НОВИНИ

Voting security: Can the hash code be manipulated?

voting security can hash code manipulated
Снимка:
bnt avatar logo
от БНТ
22:42, 27.10.2023
EN

There are three main steps in the process of authenticating the voting machines before they are deployed at polling stations. One of them is the signing of the software with which the devices are installed - the so-called hash codes.

A hash code is a cryptographic key used to sign the software installed on the machines. It is also the last step in the certification of voting machines. Before the hash code can be generated, the software on the machines must be signed by a special key, which is stored at the Central Election Commission (CEC). Anastas Gyokov has been an election observer for two years and knows the process well. According to him, there can be a change in the hash code only if the software of the machines has been change, which, however, cannot go unnoticed.

"There are two things that are called a key, and they are not the same. One is the cryptographic key, which is used to encrypt a piece of information. This is what the Central Election Commission holds and can be used with a password by three members of the CEC. The other thing, which is called a key, is the cryptographic checksum or so-called hash. Its sole purpose is to verify that a piece of information, in this case the machine's software, is unchanged from the moment it was generated," said Anastas Gyokov, an election observer and member of the CEC's Public Council.

The hash code has been public for a week. It has to be printed in a visible place in all polling stations in the country, it is also printed at the first start of the machines on election day, as well as on every ballot paper that comes out of them. The biggest guarantee for the fairness of the elections is the verification, according to Gyokov.

"As someone who has to do with computer security, I don't trust anyone. Where there is no trust, there should be an opportunity for verification. And in the case with the machines, there are all sorts of opportunities for verification. The most elementary of which is the person who gets their receipt from the machine, regardless of what the machine has counted, on that receipt it clearly says who they voted for. If what the person saw on the paper receipt is what he wanted to vote for and that paper is put in the ballot box, it doesn't matter what the software of the machine is and what has been fiddled," Gyokov further commented.

Still, security breaches are possible.

"If the CEC key is compromised in some way, theoretically someone could feed the machines information that has been altered and the machine would have no way of knowing that, because everything that is signed with the CEC key is authentic to the machine. If someone changes this key, they have to replace the procedure - that is, at some point they have to say: ' CEC will not give the key, and you should use this key', which from a purely human point of view is guaranteed not to happen," clarified the member of the CEC Public Council.

"For example, cryptographic keys are secure as long as a quantum computer is not used to break them. There only several quantum computers in the world," he added.

The deputy minister's presence during the controlled generation of the hash code does not mean the vote was compromised, Goykov is convinced.

"Even if we assume that he has the medium in which the CEC key is saved and he downloaded it, this key again cannot be used without the passwords of those three CEC members who have one-third of them. That is, he alone can do nothing," Anastas Gyokov added.

In order for a new hash code to work, the software of the machines must be changed beforehand, the IT specialist added.

Two days before local elections: Scandal about machine voting after a report by the State Agency for National Security (update)

Чуйте последните новини, където и да сте!
Последвайте ни във Facebook и Instagram
Следете и канала на БНТ в YouTube
Вече може да ни гледате и в TikTok
Намерете ни в Google News

Свали приложението BNТ News
google play badge
Свали приложението BNТ News
app store badge

More from EN

Ministry of Transport and Communications: We are witnessing another speculative statement regarding construction of railway link between Bulgaria and North Macedonia
Ministry of Transport and Communications: We are witnessing another speculative statement regarding construction of railway link between Bulgaria and North Macedonia
20:37, 13.12.2024
Чете се за: 05:25 мин.
Bulgarian Foreign Ministry: Bulgaria and the US establish enhanced partnership in border security
Bulgarian Foreign Ministry: Bulgaria and the US establish enhanced partnership in border security
19:30, 13.12.2024
Чете се за: 03:17 мин.
Conference on the role of women in diplomacy held under the patronage of Bulgaria's Vice President
Conference on the role of women in diplomacy held under the patronage of Bulgaria's Vice President
18:11, 13.12.2024
Чете се за: 02:02 мин.
Kiril Petkov of WCC-DB comments on proposal for lifting the Immunity of MP Lena Borislavova: The dirty machine started hitting us
Kiril Petkov of WCC-DB comments on proposal for lifting the Immunity of MP Lena Borislavova: The dirty machine started hitting us
17:53, 13.12.2024
Чете се за: 02:22 мин.
Prosecutor's Office asks Prosecutor General to request the immunity of MP Lena Borislavova of 'We Continue the Change'
Prosecutor's Office asks Prosecutor General to request the immunity of MP Lena Borislavova of 'We Continue the Change'
17:30, 13.12.2024
Чете се за: 02:25 мин.
MPs called for a new budget for 2025
MPs called for a new budget for 2025
16:39, 13.12.2024
Чете се за: 07:22 мин.
Hungarian Minister of Foreign Affairs and Trade, Peter Szijjártó, visits Bulgaria
Hungarian Minister of Foreign Affairs and Trade, Peter Szijjártó, visits Bulgaria
16:27, 13.12.2024
Чете се за: 02:32 мин.
30,000 victims of the BETL pyramid scheme - only 30 alerts in the Ministry of Interior
30,000 victims of the BETL pyramid scheme - only 30 alerts in the Ministry of Interior
15:17, 13.12.2024
Чете се за: 01:55 мин.
GERB-UDF leader Borissov: We will hold talks with DB, BSP and TISP
GERB-UDF leader Borissov: We will hold talks with DB, BSP and TISP
14:17, 13.12.2024
Чете се за: 02:10 мин.
One-year-old child died in ambulance, the parents blame the medics
One-year-old child died in ambulance, the parents blame the medics
14:05, 13.12.2024
Чете се за: 02:02 мин.
Four Bulgarian companies will receive grants to improve processes in energy, transport and cyber defence
Four Bulgarian companies will receive grants to improve processes in energy, transport and cyber defence
13:23, 13.12.2024
Чете се за: 01:12 мин.
Surprise before the start of the ski season in Bansko: higher prices for lift tickets and accommodation
Surprise before the start of the ski season in Bansko: higher prices for lift tickets and accommodation
13:20, 13.12.2024
Чете се за: 02:45 мин.
Топ 24
Най-четени
Словения ще удължи с 20 дни мерките за граничен контрол с Хърватия и Унгария
Словения ще удължи с 20 дни мерките за граничен контрол с Хърватия и Унгария
Нефтохимик започна с победа участието си в квалификационния турнир от Шампионска лига
Нефтохимик започна с победа участието си в квалификационния турнир от Шампионска лига