The Chief Information Officer of the Electoral Commission, Ian Brightwell,
claimed Halderman and Teague’s discovery was part of efforts by “well-funded,
well-managed anti-internet voting lobby groups,” an apparent reference to our
friends at VerifiedVoting.org, where Halderman and Teague are voluntary
Advisory Board members.
So, the CIO complains it's a smear job by an anti-internet-voting lobby group, (which it apparently was?)
Yet at the same time, Brightwell concluded that it was indeed possible that
votes were manipulated. Happily, despite criticizing the messengers, the
Electoral Commission admitted that there was a FREAK flaw with iVote and
scrambled to promptly patch it.
Then they admitted the vulnerability and rushed to patch it. Which is exactly the hoped-for response?
So what is South Wales doing wrong here, you know, other than trying to let people vote over the internet, which is a horrible idea, only perhaps matched by the absurdity of our current generation of e-voting machines? I understand their hands are not clean in many other regards with this program, but patching their cipher suite just doesn't seem newsworthy...
BTW, an open source voting machine platform (for use at the polling station) sounds like a great project for USDS or 18F.
There is only one correct response: "We thank the researchers who pointed out our mistakes, and apologize to all voters for our failure to adequately secure a vital system.".
The only correct response now, on the other hand, is the immediate firing of this "CIO", who clearly does not have the mentality necessary to be a CIO or a public servant.
They should also thank the researchers for not making 66,000 votes count towards something ridiculous, because unless I thought they would freak out about my way of proving a point, I would probably have did that when I told them how to secure their thing.
Then again, thanks to the wonders of the group voting ticket, the bar for getting a clearly ridiculous result is pretty high:
"In the New South Wales Legislative Council election of 1999, the Outdoor Recreation Party's Malcolm Jones was elected with a primary vote of 0.19%, or 0.042 of a quota."
This kind of result is perfectly valid. If candidates A and B are polarising, and candidate C is a compromise candidate, and you have a preferential voting system, then it makes sense that many people would put A or B first, and C second, producing a victory for C despite almost zero of the primary vote.
Of course, realistically, what probably happened in this case was more to do with party preferences and backroom deals, because you can give the voters an awesome voting system but then they'll just turn around and ask someone else to tell them what preferences to give anyway...
Because, you can slander everyone who discovers vulnerabilities in your software, and you can even lobby to make it illegal to disclose those vulnerabilities, and throw people in prison over it, and so on... and your software will go right on being vulnerable. You can put every security researcher and white hat in the world in prison on trumped-up charges and throw away the keys, and it will not make your software one bit more secure.
It's like, even if I convince every human being alive that I am not bound by the laws of gravity, if I jump off a cliff I will die all the same. To think otherwise is insane, but for some reason when it comes to software (and hardware) security we give people like Ian Brightwell a pass.
I'm OK with something like, 'the people who targeted the site had an agenda to find a hole, they found one, and they were happy to find it. I'm happy to hear about it from them via responsible disclosure and to have fixed it promptly. That would be close enough to ideal for me, and it seems like that's pretty much what happened.
If they denied the hole, or tried to cover it up, or did anything other than fix it immediately upon learning about it, really, that's the most we can hope for.
> So what is South Wales doing wrong here, you know, other than trying to let people vote over the internet, which is a horrible idea...
Was this sarcasm I missed? If not what is so horrible about allowing voting over the internet? To me the concept it brilliant if executed well. Especially for engaging the populace in non-compulsory voting countries where people might avoid casting their vote if it's going to take significant time commitment or simply they have other commitments such as work etc.
Voting over the internet allows intra-family coercion, reducing the freedom of women to vote. It also allows for you to vote in front of the party man and collect a bribe for so doing.
Voting on general purpose PCs is so exploitable as to not be funny. What percentage of the electorate are running unpatched XP?
These are great points and would absolutely be issues without proper implementation. Of interest, user atrip commented elsewhere in this thread:
>In Estonia the pressure issue is solved. One can vote as many times needed. When first vote was given under pressure, one can vote differently later. As many times is needed. Internet voting is not possible on the voting day, only before. That assures that when one has no possibilty to vote without pressure in internet, one has possibility to vote traditionally. Traditional vote overturnes e-vote.
This would also solve the bribe issue. And not to say there aren't issues. I feel the opportunity outweighs the risks personally as long as good practise in the system is followed. The biggest risk in my mind is blatant exploit by the person in power of the system, much like todays rigged elections.
Anonymous but verifiable/auditable online voting is a very hard problem that does not seem to be solved yet. How do you ensure that the remote voter gets one and only one vote while also being able to audit that the intended vote was recorded (it wasn't changed on the wire, in memory or on storage), without linking in any way the vote cast with the voter?
Ensuring that remote voting is not done under any form of duress or monitoring seems essentially unsolvable.
Incidentally, voting in state elections is compulsory in NSW so your example doesn't fit this case either way.
So what is South Wales doing wrong here, you know, other than trying to let people vote over the internet, which is a horrible idea, only perhaps matched by the absurdity of our current generation of e-voting machines? I understand their hands are not clean in many other regards with this program, but patching their cipher suite just doesn't seem newsworthy...
BTW, an open source voting machine platform (for use at the polling station) sounds like a great project for USDS or 18F.