Muhabi Chisi concedes attempts to hack MEC system, unveils ghost user in Malawi polls
Malawi Electoral Commission (MEC) director of ICT, Muhabi Chisi came out of the cocoon on Thursday to reveal that during the results management time of May 21 tripartite elections, there were many attempts to hack into the MEC results management system (RMS) but they all failed.

Chisi was making a simulation of the results management process in the Constitution Court as MEC’s third and last witness in the presidential elections case which is in day 58 so far.
He also took the time to unmask the ghost user who was touted to have been entering fraudulent results into the system.
“The system is secure and no one can hack into it. During elections there were many attempts from all over the world to hack into the system but they failed,” he explained.
Immediately, there was an objection from Malawi Congress Party (MCP) lawyers who argued that Chisi was giving new evidence which was not the subject of the simulation.
This was sustained and the MEC IT Director moved on to present other issues.
In his presentation, Chisi started by explaining what a result management system is and how the biometric kits were configured to ensure that they cannot be used in a different constituency.
Chisi also explained that the RMS used a blind double entry system whereby there were two data entry clerks who could enter same data and the system could accept the data when the two entries were the same.
He also explained that the RMS was developed in-house through a consultative approach with stakeholders including directors of elections in political parties and their ICT experts with from Development Partners.
“Prior to implementation we ran two dry tests and there was full participation of all stakeholders including parties, media and international observers,” he said.
In his simulation, the MEC ICT Director used Lilongwe South Constituency, which is currently vacant to demonstrate how the RMS worked because they were working on a live data base which was used for the May 21 elections and the only space available was for Lilongwe South.
Step-by-step Chisi countered presentations by MCP witness, Daudi Suleman who introduced to the concept of ghost user who was adding fraudulent results into the RMS.
Chisi told the court that once results are received into the system, they could not be corrected and any change or overwriting if done, the system could issue a trigger.
Then Chisi unmasked the ghost user by running a query that approved batch results in the system after the Commission approval.
“Approving one result at a time could take time. There was no reason to hold on the results from the public after the Commission had approved them, so we used a query to update the status of the results in the system that were all approved by the Commission,” he explained.
Chisi showed the five judge panel, from the result management system, that all results updated as batch did not have user mentioned. This has been one of the basis of the evidence of Daud Suleman – witness for second petitioner MCP presidential candidate Lazarus Chakwera – that since the user could not be known then he was a ghost.
MCP lawyers had also objected for the MEC team to use a flash disk just to copy queries for the demonstration in fear that the flash disk might contain malicious codes that can affect the system.
This was sustained and the MEC team had to type the codes direct into the computer.
Muhabi explained that there was no link or connection between the RMS and the MEC website where all the polling stations results were posted.
Follow and Subscribe Nyasa TV :
Kodi Muhabi amalowetsa zitizo Mu computer mwakemo zomwezija za tippex or zosavomeledwa let me know plz
Muhabi,muhabi,muhabi, abwana mwandimvetsa kukoma mumachedwa kuti, sibwenzi anthuwa atathawa kale
Attempts from all over the world to hack the system but failed hhmmm komatu komatu kukometsa ukuku mwaonjeza mpaka all over the world eeeeh
Muhai
You will certsinly go to jail
Munkhondya to be witness
School me plz what is the writer trying to say here I will retype * chili showed the five panel judges of con’court the result management system that all the results updated as a ‘batch’ did not have user mentioned. Then it says this has been one of the basis of the evidence of days Suleiman, that since the user could not be known then that is a ghost user. Was this Muhabi saying yes or not my understanding is poor open my mind and eyes plz only here.
Chisi not chill
Rubbish in, Rubbish out
Bumboclaat! What a bull crap testimony! He says the RMS could not be hacked! Nonsense! Where is the independent penetration test report to justify that? What he said was mere speculation and being an IT expert as he is claimed to be, he should know better what evidence to bring to ascertain those b/s claims. Where are the logs to show numerous hacking attempts? This guy is an idiot and should just go drown himself in Naperi river!
just wait agalu inu…………………
Inu o Salima ndi O chasika tinakuwuzani kuti belekanani pa May 2019 lero Chisi nyamata wokoza ma IPAD mafoni a MEC mwamuwonatu . Wosati ayi ine ,ine ndinali ku Airtel ine Eni Ndine dolo wabela wowo Ine dekha ine ndi zazimbaya
Muhabi has successfully bewitched the petitioners. Poly IT versus Soche Technical IT. Zolilalira checheche! kungobwera Muhabi kuti ziiiiiiiii! Oipa athawa yekha opanda omupitikitsa.
