SlideShare une entreprise Scribd logo
1  sur  41
Télécharger pour lire hors ligne
The Adventurous Tale of
Online Voting in Switzerland
Christian Folini – Insomni’Hack 2022 Keynote
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Plan for Today
⚫ Overview of the past 20 years
⚫ A new perspective on the events of 2019
⚫ Expert dialogue and scholarly report of 2020
⚫ Public consultation and new regulation 2021/22
⚫ Several ridiculous predictions about the future
Boring BIO
⚫ Dr. Christian Folini
⚫ Historian and Swiss Security Engineer
⚫ Open Source Security Project Lead (OWASP CRS)
⚫ Election worker blog at www.christian-folini.ch
⚫ Wearer of many hats helmets with
Swiss E-Voting
@ChrFolini
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
"We simply can’t build an Internet
voting system that is secure against
hacking because of the requirement
for a secret ballot."
Bruce Schneier, Online Voting Won’t
Save Democracy, The Atlantic, May 2017
Key Argument against Online Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Arguments in Favor of Online Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
• Citizens living abroad
Arguments in Favor of Online Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
• Citizens living abroad
• Visually impaired and quadriplegic voters
Arguments in Favor of Online Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
• Citizens living abroad
• Visually impaired and quadriplegic voters
• Formally invalid ballots
Arguments in Favor of Online Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
• Citizens living abroad
• Visually impaired and quadriplegic voters
• Formally invalid ballots
• Security weaknesses of physical voting
Arguments in Favor of Online Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2004 2009 2011
2004
2000
1st project
1st Geneva trial
Entering Scytl
Consortium
Steering Board
1st Swiss internet voting
project is launched with
three pilot cantons.
Swiss canton Neuchâtel
deploys Spanish Scytl
software for online voting.
Federal administration and
cantons establish a joint
steering committee.
Canton Geneva runs the
first Swiss internet voting
trial.
Eight Swiss cantons form a
consortium and
commission Swiss branch
of American Unisys with
the creation of an internet
voting system.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2015 2017
2015
2011
Steering Board
Consortium dies
Scytl/Swiss Post join
Mainstreaming attempt
Federal administration and
cantons establish a joint
steering committee.
Spanish Scytl and Swiss
Post form joint venture
with Scytl providing the
software and Swiss Post
operating the systems on
premise.
The eight consortium
cantons throw towel after
federal administration
barrs system from use in
national elections.
The federal chancellor calls
for 2/3 of the cantons to
offer internet voting for
national elections in 2019.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2017 / 2018 – The Resistance is Emerging
• Beyond 100 articles on Swiss E-Voting
• Feeling that 3 out of 4 quoted
Hernâni Marques
• Confrontation was fought
tooth and nail
• Sentiment Analysis: ️
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2018 / 2019 Geneva Quits
Source: Twitter: @GE_chancellerie (1141332323025195009)
2018: Development stopped
2019: System terminated
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2018.11 2019.2
2017
2016
Scytl/Swiss Post join
Mainstreaming attempt
Geneva quits
Bug Bounty
Source Code Publication
Spanish Scytl and Swiss
Post form joint venture
and go into production.
Political quarrels lead to
Geneva stopping all further
development. A year later,
the system is terminated.
The federal chancellor calls
for 2/3 of the cantons to
offer internet voting for
national elections in 2019.
Scytl / Swiss Post publish
the source code of their
system and run a 4 week
bug bounty.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Swiss Post / Scytl Source Code: Total Desaster
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2018.11 2019.2
2017
2016
Scytl/Swiss Post join
Mainstreaming attempt
Geneva quits
Start Bug Bounty
Source Code Publication
Spanish Scytl and Swiss
Post form joint venture
and go into production.
Political quarrels lead to
Geneva stopping all further
development. A year later,
the system is terminated.
The federal chancellor calls
for 2/3 of the cantons to
offer internet voting for
national elections in 2019.
Scytl / Swiss Post publish
the source code of their
system. Researchers
identify three critical
vulnerabilities within
weeks. The system is put
on hold.
2019.3
E-Voting
Referendum
Launched
Collection period for
popular initiative with the
goal of 100,000 signatures
started.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Online Voting Referendum Launched
Source: Twitter: @wecollectCH (1106865437097246722)
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Online Voting Headlines in Switzerland 2019
Data source: noevoting.ch, chart by Christian Folini
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Online Voting Signatures Promised to WeCollect
Source: archive.org → wecollect.ch (2019-03-22)
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Signatures Promised to WeCollect
Data source: https://christian-folini.ch/pub/wecollect-noevoting-numbers.csv
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2018 2019 2020.4
2017
2016
Scytl/Swiss Post join
Mainstreaming attempt
Geneva quits
E-Voting on hold
Rebooting
Spanish Scytl and Swiss
Post form joint venture
and go into production.
Political quarrels lead to
Geneva stopping all further
development. A year later,
the system is terminated.
The steering board
establishes a dialog with
25 scientists to assess
viability of internet voting
and support with writing
new regulation.
The federal chancellor calls
on 2/3 of the cantons to
offer internet voting for
national elections in 2019.
Scytl / Swiss Post publish
the source code of their
system. Researchers
identify three critical
vulnerabilities within
weeks. The system is put
on hold.
2020.6
E-Voting
Referendum
dies
Despite the promising
headlines in 2019, the
collection of signatures
fails miserably.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
CRYPTOGRAPHERS AND ONLINE VOTING EXPERTS
David Basin, ETH Zurich
Srdjan Capkun, ETH Zurich
Eric Dubuis, BFH Bern
Bryan Ford, EPF Lausanne
Reto Koenig, BFH Bern
Philipp Locher, BFH Bern
Olivier Pereira, University of Leuven, Belgium
Vanessa Teague, Australia
Bogdan Warinschi, Bristol, UK
Rolf Haenni, BFH Bern
SECURITY INDUSTRY
Stéphane Adamiste, SCRT
Sergio Alves Domingues, SCRT
Tobias Ellenberger, One Consult
Source: https://www.bk.admin.ch/bk/de/home/politische-rechte/e-voting.html
COMPUTER SCIENTISTS
David-Olivier Jaquet-Chiffelle, Uni. of Lausanne
Oscar Nierstrasz, University of Bern
Adrian Perrig, ETH Zurich
Carsten Schürmann, Denmark
Matthias Stürmer, University of Bern
Ulrich Ultes-Nitsche, University of Fribourg
POLITICAL SCIENTISTS
Florian Egloff, ETH Zurich
Fabrizio Gilardi, University of Zurich
