In recent years, hackers have increasingly targeted digital systems voting used in elections. A breach of the systems can affect the outcome of an election, so these types of attacks can have an impact on an entire country. Hacking incidents on devices have occurred in the US , as well as in the 2014 Indian election.
These incidents show that special attention must be paid to electronic voting devices. It is necessary to ensure three things: the integrity, transparency and security of the devices.
Many countries argue that for electronic voting devices to be secure, the technology they use must remain secret. On the other hand, many people do not trust systems that have been certified only by a closed group of experts.
In May 2019, Microsoft released an open-source software development kit (SDK) called ElectionGuard , which is offered for free. The SDK was released as part of an effort to strike a balance between transparency and security.
The ElectionGuard SDK can be integrated into voting systems and enable end-to-end verification and confirmation that votes have been counted correctly.

ElectionGuard Bug Bounty Program
Despite the advantages of the software, there is always the risk of a vulnerability appearing. For this reason, Microsoft has now launched the ElectionGuard Bounty program. The company is therefore inviting security researchers from all over the world to participate in the program and help identify vulnerabilities in the ElectionGuard SDK.
“The ElectionGuard Bounty program invites security researchers to work with Microsoft to protect users . It is part of Microsoft’s broader commitment to preserving and protecting electoral processes as part of the Defending Democracy Program,” Microsoft said.
“Researchers from around the world, whether they are cybersecurity, hobbyists, or students, are invited to discover critical vulnerabilities in the ElectionGuard SDK and share them with Microsoft as part of the Coordinated Vulnerability Disclosure (CVD).”
Of course, Microsoft will reward researchers who participate in the program. Researchers who discover a vulnerability and explain how it can be exploited by malicious hackers will be paid $15,000.
