‘Critical’ Vulnerability Found in Australian Internet Voting System in Advance of Next Week’s Election

'Major security hole' could allow attacker to read, change votes...

Share article:

Another new Internet Voting system, another major vulnerability to massive election fraud discovered along with it. This time in Australia, as reported by ABC:

A “major security hole” that could allow an attacker to read or change someone’s vote has been discovered in the New South Wales online iVote platform, security experts say.

The iVote system allows people to lodge their votes for Saturday’s state election online, instead of visiting a physical polling station.

It aims to make voting easier for the disabled or for people who live long distances from polling booths.

However computer security researchers said they found a critical issue and alerted the NSW Electoral Commission on Friday afternoon.

The commission said the problem was fixed over the weekend and it expected 200,000 people would use the system in the lead up to the election.

Well. If the people who run it said it was fixed, why worry? (Just because they also said it was secure in the first place? Silly you.)

“Just because they’ve patched this particular bug that they’ve been specifically notified of does not mean that they’ve fixed the fundamental questions around the security and verifiability of the system,” said University of Melbourne’s Vanessa Teague, who discovered the security vulnerability. “If anything the existence of this one particular bug serves to bolster the argument that these kinds of bugs are probably inevitable in these kinds of systems”…

“We’ve been told repeatedly that votes are perfectly secret and the whole system is secure and it can’t be tampered with and so on, and we’ve shown very clearly than that’s not true – that these votes are not secret and they can be tampered with,” Ms Teague said.

She said the attack could allow another person to either read, or even manipulate a vote, before it was sent to the electoral commission’s servers.

“The analogue would be pulling someone’s postal vote envelope out of the post, pulling out their vote and finding out how they intended to vote and then putting a different ballot in instead,” Ms Teague said.

“The point of course with the electronic equivalent is that an attacker wouldn’t necessarily need to be in New South Wales to do this and they could potentially do this in an automated way to a very, very large number of votes.”

Ms Teague said the voter would be unaware their vote had been changed.

The Chief Information Officer with the NSW Electoral Commission offered this unfortunate quote to the ABC: “We are confident however that the system is yielding the outcome that we actually initially set out to yield,” before adding: “and that is that the verification process is not telling us any faults are in the system.”

The ABC also notes that “The computer code of the iVote platform is not open source and is not available broadly for security experts to review.”

Other than that, sounds like a fantastic idea!

We’ve written about so many Internet Voting disasters over the years, along with scientifically supported reasons why it can never be done safely or verifiably, that we’ll just summarize by sharing this quote from our 2013 article about L.A. County’s plans for a new voting system which, while set to be 100% unverifiable after an election, as currently planned, at least does not include Internet Voting, according to our interview at the time with Los Angeles County Registrar-Recorder/County Clerk Dean Logan:

We have long detailed the madness of Internet Voting. Among our coverage, we’ve documented a number of disastrous attempts at Internet Voting systems and the many dangers they pose to security and oversight, as well as the warnings against them by computer science and security experts, and Election Integrity experts.

One need only look back to Washington D.C.’s disastrous experiment in Internet Voting, which almost went live in 2010 for overseas and military voters. The plans to use the system were scrapped at the last minute after it was hacked and completely taken over by “white hat hackers” (University of Michigan computer students and their professor), who had gained such total command of the system in mere hours that they were not only able to change every vote already cast on it during a mock election, but inserted a script into the system to change all future votes invisibly as well. They even modified all of the system’s main passwords to thwart similar attempts to hack the system that they discovered to be ongoing by computers from both Iran and China.

There have been many other disasters in Internet Voting — from a 2012 online Canadian election attacked by some 10,000 computers, to a 2012 CA State University student body election that was hacked by one of the candidates in order to gain control of an annual salary and the student government’s $300,000 budget, to this year’s embarrassment by the Academy of Motion Picture Arts and Sciences which attempted to use Internet Voting for the first time this year, to disturbing and questionable effect.

The non-partisan election integrity group, VerifiedVoting.org posted a “Statement on the Dangers of Internet Voting in Public Elections,” signed by nearly a dozen top computer science and security experts with backgrounds in electronic voting systems. The letter explains that “Cyber security experts at the National Institute of Standards and Technology and the Department of Homeland Security have warned that current Internet voting technologies should not be deployed in public elections,” as they “cannot be properly protected and may be subject to undetectable alteration.”

* * *
Please help support The BRAD BLOG’s fiercely independent, award-winning coverage of your electoral system and much more — now in our TWELFTH YEAR! — as available from no other media outlet in the nation…

MONTHLY BRAD BLOG SUBSCRIPTION
ONE-TIME DONATION

Choose monthly amount…

(Snail mail support to “Brad Friedman, 7095 Hollywood Blvd., #594 Los Angeles, CA 90028” always welcome too!)

Share article:

Reader Comments on

‘Critical’ Vulnerability Found in Australian Internet Voting System in Advance of Next Week’s Election

3 Comments

(Comments are now closed.)


3 Responses

  1. 1)
    Lowell Finley said on 3/24/2015 @ 9:20am PT: [Permalink]

    Thanks for covering this important story. The iVote Internet voting system was developed in partnership with Scytl, a Spanish company that has been successfully promoting its Internet voting system all over the world, including in the U.S., as completely secure against tampering and completely protecting ballot secrecy.

  2. 2)
    Michael G said on 3/25/2015 @ 10:00am PT: [Permalink]

    I’m surprised the personal privacy wanks aren’t all over this. If, as is widely suspected, the CIA has planted bugs in the root systems of most computers, any computer-related voting should be laughed at without a second thought, especially through networked systems.

