{"id":17724,"date":"2020-02-13T18:50:17","date_gmt":"2020-02-14T02:50:17","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2020\/02\/13\/news-11459\/"},"modified":"2020-02-13T18:50:17","modified_gmt":"2020-02-14T02:50:17","slug":"news-11459","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/13\/news-11459\/","title":{"rendered":"MIT researchers say mobile voting app piloted in U.S. is rife with vulnerabilities"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/09\/cw_mobile_voting_by_inueng_and_filo_gettyimages_3x2_1200x800-100772605-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lucas Mearian| Date: Thu, 13 Feb 2020 13:30:00 -0800<\/strong><\/p>\n<p>Elections officials in numerous states have piloted various mobile voting applications as a method of expanding access to the polls, but MIT researchers say one of the more popular apps has security vulnerabilities that could open it up to tampering by bad actors.<\/p>\n<p>The MIT analysis of the application, called <a href=\"https:\/\/voatz.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Voatz<\/a>, highlighted a number of weaknesses that could allow hackers to \u201calter, stop, or expose how an individual user has voted.\u201d<\/p>\n<p>Additionally, the researchers found that Voatz\u2019s use of Palo Alto-based vendor <a href=\"https:\/\/www.jumio.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Jumio<\/a> for voter identification and verification poses potential privacy issues for users.<\/p>\n<p>The study comes on the heels this month&#8217;s trouble-plagued Iowa Democratic Presidential Caucus, which used <a href=\"https:\/\/www.computerworld.com\/article\/3519217\/iowa-caucus-chaos-likely-to-set-back-mobile-voting.html\">an online app to store votes<\/a> but failed to do so accurately because of a coding flaw and insufficient testing.<\/p>\n<p>Some security experts have long argued that the only secure form of voting is paper ballots.<\/p>\n<p>Voatz iPhone mobile voting application.<\/p>\n<p>The Voatz mobile voting application has been used in small pilots involving \u00a0only about 600 voters total in Denver, <a href=\"https:\/\/www.computerworld.com\/article\/3322926\/w-va-says-mobile-voting-via-blockchain-went-smoothly.html\">West Virginia<\/a>, five counties in Oregon, <a href=\"https:\/\/www.computerworld.com\/article\/3410570\/utah-county-to-pilot-blockchain-based-mobile-voting.html\">Utah<\/a> and Washington State, where the main focus was on inclusivity for absentee voters living overseas.<\/p>\n<p>In response, Voatz\u00a0called the MIT report \u201cflawed\u201d because it based its analysis on a long-outdated Android version of the app.<\/p>\n<p>\u201cHad the researchers taken the time, like nearly 100 other researchers, to test and verify their claims using the latest version of our platform via our public bug bounty program on <a href=\"https:\/\/www.hackerone.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HackerOne<\/a>, they would not have ended up producing a report that asserts claims on the basis of an erroneous method,\u201d Voatz stated in <a href=\"https:\/\/blog.voatz.com\/?p=1209\" rel=\"nofollow noopener\" target=\"_blank\">a blog post<\/a>\u00a0today.<\/p>\n<p>\u201cWe want to be clear that\u00a0all nine\u00a0of our governmental pilot elections conducted to date, involving\u00a0less than 600 voters, have been conducted safely and securely with no reported issues,\u201d Voatz said.<\/p>\n<p>In 2018, <a href=\"https:\/\/www.computerworld.com\/article\/3322926\/w-va-says-mobile-voting-via-blockchain-went-smoothly.html\">West Virginia piloted<\/a> Voatz&#8217;s mobile voting app for resident service members and family living overseas who wanted to vote in the midterm general election.\u00a0<\/p>\n<p>West Virginia Secretary of State&#8217;s office pointed to a Department of Homeland Security security assessment of the 2018 Voatz pilots indicating there was &#8220;no threat actor behaviors or artifacts of past nefarious activities were detected in the vendor\u2019s networks.&#8221;<\/p>\n<p>Audits of paper ballots created by the Voatz plaform on election day also confirmed the results were accurate, according to the Secretary of State&#8217;s office.<\/p>\n<p>&#8220;We want to get the word out to media outlets like <em>Computerworld<\/em> to ensure WV voters that we are taking every possible precaution to balance election security and integrity with WV requirement to provide absentee ballots electronically to overseas, military and absentee voters living with physical disabilities,&#8221; Mike Queen, deputy chief of staff for West Virginia Secretary of State Mac Warner, said via email.