Blockchain voting app is dangerously vulnerable, researchers say

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=1qcIDYwP_NA



Duration: 3:12
29 views
1


Reported today on The Verge

For the full article visit: https://www.theverge.com/2020/2/13/21136219/voatz-blockchain-voting-app-election-software-hacking-mit-research-cybersecurity

Reported today in The Verge.

Blockchain voting app is dangerously vulnerable, researchers say

New research from a team of MIT engineers has found an alarming string of vulnerabilities in a leading blockchain voting system called Voatz. After reverse-engineering Voatz's Android app, the researchers concluded that an attacker who compromised a voter's phone would able to observe, suppress, and alter votes nearly at will. Network attacks could also reveal where a given user was voting and potentially suppress votes in the process, the paper claims.

Most troubling, researchers say that an attacker who compromised the servers that manage the Voatz API might even be able to alter ballots as they arrive, an alarming threat that distributed ledgers should theoretically protect against.

"Given the severity of failings discussed in this paper, the lack of transparency, the risks to voter privacy, and the trivial nature of the attacks, we suggest that any near-future plans to use this app for high-stakes elections be abandoned," the researchers conclude.

Designed as a replacement for absentee ballots, Voatz's blockchain-based voting project has been met with skepticism from security researchers but enthusiasm from many in the tech world, receiving more than $9 million in venture funding. Under the Voatz system, users would cast ballots remotely through an app, with identities verified through the phone's facial recognition systems.

Voatz has already been used in a number of minor elections in the US, collecting more than 150 votes in the 2018 general election in West Virginia.

Voatz disputed the MIT findings in a blog post, calling the research methods "erroneous." The company's main complaint is that the researchers were testing an outdated version of the Voatz client software a




Other Videos By Colin Boyd SEO


2020-02-13Oracle strikes back at Google in Supreme Court copyright case
2020-02-13Half-Life: Alyx will launch on March 23rd
2020-02-13Leverage Python and Google Cloud to extract meaningful SEO insights from server log data
2020-02-13Emma review: Comedy of manners is dazzling and witty but only skims the surface - CNET
2020-02-13Nintendo is launching pop-up Switch demo lounges at select US airports
2020-02-13January 2020 was Earth's hottest January in 141 years of climate records - CNET
2020-02-13Apple adds new AR shopping tools to Home Depot's toolbox - CNET
2020-02-13Google's GameSnacks brings bite-sized web games to slow phones - CNET
2020-02-13DOJ charges Huawei with racketeering, theft of trade secrets - CNET
2020-02-13Apple files patent for a smart home system that could configure itself
2020-02-13Blockchain voting app is dangerously vulnerable, researchers say
2020-02-13Facebook Dating postponed in Europe over GDPR compliance
2020-02-13Copyright could be the next way for Congress to take on Big Tech
2020-02-13AR Pianist app is fun to watch, but that’s about it
2020-02-13You can now directly sync Apple Watch workouts to Strava
2020-02-13Gamers are ditching Radeon graphics cards over driver issues
2020-02-13Here comes the Czinger 21C, born and bred in California - Roadshow
2020-02-13It's now possible to 3D print entire objects in seconds
2020-02-13The Galaxy S20 is the first high-refresh display phone many people will own
2020-02-13How to use Edge’s tools to protect your privacy while browsing
2020-02-13The dongle-hiding Lenovo ThinkBook 14 is great if you get the right screen