Close Menu
    Facebook X (Twitter) Instagram
    SciTechDaily
    • Biology
    • Chemistry
    • Earth
    • Health
    • Physics
    • Science
    • Space
    • Technology
    Facebook X (Twitter) Pinterest YouTube RSS
    SciTechDaily
    Home»Science»MIT Finds Hackers Can Change Votes in Voting App Used in U.S. Federal Elections
    Science

    MIT Finds Hackers Can Change Votes in Voting App Used in U.S. Federal Elections

    By Abby Abazorius, Massachusetts Institute of TechnologyFebruary 19, 202014 Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn WhatsApp Email Reddit
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email Reddit
    Voting App Security Issues
    MIT researchers identify security vulnerabilities in voting app. Credit: MIT

    Mobile voting application could allow hackers to alter individual votes and may pose privacy issues for users.

    In recent years, there has been a growing interest in using internet and mobile technology to increase access to the voting process. At the same time, computer security experts caution that paper ballots are the only secure means of voting.

    Now, MIT researchers are raising another concern: They say they have uncovered security vulnerabilities in a mobile voting application that was used during the 2018 midterm elections in West Virginia. Their security analysis of the application, called Voatz, pinpoints a number of weaknesses, including the opportunity for hackers to alter, stop, or expose how an individual user has voted. Additionally, the researchers found that Voatz’s use of a third-party vendor for voter identification and verification poses potential privacy issues for users.

    The findings are described in a new technical paper (PDF) by Michael Specter, a graduate student in MIT’s Department of Electrical Engineering and Computer Science (EECS) and a member of MIT’s Internet Policy Research Initiative, and James Koppel, also a graduate student in EECS. The research was conducted under the guidance of Daniel Weitzner, a principal research scientist at MIT’s Computer Science and Artificial Intelligence Lab (CSAIL) and founding director of the Internet Policy Research Initiative.

    After uncovering these security vulnerabilities, the researchers disclosed their findings to the Department of Homeland Security’s Cybersecurity and Infrastructure Agency (CISA). The researchers, along with the Boston University/MIT Technology Law Clinic, worked in close coordination with election security officials within CISA to ensure that impacted elections officials and the vendor were aware of the findings before the research was made public. This included preparing written summaries of the findings with proof-of-concept code, and direct discussions with affected elections officials on calls arranged by CISA.

    In addition to its use in the 2018 West Virginia elections, the app was deployed in elections in Denver, Oregon, and Utah, as well as at the 2016 Massachusetts Democratic Convention and the 2016 Utah Republican Convention. Voatz was not used during the 2020 Iowa caucuses.

    The findings underscore the need for transparency in the design of voting systems, according to the researchers.

    “We all have an interest in increasing access to the ballot, but in order to maintain trust in our elections system, we must assure that voting systems meet the high technical and operation security standards before they are put in the field,” says Weitzner. “We cannot experiment on our democracy.”     

    “The consensus of security experts is that running a secure election over the internet is not possible today,” adds Koppel. “The reasoning is that weaknesses anywhere in a large chain can give an adversary undue influence over an election, and today’s software is shaky enough that the existence of unknown exploitable flaws is too great a risk to take.”

    Breaking down the results

    The researchers were initially inspired to perform a security analysis of Voatz based on Specter’s research with Ronald Rivest, Institute Professor at MIT; Neha Narula, director of the MIT Digital Currency Initiative; and Sunoo Park SM ’15, PhD ’18 , exploring the feasibility of using blockchain systems in elections. According to the researchers, Voatz claims to use a permissioned blockchain to ensure security, but has not released any source code or public documentation for how their system operates.

    Specter, who co-teaches an MIT Independent Activities Period course founded by Koppel that is focused on reverse engineering software, broached the idea of reverse engineering Voatz’s application, in an effort to better understand how its system worked. To ensure that they did not interfere with any ongoing elections or expose user records, Specter and Koppel reverse-engineered the application and then created a model of Voatz’s server.

    They found that an adversary with remote access to the device can alter or discover a user’s vote, and that the server, if hacked, could easily change those votes. “It does not appear that the app’s protocol attempts to verify [genuine votes] with the back-end blockchain,” Specter explains.

    “Perhaps most alarmingly, we found that a passive network adversary, like your internet service provider, or someone nearby you if you’re on unencrypted Wi-Fi, could detect which way you voted in some configurations of the election. Worse, more aggressive attackers could potentially detect which way you’re going to vote and then stop the connection based on that alone.”

    In addition to detecting vulnerabilities with Voatz’s voting process, Specter and Koppel found that the app poses privacy issues for users. As the app uses an external vendor for voter ID verification, a third party could potentially access a voter’s photo, driver’s license data, or other forms of identification, if that vendor’s platform isn’t also secure.      

    “Though Voatz’s privacy policy does talk about sending some information to third parties, as far as we can tell the fact that any third party is getting the voter’s driver’s license and selfie isn’t explicitly mentioned,” Specter notes.

    Calls for increased openness

    Specter and Koppel say that their findings point to the need for openness when it comes to election administration, in order to ensure the integrity of the election process. Currently, they note, the election process in states that use paper ballots is designed to be transparent, and citizens and political party representatives are given opportunities to observe the voting process.

    In contrast, Koppel notes, “Voatz’s app and infrastructure were completely closed-source; we were only able to get access to the app itself.     

    “I think this type of analysis is extremely important. Right now, there’s a drive to make voting more accessible, by using internet and mobile-based voting systems. The problem here is that sometimes those systems aren’t made by people who have expertise in keeping voting systems secure, and they’re deployed before they can get proper review,” says Matthew Green, an associate professor at the Johns Hopkins Information Security Institute. In the case of Voatz, he adds, “It looks like there were many good intentions here, but the result lacks key features that would protect a voter and protect the integrity of elections.”

    Going forward, the researchers caution that software developers should prove their systems are as secure as paper ballots.

    “The biggest issue is transparency,” says Specter. “When you have part of the election that is opaque, that is not viewable, that is not public, that has some sort of proprietary component, that part of the system is inherently suspect and needs to be put under a lot of scrutiny.”

    Never miss a breakthrough: Join the SciTechDaily newsletter.
    Follow us on Google and Google News.

    Cybersecurity MIT Politics
    Share. Facebook Twitter Pinterest LinkedIn Email Reddit

    Related Articles

    Illuminating the Money Trail: MIT Political Scientist Shines a Bright Light on the Dark Art of Political Lobbying

    Russia Masses Military Equipment Near Ukraine Borders: A Prologue to WWIII?

    MIT Economist’s New Research: The Long Afterlife of the “China Shock”

    Deterrence With Imperfect Attribution: A Better Kind of Cybersecurity Strategy

    “Lost Votes”: What Are the Odds Your Vote Will Not Count?

    MIT: How Putting Warning Labels on Fake News Can Backfire

    Confused by U. S. Elections? MIT Researchers Use Physics to Explain Democratic Elections

    Threat to Democratic Decision Making: ‘Information Gerrymandering’

    Voters Are Influenced by “Information Gerrymandering.” Here’s How.

    14 Comments

    1. Ron McCune on February 19, 2020 9:31 pm

      In this day and age we have to demand that all elections be by paper ballot or else Russia or some one else may try to hack whatever we use. Paper pallots can’t be hacked! The results took a little longer to get but we were never in dispute of the outcome unless we had chad disputes.

      Reply
      • Bruzote on December 26, 2023 6:41 pm

        Elections require trustworthy people to count hand-written ballots. Local elections, which are highly dependent on a small number of people, are “hackable” with a small group of dedicated cheaters working the polls (doing the counting). Larger elections might still be hacked if enough independent small groups all cheat in favor of the same candidate. Basically, you only need a few people at each poll to cheat on the hand count. Still, I trust that system over any e-system not backed up by a hand count. Corrupt politicians are opposed to back-up hand-counting printed ballots. Problem is that the voting software companies invest so much money in bribes, I mean “campaign donations” and sometimes more bribes, that pols in any party are often willing to sell out democracy and approve vulnerable systems without a manual verification mechanism.

