15 ms·
Researchers find trapdoor in SwissVote election system
- eps 8y agoOriginal announcement [1] with its links intact, including one for the actual paper with technical details [2] - [1] https://about.unimelb.edu.au/newsroom/news/2019/march/researchers-find-trapdoor-in-swissvote-election-system https://about.unimelb.edu.au/newsroom/news/2019/march/resear... [2] https://people.eng.unimelb.edu.au/vjteague/SwissVote https://people.eng.unimelb.edu.au/vjteague/SwissVote
- dang 8y agoWe changed to that first one from https://techxplore.com/news/2019-03-trapdoor-swissvote-election.html https://techxplore.com/news/2019-03-trapdoor-swissvote-elect.... Thanks!
- DoofusOfDeath 8y agoIs a trapdoor the same as a backdoor?
- Devz0r 8y agoAccording to the article it certainly reads that way.
- hannasanarion 8y agoTrapdoor is an older term that means the same thing as "backdoor". I think this author chose to use it in order to distinguish between the modern colloquial meaning of "backdoor" as "a method for an attack to eavesdrop on communication", and the more abstract meaning of a correctness vulnerability in an allegedly secure counting algorithm.
- Y_Y 8y agoA trapdoor is something that's hard to invert: https://en.m.wikipedia.org/wiki/Trapdoor_function https://en.m.wikipedia.org/wiki/Trapdoor_function A backdoor is a hidden access, like this. Just a mistake in the article.
- makomk 8y agoI don't think it's a mistake. I think this is actually a trapdoor in the cryptographic sense of the term, and the security hole is the result of them using a zero-knowledge proof scheme based on these kind of trapdoor functions that relies on no-one having a copy of the trapdoor information, but incorrectly letting the untrusted party choose the trapdoor function.
- tomglynch 8y agoNo mistake. It's a trapdoor.
- cygx 8y agoYes. The Jargon File[1] lists it as a synonym, though note that Wikipedia[2] calls this usage outdated. [1] http://catb.org/jargon/html/T/trap-door.html http://catb.org/jargon/html/T/trap-door.html [2] https://en.wikipedia.org/wiki/Trapdoor_(disambiguation) https://en.wikipedia.org/wiki/Trapdoor_(disambiguation)
- archi42 8y agoNo. Neither is it an error in the article, since they use the same term in their paper: https://people.eng.unimelb.edu.au/vjteague/UniversalVerifiabilitySwissPost.pdf https://people.eng.unimelb.edu.au/vjteague/UniversalVerifiab... It seems there is a class of commitment schemes that's called "trapdoor commitment schemes" and deployed in SwissPost. I'm not aware of these, but they cite this PhD thesis on the topic: https://www.math.uni-frankfurt.de/~dmst/research/phdtheses/mfischlin.dissertation.2001.pdf https://www.math.uni-frankfurt.de/~dmst/research/phdtheses/m... (Disclaimer: I have no idea how these work - maybe the authors mixed up their terminology ;-))
- jbclements 8y agoNo, it's clear that the researchers are using the term trapdoor in a technical sense. Specifically, one of the key ideas in the swiss system is that it produce a proof that the votes produced as the result of the "shuffle" operation have the same meaning as the votes that are provided as inputs. The easiest "proof" of this would simply be to publish the input votes... but that would defeat the whole purpose of the shuffling. Instead, the Swiss system appears to involve a trapdoor commitment that produces a non-reversible token (hence "trapdoor") that could only be generated if this is a legitimate shuffling. As I read it, this is much like (for instance) a SHA-256 hash of an input message that can be generated to ensure that a document has not been tampered with.
- nathan_long 8y agoSpeaking as someone who is forced to vote on a proprietary touchscreen system with no paper trail, I wish researchers were finding cryptographic problems in my voting system.
- komali2 8y agoI love those systems. In Texas my parents tried to press Betos name, and at the "review results" screen, Cruz was selected. This was a well documented, statewide problem. Malice? User error? Ux idiocy? Who knows!
- ceejayoz 8y agoAnyone who ever owned a Palm Pilot went through this. Just shitty capacitive touchscreens.
- specialist 8y agoThe touchscreens in New Mexico 2004 simply didn't record the votes of Spanish language ballots. Kerry won the state but Bush received the electoral votes. Fortunately, the NM courts agreed and prohibited the further use of the touchscreens. What blows my mind is how invalidating (decertifying) the touchscreens has to be done in each state. I still can't fathom why the feds (eac.gov) can't just pull rank and ban them.
- ceejayoz 8y ago> I still can't fathom why the feds (eac.gov) can't just pull rank and ban them. Article One, Section Four of the Constitution gives this power solely to the State and Federal legislatures. The Executive branch (and it'd probably the FEC, not the EAC) can't pull rank here unless Congress gives them the power to.
- specialist 8y agoAnd yet HAVA. Which is it? Pick one.
- duxup 8y agoI really like the Minnesota system. You fill out a paper ballot. You load the paper ballot that gets scanned and recorded and the paper ballot gets rolled into a locked box that is attached to the machine. Recounts and etc should be relatively easy to manage and leave a very good paper trail tied to various machines and etc.
- azernik 8y agoCalifornia (or are least Alameda County) has the same system
- wahern 8y agoAFAIU, California mandates paper ballots statewide and also mandates post-election audits. It's not uncommon nationally, apparently: http://www.ncsl.org/research/elections-and-campaigns/post-election-audits635926066.aspx http://www.ncsl.org/research/elections-and-campaigns/post-el...
- labster 8y agoWe're also required to have machines in the polling place for those with disabilities. These too produce paper records, that the voter can review. California went all-in on recording elections after the debacle in Florida in 2000.
- e1ven 8y agoAgreed. We use essentially a Scantron sheet in Massachusetts. Easy to fill out, computer countable, with a hand recount as an easy backup option.
- Teever 8y agoWhy is any of this necessary? Why don't paper ballots suffice?
- JumpCrisscross 8y ago> Why don't paper ballots suffice? Hand counting is costly, time-consuming and error-prone. Paper ballots with supervised electronic tabulation puts forward the best of both worlds. (It's how we do it in New York, too.)
- archi42 8y agoIn my crypto lecture we did automatic protocol verification using proverif. Since here the implementation is at fault, and not the protocol, the next thing seems to be a (proven) compiler from the (proven) protocol specification to an implementation?
- Trisell 8y agoHere is a thread[1] from one of the researchers. She spells out what they have found. I think the most damning quote is. “Do not let people minimize this issue. This isn't "some random hacker can steal an election" this is "SwissPost can prove they didn't steal an election, even if they did" [1]https://twitter.com/sarahjamielewis/status/1105378257317191680?s=21 https://twitter.com/sarahjamielewis/status/11053782573171916...
- sschueller 8y agoFor any Swiss citizens in this thread, please consider this temporary ban on evoting: https://evoting-moratorium.wecollect.ch/ https://evoting-moratorium.wecollect.ch/
- zaroth 8y agoIt uses a trapdoor commitment function. It does not have a “trapdoor” or “backdoor”. The problem is not so much in the implementation of the function, but in the generation of parameters required by the function. The machines need to follow a particular scheme to generate the parameters of the function in order for the commitment to be secure. Think, e.g. of ZCash, where if the initial ceremony is not completed in a specific way and trusted, then the entire system after that has specific weaknesses. In this case, if the parameter generation is not done correctly, or if randomness generated by clients is compromised, votes can be altered. Now one of the issues is generating random group elements. Reading one of the linked notices [1] it talks about best practices of generating a random group element. I don’t understand exactly all the terminology in the paper (even though it is quite trivial) but it looks to me like it is talking about generating effectively a public key in an EC system. One way to do it is to generate a random integer r between 0..q-1, which is effectively the private key, and then generate the corresponding public key by doing g^r mod p. The problem with this approach is that in the process the machine generating the public key knows the private key. It could be thus saved or leaked. Instead you can generate a public key directly. This requires randomly selecting a value and checking it is valid (r/p=1), which is more expensive, or alternatively select a random r in Z and return r^2 mod p. Finally, the generation process itself must be proveably fair and random (e.g. some sort of blockchain ceremony) to be trusted. Fundamentally the Swiss system does not specify a ceremony for trusting the parameters used by its Pedersen commitment scheme, and therefore even if the implementation is perfect it still is not secure. Still reading... [1] - https://s68aa858fd10b80a7.jimcontent.com/download/version/1552395686/module/7833161661/name/PIT1.pdf https://s68aa858fd10b80a7.jimcontent.com/download/version/15...
