• Latest
MIT Wasn’t Only One Auditing Voatz – Homeland Security Did Too, With Fewer Concerns

MIT Wasn’t Only One Auditing Voatz – Homeland Security Did Too, With Fewer Concerns

Februar 14, 2020
6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

März 31, 2023
Judge denies SEC motion to keep Hinman docs secret in Ripple case

Judge denies SEC motion to keep Hinman docs secret in Ripple case

März 31, 2023
The ultimate guide to Miami – Cointelegraph Magazine

The ultimate guide to Miami – Cointelegraph Magazine

März 31, 2023
Dr. Jane Thomason – Cointelegraph Magazine

Dr. Jane Thomason – Cointelegraph Magazine

März 31, 2023
1658007797 celsius is bankrupt with 12b balance sheet hole su zhu.jpg

Celsius is bankrupt with $1.2B balance sheet hole, Su Zhu returns to Twitter and OpenSea purges 20% of employees: Hodler’s Digest, July 10-16

März 31, 2023
6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

März 31, 2023
Jed McCaleb empties XRP wallet after eight-year selloff

Jed McCaleb empties XRP wallet after eight-year selloff

März 31, 2023
Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

März 31, 2023
The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

März 31, 2023
SEC objects to XRP holders aiding Ripple defense

SEC objects to XRP holders aiding Ripple defense

März 31, 2023
Blockchain technology is transforming the real estate market – Cointelegraph Magazine

Blockchain technology is transforming the real estate market – Cointelegraph Magazine

März 31, 2023
1658612147 nfts banned in minecraft sec lists 9 tokens as securities.jpg

NFTs banned in Minecraft, SEC lists 9 tokens as securities and 3AC founder blames cockyness for company meltdown: Hodler’s Digest, July 17-23

März 31, 2023
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
CoinNewsDaily
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
CoinNewsDaily
No Result
View All Result
Home Ethereum

MIT Wasn’t Only One Auditing Voatz – Homeland Security Did Too, With Fewer Concerns

coinnewsdaily by coinnewsdaily
Februar 14, 2020
in Ethereum
0
MIT Wasn’t Only One Auditing Voatz – Homeland Security Did Too, With Fewer Concerns
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

The Department of Homeland Security (DHS) found a number of security vulnerabilities in Voatz’s tech infrastructure during a cybersecurity audit of the mobile voting app vendor’s Boston headquarters, according to a newly declassified report obtained by CoinDesk.

However, the DHS report, conducted by a Hunt and Incident Response Team with the department’s Cybersecurity and Infrastructure Security Agency (CISA) also determined Voatz had no active threats on its network during the week-long operation, conducted last September. It developed a series of recommendations to further boost Voatz’s security. Voatz has since addressed those recommendations.

Related articles

Top 3 cryptocurrencies that are faring the best in the 2022 bear market

Top 3 cryptocurrencies that are faring the best in the 2022 bear market

Mai 24, 2022
Core Ethereum developer details changes to expect after the Merge

Core Ethereum developer details changes to expect after the Merge

Mai 24, 2022

The CISA report was shared with CoinDesk hours after a technical paper by MIT researchers claimed to detail a number of major vulnerabilities in the Medici-backed Voatz’s app, including allegations that the app leaves voters’ identities open to adversaries and that ballots can be altered.

The MIT report, published Thursday by graduate students Michael Specter and James Koppel and principal research scientist Daniel Weitzner, further alleges that the app has limited transparency, a claim also raised by a number of security researchers.

“Our findings serve as a concrete illustration of the common wisdom against Internet voting, and of the importance of transparency to the legitimacy of elections,” the MIT researchers said in the report.

However, the CISA audit, which focuses less on the app itself and more on Voatz’s internal network and servers, draws a different conclusion. The DHS investigators wrote that while they found some issues which could pose future concerns to Voatz’s networks, overall the team “commends Voatz for their proactive measures” in monitoring for potential threats.

The two reports paint contrasting pictures of how the company, whose app has been used in pilot programs and live elections in West Virginia, Colorado and Utah, approaches voting security. Further, at least one election official overseeing the Voatz app rollout believes the MIT study is missing data in its evaluation.

The MIT researchers did not return a request for comment by press time.

MIT findings

The MIT report relies on a reverse-engineering of the Voatz app and reimplemented “clean room” server, according to the researchers, who did not interact with Voatz’s live servers or its purported blockchain back end.

They found privacy vulnerabilities and a wealth of potential avenues for attack in the app. Adversaries could infer user vote choice, corrupt the audit trail and even change what appeared on the ballot, the researchers said.

The researchers’ findings and faults did not focus on Voatz’s use of a blockchain, at least in part because they did not have access to the permissioned blockchain on which Voatz is said to store and authenticate votes. Instead, they report that the Voatz app never submits vote information to any “blockchain-like system.”

Criticizing Voatz’s lack of transparency, the researchers further argued the company’s “black box” approach to public documentation could, in tandem with the bugs, erode public trust.

“The legitimacy of the government relies on scrutiny and transparency of the democratic process to ensure that no party or outside actor can unduly alter the outcome,” the report said.

Ultimately, the researchers recommended elected officials “abandon” the app outright.

“It remains unclear if any electronic-only mobile or Internet voting system can practically overcome the stringent security requirements on election systems,” they said.

But Amelia Powers Gardner, a Utah County, Utah election official who supervised her county’s rollout of the Voatz system for disabled voters and service members deployed overseas, told CoinDesk that at least some of the bugs the researchers found cannot be exploited in practice.

