{"id":16056,"date":"2019-08-12T02:30:03","date_gmt":"2019-08-12T10:30:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/08\/12\/news-9799\/"},"modified":"2019-08-12T02:30:03","modified_gmt":"2019-08-12T10:30:03","slug":"news-9799","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/08\/12\/news-9799\/","title":{"rendered":"Why blockchain-based voting could threaten democracy"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/08\/election_2016_teaser_16_electronic_voting_evoting_security-100807007-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lucas Mearian| Date: Mon, 12 Aug 2019 03:00:00 -0700<\/strong><\/p>\n<p>Public tests of blockchain-based mobile voting are growing.<\/p>\n<p>Even as there&#8217;s been an uptick in pilot projects, security experts warn that blockchain-based mobile voting technology is innately insecure and potentially a danger to democracy through &#8220;wholesale fraud&#8221; or &#8220;manipulation tactics.&#8221;<\/p>\n<p>The topic of election security has been in the spotlight recently after Congress <a href=\"https:\/\/www.dhs.gov\/cisa\/news\/2019\/07\/11\/us-government-officials-participate-congressional-briefings-election-security\" rel=\"noopener nofollow\" target=\"_blank\">held classified briefings<\/a> on U.S. cyber infrastructure to identify and defend against threats to the election system, especially after Russian interference was uncovered in the 2016 Presidential election.<\/p>\n<p>Thirty-two states permit various kinds of online voting \u2013 such as via email \u2013 for some subset of voters. In the 2016 general election, more 100,000 ballots were cast online, according to <a href=\"http:\/\/www.ncsl.org\/research\/elections-and-campaigns\/internet-voting.aspx\" rel=\"nofollow noopener\" target=\"_blank\">data collected by the U.S. Election Assistance Commission<\/a>. The actual number is likely much higher, according to some experts.<\/p>\n<p>One method of enabling online voting has been to use applications based on blockchain, the peer-to-peer technology that employs encryption and a write-once, append-many electronic ledger to allow private and secure registration information and ballots to be transmitted over the internet. Over the past two years, West Virginia, Denver and Utah County, Utah have all used blockchain-based mobile apps to allow military members and their families living overseas to cast absentee ballots using an iPhone.<\/p>\n<p>Mike Queen, deputy chief of staff for West Virginia Secretary of State Mac Warner, said that while the state currently has no plans to expand the use of the mobile voting beyond military absentee voters, his office did &#8220;a ton of due diligence&#8221; on the technology before and after using it.<\/p>\n<p>&#8220;Not only does blockchain make it secure, but [the blockchain-based mobile app] has a really unique biometric safeguard system in place as well as facial recognition and thumb prints,&#8221; Queen said via email after 2018 General Election.<\/p>\n<p>Voatz iPhone mobile voting application.<\/p>\n<p>Security experts disagree. The issues around online voting include server penetration attacks, client-device malware, denial-of-service (DoS) attacks and other disruptions, all associated with infecting voters&#8217; computers with malware or infecting the computers in the elections office that handle and count ballots.\u00a0<\/p>\n<p>&#8220;If I were running for office and they decided to use blockchain for that election, I&#8217;d be scared,&#8221; said Jeremy Epstein, vice chairman of the Association for Computing Machinery&#8217;s U.S. Technology Policy Committee.<\/p>\n<p>Epstein co-authored an election security report with Common Cause, the National Election Defense Council, and the R Street Institute, &#8220;<a href=\"https:\/\/www.commoncause.org\/page\/email-and-internet-voting-the-overlooked-threat-to-election-security\/\" rel=\"noopener nofollow\" target=\"_blank\">Email and Internet Voting: The Overlooked Threat to Election Security<\/a>.&#8221; In it, he criticized blockchain and internet voting as a ready target for online attacks by foreign intelligence and said transmission of ballots over the internet, including by email, fax and blockchain systems, are seriously vulnerable.<\/p>\n<p>&#8220;Military voters undoubtedly face greater obstacles in casting their ballots. They deserve any help the government can give them to participate in democracy equally with all other citizens,&#8221; Epstein wrote. &#8220;However, in this threat-filled environment, online voting endangers the very democracy the U.S. military is charged with protecting.