<\/p>\n<p>The\u00a0<a href=\"https:\/\/internetpolicy.mit.edu\/wp-content\/uploads\/2020\/02\/SecurityAnalysisOfVoatz_Public.pdf\" rel=\"nofollow noopener\" target=\"_blank\">MIT study, however,\u00a0<\/a>underscored the need for Voatz\u2019s mobile app design to be more transparent because public information about the technology is \u201cvague\u201d at best.<\/p>\n<p>Voatz\u2019s platform uses a combination of biometrics, such as mobile-phone based facial recognition, and hardware-backed keystores to provide end-to-end encrypted and voter-verifiable ballots. It also uses blockchain as an immutable electronic ledger to store voting results.<\/p>\n<p>Voatz has declined to provide formal details about its platform, citing the need to protect intellectual property, the researchers said in their paper.<\/p>\n<p>In a blog post today, Voatz called the researchers\u2019 approach \u201cflawed,\u201d which \u201cinvalidates any claims about their ability to compromise the overall system.<\/p>\n<p>&#8220;In short, to make claims about a backend server without any evidence or connection to the server negates any degree of credibility on behalf of the researchers,\u201d Voatz said.<\/p>\n<p>The researchers also called Voatz out for reporting a University of Michigan researcher who in 2018 conducted an analysis of the Voatz app. \u201cThis resulted in the FBI conducting an investigation against the researcher,\u201d the MIT researchers said.<\/p>\n<p>It\u2019s not the first time Voatz has been criticized for not being more open about its technology. Last May,\u00a0computer scientists from Lawrence Livermore National Laboratory and the University of South Carolina, along with election oversight groups, <a href=\"https:\/\/cse.sc.edu\/~buell\/blockchain-papers\/documents\/WhatWeDontKnowAbouttheVoatz_Blockchain_.pdf\" rel=\"nofollow\">published a paper<\/a> that criticized Voatz for not releasing any &#8220;detailed technical description&#8221; of its technology.<\/p>\n<p>\u201cThere are at least four companies attempting to offer internet or mobile voting solutions for high-stakes elections, and one 2020 Democratic presidential candidate has included voting from a mobile device via the blockchain in his policy plank,\u201d the MIT researchers said in their paper. \u201cTo our knowledge, only Voatz has successfully fielded such a system.\u201d<\/p>\n<p>Along with Voatz, <a href=\"https:\/\/democracylive.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Democracy Live<\/a>, <a href=\"https:\/\/votem.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Votem<\/a>,\u00a0<a href=\"https:\/\/secure.vote\/\" rel=\"nofollow noopener\" target=\"_blank\">SecureVote<\/a>\u00a0and\u00a0<a href=\"http:\/\/www.scytl.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Scytl<\/a> have all piloted mobile or online voting technology in various public or private balloting that included company stockholder and college board elections. Most recently, a <a href=\"https:\/\/www.computerworld.com\/article\/3516504\/seattle-joins-list-of-cities-trying-out-mobile-voting.html\">Seattle district piloted the Democracy Live technology<\/a>\u00a0in a board of supervisors election that was open to 1.2 million registered voters.<\/p>\n<p>Tusk Philanthropies, a nonprofit focused on promoting mobile voting as a way to increase voter turnout, has helped fund and promote Voatz and Democracy Live.<\/p>\n<p>In a statement to <em>Computerworld<\/em>, Tusk said it feels confident in the results of all the pilot elections because it conducted independent, third-party audits \u201cwhich showed that votes cast over the blockchain were recorded and tabulated accurately.\u201d<\/p>\n<p>\u201cWith that being said, we always welcome new security information and will work with security experts to review this paper,\u201d Tusk said. \u201cSecurity is an iterative process that can only get better over time. There is no room for error in our elections, especially when it comes to data leakage, compromised encryption, broken authentication, or denial-of-service attacks.\u201d<\/p>\n<p>Medici Ventures, the wholly-owned investment subsidiary of Overstock.com, has also backed Voatz, whose application has mainly been used to allow absentee voter service members and their families to cast their ballots via their smartphones from anywhere in the world.<\/p>\n<p>Jonathan Johnson, CEO of Overstock and president of Medici Ventures, responded in <a href=\"https:\/\/finance.yahoo.com\/news\/medici-ventures-issues-statement-support-143104384.html\" rel=\"nofollow noopener\" target=\"_blank\">a statement<\/a> to a <a href=\"https:\/\/www.nytimes.com\/2020\/02\/13\/us\/politics\/voting-smartphone-app.html\" rel=\"nofollow noopener\" target=\"_blank\"><em>New York Times<\/em> article<\/a>\u00a0about the MIT study, saying he believes the Voatz technology is responsible and safe.