Moscow's blockchain voting system cracked a month before election
zdnet.com
zdnet.com
> Before going to this, we mention quickly another mistake in the design that could in itself have led to devastating attacks. The generators that are given in public- key.json are generators of the whole multiplicative group. However, due to the Chinese remainder theorem, it is a good practice to use a generator of prime order. In the present case, the generators will have their order divisible by 2, and therefore there is a huge risk that one bit of information leaks from a ciphertext. In a context like e-voting where a ballot can have a very simple form, this bit of information could reveal a lot of the vote (or even all of it in the case of a yes/no question). In principle, we would have had to investigate more in this direction. But due to the main attack that is much easier and far more powerful, we keep this as a remark.
https://arxiv.org/pdf/1908.05127.pdf
This still leaves the question why the developer(s) decided to roll his/her own crypto in this way:
> A possible explanation is a confusion with the key size that can be used when using elliptic curves for which the Number Field Sieve algorithm does not apply.
This is such an obvious mistake that the entire protocol (whether or not it's ever documented) might be vulnerable.
> Another less excusable but still possible explanation might be related to the use of the Ethereum blockchain. In the Solidity programming language that is used to write smart contracts, the bit size of the largest supported integers is 256. Maybe the authors did not want to write a multiprecision arithmetic library that would have been required to deal with larger key sizes. This hypothesis is supported by frequent tests in the source code, checking that the big integers they manipulate are not bigger than SOLIDITY_MAX_INT.
This seems more likely. However, that last sentence checking for overflow sounds like another trove of vulnerabilities.
Moreover, the claim by the developer in the ZDnet article that a patch is forthcoming seems suspect given that it will need to also include multiprecision arithmetic functionality, where there are still more opportunities for snafu.
[1]: https://members.loria.fr/PGaudry/moscow/ [2]: https://golovnev.org/papers/election.pdf
But this sure surprised me:Pierrick Gaudry, from Lorraine University, was able to break the Ethereum-based smart contract encryption in only 20 minutes using nothing more than an average desktop computer and free, publicly available software. Gaudry estimates more modern equipment and sophisticated techniques could crack the encryption in only 10 minutes."
> It was developed in-house by the Moscow Department of Information Technology
The developers claim [1] they were only using a weak private key during a "trial period" which doesn't really make sense. Who releases a different public/private key scheme before launching into production?
If the development team doesn't hire outside security testing or request public review - to test the real software - then it's pretty useless. Their response notes a meetup in Moscow in Sept (which is the same month as the election?) which seems like a strange requirement if they were expecting solid public feedback.
1. https://medium.com/@unassuming_teal_crab_127/dear-julia-7bac...
On September 8th, Russia has "universal voting day", with elections to different regional parliaments, heads of some regions and even additional members of parliament. This year, the campaign have been very political because of Moscow parliament - which was for years treated as a completely uninteresting event with very low news coverage and turnout. This year, however, in response to opposition candidates getting a serious momentum, many have been disallowed to run, triggering escalating protests - some legal, some illegal, with sometimes brutal reaction to the police, which, in turn, led even more people to take part in the protest. This amount of people in the street haven't been seen since 2011 protests.
So, after the trust in the elections, rule of law and democracy process have been eroded this much, I'm genuinely surprised that they even bothered to build a buzzword-fueled voting system.
Users submit an application to vote remotely through a government-controlled site and confirm it by receiving a SMS with code. It is obvious that government is able to submit such an application to its own server without bothering the real user.
The users vote remotely and confirm their identity by providing a code from SMS (again) and the government can just look at the code on the server. It isn't important what cryptography is used there. You don't need to guess random numbers when you have root access to the server.
The observers are supposed to see a tape where some hashes will be printed when someone votes. Maybe they will be allowed to see the registry of voters who chose to vote remotely, maybe they will not be allowed.
I cannot prove this, and this is my personal opinion, so you shouldn't believe me, but I think the government wants an opaque procedure to produce legitimate looking election results with desired outcome. With paper voting, there are too many points of failure: it is difficult to throw the ballots in the box when there is a vigilant observer. Remote voting doesn't have such flaws.
If there was a fraud, it would be difficult to explain to a non-programmer. They don't understand anything, they just see how the program says "hash doesn't match". But maybe it is just a program written by foreign agents (and stored on foreign "Github" servers) producing fake results. For comparison, with paper voting anyone can understand that there is a fraud if you show them the video.
Also, the government party is slowly losing its rating and starts losing regional elections. Remote voting might be a cure for this undesired situation.
And probably any other government (for example Estonian) that implements such an opaque system has similar aims.
As someone living in a state with mail-in ballots, it still boggles my mind waiting in line for physical voting is a thing. Mail-in ballots seem to be the best of all worlds. It's easy. I have time to do the research for who I want to choose. It's all backed by USPS so it's pretty damn secure- as secure as everything else we trust in the mail.
There are certainly other failure modes. In the last Hungarian parliamentary election the ruling party got less than 50% of the votes overall but literally 99% of the postal vote. That seems rather fishy to me.
Anyway, if you have long lines, that means the people organizing your elections are not doing their job right. There need to be more polling places. Other civilized countries manage this, the US would only need to take their democracy seriously.
However, codedokode's concerns are utterly irrelevant. Vast majority of Moscow voters won't use this system, neither care whether the election is scientifically legitimate. Those who do have a presumption of guilt wrt Voting Committee (for a thousand good reasons). As a Moscow sociologist put it: "a political party with 30% support aims to get 90% in the City Duma. How would they do that? Obviously, by cheating and violence".
Thus, codedokode's concerns have no meaning inside Russia, and outside they serve only the purpose intended by the creators of all this: for foreigners to scorn imperfect system, and be relieved when they update it to something passable, for the same ultimate effect - steal the election.
The turnout for elections into Moscow Parliament in 2014 was 21%. 79% of voters didn't vote which means that the government can falsify their votes in remote voting and nobody notices.
This time because of protests the turnout might be higher, like 30% or 40%. This still leaves 60% of people who won't vote and whose votes can be used for falsifications.
""This is a mystery," the French researcher said. "The only possible explanation we can think of is that the designers thought this would compensate for the too small key sizes of the primes involved. But 3 primes of 256 bits are really not the same as one prime of 768 bits."
However, a public key of a length of 1024 bits may not be enough, according to Gaudry, who believes officials should use one of at least 2048 bits instead."
Implementating complex crypto correctly is hard but its really not that tough to use common constructions in a secure way. A few days of reading can tell you how to build a cryptosystem that is at least not total holey cheese.
Obviously using Curve25519 would've made it possible to have a secure setup under the "256 bit arithmetic only" constraints, but I have a feeling (assuming this theory is correct) that someone who thinks that three 256-bit keys are significantly more secure than one 256-bit key probably would've messed that up too.
https://www.iad.gov/iad/library/ia-guidance/ia-solutions-for...)
https://wiki.mozilla.org/CA:GovernmentCAs
https://bugzilla.mozilla.org/show_bug.cgi?id=478418 (Status: RESOLVED WONTFIX)
https://fpki.idmanagement.gov/crls/
https://www.dau.edu/faq/p/DoD-PKI-Certificates
Although it kinda makes you wonder why China's CA was trusted by default, and it took actual, in-the-wild fraudulent certs before it was revoked.
While I'm at it, why can't... Nevermind. The certificate authority system is so damned broken I could sit here for hours. Arrrg.
Funniest thing is, they don't even need to do this. Because nearly all of the mass media is under government control, the incumbents have overwhelming support of the people as it is.
I live in an undemocratic country but even then, we have a fairly good opposition and kind of a free media thanks to the journalists taking the risk of prison and social media so I was really surprised to find out there is no powerful opposition in my country, all of the media belongs to him and we citizens are just dumb people who wouldn't know our country better than outsiders.
The thing is, a leader can't hold that much power. If he lost the election, s/he can play dirty, fight etc. but wouldn't be able to do as s/he pleases with the results. There is always a balance they need to be careful about and not everything is black and white.
Putin's Russia is a very blatant authoritarian regime.
You sure it wasn't due to other candidates giving up their ambitions to stop Zyuganov?
Russian presidents don't usually try to dance awkwardly on stage unless things are truly desperate: https://www.youtube.com/watch?v=cRysHHzLAmM :-)
The entirety of Russia's entertainment industry was paid huge amounts of cash, mostly under the table, to stage concerts in support of Yeltsin. Where that cash came from nobody knows to this day.
