Electronic voting in Estonia explained

Electronic voting in Estonia gained popularity in 2001 with the "e-minded" coalition government. In 2005, it became the first nation to hold legally binding general elections over the Internet with their pilot project for municipal elections.[1] Estonian election officials declared the electronic voting system a success and found that it withstood the test of real-world use.[2]

Internet voting was also used in the 2007 Estonian parliamentary election, another world first.[3] In 2023 parliamentary elections for the first time more than half of the total votes were cast over the internet.[4]

Internet voting

The term Power voting (or e-voting) can refer to both fixed voting locations (as in voting booths) and remote (as in over the Internet) electronic voting. To reduce confusion between the two, electronic voting is known as i-Voting in Estonia. The security model is modeled after the way in which advance voting and postal voting is handled.[5]

Overview of Estonian internet voting

See also: Estonian ID card. The Estonian internet voting system builds on the Estonian ID card. The card is a regular and mandatory[6] national identity document as well as a smart card, allowing for both secure remote authentication and legally binding digital signatures using the Estonian state supported public key infrastructure.[7] As of March 2007, over 1.08 million cards have been issued (out of the Estonian population of 1.32 million).[8]

Internet voting is available during an early voting period (four to six days prior to Election Day). Voters can change their electronic votes an unlimited number of times, with the final vote being tabulated. Anyone who votes using the Internet can vote at a polling station during the early voting period, invalidating their Internet vote. It is possible to change the electronic vote on Election Day since 2021.[9] Votes are counted on Election Day after polling stations are closed and storage media containing the votes are physically destroyed after all election complaints are resolved at least one month after elections.

A cost-efficiency comparison of the different voting channels offered in the Estonian Municipal Elections (2017) concluded that Internet voting is the most cost-efficient voting channel offered by the Estonian electoral system.

The principle of "one person, one vote" is maintained, as the voter is able to cast more than one ballot, but only one vote is ultimately recorded. This assertion was challenged in August 2005 by Arnold Rüütel, then President of Estonia, who saw the new e-voting provisions in the Local Government Council Election Act as a breach of the principle of equality of voting. The President petitioned against the e-voting provisions to the Supreme Court of Estonia but lost.[10]

Transparency and verifiability

According to the recommendations of OSCE/ODIHR election observers, and because of a voting client hacking case brought to the Supreme Court in 2011, Estonia implemented vote verification for individual voters in 2013. Voters verify their ballots by using a smartphone application which uses a QR code displayed by the desktop voting client to display the candidate for whom the vote was cast. Individual verification verifies that the vote cast was stored on the vote collection server for not more than either 30 or 60 minutes, depending on the election. The voter cannot directly verify that the vote was also tallied as cast.

The voting system's serverside source code was published in June 2013 because of social pressure initiated by Tanel Tammet, a computer scientist who coauthored research papers from 2001 on electronic voting requirements. The source code was published on GitHub and has been available for all subsequent elections. Neither the voting client's source code nor the reference code have been published, as election officials have determined that this would allow malicious actors to build fake voting clients. Because the voting protocol is public, anyone can build a voting client.

In 2015, extensive reports from OSCE/ODIHR election observers and an independent observing team led by J Alex Halderman in 2015, as well as public pressure from local activists, motivated the implementation of universal vote tally verifiability in 2017. Tally verification is done by mixnet, making use of homomorphic properties and elGamal encryption provided by Douglas Wikström. Universal tally verification is not a mandatory part of the process, and is conducted by a dedicated data auditor. Tallying the votes with mixnet is done in parallel with plain text extraction of the votes from encrypted envelopes, which are decrypted using the voting commission's secret key and from which the digital signatures of voters are removed.

Although a white paper on Estonia's 2017-2019 implementation of its electronic voting system claims that the system permits end-to-end verifiability, this has been denied by independent researchers.[11] A working group was formed by Minister of Foreign Trade and Information Technology Kert Kingo in order to assess the "verifiability, security and transparency" of electronic voting. The group produced a report consisting of 25 improvement proposals, of which proposals 11, 13 and 25 pertain to the system's problems with verifiability.[12] The government coalition agreement also asserts the need for independent international auditing of the system.

