Backdoor discovered in Swiss voting system would have allowed hackers to alter votes
Full article786 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The issue is related to a cryptographic issue with the way Switzerland’s voting system receives and counts votes.
A team of cybersecurity researchers on Tuesday revealed technical flaws in the Swiss government’s electronic voting system that could enable outsiders to replace legitimate votes with fraudulent ones.
The issue is related to the way Switzerland’s voting system receives and counts votes. Anyone familiar with the sequence of “shuffle proofs” — the cryptographic protocol the system relies on to verify votes — could manipulate ballots that would pass the system’s authentication test, according to a paper published by Sarah Jamie Lewis, Olivier Pereira and Vanessa Teague.
Swiss Post, the country’s national postal service, which developed the system along with Scytyl, a Spanish company, said Tuesday the issue had been resolved. But researchers say this flaw personifies the kind of worst-case scenario election security experts have warned about as more governments move toward paperless voting.
“This system as apparently been audited multiple times, and both Scytl and Swiss Post have not been shy about their confidence in this system. Why did those audits miss this critical issue?” Sarah Jamie Lewis, the executive director of the Open Privacy Research Society, said in a series of tweets. “This code is being held up as ‘state-of-the-art,’ and yet the system contained at least one critical cryptographic vulnerability – apparently left open for years.”
“Let us not downplay this,” she said. “This code is intended to secure national elections. Election security has a direct impact on the distribution of power within a democracy. The public has a right to know everything about the design and implementation of the system.”
Switzerland has experimented with electronic voting since 2004, and has plans to make it a nationwide option as soon as October.
This disclosure comes after the Swiss government offered rewards of up to CHF 50,000 (roughly $50,000) to any researcher who reported vulnerabilities in the e-voting system. The contest is scheduled to run through March 24.
Lewis said she did not participate in the bounty program, but that she is now aware of other issues in the code, though they are not as serious as the one disclosed Tuesday.
“This code is simply not up to the standard we should require of critical public infrastructure,” she said.
More Scoops
Election official says Tina Peters would be consultant, won’t have access to election systems
Shasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction.
Picketed at work, confronted at church: Why election workers have left the job
First major voting vendor, Hart InterCivic, partners with Microsoft on ambitious software security tool ElectionGuard
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/swiss-voting-system-flaw-encryption/