In more Securing Democracy at #enigma2021, @ChrFolini talking about "THE ADVENTUROUS TALE OF ONLINE VOTING IN

Switzerland is a direct democracy where citizens get to vote at least 4x/year, with a lot of mail-in voting. We have a long history of online voting.

Disclaimer: THIS IS NOT SWEDEN.

[I get the picture that @ChrFolini has had to explain the difference several times.]
Process around mail-in ballots.

[tl;dr it's very complicated and wasn't threat-modeled until recently]
But the in-person ballots are complicated, too!
Most security folks don't think that we can't make a secure online voting system.

@ChrFolini says this is because of encryption
[Note: this is not the main reason that a lot of people cite -- we're more worried about things like malware but it's complicated]
There are reasons to want online voting:
* Citizens living abroad
* Visually impaired and quadriplegic voters need to have assistants that they trust
* Many invalid ballots (even <10%!)
* Physical voting has security problems, too
Like the states of the US, there are cantons in Switzerland, federalized system. The cantons have almost complete control over the elections *except* that the federal system has exclusive control over the security of online voting.
Several cantons have been experimenting, with Geneva being the first, followed by a group of eight cantons.
In 2017 the federal chancellor calls for 2/3 of the cantons to offer internet voting for national elections in 2019. There were not many CS people represented and they declared internet voting "solved".

That was a wakeup for people on internet voting.
Geneva pulled funding after political quarrels... which paved the way for SwissPost.

In 2019 they posted the source code before the election. It didn't take long for several fundamental security flaws to be found.

[ I can't type this fast and find everyone's names sorry]
In the wake of that failure everyone figured out that internet voting was not, in fact, solved. At all.

So they brought in a bunch of experts.
What happens if you get together a bunch of experts? A scientific report!
[If someone has a link, please reply with it]

@ChrFolini was brought in to moderate the workshops... then the pandemic hit. Lots of debate on cryptography, software development, etc.
After all that debate and new work, there is a new report [anyone have a link? @ChrFolini?] in line with the recommendations of the scientists. But we'll need to keep tweaking as tech changes.
Key recommendations:
* Strict hierarchy of recommendations, starting with a verifier model which can be reasoned about, then moving to pseudocode then code. Use formal models.
* Diversity of hard- and soft-ware to resist attacks. It's more expensive, but there are security benefits.

[Boy howdy this is going to be controversial one, depending on how this is set up -- checks of different versions against each other?]
* Maximum level of transparency, especially in development

* Voting security beyond internet voting
Summary:
* Switzerland is a useful testbed for online voting
* Iterative process with strict supervision on federal level
* Expert dialogue with recommendations in 2020
@ChrFolini sees online voting as something which may or may not be securable but it's a political question whether it's introduced... so we'd better work on it.

[paraphrased]
Giving my hands a break, so end of talk as the questions are coming thick and fast (not at all shocking!)

More from Lea Kissner

More from World

A quick thread on #Myitsone dam & #MyanmarChinaRelations in light of the SAC announcement that they would be restarting some stalled Chinese projects in Burma. This announcement has led to speculation about Myitsone, which has been suspended since 2011. Let’s go! ➡️ China has


consistently misunderstood & underestimated popular opposition to Myitsone. First and foremost, to the Burmese people, this is about the “mother river” of Burma - the Irrawaddy- and it’s nearly sacred importance to them as a lifeline of their country. This is what drove the

organic anti-dam movement that started locally in Kachin but +/- 2007 was effectively picked up & nationalized by Burmese environmental CSOs. Instead of understanding this, the Chinese lashed out and blamed the United States when Thein Sein suspended the project. I assure you

the USG was as surprised as China when the project was suspended. But China never believed it was truly the desire of the Burmese people that stopped the project. Today, the dam doesn’t make sense economically for Beijing & will definitely alienate Burmese, yet they stubbornly

continue to push it. Why? Let’s unpack a bit further. In addition to Myitsone, there were other campaigns & protests targeting Chinese projects such as Letpadaung copper mine & Kyaukphyu pipeline, port & SEZ. While these campaigns had varying levels off effect, none was as

You May Also Like

The entire discussion around Facebook’s disclosures of what happened in 2016 is very frustrating. No exec stopped any investigations, but there were a lot of heated discussions about what to publish and when.


In the spring and summer of 2016, as reported by the Times, activity we traced to GRU was reported to the FBI. This was the standard model of interaction companies used for nation-state attacks against likely US targeted.

In the Spring of 2017, after a deep dive into the Fake News phenomena, the security team wanted to publish an update that covered what we had learned. At this point, we didn’t have any advertising content or the big IRA cluster, but we did know about the GRU model.

This report when through dozens of edits as different equities were represented. I did not have any meetings with Sheryl on the paper, but I can’t speak to whether she was in the loop with my higher-ups.

In the end, the difficult question of attribution was settled by us pointing to the DNI report instead of saying Russia or GRU directly. In my pre-briefs with members of Congress, I made it clear that we believed this action was GRU.