Criticism

Despite praise from Estonian election officials, computer security experts from outside the country who have reviewed the system have criticized it, warning that any voting system that transmits ballots electronically cannot be secure.[13] This criticism was underscored in May 2014, when a team of international computer security experts released their examination of the system, claiming they could breach the system, change votes and vote totals, and erase all evidence of their actions if they were to install malware on Estonian election servers.[14] The team advised the Estonian government to halt all online voting because of the potential threats that it posed to their government.

The Estonian National Electoral Committee reviewed the concerns and published a response, saying that the claims "give us no reason to suspend online balloting". The purported vulnerabilities were said to be either infeasible in reality or already accounted for in the design of the e-voting system.[15] The Estonian Information System Authority also responded to the claims, describing them as a political, rather than technical, attack on the e-voting system, and criticizing the method of disclosure.[16] The researchers' connection to the Estonian Centre Party, which has long been critical of e-voting, has also been a common speculation among Estonian state officials and has been even suggested by a prime minister.[17] [18] [19]

The main author of a white paper on Estonian electronic voting from 2001,,[20] has been critical of the system, and uses paper ballots to cast his own votes.[21] The main author of the second white paper on Estonian electronic voting from 2001, Tanel Tammet,[22] has been campaigning for the opening of the system's source code and for the implementation of independent parallel systems to guarantee trust in the e-voting system.[23] [24] The serverside code was published under the Creative Commons BY-NC-ND license on GitHub as a result of those efforts in July 2013.[25]

The OSCE/ODIHR election observation mission has voiced concerns about Estonian e-voting during every parliament election, initially proposing in 2007 that e-voting be suspended if its problems remain unaddressed,[26] then suggesting in 2011 that the election commission should create an inclusive working group for improving e-voting and that cryptographic measures should be implemented to ensure that voting is observable[27] [28] and noting that the verification features implemented for the 2015 elections only partially address their previous recommendations.[29]

In a 2012 overview of international e-voting implementations, IFES independent researchers found that, although insofar successful, in situation of "emerging international electoral standards with respect to Internet voting" Estonian voting system faces necessary improvements for "better legislation, a transparent policy and formalized procedures" as well as "broader democratic goals, such as enhancing civic e-participation" need to be considered.[30]

In 2013 Free Software Foundation Europe criticized partial publishing of the source code of e-voting system and for using non-software licenses for publication. FSFE also suggests researching into solutions that lessen reliance on system administrators and instead build the system on cryptographic models of trust. Since the weakest part of voting infrastructure is voter's computer, FSFE suggests Estonia should mitigate the risks of unnoticed subversion of votes in compromised client machines and "publicise the dangers as widely as possible, along with instructions to minimise the risk and rectify the situation should a risk realise".[31]

There have been also attempts to expose problems of voting system by proofs of concept. In 2011 Paavo Pihelgas created a trojan that was theoretically able to change voter's choice without user noticing. He used this as basis for filing an election complaint and demanded that Supreme Court invalidates election results. The court dismissed the case because Pihelgas's "voter's rights had not been infringed as long as he had knowingly put himself into the situation".[32] [33]

In 2015, an activist from the Estonian Pirate Party, Märt Põder, took credit for casting an invalid ballot "using a GNU debugger to locate the breakpoint in Linux IVCA where the candidate number is stored and replace it with an invalid candidate number".[34] Being only one among 176,491 e-voters to do it, the activist explained to the media that client application source code should be opened up and taught as part of general education in public schools to make people trust e-voting.[35] Later negotiating with electoral commission, an activist went on to stress that end-to-end verifiability is a prerequisite for reliable e-voting, and that the whole process of planning, procuring and implementing e-voting should be conducted in English as well, which opens up to the international community for proper scrutiny.[36] [37]