Uwe Serdült, Center for Democracy, Aarau
MODERATOR
Christian Folini, netnea.com
Expert Dialogue – Participating Scientists
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2020.4 2020.7 2020.11
2020.3
2020.2
Survey
Covid-19 hits
Online dialogue
Additional research
Scientific report
The dialogue starts with a
survey over 62 questions
sent to 25 scientists
The workshops are
replaced with a 12 weeks
online dialogue on a
dedicated gitlab platform.
The steering board
publishes the 70 pages
report with the re-
commendations of the
scientists.
When the on-site
workshops were slowly
taking shape, Switzer-land
entered a lock-down and
the on-site gatherings had
to be called off.
Several separate re-search
articles are commissioned
with individual scientists to
bring up more infor-mation
on individual questions.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
https://www.bk.admin.ch/bk/en/home/politische-rechte/e-voting.html
Scholarly report
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
• Cryptography: A ton of advice, also on quantum
• Call for diversity in hard- and software
• Maximum level of transparency, Open Source
• Cross-Channel plausibility checks
Key Recommendations of Dialogue
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
2020.4 2020.7 2020.11
2020.3
2020.2
Survey
Covid-19 hits
Online dialogue
Additional research
Scientific report
The dialogue starts with a
survey over 62 questions
sent to 25 scientists
The workshops are
replaced with a 12 weeks
online dialogue on a
dedicated gitlab platform.
The steering board
publishes the 70 pages
report with the re-
commendations of the
scientists.
When the on-site
workshops were slowly
taking shape, Switzer-land
entered a lock-down and
the on-site gatherings had
to be called off.
Several separate re-search
articles are commissioned
with individual scientists to
bring up more infor-mation
on individual questions.
2021.4
Public Consultation
Following standard Swiss
procedure the draft new
e-voting regulation is put
up for a public
consultation where all
interested parties are
invited to provide
feedback.
Timeline Online Voting in Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Public Consultation for New Regulation
Source: Federal Chancellery
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
67 Responses in Public Hearing
Source: DigiGes Switzerland
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Response Report of Public Consultation
Source: Federal Chancellery
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Who Has Responded? And How?
Source: Federal Chancellery
67 Responses
48 positive
11 positive with fundamental
reservations
8 negative
697 pages all in all
Missing:
EVP
GLP
Swiss ICT
ISSS
CCC-CH
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Who Responded to the Technical Annex?
Source: Federal Chancellery
24 Responses:
6 minimal:
AI, GE, Pirate Party, SBb, Procap,
SZBlind
18 substantial:
AG, BE, BS, FR, GL, GR, SG, SO,
SZ, TG, VS, ZH
BFH, SBV, Post, SSK, Florian Moser, IsA
Missing:
Political Parties, SATW, DigitalSwitzerland,
SWICO, DigiGes
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Call for Open Source
Source: Federal Chancellery
11 responses support an enforced Open Source approach for the software.
Alternative Linke Bern "Open Source bedeutet Lizenzierung"
CH++ "vollständiger Open Source Ansatz eine essentielle Bedingung"
Digitale Gesellschaft "Versäumnis eines fehlenden Zwangs zu Open Source hat negative Signalwirkung"
digitalswitzerland* "Weiter begrüsst digitalswitzerland die Vorgaben zu Open Source"
Economiesuisse* "Vorgaben zu Open Source ... zu begrüssen"
Florian Moser "konkret die Publizierung sämtlichen Materials unter einer Open Source Lizenz vorschreiben"
Grüne "Wir fordern mehr Open Source"
IsA "im Widerspruch zur Empfehlung ... keine Open Source Lizenz verordnet"
Piratenpartei "Vollständige Publikation des Source Codes unter einer Open Source Lizenz"
SP "erachten wir bereits im Testbetrieb einen vollständigen Open-Source-Ansatz für notwendig."
Stift. Konsumentens. "keine umfassende Open-Source-Pflicht enthalten"
* The two marked organisations misread the regulation and believe Open Source was actually
in the draft regulation. It is not.
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Open Source in Federal Chancellery’s Media Release
Source: Federal Chancellery
“Others who took part in the consultation
also raised fundamental issues: for
example, some would like to see all e-
voting systems and their components
disclosed under an open source licence.
The Federal Council takes these
fundamental issues very seriously. They
concern the security of e-voting and the
public's confidence in this voting method
and will be addressed in the longer
term ...”
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Timeline Online Voting in Switzerland
2022 Q2/3 2022/23
2021.12
2021.4
Report on
Public Consultation
New Regulation
New E-Voting Trials
New regulation is expected
for Summer 2022
Report comes in at
whopping 697 pages with
67 individual responses.
A small number of Swiss
Cantons will take up new
E-Voting trials in late 2022
or 2023 aiming for national
elections in Autumn 2023.
Public Consultation
Following standard Swiss
procedure the draft new
online voting regulation is
put up for a public
consultation where all
interested parties are
invited to provide
feedback.
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Ridiculous Predictions Beyond 2022/23
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Ridiculous Predictions Beyond 2022/23
• Slow expansion of E-Voting after the national election 2023
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Ridiculous Predictions Beyond 2022/23
• Slow expansion of E-Voting after the national election 2023
• E-Voting system of Swiss Post will become open source
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Ridiculous Predictions Beyond 2022/23
• Slow expansion of E-Voting after the national election 2023
• E-Voting system of Swiss Post will become open source
• A disability organization will sue for E-Voting
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Ridiculous Predictions Beyond 2022/23
• Slow expansion of E-Voting after the national election 2023
• E-Voting system of Swiss Post will become open source
• A disability organization will sue for E-Voting
• Cross-Channel plausibility checks will improve security for all
voting channels
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Ridiculous Predictions Beyond 2022/23
• Slow expansion of E-Voting after the national election 2023
• E-Voting system of Swiss Post will become open source
• A disability organization will sue for E-Voting
• Cross-Channel plausibility checks will improve security for all
voting channels
• On the mid-term we’ll see a severe security problem in a
public vote
Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote
Questions and Answers, Contact
Contact: @ChrFolini
christian.folini@netnea.com
Election worker blog: www.christian-folini.ch

