 Shannon Morse with DEF CON 30 here. I am joined by Harry Hersey. I am so excited. This is one of my favorite villages to join and check out and research personally from my own experience, the Voting Machine Village. And you have a very interesting machine to share with us this year. Yes, every year we try to find new machines and get new things for people to poke around. And we have been looking for this machine or something like this for quite a while. Ivanka Trump, it was widely published that Ivanka Trump registered a trademark for Voting Machine in China. And since there's no Chinese Voting Machines as such, we have been keeping looking and looking until now the machine popped up. We don't know if this is the same machine, but that's the reason we were looking for a Chinese Voting Machine. So in Alibaba we found a machine which is advertised with the pictures of Trump and Hillary Clinton. So crazy, crazy. And we ordered it. We got it. Here it is. So when did you order this machine? When did you see it pop up? We saw it popping up in July, in early July and we ordered immediately. Wow. And they ship it. And after that I saw it's returned to sender because it had two big batteries. Oh no. And then they removed the battery and they sent it. There was something else it eventually got just a week ago to us. So we were sweating because of all these shipping problems. But we got it in and we also wanted to know as much as we can from the vendor. So the company which we bought this from is claim that they had a designer and they said that this is at least in use in Nigeria. We also have discovered since it came here that there's a second company in China who is selling this under their own name. So we don't know what is the story. We are just investigating this. We didn't know about the other company until we saw the sticker in behind us. So that is not matching with the name of the company we bought it from. That's really interesting. It almost sounds like the same manufacturer is selling this under different brands or selling it out to other manufacturers. We don't know. That's very interesting. But again, the company which we contacted is different than what is actually the sticker behind. Right, right. Now so far this weekend we have seen a lot of interesting information coming out about this machine. You had a team come in here and write up an entire report which we have not seen yet. Yeah. So first of all, because this is a one-off machine, it's the only one, and also we have never seen anything, there was a dedicated team who went very methodological, documented everything, went step by step, got the forensic images out, and that's why it took them five and a half hours to get a route, because they actually didn't even turn it on for the first three hours. Oh, wow. But what did they find once they got in? Do we have any information about that yet? I mean, only thing what they have been reporting to me is running Android or Ubuntu Firefly. Oh. It has wireless, so it has LTE, mobile network, Wi-Fi, Bluetooth, all connectivity you can possibly imagine. We also found there is a UART port right on the main board. Exposed UART port. An exposed UART port, and I also noticed on this machine, and this is so interesting to me as somebody who picks locks. This is a very easy lock to pick. This is a very, very generic key, and a very generic lock, and apparently they sell it everywhere. You can find one over in the hardware village. Every single voting machine we have seen has a very simple lock. There is no secure locks in any of the machines. So with the machines as a whole in your village, I'm hearing that there's a lot of physical security issues, which if somebody could physically get access to the machine, obviously they would be able to own it, most likely. Basically all machines used in the United States, this is not used in the US, but all machines used in the US are designed at the time when cyber war was science fiction. So there has to be no security considerations to mention in any of these designs. So once you get physical access, the game is always over. At the same time, a lot of these machines do have a capability of being attacked remotely or in a wholesale basis. So there are different ways of getting in. Discovering the vulnerability is one thing, but weaponizing and thinking about how this can be misused and abused. That's the second thing. Have you found that a lot of people have come in here and found not only those physical penetration access, but also remote access as well? Yes, we have seen that from every year people are coming up with the new ways. One of the beauty of voting delicious for a lot of people, that's just the first time they have any access to voting machines. They don't know what has been discovered before. So there's a lot of rediscovery. People are finding something that we knew existing, but they might have a completely different approach how to get there. So there are all the time new ways to exploit the same thing which has been found before. So we know this one is currently not being used in the United States. Are any of the other voting machines that you have here currently being used here in the US? I believe everything else we have there really is in use in the United States. And by the way, one of the things where we had a secretary chief of local, very big county in the United States, and he was like, please tell me that this doesn't get to solve. I said, well, it shouldn't, but that is, actually honestly, this is not complying with the US requirements. So it should not be ever able to enter the US market. But we also know that this manufacturer has more voting machine models. So I have another model on the way here. Oh. And they were telling me that they have a whole catalog. So we don't even know what all they are making. So are you intending to bring some of those back in next year for DEF CON 31? Absolutely. I mean, the other machine just didn't arrive in time. Right, right. Well, hopefully we will see them next year. I'm sure that we will. I love the fact that you bring in all of these different machines for people to hack on and people to mess around with, get access to, just like you said. If I am brand new to this audience, if I am brand new to coming in here to the voting machine village, are there people that I can talk to? Are there ways that I can find access to these as an entry level hacker? Well, it's always every year, the people who have been coming earlier are educating and helping the next incomeers. Wonderful. So our mission is educational. Yes. So this is the primary thing. This year we also have been taking a big step towards debunking conspiracy theories. So there has been so many claims that there's this secret algorithm in these machines. Well, that's what we encouraged from day one, from Friday. Please pull the hardware, pull the firmware out and see yourself if there's a debunked myth or conspiracy theory. And there have been so many people doing exactly that. Have you found that brands of the manufacturers and brands themselves have been open to the idea of having the voting machines here? We have been openly inviting them every year. This year we had a, from the February-Marche conversation with three different vendors of not only voting system, but every system we used in Edox and environment, three vendors were indicating they're willing to come and then about a month before they say, well, we just realized this is even a year. So this is an election year, we are busy. Oh, wow. Well, hopefully next year. So we're trying, we're trying. We every year try and every year we get closer. I mean, this was the first time when we had a such an advanced talks. And we have had other kind of vendors here every year who have been exposing their stuff for hacking. We have a DARPA, Defense Advanced Research Project and their chips. We have here now Ori, who will have a mock-up of an election system as a hacking challenge for their identity management system. So we have an election-related things which are not in use in elections, but are something which can be related. So we all the time invite everyone. Are there any other challenges happening with the village this weekend? No, no, this is the only challenge, but it's also a remote challenge. So you don't have to be here. Oh, that's great, that's great. Is there anything that we didn't touch based on that you would like to share with our online audience? Well, I think the most important thing is that even when we talk about vulnerabilities in elections, never ever feel that that should be discouraging you to vote. Always vote where you're eligible, vote, participate. Also, if you really care, become a poll worker. We have a problem of hiring poll workers across the US. And last but not least, in the United States, there are different election laws in every state and different practice counties. People get very confused when misinformation is targeting and telling a story which might be touching one county because of the way they do it, but exposing it to different locations. Yes. So be very careful with misinformation, malinformation, because be very careful what you want to believe. I absolutely agree, yes. Please register to vote, especially if you have issues with what's going on in the political climate. That's so important. Our voices are the ones that change the world, so we need to make sure that we make those voices heard. Absolutely. Thank you so much, Harry. I really appreciate you talking to me today. I'm personally a huge fan, so it was really such a pleasure. Thank you so much. Have a great day. You too.