惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
V
Visual Studio Blog
爱范儿
爱范儿
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
有赞技术团队
有赞技术团队
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News
Blog — PlanetScale
Blog — PlanetScale
The Cloudflare Blog
Engineering at Meta
Engineering at Meta
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
Vercel News
Vercel News
F
Fortinet All Blogs
Last Week in AI
Last Week in AI
M
MIT News - Artificial intelligence
小众软件
小众软件
月光博客
月光博客
A
About on SuperTechFans

ashishb.net

A day in Luxembourg - the richest country in the world I was asked to install malware during a fake interview Book summary: Breakneck - China's quest to engineer the future by Dan Wang Book summary: How to Teach Your Baby to Read Book Summary: The Discontented Little Baby Book by Pamela Douglas Introducing Amazing Sandbox - run third-party tools and AI agents securely on your machine Why software outsourcing gets a bad reputation? Book summary: The Natural Baby Sleep Solution by Polly Moore A day in Antwerp, Belgium Journey of online influencers Two days in Brussels, Belgium Shortcuts - when we love them and when we don't A visit to Rakhigarhi Three days in overhyped Paris Empty Japan, crowded Tokyo The real lock-in in GitHub is not the code, but the stars 11-day Norwegian Breakaway East Caribbean cruise Sanskrit and Sri Lankan Air Force Use REST with Open API The Achilles heel of American capitalism Costa Rica in 4 days At a juice stall in Sri Lanka A short stay at Warsaw, Poland Best practices for using Python & uv inside Docker Two days in Vilnius, Lithuania How IntelliJ IDEs waste disk space Pregnancy Why there aren't many digital nomads from India Two days in Riga, Latvia To keep your machine secure, run third-party tools inside Docker
EVM controversy in India
Ashish Bhatia · 2010-11-11 · via ashishb.net

The post is written in honor of Sh. Hari Prasad, the winner of EFF Pioneer Award 2010

About a decade ago, Election Commission of India( ECI) began mass deployment of the Electronic voting machine( EVM) for elections. The security of EVM lies only in their obscured details, the details about software and hardware are only vaguely available. No third-party audits of its security have ever been done. Time and again, security researchers have asked for access to EVM but they have been denied regularly except in September 2009, where Hari Prasad was asked to demonstrate an attack on EVM in 2 hours and then stopped within 10 minutes showing intellectual property concerns.

Unlike technology-based financial transaction systems which evolved over years to handle phishing attacks, MITM and credit card based fraud, unlike financial transactions, the elections are held relatively infrequently and hence does not provide much opportunity to evolve and learn the adversaries. Unless the results of elections are verified against another source, it is impossible to tell if the machine is without bugs or not. Also unlike finance, there is nothing to hedge against here. As we know embedded systems are inherently prone to bugs. Yes, even those who are deeply scrutinized space rockets and satellites have integer overflow errors, attacked by worms and assume wrong units, without a rigorous audit, it is impossible to say that they will work fine.

Given how Indian govt deals with technology, this is not something new but what is intriguing is the fact that when researchers demonstrated that EVMs are not secure, rather than awarding the whistleblowers, ECI arrested Hari Prasad[the only Indian national in the group], blatantly denied that EVM can be compromised and used all sorts of harassments to pressurize him to reveal the “source” which provided the EVM. Even the highest judiciary body in India, the Supreme Court has already declared that ECI is the sole authority on this topic. Hitherto that, even ECI does not have the source code of the machines (their “technical team” has looked at the source code but the machines’ source code is read protected so even ECI cannot verify that the machines they have received are untampered). Quoting Prasad, now ECI is planning for paper audit trail which can be later used for verification in case of later verification.

Disclaimer: This is my personal blog. The views expressed on these pages are mine alone and not those of my employer.