Estonia sues Gemalto for €152M over ID card flaws
reuters.com
reuters.com
Not only did Gemalto fail to notify Estonia in good time about the ROCA flaw (the discoverers of which noticed that Estonia were still issuing vulnerable cards, so notified them themselves), some cards had their private keys generated outside of the card and then inserted, rather than on-card generation. I think Estonia is to be applaued here for handling all this in a sane manner.
[0] https://dan.enigmabridge.com/estonia-hits-gemalto-again-inse...
Just when I'd decided to use my e-Residency for something, it becomes worthless.
They're asking me to reapply for a new ID document and pay the fee all over again. I'd honestly do it, but then they can't hand it over to me in Pakistan and I'm not flying out of the country just to grab an e-Residency card when my previous one hasn't even expired yet.
I guess I'm still a bit sour over this.
By the time I looked into it, I was a month or two late.
Problem was that Gemalto did not tell Estonia that there is security flaw.
That led to rush security fix which could have been worked on for months before not do it in weeks.
That's a hardware design error. The claim is that Gemalto failed to fullfil the contractual clauses about quickly informing the customer (the Estonian state) of the security breach, not the existance of the security breach itself.
https://www.wired.com/2015/02/gemalto-confirms-hacked-insist...
I'm sure the OP wasn't claiming the concept discussed in your link is a universally accepted as secure. That's because someone who thinks any voting method that allows a votes to be bought and sold is of course in a state of sin. Internet voting is one of those methods.
Who knows, the OP may have also not been claiming purely electronic voting is a solved problem. Opinions may vary on that one, depending on how secure you think end-to-end audited voting is in practice. If all voters took the time to do the 60 second audit procedure it would of course be perfectly secure, but that's an unrealistic assumption.
Which leaves a hybrid system - were the voting is done electronically using an end-to-end auditable system and the initial count is done electronically, but each vote is also printed and manually placed in the ballot box by the voter in the normal manner so if something goes wrong they can be manually re-counted.
If that is what the OP is talking about then they are right - such a system is faster to use, gets the counting done near instantaneously, easier to use (particularly for voters with disabilities), is more accurate (because it can point out mistakes in the vote), is less wasteful (because how to vote cards and information on candidates can be presented electronically) and of course is more secure than the existing manual system. And yes, on that the experts agree pretty much universally.
The sad thing is I only know of one electronic voting system that did it that way, and it was only a trial. All other deployed e-voting systems I've seen were mostly windows desktop's enclosed in an impressive looking box.
Some things in this world are very hard to explain.
The Australian Ballot works pretty good. Private voting, public counting.
https://en.wikipedia.org/wiki/Secret_ballot
Like all systems, requires funding and attention, of course.
Comparatively...
There is no electronically mediated equivalent of the one-way hash of dropping your ballot into the box suitable for elections in the USA.
Because our ballots are complicated and our units of administration (precincts) are small. Meaning any end-to-end auditable system for hashing ballots won't generate the necessary hash collisions to hide one's ballot within the herd of ballots.
I'm a Greek citizen. At the voting place of the city where I was born and am registered since, there are many rooms. Depending on the initial letters of your last name, you have to go and vote in a specific one. Each room has at least two randomly conscripted citizens, responsible to strike out your name from the list they have, once you drop your single vote envelope. Reminds me of the jury duty of USA citizens. Every few rooms have police officers (very possibly also randomly chosen) inspecting and protecting the procedure.
What really makes the paper ballots secure is that counting fraud does not scale. It is impossible to do it on substantial number of voting stations with nobody noticing even in semifunctional democracy. With electronic voting scaling an exploit to all voting machines is straightforward.
Paper voting is comprehensible by everyone.
>No single person can even fully observe a single counting station, much less a whole election.
First is possible (just observe the person whos counting), second not, for obvious reasons that you can't be at two places at once.
.. and trust the votes to all be real?
A person voting could put two votes instead of one. (It can still look like one, using the same method that's used for card tricks.) Even if you introduce extra steps, like every paper needing a stamp or something, you're still going to need to trust this stamper person. They could be in on it, and either stamp multiple or leak the stamp design.
The staff could be inserting fake votes into the ballot box before it gets counted, even without actual voters.
The counters could add votes from their sleeves, again classic card trick mechanics.
The counters can remove votes from the pile by stacking two or just sliding one off the table while also performing a distraction. Once again, classic magic trick mechanics that are used for vanishing jewelry etc.
Basically my point is that if the counting station is being staffed by magicians from Vegas, they can produce any result they want without an average person that's observing understanding anything.
Besides, at the end of the day it doesn't even matter, because one counting station is within the margin of error for the whole election.