Blog · IT scandals · Security

He reported a flaw in Buenos Aires's e-voting system. Two days before the election, police raided his home

In 2015, a programmer told the vendor that he had found a vulnerability in the City of Buenos Aires's Boleta Única Electrónica (single electronic ballot) system. On the night of Friday, July 3, two days before the election, police raided his home and took his computers. In 2016, the prosecutor's office recommended dismissing the case against him. The case shows what happens when the person who reports a flaw ends up treated like an attacker.

Boleta Única Electrónica voting machine
Boleta Única Electrónica voting machine. Cropped to 16:9. Photo: Defensoría del Pueblo de la Ciudad de Buenos Aires · CC BY-SA 4.0 · Wikimedia Commons

What happened

About ten days before the city election, the programmer found a flaw in how results were sent from the schools used as polling places to the vote-counting center, and alerted the company in charge of the system, Grupo MSA. According to his account, the SSL certificates of the terminals that sent that data had leaked and weren't password-protected. With them, he explained, someone could send fake results or overload the system.

Acting on a criminal complaint, a judge ordered the search. The Cybercrime Division of the Policía Metropolitana (Buenos Aires city police) entered his home on the night of Friday, July 3, 2015, and took computers, e-book readers and memory drives. He was accused of computer damage. Eight months later, according to ANCCOM, a University of Buenos Aires news agency, his devices were still held in judicial storage.

In August 2016, the prosecutor's office recommended dismissing the case and noted that his actions had exposed a system that could be easily breached.

What's the broader lesson?

When an organization answers a warning with a criminal complaint, everyone else gets a clear message: the next person who finds a flaw won't report it. The vulnerability is still there; the only thing that changes is who finds out first.

At the time, Fundación Vía Libre, an Argentine digital rights organization, criticized the courts for going after the messenger instead of those responsible for securing the system. Around the same time, the foundation and other computer specialists also showed how to write several votes onto a ballot's chip with a cell phone. The programmer later said the raid seemed designed to intimidate people looking for vulnerabilities.

Sources

  1. Notimérica, 7/4/2015
  2. Primera Fuente
  3. ANCCOM (UBA)

Consulting: technical leadership →

← Back to the blog