{"id":9010,"date":"2018-08-07T18:43:25","date_gmt":"2018-08-07T18:43:25","guid":{"rendered":"https:\/\/davidgerard.co.uk\/blockchain\/?p=9010"},"modified":"2022-06-30T18:07:24","modified_gmt":"2022-06-30T18:07:24","slug":"west-virginia-and-the-voatz-blockchain-voting-system-scaling-and-security-concerns","status":"publish","type":"post","link":"https:\/\/davidgerard.co.uk\/blockchain\/2018\/08\/07\/west-virginia-and-the-voatz-blockchain-voting-system-scaling-and-security-concerns\/","title":{"rendered":"West Virginia and the Voatz &#8220;blockchain&#8221; voting system \u2014 scaling and security concerns"},"content":{"rendered":"<p>In May, West Virginia ran a limited pilot programme using Voatz&#8217; &#8220;blockchain&#8221; voting system, which I <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2018\/06\/05\/the-west-virginia-voatz-blockchain-voting-pilot-another-single-user-blockchain-as-a-database\/\">wrote about in June<\/a> \u2014 it&#8217;s actually a mobile phone voting system, with a blockchain tacked on the side. This was for military people who were eligible to vote in Harrison and Monongalia Counties, but were stationed overseas.<\/p>\n<p>West Virginia were sufficiently impressed to use the Voatz system again, for this November&#8217;s <a href=\"https:\/\/en.wikipedia.org\/wiki\/United_States_midterm_election\">mid-term elections.<\/a> This was reported on local WVNews sites at the <a href=\"https:\/\/web.archive.org\/web\/20180807100214\/https:\/\/www.wvnews.com\/morgantownnews\/news\/voatz-mobile-election-system-set-to-open-up-for-november\/article_ddd3c67e-583f-5abf-abb7-da187bf249db.html\">end of July,<\/a> but exploded when <a href=\"https:\/\/money.cnn.com\/2018\/08\/06\/technology\/mobile-voting-west-virginia-voatz\/index.html\">CNN reported it yesterday.<\/a><\/p>\n<p>And my June post took off again, my <a href=\"https:\/\/twitter.com\/davidgerard\">Twitter<\/a> mentions melted, and I was quoted in a <a href=\"https:\/\/www.vanityfair.com\/news\/2018\/08\/smartphone-voting-is-coming-just-in-time-for-midterms-voatz\">Vanity Fair article<\/a> today on the kerfuffle. So what&#8217;s going on here?<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2018\/06\/05\/the-west-virginia-voatz-blockchain-voting-pilot-another-single-user-blockchain-as-a-database\/voatz-logo\/\" rel=\"attachment wp-att-7607\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7607\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/06\/voatz-logo.jpg\" alt=\"\" width=\"500\" height=\"250\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/06\/voatz-logo.jpg 500w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/06\/voatz-logo-300x150.jpg 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>Why would you run a mobile phone vote?<\/h3>\n<p>Mobile phone voting sounds like an obviously terrible idea in all sorts of ways. But they need to solve a <a href=\"https:\/\/web.archive.org\/web\/20180807100214\/https:\/\/www.wvnews.com\/morgantownnews\/news\/voatz-mobile-election-system-set-to-open-up-for-november\/article_ddd3c67e-583f-5abf-abb7-da187bf249db.html\">genuine<\/a> <a href=\"http:\/\/www.govtech.com\/biz\/West-Virginia-Becomes-First-State-to-Test-Mobile-Voting-by-Blockchain-in-a-Federal-Election.html\">problem:<\/a><\/p>\n<blockquote><p>&#8220;Think of a soldier on a hillside in Afghanistan or a sailor under the polar ice caps. They don\u2019t have access to U.S. mail. Sometimes they\u2019re in a classified area such as a nuclear sub or simply don\u2019t have access to scanners, fax machines and that sort of thing. They do have access to the internet, mobile devices. It\u2019s a tremendous solution to a very difficult problem and with West Virginia having the highest per capita volunteers in the U.S. military, we owe it to them.&#8221;<\/p>\n<p>\u201cI\u2019ve had voters who have overnighted to our jurisdiction and paid over $50 to do so, and it still didn\u2019t get back to us by voting day.