Contenu connexe

Similaire à The Adventurous Tale of Online Voting in Switzerland

Approaches for Tackling Online Misinformation.
Approaches for Tackling Online Misinformation.Approaches for Tackling Online Misinformation.
Approaches for Tackling Online Misinformation.Weverify
 
Qurator keynote berlin 2101 2020
Qurator keynote berlin 2101 2020Qurator keynote berlin 2101 2020
Qurator keynote berlin 2101 2020Weverify
 
Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...
Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...
Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...Weverify
 
Understanding Online Misinformation: Major Challenges Ahead, Rome,
Understanding Online Misinformation: Major Challenges Ahead, Rome, Understanding Online Misinformation: Major Challenges Ahead, Rome,
Understanding Online Misinformation: Major Challenges Ahead, Rome, Weverify
 
Using Apache Spark and Differential Privacy for Protecting the Privacy of the...
Using Apache Spark and Differential Privacy for Protecting the Privacy of the...Using Apache Spark and Differential Privacy for Protecting the Privacy of the...
Using Apache Spark and Differential Privacy for Protecting the Privacy of the...Databricks
 
SemiWEEK: Stocks jumped
SemiWEEK:  Stocks jumpedSemiWEEK:  Stocks jumped
SemiWEEK: Stocks jumpedVLSIresearch
 
UK Report - Disinformation and Fake News - St Lucia Implicated
UK Report - Disinformation and Fake News - St Lucia ImplicatedUK Report - Disinformation and Fake News - St Lucia Implicated
UK Report - Disinformation and Fake News - St Lucia ImplicatedTHINK FORWARD
 
OTT Services - Colour to the internet
OTT Services - Colour to the internetOTT Services - Colour to the internet
OTT Services - Colour to the internetRené C.G. Arnold
 
Human Rights Council Study Guide
Human Rights Council Study GuideHuman Rights Council Study Guide
Human Rights Council Study Guidedudasings
 
Fake news detection for Arabic headlines-articles news data using deep learning
Fake news detection for Arabic headlines-articles news data  using deep learningFake news detection for Arabic headlines-articles news data  using deep learning
Fake news detection for Arabic headlines-articles news data using deep learningIJECEIAES
 
INSPEC2T System Security & Privacy Considerations
INSPEC2T System Security & Privacy ConsiderationsINSPEC2T System Security & Privacy Considerations
INSPEC2T System Security & Privacy ConsiderationsTrilateral Research
 
