The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections
Michael A. Specter, James Koppel, Daniel J. Weitzner
摘要
In the 2018 midterm elections, West Virginia became the first state in the U.S. to allow select voters to cast their ballot on a mobile phone via a proprietary app called "Voatz." Although there is no public formal description of Voatz's security model, the company claims that election security and integrity are maintained through the use of a permissioned blockchain, biometrics, a mixnet, and hardware-backed key storage modules on the user's device. In this work, we present the first public security analysis of Voatz, based on a reverse engineering of their Android application and the minimal available documentation of the system. We performed a cleanroom reimplementation of Voatz's server and present an analysis of the election process as visible from the app itself. We find that Voatz has vulnerabilities that allow different kinds of adversaries to alter, stop, or expose a user's vote, including a sidechannel attack in which a completely passive network adversary can potentially recover a user's secret ballot. We additionally find that Voatz has a number of privacy issues stemming from their use of third party services for crucial app functionality. Our findings serve as a concrete illustration of the common wisdom against Internet voting, and of the importance of transparency to the legitimacy of elections.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Security Analysis of the Democracy Live Online Voting SystemMichael A. Specter, J. Alex HaldermanUSENIX Security 2021 · 被引用 24 次
- "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaignsSunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas 等USENIX Security 2021 · 被引用 15 次
- Busting the Paper Ballot: Voting Meets Adversarial Machine LearningKaleel Mahmood, Caleb Manicke, Ethan Rathbun, Aayushi Verma 等CCS 2025
- Investigating State-of-the-Art Practices for Fostering Subjective Trust in Online Voting through InterviewsKarola Marky, Paul Gerber, Sebastian Günther, Mohamed Khamis 等USENIX Security 2022
它引用的顶会 Paper1
相关 Paper
- Reversing, Breaking, and Fixing the French Legislative Election E-Voting ProtocolAlexandre Debant, Lucca HirschiUSENIX Security 2023
- ElectionGuard: a Cryptographic Toolkit to Enable Verifiable ElectionsJosh Benaloh, Michael Naehrig, Olivier Pereira, Dan S. WallachUSENIX Security 2024 · 被引用 12 次
- Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingTobias Hilt, Christian Mack, Benjamin Maximilian Berens, Melanie VolkamerCHI 2026
- Kryvos: Publicly Tally-Hiding Verifiable E-VotingNicolas Huber, Ralf Küsters, Toomas Krips, Julian Liedtke 等CCS 2022 · 被引用 23 次
- Investigating Voter Perceptions of Printed Physical Audit Trails for Online VotingKarola Marky, Nina Gerber, Henry John Krumb, Mohamed Khamis 等S&P 2024 · 被引用 1 次