\u201d<\/p><\/blockquote>\n<p>The voters are identified by biometrics. The Voatz system will be limited to military personnel on deployment \u2014 people whose biometrics are thoroughly known and documented. It&#8217;s entirely optional, and soldiers can use a conventional paper vote instead if they want to.<\/p>\n<p>The pilot programme in May wasn&#8217;t huge \u2014 literally 11 voters from Monongalia County used the system. &#8220;I think all 11 military voters who used it in our county were pleased with it.&#8221;<\/p>\n<h3>Mobile phone voting: &#8220;a horrific idea&#8221;<\/h3>\n<p>Obviously, Voatz want to expand mobile phone voting. But the notion is <a href=\"https:\/\/money.cnn.com\/2018\/08\/06\/technology\/mobile-voting-west-virginia-voatz\/index.html\">controversial,<\/a> to say the least:<\/p>\n<blockquote><p>&#8220;Mobile voting is a horrific idea,&#8221; Joseph Lorenzo Hall, the chief technologist at the Center for Democracy and Technology, told CNN in an email. &#8220;It&#8217;s internet voting on people&#8217;s horribly secured devices, over our horrible networks, to servers that are very difficult to secure without a physical paper record of the vote.&#8221;<\/p>\n<p>Marian K. Schneider, president of the election integrity watchdog group Verified Voting, was even more blunt. Asked if she thought mobile voting is a good idea, she said, &#8220;The short answer is no.&#8221;<\/p><\/blockquote>\n<p>If mobile phone voting can be usably secure at all, it will only be in a small and highly constrained system such as these pilot programmes.<\/p>\n<h3>How the blockchain bit works<\/h3>\n<p>The &#8220;blockchain&#8221; part of Voatz&#8217; system is functionally superfluous \u2014 it&#8217;s a ledger of the votes, kept on a four-node Hyperledger instance run entirely by the company. So it&#8217;s another <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2017\/11\/26\/the-world-food-programmes-much-publicised-blockchain-has-one-participant-i-e-its-a-database\/\">single-user &#8220;blockchain&#8221;<\/a> being used as a clustered database.<\/p>\n<p>I must note that Voatz <a href=\"https:\/\/twitter.com\/Voatz\/status\/1026847281021181952\">disagree<\/a> with this characterisation, referring me to the FAQ on <a href=\"https:\/\/wvexperience.voatz.com\/faq.html\">wvexperience.voatz.com<\/a> (go to <a href=\"https:\/\/wvexperience.voatz.com\/faq.html\">the page,<\/a> click &#8220;Blockchain &amp; Security&#8221; on the left):<\/p>\n<blockquote><p>Once the voter is verified, Election jurisdictions start the process by sending a qualified voter a mobile ballot. Contained in the mobile ballot are &#8220;tokens&#8221; \u2014 think of them as potential votes \u2014 which are cryptographically tied to a candidate or ballot measure question. The number of tokens a given voter receives is the same as the number of ovals he or she would have received on a paper ballot handed out at the voter&#8217;s precinct or sent through the mail. The voter makes selections on the Voatz app on their smartphone. As they make selections, it alters the tokens with their selections (like filling in a ballot oval). Overvotes are prevented, as each voter only receives a total number of tokens as they have potential votes. Once submitted, the votes for choices on the ballot are verified by multiple distributed verifying servers called &#8220;verifiers&#8221; or validating nodes. Upon verification, the token is debited (i.e. subtracted) from the voter&#8217;s ledger and credited (i.e. added) to the candidate&#8217;s ledger. The blockchain on every verifier is automatically updated and the process repeats as additional voters submit their selections.<\/p>\n<p>The Voatz blockchain is built using the HyperLedger blockchain framework. The minimum number of validating nodes used is 4. These get expanded to 16 for the pilot as needed depending on the anticipated number of participants. Additional scaling is planned for the future.<\/p><\/blockquote>\n<p>Though I still think this constitutes a private clustered database \u2014 and certainly as long as Voatz control all verification nodes, or even if they control who gets to run a verification node.