Paper 2025/2033
Vestigial Vulnerabilities in Deployed Verifiable E-Voting Systems
Abstract
Electronic voting systems claiming to provide verifiability are seeing increased adoption. Previous work on analyzing these systems has focused on vulnerabilities arising in the specification and implementation of the core protocol and primitives; once the system has been analyzed for these vulnerabilities and appropriate fixes deployed, one might have hoped that the systems would provide the claimed security. In this paper, we discuss two categories of vulnerabilities which still seem prevalent in otherwise carefully designed, implemented, and audited systems. We present ten examples of vulnerabilities or weaknesses in these categories drawn from the SwissPost and Belenios systems. Our discussion covers why vulnerabilities in these categories maybe escaping detection and what can be done about it; all the solutions we considered are unsatisfactory and our aim is to highlight this area as an important open problem.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Contact author(s)
-
thomas haines @ anu edu au
u6899393 @ anu edu au - History
- 2025-11-05: approved
- 2025-11-02: received
- See all versions
- Short URL
- https://ia.cr/2025/2033
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2033,
author = {Thomas Haines and Jarrod Rose},
title = {Vestigial Vulnerabilities in Deployed Verifiable E-Voting Systems},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2033},
year = {2025},
url = {https://eprint.iacr.org/2025/2033}
}