- rocqua 8y agoIf all that's needed is a public key without known private key (i.e. some element Ga with a unknown) then a simple ceremony is possible. Anyone who wants gets to submit a value H_i = G a_i. With a proof that H lies in the correct subgroup. Then the final value can bu the sum of all H_i s. The final private key would be the sum of all a_i s. If even one of those private keys is unkown, the final value is also unknown.
- eli 8y agoIf you're interested in voting systems and the challenges of election administration, the National Academies of Science published a paper last year that is approachable, relatively comprehensive and free to read: https://www.nap.edu/read/25120/chapter/1 https://www.nap.edu/read/25120/chapter/1 It is a much harder problem than a lot of technologist think. And "just add blockchain" is almost certainly the wrong move.
- Niksko 8y agoOn a personal note, I'm glad to see the outcome of this bug bounty was as I expected from the beginning: bugs, and pretty serious ones. E-voting is a bad idea, and government attempting to implement it is an even worse idea.
- jampekka 8y agoPrivate company implementing it seems even even worse.
- danra 8y agoE-voting over blockchain to the rescue! :0
- Buttons840 8y agoSure, maybe you can design a provably correct e-voting system, but 99% of the people will just have to blindly trust the system. Then one day a politician will point out that his new election system is better, because it has nicer colors and some stuff, and maybe a lot of people will agree with him. A lot of people will be willing to move from from the provably correct system, which they blindly trust, to another system which they blindly trust. Except maybe the new system did away with all that blockchain mambo-jumbo and a few people on weird internet sites are complaining about it and saying that this isn't what we signed up originally with e-voting, but who listens to them?
- tracker1 8y agoThe issue at hand, is people are REALLY sensitive to having their voting record(s) tracked. If you know someone's key, you can track all their votes on the blockchain. If the blockchain isn't public, then it isn't trustable. You can't have non-tracked + blockchain + trust.
- danra 8y agoI thought the :0 would hint at the tongue in cheek. The replies and downvotes say otherwise.
- harry8 8y agoEven if it were possible to design a provably correct, impossible to tamper with, anonymous electronic voting system (which seems unlikely to me) it still should NOT be used. Why? Everyone understands paper in ballot boxes, and how they can be cheated, what to look for. Everyone can assess an argument as to whether this happened based on the evidence presented. Basically nobody would understand what to even look for in cheating the electronic system. It would be totally my expert says your expert is wrong and so it is/isn't fraud. Having even the possibility of that argument for electoral fraud is completely insane. It doesn't just have to be fair, it has to be seen to be fair. Really it does. We need to have reason to have faith in our democratic processes most especially when the people you want to win, don't and the result surprises you. The sooner we get to "Any electronic voting must be used to mark a standard paper ballot which becomes the entire source of truth." The better. Everything else in electronic voting is dangerous, sinister and flat out evil. Oppose it. Loudly. At every opportunity. Especially if you're known as someone who understands computers on some level.
- pbz 8y agoHow about this? 1) you go to vote with your voting card 2) you get a paper printout of your vote 3) the voting machine then broadcasts your vote (only IDs) to N independent checkers; this makes your vote public but anonymous 4) later you check the printout against your favorite online checker to make sure it registered properly To make all this work the paper and electronic trail is digitally signed with something that's only on your voting card.