<\/p>\n<p>\u201cIt not only prevents voting fraud, but it also protects the privacy of each voter. The Voatz app even generates a paper ballot that can be audited to guarantee the fidelity of the vote,\u201d Johnson said. \u201cThis is, we believe, the right path forward to safe innovation in election technology. We should not let ourselves derail the future of voting.&#8221;<\/p>\n<p>Critics of mobile or online voting,\u00a0<a href=\"https:\/\/www.computerworld.com\/article\/3430697\/why-blockchain-could-be-a-threat-to-democracy.html\">including security experts<\/a>, believe it opens up the prospect of server penetration attacks, client-device malware, denial-of-service attacks and other disruptions \u2014 all associated with infecting voters&#8217; computers with malware or infecting the computers in the elections office that handle and count ballots.<\/p>\n<p>Jeremy Epstein, vice chair of the Association for Computing Machinery\u2019s US Technology Policy Committee (USTPC), has been a vocal critic of mobile voting platforms, including Voatz. He said the MIT study was \u201cvery thorough\u201d and demonstrates exactly what experts have been saying for years.<\/p>\n<p>\u201cInternet voting is risky. It&#8217;s no surprise that the Voatz system is vulnerable to many kinds of attacks, even to an attacker with no access to source code or other inside information,\u201d Epstein said via email. \u201cThe attacks demonstrated by MIT are well within the capabilities of nation-state adversaries who are interested in manipulating US elections, and such an adversary won&#8217;t publish their results as the MIT team has done, leaving us with an election that may be undetectably manipulated.\u201d<\/p>\n<p>The five-year-old Voatz slammed the MIT researchers for never connecting even the outdated app they used to the company\u2019s servers, which are hosted by Amazon AWS and Microsoft Azure.<\/p>\n<p>In the absence of connecting to the actual servers recording public votes, \u201cthe researchers fabricated an imagined version of the Voatz servers, hypothesized how they worked, and then made assumptions about the interactions between the system components that are simply false,\u201d Voatz said.<\/p>\n<p>Epstein retorted that Voatz&#8217;s comments \u201cdemonstrate that they don&#8217;t understand either the severity of the attacks or the way security works in general.<\/p>\n<p>\u201cAny election official using Voatz products would be well advised to cancel their plans, before a stealthy attack in a real election compromises democracy,\u201d Epstein said.<\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3527450\/mit-researchers-say-mobile-voting-app-piloted-in-us-is-rife-with-vulnerabilities.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/09\/cw_mobile_voting_by_inueng_and_filo_gettyimages_3x2_1200x800-100772605-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lucas Mearian| Date: Thu, 13 Feb 2020 13:30:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Elections officials in numerous states have piloted various mobile voting applications as a method of expanding access to the polls, but MIT researchers say one of the more popular apps has security vulnerabilities that could open it up to tampering by bad actors.<\/p>\n<p>The MIT analysis of the application, called <a href=\"https:\/\/voatz.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Voatz<\/a>, highlighted a number of weaknesses that could allow hackers to \u201calter, stop, or expose how an individual user has voted.\u201d<\/p>\n<p>Additionally, the researchers found that Voatz\u2019s use of Palo Alto-based vendor <a href=\"https:\/\/www.jumio.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Jumio<\/a> for voter identification and verification poses potential privacy issues for users.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3527450\/mit-researchers-say-mobile-voting-app-piloted-in-us-is-rife-with-vulnerabilities.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[11526,11070,11067,10554,5897,714],"class_list":["post-17724","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-blockchain","tag-emerging-technology","tag-government-it","tag-mobile","tag-privacy","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17724"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17724\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17724"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}