
In the news that one of the most respected cryptographs in the world found vulnerability in the data encryption system that will be used in the elections to the Moscow City Duma, the problem is not so much in the revealed vulnerability, but in the fact that this is revealed during the election campaign three weeks before the vote.
The developers, of course, promise to introduce a more stable encryption scheme. Despite the fact that they demonstrated unprofessionalism, it should be borne in mind that they initially delivered unrealistic terms for the development of a reliable system, which requires multiple audits and tests before “combat” use. First of all, I have complaints about the initiators of a hasty decision on Internet voting in the upcoming elections, who decided to put an experiment on the votes of voters without having a reliable system in their hands.
For our part, of course, we will make every effort in the framework of interaction with the developers in order to make voters to the maximum and make sure that the vulnerabilities of the system are minimized, but time is catastrophically not enough.
* * *
The encryption used in the Russian electronic voting system, which will be applied for the first time in the Moscow City Duma on September 8, is “completely unsafe” and can be hacked by attackers in about 20 minutes. This is stated in an article by Pierrik Godry, director of research by the National Center for Scientific Research on France, published on the website of Cornell University.
Details in Russian in RBC: rbc.ru/technology_and_me .../08/ 2019/5d55640b9a7947b1c444371 and in BBC BBC.com/russian/features-49365197
Article Pierrik Godry in the original in English: arxiv.org/pdf/1908.05127.pdf
Original