Estimating migrant stocks and flows using social media data
Estimating migrant stocks and flows using social media dataEstimating migrant stocks and flows using social media data
Estimating migrant stocks and flows using social media dataJisu Kim
 
CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...
CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...
CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...CORBEL
 
Marsden Regulating Disinformation Kluge 342020
Marsden Regulating Disinformation Kluge 342020Marsden Regulating Disinformation Kluge 342020
Marsden Regulating Disinformation Kluge 342020Chris Marsden
 
Science Barometer Switzerland COVID-19 Edition
Science Barometer Switzerland COVID-19 EditionScience Barometer Switzerland COVID-19 Edition
Science Barometer Switzerland COVID-19 EditionMike Schäfer
 
EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...
EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...
EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...Steven Rhyner
 
Perceptions of Corruption in Sweden 2010
Perceptions of Corruption in Sweden 2010Perceptions of Corruption in Sweden 2010
Perceptions of Corruption in Sweden 2010EUROsociAL II
 
Wellbeing and Hybrid Working Strategies for Facility Managers
Wellbeing and Hybrid Working Strategies for Facility ManagersWellbeing and Hybrid Working Strategies for Facility Managers
Wellbeing and Hybrid Working Strategies for Facility ManagersChris Leake
 

Similaire à The Adventurous Tale of Online Voting in Switzerland (20)

Approaches for Tackling Online Misinformation.
Approaches for Tackling Online Misinformation.Approaches for Tackling Online Misinformation.
Approaches for Tackling Online Misinformation.
 
Qurator keynote berlin 2101 2020
Qurator keynote berlin 2101 2020Qurator keynote berlin 2101 2020
Qurator keynote berlin 2101 2020
 
Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...
Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...
Presentation "Understanding Online Misinformation: Major Challenges Ahead" by...
 
Understanding Online Misinformation: Major Challenges Ahead, Rome,
Understanding Online Misinformation: Major Challenges Ahead, Rome, Understanding Online Misinformation: Major Challenges Ahead, Rome,
Understanding Online Misinformation: Major Challenges Ahead, Rome,
 
Using Apache Spark and Differential Privacy for Protecting the Privacy of the...
Using Apache Spark and Differential Privacy for Protecting the Privacy of the...Using Apache Spark and Differential Privacy for Protecting the Privacy of the...
Using Apache Spark and Differential Privacy for Protecting the Privacy of the...
 
SemiWEEK: Stocks jumped
SemiWEEK:  Stocks jumpedSemiWEEK:  Stocks jumped
SemiWEEK: Stocks jumped
 
The state of Open Data in Belgium
The state of Open Data in BelgiumThe state of Open Data in Belgium
The state of Open Data in Belgium
 
UK Report - Disinformation and Fake News - St Lucia Implicated
UK Report - Disinformation and Fake News - St Lucia ImplicatedUK Report - Disinformation and Fake News - St Lucia Implicated
UK Report - Disinformation and Fake News - St Lucia Implicated
 
#NISWAW Session 2
#NISWAW Session 2#NISWAW Session 2
#NISWAW Session 2
 
OTT Services - Colour to the internet
OTT Services - Colour to the internetOTT Services - Colour to the internet
OTT Services - Colour to the internet
 
Human Rights Council Study Guide
Human Rights Council Study GuideHuman Rights Council Study Guide
Human Rights Council Study Guide
 
Fake news detection for Arabic headlines-articles news data using deep learning
Fake news detection for Arabic headlines-articles news data  using deep learningFake news detection for Arabic headlines-articles news data  using deep learning
Fake news detection for Arabic headlines-articles news data using deep learning
 
INSPEC2T System Security & Privacy Considerations
INSPEC2T System Security & Privacy ConsiderationsINSPEC2T System Security & Privacy Considerations
INSPEC2T System Security & Privacy Considerations
 
Estimating migrant stocks and flows using social media data
Estimating migrant stocks and flows using social media dataEstimating migrant stocks and flows using social media data
Estimating migrant stocks and flows using social media data
 
CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...
CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...
CORBEL/EOSC-Life webinar Practical Tips for Stepping Up Your Science Communic...
 
Marsden Regulating Disinformation Kluge 342020
Marsden Regulating Disinformation Kluge 342020Marsden Regulating Disinformation Kluge 342020
Marsden Regulating Disinformation Kluge 342020
 
Science Barometer Switzerland COVID-19 Edition
Science Barometer Switzerland COVID-19 EditionScience Barometer Switzerland COVID-19 Edition
Science Barometer Switzerland COVID-19 Edition
 
EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...
EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...
EUROPEAN PARLIAMENT TAKES INITIATIVE TO PUT CRYPTOCURRENCY, BLOCKCHAIN ON FAS...
 
