‘Critical’ Vulnerability Found in Australian Internet Voting System in Advance of Next Week’s Election

'Major security hole' could allow attacker to read, change votes...

Share article:

Another new Internet Voting system, another major vulnerability to massive election fraud discovered along with it. This time in Australia, as reported by ABC:

A “major security hole” that could allow an attacker to read or change someone’s vote has been discovered in the New South Wales online iVote platform, security experts say.

The iVote system allows people to lodge their votes for Saturday’s state election online, instead of visiting a physical polling station.

It aims to make voting easier for the disabled or for people who live long distances from polling booths.

However computer security researchers said they found a critical issue and alerted the NSW Electoral Commission on Friday afternoon.

The commission said the problem was fixed over the weekend and it expected 200,000 people would use the system in the lead up to the election.

Well. If the people who run it said it was fixed, why worry? (Just because they also said it was secure in the first place? Silly you.)

“Just because they’ve patched this particular bug that they’ve been specifically notified of does not mean that they’ve fixed the fundamental questions around the security and verifiability of the system,” said University of Melbourne’s Vanessa Teague, who discovered the security vulnerability. “If anything the existence of this one particular bug serves to bolster the argument that these kinds of bugs are probably inevitable in these kinds of systems”…

“We’ve been told repeatedly that votes are perfectly secret and the whole system is secure and it can’t be tampered with and so on, and we’ve shown very clearly than that’s not true – that these votes are not secret and they can be tampered with,” Ms Teague said.

She said the attack could allow another person to either read, or even manipulate a vote, before it was sent to the electoral commission’s servers.

“The analogue would be pulling someone’s postal vote envelope out of the post, pulling out their vote and finding out how they intended to vote and then putting a different ballot in instead,” Ms Teague said.

“The point of course with the electronic equivalent is that an attacker wouldn’t necessarily need to be in New South Wales to do this and they could potentially do this in an automated way to a very, very large number of votes.”

Ms Teague said the voter would be unaware their vote had been changed.

The Chief Information Officer with the NSW Electoral Commission offered this unfortunate quote to the ABC: “We are confident however that the system is yielding the outcome that we actually initially set out to yield,” before adding: “and that is that the verification process is not telling us any faults are in the system.”

The ABC also notes that “The computer code of the iVote platform is not open source and is not available broadly for security experts to review.”

Other than that, sounds like a fantastic idea!

We’ve written about so many Internet Voting disasters over the years, along with scientifically supported reasons why it can never be done safely or verifiably, that we’ll just summarize by sharing this quote from our 2013 article about L.A. County’s plans for a new voting system which, while set to be 100% unverifiable after an election, as currently planned, at least does not include Internet Voting, according to our interview at the time with Los Angeles County Registrar-Recorder/County Clerk Dean Logan:

We have long detailed the madness of Internet Voting. Among our coverage, we’ve documented a number of disastrous attempts at Internet Voting systems and the many dangers they pose to security and oversight, as well as the warnings against them by computer science and security experts, and Election Integrity experts.

One need only look back to Washington D.C.’s disastrous experiment in Internet Voting, which almost went live in 2010 for overseas and military voters. The plans to use the system were scrapped at the last minute after it was hacked and completely taken over by “white hat hackers” (University of Michigan computer students and their professor), who had gained such total command of the system in mere hours that they were not only able to change every vote already cast on it during a mock election, but inserted a script into the system to change all future votes invisibly as well. They even modified all of the system’s main passwords to thwart similar attempts to hack the system that they discovered to be ongoing by computers from both Iran and China.

There have been many other disasters in Internet Voting — from a 2012 online Canadian election attacked by some 10,000 computers, to a 2012 CA State University student body election that was hacked by one of the candidates in order to gain control of an annual salary and the student government’s $300,000 budget, to this year’s embarrassment by the Academy of Motion Picture Arts and Sciences which attempted to use Internet Voting for the first time this year, to disturbing and questionable effect.

The non-partisan election integrity group, VerifiedVoting.org posted a “Statement on the Dangers of Internet Voting in Public Elections,” signed by nearly a dozen top computer science and security experts with backgrounds in electronic voting systems. The letter explains that “Cyber security experts at the National Institute of Standards and Technology and the Department of Homeland Security have warned that current Internet voting technologies should not be deployed in public elections,” as they “cannot be properly protected and may be subject to undetectable alteration.”

* * *
Please help support The BRAD BLOG’s fiercely independent, award-winning coverage of your electoral system and much more — now in our TWELFTH YEAR! — as available from no other media outlet in the nation…

The BRAD BLOG, The BradCast and Green News Report are all 100% independent and 100% listener and reader supported!Please CLICK HERE to help support our work today!

Share article:

Reader Comments on

‘Critical’ Vulnerability Found in Australian Internet Voting System in Advance of Next Week’s Election

3 Comments

(Comments are now closed.)


3 Responses

  1. 1)
    Lowell Finley said on 3/24/2015 @ 9:20am PT: [Permalink]

    Thanks for covering this important story. The iVote Internet voting system was developed in partnership with Scytl, a Spanish company that has been successfully promoting its Internet voting system all over the world, including in the U.S., as completely secure against tampering and completely protecting ballot secrecy.

  2. 2)
    Michael G said on 3/25/2015 @ 10:00am PT: [Permalink]

    I’m surprised the personal privacy wanks aren’t all over this. If, as is widely suspected, the CIA has planted bugs in the root systems of most computers, any computer-related voting should be laughed at without a second thought, especially through networked systems.