ALI KUTI MTAMBO APITESO KUMA DEMO
No need for cross-examination. Or re-examination. Wait for Dec 19.
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk they have failed again kkkk
kkkk tsopano maganizo anu ndiokuti chisi wapangitsa case MEC NDI DPP kupamban???????? ohok……..ai time is ticking,koma kukhala anthu kuthawa sizinaoneke
kkkkkkkkkkkkkkkkkkkkkkkkkkkkk akuganiza choncho
Muthawa ndinu kkkkkkkkkkkkkk
Here is the puzzle. Chilima and counterparts claim to seek justice. No objection. Philosophically this implies innocence on their part otherwise their seeking of justice would be hypocrisy if they are not exonerated from any wrong doing in the process. Now when Mihabi Chisi highlighted that there were attempts to hack the system the Lawyers for SKC and Laz were quick to object. If they are indeed seeking justice wouldn’t they be interested to learn who were attempting to hack the RMS. I fear that statement alone by Chisi if pursued further would open a can of worms and none of the justice seekers would be exonerated. Which begs the question, ‘who needs justice?’ Malawian politicians are written as such. It is the common man who needs justice. Robbed by these politicians whether from the opposition or in power. None of these guys is innocent and their “seeiing of justice” is for selfish purposes.
speaking things other than what is in your sworn statement is an act of being off an order. That would simply mean you are bringing a different evidence other than what you told the court in the first place.
Big YES
I HAVE FOUGHT A GOOD WAR!!!! I’M OUTER!!!!!!!! MEET YOU IN 2024!!!!!!!!!!!!
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk mwalephera amwene
Mundifunsire a Chisi kuti kodi amakonda akazi a mtundu wanji tisakesake tiwapatse.Ntchito agwira kkk
Indeed you are a Zombie. Ignorant person like you making conclussion. Leave this to the five judges please. Umbuli winawu abale
just an opinion
The problem of MEC and DPP are listing so much in that Animal for big and ugly face you call Kaphale. That guy he is trying all means to win this case! He is trying to coach everybody who stand as a witness for MEC and DPP to pay fake evidence and witness in the court so that will take them into trouble. Why Chisi refuse other day to backup and put back data saver which Mec removed in their kit? when Suleman was demostrate how Results was manipulated? Why now he big mouth and start bra, bra, bra, Mr Chisi watch out.
kkkkkkkkkkkk muzionaaaaaaaaaaaaa!!!!!!!!!!!
I expalined before that as an ICT expert, Daudi was misleading naive computer users. But computer pundits had it that the explanation wasn’t even fit for an ICT Auditor. I explained last time that even I myself could simply use an excel spreadsheet to determine results. The description by Daudi about relational databases schemas doen’s fit at all i an audit process. It is the owner of a system that may have a wholesome description of the system they own. Things like batch processing, creation of users is merely at the discretion of the system owner. Good lick opposition. But the way I see this case, you have scored less than 10% to the appeasement of the judges!!!! PETER MUTHARIKA RETAINS PRESIDENCY. GOD HAS DEFENDED HIM!!!
Ict expert 😲😲 ndiwe galu weniweni
Not only Galu but omwa mazi ometera. Mphevu yeniyeni ikati yadya ndizosala ku mthiko. Anthu ena kunvesa chisoni
Nenani mfundo zany akulu
Suleman has a case to answer – he tried to hack into MEC RMS system
YAAAA, KOMA CHISI ANAKONZA!!!! MPAKA MALAWYER A CHILIMA NDI CHAKWERA KUTHAWA KUFUSA MAFUSO!!!! HAYAYAYYAAAAS!!!!! KKKKKKKKKKKKK
No crossexamination, Muhabi chisi anaumba
Someone says Muhabi Muhabi with someone wanting to use a flash disk my foot. Cadet sizilibwino apa. The simulation of Muhabi Chasi has failed the following
1. Not to prove that MEC announced results if they were 100% approved by the system.
2. Failed to prove that data was not deleted in the system including that of Dowa east as proved by Sulemani
3. Has not justified the use of private emails instead of the secure MEC Emails
4. Has not justified the presence of ghost user in the system.
5. Why the results were uploaded into the system 4 days after results were announced .
6. Has not explained how MEC data system was hacked 2days before elections
7. Has not justified why computer generated results had different result sheets from the monitor signed manuals
8. Has not justified why ICT team and ghost user were approving results instead of Commissioners as dictated by law
9. Has not justified how millions of data was being approved in a millisecond
10. Has not justified why and how 1 MEC kit was used to process results for 2 constituencies in Thyolo
This empty simulation. No wonder Muhabi Chisi opted for a flash disk.
manja mwanu
Unfortunately Suleiman is not an IT Expert, so all this listed above, he lied to you and you believed him.
