Live data from Hacker News

Moscow's blockchain voting system cracked a month before election

zdnet.com

71–80 of 112 posts

Re: Moscow's blockchain voting system cracked a month before election

#71

Earlier quoted context omitted.

So more manipulation is better?

Think of the possible outcomes: -Status quo, old voting system. Corrupt process with vote results that remain in force. Nothing changes. -Novel, manipulated system where the regime loses the vote. The vote gets overturned because it's illegitimate in the wrong way. Maybe embarrassing to the authorities?

> The vote gets overturned because it's illegitimate in the wrong way.

...and it's house cleaning time, because the Enemy of the State(TM) was identified and it was caught red-handed stealing the national election! The dictator can name whoever he wants as the Enemy of the State(TM), sending a few choice persons to path of exile or worse, and the public will eat it up, because their country is under attack!

Just think about what 9/11 did to Bush's support rating.

Re: Moscow's blockchain voting system cracked a month before election

#72
post #16

Earlier quoted context omitted.

This election is already a sham since some opposition candidates were illegally prevented from participating in it.

>some opposition candidates were illegally prevented from participating in it Can you provide a source for that?

https://www.washingtonpost.com/opinions/2019/07/22/protests-...

Re: Moscow's blockchain voting system cracked a month before election

#73
post #68

Earlier quoted context omitted.

I didn’t say it was free and fair.

How do you know he's popular either? State run opinion polls? Asking people on the street about if they like their ruthless dictator or not? Sure.

He is genuinely popular I believe, not just from state run polls but also independent ones. You must understand the fact that he pulled Russia out of one of its worst crises in history and made it a force to be reckoned with again.

Yeah there’s plenty to criticise but that fact alone will make him quite popular. He’s certainly authoritarian, I wouldn’t characterize him as a “ruthless dictator”

Re: Moscow's blockchain voting system cracked a month before election

#74
post #18

Earlier quoted context omitted.

The article doesn't mention this, but if you look at the paper[1] it turns out they aren't using ElGamal with elliptic curve fields -- instead they're using prime fields. In that case, you'd want similar key sizes to RSA. (The "less than 256 bit" part is a red herring, the problem is that they are using key sizes that would only be safe if they were using elliptic curves.) [1]: https://arxiv.org/pdf/1908.05127.pdf

Wow. Even I know this. It's mentioned in every entry level text on EC cryptography.

Haha same. You know it's bad when someone with only an introductory course in cryptography understands what the problem is

Re: Moscow's blockchain voting system cracked a month before election

#75
post #66

Earlier quoted context omitted.

>largely won by Yeltsin by hiring a bunch of consultants from the US to run it You sure it wasn't due to other candidates giving up their ambitions to stop Zyuganov?

Pretty sure. In the first round Zuyganov and Yeltsin were neck and neck. Zuyganov looked _very_ viable to most of the older voting population who had quite enough of the "wild 90's" and wanted to go back to the socialist certainty of how things were before Perestroika, at least to some extent, and Zuyganov promised exactly that. Or at least how they remembered how things were: people tend to forget the bad things fir…

>Russian presidents don't usually try to dance awkwardly on stage

Probably not in the case of Yeltsin though, who willingly jumped from the CPSU Olympus once (which was probably the only relatively bright moment in his career) and was fairly eccentric otherwise, especially when drunk.

I was one year short of the voting age back then, but I remember it very well. What you're saying is true, but you're only describing his "Vote or Lose" campaign. My impression was that he won mostly due to the support of the elites (aka oligarchs who owned the media) faced with the possibility of a communist president, not just because he paid the media. Also the support of other candidates, in particular he convinced Chernomyrdin and Nemtsov, fairly popular back then, to abstain from running for presidency in his favor, after they declared they would run for the office.

Regarding the US consultants, I think his only foreign consultant was Tim Bell, who was British, IIRC he didn't design Yeltsin's Vote or Lose since his experience wasn't directly applicable in Russia, it was Malashenko who designed it.