In 2016, computer scientists at the University of Oxford, while acknowledging relative success of conducting e-voting, they claimed that e-voting system officials "have relied since the system's inception on building trust through interpersonal relations," and that "may work well for a close-knit society such as that of Estonia". However, "informal processes (including lessons learned) should be further clarified and formally documented".[38]

In beginning of June 2019, Kert Kingo, Minister of Foreign Trade and Information Technology of the newly elected government created an inclusive working group to assess the "verifiability, security and transparency"[39] [40] of the Estonian electronic voting system. The working group consisted of state officials, representatives from universities and research institutes, critics, and creators of the system.[41] [42] In December 2019 they presented results of the six-month investigation, with 25 proposals for improving the core infrastructure of the Estonian e-voting system.[43]

History

2023 elections

With 312,181 electronic votes, these were the first elections in history where more than half of the votes (51.1%) were cast online.[44]

After the publication of the e-vote results, Martin Helme, the leader of EKRE, stated that "he does not trust the e-vote results" and demanded a recount.[45]

2019 elections

In the 2019 parliamentary elections, 247,232 people, or 43.8% of all participants, voted over the Internet.[46]

In the European Parliamentelections, 155,521 people voted over the Internet. This means that roughly 46.7% of participating voters gave their vote over the Internet.[47]

2017 elections

In the 2017 local municipal elections, 186,034 people voted over the Internet. This means that roughly 31.7% of participating voters gave their vote over the Internet.[48]

2015 elections

In the 2015 parliamentary elections, 176,491 people, 30.5% of all participants, voted over the Internet.[49]

2014 elections

In the European Parliament elections, 103,151 people voted over the Internet. This means that roughly 31.3% of participating voters gave their vote over the Internet.[49]

2013 elections

In the 2013 local municipal elections, 133,808 people voted over the Internet.[50] This means that roughly 21.2% of participating voters gave their vote over the Internet.[49] It was also the first election where vote verification with mobile device was implemented.[51]

2011 elections

In the 2011 parliamentary elections, 140,846 people voted over the Internet. This means that roughly 15.4% of the persons with the right to vote and 24.3% of participating voters gave their vote over the Internet.[49] It was also the first election to allow for voting through chip-secure mobile phones, following a law approved by Parliament in 2008.[52]

2009 elections

In the 2009 local municipal elections, 104,415 people voted over the Internet.[53] This means that roughly 9.5% of the persons with the right to vote gave their vote over the Internet.[54]

In the European Parliamentelections, 58,669 people voted over the Internet. This means that roughly 14.7% of participating voters gave their vote over the Internet.[49]

2007 elections

In 2007 Estonia held its and the world's first general elections with Internet voting available from February 26 to 28. A total of 30,275 citizens used Internet voting (3.4%), which means for every 30 eligible voters one of them voted through the Internet.[55]

2005 elections

In 2005 Estonia became the first country to offer Internet voting nationally in local elections.[56] 9,317 people voted online (1.9%).

