Voting machine source-code leak shows odd subroutines
boingboing.net
boingboing.net
The code I helped write had to run on as little as 8 megabytes of RAM on an embedded MS-DOS-like OS (our version targeted Windows CE, but it had to run on the older, 386-ish machines). It was written in very compact ANSI C, had data in plain-text files and certainly didn't need a relational database embedded in the ballot.
All this reeks of incompetence.
Akin to how in Chicago we say, "Vote early, and vote often!"
It's almost as if they just cared about the short term exposure and not the longer term goal.
Correction: " It appears the files were NOT VANDALIZED and will open in MS-SQL Server 2005."
Claim: "This in turn revealed thousands of lines of Microsoft SQL code that appear to control the logical flow of the election. Stuff like:" (example follows)
The example they give looks like some code which adds a new candidate to the ballot.
This looks like an embarrassing debacle so far.
I can't download that guide at the moment, but the part quoted says:
"Self-modifying, dynamically loaded, or interpreted code is prohibited, except under the security provisions outlined in section 6.4.e [sic - see note below]. This prohibition is to ensure that the software tested and approved during the qualification process remains unchanged and retains its integrity. External modification of code during execution shall be prohibited. Where the development environment (programming language and development tools) includes the following features, the software shall provide controls to prevent accidental or deliberate attempts to replace executable code"
and
6.4.e: "After initiation of election day testing, no source code or compilers or assemblers shall be resident or accessible."
I think that most readings of that would interpret it to mean that SQL statements to create tables would be permitted, but that the interfaces to the databases should be secured.
The whole thing is a beat-up.
Such accusations should only be made with very solid evidence in hand to avoid blowing the media attention on a 'dud', then next time when there is real evidence you'll get a small fraction of the response.