Chimenecho ndicho chibakale cha ma petitioners , samala mano amenewo Jenala
Why did MCP and UTM lawyers not ask all these questions?????????
THIS GUY IS TELLING THE TRUTH ONLY THAT MOST PEOPLE DON`T WANT THE TRUTH
palibe zachilungamo apa man
Inu simukuziwa za ICT ndiye khalani chete mudikire ngati angakwanitse kuchita defend zomwe wanena zija coz anzake amatengatu ma screen shots komaso mlandu uli apa wagonatu pa tipex, jubliket, ndi zina oterozo coz mu computer mumangoikidwa zilizonse zabwino komaso zoipa
For us who did IT, batch processing is known to be risky is situations that accountability and transparency is paramount. Batch processing is kutapa osasankha in chichewa.
If the RMS does not show the user when approving a batch then the system is weak. Any IMS must show the user in the audit trail.
It is apparent that it was a scheme by MEC to rig the election in favour of APM. What else do you expect these MEC staff to say.
It is clear they gave access to the ghost user to manipulate RMS data, hence, they deny that he was there.
It looks like evidence from the ICT part is secondary. The case rests on what was being entered into the system – was it altered or not?? Again there are other holes from Sulemans simulation (testimony) of which holes still exist. The deleted data trails etc. Has Chisi explained anything on that? Even the batch thing of approving results he claims to have used remains questionable. For a highly sensitive exercise like vote approval, why using no ID?? Ngakhale some quarters from MEC/DPP side appear excited, they just need to be very careful of what might arise from cross-examination. NB: I am mindful of most comments here written in Chichewa. Their analysis appear shallow and nonsensical
I like this. I totally agree with you. The RMS adds no value to this case as it relied on the primary source which was the approved results sheets. The outcome will be determined based on the primary source not secondary source.
There was ample opportunity to challenge what Suleman has presented. That opportunity was squandered. Chisi was there when the RMS was torn to pieces. What he presented yesterday represents how the RMS is supposed to work. Suleman analysed how the RMS was used! That’s a big difference.
I Agree chisi has failed he just outlined how the system without prearranged plan to a manipulate it work.The thing is he has failed to overshadow suleman who clearly using MEC system on how data was entered and manipulated.Simple question to CHISI is it true that the system through scripting could change results.THIS IS WHERE SULEMAN SURPASSED YOU HE DID SHOW USING THE SAME SYSTEM AND WITH PROOF.NO NEED TO CROSS EXAMINE EMPTY SIMULATION.
Atumbuka nonse mwagwanayo.Kodi let me ask mtumbukas are bad hearted tribe in Malawi.Atchukatu ndi zonyasa anthuwa.Kuda”kuzikonda”sankho”kuzimva nzeru etc mulape atumbukanu mukaphya kumwamba alomwe akukalowa
Gondolosi every day akalowe kumwamba??
Alomwe akuba kkkkkk?? chitamanyazi
Unfortunately, this egg has already been scrambled. Noone can unscramble it.
I do not know if most commentators are able to tell that Chisi has gulfed by disclosing and accepting ghost user who only entered batches.Was that the design of the system? Who was batch logger? Why did he hide his name?
Unless the MEC system was deliberately weakened even with batch processing a user is supposed to be identified????????It is only wuhawi or witchcraft type of an operating system that would hide a user. Was non identification of user in batch processing disclosed in the MEC systems operational procedures manual, Mr Muhabi Chisi? Hiding behind the batching processing to hide users and compromise the trail of the data processing is still a case of not having credible data Mr Chisi???? Why was that allowed ???
Koma iwe Chisi. You have made me loose my mind. My wife thinks Iam getting mad. You are really a computer genius.
You have pulled down Sulemani and Bandulos’ textacles.
