Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Uncategorized

FREAK security flaw exposed in iVote system, allow to intercept voter’s internet traffic, coding into web browsers

byCustoms Today Report
23/03/2015
in Uncategorized
Share on FacebookShare on Twitter

NEW SOUTH WALES: The results of New South Wales elections is seems to be changed as a new security flaw has been exposed in its iVote system. The security flaw named as FREAK has the ability to intercept the internet traffic of voter and can change the vote of the voter with his or her knowledge. Through this the 66,000 voters’ decision is now at a risk of being manipulate.

How do we know that? Because we uncovered a security flaw in the popular iVote system that would have let us do exactly that, if we’d chosen to. That’s despite repeated assurances from the New South Wales Electoral Commission that:

You might also like

Pakistan to get $3b loan from Islamic Trade Financing Corporation

20/10/2024

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

10/09/2024

People’s vote is completely secret. It’s fully encrypted and safeguarded, it can’t be tampered with.

We should stress that rather than do anything illegal or disrupt the March 28 state election result, we tested this security weakness only on our own practice vote at the iVote practice server. After checking that the same weakness affected the real voting server, we alerted the authorities late last week. We also waited until we could see the problem had been fixed before talking publicly about it.

The problem we found was that the voting server had loaded some code from a third-party site vulnerable to the FREAK attack, a major security flaw that left Apple and Google devices vulnerable to hacking.

How did that global security problem affect iVote? For a longer, more technical explanation of what we did and found, read more here.

The shorter version is that with less than a week of concerted effort, the two of us discovered that the FREAK flaw allowed us – or potentially anyone with the right technical knowledge – to intercept a NSW voter’s internet traffic, and insert different code into vulnerable web browsers. Many, but not all, browsers have been appropriately patched over the last week – this site lets you check whether yours is still vulnerable.

We demonstrated that we could make the voter’s web browser display what the voter wanted, but secretly send a different vote to the iVote voting server.

The iVote system does include a vote verification process for people who choose to vote online or by phone, where they can subsequently call an automated interactive phone line to double-check what vote the system holds for them.

However, that verification system could have errors or security vulnerabilities; we can’t tell you with any certainty either way, since there’s no publicly-available source code or system details.

Given the supposedly “fully encrypted and safeguarded” iVote system proved so vulnerable to attack, we certainly would not recommend people take any chances by voting online in the NSW election.

Related Stories

Pakistan to get $3b loan from Islamic Trade Financing Corporation

byCT Report
20/10/2024

ISLAMABAD: Islamic Trade Financing Corporation (ITFC) to provide Pakistan with a $3 billion loan, according to an official statement released...

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

byCT Report
10/09/2024

LAHORE:  Regional Directorate of Customs Intelligence & Investigation has demonstrated exceptional performance in the first two months of the fiscal...

ICCI and CDA to join hands for tree plantation drive in Capital

byQaisar Mansoor
09/08/2023

ISLAMABAD: Islamabad Chamber of Commerce and Industry (ICCI) in collaboration with the Capital Development Authority (CDA) would jointly launch a...

Customs Officials Yawar Abbas & Tariq Mehmood kidnapped in Karachi

byCT Report
08/07/2023

KARACHI: Customs Intelligence Officer Yawar Abbas and Customs Preventive Officer Tariq Mehmood who were working against smuggling were kidnapped by...

Next Post

Finnish shipyard ready to build 212 meter LNG power fast fairy

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.