“[The researchers] weren’t able to substantiate these claims because they were never able to actually connect to the Voatz server,” Powers Gardner said. “So in theory, they claim that they may have been able to do these things, and only on the Android version, not the Apple version.”

She said the MIT researchers’ effort comes from “what ifs, and perhaps, and maybes, that frankly just haven’t panned out,” and that the app had been patched since.

For Powers Gardner, Voatz’s benefits far outweigh any security risks. She said the software is a far better alternative for otherwise disenfranchised voting groups than the current technological solution: email.

“While these concerns of around mobile loading can be valid, they don’t rise to a level of security that causes me to even question the use of the mobile app,” she said.

John Sebes, co-founder and Chief Technology Officer of the Open Source Election Technology Institute, said that a number of the researchers’ concerns still stand, despite Powers Gardner’s claims.

Election officials and computer scientists live in very different worlds, and therefore may not see eye to eye, he said. However, he added that computer science researchers do not need to understand an election official’s world to be able to assess a software vendor’s claims.

“We can’t validate Voatz’s claims that newer versions were better, but it’s still the case that the version inspected had some fairly basic issues,” Sebes said.

In response to Powers Gardner’s claims that the researchers claims were speculative, or “what ifs,” Sebes said this reflected a misunderstanding of the value of this kind of security assessment.

The goal is to find vulnerabilities in the software that could enable adversaries to conduct a successful cyber operation, rather than claim an actual attack occurred, which is also the framing the DHS conclusion takes, Sebes said.

Still voting electronically

Voatz itself took issue with the MIT report, insinuating in a statement that the researchers were embarking on a fear campaign.

“It is clear that from the theoretical nature of the researchers’ approach…  that the researchers’ true aim is to deliberately disrupt the election process, to sow doubt in the security of our election infrastructure, and to spread fear and confusion,” the statement said.

The company’s response to the DHS report was more measured; while there was no written statement – and a spokesperson did not return a request for comment – the government investigators said Voatz had taken action on most of their recommendations.

Still, the DHS report remains inconclusive about the Voatz app itself.

West Virginia, one of the states which deployed the app, claims it has seen no issues so far.

Mike Queen, a spokesperson for West Virginia Secretary of State Mac Warner, said the state’s 2018 pilot for overseas military voters went off without a hitch. However, he was noncommittal as to whether the state would continue using Voatz.

“Secretary Warner and his team will make a decision prior to March 1 regarding the technology that we will prescribe for use in the May 2020 Primary Election,” he said. “As we have done from the very start, our decision will be based on the best available information with a strong emphasis on security and accessibility.”

Like Utah’s Powers Gardner, Queen said any potential physical disabilities or geographic location should not prevent voters from participating in the democratic process.

“I don’t have a duty to an out-of-town researcher who doesn’t understand how elections are actually run,” Powers Gardner said. “I have a duty to stand up for the constitutional rights of the disabled voters in my community, and I’m going to ensure their constitutional right to vote in the safest way that I know how.”

Read the full DHS report below:

Disclosure Read More

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.

Credit: Source link

Tags: Ethereum
Share76Tweet47
Previous Post

US DOJ Calls Bitcoin Mixing ‚a Crime‘ in Arrest of Software Developer

Next Post

Trump’s Fed Nominee Judy Shelton Says US Should Be Proactive on Digital Dollar

coinnewsdaily

coinnewsdaily

CoinNewsDaily.com is an online Crypto Coin News Website that aims to provide latest trendy news from market and around the world.

Related Posts

Top 3 cryptocurrencies that are faring the best in the 2022 bear market
Alt Coin

Top 3 cryptocurrencies that are faring the best in the 2022 bear market

Mai 24, 2022
Core Ethereum developer details changes to expect after the Merge
Ethereum

Core Ethereum developer details changes to expect after the Merge

Mai 24, 2022
fUSD stablecoin launch and rumors of Cronje’s return send Fantom (FTM) price higher
Ethereum

fUSD stablecoin launch and rumors of Cronje’s return send Fantom (FTM) price higher

Mai 23, 2022
Price analysis 5/23: BTC, ETH, BNB, XRP, ADA, SOL, DOGE, DOT, AVAX, SHIB
Alt Coin

Price analysis 5/23: BTC, ETH, BNB, XRP, ADA, SOL, DOGE, DOT, AVAX, SHIB

Mai 23, 2022
The Moon ‘created’ his lavish reality… and says you can, too
Ethereum

The Moon ‘created’ his lavish reality… and says you can, too

Mai 23, 2022
Layer-2 adoption could spur the next crypto turning point
Ethereum

Layer-2 adoption could spur the next crypto turning point

Mai 23, 2022
Load More
Next Post
Trump’s Fed Nominee Judy Shelton Says US Should Be Proactive on Digital Dollar

Trump's Fed Nominee Judy Shelton Says US Should Be Proactive on Digital Dollar

Kategorien

  • Alt Coin
  • Bitcoin
  • Business
  • Ethereum
  • ICO
  • Litecoin
  • Mining
  • NFT
  • Ripple
  • Tech
  • Trading

What New here?

  • 6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine
  • Judge denies SEC motion to keep Hinman docs secret in Ripple case
  • The ultimate guide to Miami – Cointelegraph Magazine
  • About Us
  • Contact Us
  • Privacy & Policy

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev

Please enter CoinMarketCap Free Api Key to get this plugin works.
✕
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev