Experts Find Serious Problems With Switzerland's Online Voting System

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+hWj5XAWf6sfYywrfph6Vnbu=+iB8OFb7uMQnDb5ExEA@mail.gmail.com>
'Switzerland made headlines this month for the transparency of its
internet voting system when it launched a public penetration test and
bug bounty program to test the resiliency of the system to attack. But
after source code for the software and technical documentation
describing its architecture were leaked online last week, critics are
already expressing concern about the system's design and about the
transparency around the public test. Cryptography experts who spent
just a few hours examining the leaked code say the system is a poorly
constructed and convoluted maze that makes it difficult to follow
what's going on and effectively evaluate whether the cryptography and
other security measures deployed in the system are done properly.

"Most of the system is split across hundreds of different files, each
configured at various levels," Sarah Jamie Lewis, a former security
engineer for Amazon as well as a former computer scientist for
England's GCHQ intelligence agency, told Motherboard. "I'm used to
dealing with Java code that runs across different packages and
different teams, and this code somewhat defeats even my
understanding." She said the system uses cryptographic solutions that
are fairly new to the field and that have to be implemented in very
specific ways to make the system auditable, but the design the
programmers chose thwarts this. "It is simply not the standard we
would expect," she told Motherboard. [...] It isn't just outside
attackers that are a concern; the system raises the possibility for an
insider to intentionally misconfigure the system to make it easier to
manipulate, while maintaining plausible deniability that the
misconfiguration was unintentional.

"Someone could wire the thing in the wrong place and suddenly the
system is compromised," said Lewis, who is currently executive
director of the Open Privacy Research Society, a Canadian nonprofit
that develops secure and privacy-enhancing software for marginalized
communities. "And when you're talking about code that is supposed to
be protecting a national election, that is not a statement someone
should be able to make." "You expect secure code to be defensively
written that would prevent the implementers of the code from wiring it
up incorrectly," Lewis told Motherboard. But instead of building a
system that doesn't allow for this, the programmers simply added a
comment to their source code telling anyone who compiles and
implements it to take care to configure it properly, she said.

The online voting system was developed by Swiss Post, the country's
national postal service, and the Barcelona-based company Scytl. "Scytl
claims the system uses end-to-end encryption that only the Swiss
Electoral Board would be able to decrypt," reports Motherboard. "But
there are reasons to be concerned about such claims."'

-- source: https://developers.slashdot.org/story/19/02/21/2227234

At least they had a public test to figure that out, rather than an
actual election...

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.