Researchers Find Security Flaws in Mobile Voting App

A man takes a Democratic ballot to vote in the New Hampshire Primary at Parker-Varney Elementary School, Tuesday, Feb. 11, 2020, in Manchester, N.H.

A man takes a Democratic ballot to vote in the New Hampshire Primary at Parker-Varney Elementary School, Tuesday, Feb. 11, 2020, in Manchester, N.H. AP Photo/Andrew Harnik

 

Connecting state and local government leaders

Hackers could detect how people voted and potentially change their votes on the Voatz mobile voting app tested by West Virginia and jurisdictions in Utah, Oregon, Colorado and Washington.

A mobile voting app used by West Virginia and several local governments in the 2018 midterm elections contains vulnerabilities that could allow hackers to determine how someone voted or even change their vote, according to a report released Thursday by security researchers.

Researchers from the Massachusetts Institute of Technology found the security flaws in the Voatz voting app, which was originally designed as a way for overseas service members to cast ballots. The researchers said their findings underscore prior security recommendations that the internet not be used for voting.  

“Perhaps most alarmingly, we found that a passive network adversary, like your internet service provider, or someone nearby you if you’re on unencrypted Wi-Fi, could detect which way you voted in some configurations of the election,” said Michael Specter, a graduate student in MIT’s Department of Electrical Engineering and Computer Science.

 “Worse, more aggressive attackers could potentially detect which way you’re going to vote and then stop the connection based on that alone.”

In addition to West Virginia, several local governments, including ones in Washington state, Colorado, Utah and Oregon, have conducted their own pilots with the Voatz system. Additional states are also considering whether to use the app to assist absentee voters in upcoming elections.

Voatz has defended those pilot projects, saying it has made open audit tools available to the public so that vote tallies can be independently verified and said that so far  there have been no reported issues with the technology.

The company pushed back against the MIT findings, calling the report’s methodology “flawed.” The MIT researcher did not have access to the voting system’s design and source code and instead reverse-engineered the app and recreated what they could of the company’s server from information that was publicly available.

Voatz said the Android version of the app that researchers used was old, with 27 newer versions released since then, and never used in an election. Further, the company said by reverse engineering the system, the researchers “made assumptions about the interactions between the system components that are simply false.”

The West Virginia Secretary of State’s Office said Thursday that the state will go forward with using an electronic ballot delivery system in the upcoming 2020 primary and general elections, which it plans to extend mobile voting capabilities to severely disabled voters. But the state has not decided whether to continue using Voatz or to utilize another vendor, said spokesman Mike Queen. 

“We’re concerned about the technology but we are not scared of it,” Queen said, adding that his office is closely monitoring research like MIT’s on mobile voting system technology. 

Software issues with a smartphone app delayed the tally of results in the Iowa Democratic Party’s caucuses last week, underscoring the perils of using untested new technology in local elections. To mitigate issues with new tech, David Levine, an elections expert with the Alliance for Securing Democracy, said local elections officials should try to vet any major changes by holding a mock election.

“It becomes more important to try to go to a mock election as you are trying to make a bigger change,” said Levine, who recently authored a guidebook for local elections officials offering tips on securing election infrastructure. “If you are talking about mobile voting, that is a substantial change.”

Mobile voting is still not a mainstream endeavor, Levine said. While it remains a fringe practice, he said Voatz and other companies looking to offer the same services should engage researchers in the security community. That would enable future dynamic testing of mobile voting technology during a mock election. 

Earlier concerns about the security of the Voatz app led a U.S. senator to ask the Department of Defense and National Security Agency to conduct a full cybersecurity audit of the technology used by the company. In a letter sent to the agencies in November, Sen. Ron Wyden, an Oregon Democrat, said the company has not been sufficiently transparent about its efforts to vet and safeguard the voting app to inspire confidence in its technology.

The MIT researchers reported their findings to the Department of Homeland Security, which said it shared the information with state and local election officials who plan to pilot or use this technology in 2020 elections. A spokeswoman for DHS’s Cybersecurity and Infrastructure Security Agency said there is “no known exploitation of the vulnerabilities” and that potentially affected election officials were able to speak with researchers to understand and manage risks to their systems.

Andrea Noble is a staff correspondent with Route Fifty.

NEXT STORY: With Cybercriminals on the Attack, States Help Cities Punch Back

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.