Skip to content
Search AI Powered

Latest Stories

Kids at a Hacking Conference Just Exposed Serious Vulnerabilities In Our Election Systems

Kids at a Hacking Conference Just Exposed Serious Vulnerabilities In Our Election Systems

Will the vulnerabilities be addressed in time for the midterms?

At the DEFCON hacking conference in Las Vegas, kids aged 8-16 had the chance to hack into simulated US election systems — and they found it alarmingly quick and easy.

Emmett Brewer, an 11-year-old Texan, was able to access a duplicate of Florida’s state election website in under 10 minutes. Once inside, he changed the vote tallies in the site to award himself 239 billion votes in less than five minutes. An 11-year-old girl was able to perform the same hack in about 15 minutes.


A 17-year-old from Washington went farther, using easily Googled shutdown commands to completely crash a midterm election simulation. All vote counts were lost, and the website presented an execution error. It took him 10 minutes. “And I’m not even a very good hacker,” he said.

These election vulnerabilities were on show at DEFCON 26, an annual hacking conference in Las Vegas. This year, organizers launched the Voting Machine Village, and invited youth attendees to manipulate candidate names and vote totals in hardware and software used in several battleground states. About 50 kids participated in the Village, and they found plenty of vulnerabilities.

In the Diebold TSX machine,widely deployed in hundreds of counties and cities nationwide (including the swing states of Pennsylvania, Ohio, Wisconsin and Virginia), hackers found SSL certificates that expired in 2013 which means each machine is subject to all vulnerabilities in that software cataloged in the past five years. One hacker was able to upload a Linux OS to a Diebold TSX andthen programmed the machine to play gifs and music.

TheDiebold Express Poll 5000 was found to be even more vulnerable (again). That machine’s memory cards are easily accessible at the top of the machine, and another market-purchased card with alternative information and vote tallies can be inserted in its place. Switching the two cards can be done in less than five seconds. Once removed, the original cards can be accessed by a hacker to collect unencrypted supervisor passwords and voters’ personal data. Voter information gathered included home addresses, drivers’ license numbers, and the last four digits of Social Security Numbers. In the most embarrassing cases, the unencrypted password was “Password.”

All told, Voting Machine Village co-organizer Nico Sell said that more than 30 children were able to hack into other states’ website duplicates in half an hour or less.

“These are very accurate replicas of all of the sites,” Selltold the PBS NewsHour. “These things should not be easy enough for an 8-year-old kid to hack within 30 minutes, it’s negligent for us as a society.”

In response to the event’s widespread publicity, the National Association of Secretaries of State (NASS) issued a statement re-confirming their states’ election security.

“While it is undeniable websites are vulnerable to hackers, election night reporting websites are only used to publish preliminary, unofficial results for the public and the media. The sites are not connected to vote counting equipment and could never change actual election results,” NASS said in a statement. They added that they welcome cooperation from the hacker community to eliminate any vulnerabilities.

The good news is that Brewer, the 11-year-old hacker from Texas,is on board with increasing voter security and confidence.

"I'm just trying to help the world," he said.

More from News

Paul Castle; 'The Secret Ingredient' children's book cover
@matthewandpaul/TikTok, Paul Castle Studio

TikTokers Rally Behind Blind Author Whose Inclusive Kids' Book Got Review-Bombed By Conservatives

The author of an inclusive-inspired children's book received tons of support from the internet after his book was banned from a bookstore and review-bombed by conservatives.

Paul Castle is a blind influencer who wrote and illustrated a children's book called The Secret Ingredient. It is about two male penguins who adopt a baby and discover "the secret ingredients" to being a happy family.

Keep ReadingShow less
Two king penguins
Wolfgang Kaehler/LightRocket via Getty Images

Wildlife Park Renames Penguin They Thought Was Female After It Turns Out To Be A Gay Male

A UK wildlife park renamed a king penguin they thought was female after some confusion concerning her inability to lay eggs. After observing the penguin constantly flirting with another male penguin, staffers realized it was a gay male.

Birdland Park and Gardens in Bourton-on-the-Water, Gloucestershire, is home to the UK's only king penguin breeding colony.

Keep ReadingShow less
Robert F. Kennedy Jr.; Amaryllis Fox Kennedy
Rebecca Noble/Getty Images; Tristar Media/Getty Images

We Now Know The Real Reason RFK Jr. Is Pushing For His Daughter-In-Law To Help Run The CIA

Robert F. Kennedy Jr. is facing criticism for pushing President-elect Donald Trump to hire his daughter-in-law Amaryllis Fox Kennedy to be Deputy Director of the CIA after an exclusive Axios report revealed he is doing so because he believes the CIA had a role in assassinating his uncle, President John F. Kennedy.

SCOOP: RFK Jr.'s daughter-in-law is making a push to serve as deputy director at the CIA next year — and RFK Jr. is making calls on her behalf.

[image or embed]
— Axios (@axios.com) December 10, 2024 at 3:23 PM


Keep ReadingShow less
Screenshots of YesMadam Logo and YesMadam's email to employees
YesMadam

Company's Stunt Claiming Workers Were Fired For Having 'Stress At Work' Awkwardly Backfires

Home salon services company YesMadam sparked immediate backlash after claiming they surveyed employees about their workplace stress before sending out an email letting those stressed workers know they were fired—except YesMadam claims it was a marketing stunt gone wrong.

An initial post alleged that YesMadam had dismissed approximately 100 employees following the results of a mental health survey indicating widespread workplace stress. Anushka Dutta, identified as an employee, shared a leaked email from the HR department on LinkedIn.

Keep ReadingShow less
Taylor Swift
Emma McIntyre/TAS24/Getty Images for TAS Rights Management

Taylor Swift Gave Massive Bonuses To Everyone Who Worked On 'Eras Tour'—And Fans Are Applauding

Taylor Swift's monumental The Eras Tour has come to a conclusion after 21 months of performing around the globe.

The tour itself raked in over $2 billion in sales, performing to around 10 million people. The singer has, accordingly, rewarded those crew who helped the massive endeavor go well with bonuses totaling about 10% of overall sales.

Keep ReadingShow less