AlgoSec Security. Visibility. Governance
   
 
Press Releases
News Coverage
Events
Case Studies
 

VULNERABILITIES WITH PROPOSED RFID E-VOTING INITIATIVE IDENTIFIED BY ALGOSEC CTO

Research Conducted at Tel Aviv University by Dr. Avishai Wool Reveals Multiple Attack Vectors for Disrupting New Voting Technology

Reston, VA, April 20, 2010 – Dr. Avishai Wool, co-founder and CTO of AlgoSec®, the leading provider of firewall operations and security risk management solutions, recently identified a number of vulnerabilities associated with a new RFID-based Israeli e-voting system. From labs in the School of Electrical Engineering at Tel Aviv University where he is also a professor, Dr. Wool and his students uncovered the vulnerabilities after security testing and analysis of the new e-voting system.

Under the proposed e-voting system, introduced by the Finance Ministry last year, voters hold an empty smart card against a voting terminal (computer) as they select their desired candidates. Through RFID, the empty smart card is populated with the cardholder’s votes. Upon completion, the voter inserts the smart card into a ballot box whereby election officials verify if there is a discrepancy between the figures recorded by the computer and those in the smart cards.

Dr. Wool, who has also assisted in securing RFID technology used today in American passports, and his team built homemade hacking devices out of simple, cheap materials like disposable cameras and copper pipes from cooking appliances that were capable of disrupting the cards' radio frequency (RF) signals. Their work was presented at the IEEE RFID conference in Orlando, FL, just last week.

“RFID-based e-voting is not used in any other country and there’s a reason: at its current stage, the technology is simply not secure enough,” said Dr. Wool. “For all its technological sophistication, the system can quickly be rendered useless by even amateur hackers with minimal RF knowledge and a few household materials.”

In his lab, Dr. Wool and and hist students Yossi Oren and Dvir Schirman assembled three different attack mechanisms for disrupting the new e-voting technology. One mechanism was an RFID “zapper” made from a disposable camera. Dr. Wool and his team replaced the camera’s bulb with an RFID antenna to create an electro-magnetic pulse capable of destroying data on nearby RFID chips such as ballots. "In a voting system, this would be the equivalent of burning ballots — but without the fire and smoke," said Dr. Wool.

A second attack “jammed” the radio frequencies that read the smart card. The card’s transmissions though designed to be read by a receiving antennae no more than 2 inches away, can be blocked from more than 20-30 meters away using a low-energy transmitter powered by something as simple as a car battery. In this way, entire voting centers could feasibly be taken offline by hackers across the street.

Another, much more sinister and sophisticated attack demonstrated by Dr. Wool is a “relay attack” which confuses a voting station into believing it is communicating with an RFID ballot when in fact it is being sent a false communication from a hacker using homemade transmission equipment.
 



AlgoSec’s Firewall Analyzer is a must have for anyone who manages a rule set of 100 or more.


Network World Magazine



By creating FireFlow using the AFA engine, AlgoSec has effectively created a solution that can automate the entire network security lifecycle...


Frost & Sullivan Analyst



We quickly saw a clear return on our investment with the AlgoSec Firewall Analyzer...


Anton Spitzer,
Infrastructure Services, Porsche Informatik



The AFA allows us to get all of our firewall information in one place, providing IT Governance and visibility where it did not exist.


Anton Spitzer,
Infrastructure Services, Porsche Informatik



Network security VARs, take note: AlgoSec’s FireFlow network policy change workflow management software is the next hot-ticket item for customers.


eWeek Magazine



The AlgoSec Firewall Analyzer fills a critical need for us by automating what was a manual, labor intensive and error prone process.


Anton Spitzer,
Infrastructure Services, Porsche Informatik



By utilizing AFA we no longer require the services of an external source to perform an audit.


Ruza Manojilovic,
Manager Security Operations Teranet



It (AFA) easily and quickly provided Atos Worldline with the ability to understand, track and verify changes to our firewall infrastructure…


Massoud Kamran,
Security Consultant at Atos Worldline Belgium



AlgoSec Firewall Analyzer’s automated and intelligent analysis lets us know the implications of a change and avoid potential risks which save us time, effort and money.


Peter Johannes,
head of Security and Architecture Policy at Atos Worldline Belgium



AlgoSec’s Firewall Analyzer has helped us significantly improve our overall network security.


Ruza Manojilovic,
Manager Security Operations Teranet



Using AFA’s turnkey solution for PCI DSS has been invaluable for us in terms of time and effort.


Ruza Manojilovic,
Manager Security Operations Teranet

 

The integrity of the company (AlgoSec) and its employees surpassed our expectations and has raised the bar for what we look for in other vendors as well.”


Lutz Bleyer, Chief Security Officer,
FIDUCIA



By utilizing AFA we no longer require the services of an external source to perform an audit.


Ruza Manojilovic,
Manager Security Operations Teranet.



With the AFA we can focus on what is most important to Porsche Informatik – our customers.


Anton Spitzer,
Infrastructure Services, Porsche Informatik



AlgoSec affords us realizing operational efficiencies in global security policy management and compliance.


Hugo Van der Veeken,
Atos Worldline SA/NVsecurity department head