Perceptions of Corruption in Sweden 2010
Perceptions of Corruption in Sweden 2010Perceptions of Corruption in Sweden 2010
Perceptions of Corruption in Sweden 2010
 
Wellbeing and Hybrid Working Strategies for Facility Managers
Wellbeing and Hybrid Working Strategies for Facility ManagersWellbeing and Hybrid Working Strategies for Facility Managers
Wellbeing and Hybrid Working Strategies for Facility Managers
 

Plus de Christian Folini

OWASP ModSecurity - A few plot twists and what feels like a happy end
OWASP ModSecurity - A few plot twists and what feels like a happy endOWASP ModSecurity - A few plot twists and what feels like a happy end
OWASP ModSecurity - A few plot twists and what feels like a happy endChristian Folini
 
Crazy incentives and how they drive security into no man's land
Crazy incentives and how they drive security into no man's landCrazy incentives and how they drive security into no man's land
Crazy incentives and how they drive security into no man's landChristian Folini
 
Never Walk Alone - Inspirations from a Growing OWASP Project
Never Walk Alone - Inspirations from a Growing OWASP ProjectNever Walk Alone - Inspirations from a Growing OWASP Project
Never Walk Alone - Inspirations from a Growing OWASP ProjectChristian Folini
 
What’s new in CRS4? An Update from the OWASP CRS project
What’s new in CRS4? An Update from the OWASP CRS projectWhat’s new in CRS4? An Update from the OWASP CRS project
What’s new in CRS4? An Update from the OWASP CRS projectChristian Folini
 
Extensive Introduction to ModSecurity and the OWASP Core Rule Set
Extensive Introduction to ModSecurity and the OWASP Core Rule SetExtensive Introduction to ModSecurity and the OWASP Core Rule Set
Extensive Introduction to ModSecurity and the OWASP Core Rule SetChristian Folini
 
Introduction to ModSecurity and the OWASP Core Rule Set
Introduction to ModSecurity and the OWASP Core Rule SetIntroduction to ModSecurity and the OWASP Core Rule Set
Introduction to ModSecurity and the OWASP Core Rule SetChristian Folini
 
Folini Extended Introduction to ModSecurity and CRS3
Folini Extended Introduction to ModSecurity and CRS3Folini Extended Introduction to ModSecurity and CRS3
Folini Extended Introduction to ModSecurity and CRS3Christian Folini
 
Gedanken zur elektronischen Stimmabgabe für Datenschützer
Gedanken zur elektronischen Stimmabgabe für DatenschützerGedanken zur elektronischen Stimmabgabe für Datenschützer
Gedanken zur elektronischen Stimmabgabe für DatenschützerChristian Folini
 
Medieval Castles and Modern Servers
Medieval Castles and Modern ServersMedieval Castles and Modern Servers
Medieval Castles and Modern ServersChristian Folini
 
E-Voting, die Sicherheit und die Rolle der Experten
E-Voting, die Sicherheit und die Rolle der ExpertenE-Voting, die Sicherheit und die Rolle der Experten
E-Voting, die Sicherheit und die Rolle der ExpertenChristian Folini
 
Black alps 2018-folini-d-dos
Black alps 2018-folini-d-dosBlack alps 2018-folini-d-dos
Black alps 2018-folini-d-dosChristian Folini
 
Optimizing ModSecurity on NGINX and NGINX Plus
Optimizing ModSecurity on NGINX and NGINX PlusOptimizing ModSecurity on NGINX and NGINX Plus
Optimizing ModSecurity on NGINX and NGINX PlusChristian Folini
 
A General Look at the State of Security - AFCEA 2017
A General Look at the State of Security - AFCEA 2017A General Look at the State of Security - AFCEA 2017
A General Look at the State of Security - AFCEA 2017Christian Folini
 
Introducing the OWASP ModSecurity Core Rule Set
Introducing the OWASP ModSecurity Core Rule SetIntroducing the OWASP ModSecurity Core Rule Set
Introducing the OWASP ModSecurity Core Rule SetChristian Folini
 
OWASP ModSecurity Core Rules Paranoia Mode
OWASP ModSecurity Core Rules Paranoia ModeOWASP ModSecurity Core Rules Paranoia Mode
OWASP ModSecurity Core Rules Paranoia ModeChristian Folini
 

Plus de Christian Folini (15)

OWASP ModSecurity - A few plot twists and what feels like a happy end
OWASP ModSecurity - A few plot twists and what feels like a happy endOWASP ModSecurity - A few plot twists and what feels like a happy end
OWASP ModSecurity - A few plot twists and what feels like a happy end
 
Crazy incentives and how they drive security into no man's land
Crazy incentives and how they drive security into no man's landCrazy incentives and how they drive security into no man's land
Crazy incentives and how they drive security into no man's land
 
Never Walk Alone - Inspirations from a Growing OWASP Project
Never Walk Alone - Inspirations from a Growing OWASP ProjectNever Walk Alone - Inspirations from a Growing OWASP Project
Never Walk Alone - Inspirations from a Growing OWASP Project
 
What’s new in CRS4? An Update from the OWASP CRS project
What’s new in CRS4? An Update from the OWASP CRS projectWhat’s new in CRS4? An Update from the OWASP CRS project
What’s new in CRS4? An Update from the OWASP CRS project
 
Extensive Introduction to ModSecurity and the OWASP Core Rule Set
Extensive Introduction to ModSecurity and the OWASP Core Rule SetExtensive Introduction to ModSecurity and the OWASP Core Rule Set
Extensive Introduction to ModSecurity and the OWASP Core Rule Set
 