Further reading

Notes and References

  1. News: BBC NEWS Europe Estonia forges ahead with e-vote. news.bbc.co.uk. 2017-01-29. 2005-10-14.
  2. http://www.vvk.ee/index.php?id=11509 Reports and Statistics about Internet Voting in Estonia
  3. https://archive.today/20120713191050/http://news.com.com/Estonia+to+hold+first+national+Internet+election/2100-1028_3-6161005.html Estonia to hold first national Internet election
  4. News: Estonia sets new e-voting record at Riigikogu 2023 elections . . 6 March 2023 . 31 March 2023.
  5. Web site: Archived copy . 2010-01-07 . http://veebiarhiiv.digar.ee/a/20101118111444/http%3A//www.vvk.ee/public/dok/Internet_Voting_in_Estonia.pdf . 2010-11-18 . dead.
  6. Web site: Isikut tõendavate dokumentide seadus – Riigi Teataja.
  7. http://www.pass.ee/index.php/pass/eng/id_card What is the ID card?
  8. http://www.id.ee/?lang=en ID Card Issuing Statistics info-box at the top of the page
  9. Web site: E-votes can be canceled by voting at polling stations on election day . 5 October 2021 .
  10. Web site: Judgment of the Constitutional Review Chamber of the Supreme Court, Case No. 3-4-1-13-05 . 2007-01-15 . 2011-07-20 . https://web.archive.org/web/20110720125506/http://www.nc.ee/?id=381 . dead .
  11. Web site: A framework for comparing the security of voting schemes. Juvonen. Atte. October 1, 2019. Blog of Atte Juvonen. 79. May 28, 2020.
  12. Web site: E-valimiste turvalisuse töörühma koondaruanne. December 12, 2019. Ministry of Economic Affairs and Communications. May 28, 2020.
  13. "Report on the Estonian Internet voting system," Sept. 3, 2011. https://www.verifiedvoting.org/report-on-the-estonian-internet-voting-system-2/
  14. "Independent Report on E-voting in Estonia," https://estoniaevoting.org/
  15. http://vvk.ee/valimiste-korraldamine/vvk-uudised/vabariigi-valimiskomisjoni-vastulause-the-guardianis-ilmunud-artiklile Comment on the article published in The Guardian
  16. https://www.ria.ee/en/e-voting-is-too-secure.html E-voting is (too) secure
  17. http://estonianworld.com/security/attacks-estonias-e-voting-political-rather-technical Attacks on Estonia's e-voting are political rather than technical
  18. https://www.youtube.com/watch?v=JY_pHvhE4os&t=46m41s Security Analysis of Estonia's Internet Voting System [31c3] by J. Alex Halderman]
  19. http://www.baltictimes.com/estonia_e-votes_despite_cyber_security_concerns/ "The criticism made headlines in the international media, receiving coverage from The Guardian and the BBC. This led to a public debate between Alex Halderman and the Estonian authorities. According to Professor Robert Krimmer, the report had many valid points, although the assessment of the impact could be debated. The results of the debate, in terms of immediate consequences, was limited, however."
  20. Web site: E-valimiste realiseerimisvõimaluste analüüs . 2016-09-30 . 2015-06-29 . https://web.archive.org/web/20150629200701/http://www.vvk.ee/public/dok/lipmaamyrk.pdf . dead .
  21. https://helger.wordpress.com/2011/03/05/paper-voted-and-why-i-did-so/ Paper-voted (and why I did so)
  22. Web site: E-valimised Eesti Vabariigis: võimaluste analüüs . 2016-09-30 . 2015-06-29 . https://web.archive.org/web/20150629224127/http://www.vvk.ee/public/dok/evalimisteanalyys24okt.doc . dead .
  23. http://www.praxis.ee/wp-content/uploads/2014/03/2003-E-valimiste-voimalikud-tehnoloogilised-platvormid.pdf E-valimiste võimalikud tehnoloogilised platvormid
  24. https://www.facebook.com/evalimised/about/ Teeme ära avaliku e-valimiste kontrolli, kõik huvilised turvaspetsid oodatud kaasa lööma!
  25. http://news.err.ee/v/news/scitech/940d2015-ffe1-4c9f-98e8-6fc60935fa0c/release-of-e-election-software-code-did-not-go-far-enough Release of E-Election Software Code 'Did Not Go Far Enough'
  26. http://www.osce.org/odihr/elections/estonia/25925 "Yet, unless the above-mentioned factors are effectively addressed, the authorities should reconsider whether the internet should be widely available as a voting method, or alternatively whether it should be used only on a limited basis or at all."
