An independent audit of mobile voting app Voatz, which has been used in elections in four US states, details many critical vulnerabilities and recommends fixes
Voatz allows voters to cast their ballots from any geographic location on supported mobile devices.
Trail of Bits BlogDan Guido
Context & Ripple Effects
Voatz's mobile voting platform entered US elections through West Virginia's 2018 midterm rollout for overseas troops and spread to four more states, but the security story has been deteriorating all year: February researcher findings already flagged elementary flaws that could let an attacker intercept and alter votes.
This Trail of Bits audit is the independent confirmation of those claims, and it lands between two escalations — the researchers' disclosure and Voatz's subsequent expulsion from HackerOne over hostile treatment of security researchers — leaving election officials with a vendor whose product and security posture are both under documented challenge.
First-order effects
Jurisdictions in the four states using Voatz now have an independent audit recommending fixes for critical vulnerabilities, forcing each to decide whether to keep running elections on the app, pause it, or demand remediation before the next cycle.
Voatz must implement the audit's recommended fixes while its researcher relationships are broken — it no longer has a bug-bounty channel after the HackerOne removal, so vulnerability reports have fewer legitimate paths in.
Second-order effects
Scrutiny spreads to adjacent vendors: OmniBallot, used nationally for ballot delivery and marking, was independently flagged weeks later, so buyers of mobile and web voting tools now treat third-party audits as table stakes rather than optional diligence.
Expansion plans like the Greater Seattle district's smartphone voting for ~1.2M voters face a higher evidentiary bar, since every new deployment now gets measured against the Voatz audit record rather than against vendor assurances.
Third-order effects
If the pattern holds — independent audits contradicting vendor claims, followed by platform bans and expert skepticism about trial 'successes' — procurement of internet-based voting shifts toward mandatory external verification, and vendors that resist researcher engagement get priced out of public contracts.
The trend: US mobile voting is moving from pilot enthusiasm toward audit-gated adoption, where independent security review — not vendor marketing or early state trials — determines which systems stay deployed.
That Voatz had the audacity to paint researchers as malicious when they were using hardcoded encryption keys from a stack overflow answer to “protect” ballot receipts says everything you need to know about e-voting vendors. Closed source e-voting has no future. https://twitter.co…
US election Blockchain voting company Voatz have had another independent security audit, this time by @trailofbits. It shows an incredible array of basic security issues, with systems and code used in live US elections. https://blog.trailofbits.com/ ... https://twitter.com/...
Nice summary thread on comprehensive report - this is the model of the kind of scrutiny that voting systems should be subject to *before* used for actual voting in real elections. @voatz put real-live voters ballots at risk all around the country. https://blog.trailofbits.com/ ..…
https://blog.trailofbits.com/ ... This is a stunning result, Voatz's blockchain nonsense had no business being anywhere near a US election. This is a pattern I've seen repeated in the public sector: Blockchain not solving problems securely, but scamming governments out of money a…
This is good work by a highly respected team. Looks like Voatz is trying to dig themselves out of the hole they created with their horrible response to MIT. https://twitter.com/...
New study on Voatz from @trailofbits is by far the most comprehensive one yet made public. They discovered a *lot* of vulnerabilities, and many issues unfixed, though the fact that we're able to read this is also significant progress from Voatz. https://blog.trailofbits.com/ ...
“The quantity of findings discovered during this assessment, the complexity of the system, and the lack of access to both a running test environment as well as certain codebases leads us to believe that other vulnerabilities are latent.” https://twitter.com/...
Remember that Voatz mobile voting app? MIT researchers who published a recent report weren't able to examine all of it, but @trailofbits has now taken a more comprehensive look and found 79 issues - 1/3 of them “high severity” https://blog.trailofbits.com/ ...
Vote-By-Mail is urgently needed all over the country. Also, hucksters shilling “smart” voting tech should be avoided like the coronavirus. https://twitter.com/...
And here's some commentary from @SarahJamieLewis on that new Voatz report (Sarah had previously examined the Swiss internet voting system and found severe security flaws with that system, which I reported here at the time: https://t.co/...) https://twitter.com/...