r/linux • • 13h ago

Popular Application Brazil election - 560K devices, the most fast e electronic election

Post image
3.9k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

8

u/Jarcode 12h ago

I have worked in high-level administration and happen to have a deep academic familiarity with nascent proposals for E2E validated electronic voting systems, and older implementations like this.

There is a laundry list of problems that still exist, and some of them are fundamentally impossible to solve (registrar corruption in the case of online public ledger systems, chain of custody and ability to scrutinize the process in offline approaches like this).

Offline systems like this can be resistant to external tampering but have serious issues when it comes to their inability to distribute what would otherwise be single points of failure in election integrity. Generally, third party vendors that help design these systems (both software and hardware) effectively hold the keys to the election, whether they admit it or not. Truly auditing these systems is not possible (see "Reflections on Trusting Trust" by Ken Thompson).

This is actually why most modern proposals for electronic voting are now opting for E2E validation, which is still flawed.

1

u/StingMeleoron 12h ago

You know that's a lot of words against a system that has proved to work for multiple times in national scale.

All your concerns are real. The result is the same: the country shows it works, and in a physical scale (logistics) that would rival whole peninsulas (Europe for example).

But anyway. Each nation to its own, right?

2

u/Jarcode 9h ago

You know that's a lot of words against a system that has proved to work for multiple times in national scale.

Proven to work (or even proven to be resistant against external attacks) is not the same thing as universal resilience. Brazil's implementation is considered out of date when compared to modern proposals that still fail to solve the problem in its entirety.

I don't want to come across as condescending but the gist of the situation is that traditional paper ballot elections are far harder to compromise via election official corruption, which is a legitimate issue in many democracies. The ability to introduce scrutineers in traditional elections and verify that every physical ballot cast was associated with an actual person introduces protections that are impossible to replicate with any receipt-free electronic system. Any attempts to compromise traditional elections either rely on improper procedure (ie. ballot box stuffing is effectively impossible with in-place counts at polling places) or a mass conspiracy that requires too many officials to be in on the scheme to not risk exposure.

There's plenty of nuance when it comes to technology in elections. Electronic poll book (EPB) systems are excellent and do not introduce the same risks as an electronic voting system, and electronic tabulators can also be audited and tested in a way that makes the count far smoother and less error prone than hand-counted ballots. The issues start when you try to replace the paper ballot with something digital, because it loses the transparent properties that make our traditional elections secure.

0

u/H_DANILO 4h ago

Holding of signature keys is not a true challenge because of multisig X out of Y. Yes, the system has inherent flaws, yet, they are more expensive and harder to tamper with than ballot voting.

In the center of all hacking and tampering discussion the main core is economics, its cheaper to invest in social media, and campaigning than attempting to tamper with this. There are way too many chances of getting caught. The system doesn't need to be perfect, it just needs to be economically unviable, or better, economically safer than ballot voting.

1

u/Jarcode 2h ago

In the center of all hacking and tampering discussion the main core is economics

If you're familiar with literally any cybersecurity research in this field you would know that this is false. The claim that "hacking" an election is expensive has been false in virtually every demonstration, against both offline and online systems.

This also plays on the myth in election administration that every decision made is a balance between access and security, and that attacks on security must "scale" with costs (in that the costs to compromise an election scale with the number of votes you wish to manipulate). This linear paradigm for understanding security in this context neglects the actual dangers of electronic voting systems -- malicious vendors compromising the system is effectively a binary: if they own the systems and implement a software vote proxying attack, then they own the whole election. The costs are static.

The reality gets even worse in E2E verifiable online systems that are used in some jurisdictions, which suffer registrar vulnerabilities and can be very easily defrauded by automated systems en masse.

1

u/HelpMyCatGotMyBalls 11h ago

Why is auditing impossible? The way they do on brazil is, balots that are in voting posts get chosen randomly, they are then tested live, their softwares hash is verified, they recieve mock votes which gets comapred to the printed reciepts the machines print.

While a suply chain could be compromised you can just test what actualy reaches the hands of the voters. If there is anything wrong, it becomes obvious.

The only real actor that couls realy influence brazils elections is the TSE the Superior Electoral Court, tough they would need to post the wrong voting numbers.

Its not realistic to comprimise the voting machines, they are hundreds of thousands of air gapped sistems that get audited a milion different ways.

The instituitions are the most fragile point. But this is valid to all systems.

If someone wanted to steal a paper balot election, they would likely need internal help. If someone wanted to steal a digital election they would need inside help.

And you solve both of this problems exactly the same way. So eletronic voting is just much faster and convienient. While not having aditional structural vulnerabilities.

That said, they could

3

u/Jarcode 9h ago edited 2h ago

Exhaustive auditing is impossible because of electronic vote proxying if paper ballot backups are not printed (aka. receipt-free systems). Brazil's implementation is uniquely vulnerable to this. The attack goes as follows: a modified version of the software running on the client device proxies a statistically significant amount of votes for one candidate to simply go to another instead, but falsely presents the vote that was cast to the elector. Because of the secret ballot, the digital data recorded does not allow this type of attack to be detected. Because of fundamental issues in computer science, it is not possible to verify the software actually running on a system is what you wrote on it without implicitly placing trust in the vendor(s) responsible for the device's boot integrity. This security model may be sufficient for other applications in computing, but it is a glaring problem in election security.

