Earlier quoted context omitted.
I watched the video. It's a load of crap. I mean, here are his arguments (feel free to tell me if I missed something): - voting systems inevitably have to be closed source, loaded on easily compromisable USB stick, connected to internet unguarded and sitting that way for years. In what reality is this nihilistic fatalism a reasonable expectation? - voter has no way of independently verifying that their vote has been…
1. Whole paper ballot process is monitored (and understood) by all parties. They keep each other in check. I can sign up for such monitoring and see for my self (at least in my country). Nobody will allow me to inspect actual machine used to count votes. 2. To hack paper ballot voting, conspirasy must include many more people than e-voting.
Estonian Electronic Identity Card: Security Flaws in Key Management
71–80 of 82 posts
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#72So, an argument that I hear regularly is that having a mandatory centralised and cryptographic ID system really expedites certain ID-related tasks. Can anyone in Estonia comment on this? Within the US and U.K., there’s no mandatory ID, which I think is probably a good thing for civil liberties (no papers please, for instance), but also fosters certain industries such as credit reference agencies and has all sorts of…
Paper signatures and fax are both considered obsolete, the latter is basically never used. Cheques? Never seen them. Logging into any high-value service is done using the eID. If you use local services there's rarely any need for any site specific passwords, password managers, U2F, FIDO(2), GPG or similar identity technology. There's no need to send a pic of yourself to verify your identity anywhere, zero shit like that.
You know how PayPal, Stripe or similar payment processors felt/feel really cool and fast? Yeah, we barely felt that because banklinks have fulfilled that use case for the majority for a really long time now.
There aren't any other examples on the top of my head right now, but they're really not the only things. By now, there's basically an entire generation in Estonia that literally have zero idea how things were before, and are thus often shocked by what and how much is required from them in other countries.
> Are there companies like Jumio and Acuant in Estonia, or has the government rendered them pointless?
They're basically nonexistent.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#73Earlier quoted context omitted.
Regarding your last point, I have a hard time seeing what you mean. The system is audited both internally and externally fairly regularly, the latest report being released just December last year [0]. There is also frequent news coverage, both supporting and criticizing the system [1][2]. One of the current government parties [3] is an active critic of the system. So it seems like a fair stretch to say that discussin…
> The system is audited both internally and externally fairly regularly, the latest report being released just December last year Can you please clarify the 'fairly regularly' part? One of the members of that commission said that this is the first time that this kind of audit has been undertaken: https://digi.geenius.ee/rubriik/uudis/e-valimiste-tooruhma-l... To be fair, there are lots of other reviews having taken p…
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#74Earlier quoted context omitted.
I watched the video. It's a load of crap. I mean, here are his arguments (feel free to tell me if I missed something): - voting systems inevitably have to be closed source, loaded on easily compromisable USB stick, connected to internet unguarded and sitting that way for years. In what reality is this nihilistic fatalism a reasonable expectation? - voter has no way of independently verifying that their vote has been…
Please try to think here in terms of probabilities, not absolutes and about the threat model. 1. Closed source and loaded on an USB stick is the simplest case. But in the end, how will you still know what is the actual code that the eventual tallying system is running? 2. Verification of votes is not about encryption. If you allow it to be unlimited, then you can actually sell your vote. In Estonia, you can verify yo…
1. In cryptographical/philosophical sense that’s a tough problem. But our goal is to improve on existing solution not come up with an absolutely ideal scheme, right? So let’s look at what sort of trust our current system provides us. Do you get to see how the whole system works? No. Does any single person gets to see the whole system for that matter? No. But you are provided with the description of the process and large part of it is happening in the open even though though you can’t attend all the places / oversee everything in a single election due to real life and restrictions. Some people are also provided with the power to inspect arbitrary components of the whole scheme when they see fit and even though they don’t inspect even the whole components all the time and no one is inspecting absolutely everything, these people are attracted from all interested parties and can act on random, so we believe that if there were any symptomatic fault play someone would have found it simply by chance. And we generally don’t believe in conspiracies but we try to counteract them by providing more incentives for people to speak up, get involved, become a whistleblower if that’s necessary so that any largish conspiracy would inevitably become public knowledge quickly enough. Well, we can arrange all of these in electronic voting as well and we can even double down on all the in depth mitigations by providing more monitoring capabilities in real time & possibly even making data openly available in whole after election.
2. You can sell your vote in our current system as well. But somehow that’s fine because we have different standards for what we grandfathered already, am I right? Yeah, you could pay people if they film themselves voting, but there is no evidence of they being widespread so no need to worry. Mail ballots aren’t anonymous and could be spied/spoofed easily but there is no evidence of that ever happening, so no need to worry. Lack of strong ID requirements in US could lead to massive voter fraud but there is no evidence of they ever happening in a large enough numbers to skew the election, so no need to worry about. And yet when it comes to electronic voting, geek versions of Penn and Teller - cryptographers have shown us in their stage shows that they can conceive such situations where the victim gets unknowingly duped into disclosing their vote, or the vote being miscounted. So that means literally anyone could carry out the same attack in practice and at an arbitrary scale (or maybe not but we’d better err on side of caution).