<\/p>\n<p>The token arrangement seems bizarrely convoluted and gratuitous \u2014 cryptographic tokens are widely used, work well, and they don&#8217;t need a blockchain. This still feels to me like implementing a naturally-centralised system on a blockchain because you want to say you used a blockchain.<\/p>\n<p>The functional aspect of the blockchain bit is <a href=\"https:\/\/web.archive.org\/web\/20180807100214\/https:\/\/www.wvnews.com\/morgantownnews\/news\/voatz-mobile-election-system-set-to-open-up-for-november\/article_ddd3c67e-583f-5abf-abb7-da187bf249db.html\">promotional:<\/a><\/p>\n<blockquote><p>Secretary of State deputy legal counsel and elections officer Donald Kersey said this means votes on Voatz become immutable and tamper proof, with records virtually impossible to crack.<\/p><\/blockquote>\n<p>Anyone reading this knows that <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2018\/06\/28\/ibm-the-gdpr-and-blockchain-whatever-that-word-specifically-means\/\">none of that automatically follows<\/a> from <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/business-bafflegab-but-on-the-blockchain\/\">bolting a blockchain onto the side<\/a> of your system.<\/p>\n<p>There&#8217;s also a huge problem with the idea of recording the votes themselves on a permanent ledger.<a href=\"https:\/\/josephhall.org\/\"> Joseph Lorenzo Hall<\/a> in Vanity Fair asks you to &#8220;imagine that in 20 years, the entire contents of your ballot are decryptable and publicly available&#8221; \u2014 rather than on pieces of paper that can&#8217;t be traced back to you personally.<\/p>\n<h3>Voatz in Utah, April 2018 \u2014 1400 voters go back to using paper<\/h3>\n<p>One thing that has to work with absolutely 100% reliability is voters being able to vote at all.<\/p>\n<p>Tony Adams <a href=\"https:\/\/twitter.com\/tadams0620\/status\/1026846195971514368\">notes<\/a> the 14 April 2018 <a href=\"https:\/\/www.ucrp.org\/2018-nominating-convention\/2018-nominating-convention-results\/\">Republican County Convention<\/a> in Utah County, Utah, a caucus with about 1400 voters. They <a href=\"https:\/\/ucrp.voatz.com\/\">tried using Voatz,<\/a> and it scaled so badly that they had to revert to using paper ballots.<\/p>\n<p>Here&#8217;s some voter reviews:<\/p>\n<blockquote><p>This app is terrible. Good thing there were backup paper ballots &#8230; seriously awful<\/p>\n<p>Just wow! What an epic failure of an app. I had to sign up several times, validate, scan and wait wait wait for a &#8220;connection issue&#8221;. Me and the 1400 ish Delegates ended up doing paper ballots which made our convention go several hours overtime.<\/p>\n<p>After going through the lengthy and counter-intuitive verification process, I could not understand the directions and ended up calling them over the phone before the Utah County Republican precinct caucus meeting. I was exited to vote and still be with my kids. When voting was supposed to happen the server was over loaded. Eventually the app stopped working. I had to reinstall and reverify. Could not vote. The next day I come to find out my precinct gave up on the app and just used paper ballots instead. Major let down.<\/p>\n<p>Bye the way it also failed during many local caucus meetings a few weeks before. Out of 273 caucus meetings it only worked for three of them.<\/p><\/blockquote>\n<h3>Voatz&#8217; security embarrassments<\/h3>\n<p>Election manipulation is, of course, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Russian_interference_in_the_2016_United_States_elections\">huge news at the moment.<\/a> So Voatz should have expected <em>tremendous<\/em> scrutiny of their security and technological transparency, in every detail.<\/p>\n<p>It&#8217;s unfortunate they had an <a href=\"https:\/\/twitter.com\/Voatz\/status\/1026700029665402880\">old server still up<\/a>\u00a0\u2014 always remember to stop your old Amazon Web Services instances!