        Reply
    2. I R A Darth Aggie on February 22, 2020 6:45 am

      Paper. Pen. Can’t. Be. Hacked.

      Reply
    3. TITA on June 1, 2020 12:13 am

      Thank you very much for the information!

      Reply
    4. kamir bouchareb st on June 20, 2020 6:20 am

      good article

      Reply
    5. tita on November 4, 2020 12:55 am

      GOOD WRITE-UP. I CERTAINLY LOVE THIS SITE. KEEP IT UP!
      http://virtuelcampus.univ-msila.dz/inst-gtu/

      Reply
    6. tassnime on March 4, 2021 12:27 pm

      great article

      Reply
    7. tassnime on April 21, 2021 5:26 pm

      very nice blog post! thank you..

      Reply
    8. ferahtia.FS on May 2, 2021 3:17 pm

      Very informative post. Thanks for share it with us.
      http://virtuelcampus.univ-msila.dz/facscience

      Reply
    9. ferahtia.FS on May 2, 2021 3:17 pm

      good sharing; many thanks
      http://virtuelcampus.univ-msila.dz/facscience

      Reply
    10. ferahtia.FS on May 3, 2021 2:36 am

      Thank you so much for sharing.

      http://virtuelcampus.univ-msila.dz/facscience

      Reply
    11. tita on July 14, 2021 4:00 am

      thank you so much
      http://virtuelcampus.univ-msila.dz/inst-gtu/

      Reply
    12. tassnime on August 30, 2021 3:45 am

      Great, thanks for sharing this blog post.

      http://virtuelcampus.univ-msila.dz/inst-gtu/

      Reply
    13. tita on September 6, 2021 7:12 am

      good post
      http://virtuelcampus.univ-msila.dz/inst-gtu/

      Reply
    Leave A Reply Cancel Reply

    • Facebook
    • Twitter
    • Pinterest
    • YouTube

    Don't Miss a Discovery

    Subscribe for the Latest in Science & Tech!

    Trending News

    289-Million-Year-Old Reptile Mummy Reveals Origin of Human Breathing System

    New Brain Discovery Challenges Long-Held Theory of Teenage Brain Development

    Scientists Discover Plants “Scream” – We Just Couldn’t Hear Them Until Now

    Scientists Discover a Surprising Reason Intermittent Fasting Extends Life

    This Simple Fruit Wash Could Make Produce Safer and Last Days Longer

    Scientists Say Adding This Unusual Seafood to Your Diet Could Reverse Signs of Aging

    Scientists Say a Hidden Structure May Exist Inside Earth’s Core

    Doctors Surprised by the Power of a Simple Drug Against Colon Cancer

    Follow SciTechDaily
    • Facebook
    • Twitter
    • YouTube
    • Pinterest
    • Newsletter
    • RSS
    SciTech News
    • Biology News
    • Chemistry News
    • Earth News
    • Health News
    • Physics News
    • Science News
    • Space News
    • Technology News
    Recent Posts
    • Hidden Parasite Found in Popular Portuguese Lake Raises Health Concerns
    • This Simple Trick Can Boost Your Workout Endurance by 20%
    • This Popular Supplement May Interfere With Cancer Treatment, Scientists Warn
    • Scientists Propose Radical New Way To Detect Alien Life – Without Traditional Biosignatures
    • Scientists Just Discovered Light Can Actually Slow Plant Growth
    Copyright © 1998 - 2026 SciTechDaily. All Rights Reserved.
    • Science News
    • About
    • Contact
    • Editorial Board
    • Privacy Policy
    • Terms of Use

    Type above and press Enter to search. Press Esc to cancel.