3. How do you know that that nice lady overseeing voting in your district isn’t a secret Trump/Clinton/Nazi/Communist sympathizer? You don’t, but you have a faith in the system as a whole that it won’t crumble because of a single person. Similarly we can use defense in depth tactics in designing election security. The hardware would only be able to run signed code in a minimal environment, you could even make the decided stateless, meaning the code gets reset before each new vote gets accepted, maybe even provide an option for voters to reflash the device themselves (with a click of a button on their phone). Devices themselves don’t have to be generic PCs with USB ports and what not, these could be a really dumb chips enclosed into sealed & transparent casing with each one being certified etc. You could make the system modular by having multiple devices each doing their small thing - like the Unix utilities but with each utility being separate hw and most of them disconnected from any networking / being air gapped with obvious input/output interfaces. There are so many things we could do it we approached this in a sane manner as a serious engineering challenge instead of trying to out-cynic each other.
4,5,6,7 That’s exactly my point, electronic voting can be made even more transparent and with the records being forensically preserved they could be analyzed in full at any time after the votes have been casted (with the operational stuff being able to run all sort of threat hunting / anomaly detection during the Election Day). Granted this assumes the whole system uses the same protocols and is run/overseen by a joint committee which might or might not be viable in US, but the discussion started from Estonia - European country, where this would be totally expected.
9, 10 Not all 0days are noclick RCEs present in a default configuration (of a desktop/mobile). In fact we haven’t seen such a beauty in a long time. So no, there isn’t a price for that as it’s not something you could buy off the shelf. And if you could get one you would burn it pretty fast by using it in such a campaign. Makes much more sense to keep it as a nuclear option as no matter how aggressive in your opinion nation state attackers are, their primary incentive is fear for the survival/integrity of their own country (yes the bears crap their pants thinking about possible armed intervention any year soon and so do the pandas). So no I don’t think there is any conceivable way to exploit large portion of private devices in a country in a uniform fashion. You totally could do that using top bottom approach - sort of like exploiting DC and pushing malware from it via group policy. But in case of Estonia voting apps would be the last tech to use for that. They are already mandated to use governmental services for various everyday tasks, they have centralized ID and there are just a couple of major banks - all of which require having an app for modern banking. So there are already plenty of avenues to wreck havoc for a skillful/motivated attacker. And yet we don’t have panic attacks over it, it’s just operational risk that we seek to understand & mitigate just like in every other enterprise.Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#75Earlier quoted context omitted.
Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.
ID card is mandatory by law, but there aren't sanctions (in my knowledge). You need some kind document though, in US that is usually drivers license. I don't see big difference here.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#76Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#77Earlier quoted context omitted.
Didn't read the paper but it appears to be fresh, so maybe the newsworthy part is that they are still not fixed?
The paper is half for giving a technical overview of the issues and part new analysis based on datamining old certificates. The issues have been mostly fixed, compliance violations however are still badly monitored.
Looks like the ID cards issued after 2018 are not covered, so I guess this really is "old news".
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#78Earlier quoted context omitted.
ID card is mandatory by law, but there aren't sanctions (in my knowledge). You need some kind document though, in US that is usually drivers license. I don't see big difference here.
In the US you are required to have your drivers license while driving, but I do not believe there are any blanket requirements (since it would vary from state to state) that you must be able to furnish identifying documents at all times.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#79> The flaws of the ID-card is a very politically charged topic to discuss in Estonia, having any doubts about the ID-card or e-voting will make you a persona non grata. I somewhat disagree, the discussion tends to get bent by some populist agent provocateurs and some of the initial reactions from the private sector media. (In Estonia, the government media is the most centered out of all news outlets, go figure). What…
Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.
Elsewhere, "Papers, please" tends to be sign of excessive "stop-and-frisk" or movement restrictions, and the idea of having basic ID card seems to not have much of an opposition. Especially since it's much simpler than sometimes circular requirements of "web of trust" confirmations like in UK (though I heard it got better)
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#80Earlier quoted context omitted.
In the US you are required to have your drivers license while driving, but I do not believe there are any blanket requirements (since it would vary from state to state) that you must be able to furnish identifying documents at all times.
Documents are two way streets. You need them to prove your rights. You need document to prove your identity to bank or notary. If you are younger side, document helps validate your age in liquor store. I trying use "american" examples here, but other countries can have other regulations or customs. Document, especially digital one, is very useful. For example, I like do encrypt with id card, when sharing materials ov…
Given the structural deficiencies of the US police (And other police forces) giving them an excuse to stop people is to be avoided unless strictly required.