\u00a0\u2014 for Kevin Beaumont to <a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1026607447996354561\">find at a glance:<\/a><\/p>\n<blockquote><p>The Voatz website is running on a box with out of date SSH, Apache (multiple CVSS 9+), PHP etc. Pop3 to the Internet, NTP, PHP3, <a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1026609242999009280\">Plesk from 2009.<\/a> The database (on Azure) has an admin panel on port 8080, no SSL. I\u2019m off to bed.<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2018\/08\/07\/west-virginia-and-the-voatz-blockchain-voting-system-scaling-and-security-concerns\/porg-cowboy-riding-porg-dog\/\" rel=\"attachment wp-att-9059\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-9059\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/08\/porg-cowboy-riding-porg-dog-150x150.jpg\" alt=\"\" width=\"150\" height=\"150\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/08\/porg-cowboy-riding-porg-dog-150x150.jpg 150w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/08\/porg-cowboy-riding-porg-dog-300x300.jpg 300w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2018\/08\/porg-cowboy-riding-porg-dog.jpg 400w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>The United States needs some form of vetting process for online voting in elections. I\u2019m a foreign dude with an avatar of a cowboy porg riding a porg dog on Twitter who appears to have done more investigation of the security implications of this than anybody. Bonkers, America.<\/p>\n<p>If a startup (I\u2019m sure they\u2019re nice people btw) with 2m in funding approaches and says they have biometric security and Blockchain it still need independent vetting, at least to level a crab paste company would get a HR provider. There needs to be oversight here.<\/p>\n<p>I can\u2019t even find a Voatz CISO (or security person) to report stuff to. They have long unpatched boxes and weird services online, this wouldn\u2019t pass a crab paste company pentest.<\/p>\n<p>I used to work for a crab paste company with little to no IT budget, I wouldn\u2019t have accepted this into production, but apparently the world\u2019s most prosperous nation will.<\/p><\/blockquote>\n<p>Voatz say this was an old test site \u2014 but leaving exploitable old servers up is a gateway to your new stuff. Did they check that nobody could get from the old server to the new servers? Are they in different Amazon VPCs?<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Crucially, I find it unlikely that if you&#39;re running a Plesk from 2009 and a run of the mill poorly written PHP app on the user facing site that your security is all that great on the backend. There&#39;s at least someone in the org that is totally fine with an exploitable site.<\/p>\n<p>&mdash; Keith Gable \ud83c\uddfa\ud83c\udde6\ud83c\udf3b (@ZiggyTheHamster) <a href=\"https:\/\/twitter.com\/ZiggyTheHamster\/status\/1026864221328293888?ref_src=twsrc%5Etfw\">August 7, 2018<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>&nbsp;<\/p>\n<p>Voatz claim the West Virginia election site was audited by <a href=\"https:\/\/www.securityinnovation.com\/\">Security Innovation<\/a>, <a href=\"https:\/\/iinfosec.com\/\">Ingalls Information Security<\/a>, <a href=\"https:\/\/www.hackerone.com\/\">Hacker One<\/a>, <a href=\"https:\/\/www.hackerguardian.com\/\">Comodo\/HackerGuardian<\/a> and <a href=\"https:\/\/www.ssllabs.com\/\">Qualys SSL Labs.<\/a><\/p>\n<p>Kevin asked them about this, and <a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1026868106528993280\">says<\/a> that &#8220;One of the companies listed as providing a security audit says they did not provide a security audit.&#8221;<\/p>\n<p>Hacker One just means Voatz have a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Bug_bounty_program\">bug bounty programme<\/a> \u2014 though I couldn&#8217;t find where they&#8217;ve listed it. <b>Edit:<\/b> it&#8217;s on <a href=\"https:\/\/hackerone.com\/voatz\">Hacker One&#8217;s own site.