{"id":1308,"date":"2024-09-22T16:47:29","date_gmt":"2024-09-22T16:47:29","guid":{"rendered":"https:\/\/xdr-mdr.lmntrix.com\/main_web\/?p=1308"},"modified":"2024-10-19T13:13:20","modified_gmt":"2024-10-19T13:13:20","slug":"digitizing-democracy-the-risks-and-rewards-of-evoting","status":"publish","type":"post","link":"https:\/\/lmntrix.com\/blog\/digitizing-democracy-the-risks-and-rewards-of-evoting\/","title":{"rendered":"Digitizing democracy \u2013 the risks and rewards of evoting"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/lmntrix.com\/blog\/wp-content\/uploads\/2024\/09\/43951115_585a35af24_z-1-150x150-1.webp\" alt=\"Polling Booth\" class=\"wp-image-1309\" style=\"width:412px;height:auto\"\/><\/figure>\n<\/div>\n\n\n<p>As technology advances, previously analogue processes become increasingly digitized \u2013 in some countries, this even extends to the democratic foundation of voting. Estonia is the clear leader in digitizing democracy, though many other nations are wary of the risks. Without getting too bogged down in whether or not electronic voting is a smart decision, it is safe to say that any electronic system transmitting information over the internet has inherent security risks.&nbsp;<br><br>In the case of voting, it is paramount the process be secure lest the final result be called in to question, potentially destabilizing an entire nation.<br><br><a href=\"https:\/\/ccc.de\/en\/updates\/2017\/pc-wahl\" target=\"_blank\" rel=\"noopener\">Chaos Computer Club<\/a>\u2019s (CCC) recent analysis of Germany\u2019s PC-Wahl 10 voting software underscores this concern. PC-Wahl is used to collect and tally parliamentary votes from polling stations throughout the country. The system is supposed to work like this: a voter walks into a polling booth and submits their vote into a machine running PC-Wahl 10, which then transfers the data to a server for analysis. While this seems simple enough, because the machines require an internet connection to operate, there is room for remote interference. According to CCC, they were able to breach PC-Wahl software in not just one, but three different ways, using attacks they described as \u201ctrivial.\u201d &nbsp;<br><br>\u201cElementary principles of IT-security were not heeded to. The amount of vulnerabilities and their severity <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/paanjz\/hacking-germanys-vote-counting-software-was-trivial-researchers-warn\" target=\"_blank\" rel=\"noopener\">exceeded our worst expectations<\/a>,\u201d said Linus Neumann, a member CCC.<br><br>According to CCC, the package had \u201ca whole chain of serious flaws.\u201d Their three attacks targeted an update server, the software, and the election results themselves. This means an attacker could edit the tallied data, and submit essentially anything to the server for tallying \u2013 all without physical access. CCC also found a complete takeover of the software was \u201cquite feasible,\u201d and due to the simplicity of the security vulnerabilities, almost anyone could conduct these attacks.<br><br>Many governments have resisted calls to digitize voting, and based upon CCC\u2019s analysis, the hesitation seems prudent. On the other side of the fence, Estonia has successfully held electronic elections since 2005 and is<a href=\"https:\/\/www.forbes.com\/sites\/kalevleetaru\/2017\/06\/07\/how-estonias-e-voting-system-could-be-the-future\/#20a328373b95\" target=\"_blank\" rel=\"noopener\"> the clear trailblazer<\/a> in such technology.&nbsp;<br><br>Whereas Germany\u2019s system still requires voters attend a polling booth, Estonians can vote from home. <a href=\"http:\/\/www.euronews.com\/2017\/10\/19\/why-is-online-voting-so-rarely-used-in-europe\" target=\"_blank\" rel=\"noopener\">Estonia\u2019s system<\/a> is secured by establishing a robust digital identity for every citizen \u2013 not just for voting, but for identification, banking and tax purposes. This is buttressed by a two-factor system where one device is required to cast a vote, and a second device must be used to check the vote has been received.<br><br>Perhaps counterintuitively, more than 40 per cent of e-votes in Estonia\u2019s recent elections have been cast by those over 45, suggesting the digital form enjoys broad support beyond just millennials. The idea behind Estonia\u2019s embrace of e-voting is simple \u2013 make voting easier, and more people will vote.&nbsp;<br><br>While the concept still makes many government nervous, new technologies such as <a href=\"http:\/\/techau.com.au\/blockchain-could-have-saved-120-million-on-australias-ssm-vote\/\" target=\"_blank\" rel=\"noopener\">blockchain<\/a> could pave the way for the next evolution in e-voting. Blockchain technology aims to remove the largest security risk in e-voting \u2013 the centralized repository of votes. If someone were to gain access to this centralized server, the risks are enormous. Nullifying this single point of failure makes the whole process infinitely more secure.&nbsp;<br><br>Given the relatively early stage of the technology, it will be some time before voting systems built on blockchain gain widespread adoption. In the meantime, the National Institute of Standards and Technology (NIST) recently released a draft <a href=\"https:\/\/www.eac.gov\/assets\/1\/6\/TGDC_Recommended_VVSG2.0_P_Gs.pdf\" target=\"_blank\" rel=\"noopener\">Voluntary Voting Systems Guideline 2.0<\/a> to help states develop robust e-voting practices. While it was written with the US in mind, in light of nation state targeting of electoral systems, the draft guideline includes globally applicable concepts to mitigate against stolen credentials and more direct network-based attacks. The guidelines also outline various measures to ensure equal, transparent and auditable access for eligible voters.&nbsp;<br><br>As the PC-Wahl 10 analysis shows there are still real, valid concerns surrounding e-voting. Estonia\u2019s example displays a clear way forward for the future of voting, as does the potential to incorporate blockchain technology to further increase security.&nbsp;<br><br>Ultimately, voters need confidence in the elections in which they participate, and their participation is the key to a functional, healthy democracy. While security risks can undermine democracy, the resulting voter disenchantment from an insecure system is perhaps the greatest risk of all.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As technology advances, previously analogue processes become increasingly digitized &ndash; in some countries, this even extends to the democratic foundation of voting. Estonia is the clear leader in digitizing democracy, though many other nations are wary of the risks. Without getting too bogged down in whether or not electronic voting is a smart decision, it [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1309,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-1308","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/posts\/1308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/comments?post=1308"}],"version-history":[{"count":2,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/posts\/1308\/revisions"}],"predecessor-version":[{"id":3705,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/posts\/1308\/revisions\/3705"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/media\/1309"}],"wp:attachment":[{"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/media?parent=1308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/categories?post=1308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lmntrix.com\/blog\/wp-json\/wp\/v2\/tags?post=1308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}