HomeSecurityVoting Apps: Democracy in the Hands of Technology

Voting Apps: Democracy in the Hands of Technology

In recent years, there has been growing interest in using online and mobile technology to augment voting processes. At the same time, cybersecurity experts point out that paper ballots are the only secure means of voting.

voting technology

Now, MIT researchers are raising another concern: They report they have discovered security vulnerabilities in a voting app used during the 2018 election in West Virginia. The security analysis of the app, called Voatz, identifies a number of weaknesses, including the ability for hackers to change, stop, or expose how an individual user voted. In addition, the researchers found that Voatz’s use by an outside partner to identify and verify voters poses potential privacy concerns for users.

After uncovering these security vulnerabilities, the researchers disclosed their findings to the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). The researchers worked with the Boston University/MIT Technology Law team and CISA election security officials to ensure that election officials and the software partner were aware of the findings before the research was released. This included preparing written summaries of the findings and directly discussing them with affected election officials on calls hosted by CISA.

In addition to its use in the 2018 West Virginia election, the app was used in elections in Denver, Oregon, and Utah, as well as the Massachusetts and Utah Democratic conventions in 2016.

The findings highlight the need for transparency in the design of voting systems, according to the researchers.

“We all have a vested interest in increasing access to voting to increase participation, but to maintain trust in our electoral system, we must ensure that voting systems meet high standards of technical and operational security before they are put into operation,” Weitzner says. “We cannot experiment with our democracy.”.

“The view among security experts is that conducting secure elections over the internet is not possible today,” adds Koppel. “The reasoning is that application weaknesses can give an adversary undue influence in an election, and today’s software is unstable enough that the existence of unknown exploitable flaws is too great a risk.”.

Recording of results

The researchers were initially inspired by Voatz’s security analysis based on Spectre research with Ronald Rivest, a professor at the Institute at MIT. Neha Narula, director of MIT’s Digital Law Initiative, exploring the feasibility of using blockchain in elections. According to the researchers, Voatz claims to use a blockchain to ensure security, but has not released any source code or public documentation of how its system works.

Specter, who teaches an independent study course at MIT founded by Koppel that focuses on reverse engineering software, described the idea of ​​reverse engineering Voatz’s application in an attempt to better understand how its system worked. To ensure they weren’t interfering with pending elections or exposing user records, Specter and Koppel reverse engineered the application and then built a mock-up of Voatz’s server.

vote-technology

They found that an adversary with remote access to the device could change or discover a user’s vote, and that the server, if compromised, could easily change those votes. “It doesn’t appear that the application protocol attempts to verify [authentic votes] via the blockchain,” Specter explains.

“We found that your internet service provider, or someone near you if you are on unencrypted Wi-Fi, could detect how you voted in certain election configurations. More aggressive malicious actors could potentially detect how you are going to vote and then terminate your connection based on that alone.”

In addition to finding vulnerabilities with Voatz's voting process, Specter and Koppel found that the app poses privacy concerns for users. Because the app uses an external provider to verify a voter's identity, a third party could potentially access a voter's photo, driver's license data, or other forms of identification if the provider's platform is not secure.

Need for greater transparency

Specter and Koppel state that their findings point to the need for transparency in election administration to ensure the integrity of the electoral process. Currently, they note that the electoral process in states that use paper ballots is designed to be transparent and that citizens and political party representatives have opportunities to observe the voting process.

In contrast, Koppel notes that “the Voatz app and infrastructure were completely closed infrastructure. We could only access the app itself.”

“I think this type of analysis is incredibly important. There’s an effort right now to make voting more accessible, using online and mobile voting systems. The problem here is that sometimes these systems are not built by people who have experience in maintaining the security of voting systems,” says Matthew Green, an associate professor at the Johns Hopkins Information Security Institute. In the case of Voatz, he adds, “It seems like there were a lot of good intentions here, but the result lacks key features that would protect a voter and the integrity of the election.”.

Looking ahead, the researchers warn that software developers will need to prove that their systems are as secure as paper.

“The biggest issue is transparency,” Specter says. “When you have a part of the election that is opaque, it’s not visible, it’s not public, and it has some kind of proprietary element, that part of the system is inherently suspect and needs to be scrutinized.”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS