The Chief Information Officer of the Electoral Commission, Ian Brightwell,
claimed Halderman and Teague’s discovery was part of efforts by “well-funded,
well-managed anti-internet voting lobby groups,” an apparent reference to our
friends at VerifiedVoting.org, where Halderman and Teague are voluntary
Advisory Board members.
So, the CIO complains it's a smear job by an anti-internet-voting lobby group, (which it apparently was?) Yet at the same time, Brightwell concluded that it was indeed possible that
votes were manipulated. Happily, despite criticizing the messengers, the
Electoral Commission admitted that there was a FREAK flaw with iVote and
scrambled to promptly patch it.
Then they admitted the vulnerability and rushed to patch it. Which is exactly the hoped-for response?So what is South Wales doing wrong here, you know, other than trying to let people vote over the internet, which is a horrible idea, only perhaps matched by the absurdity of our current generation of e-voting machines? I understand their hands are not clean in many other regards with this program, but patching their cipher suite just doesn't seem newsworthy...
BTW, an open source voting machine platform (for use at the polling station) sounds like a great project for USDS or 18F.