&#8221;<\/p>\n<p>There are many reasons blockchain is not good for voting, Epstein said. For one, it assumes there&#8217;s no malware in the voter&#8217;s computer. It also assumes you want all the votes to be perennially public, because if someone finds a way to hack into the blockchain, everyone&#8217;s vote becomes public. And, while blockchain networks may be able to handle small absentee voter populations, the technology could not stand up to use by the general voter populace and its volumes.<\/p>\n<p>Until there is a major technological breakthrough in or fundamental change to the nature of the internet, the best method for securing elections is a tried-and-true one: mailed paper ballots, according to Epstein.<\/p>\n<p>While paper ballots are not tamper-proof, they are not vulnerable to the same wholesale fraud or manipulation associated with internet voting, Epstein said.<\/p>\n<p>&#8220;Tampering with mailed paper ballots is a one-at-a-time attack. Infecting voters&#8217; computers with malware or infecting the computers in the elections office that handle and count ballots are both effective methods for large-scale corruption,&#8221; Epstein said.<\/p>\n<p>West Virginia, the first state to use a blockchain-based mobile voting system, was also criticized by Epstein who said the state was willing to go out on a limb &#8220;pretty much more than anyone else&#8221; and &#8220;never shared publicly how they decided these systems were secure.<\/p>\n<p>&#8220;They&#8217;re taking word of the vendor,&#8221; Epstein said.<\/p>\n<p>In <a href=\"https:\/\/cse.sc.edu\/~buell\/blockchain-papers\/documents\/WhatWeDontKnowAbouttheVoatz_Blockchain_.pdf\" rel=\"noopener nofollow\" target=\"_blank\">a research paper<\/a> written by computer scientists from Lawrence Livermore National Laboratory and the University of South Carolina, along with election oversight groups, internet voting <a href=\"https:\/\/voatz.com\/faq.html\" rel=\"nofollow\">startup Voatz<\/a> was called out for not releasing any &#8220;detailed technical description&#8221; of its technology.<\/p>\n<p>Voatz&#8217;s blockchain-based voting service was the one used West Virginia, Denver and Utah County to enable military absentee voting.<\/p>\n<p>&#8220;Most of the details of the architecture and procedure are apparently confidential, though it is not clear why,&#8221; the research paper said. &#8220;The system has not gone through federal certification, or any public certification to our knowledge. The company has not disclosed its source code nor allowed its system to be examined open by third parties.&#8221;<\/p>\n<p>Voatz has contracted with Palo Alto-based authentication company <a href=\"https:\/\/www.jumio.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Jumio<\/a> to perform remote voter authenticaiton. The authentication procedure requires a voter using the Voatz iPhone app to send to Jumio a photo of their driver&#8217;s license or passport photo page along with a short, live selfie video of their face. Jumio uses machine learning facial comparison software to determine whether the face on the ID matches the one in the video. If it does, the voter is authenticated.<\/p>\n<p>The researchers questioned the efficacy of using a tiny driver&#8217;s license or passport photo for authentication purposes and noted those photos can be up to 10 years old. Among other problems, they also noted facial comparison systems have been discovered to have high error rates, especially for minorities.<\/p>\n<p>One of the groups that contributed to the report was the non-profit <a href=\"https:\/\/www.verifiedvoting.org\/\" rel=\"nofollow noopener\" target=\"_blank\">Verified Voting Foundation<\/a>, whose stated purpose is to preserve the democratic process with modern voting technology. Marian Schneider, president of the Verified Voting Foundation, said online voting can&#8217;t be made safe and blockchain is an unnecessary complexity.<\/p>\n<p>&#8220;Current commercial systems with blockchain components are using the blockchain as an encrypted ballot box. Votes go there after they are susceptible to all of the attacks [already mentioned],&#8221; Schneider said. &#8220;If something happens, it might not be detected, and incorrect data would be in the blockchain.<\/p>\n<p>&#8220;I don&#8217;t think online voting can resolve any issues because the issues it purports to resolve create other issues that are worse,&#8221; she continued. &#8220;The ability to track back to a voter&#8217;s vote makes current systems not secret so they do not preserve the right to a secret ballot.&#8221;<\/p>\n<p>Voatz CEO Nimit Shawhney called some claims made in the research paper &#8220;inaccurate&#8221; and his company&#8217;s mobile voting system has undergone several independent, third-party audits, including penetration testing and source code reviews.<\/p>\n<p>&#8220;These audits were additionally audited by multiple independent security auditors (including former members of the FBI\u2019s elite cyber division). Voatz has also scheduled ongoing audits with the Department of Homeland Security&#8217;s Cybersecurity and Infrastructure Security Agency (CISA),&#8221; Shawhney said via email.<\/p>\n<p>Federal certification standards for mobile-focused election systems, he noted, are not available &#8220;as yet.&#8221; And he argued that revealing the company&#8217;s intellectual property \u00a0would court poaching by competitors.<\/p>\n<p><span style=\"caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;\">&#8220;We do share the confidential details about our system with our customers and relevant parties (e.g. security auditors),&#8221; Shawhney said. <\/span><\/p>\n<p><span style=\"caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;\">Voatz&#8217;s mobile system uses a combination of in-house and third-party solutions, such as Jumio&#8217;s, to perform remote identity proofing.<br \/><\/span><\/p>\n<p><span style=\"caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;\">The photograph on a license or passport, Shawhney explained, is just one of the data points used to verify a remote voter\u2019s identity. Others include a short video &#8220;selfie,&#8221; and a manual review of each image and document comparison. <\/span><\/p>\n<p><span style=\"caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;\">&#8220;Whenever there is even a slight doubt about the veracity of a document or the selfie, the voter is prompted to provided additional information and cannot proceed with the voting process without passing all the checks,&#8221; Shawhney said.<\/span><\/p>\n<p>Blockchain andinternet-based voting platforms, however, have been viewed as one way to boost voter participation by making the process easier through mobile apps that allow both registration and ballot casting to occur from anywhere in the world. Voters in those systems pre-register and then can use their smartphone&#8217;s biometric finger print readers or facial recognition technology to sign in to cast their votes.<\/p>\n<p>The number of pilots, while growing, remains relatively small &#8211; a few dozen, mainly for shareholder proxy voting and university student government elections. But state and municipal governments have been testing blockchain-based mobile voting over the past year.<\/p>\n<p>In the 2018 election, 144 registered West Virginia voters from 21 counties cast ballots from 31 different countries using an app from Voatz.<\/p>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/1aKVRaWY_Stzr1ba7feXYCv8KHRaRkA-0\/view\" rel=\"nofollow noopener\" target=\"_blank\">New research from the University of Chicago<\/a>\u00a0found that allowing military members overseas to vote using a mobile device increased turnout by 3% to 5% among those eligible to use the system in the 2018 federal election in West Virginia.<\/p>\n<p>Anthony Fowler, lead study author and associate professor at the University of Chicago, said that being able to cast ballots online using only smartphones or other mobile devices can dramatically reduce the costs of voting, particularly for under-represented groups, and has significant effects on the size and composition of the voting population.<\/p>\n<p>&#8220;We are likely to see more trials soon, so this is a good time to study the consequences of this reform,&#8221; Fowler wrote. &#8220;New survey data shows that many Americans are understandably wary of online voting.&#8221;<\/p>\n<p>A third-party audit conducted by the National Cybersecurity Center (NCC) and Denver Election Divisions showed that votes cast over the blockchain application were <a href=\"https:\/\/www.prnewswire.com\/news-releases\/national-cybersecurity-center-successfully-completes-third-party-security-audit-for-denvers-mobile-voting-pilot-300896234.html?tc=eml_cleartime\" rel=\"noopener nofollow\" target=\"_blank\">recorded and tabulated accurately<\/a>. The final numbers showed that voter turnout doubled from the 2015 election and a post-election survey from the Denver Elections Division found that 100% of respondents said they favored secure mobile voting over all methods available to them.<\/p>\n<p>&#8220;We are very excited about the promise of this technology,&#8221; Jocelyn Bucaro, Denver&#8217;s Deputy Director of Elections, said in a statement. &#8220;Our goal was to offer a more convenient and secure method for military and overseas citizen voters to cast their ballots, and this pilot proved to be successful. More voters participated in this cycle, in part thanks to this convenient method, and those voters who voted using the application prefer to vote by this method in all elections in the future.