    Hey, Brad, in light of how simple it is to make money off such vulnerable systems as you’ve demonstrated endlessly, and as knowledgeable you are about these systems, maybe you should consider starting a computerized voting system yourself. The ironies will get a lot of attention and sales and then you can sell the company and not worry about raising money from your readers.

  3. 3)
    Brad Friedman said on 3/25/2015 @ 6:39pm PT: [Permalink]

    Michael G –

    If, as is widely suspected, the CIA has planted bugs in the root systems of most computers…

    Along those lines, you may enjoy this piece of ours from 2009: CIA Warning: ‘E-Voting Not Secure’ – U.S. EAC Finally Releases Complete Transcript of Cybersecurity Expert’s Stunning Remarks

    maybe you should consider starting a computerized voting system yourself. The ironies will get a lot of attention and sales and then you can sell the company and not worry about raising money from your readers.

    I like that last part! But, other than that, I couldn’t do it. Sure, I could make money selling crack, and I think it should be legal to sell crack, even if I think selling (and/or using) crack is a bad idea. So, even if I could make money at it…well, you get the idea. 🙂

    (Though, I should add, if crack were legal to sell, I think I would prefer to sell that over an e-voting system!)

(Comments are now closed.)


Please help The BRAD BLOG, BradCast and Green News Report remain independent and 100% reader and listener supported in our 23rd YEAR!!!

ONE TIME
any amount...

MONTHLY
any amount...

OR VIA SNAIL MAIL
Make check out to...
Brad Friedman/
BRAD BLOG
7095 Hollywood Blvd., #594
Los Angeles, CA 90028

RECENT POSTS

But Here’s Another Post That Comes AFTER the Stay-on-Top Test!

But is it really under the sticky post?

Trying Out Stay-on-Top Functionality

How does it work?

You tell me!

‘Dangerous Times’: Climate Scientist Warns Trump ‘Censorship’ Endangering National Security: ‘BradCast’ 3/6/2026

Guest: Dr. Peter Gleick; Also: Admin deported at least 50 legal Venezuelan migrants; Judge says South Sudan deportations violated court order

This is the Sub Sub title line. Have added it so that we can see how the spacing works everywhere with both sub headers...

TEST

Guest: Election expert Marilyn Marks on GA 2018 Lt. Gov. election contest as state moves to unverifiable barcoded ballots; Also: FL 2020 GOP power-grab update; IA Repubs vote to NOT count absentee ballots...

Investigators reportedly examining federal judge's long history of alleged domestic abuse, while Congressional impeachment looms...

The Attempted 2018 Voter Suppression Begins: ‘BradCast’ 8/20/2018

And other news, both good and bad, around the country and world, 78 days out from the midterm elections...

A New Test Post for Linux61

This is one of those famous sub-titles you've heard so much about, that have been so vexing

And this, believe it or not, is a sub-sub-title!...

Sunday ‘Cutting Corners’ Toons

THIS WEEK: Big Barbaric Bill ... Conman's Clowns ... Anti-Semitism ... In Memoriam ...

‘A World of Tyrants, Bribes, and Influence’: ‘BradCast’ 5/22/2025

Guests: Heather Digby Parton of Salon, 'Driftglass' of 'Pro Left Podcast'...

‘Green News Report’ – May 22, 2025

With Brad Friedman & Desi Doyen...

And Then They Came for Members of Congress…: ‘BradCast’ 5/20/2025

Guest: Attorney Keith Barber; Also: Noem doesn't know what Habeas Corpus means; Paramount owner wants CBS News to roll over to Trump...

‘Green News Report’ – May 20, 2025

With Brad Friedman & Desi Doyen...

Appeals Court Blocks Last Route for Voters to Challenge Violations of the Voting Rights Act: ‘BradCast’ 5/19/2025

Guest: Justin Levitt, former Dep. Asst. A.G. at DOJ; Also: Springsteen sounds alarm; Far-right loses in Romania; SCOTUS blocks Trump again...

Sunday ‘Now Hoarding’ Toons

THIS WEEK: From the Middle East ... to Capitol Hill ... and Across the MAGAVerse ...

Mad World: ‘BradCast’ 5/15/2025

Birthright citizenship and nationwide injunctions at SCOTUS; GOP tax and health care cuts in the House; Eliminating FEMA, dismantling NWS before hurricane season; Noem's surreal tattoo testimony; Souter's warning...

‘Green News Report’ – May 15, 2025

With Brad Friedman & Desi Doyen...

About Brad Friedman...

Brad is an independent investigative journalist, blogger and broadcaster.
Full Bio & Testimonials…
Media Appearance Archive…
Articles & Editorials Elsewhere…
Contact…
He has contributed chapters to these books…
…And is featured in these documentary films…

BRAD BLOG ON THE AIR!

THE BRADCAST on KPFK/Pacifica Radio Network (90.7FM Los Angeles, 98.7FM Santa Barbara, 93.7FM N. San Diego and nationally on many other affiliate stations! ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

GREEN NEWS REPORT, nationally syndicated, with new episodes on Tuesday and Thursday. ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

Media Appearance Archives…

AD
CONTENT

ADDITIONAL STUFF

Brad Friedman/
The BRAD BLOG Named...

Buzz Flash's 'Wings of Justice' Honoree
Project Censored 2010 Award Recipient
The 2008 Weblog Awards