Security Analysis of the Democracy Live Online Voting System
Michael A. Specter, J. Alex Halderman
摘要
Democracy Live's OmniBallot platform is a web-based system for blank ballot delivery, ballot marking, and (optionally) online voting. Three states-Delaware, West Virginia, and New Jersey-recently announced that they will allow certain voters to cast votes online using OmniBallot, but, despite the well established risks of Internet voting, the system has never been the subject of a public, independent security review. We reverse engineered the client-side portion of OmniBallot, as used in Delaware, in order to detail the system's operation and analyze its security. We find that OmniBallot uses a simplistic approach to Internet voting that is vulnerable to vote manipulation by malware on the voter's device and by insiders or other attackers who can compromise Democracy Live, Amazon, Google, or Cloudflare. In addition, Democracy Live, which appears to have no privacy policy, receives sensitive personally identifiable informationincluding the voter's identity, ballot selections, and browser fingerprintthat could be used to target political ads or disinformation campaigns. Even when OmniBallot is used to mark ballots that will be printed and returned in the mail, the software sends the voter's identity and ballot choices to Democracy Live, an unnecessary security risk that jeopardizes the secret ballot. We recommend changes to make the platform safer for ballot delivery and marking. However, we conclude that using OmniBallot for electronic ballot return represents a severe risk to election security and could allow attackers to alter election results without detection. the online voting option available to voters with disabilities, calling the move "a pilot for if we need to use it more broadly in the future" [26] . West Virginia allows not only the disabled but also military voters and residents overseas to vote online using OmniBallot [38] . Most significantly, Delaware [23] offers OmniBallot online voting to all voters who are sick or who are self-quarantining or social distancing to avoid exposure to SARS-CoV-2-practically the entire state [13, 23] . Increasing voter access is a laudable goal. Voters who are sick, disabled, or stationed overseas sometimes face substantial obstacles to participation, and the coronavirus pandemic threatens to disrupt in-person voting for everyone. However, elections also face substantial risks from cyberattacks-risks that are magnified when delivering or returning ballot online. Election officials have the complicated job of weighing these risks in light of the access needs of their constituencies. For online voting, the consensus of election security experts and national security experts is that the risks are unacceptable. Numerous studies of Internet voting systems used or slated for use in real elections have uncovered critical security flaws (e.g., [25, 28, 30, 48, 49, 61] ). The National Academies of Science, Engineering, and Medicine concluded that "no known technology guarantees the secrecy, security, and verifiability of a marked ballot transmitted over the Internet," and that, "[a]t the present time, the Internet (or any network connected to the Internet) should not be used for the return of marked ballots" [40] . In light of Russia's attacks on U.S. election infrastructure during the 2016 presidential election, the Senate Select Committee on Intelligence has recommended that "[s]tates should resist pushes for online voting," including for military voters [58] . As recently as May 2020, the Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, U.S. Election Assistance Commission, and National Institute of Standards and Technology privately warned states that "electronic ballot return technologies are high-risk even with [risk-mitigation] controls in place," and that attacks "could be conducted from anywhere in world, at high volumes, and could compromise ballot confidentiality, ballot integrity, and/or stop ballot availability" [60] . Despite these risks, to our knowledge, OmniBallot has never been the subject of a public, independent security review, 3 and there is little public documentation about its functionality. Democracy Live even claims that the online ballot return capability should not be considered Internet voting at all, but rather a "secure portal" or "document storage application" [43] . (In fact, it completely matches the definition of Internet voting as used by security experts [1] and by the Election Assistance Commission [56] .) These factors make it difficult for voters, election officials, and other policymakers to understand whether the technology is safe. In this paper, we present the first public, independent analysis of OmniBallot's security and privacy properties. We obtained the portion of the software that
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaignsSunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas 等USENIX Security 2021 · 被引用 15 次
- Investigating State-of-the-Art Practices for Fostering Subjective Trust in Online Voting through InterviewsKarola Marky, Paul Gerber, Sebastian Günther, Mohamed Khamis 等USENIX Security 2022
它引用的顶会 Paper4
- A Systematic Analysis of the Juniper Dual EC IncidentStephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried 等CCS 2016 · 被引用 91 次
- How not to prove your election outcomeThomas Haines, Sarah Jamie Lewis, Olivier Pereira, Vanessa TeagueS&P 2020 · 被引用 57 次
- Can Voters Detect Malicious Manipulation of Ballot Marking Devices?Matthew Bernhard, Allison McDonald, Henry Meng, Jensen Hwa 等S&P 2020 · 被引用 44 次
- The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal ElectionsMichael A. Specter, James Koppel, Daniel J. WeitznerUSENIX Security 2020
相关 Paper
- DVSorder: Ballot Randomization Flaws Threaten Voter PrivacyBraden L. Crimmins, Dhanya Narayanan, Drew Springall, J. Alex HaldermanUSENIX Security 2024 · 被引用 2 次
- Investigating Voter Perceptions of Printed Physical Audit Trails for Online VotingKarola Marky, Nina Gerber, Henry John Krumb, Mohamed Khamis 等S&P 2024 · 被引用 1 次
- Reversing, Breaking, and Fixing the French Legislative Election E-Voting ProtocolAlexandre Debant, Lucca HirschiUSENIX Security 2023
- Busting the Paper Ballot: Voting Meets Adversarial Machine LearningKaleel Mahmood, Caleb Manicke, Ethan Rathbun, Aayushi Verma 等CCS 2025
- Minerva- An Efficient Risk-Limiting Ballot Polling AuditFilip Zagórski, Grant McClearn, Sarah Morin, Neal McBurnett 等USENIX Security 2021 · 被引用 9 次