Hashing does not fix the problem because you can falsely present a hash to be passing if you control the system. And the vendors control the system. This is why I referenced Reflections on Trusting Trust: it is a recognition of the limitations of validation within any computer system; you can't actually verify any of this.

Live testing only introduces an extra requirement for the test: the machines must be able to detect they are being audited. This is relatively trivial if the vendor is committing the attack, as they can consolidate data on the storage mediums transported from these machines for the central count in a way that two data sets exists: the true results and the tampered results. The tampered results can simply sit in some unallocated space on a drive partition and be used for the final count, while auditors can only see the true results. Any artifact from the testing procedure would simply trigger these machines to never write the tampered results in the first place (ie. the timing of votes, number of ballots cast, etc), and the auditability quickly becomes a nightmare.

This is why paper ballot receipts are often used in electronic systems like this because a paper backup that can be verified by the elector holds remarkable significance.

This is also why electronic voting systems are remarked as fundamentally non-transparent systems in election administration because scrutineers cannot actually witness the function of a ballot being deposited. Auditability of these systems pretty much ends at balancing the poll book, which is not sufficient.

E2E validated systems solve a lot of these problems but end up introducing new issues due to excessive trust being placed on the registrar, which requires a regime for voter registration with cryptographic eligibility checks (ie. Estonia). And even then, the registrar basically gains the ability to covertly create tokens for casting ballots, whether the elector actually exists or not.

If someone wanted to steal a paper balot election, they would likely need internal help. If someone wanted to steal a digital election they would need inside help.

This is true, but the difference is the scale in which you need to compromise election officials in order to pull this off. In electronic systems, you need to compromise one or two key people who work for the associated software vendors. In a paper ballot election, you need to compromise election officials and scrutineers at scales that are typically unsustainable (at which point your conspiracy is easily exposed).

It's also important to understand external vulnerabilities are not the same as resistance against internal attacks. Brazil's system is actually considered quite archaic in this field and isn't considered nearly as tamper resistant by other national electoral management bodies.

1

u/HelpMyCatGotMyBalls 8h ago

Thank You for engaging and building presenting arguments! I was tired of 3 line answers.

That said: You have brought a important problem about receipt free systems. It is indeed true, i myself cannot know if my vote was counted correctly. This is mitigated by the live testing. You dont need to know if your vote was correct, if the live testing can show that the vote counts are valid. (I think we can agree on this. So the problem now shifts to the live test)

Before i talk about the live test i must say that the digital ballot prints a session receipt, before it even leaves the perimeter and the public eye, this receipt has a digital signature you can use to verify later in with the government. You can essentially recount based solely on this little papers, so even if the courts tried to meddle in things after the end of they receive the votes, they can be discovered and held accountable.

So it all hinges on one thing, can you trust the machine to correctly count your vote and print it out on the little paper at the end? as long as this works, the rest does not matter. Because while there are not individual receipts, there are group ones. Everything else is as robust as paper elections So once again it all hinges on the live tests.

For the live tests i disagree that its trivial to dupe them. So the set up is like this, all machines are finalized a few days before the elections and get sealed with anti-tamper measures, from here, they get into the custody of either the military or the police. So election day comes, and the machines are sent to their voting places. From these, some machines are randomly selected and then the live testing commences.

(I myself am not fully sure on how they ensure the testing conditions are equal to the voting conditions, but i believe they just test it on site, with public voting records, but i could look it up to be sure)

The live testing goes as follows, known votes are cast and then we compare the votes we know we imputed into the machine with the votes it prints out on the little paper. If those are correct, things are fine because these receipts will be used to verify the later country wide counting. So a machine cannot just print a set of votes and store another on the things that will be sent to the courts. So it doesn't matter if it stores two different results internally, as long as the thing printed on paper is correct we can verify all later steps.

Its very hard for a machine to know if its a test condition. It has no outside connection, no GPS, etc. The clock timing can only be set in advance once they get closed, otherwise it is just guessing. Since it has no communication with outside it would need to determine if its being tested solely on internal conditions. Number of ballots cast, vote timing etc are all variable, and this is true for the testing runs as well. And any choreographed way to activate a testing aware mode could be seen by the live records.

That said, im not saying its impossible, but its much more than corrupting one or two people who hold the keys. You need to compromise hardware design (easily verifiable and compared to the machines that did pass the public security auditing), the testers so they do something to trigger the testing aware mode, etc.

While the system is fundamentally less transparent then normal ballots, by using statistics we can be almost sure nothing funny is going on. Ive calculated some probabilities. If you somehow tampered with 10% of voting machines, if only 440 were chosen to be live audited, the chance of not catching any tampered machine is in the order of 10^(-21).

To actually prove this elections are valid the live testing is the most essential piece. And i believe our methodology is good enough.

Im not sure what other system improve upon, if you could point me to them, i will definetly exert pressure as a citzen to make sure this things get implemented.

