Type of site | Private |
---|---|
Founded | December 22, 2016; 6 years ago |
Area served | Worldwide |
Founder(s) | Nimit Sawhney |
Key people | Nimit Sawhney (Co-Founder and CEO) Simer Sawhney (Co-Founder and Board Member) Jesse Andrews (Director of Sales and Business Development) Kahlil Byrd (Board Member) |
Industry | Technology |
URL | voatz |
Voatz is a for-profit, private mobile Internet voting application. The stated mission of Voatz is to "make voting not only more accessible and secure, but also more transparent, auditable and accountable." [1] The company is headquartered in Boston, Massachusetts. [2]
Citizens in Utah, Colorado, West Virginia, and other spots around the country have used the mobile app Voatz to cast their ballots in statewide elections. 2020, ″marks the first time people have used the technology to vote in a presidential contest.″ [3] The app has also been used by the city of Denver for its municipal elections in 2019, and West Virginia used it for its primary in 2018. [3]
In a 2018 pilot project for West Virginia, using Voatz, American voters submitted ballots from 29 countries including Albania, Botswana, Egypt, Mexico and Japan. [4]
Before 2020, Voatz received substantial criticism for not being transparent with their auditing process; although Voatz had claimed to be subjected to security audits by independent technology firms, it was not been forthcoming with the results. For example, when reporters have reached out to auditors they did not hear back, [5] and Voatz has insisted that these same companies sign non-disclosure agreements prior to investigating the company. [6]
In 2020, a report by MIT researchers identified a number of high-severity vulnerabilities in Voatz's architecture, [7] which Voatz vehemently denied, calling the research "flawed.". [8] A follow-on security assessment, paid for by Voatz itself, was released by the security auditing firm Trail of Bits, confirming the MIT researchers' results, and another 48 technical issues were reported (plus 31 threat model findings for a total of 79 findings), a third of which were rated 'high severity.' [9] 8 of the 48 technical issues were addressed. [9]
Voatz was created by Nimit Sawhney in 2014, and was developed as a side project at a SXSW hackathon. [10] As of October 2019, the startup has conducted over 31 pilots and completed a $7 million Series A in June. [11]
Voatz uses blockchain technology and biometrics in order to verify voter identities, forgoing the storage of sensitive personal information in a database. The blockchain infrastructure of Voatz includes 32 identically arranged verifying servers that are distributed across Amazon's AWS and Microsoft's Azure. [12] Each server runs an identical copy of Hyperledger, an open source blockchain software. [13]
Once a user downloads the Voatz app, they verify their phone number, provide a photo ID, as well as a "selfie". Facial recognition and voter rolls are used to verify identity and confirm a match between the picture and ID submitted. After the user is offered a secure token (activated through the use of a fingerprint) applicable to eligible elections, the user's biometric information is removed from the Voatz system. [14] After all votes are submitted to Voatz, votes are printed on a paper ballot and fed into a machine.
The Voatz mobile application offers an interface available to administrators of the election incorporating Voatz. Election officials are able to view ballots, add voters, and publish results if needed. [15] Voatz does not allow voters to interact with the mobile application's blockchain-specific functions. Thus, rather than voters using wallet addresses, tokens, or private keys, voters are able to designate a 6-digit code or use biometric verification as their private key. [15]
From March to May 2018, West Virginia implemented a temporary mobile voting solution for a series of pilot studies that recorded votes for deployed members of the military. [16] Core functionalities included, but were not limited to, the ability to spoil a ballot, post-election audits, and automatic "tabulatable" audits. [13] In order to run the applications, Voatz implemented minimum software and hardware requirements for participants. iPhone users needed to own an iPhone 5s or later with iOS 10+. Android users required a functioning Android OS version 6+ with KNOX support. [13]
In June 2016, Voatz was used to authenticate delegate badges at the 2016 Massachusetts Democratic State Convention. [17] Over 2,000 Democratic leaders and elected officials from Massachusetts traveled to Lowell for the party's state convention. [18] Voatz created a QR code for each delegate on a list provided by the Massachusetts Democratic Party. Before being able to vote, every delegate was required to verify their identity through the Voatz app's photo recognition. Voatz was used at the Massachusetts Democratic State Convention alongside a paper ballot. Veronica Martinez, executive director for the Massachusetts Democratic Party, reported that the party intends to use Voatz in the future. [19] Photo comparison and identification were additional ballot-specific identity features tested. Once voters scanned their QR code and cast their vote — all while using the same device — voters could use their device to take a picture with them in it. Every time a voter used another station or device in order to vote, the voter would take another picture of themselves and compare it to the first picture they took of themselves. [15]
At Tufts University in Medford, Massachusetts, Voatz was used to assist in the Tufts Community Union (TCU) Senate election. The Tufts Registrar created a list of students in order for Voatz to create QR codes for every student. The QR codes were sent to student emails on the day of the election. [20] Students used their smartphone to scan their Tufts Student ID card in order to verify their identity. [21]
The TCU Senate has continued to use Voatz in every election since 2017. After 2017, the TCU Senate created two options for student voting. The first option is to vote online. Tufts students may download the Voatz app, which can only be downloaded by signing up with an official Tufts email address. Tufts students can also check their email for a security key and vote on the Voatz Lite Web Portal. Alternatively, students can vote in person. On the day of elections, students can arrive to a designated campus center with the security key sent to their email. There, they can vote using Voatz tablets provided by Voatz representatives who are there to assist and answer questions. [22]
In October 2020, a Utah resident became the first person to cast a vote for president in a U.S. general election via a blockchain-based voting app on a personal cellphone, according to Fox News. [23] GovTech reported that the vote in question was submitted in Utah County with the Voatz app, which has been piloted in a number of states, including West Virginia, Colorado and Oregon. Utah was the first state to hold a live demonstration of how Voatz ballots can be audited...Utah County started utilizing Voatz in 2019 to give military voters a more secure voting option than email. The county eventually allowed voters with disabilities to use the app in a local election. [24]
According to CNN Philippines, of 669 volunteers, 348 voted on mobile, website, and assisted kiosks for two days for a 52.01% turnout. CNN quoted Comelec Director for Overseas Voting Bea Wee-Lozada, ″This looks promising because traditionally, we never go beyond 50% when it comes to voters who actually voted for overseas voting.″ [25]
Voatz makes revenue from operating elections that use its technology. In 2018, a $2.2 million investment [26] by Overstock — an American internet retailer —was made in order to further Overstock's vision of bringing Voatz to election season [27] and to also rebrand Overstock as a financial technology company. [28] Overstock's blockchain subsidiary — Medici Ventures — invests in several sectors: Payments & Banking, Capital Markets, Identity, Property Management, Supply Chain, and Voting. Medici Ventures has invested in 19 blockchain firms including Voatz. [29]
Voatz has received criticism from several security experts. Josh Benaloh, senior cryptographer at Microsoft Research, argues that Voatz's scheme is insecure and over complicated, stating that "blockchains just don't help". [30] Ron Rivest, a professor of computer science at the Massachusetts Institute of Technology, supported Benaloh's conclusion regarding the privacy properties of mobile voting solutions in general, stating that "It could be that the program on your computer is secretly shipping your information off to a government agency and telling them how you voted." [30]
In 2020, a security assessment was released by the security auditing firm Trail of Bits (co-founded by Alexander Sotirov). 48 technical issues were reported (plus 31 threat model findings for a total of 79 findings), a third of which were rated 'high severity.' [9] 8 of the 48 technical issues were addressed. [9] The report also confirmed security issues reported earlier by MIT researchers, [7] despite Voatz's denial. [8]
In 2018, it was reported that there had been an attempted intrusion into the West Virginia military voting system by an unknown source. In relation to the attack, the FBI is investigating students from the University of Michigan [31] enrolled in EECS 498–009, [32] an Electrical Engineering special topic course at the University of Michigan. The course description states its objective is to "provide a deep examination of the past, present, and future of elections, informed by perspectives from computer security, tech policy, human factors, and more." [32] According to Alex Warner, West Virginia's Secretary of State, in a press conference on October 1, 2019, "the IP addresses from which the attempts were made have been turned over to the FBI for investigation. The investigation will determine if crimes were committed." [6] A CNN report [33] on October 4, 2019, reported that Mike Stuart, the U.S. Attorney for the Southern District of West Virginia, was informed that the IP addresses in the investigation matched the IP addresses for the University of Michigan.
It was revealed in October 2019 that the Federal Bureau of Investigation (FBI) had launched an investigation into the attempt to hack Voatz during the 2018 midterm elections. [33] Computer science students at the University of Michigan may have been involved with the case. [31] FBI investigators are speculating that the motive behind the attempted hack into the Voatz app may have been for a class assignment, rather than to alter votes.
Electronic voting is voting that uses electronic means to either aid or take care of casting and counting ballots.
Electoral fraud, sometimes referred to as election manipulation, voter fraud or vote rigging, involves illegal interference with the process of an election, either by increasing the vote share of a favored candidate, depressing the vote share of rival candidates, or both. It differs from but often goes hand-in-hand with voter suppression. What exactly constitutes electoral fraud varies from country to country.
An electronic voting machine is a voting machine based on electronics. Two main technologies exist: optical scanning and direct recording (DRE).
Vote counting is the process of counting votes in an election. It can be done manually or by machines. In the United States, the compilation of election returns and validation of the outcome that forms the basis of the official results is called canvassing.
Barbara Bluestein Simons is an American computer scientist and the former president of the Association for Computing Machinery (ACM). She is a Ph.D. graduate of the University of California, Berkeley and spent her early career working as an IBM researcher. She is the founder and former co-chair of USACM, the ACM U.S. Public Policy Council. Her main areas of research are compiler optimization, scheduling theory and algorithm analysis and design.
