Hackers uncover ‘significant’ flaw in Swiss Post e-voting
More than 3,000 hackers around the world are testing the e-voting system until March 24.
Keystone
A major bug has been identified in the new Swiss Post’s e-voting system. Hackers reported the flaw to Swiss authorities as part of a public intrusion test. Swiss Post has resolved the issue.
This content was published on
3 minutes
swissinfo.ch/jdp, urs
Español
es
Identificado el fallo en el sistema de votación electrónica
In mid-February, the Swiss government launched a public intrusion test, challenging IT experts to reveal cracks in the country’s new e-voting system by March 24. On March 12, a flaw concerning universal verifiabilityExternal link was discovered in the Swiss Post’s e-voting system by studying the system’s source code, which was released as part of the test. Universal verifiability makes it possible to determine with mathematical evidence whether votes have been manipulated.
While the flaw uncovered by the hackers does not allow the system to be penetrated, the Federal Chancellery still deemed it a “significant flaw” as it means it is not possible to detect whether the votes have been tampered with.
In a statement, the chancellery explained that the flaw means that “the Swiss Post system does not meet the legal requirements,” and it urged Swiss Post to review and improve its security processes to prevent such flaws.
The e-voting system currently being used in the cantons of Thurgau, Neuchâtel, Fribourg and Basel-City is not affected by this gap in the source code. It exclusively affects the system with universal verifiability provided for the intrusion test, which has never been used for a real vote.
In a statement on its websiteExternal link, Swiss Post acknowledged that the error in the source code had already been identified in 2017. However, the correction was not fully implemented by technology partner Scytl, which Swiss Post regrets. “Swiss Post regrets this and has asked Scytl to make the correction in full immediately, which they have done. The modified source code will be applied with the next regular release.”
The public intrusion test of the Swiss Post e-voting system ordered by the Swiss government and the cantons has been running for just over two weeks now. More than 3,000 hackers around the world are testing the system until 24 March.
People’s initiative
Opponents of e-voting say the latest flaw has permanently undermined trust in online voting systems.
They announced that they will officially launch their people’s initiative next Friday, calling for a five-year moratorium on e-voting and an end to ongoing trials with the digital technology.
The committee made up of politicians and computer experts has 18 months to collect at least 100,000 signatures for a nationwide vote on the issue.
In January, the group presented its plans which involve winning pledges from 10,000 people to help collect the necessary signatures.
The Swiss government wants to introduce e-voting as an additional option for citizens to participate actively in democracy.
The Organisation of the Swiss Abroad has called for online voting to be made available for all expatriates Swiss by 2021. It submitted a petition last November.
More
More
Opposition against e-voting project gathers pace
This content was published on
A committee of politicians and IT experts launches an initiative aimed at banning online voting for at least five years in Switzerland.
Pilots’ union seeks to end deal with SWISS over working conditions
This content was published on
The Aeropers pilots’ union is expected to end its collective labour agreement with SWISS, as it pushes for better working conditions for its members.
Drugs often approved for wider use than tested, says Swiss study
This content was published on
A study by the University of Zurich, ETH Zurich and Yale and Harvard universities found that many medicines are approved for groups not tested in trials.
This content was published on
Over the four days, around 98,000 people – including volunteers – made their way up Bern’s local mountain for the 42nd edition of the festival.
Foreign residents in Moutier gain voting rights before town joins canton Jura
This content was published on
Foreign nationals living in Moutier will be able to vote in local and cantonal elections this year, even before the town joins the canton of Jura in 2026.
This content was published on
By 8am on Saturday, an 11-kilometre queue had formed at the Gotthard tunnel’s northern entrance, with drivers facing nearly two hours of delays.
Plant-based meat market in Switzerland set to grow to CHF361 million by 2030
This content was published on
Switzerland’s market for plant-based meat alternatives has a potential value of around CHF 242 million this year, though it remains a niche market.
This content was published on
The army is looking for a modern solution for its decommissioned fortress mortar bunkers, with plans to turn them into hardened defence hubs.
This content was published on
Spain ended Switzerland’s run in the Women’s Euros on Friday, but fans in Bern made history with the largest supporters’ march in Women’s Euros history.
This content was published on
Solar energy pioneer Raphaël Domjan and his team continued preparations for the altitude record attempt at 10,000 metres with the SolarStratos solar aircraft.
This content was published on
Cattle in the canton of Geneva and in the neighbouring region of Terre Sainte in the canton of Vaud are being vaccinated against the contagious viral skin nodule disease. The first cases of the animal disease were reported at the end of June in France, just outside Geneva.
Flaw reported in Switzerland’s biggest e-voting system
This content was published on
A hacker claims to have discovered a weakness in canton Geneva’s e-voting system to attacks that could redirect online voters to malicious websites.
You can find an overview of ongoing debates with our journalists here . Please join us!
If you want to start a conversation about a topic raised in this article or want to report factual errors, email us at english@swissinfo.ch.