Introduction to ModSecurity and the OWASP Core Rule Set
Introduction to ModSecurity and the OWASP Core Rule SetIntroduction to ModSecurity and the OWASP Core Rule Set
Introduction to ModSecurity and the OWASP Core Rule Set
 
Folini Extended Introduction to ModSecurity and CRS3
Folini Extended Introduction to ModSecurity and CRS3Folini Extended Introduction to ModSecurity and CRS3
Folini Extended Introduction to ModSecurity and CRS3
 
Gedanken zur elektronischen Stimmabgabe für Datenschützer
Gedanken zur elektronischen Stimmabgabe für DatenschützerGedanken zur elektronischen Stimmabgabe für Datenschützer
Gedanken zur elektronischen Stimmabgabe für Datenschützer
 
Medieval Castles and Modern Servers
Medieval Castles and Modern ServersMedieval Castles and Modern Servers
Medieval Castles and Modern Servers
 
E-Voting, die Sicherheit und die Rolle der Experten
E-Voting, die Sicherheit und die Rolle der ExpertenE-Voting, die Sicherheit und die Rolle der Experten
E-Voting, die Sicherheit und die Rolle der Experten
 
Black alps 2018-folini-d-dos
Black alps 2018-folini-d-dosBlack alps 2018-folini-d-dos
Black alps 2018-folini-d-dos
 
Optimizing ModSecurity on NGINX and NGINX Plus
Optimizing ModSecurity on NGINX and NGINX PlusOptimizing ModSecurity on NGINX and NGINX Plus
Optimizing ModSecurity on NGINX and NGINX Plus
 
A General Look at the State of Security - AFCEA 2017
A General Look at the State of Security - AFCEA 2017A General Look at the State of Security - AFCEA 2017
A General Look at the State of Security - AFCEA 2017
 
Introducing the OWASP ModSecurity Core Rule Set
Introducing the OWASP ModSecurity Core Rule SetIntroducing the OWASP ModSecurity Core Rule Set
Introducing the OWASP ModSecurity Core Rule Set
 
OWASP ModSecurity Core Rules Paranoia Mode
OWASP ModSecurity Core Rules Paranoia ModeOWASP ModSecurity Core Rules Paranoia Mode
OWASP ModSecurity Core Rules Paranoia Mode
 

Dernier

🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 

Dernier (20)

🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 

The Adventurous Tale of Online Voting in Switzerland

  • 1. The Adventurous Tale of Online Voting in Switzerland Christian Folini – Insomni’Hack 2022 Keynote
  • 2. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Plan for Today ⚫ Overview of the past 20 years ⚫ A new perspective on the events of 2019 ⚫ Expert dialogue and scholarly report of 2020 ⚫ Public consultation and new regulation 2021/22 ⚫ Several ridiculous predictions about the future
  • 3. Boring BIO ⚫ Dr. Christian Folini ⚫ Historian and Swiss Security Engineer ⚫ Open Source Security Project Lead (OWASP CRS) ⚫ Election worker blog at www.christian-folini.ch ⚫ Wearer of many hats helmets with Swiss E-Voting @ChrFolini
  • 4. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote "We simply can’t build an Internet voting system that is secure against hacking because of the requirement for a secret ballot." Bruce Schneier, Online Voting Won’t Save Democracy, The Atlantic, May 2017 Key Argument against Online Voting
  • 5. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Arguments in Favor of Online Voting
  • 6. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote • Citizens living abroad Arguments in Favor of Online Voting
  • 7. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote • Citizens living abroad • Visually impaired and quadriplegic voters Arguments in Favor of Online Voting
  • 8. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote • Citizens living abroad • Visually impaired and quadriplegic voters • Formally invalid ballots Arguments in Favor of Online Voting
  • 9. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote • Citizens living abroad • Visually impaired and quadriplegic voters • Formally invalid ballots • Security weaknesses of physical voting Arguments in Favor of Online Voting
  • 10. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2004 2009 2011 2004 2000 1st project 1st Geneva trial Entering Scytl Consortium Steering Board 1st Swiss internet voting project is launched with three pilot cantons. Swiss canton Neuchâtel deploys Spanish Scytl software for online voting. Federal administration and cantons establish a joint steering committee. Canton Geneva runs the first Swiss internet voting trial. Eight Swiss cantons form a consortium and commission Swiss branch of American Unisys with the creation of an internet voting system. Timeline Online Voting in Switzerland
  • 11. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2015 2017 2015 2011 Steering Board Consortium dies Scytl/Swiss Post join Mainstreaming attempt Federal administration and cantons establish a joint steering committee. Spanish Scytl and Swiss Post form joint venture with Scytl providing the software and Swiss Post operating the systems on premise. The eight consortium cantons throw towel after federal administration barrs system from use in national elections. The federal chancellor calls for 2/3 of the cantons to offer internet voting for national elections in 2019. Timeline Online Voting in Switzerland
  • 12. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2017 / 2018 – The Resistance is Emerging • Beyond 100 articles on Swiss E-Voting • Feeling that 3 out of 4 quoted Hernâni Marques • Confrontation was fought tooth and nail • Sentiment Analysis: ️
  • 13. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2018 / 2019 Geneva Quits Source: Twitter: @GE_chancellerie (1141332323025195009) 2018: Development stopped 2019: System terminated
  • 14. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2018.11 2019.2 2017 2016 Scytl/Swiss Post join Mainstreaming attempt Geneva quits Bug Bounty Source Code Publication Spanish Scytl and Swiss Post form joint venture and go into production. Political quarrels lead to Geneva stopping all further development. A year later, the system is terminated. The federal chancellor calls for 2/3 of the cantons to offer internet voting for national elections in 2019. Scytl / Swiss Post publish the source code of their system and run a 4 week bug bounty. Timeline Online Voting in Switzerland
  • 15. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Swiss Post / Scytl Source Code: Total Desaster
  • 16. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2018.11 2019.2 2017 2016 Scytl/Swiss Post join Mainstreaming attempt Geneva quits Start Bug Bounty Source Code Publication Spanish Scytl and Swiss Post form joint venture and go into production. Political quarrels lead to Geneva stopping all further development. A year later, the system is terminated. The federal chancellor calls for 2/3 of the cantons to offer internet voting for national elections in 2019. Scytl / Swiss Post publish the source code of their system. Researchers identify three critical vulnerabilities within weeks. The system is put on hold. 2019.3 E-Voting Referendum Launched Collection period for popular initiative with the goal of 100,000 signatures started. Timeline Online Voting in Switzerland
  • 17. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Online Voting Referendum Launched Source: Twitter: @wecollectCH (1106865437097246722)
  • 18. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Online Voting Headlines in Switzerland 2019 Data source: noevoting.ch, chart by Christian Folini
  • 19. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Online Voting Signatures Promised to WeCollect Source: archive.org → wecollect.ch (2019-03-22)
  • 20. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Signatures Promised to WeCollect Data source: https://christian-folini.ch/pub/wecollect-noevoting-numbers.csv
  • 21. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2018 2019 2020.4 2017 2016 Scytl/Swiss Post join Mainstreaming attempt Geneva quits E-Voting on hold Rebooting Spanish Scytl and Swiss Post form joint venture and go into production. Political quarrels lead to Geneva stopping all further development. A year later, the system is terminated. The steering board establishes a dialog with 25 scientists to assess viability of internet voting and support with writing new regulation. The federal chancellor calls on 2/3 of the cantons to offer internet voting for national elections in 2019. Scytl / Swiss Post publish the source code of their system. Researchers identify three critical vulnerabilities within weeks. The system is put on hold. 2020.6 E-Voting Referendum dies Despite the promising headlines in 2019, the collection of signatures fails miserably. Timeline Online Voting in Switzerland
  • 22. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote CRYPTOGRAPHERS AND ONLINE VOTING EXPERTS David Basin, ETH Zurich Srdjan Capkun, ETH Zurich Eric Dubuis, BFH Bern Bryan Ford, EPF Lausanne Reto Koenig, BFH Bern Philipp Locher, BFH Bern Olivier Pereira, University of Leuven, Belgium Vanessa Teague, Australia Bogdan Warinschi, Bristol, UK Rolf Haenni, BFH Bern SECURITY INDUSTRY Stéphane Adamiste, SCRT Sergio Alves Domingues, SCRT Tobias Ellenberger, One Consult Source: https://www.bk.admin.ch/bk/de/home/politische-rechte/e-voting.html COMPUTER SCIENTISTS David-Olivier Jaquet-Chiffelle, Uni. of Lausanne Oscar Nierstrasz, University of Bern Adrian Perrig, ETH Zurich Carsten Schürmann, Denmark Matthias Stürmer, University of Bern Ulrich Ultes-Nitsche, University of Fribourg POLITICAL SCIENTISTS Florian Egloff, ETH Zurich Fabrizio Gilardi, University of Zurich Uwe Serdült, Center for Democracy, Aarau MODERATOR Christian Folini, netnea.com Expert Dialogue – Participating Scientists