Probably not in the case of Yeltsin though, who willingly jumped from the CPSU Olympus once (which was probably the only relatively bright moment in his career) and was fairly eccentric otherwise, especially when drunk.
I was one year short of the voting age back then, but I remember it very well. What you're saying is true, but you're only describing his "Vote or Lose" campaign. My impression was that he won mostly due to the support of the elites (aka oligarchs who owned the media) faced with the possibility of a communist president, not just because he paid the media. Also the support of other candidates, in particular he convinced Chernomyrdin and Nemtsov, fairly popular back then, to abstain from running for presidency in his favor, after they declared they would run for the office.
Regarding the US consultants, I think his only foreign consultant was Tim Bell, who was British, IIRC he didn't design Yeltsin's Vote or Lose since his experience wasn't directly applicable in Russia, it was Malashenko who designed it.
https://www.jacobinmag.com/2017/03/russia-us-clinton-boris-y...
Here is an article in Russian with graphs [1]. This [2] is a graph where axis X contains a turnout percent (how many voters took part in voting at a polling station) and axis Y contains a number of polling stations with that value of turnout.
Here is another graph [3]: axis X contains turnout percent, axis Y contains number of people registered at the polling stations and each point is a station (there are about 90 000 total in Russia). You can see that there are large polling stations with turnout above 90% and number of voters above 2000. You can also see that elections seem to be very popular as majority of the points lie in the right part of the graph.
This graph [4] is built by the same rules, but contains data only on polling stations from one southern region - Ingushetia. You can see how neatly points align along the line at 80% turnout. People of Ingushetia are very active.
These graphs [5] are built by the same rules, but for other region - Chechnya and for 4 different elections in 2011, 2012, 2016 and 2018. The perfect line in 2011 becomes diffused by 2018 and slightly shifts to the left. On the graph for year 2018 one can see that there are "atypical" polling stations who have suspiciously low turnout. One of possible explanations for this could be that in 2018 several dozens of brave volunteers decided to take a risk to go to Chechnya as observers.
[1] https://habr.com/ru/post/352424/
[2] https://hsto.org/webt/2y/xh/wf/2yxhwffbr7oy0escvp1ecvmcjdc.p...
[3] https://hsto.org/webt/4h/3e/ko/4h3ekola6f-to10zgpvlbg9bd1g.p...
[4] https://hsto.org/webt/ri/c6/ul/ric6ulcyzuefrxvnjm7n6g7qcz8.p...
[5] https://hsto.org/webt/dw/j2/bl/dwj2blnsrah7_fwkzbqk4eyucga.p...
If this was about to be used for elections, shouldn't such a critical piece of software have more developers working on it? Why is there only one contributor to the whole project? Why does it have only 37 stars? Is this project well known among the citizens?
So it's more like a proof of concept, and a first step in making larger-scale electronic elections possible in the future (from technological, political, organizational, and public trust standpoints).
> This repository contains the code for electronic voting that will be used for Moscow City Parliament elections.
> Purposes of creating this repository
> The repository was created to allow examination of a source code. Although the purpose of the system is electronic voting, we ask to leave comments and open issues only on technical questions. All comments containing political statements will be deleted.
But the code is incomplete. For example, PHP code looks like a "module" for a larger CMS and cannot be run independently. Also, here [1] there is a header that says "prototype" in Russian. And in several files where there should be the rules and explanations for users there is just a placholder, for example in this file [2]. So I assume this is just an early version of code.
This code was published as a part of a challenge to break the encryption used in remote voting.
There is no git history probably because this is just a snapshot, github is not used for development.
[1] https://github.com/moscow-technologies/blockchain-voting/blo...
[2] https://github.com/moscow-technologies/blockchain-voting/blo...
> Testing cryptographic strength
> Data for testing are in the following directories:
> - data - contains randomly generated data set for applying encryption keys
> - keys - contains encryption keys
> In the beginning of every day, the `data` folder will contain a file with encrypted data and `keys` folder will contain a public key. The task is to decrypt the data in time that is equal to voting duration - 12 hours.
> 12 hours later, original data will be published in the `data` folder and `keys` folder will contain a private key.