&#8221;<\/p>\n<p>Jonathan Johnson, an Overstock.com board member and the president of <a href=\"https:\/\/www.mediciventures.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Medici Ventures<\/a>, Overstock&#8217;s subsidiary responsible for advancing blockchain technology, believes remote voting via electronic devices will be more widely adopted.<\/p>\n<p>&#8220;After <a href=\"https:\/\/www.computerworld.com\/article\/3322926\/w-va-says-mobile-voting-via-blockchain-went-smoothly.html?nsdr=true\">a successful pilot program in West Virginia<\/a> of the Voatz digital remote voting application&#8230; more states will look to re-enfranchise their overseas voters,&#8221; Johnson said in an earlier interview. &#8220;Other states may use it to make accommodations for disabled voters. But, as people get comfortable with it, there will be an outcry for it from the voting citizenry. If I can vote overseas using it, then why can&#8217;t I use it when I&#8217;m here [in country]?&#8221;<\/p>\n<p>Medici Ventures-backed Voatz is among a small community of mobile voting platforms worldwide using blockchain as the basis for a distributed voting system. Other companies include Barcelona-based <a href=\"http:\/\/www.scytl.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Scytl<\/a>, Australia-based <a href=\"https:\/\/secure.vote\/\" rel=\"nofollow noopener\" target=\"_blank\">SecureVote<\/a>, London-based <a href=\"https:\/\/www.smartmatic.com\/us\/contact\/\" rel=\"nofollow noopener\" target=\"_blank\">Smartmatic Corp.<\/a> and Cleveland-based <a href=\"https:\/\/votem.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Votem Corp<\/a>. Though Votem reportedly shuttered its operations after layoffs, Votem CEO Peter Martin said via email the company continues to support its customers &#8220;and in fact have signed up some new customers.&#8221;<\/p>\n<p>Even so, several European countries abandoned internet voting after seeing that the increases in turnout were not as large as expected, the Univeristy of Chicago study pointed out; those lower-than-expected increases, however, could have been affected by already waning voter turnout in those European nations.<\/p>\n<p>Estonia, however, has embraced internet-based voting and created the world&#8217;s first <a href=\"https:\/\/www.valimised.ee\/en\/internet-voting\/internet-voting-estonia\" rel=\"nofollow\">national online voting system<\/a>. In 2005, the Baltic nation of 1.3 million people introduced online voting via Smartmatic Corp.&#8217;s technology and used it for local government elections; two years later, Estonia used internet voting for parliamentary elections in which more than 30,000 people voted online.<\/p>\n<p>The Estonian internet voting system has now been used in eight major elections over 10 years. Today, online voting participation in the Balkan state has reached 44.4% of the population.<\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3430697\/why-blockchain-could-be-a-threat-to-democracy.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/08\/election_2016_teaser_16_electronic_voting_evoting_security-100807007-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lucas Mearian| Date: Mon, 12 Aug 2019 03:00:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Public tests of blockchain-based mobile voting are growing.<\/p>\n<p>Even as there&#8217;s been an uptick in pilot projects, security experts warn that blockchain-based mobile voting technology is innately insecure and potentially a danger to democracy through &#8220;wholesale fraud&#8221; or &#8220;manipulation tactics.&#8221;<\/p>\n<p>The topic of election security has been in the spotlight recently after Congress <a href=\"https:\/\/www.dhs.gov\/cisa\/news\/2019\/07\/11\/us-government-officials-participate-congressional-briefings-election-security\" rel=\"noopener nofollow\" target=\"_blank\">held classified briefings<\/a> on U.S. cyber infrastructure to identify and defend against threats to the election system, especially after Russian interference was uncovered in the 2016 Presidential election.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3430697\/why-blockchain-could-be-a-threat-to-democracy.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[11526,11064,11070,11067,8826,10554,714],"class_list":["post-16056","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-blockchain","tag-cloud-computing","tag-emerging-technology","tag-government-it","tag-iphone","tag-mobile","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16056"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16056\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16056"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16056"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}