Perimeter
12/16/2008
03:51 PM
Connect Directly
RSS
E-Mail
50%
50%

Can You Vote for Me Now? Estonia First Country to Cast Cell Phone Votes

The Estonian Parliament has passed a law that will allow citizens to vote via cell phone by 2011. In the past, Estonians were able to cast their votes over the Internet, which apparently worked seamlessly despite security concerns. (See Sara Peters' coverage of e-voting in Estonia in the November 2005 Alert, Academic Group Publishes Criticisms of e-Voting; memb

The Estonian Parliament has passed a law that will allow citizens to vote via cell phone by 2011. In the past, Estonians were able to cast their votes over the Internet, which apparently worked seamlessly despite security concerns. (See Sara Peters' coverage of e-voting in Estonia in the November 2005 Alert, Academic Group Publishes Criticisms of e-Voting; membership required.)The cell phones will each have a free, authorized chip that verifies each voter's identity. However, the Estonia government should be wary of this new system because of what could happen if a person's cell phone is stolen and used to cast a vote. Additionally, hasn't it learned from its sustained cyberattack on the country's Internet infrastructure last year?

Although Estonian officials did not accuse Russia of being behind the attacks, relations between the Kremlin and former parts of the Soviet Union have been on shaky terms. The cyberattack involved users overloading the Internet system, thus making it impossible for Estonians to perform such basic tasks as buying bread, milk, and gas. Several of the main targets were Estonian government ministries, news and communications organizations, and banks.

The Estonian government estimated the attack cost US$2.7 million to $4.5 million in damages.

Estonia is the first country to have cell phone voting, but supposedly Finland and Sweden also have the capability to hold one. Time will tell how cell phones set the tone for future voting methods.

Kristen Romonovich is Associate Editor at the Computer Security Institute. She is dedicated to Green IT, Web 2.0 and the security of social media, and data security at the upcoming annual conference CSI 2008: Security Reconsidered. Visit www.CSIAnnual.com to learn more.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6335
Published: 2014-08-26
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and ...

CVE-2014-0480
Published: 2014-08-26
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL ...

CVE-2014-0481
Published: 2014-08-26
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a d...

CVE-2014-0482
Published: 2014-08-26
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors relate...

CVE-2014-0483
Published: 2014-08-26
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.