Live data from Hacker News

Estonian Electronic Identity Card: Security Flaws in Key Management

usenix.org

61–70 of 82 posts

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#61
post #34

Earlier quoted context omitted.

Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…

> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. How many more votes would the party in second place at the last election have needed in order to have won instead? > If some party suddenly receives a lot more votes than they polled for - it will be noticed. Is there a mechanism by which the election could be run again (before the winners of the electio…

> How many more votes would the party in second place at the last election have needed in order to have won instead?

5.8% of the total votes [1] but winning the election is just part of the game. This time around the winning party isn't in power because the runner ups formed a coalition.

> Is there a mechanism by which the election could be run again (before the winners of the election have a chance to prevent this)?

Several - the previous government would still be in power for some time to react, the president has to sign off on the winners, the defense police could intervene, and then there are the courts. None of these entities depend on the newly elected government.

> both hand-counting and digital counting

That would certainly be more secure, but like all security it would be a trade off.

--

[1] https://rk2019.valimised.ee/en/election-result/election-resu...

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#62
post #12

Earlier quoted context omitted.

> I was shocked at how slow business got in the EU in summer, there's for sure a dip in the US with people going on vacation but nothing like Europe in July/August Reminds me of back when I worked for a company that exported machines to the US and my boss told an American customer that we couldn't get a shipment sent in June which meant it couldn't be sent before somewhere in August since key personell was on holiday…

One time here in the US I had to work late hours and weekends to hit an ambitious deadline for a French customer who wanted to review our work before they all went on their vacations.

Oh, that was a nice thank you from us pampered Europeans! /s

Sorry, hope you got some nice overtime bonus (but I fear not.)

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#63
post #56
post #44

Earlier quoted context omitted.

It's not about it being compulsory, but the system being unverifiable end-to-end and any criticism of that being laughed at. If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and no…

I watched the video. It's a load of crap. I mean, here are his arguments (feel free to tell me if I missed something): - voting systems inevitably have to be closed source, loaded on easily compromisable USB stick, connected to internet unguarded and sitting that way for years. In what reality is this nihilistic fatalism a reasonable expectation? - voter has no way of independently verifying that their vote has been…

Please try to think here in terms of probabilities, not absolutes and about the threat model.

1. Closed source and loaded on an USB stick is the simplest case. But in the end, how will you still know what is the actual code that the eventual tallying system is running?

2. Verification of votes is not about encryption. If you allow it to be unlimited, then you can actually sell your vote. In Estonia, you can verify your vote 3 times for 30 minutes after your vote was cast: https://www.oiguskantsler.ee/sites/default/files/field_docum... (point 14 on page 5)

3. Mostly agreed with you about the rate of vulnerabilities. But the issue here is that voting is such an important of how democractic society works that there should be no obvious vulnerabilities or any exploitations of vulnerabilities can be easily discovered. E-voting has neither of these because again, how can we know what code is actually being executed?

4., 5., 6., 7. Yes, one vote can get lost. Hell, thousands can get lost. But on average, I can still count on the process eventually working out due to the observability. Somebody will find ballots thrown in trash, pre-filled ballots, 117% of eligible people voting. Sure, in those cases the country is unsalvageable, but you will at least know that it is happening.

8. OK, but that is neither here nor there.

9., 10. If you open up Google Maps and look one country eastward, you will understand. As a reference, https://en.wikipedia.org/wiki/2007_cyberattacks_on_Estonia Not sure on what their planning divisions are cooking up, but I do not doubt that they will use any angle they can. What is the going price for a Windows 10 0-day anyway, on the order of a few hundred k to 1M, I assume? Peanuts.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#64
post #62

Earlier quoted context omitted.

One time here in the US I had to work late hours and weekends to hit an ambitious deadline for a French customer who wanted to review our work before they all went on their vacations.

Oh, that was a nice thank you from us pampered Europeans! /s Sorry, hope you got some nice overtime bonus (but I fear not.)

