Software to capture votes in upcoming national election is insecure

Found on Chaos Computer Club on Thursday, 07 September 2017
Browse Software

The Chaos Computer Club is publishing an analysis of software used for tabulating the German parliamentary elections (Bundestagswahl). The analysis shows a host of problems and security holes, to an extent where public trust in the correct tabulation of votes is at stake.

„Elementary principles of IT-security were not heeded to. The amount of vulnerabilities and their severity exceeded our worst expectations“, says Linus Neumann, a speaker for the CCC that was involved in the study.

„A whole chain of serious flaws, from the update server, via the software itself through to the election results to be exported allows for us to demonstrate three practical attack scenarios in one“, Neumann continues.

At the same time politicians stand in front of cameras, talk about IoT, Industry 4.0 and the importance of crypto and security. What an irony.