National: Microsoft Research Proposes E-Voting Attack Mitigation | threatpost
Microsoft Research has proposed a mitigation for a known potential attack against verifiable electronic voting machines that could help prevent insiders from being able to alter votes after the fact. The countermeasure to the “trash attack” involves adding a cryptographic hash to the receipts that voters receive.
Many verifiable voting systems already include hashes on the receipts, but that hash typically is of the ballot data for each specific voter. The idea proposed by Microsoft Research involves using a running hash that would add a hash of the previous voter’s receipt to each person’s receipt, ideally preventing a privileged insider from using discarded receipts to alter votes. The trash attack that the mitigation is designed to address involves election workers or others who might be motivated to change votes gathering discarded receipts and then altering those votes.
“The provision of receipts to voters who may not want them, however, suggests a very simple means by which election workers could find votes that are good candidates for alteration: poll workers could simply collect the contents of the nearest trash receptacles. Any receipts that have been discarded by voters would be strongly correlated with votes that could be altered without detection.3 Active collection of receipts may also be viable through social engineering,” Josh Benaloh of Microsoft Research and Eric Lazarus of DecisionSmith wrote in a research paper, “The Trash Attack”.

