Attacking the Washington, D.C. Internet Voting System
jhalderm.com
jhalderm.com
Yeah, it sucks that the security was surprisingly bad. But I wonder, would any of my websites stand up to a group of high-level security researchers actively seeking to exploit them? I doubt it.
Within 48 hours of the system going live, we had gained near complete control of the election server. We successfully changed every vote and revealed almost every secret ballot. Election officials did not detect our intrusion for nearly two business days — and might have remained unaware for far longer had we not deliberately left a prominent clue.