French researcher hacks into Moscow's new e-voting system

Image
AFP Strasbourg
Last Updated : Aug 28 2019 | 11:40 PM IST

A French researcher has exposed a security breach in an electronic voting system to be used in next month's municipal elections in Moscow, potentially giving hackers access to voters' choices.

The University of Lorraine and France's CNRS research institute said this week the cryptographer had taken up a challenge set by Echo of Moscow radio to test the system being rolled out for the vote.

"Less than a month before Moscow tries online voting for electing the city's new parliament, a French cryptographer has just exposed a security breach for the protocol being tested," the two institutions said in a statement.

The researcher, Pierrick Gaudry, was able to crack into the source code being published daily as part of a public test since late July.

Gaudry needed only 20 minutes to break the encryption code, or "private key", that is supposed to protect voters' identities and choices. He used a standard computer and widely available free software.

"According to him, a hacker would have been able to get this private key in just 10 minutes," they said.

"In the worst-case scenario, the votes of all the voters using this system would be revealed to anyone as soon as they cast their vote," Gaudry wrote of his findings in a research paper posted online.

Since mid-July, Moscow has seen a wave of rallies drawing tens of thousands onto the streets after opposition figures were barred from standing in the elections to Moscow's city parliament on September 8.

The online voting system, available through the City Hall website, requires passport information, home address and other sensitive information, and uses text message verification.

Officials say the system testing won't be complete until next week, just days ahead of the election.

Since the publication of Gaudry's paper on August 14, Moscow authorities have said the encryption code has been made more complex, and will be divided into seven distinct parts kept separate until voting ends.

The editor-in-chief of Echo of Moscow, Alexey Venediktov, announced on his Telegram channel Tuesday that he had given Gaudry a prize of one million rubles (USD 15,000). Other awards would be offered to anyone else who exposed breaches in the system.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Aug 28 2019 | 11:40 PM IST

Next Story