1

u/Jarcode 6h ago

Its very hard for a machine to know if its a test condition. It has no outside connection, no GPS, etc. The clock timing can only be set in advance once they get closed, otherwise it is just guessing. Since it has no communication with outside it would need to determine if its being tested solely on internal conditions. Number of ballots cast, vote timing etc are all variable, and this is true for the testing runs as well. And any choreographed way to activate a testing aware mode could be seen by the live records

Time sensitive approaches to determining whether the machine is being tested is not a reasonable mechanism to detect attacks, as the machines should be tested while the actual election is ongoing to completely rule this out. This is also good practice for testing electronic tabulation during an election period, which rules out any timing attacks used in that kind of equipment as well. However, unlike tabulation, reproducing "live" circumstances for testing purposes is relatively trivial.

These voting machines would have to be tested in a way that is public (ie. with scrutineers involved) and consistent with the usage in the election itself. It is possible to implement this with procedural changes, but only solves part of the integrity problem. However, these kinds of testing practices are not employed anywhere, in any jurisdiction that uses these old-school electronic voting systems. This also still suffers a problem in that a process that was previously verifiable by the elector themselves (marking a physical ballot and physically placing it into a ballot box) now requires trusting third-party auditors to establish the same end result.

These systems also require the transportation of digital ballots (along with their paper records) for a centralized official addition, rather than counting in-place with a traditional election. The benefits of in-place counts are incredibly important in any electoral system due to ballot stuffing risks, as any transport of sensitive materials without scrutineers present could allow the manipulation of said materials -- whether digital or otherwise.

That said, im not saying its impossible, but its much more than corrupting one or two people who hold the keys. You need to compromise hardware design (easily verifiable and compared to the machines that did pass the public security auditing), the testers so they do something to trigger the testing aware mode, etc.

Compromised hardware design is not realistically possible to detect if it involves processor microcode or its actual silicon. The ability to introduce hardware backdoors is often reserved with the most sophisticated nation-state attacks, but is not a fantasy. The same applies for locked down firmware in system components like the Intel Management Engine or AMD's Platform Security Processor -- or any other system management firmware on ARM systems. All of the involved vendors are a vector for compromising these systems. While the likelihood of seeing these kinds of attacks in this jurisdiction are quite low, these vectors do exist.

Attacks on the integrity of hardware isn't always soldering on some internal chip as a PCIe or USB device.

I would also like to point out an associated flaw in the software engineering side of things here: I have not seen formal verification used in any of these systems to date. I understand this is a tall order for a full-fledged multitasking operating system, but it is quite feasible for a simpler system design. The stakes involved with elections ought to require the standards associated with FV toolchains in any software attempting to solve these problems. Personally, I think the lack of solutions that attempt to approach this kind of standard simply boils down to the fact that few programmers even know how to write code like this.

Im not sure what other system improve upon, if you could point me to them, i will definetly exert pressure as a citzen to make sure this things get implemented.

There are papers on end-to-end verifiable voting systems that solve the auditability problem with respect to casting a ballot by using a public ledger / chain of trust, so I would start with reading that. These systems also generally solve the count integrity problem with the same cryptography. Unfortunately, they tend to introduce a new class of problem in that the public data cannot be verifiably proven to be associated with legitimate registrations, which is the other can of worms involving registrar corruption. These systems also require regimes for proving eligibility similar to what Estonia has implemented, as without it a particularly glaring external vulnerability is created.

However, I propose a different way of thinking about this: an electronic voting system that produces verifiable ballots, counts them, and physically casts them into a box all for the elector to see can be in theory just as secure as marking a paper ballot. Similarly, you could have an extremely rigorous public auditing regime in place for Brazil's system to approach (but not establish) a comparable degree of trust. But all of these offline systems require electors to show up at a poll anyways, where they could just mark a physical ballot instead. There is no benefit in terms of elector access in exchange for all this complexity and cost, especially in the case of Brazil's system.

The only proposals that actually offer anything tangible in contrast to paper ballots are online systems that allow ballots to be remotely cast, but these suffer a different set of fundamental issues, with even more alarming avenues for attacks.

Thank You for engaging and building presenting arguments! I was tired of 3 line answers.

Well, this is my profession, and I also write software, and also have experience auditing physical and digital election materials. I'm happy to advocate for well-designed EPB software, electronic ballot tabulation, and cryptographic regimes for citizenship/eligibility verification -- these are all incredible innovations and I would love to see these all implemented in my own country. But electronic voting, offline or online, needs to be kept out of our democracies.

One thing I think is missing from the public perception on these issues is just how messy elections really are in practice. The institutional challenges involved with having to hire tens of thousands of election officers on short notice introduces a unique organizational chaos that requires a lot of work to wrangle. We manage to conduct safe, fair, and trustworthy elections because the process itself can be transparently auditable by the average person -- and election officers themselves were often just average people before their appointments, many of which had no experience before working at their poll. Introducing the vast complexity involved in auditing these electronic voting systems completely clashes with these realities and often results in officials just being told to blindly trust these systems.