An absentee ballot is a vote cast by someone who is unable or unwilling to attend the official polling station to which the voter is normally allocated. Methods include voting at a different location, postal voting, proxy voting and online voting. Increasing the ease of access to absentee ballots is seen by many as one way to improve voter turnout through convenience voting, though some countries require that a valid reason, such as infirmity or travel, be given before a voter can participate in an absentee ballot. Early voting overlaps with absentee voting. Early voting includes votes cast before the official election day(s), by mail, online or in-person at voting centers which are open for the purpose. Some places call early in-person voting a form of "absentee" voting, since voters are absent from the polling place on election day.
Voter verifiable paper audit trail (VVPAT) or verified paper record (VPR) is a method of providing feedback to voters using a ballotless voting system. A VVPAT is intended as an independent verification system for voting machines designed to allow voters to verify that their vote was cast correctly, to detect possible election fraud or malfunction, and to provide a means to audit the stored electronic results. It contains the name of the candidate and symbol of the party/individual candidate. While it has gained in use in the United States compared with ballotless voting systems without it, it looks unlikely to overtake hand-marked ballots.
Electronic voting in Estonia gained popularity in 2001 with the "e-minded" coalition government. In 2005, it became the first nation to hold legally binding general elections over the Internet with their pilot project for municipal elections. Estonian election officials declared the electronic voting system a success and found that it withstood the test of real-world use.
Patrick Michael Byrne is an American businessman. In 1999, Byrne launched Overstock.com after leading two smaller companies. Byrne led Overstock as chief executive officer for two decades, from 1999 to 2019. In 2002, Byrne took Overstock public. Early in his tenure he attracted public attention for a long-running legal battle against short sellers and "naked short selling." He eventually resigned as CEO in August 2019, following revelations that he had been in an intimate relationship with Russian agent Maria Butina.
End-to-end auditable or end-to-end voter verifiable (E2E) systems are voting systems with stringent integrity properties and strong tamper resistance. E2E systems often employ cryptographic methods to craft receipts that allow voters to verify that their votes were counted as cast, without revealing which candidates were voted for. As such, these systems are sometimes referred to as receipt-based systems.
The Voluntary Voting System Guidelines (VVSG) are guidelines adopted by the United States Election Assistance Commission (EAC) for the certification of voting systems. The National Institute of Standards and Technology's Technical Guidelines Development Committee (TGDC) drafts the VVSG and gives them to the EAC in draft form for their adoption.
Electronic voting by country varies and may include voting machines in polling places, centralized tallying of paper ballots, and internet voting. Many countries use centralized tallying. Some also use electronic voting machines in polling places. Very few use internet voting. Several countries have tried electronic approaches and stopped, because of difficulties or concerns about security and reliability.
A risk-limiting audit (RLA) is a post-election tabulation auditing procedure which can limit the risk that the reported outcome in an election contest is incorrect. It generally involves (1) storing voter-verified paper ballots securely until they can be checked, and (2) manually examining a statistical sample of the paper ballots until enough evidence is gathered to meet the risk limit.
Politics and technology encompasses concepts, mechanisms, personalities, efforts, and social movements that include, but are not necessarily limited to, the Internet and other information and communication technologies (ICTs). Scholars have begun to explore how internet technologies influence political communication and participation, especially in terms of what is known as the public sphere.
An election audit is any review conducted after polls close for the purpose of determining whether the votes were counted accurately or whether proper procedures were followed, or both.
The Verified Voting Foundation is a non-governmental, nonpartisan organization founded in 2004 by David L. Dill, a computer scientist from Stanford University, focused on how technology impacts the administration of US elections. The organization’s mission is to “strengthen democracy for all voters by promoting the responsible use of technology in elections.” Verified Voting works with election officials, elected leaders, and other policymakers who are responsible for managing local and state election systems to mitigate the risks associated with novel voting technologies.
Election cybersecurity or election security refers to the protection of elections and voting infrastructure from cyberattack or cyber threat – including the tampering with or infiltration of voting machines and equipment, election office networks and practices, and voter registration databases.
Helios Voting is an open-source, web-based electronic voting system. Users can vote in elections and users can create elections. Anyone can cast a ballot; however, for the final vote to be counted, the voter's identification must be verified. Helios uses homomorphic encryption to ensure ballot secrecy.
VR Systems is a provider of elections technology systems and software. VR Systems is based in Tallahassee, Florida. The company's products are used in elections in eight U.S. states. The company was founded in 1992 by Jane and David Watson. The CEO and President is Mindy Perkins.
Electronic voting in the United States involves several types of machines: touchscreens for voters to mark choices, scanners to read paper ballots, scanners to verify signatures on envelopes of absentee ballots, and web servers to display tallies to the public. Aside from voting, there are also computer systems to maintain voter registrations and display these electoral rolls to polling place staff.