USENIX Security2020Top-tier venue
The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections
Michael A. Specter, James Koppel, Daniel J. Weitzner
Abstract
In the 2018 midterm elections, West Virginia became the first state in the U.S. to allow select voters to cast their ballot on a mobile phone via a proprietary app called "Voatz." Although there is no public formal description of Voatz's security model, the company claims that election security and integrity are maintained through the use of a permissioned blockchain, biometrics, a mixnet, and hardware-backed key storage modules on the user's device. In this work, we present the first public security analysis of Voatz, based on a reverse engineering of their Android application and the minimal available documentation of the system. We performed a cleanroom reimplementation of Voatz's server and present an analysis of the election process as visible from the app itself. We find that Voatz has vulnerabilities that allow different kinds of adversaries to alter, stop, or expose a user's vote, including a sidechannel attack in which a completely passive network adversary can potentially recover a user's secret ballot. We additionally find that Voatz has a number of privacy issues stemming from their use of third party services for crucial app functionality. Our findings serve as a concrete illustration of the common wisdom against Internet voting, and of the importance of transparency to the legitimacy of elections.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a9a47435-8667-44d1-a5fa-2947de787ac1Cited by top-tier papers4
- Security Analysis of the Democracy Live Online Voting SystemMichael A. Specter, J. Alex HaldermanUSENIX Security 2021 · 24 citations
- "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaignsSunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas et al.USENIX Security 2021 · 15 citations
- Busting the Paper Ballot: Voting Meets Adversarial Machine LearningKaleel Mahmood, Caleb Manicke, Ethan Rathbun, Aayushi Verma et al.CCS 2025
- Investigating State-of-the-Art Practices for Fostering Subjective Trust in Online Voting through InterviewsKarola Marky, Paul Gerber, Sebastian Günther, Mohamed Khamis et al.USENIX Security 2022
Builds on1
Related papers
- Reversing, Breaking, and Fixing the French Legislative Election E-Voting ProtocolAlexandre Debant, Lucca HirschiUSENIX Security 2023
- ElectionGuard: a Cryptographic Toolkit to Enable Verifiable ElectionsJosh Benaloh, Michael Naehrig, Olivier Pereira, Dan S. WallachUSENIX Security 2024 · 12 citations
- Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingTobias Hilt, Christian Mack, Benjamin Maximilian Berens, Melanie VolkamerCHI 2026
- Kryvos: Publicly Tally-Hiding Verifiable E-VotingNicolas Huber, Ralf Küsters, Toomas Krips, Julian Liedtke et al.CCS 2022 · 23 citations
- Investigating Voter Perceptions of Printed Physical Audit Trails for Online VotingKarola Marky, Nina Gerber, Henry John Krumb, Mohamed Khamis et al.S&P 2024 · 1 citation