I am thinking of going to Chakwera house to commit suicide in his bedroom
Msiska will be taken to Zomba mental hospital. He didn’t expect this last blow 😂
Iyi nde mbuli ya IT, one has to be accountable for any transaction done in a system whether batch processing or single transaction is involved.
One need to know who did the batch processing, it cannot be blank.
Salaries are processed in batches at banks, but they are able to know the user who did the batch processing.
Awa nde mmm, IT ya chiboma
Guys uyu chisi uyu anapanga. Whethet he was lying or not but you could get the sense that the guy is indeed an ict expert and that he once worked for rbm in this field osati ict expert was self taught like daud and bendulo. By the way bendulo and daud are ict entrepreneurs and not experts. Even in usa yesterday, they had a team of four professors giving their professorial views on whether trump should be impeached or not and this was being done before the lower house. Even the founders of Google have a ceo with masters in ict becoz they themselves know that as entrepreneurs their job was done and now somebody should run the firm as a corporate entity. Ndiye izi zomanena kuti a daud and bendulo they are experts then you are missing a point about who an expert is. Chisi our expert kaya watinamiza or not. You have made my day.
Mbwiye !
You are really a product of CDS ( Schools ) . A very useless person who cannot even translate what he has written and indeed an expert in broken English.
Give us a break in your useless contributions.
I know you cant appreciate my views becoz you are partisan to the borne marrow. Otherwise you are useless.
Mr Mbwiye, hahahahahahahahahaaha the IT man has just do exactly to your level of understanding, are you aware that your man as you claim has just forgotten that all the data which were loaded in the system is what the auditors refused to verify because they were useless and full of alterations? Are you were and or know the letter form Alufandika forcing the auditors to verify them before they display on the screen? What was the response from the auditors? Therefore what you are clapping hands for here in this case just simply means how your level is, the data again was entered by unknown user, did you heard him saying that? That is the ghost dude, can I tell you where the ghost user was? Listen to what Munkhondiya said,, there was another desk after his desc to verify votes,,, who was the in charge of the Desk? The other person including him as they were rotating, this Desk Mr Mbwiye is a desk of verification, now the ghost was here, so what your man has shown the Court is what everyone would want it to be unlike the way it was done. So keep your hands clean from this mess otherwise I see the same hands taking the rope and hang yourself.
mmmmmmm
Now tell me what degrees Steve Jobs had to build Apple and Bill Gates to build Microsoft. Kuganiza kwachinetefe kumeneko sir! Knowledge is at your fingertips nowadays and you don’t need to sit in a classroom to acquire it and have someone give you a piece of paper to say that now you are an expert. Expertise comes from working on solutions to problems for a long time in a specific job as it is said “a sailor is not made expert in calm seas”.
zawadi ndi chembwana tikukuziwani mayi
na Anu eni..tikusakani January Mulandu ukatha
Why shoot the messenger for reporting facts? It’s unfortunate commentators here you want to hear what pleases you and not contrasting info….the World doesn’t operate like that, people are entitled to their opinions and you can’t force stop them….MCP and UTM supporters you are ultra right, a dangerous position, shift to the center please and be liberal
Thank you for trying cadet Zawadi Chilunga where is your friend Chembwana Mukolokosa.Inu ndimbambande posapota DPP Milonde wakupasani zambiri
Help me pse! What does the name Muhabi mea ns?
Mfiti, witch
kikikik that’s atumbuka/ngoni name which means wizard ( pronounce as muhawi)
Join the MUHABI MEANS MFITI kkkkkkkkkkk
Mfiti
Means witch or wizzard
Mfiti kkkk
Chisi tell them Kuti Suleiman was one of the ghost users
Ngakhale It sindiyiziwa koma mkuluyi walongosola bwino kuti ngakhale ndimachokera kumunda kozala sawa koma ndamunva .ndiye Kaya Che Selemani Zina amanena anazitenga kuti ? INE pheee kumvera basiii
For sure it was Chilima’s team who were trying to hack the system. That we all know. 😅😅😅
Muhabi muhabi muhabi, how many times have I called you? Shake my hand,,,, sulaimana mutu wayima
We need Peter in the dock please ! Please !
Makape inu Peter ndi bigman osati adodolido akulirawo.Ayisova we are in Spain mtima ziii.
Unenesko…..
Wakumana nayo mtumbuka, wachepa wena suleimani awa.
Few hours later no comment.😁😁😁😁
One Chisi has demonstrated his ignorance about his capabilities in IT. He failed to simulate using Presidential mode of the system because the system is live. Is he aware of backup and restoration.
In SQL, there are only two commands he can use to update data, INSERT is used to insert data in a database table, UPDATE is used to update the data in a database table.
If its an insert, and you want to insert 100 rows of data, you will have to type 100 rows in your SQL, this is also true for UPDATE query. If the table contains a field for user ID, it means you need to include the user ID in the query.
For example: Insert command will go like this, our table name is results, the table will capture polling centre ID, Candidate1 Results, Candidate2 Results, Candidate3 Results and UserID(Name);
The query will be like this;
Insert into results( pollingcenterID, Candidate1Results, Candidate2Results, Candidate3Results, userID) VALUES
(1001, 234,14,452,20),
(1002, 228,15,5663,19),
–
–
–
–
(1100, 635,450,253,5);
when you run this command it will insert all the hundred records including the userID. this means a script cannot be run without writing these command and rows manually. Username was supposed to be captured. Deliberately the userID/name was left out.
If it was an UPDATE command, still userID was supposed to be captured as well.
the command would be like this;
Update results
set Candidate1Results = 251, Candidate2Results = 400, Candidate3Results=0, UserID= 8 Where PollingCenterID = 1001;
Here the Where is a condition to only affect polling center id 1001
So his assertion on SQL lacks basis, he is ignorant of what he said
Zimenezi zimafunika mu khothi tu osati pa nyasatimes. Olo mutatifotokozera ife zikuthandizani chani? Kkkkkkk
Mwangoyamba kuphunzira kumene, tadikirani muphunzire bwino bwino kaye. Do you really know why we use scripts
Is a script generated automatically or manually written
My friend I am also an ICT expert. Any mistake or deletion or update to a live record is a serious issue. You can’t temper with the insert, update or delete to live data that is already under contest in court. Next if he deletes an already existing record by mistake and the court calls for independent auditors, who will be to blame when he logs into the system with his credentials? I know dates can be used but its wiser to stay away from live data in the system and rather simulate new data. If the courts calls for use of presidential data, a due process can be followed and papers signed accordingly for due diligence to play around with live data. I guess you understand principles of the Data Protection Act irregardless of the fact that you are in court!!!
What was the use of backup server. Is the system still live? Are they still entering data
The flow diagram will explain what was supposed to be done. All will be as presented to stakeholders during presentation. Any deviation will be tantamount to cheating. Kaphale thought UTM lawyers will go straight to cross examination. They want to bring Muhabi to submission tomorrow and that they will do with ease. Did he touch on orphan data base?
IWE DAUDI SULEMANI WOPENGA IWE. MANYAZI BWAZNJIIIIIIII
Please people make a proper follow up of the deliberations Tomorrow and at the end of cross examination of Mr Chisi people will appreciate how the IT system of MEC performed during the last elections. Mind you people voted manually and the data was being entered by Data Entry Officers. So the computers could do nothing on its own apart from what was entered manually.
Shut up!!!
Yes we did!!! All we witnessed were the running away of MCP and UTM lawyers from Muhabi Chisi the destroyer kkkkkkkkkk
I found the presentations by Muhabi Chisi not edifying at all. In fact they fall 80% lower than what was presented by Daud.
I am surprised that his lawyer was equally awful during cross examinations
Mpaka pano no comment ndinakuuzani ibe way back in February pa river walk koma kusanva kkkkkkkkkkkkk
Achina ndani ndani pa amazon po tulukani ndi sulaimana wanuyo timuone
Muli kuti kadxibwerani kkkkkk
But even batch processing needs to have an identified user
Auzeni anthu awa. Yes who was processing those batches?.Malawi pamafunika computer lessons ndiwofuna kuwapunzira ku Primary school.
Muhabi I salute you. Wagwetsa a Tonde awili Chakwera and Nchilima
That’s the end of the game.parties should now start campaining for 2024 still mcp and UTM will never rule ,over my dear body
Muhabi is a custodian of the MEC RMS….I was surprised to hear Daudi Sulemani is an IT expert… When we were busy going to school in the late 90s and early 2000s, Daudi Sulemani was busy playing basketball at LL Community Ground, not a single day did I see him carrying books or entering the community library…..in Falls Estate….lero nkumati Dolo wa IT….masanje eti
Yes
kwambiri he a true technocrat