Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 5 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Securing the vote

by The Gurus
December 19, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

“It is enough that the people know there was an election. The people who cast the votes decide nothing. The people who count the votes decide everything.” – Joseph Stalin
We recently had an election in the US – you may have heard about it. In the run-up to the election, and in its aftermath, candidates from all parties have raised the specter of the vote being hacked. Even long established technology magazine Scientific American asked: “Is the vulnerability of computerized voting systems to hacking a critical threat to our national security?”.
Maybe, maybe not. There’s no hard evidence that any hacking was done to the voting and tabulating process. Of course, a really good hacker doesn’t leave fingerprints.
But, according to a report in New York magazine, a group of prominent computer scientists and election lawyers claim that “the share of votes received by [Hillary] Clinton was significantly lower in precincts that used a particular type of voting machine” According to security guru Bruce Schneier, “The magazine story suggested that Clinton had received 7 percent fewer votes in Wisconsin counties that used electronic machines, which could be hacked, than in counties that used paper ballots.”
Anecdotal accounts of the dead and non-citizens voting, as well as tales of people voting multiple times in multiple localities have not been proven. In fact, only a handful of votes from these sources have been validated over the past dozen years. No, it’s as Stalin alluded in the quote above – it’s not the people who vote but the tabulation of the voters that could be easily manipulated.
So can we, as technologists, see a way to insure the integrity of the vote, a valid count of the votes and the election of an officeholder that’s free from hacking? Perhaps the Blockchain could be the answer.
In a recent paper, Philip Nicholas Boucher, of the EU Parliamentary Research Service, wrote: “The blockchain protocol is a means of logging and verifying records that is transparent and distributed among users. Usually, votes are recorded, managed, counted and checked by a central authority. Blockchain-enabled e-voting (BEV) would empower voters to do these tasks themselves, by allowing them to hold a copy of the voting record. The historic record could then not be changed because other voters would see that the record differs from theirs. Illegitimate votes could not be added, because other voters would be able to scrutinise whether votes were compatible with the rules (perhaps because they have already been counted, or are not associated with a valid voter record). BEV would shift power and trust away from central actors, such as electoral authorities, and foster the development of a tech-enabled community consensus.”
I don’t think there’s any need to remove electoral authorities from their role, provided the votes are transparent and can be shown to be properly cast and tabulated. In fact, a recent start-up (2012) in Blacksburg, Virginia USA believes they’ve created a way to do just that. FollowMyVote explain their method as:
“When using our blockchain voting system, the voter would download and install the Follow My Vote voting booth on the personal device of their choice (i.e. desktop computer, laptop computer, smartphone, or tablet). From there, the voter would submit the appropriate identity information in order to have their identity verified by an Identity Verifier, which would be approved by the organization hosting the election ahead of time. Once their identity is verified, the voter would be able to request their ballot, at which point they are issued their correct ballot type by the Registrar. The voter would then complete their ballot and securely submit their vote(s) to the blockchain-based ballot box. To obtain proof of casting their ballot, the voter would have the option to print out a receipt. If allowed by the organization hosting the election, the voter may vote early and could even re-enter the Follow My Vote voting booth to change their vote if they change their mind in the days leading up to the election. When the polls close on Election Day, the most current votes submitted by each voter would be considered the official votes; and, voters would be allowed to follow their vote into the ballot box to ensure that their vote was cast as intended and counted as cast. If they choose to do so, each voter would also be allowed to audit each ballot in the ballot box to confirm the vote totals being reported by our blockchain voting system are accurate, without revealing the identity of each voter.”
The FollowMyVote scenario allows each voter to use their own device, but security experts have long warned that this is susceptible to computer hacking (via malware and/or phishing) which could change a person’s vote. The FollowMyVote people recognize this problem (“The greatest risk of compromise from malware will be on desktop and laptop computers, where the operating systems do not have as strong of a security model, and malware can be difficult to find and remove. Because of this, Follow My Vote will recommend users only vote from these computers using a live operating system (a temporary computer operating system which runs in RAM and is used only for voting), which will neutralize the threat of malware on the computer while the Follow My Vote application is running and storing data on the computer.”)
I’m personally skeptical about how that would work in practice, but by utilizing centrally located voting places (such as the current polling stations) with hardened systems and certified malware-free operating systems and apps (which could be on a tablet running a purpose-built OS) and utilizing Blockchain technology for recording, tabulating and safeguarding the votes then I believe that all hints of hacked votes can be removed from the system and its integrity restored. And all at a lower cost than constant vote recounts by hand!

ShareTweet
Previous Post

Do You Need a Threat Intelligence Team?

Next Post

SVG Ransomware: It’s About Much More than Facebook

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol