Connect with us

Noticias

Researcher hacked Moscow’s online voting system in 20 minutes. Reporters repeated the experiment

French cryptographer Pierreck Godry hacked the Internet voting system developed by the Moscow Department of Information Technology (DIT), which put some of its components in the public domain, inviting everyone to find vulnerabilities, Meduza reports. On September 8, residents of three districts in Moscow will be able to vote in elections through the Internet. Three weeks before the election, it turned out that the voting system is unreliable – it is quite simple […]

Published

on

French cryptographer Pierreck Godry hacked the Internet voting system developed by the Moscow Department of Information Technology (DIT), which put some of its components in the public domain, inviting everyone to find vulnerabilities, Meduza reports.

So, the developers of DIT published encrypted messages and public keys, and after a while – decrypted messages and three secret keys. In this way, hackers could check if they had successfully cracked the system.

Note that messages are hypothetical votes of voters that are recorded on the blockchain. In this case, the secret key in theory is distributed among the members of the election commission, and is collected back only after the vote.

Godri allegedly managed to recover all three secret keys in just 20 minutes. A similar experiment was repeated by the journalists of Medusa, now they only have to verify the secret keys if the representatives of the DIT publish them.

According to Godry, the main weakness of the system is that the size of the keys for encryption is too small – less than 256 bits, and, according to him, 2048 bits are necessary. Godry suggested that DIT employees might encounter features of the programming language for smart contracts Solidity, which does not allow direct operation with integers larger than 256 bits.

The DIT did not recognize the fact of breaking the encryption scheme, but promised to increase the key size to 1024 bits. It is interesting that earlier it was reported that the system was allegedly checked by the FSB and the FSTEC, Medusa writes.

It is worth adding that the hacking did not prove that the anonymity of the vote is at stake, but showed that the election process can be monitored in real time, which contradicts the legislation of the Russian Federation.

Recall that the election to the Moscow City Duma will take place on September 8. Residents of three districts will be able to vote via the Internet through a blockchain-based system .

Subscribe to BlockchainJournal news on Facebook !

<< aside id = "unisender_subscribe_form-10" class = "widget unisender_form">

BlockchainJournal.news

BlockchainJournal.news

Continue Reading
Advertisement

Compañías

ARK Invest Deshace Acciones de Coinbase y GBTC por Millones en Medio del Auge del Mercado

Published

on

ARK Invest: $33 Millones en Acciones de Coinbase y $5.9 Millones en GBTC

ARK Invest, liderada por Cathie Wood, continúa navegando sus movimientos estratégicos de acciones en el mercado, realizando ventas destacadas de acciones de Coinbase y Grayscale Bitcoin Trust (GBTC) en medio del continuo aumento de los precios del mercado.

(más…)

Continue Reading

Compañías

El Descuento de GBTC se Reduce a Medida que Aumenta el Precio de Bitcoin

Published

on

By

El Descuento de GBTC se Reduce a Medida que Aumenta el Precio de Bitcoin

Grayscale Bitcoin Trust (GBTC), uno de los vehículos de inversión en criptomonedas más grandes y populares, ha visto su descuento reducirse significativamente en los últimos días a medida que los alcistas continúan elevando su precio. Según datos de Kaiko, una plataforma de inteligencia blockchain, el descuento del GBTC, que mide la diferencia entre el precio de mercado y el valor liquidativo (NAV) del fideicomiso, está en su nivel más estrecho en años, con solo el 8% hasta ayer. (más…)

Continue Reading

Compañías

IBM Presenta OSO, Diseñada Para el Almacenamiento en Frío de Activos Digitales

Published

on

By

ibm featured

IBM presentó una nueva tecnología denominada «IBM Hyper Protect Offline Signing Orchestrator» (OSO), diseñada para gestionar activos digitales en almacenamiento en frío. Esta innovación surge como respuesta a los riesgos asociados con los procedimientos manuales y tiene como objetivo mantener los activos a una distancia segura de las conexiones a Internet. (más…)

Continue Reading

Trending