News: 1599181991

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Surprise! Voting app maker roasted by computer boffins for poor security now begs US courts to limit flaw finding

(2020/09/04)


Voatz, the maker of a blockchain-based mobile election voting app [1]pilloried for poor security earlier this year, has urged the US Supreme Court not to change the 1986 Computer Fraud and Abuse Act (CFAA), a law that critics say inhibits security research because it's overly broad.

The app maker filed an amicus brief

[2]PDF

on Thursday in Van Buren v. United States in support of the US government, which seeks to uphold the 2017 conviction of former Georgia police officer Nathan Van Buren under the CFAA.

Van Buren was convicted of violating the CFAA for conducting a computer search for a license plate number. Although he was authorized to access the police database as part of his job, he offered to [3]look up license plates for a stripper in exchange for cash. The exotic dancer went to the Feds, who busted him in a sting operation: for a fee, he ran a plate on someone the stripper described as an undercover cop investigating her for prostitution. The license was a fake, and Van Buren was collared.

While his actions were alleged to have violated other laws related to wire fraud, to say nothing of workplace ethics, his conviction under the CFAA is what has alarmed computer security pros and cyber liberties advocates.

"Under this expansive interpretation of the CFAA, it would be a federal crime any time a person violates a website's terms of service," the EFF [4]said in its summary of the case. "If violating terms of service is a crime, private companies get to decide who goes to prison and for what, putting us all at risk for everyday online behavior."

And it's easy to see how problems might arise from the vagueness of the law's language. The US Department of Justice's own guidelines on prosecuting computer crimes

[5]PDF

acknowledge that, "The term 'without authorization' is not defined by the CFAA."

And their interest is...

Voatz, as a private company, wants to be able to fill in the blanks and decide who can interact with its systems and in what capacity.

Coincidentally, its app was slammed in February by computer scientists for [6]a variety of security flaws . And it cites that uninvited scrutiny by MIT's computer scientists in its filing as an example of the problematic nature of unauthorized security inquiry.

These are roughly the last people I would go to for advice on what would "harm computer security". More of an inimicus brief if you ask me. — matt blaze (@mattblaze) [7]September 3, 2020

"Voatz’s own security experience provides a helpful illustration of the benefits of authorized security research, and also shows how unauthorized research and public dissemination of unvalidated or theoretical security vulnerabilities can actually cause harmful effects," the company's filing says, even as it insists the MIT researchers found no meaningful flaws.

In opposition to the arguments advanced by the Electronic Frontier Foundation and other organizations including security firms that support narrowing the CFAA, Voatz contends unauthorized, independent research should not be exempted from the law.

CFAA latest: Supremes to tackle old chestnut of what 'authorized use' of a computer really means in America [8]READ MORE

"Rather, the necessary research and testing can be performed by authorized parties," the firm's brief says.

Voatz goes on to argue that allowing security researchers to violate rules and policies upends the expectations of companies setting those policies, as if their words should be law.

The company says that just as people can be prosecuted for trespassing on physical property, they should be subject to punishment for breaking terms of service rules under the CFAA, an analogy that fails to appreciate that trespassing isn't likely to result in a sentence of several years in prison.

In an email to The Register , Daniel Weitzner, Founding Director of the MIT Internet Policy Research Initiative, and one of the three authors of the Voatz app analysis

[9]PDF

, opposed the idea of letting companies criminalize security testing in their terms of service.

"The vagueness and potential breadth of the Computer Fraud and Abuse Act made it considerably more difficult for us to conduct our security analysis," said Weitzner.

"Allowing tech companies to threaten criminal action for violations of policies that the companies write themselves places independent research in constant jeopardy. And without independent research, there is no basis for the public to trust the safety or security of these systems." ®

Get our [10]Tech Resources



[1] https://www.theregister.com/2020/02/13/voatz_mit_election_app/

[2] https://www.supremecourt.gov/DocketPDF/19/19-783/153062/20200903122434600_Voatz%20Amicus%20Brief.pdf

[3] https://www.theregister.com/2020/04/20/supreme_court_cfaa/

[4] https://www.eff.org/cases/van-buren-v-united-states

[5] https://www.justice.gov/sites/default/files/criminal-ccips/legacy/2015/01/14/ccmanual.pdf

[6] https://www.theregister.com/2020/02/13/voatz_mit_election_app/

[7] https://twitter.com/mattblaze/status/1301589959103713281?ref_src=twsrc%5Etfw

[8] https://www.theregister.com/2020/04/20/supreme_court_cfaa/

[9] https://internetpolicy.mit.edu/wp-content/uploads/2020/02/SecurityAnalysisOfVoatz_Public.pdf

[10] https://whitepapers.theregister.com/

Voatz meet the Streisand Effect.

Anonymous Coward

In California at least the changes you want may be thwarted by a simple Anti-SLAPP suit. That's a Strategic Lawsuit Against Public Participation.

Security researchers discussing your products security or lack thereof is the very definition of that Public Participation part. Not to mention their 1st Amendment Rights to discuss what a shitty company you're being for trying to stop them from publicly discussing your abysmal security.

And the harder you try to bury the truth the more the internet will keep bringing it to the front of searches on what all the fuss is about.

"What's this Voatz thing? Oh wow. They wrote a program with such shitty security it took a team of security pros less time to get in than it takes to get into a hookers knickers!"

Re: Voatz meet the Streisand Effect.

doublelayer

Ah, but it's not the discussion that they mind. If people investigate a system to find that it's a hideous mass of holes, they're violating the trust of the organization that put out the hideous mass of holes. It's important that we respect the rights of places that don't bother doing their own security testing and choose to use untrustworthy and unsafe code to store and process our information to make money. More than that, we must protect those who don't want to bother making good products from people who shamelessly figure out whether something will become a safety risk and, these people have no scruples, have the gall to tell the public about it after they tell the company who doesn't fix it. Consider how you would feel if someone researched the safety of cars and told people about the ones that blow up so you couldn't purchase one of those. Consider how you would feel if there was someone with the audacity to check if the claims of other product's advertisements were true and call out the selfless manufacturers when they were found to be lying through their teeth. These people must be stopped today.

Real Life Superhero's

Anonymous Coward

In my book security researchers/reverse engineers are like real-life modern day Superhero's.

They are the only ones that keep people safe and secure and in some cases can even save lives by exposing flaws and sh*tty security practices in todays internet connected world.

I also believe that overly broad and expansive terms and conditions that threaten users about reverse engineering their sh*tty app is usually in place because the developer has either baked in some kind of spyware/malware or has some really sh*tty security/privacy they are trying to hide (like the app in the article).

I am sure there are many that would disagree with me and would glady support laws that limit securty researchers like say, DLink, Lenovo, Cisco, Linksys, Microsoft etc etc....

There are many great Hero's out there protecting lives like: Citizen Lab, Kaspersky Labs, SandboxEscaper, etc etc

With the horrific state of our nations politics ALL voting apps should be completely open-source.

/rant

Security of voting machines

DS999

Is hardly the biggest problem with voting in the US. If you have a paper trail for every vote then I say who cares if the software running the machines is open source. Just have a requirement to conduct random hand recounts of a statistically significant percentage to verify the totals and you know the machines are counting accurately.

The real problem that needs to be fixed is access to the polls. In Georgia in 2018 the republican secretary of state, who is by law responsible for the election, was running for governor. He used his authority as SOS to order the closing of a bunch of polling places in majority black precincts. As a result, the average wait time to vote in majority white precincts was 6 minutes. The average wait time to vote in majority black precincts was 51 minutes. That is what voter suppression looks like, and is a far greater concern that whether source code for the election machines is publicly available.

"Those who believe in astrology are living in houses with foundations of
Silly Putty."
-- Dennis Rawlins, astronomer