<\/a><\/p>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Qualys\">Qualys<\/a> just provides a <a href=\"https:\/\/www.ssllabs.com\/ssltest\/\">free SSL server test<\/a> for any public website \u2014 and Voatz do seem to mean the free SSL test, as the <a href=\"https:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=voatz.com&amp;hideResults=on\">free test of their website<\/a> was the link they provided to Vanity Fair as a sample of their security practices.<\/p>\n<p>In fact, Voatz tweeted this quick SSL server test as <a href=\"https:\/\/twitter.com\/TheBlueMeme\/status\/1026771600853454849\">evidence<\/a> their servers had passed <em>penetration<\/em> tests.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Yes, you can do a quick self verification SSL test here to get a sample of that &#8211; <a href=\"https:\/\/t.co\/7GEZRPqdXX\">https:\/\/t.co\/7GEZRPqdXX<\/a><\/p>\n<p>We always appreciate constructive feedback to improve.<\/p>\n<p>&mdash; Voatz (@Voatz) <a href=\"https:\/\/twitter.com\/Voatz\/status\/1026798299335012352?ref_src=twsrc%5Etfw\">August 7, 2018<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>&nbsp;<\/p>\n<h3>Summary<\/h3>\n<p>To be fair, the Twitter is probably just the social media person, having an absolutely terrible day \u2014 not one of the technical people. But they need to get the techies on the job straight away.<\/p>\n<p>The failure to scale in Utah is a serious problem, though overseas military voters are likely to be a small enough use case for the system to cope.<\/p>\n<p>But mobile phone voting worries people a lot.<\/p>\n<p>Voatz need to put out public reports \u2014 as fully detailed and transparent as is feasible \u2014 on every aspect of the entire system, as soon as they can.<\/p>\n<p>Treat every scornful tweet today as a pointer to an opportunity to excel. A chance to restore confidence.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/Voatz?ref_src=twsrc%5Etfw\">@Voatz<\/a>, we&#39;re not just being mean.  You&#39;re going to be hit by the best state and private hackers in the world.  Be prepared or go away.<\/p>\n<p>&mdash; Al Swearengen (@E_A_Swearengen) <a href=\"https:\/\/twitter.com\/E_A_Swearengen\/status\/1026887451413864448?ref_src=twsrc%5Etfw\">August 7, 2018<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><b>Update:<\/b> Voatz have <a href=\"https:\/\/blog.voatz.com\/?p=454\">responded<\/a> to everyone\u2019s security concerns! \u201cIn the West Virginia pilot, a paper ballot is printed for each mobile ballot submitted on the blockchain, then tabulated like a normal absentee ballot.\u201d<\/p>\n<br><br><div align=\"center\"><p><a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\"><img src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/10\/become_a_patron_button.svg\" alt=\"Become a Patron!\" title=\"Become a Patron!\" width=217 height=51><\/a><br><p style=\"align:center;\" class=\"patreon-badge\"><i>Your subscriptions keep this site going. <a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\">Sign up today!<\/a><\/i><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>The slapstick comedy horror saga of a plucky little blockchain startup who aren&#8217;t quite ready for every state-level hacker in the world, or more than eleven voters.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[74,694,693],"class_list":["post-9010","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-blockchain","tag-voatz","tag-west-virginia"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/9010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/comments?post=9010"}],"version-history":[{"count":65,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/9010\/revisions"}],"predecessor-version":[{"id":10393,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/9010\/revisions\/10393"}],"wp:attachment":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media?parent=9010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/categories?post=9010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/tags?post=9010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}