Overtime? Ha. Almost all salaried jobs in the US are exempt from overtime laws.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#65
post #56
post #44

Earlier quoted context omitted.

It's not about it being compulsory, but the system being unverifiable end-to-end and any criticism of that being laughed at. If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and no…

I watched the video. It's a load of crap. I mean, here are his arguments (feel free to tell me if I missed something): - voting systems inevitably have to be closed source, loaded on easily compromisable USB stick, connected to internet unguarded and sitting that way for years. In what reality is this nihilistic fatalism a reasonable expectation? - voter has no way of independently verifying that their vote has been…

1. Whole paper ballot process is monitored (and understood) by all parties. They keep each other in check. I can sign up for such monitoring and see for my self (at least in my country). Nobody will allow me to inspect actual machine used to count votes. 2. To hack paper ballot voting, conspirasy must include many more people than e-voting.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#66

> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…

Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.

Correct, wikipedia even documents this:

https://en.m.wikipedia.org/wiki/Your_papers,_please

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#67
post #52

Earlier quoted context omitted.

Ah, right. Yeah I should definitely check with an accountant in the country where I will end up residing.

Yeah, highly recommend that. You can also contact Estonian folks who do understand the idea of running a co in Estonia and living elsewhere which isn't common in a country like Germany as local accountants there may be confused, there's a bunch of people on this list that have gone through at least some govt vetting https://e-resident.gov.ee/marketplace/service-providers/ I personally had a good working relationship…

Would you incorporate again in Estonia?

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#68
So, an argument that I hear regularly is that having a mandatory centralised and cryptographic ID system really expedites certain ID-related tasks. Can anyone in Estonia comment on this? Within the US and U.K., there’s no mandatory ID, which I think is probably a good thing for civil liberties (no papers please, for instance), but also fosters certain industries such as credit reference agencies and has all sorts of weird side effects from bootstrapping things like SSNs and NI numbers into secrets. Are there companies like Jumio and Acuant in Estonia, or has the government rendered them pointless?

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#69

> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…

Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.

Wow - that's like 3 negative "modifier" words. I don't actually know what you're saying with that sentence and I've been reading it for about 3 minutes now.

Re: Estonian Electronic Identity Card: Security Flaws in Key Management

#70
post #57

Earlier quoted context omitted.

> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. How many more votes would the party in second place at the last election have needed in order to have won instead? > If some party suddenly receives a lot more votes than they polled for - it will be noticed. Is there a mechanism by which the election could be run again (before the winners of the electio…

> How many more votes would the party in second place at the last election have needed in order to have won instead? It's a multiple party proportional representation system so who "wins" doesn't really matter that much. > Is there a mechanism by which the election could be run again (before the winners of the election have a chance to prevent this)? I'm not an electoral law expert, but complaints about election proc…

> It's a multiple party proportional representation system so who "wins" doesn't really matter that much.

Obviously by "wins" I meant "becomes the (biggest party in a coalition) government", not "gains the most first preference votes" or some other strawman interpretation. And yes, I admit that it is hard to calculate the minimum number of extra votes that would need to be added to change which party leads the government, but I do think that a good proportional voting system should allow that number to be determined at least to a reasonable approximation.

> I'm not an electoral law expert, but complaints about election process go to National Electoral Committee, which can have its decision contested in Supreme Court.

I wonder how long that process would take in practice, and whether the Supreme Court would decide it had the power to invalidate an election. In particular, what sort of evidence would be required to satisfy the court that it had to demand that remedy? I imagine that "The opinion polls were wrong by 6%" might not be enough, and the political biases of the judges themselves might well be significant in such a situation.

> The e-voting over here is actual e-voting - the vote is purely digital and done remotely. Not in any way related to the digital vote counting machines used in the US.

Yes, the fact that the voting can be done remotely is another problem, since someone can be bribed or coerced into voting a certain way. I believe the mitigation for this is that the voter can supersede their online vote with an in-person vote, but an attacker could quite cheaply work around this by having tracking software on the victim's phone, and henchmen outside the polling stations.

Post reply on HN