[1] https://github.com/moscow-technologies/blockchain-voting/tre...
Electronic voting could also be used simply as a way to save and fast-track the voting process, making it more convenient. Confirm your votes on the app, get to upload them in-bulk to the machine (via QR code or something), and all you have to do is confirm. Lots more time to think about the vote, but you still have t confirm in person.
Longer, more casual access to voting booths and mandatory paid time off is the best thing most democratic/semi-democratic systems could do to help voting these days.
All other properties must be verified by the client, don't require a blockchain, and are typically some other cryptographic proof.
There are many properties of a blockchain that are an anti-feature of voting.
I don't know much of anything about blockchains and voting. What properties do you consider antifeatures?
In case of voting, there are no independent nodes, all modifications to the registry are done by the election committee (or authorised by them) and users can only verify the transaction list. So it would be easier to just present election events as a Merkle tree (voter X has submitted an encrypted ballot Y, and the hash of the registry before this was Z).
But in this case there would be no "blockchain" and no feeling of reliability and security.
If I made a mistake here, I would be happy if someone would point at it.
Thru recurring embarrassment, I've learned that you start with the jurisdiction's laws, rules, procedures, manuals.
Update: Julia Krivonosova, cited by this OC paper, appears to be doing excellent work, and does cover some of the context, assumptions. She'd definitely a better election integrity advocate than I ever was.
Internet voting in Russia. How? https://medium.com/@juliakrivonosova/internet-voting-in-russ...
The Dizzying Whimsy of Russia’s Electoral Laws https://medium.com/@juliakrivonosova/the-dizzying-whimsy-of-... https://www.ridl.io/en/the-dizzying-whimsy-of-russias-electi...
--
It's possible (however unlikely) that a voting system built on top of Etherium is perfectly reasonable for Moscow, Russia, where ever.
Even in the USA, where the Australian Ballot (private voting, public counting) is the gold standard, there are many, many exceptions (compromises made). For very good reasons. For instance, postal balloting. Originally implemented to enfranchise soldiers kept away from their homes for long durations.
Further, even in the USA, YMMV. Local variations impact election administration. For instance, how "voter intent" is adjudicated (when a mistake is made by the voter).
If we don't start with the context and assumptions, we end up talking past each other, and getting no where.
--
Though I am a blockchain skeptic, for voting and tabulation, there are other exciting potential applications. Election administration is a big, complicated problem. While tabulation is the most important step, it's also relatively minor.
Since blockchain is just a shared ledger, it could help with pretty much every other step: candidate filing, political boundaries (GIS), voter registration (eligibility), reporting campaign contributions and expenses, publishing reports (certification), audit of material handling. Etc.
Seriously?
-Status quo, old voting system. Corrupt process with vote results that remain in force. Nothing changes.
-Novel, manipulated system where the regime loses the vote. The vote gets overturned because it's illegitimate in the wrong way. Maybe embarrassing to the authorities?
...and it's house cleaning time, because the Enemy of the State(TM) was identified and it was caught red-handed stealing the national election! The dictator can name whoever he wants as the Enemy of the State(TM), sending a few choice persons to path of exile or worse, and the public will eat it up, because their country is under attack!
Just think about what 9/11 did to Bush's support rating.
Can you provide a source for that?
/s
American provinciality is really bizarre and offputting.
Even if they were, how does one person's comment on HN apply to a couple hundred million people? It obviously doesn't. You're making a similar type of intellectual mistake as the parent (Russia bad; Americans bad).
Sure.
Yeah there’s plenty to criticise but that fact alone will make him quite popular. He’s certainly authoritarian, I wouldn’t characterize him as a “ruthless dictator”
You mean except for the part where his opposition periodically gets assassinated?
A moth ago a scientific paper was published with a formally proven mathematical model which described the last year's election of a Primorskiy kray governor. Results of that vote were nullified in 2 weeks just to make a new temporary governor so he would win an opposing candidate in the next one by using an administrative resource.
If they could win easily, why would they falsify election results or ban opposition candidates? They don't want to play fair.
This is actually a problem for Putin, that he has certain popularity and trust, but it isn't transferred to people from his party, to governors etc.
What's the relevance to a French researcher of publishing Russian protocols in English?