    Hey, Brad, in light of how simple it is to make money off such vulnerable systems as you’ve demonstrated endlessly, and as knowledgeable you are about these systems, maybe you should consider starting a computerized voting system yourself. The ironies will get a lot of attention and sales and then you can sell the company and not worry about raising money from your readers.

  3. Avatar photo
    3)
    Brad Friedman said on 3/25/2015 @ 6:39pm PT: [Permalink]

    Michael G –

    If, as is widely suspected, the CIA has planted bugs in the root systems of most computers…

    Along those lines, you may enjoy this piece of ours from 2009: CIA Warning: ‘E-Voting Not Secure’ – U.S. EAC Finally Releases Complete Transcript of Cybersecurity Expert’s Stunning Remarks

    maybe you should consider starting a computerized voting system yourself. The ironies will get a lot of attention and sales and then you can sell the company and not worry about raising money from your readers.

    I like that last part! But, other than that, I couldn’t do it. Sure, I could make money selling crack, and I think it should be legal to sell crack, even if I think selling (and/or using) crack is a bad idea. So, even if I could make money at it…well, you get the idea. 🙂

    (Though, I should add, if crack were legal to sell, I think I would prefer to sell that over an e-voting system!)

(Comments are now closed.)


Thanks to you, The BRAD BLOG has been trouble-making and muckraking for … 22 YEARS!!!

Please help The BRAD BLOG, BradCast and Green News Report remain independent and 100% reader and listener supported in our 23rd YEAR!!!

ONE TIME
any amount...

MONTHLY
any amount...

OR VIA SNAIL MAIL
Make check out to...
Brad Friedman / BRAD BLOG
7095 Hollywood Blvd., #594
Los Angeles, CA 90028

RECENT POSTS

The BRAD BLOG Reborn…

And it only took 20 years or so...

Corrupt SCOTUS Undermines U.S. Constitution, Guts Last Remaining Protections of Voting Rights Act: ‘BradCast’ 4/29/2026

Guest: Redistricting expert Dan Vicuña of Common Cause; Also: Comey's dumb new indictment; E. Jean Carroll wins again; More new lows for Trump approval...

Trump’s Activist Rightwing ‘Originalist’ Judges Strike Again in Texas: ‘BradCast’ 4/28/2026

Guest: Jay Willis of Balls and Strikes; Also: Dem takes polling lead for U.S. Senate in TX as Repubs brace for 'sour, ugly, bad, bleak' midterm elections...

‘Green News Report’ – April 28, 2026

With Brad Friedman and Desi Doyen

Trump, Repubs Exploit Failed Assassination Plot to Advance Ballroom Blitz: ‘BradCast’ 4/27/2026

What we know about the alleged shooter, Trump's opportunist response, corrupt contracting for the ballroom, fury at being described as a 'pedophile'; Also: Callers ring in!...

Sunday ‘So Much Winning’ Toons

THIS WEEK: Punch Drunk ... Kash Poor ... Forever War ... The Shadow Docket Knows! ...

So Much Losing: ‘BradCast’ 4/23/2026

In Iran, in public opinion, at the ballot box, in the courtroom...

‘Green News Report’ – April 23, 2026

With Brad Friedman & Desi Doyen...

‘A Scammer’s Treasure Trove’: DOGE Bros Stole Your Social Security Data: ‘BradCast’ 4/22/2026

Guest: Nancy Altman of Social Security Works; Also: 'Yes', Virginia, there is a new U.S. House map! (For now)...

Insiders Making a Killing Betting on Trump’s War: ‘BradCast’ 4/21/2026

Guest: Craig Holman of Public Citizen; Also: Judge blocks Admin scheme to prevent wind, solar development; Another TACO Tuesday for Iran...

‘Green News Report’ – April 21, 2026

With Brad Friedman & Desi Doyen...

Week 8: Iran War Lies Continue from Sundowning Gaslighter-in-Chief: ‘BradCast’ 4/20/2026

Also: Approval rating plummets; More Dem overperformance in NJ; VA voters voting; CA primary election chaos; Callers ring in...

Sunday ‘WWJD?’ Toons

THIS WEEK: Paging Dr. Jesus ... Strait Outta Hormuz ... It's What's for Dinner ...

U.S. Middle Eastern ‘War Crimes’ Then and Now: ‘BradCast’ 4/16/2026

Guest: Attorney, former U.S. Army Captain Keith Barber; Also: Eastman disbarred; ICE official charged in MN...

‘Green News Report’ – April 16, 2026

With Brad Friedman & Desi Doyen...

About Brad Friedman...

Brad is an independent investigative journalist, blogger and broadcaster. Full Bio & Testimonials… Media Appearance Archive… Articles & Editorials Elsewhere… Contact…

He has contributed chapters to these books…
…And is featured in these documentary films…

BRAD BLOG ON THE AIR!

THE BRADCAST on KPFK/Pacifica Radio Network (90.7FM Los Angeles, 98.7FM Santa Barbara, 93.7FM N. San Diego and nationally on many other affiliate stations! ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

GREEN NEWS REPORT, nationally syndicated, with new episodes on Tuesday and Thursday. ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

Media Appearance Archives…

AD
CONTENT

ADDITIONAL STUFF

Brad Friedman/
The BRAD BLOG Named...

Buzz Flash's 'Wings of Justice' Honoree
Project Censored 2010 Award Recipient
The 2008 Weblog Awards