Re: Moscow's blockchain voting system cracked a month before election

#76
post #51

I'm not surprised. But this sure surprised me:Pierrick Gaudry, from Lorraine University, was able to break the Ethereum-based smart contract encryption in only 20 minutes using nothing more than an average desktop computer and free, publicly available software. Gaudry estimates more modern equipment and sophisticated techniques could crack the encryption in only 10 minutes."

Poor programming and cryptography by the contract developers is always going to be the biggest weakness of smart contracts. This one was developed by a government entity so the quality issue is not really surprising...

> It was developed in-house by the Moscow Department of Information Technology

The developers claim [1] they were only using a weak private key during a "trial period" which doesn't really make sense. Who releases a different public/private key scheme before launching into production?

If the development team doesn't hire outside security testing or request public review - to test the real software - then it's pretty useless. Their response notes a meetup in Moscow in Sept (which is the same month as the election?) which seems like a strange requirement if they were expecting solid public feedback.

1. https://medium.com/@unassuming_teal_crab_127/dear-julia-7bac...

Re: Moscow's blockchain voting system cracked a month before election

#77

Earlier quoted context omitted.

Totally different kind of cryptography. sec256k1 is an elliptic curve, and 256-bit elliptic curves are generally believed to provide comparable security to 3072-bit RSA or DH or ElGamal. (See https://www.keylength.com for a good compilation of reputable comparisons along these lines.)

When I click the reference footnote on that page leading to iad.gov I get an invalid certificate authority error, heh. https://www.iad.gov/iad/library/ia-guidance/ia-solutions-for... )

For obvious reasons, the US government was never an authorized CA in firefox, and the application to be put on the list of trusted CAs was denied. The DoD root cert (for .mil addresses) is similarly distrusted. AFAIK most other browsers operate similarly. If you so desire, you can simply add the FCPCA and DoD certs to your trust store. Or... you know.. not.

https://wiki.mozilla.org/CA:GovernmentCAs

https://bugzilla.mozilla.org/show_bug.cgi?id=478418 (Status: RESOLVED WONTFIX)

https://fpki.idmanagement.gov/crls/

https://www.dau.edu/faq/p/DoD-PKI-Certificates

Although it kinda makes you wonder why China's CA was trusted by default, and it took actual, in-the-wild fraudulent certs before it was revoked.

Re: Moscow's blockchain voting system cracked a month before election

#78
post #77

Earlier quoted context omitted.

When I click the reference footnote on that page leading to iad.gov I get an invalid certificate authority error, heh. https://www.iad.gov/iad/library/ia-guidance/ia-solutions-for... )

For obvious reasons, the US government was never an authorized CA in firefox, and the application to be put on the list of trusted CAs was denied. The DoD root cert (for .mil addresses) is similarly distrusted. AFAIK most other browsers operate similarly. If you so desire, you can simply add the FCPCA and DoD certs to your trust store. Or... you know.. not. https://wiki.mozilla.org/CA:GovernmentCAs https://bugzilla.m…

My understanding is that the FPKI has tons of sub-CAs all doing their own thing and thus couldn't meet the Baseline Requirements. If they could meet the BRs then I'm sure the public comments would be full of comments about the NSA et al, but pre-CNNIC Mozilla was a lot more willing to follow a technical checklist for approval. The the recent DarkMatter request indicates the process isn't so trusting anymore.

Re: Moscow's blockchain voting system cracked a month before election

#79
My old country as always at its best when it comes to propaganda. This elections will be noted in history for the first usage of blockchain instead of for the brutal suppression of opposition https://www.cnn.com/2019/08/14/europe/russia-protests-arrest... (note the helmeted Russian storm-troopers don't have any ID on their uniform, so they are practically unpunisheable for their actions - I mean there is even no guarantee that it is actual law enforcement and not just some dressed up guys who enjoy beating people )

Re: Moscow's blockchain voting system cracked a month before election

#80

The only benefit a "Blockchain" can provide is decentralized time ordering. All other properties must be verified by the client, don't require a blockchain, and are typically some other cryptographic proof. There are many properties of a blockchain that are an anti-feature of voting.

[deleted]
Post reply on HN