7 ms·
Bounty Hunt Announced on Swiss eVoting System
- biggerfisch 8y agoPosted 19h ago: https://news.ycombinator.com/item?id=19127631 https://news.ycombinator.com/item?id=19127631
- runeks 8y ago> An amount of CHF 150'000.- is available for compensations. Seems to me like this is the wrong approach. Essentially, they’re saying they they have no idea how much they can pay per bug. A sensible approach would be to insure bug bounties, at least up to the amount that a black hat could profit from compromising the system.
- janekm 8y agoGood luck getting a legislature to sign off on an unlimited bug bounty budget though...
- heartbreak 8y agoAn insurance policy would suffice.
- consp 8y agoGood luck insuring this. I'm pretty sure the insurance premium will be the same as the actual cost.
- Thorrez 8y agoThey have a table below that with amounts listed for different types of bugs. I'm guessing the 150'000 means they'll stop paying for new bugs once they've reached that amount.
- born2discover 8y agoWhat it means is that they only have a budget of 150k CHF for all of the compensations they have to pay out. So if there are 4 bugs that would amount to 50k per bug, then only first 3 would get compensated and the rest would not. Source: [1] -> Q&A regarding the public intrusion test -> Is the federal government allowed to pay for hacker attacks? [1]: https://www.bk.admin.ch/bk/en/home/politische-rechte/e-voting/oeffentlicher_intrusionstest.html https://www.bk.admin.ch/bk/en/home/politische-rechte/e-votin...
- lolc 8y agoThe central issue with electronic voting is that it's opaque to observers. You can't guarantee vote privacy and monitor the counting process at the same time in electronics. I find that problem alone should mean no electronic voting should be used at scale. Further, vote privacy is threatened at the client side. The fact that they specifically exclude client vulnerabilities is telling: "... known and accepted characteristics of the system will however not be accepted. Such “issues” include: Any operation compromising the vote privacy on the client-side (e.g. browser extension);" They even met "issues" in quotes, even tough these are a common attack vector. They are real and dangerous. It's common in Switzerland to vote by mail, so there's the possibility that people get pressured into voting in a certain way by their relatives. But the scale is very different when people must expose their voting preferences to a machine they already know watches them.
- Mirioron 8y agoI agree about the risk of client-side vulnerabilities. Another state-level actor could easily abuse this to influence an election. On the counting side though, I don't fully agree. Paper voting sees some enormous mistakes. Whether they are intentional or not, but it has happened before where an entire town's votes for a candidate missed a zero. No election observers or people sent from either party noticed it until a volunteer pointed it out. Electronic voting isn't going to make such mistakes and I believe that if the process is handled well, then the secrecy of the vote shouldn't be an issue from the server side. But again, there's nothing you can do about the client side attack vector.
- sametmax 8y agoIn your example it worked: a volunteer pointed it out. The volunteer probably would not have been able to with e-vote. Who has the skill to be able to assess such a system ? And among those, who has the time ? I've been a programmer for 15 years and I'm pretty sure I would not be able to look at such a system and feel confident there is no error. And definitly not in the reasonable time period required for voting.
- 8y ago
- nairboon 8y agoThis program is a failure for the get go. > Scalable manipulation of votes that is undetectable by voters and trusted auditors; Such a bug would be a complete worst-case failure and if you report it, it would net you up to 50'000 CHF. This is a ridiculously low amount for such a critical infrastructure. The expected black market value of such a vulnerability is way way higher. Just to give you a frame of reference, in Switzerland we have 4 national votes a year and depending on the topic, affected interest groups and parties spend between 3 to 6 Mio CHF per vote for ads and influence. Now do the math yourself, whats the expected value of a vulnerability "undetectable by voters and trusted auditors" in a 10-20 Mio/y market (just at the national level) for influence?
- TheSpiceIsLife 8y agoI am from a far far away land. Would you mind explaining what Mio means in this context.
- PetitPrince 8y agoMio == million
- TheSpiceIsLife 8y agoThere are, what, 6 million or so voting age people in Switzerland. 6 million x 3 to 6 million CHF = I’m confused. 1 CHF = about 1 USD? 36,000,000,000,000 CHF four times a year. M I know I’m very tired. Did I miss something?
- StreakyCobra 8y agoNot exactly related to this e-voting system, but more generally there will probably be a federal popular initiative for a moratorium on e-voting in Switzerland [1,2]. It is possible (for Swiss citizens) to support the collection of signatures by registering here [3]. [1] https://www.admin.ch/gov/en/start/documentation/events.event-id-7231.html https://www.admin.ch/gov/en/start/documentation/events.event... [2] http://e-voting-moratorium.ch/ http://e-voting-moratorium.ch/ [3] https://evoting-moratorium.wecollect.ch/ https://evoting-moratorium.wecollect.ch/
- born2discover 8y agoOh, that is great to know, thank you!
- chirau 8y agousername checks out
- atemerev 8y agoFirst of all, great news! I live in Switzerland, and this is really good to hear. To those who think that 150’000 Fr. compensation is too low — think of the prestige! Hacking the Swiss voting system, the only direct democracy in the world! No amount of money is equal to that.
- nostrebored 8y agoRight, because extolling political capital from one of the centers of global banking is definitely not more valuable than a CV blurb
- atemerev 8y agoThe Swiss are actually ready to shut down the e-voting system for good. This is the final “military excercise” test; if it will be able to stand the combined power of the finest hackers of the planet (which is doubtful), it might survive. But I don’t think so. This is a suicide letter for the system. At the very least, it will be DDoSed out of existence.
- folli 8y agoThis is still my favorite take on the eVoting topic: https://xkcd.com/2030/ https://xkcd.com/2030/
- TulliusCicero 8y agoReminds me of developers' attitudes towards software patents (similarly, near-universal consensus that they're a terrible idea).
- TulliusCicero 8y agoThere's lots of direct democracy at sub-national levels in various countries.
- mfsch 8y agoFor a bit more background: The online newspaper Republik recently published a piece about this project and some of the problems with the company Scytl providing the system. They provide an English translation of that article: https://www.republik.ch/2019/02/07/the-tricky-business-of-democracy https://www.republik.ch/2019/02/07/the-tricky-business-of-de...
- beefhash 8y agoAfter Geneva made their system available as free software (AGPLv3), I can't help but feel a tiny bit disappointed about the restrictive terms for the release of the source code.
- sosodev 8y agoWhy is arbitrary code execution worth so little? Isn't that usually considered the worst bug somebody could find?
- mithr 8y agoThe way I read it, if you can leverage arbitrary code execution to manipulate votes, then you can claim one of the higher-paying categories... but if you can execute code, but can't figure out how to use that to actually affect votes, they don't care as much. I can't say I'm 100% sure that's the best strategy, but I think it makes at least some sense.
- sschueller 8y agoStop trying to fix something that isn't broken. The paper ballot and manual counting here is Switzerland works and needs no fixing.
- mittermayr 8y agoSo did a pair of feet, but the car made things a whole lot easier eventually. Humanity is only here for a bit, I feel we owe it to ourselves to keep innovating, regardless of whether or not all of our innovations turn out to be great.
- ataturk 8y agoThe oligarchy can't disenfranchise you as easily, though. Look at how screwed up the US is where liberal states import massive amounts of illegal immigrants and then launder them into voters by giving them driver's licenses. And when they're not running the tables with illegal immigration, they're doing it via gerrymandering (census counts legal and illegal alike), disavowing Voter ID laws as "Racist"--when every other thing we do requires an ID that is never accused of being racist, mind you. And then there's the vote "counting" itself. I think if Americans knew the full scale of fraud around voting there would be a real revolution.