  • 23. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2020.4 2020.7 2020.11 2020.3 2020.2 Survey Covid-19 hits Online dialogue Additional research Scientific report The dialogue starts with a survey over 62 questions sent to 25 scientists The workshops are replaced with a 12 weeks online dialogue on a dedicated gitlab platform. The steering board publishes the 70 pages report with the re- commendations of the scientists. When the on-site workshops were slowly taking shape, Switzer-land entered a lock-down and the on-site gatherings had to be called off. Several separate re-search articles are commissioned with individual scientists to bring up more infor-mation on individual questions. Timeline Online Voting in Switzerland
  • 24. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote https://www.bk.admin.ch/bk/en/home/politische-rechte/e-voting.html Scholarly report
  • 25. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote • Cryptography: A ton of advice, also on quantum • Call for diversity in hard- and software • Maximum level of transparency, Open Source • Cross-Channel plausibility checks Key Recommendations of Dialogue
  • 26. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 2020.4 2020.7 2020.11 2020.3 2020.2 Survey Covid-19 hits Online dialogue Additional research Scientific report The dialogue starts with a survey over 62 questions sent to 25 scientists The workshops are replaced with a 12 weeks online dialogue on a dedicated gitlab platform. The steering board publishes the 70 pages report with the re- commendations of the scientists. When the on-site workshops were slowly taking shape, Switzer-land entered a lock-down and the on-site gatherings had to be called off. Several separate re-search articles are commissioned with individual scientists to bring up more infor-mation on individual questions. 2021.4 Public Consultation Following standard Swiss procedure the draft new e-voting regulation is put up for a public consultation where all interested parties are invited to provide feedback. Timeline Online Voting in Switzerland
  • 27. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Public Consultation for New Regulation Source: Federal Chancellery
  • 28. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote 67 Responses in Public Hearing Source: DigiGes Switzerland
  • 29. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Response Report of Public Consultation Source: Federal Chancellery
  • 30. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Who Has Responded? And How? Source: Federal Chancellery 67 Responses 48 positive 11 positive with fundamental reservations 8 negative 697 pages all in all Missing: EVP GLP Swiss ICT ISSS CCC-CH
  • 31. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Who Responded to the Technical Annex? Source: Federal Chancellery 24 Responses: 6 minimal: AI, GE, Pirate Party, SBb, Procap, SZBlind 18 substantial: AG, BE, BS, FR, GL, GR, SG, SO, SZ, TG, VS, ZH BFH, SBV, Post, SSK, Florian Moser, IsA Missing: Political Parties, SATW, DigitalSwitzerland, SWICO, DigiGes
  • 32. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Call for Open Source Source: Federal Chancellery 11 responses support an enforced Open Source approach for the software. Alternative Linke Bern "Open Source bedeutet Lizenzierung" CH++ "vollständiger Open Source Ansatz eine essentielle Bedingung" Digitale Gesellschaft "Versäumnis eines fehlenden Zwangs zu Open Source hat negative Signalwirkung" digitalswitzerland* "Weiter begrüsst digitalswitzerland die Vorgaben zu Open Source" Economiesuisse* "Vorgaben zu Open Source ... zu begrüssen" Florian Moser "konkret die Publizierung sämtlichen Materials unter einer Open Source Lizenz vorschreiben" Grüne "Wir fordern mehr Open Source" IsA "im Widerspruch zur Empfehlung ... keine Open Source Lizenz verordnet" Piratenpartei "Vollständige Publikation des Source Codes unter einer Open Source Lizenz" SP "erachten wir bereits im Testbetrieb einen vollständigen Open-Source-Ansatz für notwendig." Stift. Konsumentens. "keine umfassende Open-Source-Pflicht enthalten" * The two marked organisations misread the regulation and believe Open Source was actually in the draft regulation. It is not.
  • 33. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Open Source in Federal Chancellery’s Media Release Source: Federal Chancellery “Others who took part in the consultation also raised fundamental issues: for example, some would like to see all e- voting systems and their components disclosed under an open source licence. The Federal Council takes these fundamental issues very seriously. They concern the security of e-voting and the public's confidence in this voting method and will be addressed in the longer term ...”
  • 34. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Timeline Online Voting in Switzerland 2022 Q2/3 2022/23 2021.12 2021.4 Report on Public Consultation New Regulation New E-Voting Trials New regulation is expected for Summer 2022 Report comes in at whopping 697 pages with 67 individual responses. A small number of Swiss Cantons will take up new E-Voting trials in late 2022 or 2023 aiming for national elections in Autumn 2023. Public Consultation Following standard Swiss procedure the draft new online voting regulation is put up for a public consultation where all interested parties are invited to provide feedback.
  • 35. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Ridiculous Predictions Beyond 2022/23
  • 36. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Ridiculous Predictions Beyond 2022/23 • Slow expansion of E-Voting after the national election 2023
  • 37. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Ridiculous Predictions Beyond 2022/23 • Slow expansion of E-Voting after the national election 2023 • E-Voting system of Swiss Post will become open source
  • 38. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Ridiculous Predictions Beyond 2022/23 • Slow expansion of E-Voting after the national election 2023 • E-Voting system of Swiss Post will become open source • A disability organization will sue for E-Voting
  • 39. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Ridiculous Predictions Beyond 2022/23 • Slow expansion of E-Voting after the national election 2023 • E-Voting system of Swiss Post will become open source • A disability organization will sue for E-Voting • Cross-Channel plausibility checks will improve security for all voting channels
  • 40. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Ridiculous Predictions Beyond 2022/23 • Slow expansion of E-Voting after the national election 2023 • E-Voting system of Swiss Post will become open source • A disability organization will sue for E-Voting • Cross-Channel plausibility checks will improve security for all voting channels • On the mid-term we’ll see a severe security problem in a public vote
  • 41. Christian Folini / @ChrFolini – Insomni’hack 2022 Keynote Questions and Answers, Contact Contact: @ChrFolini christian.folini@netnea.com Election worker blog: www.christian-folini.ch