3 ms·
This has been solved, and it's really simple actually. I wrote about it in another comment, but I'll quickly go over the technology here as well. When a citiz
by simpss 9y ago
This has been solved, and it's really simple actually.
I wrote about it in another comment, but I'll quickly go over the technology here as well.
When a citizen votes, the vote is encrypted with the government public key. The vote is then put into a container and is signed with the citizens private key.
The vote gets sent to the voting-system servers and is then stored until counting day.
Once the voting period has ended the encrypted votes are pulled out of the signed containers and the signed containers themselves are destroyed, this anonymizes the votes. Only then are the encrypted votes decrypted with the government private key.
We keep the signed containers around the encrypted vote to make sure no-one can be forced to e-vote.
Every citizen can vote as many times as they want during the e-voting period and only the last vote counts.
So if someone is standing behind you and telling you to vote somehow, you can do as they say and just vote again afterwards.
As an extra backup, if you do cast your vote on paper as well, then the paper vote is counted and the e-vote is discarded.
The system has a prerequisite though, each citizen must have a private key. We do, as it's stored on our id-cards(equivalent to passports within the EU).
Procedures are in place to protect the Government private key during the voting period and just like with paper-voting observers are involved in every step of the process.
The English documentation is scarce, but the software itself is open source: https://github.com/vvk-ehk/evalimine https://github.com/vvk-ehk/evalimine
- specialist 9y agoAh. Opened that link. Stopped once I saw "Estonia internet voting" https://en.wikipedia.org/wiki/Electronic_voting_in_Estonia#Criticism https://en.wikipedia.org/wiki/Electronic_voting_in_Estonia#C...
- simpss 9y agoThat one, yes :) Their whole analysis is based on this claim: "claiming they could be able to breach the system, change votes and vote totals, and erase any evidence of their actions if they could install malware on the election servers." That is true for all server based software. Procedures have been set up to mitigate this risk. All software, servers and anything else running in the network is audited before, during and after the election. The whole process is public and anyone can become an observer, just like with paper ballots. There really are many eyeballs making sure the election servers are running the software they are supposed to. AFAIK everything else they pointed out was purely procedural and the guidelines there have been updated. There really weren't any reproducible technical issues and some of the procedural ones are outright misrepresentations. The full sources for these two are sadly in Estonian, but the main response to that research can be seen here in English: http://www.vvk.ee/uudised/vabariigi-valimiskomisjoni-vastulause-the-guardianis-ilmunud-artiklile/?tpl=1062 http://www.vvk.ee/uudised/vabariigi-valimiskomisjoni-vastula... """ Posted Wi-Fi credentials — The official video of the pre-election process reveals credentials for the election officials’ Wi-Fi network, which are posted on the wall. """ The credentials were actually just for a separate public guest network, that has nothing to do with the "election officials network" or the network where the voting servers are. or: """ Keystrokes reveal root passwords — Videos posted by officials during the election show operators typing, inadvertently revealing root passwords for election servers. """ Although this was recognized as a possible attack vector and the procedures for filming have been updated, the "operator" typing a password was actually one of the observers typing a password in their own computer. Obviously any hints to compromised processes are taken with 100% seriousness and if needed processes and guidelines are changed to protect the integrity of the system. Any technical reports are also (publicly) analyzed and if an issue is indeed found, they're fixed. The thing is, "https://estoniaevoting.org" https://estoniaevoting.org" said everything is bad, and the system should not be used, but never published/provided any re-producible test-cases that could be verified. OSCE has audited all of our elections, they've given some procedural pointers that have been implemented, but OSCE observers have not deemed our elections compromised. This is their 2011 audit: http://www.osce.org/odihr/77557?download=true http://www.osce.org/odihr/77557?download=true, the pointers given to improve our system have been implemented by now. And here is their 2015 audit: http://www.osce.org/odihr/elections/estonia/160131?download=true http://www.osce.org/odihr/elections/estonia/160131?download=..., which has some new pointers, but again has not deemed the system to be insecure. We're having another parlamentary election in 2019 and again, the system will be improved for that(more verification methods are being implemented), but so far, all of our elections have been deemed acceptable and work is being done to keep the track record.
- peterwwillis 9y agoThe Estonian method is too complex to be easily proved to be secure. You have to play a cat-and-mouse game ad infinitum to keep up its integrity. Simpler systems are less costly over the short and long term, and more secure by default.
- simpss 9y agoCould you give me an example of what makes it too complex and maybe an example of a system that is simpler?