Web voting, security and cryptography
Andrea Pasquinucci · Computer Fraud & Security · 2007
Estonia is the first country in the world to allow online voting in its national election. But this month, Computer Fraud & Security features an exclusive article from security consultant Andrea Pasquinucci, which argues that online voting is not yet fraud-proof enough for political elections. He believes online voting is not secure enough to guarantee that votes cannot be sold. He recommends that Web voting should not be used in cases where democracy could be put in jeopardy such as in political elections. But he believes it is acceptable for opinion polls. According to Pasquinucci, Web voting is far from mature and very much work in progress. Cryptography should not be seen as the Holy Grail for handling the end-to-end voting process, as it is often difficult to use, he says. Estonia – casting a vote of trust in the Internet • Estonians were allowed to vote online for the 4 March 2007 national election. • The country tested Internet voting in 2005 in local elections. • To vote, they insert their chipped national identity card into a reader attached to a computer. He points out the many weak points in digital systems that introduce loopholes in voting. Network connections are one example where privacy might be at risk. In practice, it is difficult to design perfect anonymous networks. Yet, during the voting process, it is essential that the IP address of the voter's PC is concealed from the Web server. He recommends that online authentication should not be performed by the same Web server that processes the votes. It is important because the authentication server needs to know who the voters are, but the vote server must not recognize who is voting. Both must be kept completely separate. The vote Web server must also be able to protect votes from manipulation before they are counted. This is achieved by encrypting each vote with the public key of the electoral committee, which means that the votes can only be decrypted with the corresponding private key, which must be key safe until the time to count votes arrives. Andrea Pasquinucci delves into the dangers to democracy of online voting and looks at how it can be made safer to cast a ballot online.