- rtpg 8y agoThis leads to the problem of letting _other people_ force you to show them how you voted. This is a real problem! The secret vote isn't just about making sure that you can choose privately, but also about making sure that other people don't have ways of coercing you into certain choices.
- keymone 8y agoThere are ways to solve this issue with cryptography.
- seanwilson 8y agoHmm, the algorithm used was formal proven secure: https://people.eng.unimelb.edu.au/vjteague/UniversalVerifiabilitySwissPost.pdf https://people.eng.unimelb.edu.au/vjteague/UniversalVerifiab... > How can there be a trapdoor when the system has been formally proven secure? Any formal proof of correctness for any system makes some assumptions that become axioms in the formal proof. Scytl’s formal proof of security [Scy18] simply models the mixnet as sound, based on an informal interpretation of Bayer and Groth’s security proof. It does not model the proper generation of commitment parameters. We do not see any reason to believe there is an error in Scytl’s proof, but when the axioms are mistaken the conclusions are not valid. This does not mean that formal proofs are not valuable—at an absolute minimum, they clarify assumptions and explain the reasons for trust—but it does mean that they are not a substitute for broad and open public scrutiny. It is quite possible that there are errors in the implementations of other cryptographic primitives, that their details may not be modelled in the formal proofs, and that they may affect either privacy or verifiability. There wasn't a better path to translate the proof into an implementation? How was the algorithm translated into code (Java I think)?
- ignoranceprior 8y agoRelevant xkcd: https://xkcd.com/2030/ https://xkcd.com/2030/
- kgwgk 8y agoBad timing for the "aircraft safety" example...
- nullc 8y agoTLDR: E-voting system uses pedersen commitments, but doesn't provide any evidence that the generators used are nothing-up-my-sleeve values. To understand what a pedersen commitment is think "cryptographic hash" but constructed so that you can 'add' hashes to get the hash of the added values. Pedersen commitments require as system parameters multiple base points where, for soundness, no one knows the discrete log any of them with respect to each other. The normal way to accomplish this is to generate them all in a "nothing up my sleeve" way by hashing some data. In my work on confidential transactions ( https://people.xiph.org/~greg/confidential_values.txt https://people.xiph.org/~greg/confidential_values.txt ) the base points I used were the standard secp256k1 generator, and a second point constructed by hashing the standard generator with sha256. If implementations of the SwissVote system were initialized in the say way they could simply add the information about the hashed data to their audit logs, even after the fact. If, instead, they picked the base points "randomly" then they could not prove that past usage wasn't compromised. I have often been frustrated by the lack of clarity in academic cryptographic papers about the exact trust implications about initialization -- e.g. it often takes a careful reading to tell if a paper requires a trusted setup, if the values can just be chosen in a provably random way (and if so, will a simple method suffice or is there a strong requirement on uniformity) ... but pedersen commitments (even the vector versions) are really bread and butter simple stuff. I would be worried that anyone who didn't know that choice of the base points resulted in a trapdoor would be unlikely to spot actually subtle implementation or algorithmic mistakes.
- remcob 8y agoTitle makes it sound like a bug is discovered. The 'trapdoor' is in the protocol by design. A lot of zero knowledge proof protocols have an initial setup phase in which values are created that need to be forgotten for the system to be secure. These values are sometimes know as 'toxic waste'. ZCash has a good write up on how this went in their zero-knowledge proof based system: https://z.cash/technology/paramgen https://z.cash/technology/paramgen The main criticism by the researchers seems to be that the process around this setup was insufficient to demonstrate security.
- ewillbefull 8y ago> The 'trapdoor' is in the protocol by design. Only due to ignorance. It is well known that the bases of a Pedersen commitment can and should be sampled randomly; a trusted setup is only subverting the security of the primitive.
- inved001 8y agoHere are some more details about this: https://e-voting.bfh.ch/publications/2019/ https://e-voting.bfh.ch/publications/2019/