebold management was either unaware of proper information security practices, or chose to ignore them out of expediency, experts said.

Again I am forced to ask why so many election officials are happy trusting something so important to a company so obviously lacking competent security analysts.