  27. http://www.osce.org/odihr/77557 "In recent years, advances have been made in the field of cryptography to enable end-to-end verification of the votes cast, i.e. a possibility for an individual voter to verify that his/her vote was (i) cast as intended, (ii) recorded as cast, and (iii) counted as recorded. /—/ Estonia's Internet voting system does not employ such tools. /—/ The OSCE/ODIHR recommends that the NEC forms an inclusive working group to consider the use of a verifiable Internet voting scheme or an equally reliable mechanism for the voter to check whether or not his/her vote was changed by malicious software."
  28. Heiberg. Sven. Willemson. Jan. 2014. Verifiable internet voting in Estonia. IEEE Conference Publications. 2014 6th International Conference on Electronic Voting: Verifying the Vote (EVOTE). 1–8.
  29. http://www.osce.org/odihr/elections/estonia/160131 "The NEC introduced a verification process for voters to confirm that their online vote was cast as intended and recorded on the ballot storage server as cast, which partially addressed an OSCE/ODIHR recommendation."
  30. https://www.parliament.uk/documents/speaker/digital-democracy/IFESIVreport.pdf International Experience with E-Voting
  31. Web site: Open Letter on Freedom and Internet Voting to Estonia's National Electoral Committee . 2016-09-30 . 2016-10-02 . https://web.archive.org/web/20161002112847/https://fsfe.org/ee/i-voting/2013-07-26_Open_Letter_to_NEC.html . dead .
  32. https://edri.org/edrigramnumber9-11e-voting-osce-estonia/ OSCE findings on Estonian e-voting
  33. https://www.riigikohus.ee/en/constitutional-judgment-3-4-1-4-11
  34. Heiberg. Sven. Parsovs. Arnis. Willemson. Jan. 2015. Log Analysis of Estonian Internet Voting 2013--2015, section 5.24.1. An activist from the Estonian Pirate Party took credit for casting the spoiled ballot [18]. The technique employed involved using a GNU debugger to locate the breakpoint in Linux IVCA where the candidate number is stored and replace it with an invalid candidate number.
  35. Web site: Kuidas ma e-valimisi otsast natuke häkkisin . 2017-09-20 . 2016-07-14 . https://web.archive.org/web/20160714103726/http://boamaod.github.io/blog/2015/03/02/minu-evalimised/ . dead .
  36. https://www.facebook.com/boamaod/posts/10200428572913123 Püüan nüüd aktivistina olla läbipaistvuse osas riigile eeskujuks ja annan teada, et käisin neljapäeval Vabariigi Valimiskomisjonis vestlusel
  37. Web site: Vaadeldamatu e-hääletus pole usaldusväärne . 2017-09-20 . 2016-02-16 . https://web.archive.org/web/20160216094709/http://boamaod.github.io/blog/2015/03/30/rohkem-kryptot-v2hem-usaldust/ . dead .
  38. Web site: An Independent Assessment of the Procedural Components of the Estonian Internet Voting System . 2017-04-29 . 2016-10-11 . https://web.archive.org/web/20161011122854/http://www.politics.ox.ac.uk/materials/publications/15483/workingpaperno6nurse.pdf . dead .
  39. Web site: Kinnitati e-valimiste töörühma koosseis. 21 June 2019. Ministry of Economic Affairs and Communications. 27 June 2019. 27 June 2019. https://web.archive.org/web/20190627133420/https://www.mkm.ee/et/uudised/valiskaubandus-ja-it-minister-kutsub-kokku-elektroonilise-valimissusteemi-ja-elektroonilise. dead.
  40. Web site: Väliskaubandus- ja IT-minister kutsub kokku elektroonilise valimissüsteemi ja elektroonilise hääletamise töörühma. 7 June 2019. Ministry of Economic Affairs and Communications. 27 June 2019. 27 June 2019. https://web.archive.org/web/20190627133420/https://www.mkm.ee/et/uudised/valiskaubandus-ja-it-minister-kutsub-kokku-elektroonilise-valimissusteemi-ja-elektroonilise. dead.
  41. Web site: E-voting creator: the system is bulletproof. Punamäe. Sander. 26 June 2019. Postimees.
  42. Web site: Estonian e-voting creator deems formation of working group political statement. 2019-06-26. The Baltic Times.
  43. Web site: E-voting task force finishes report including 25 proposals for improving system . Post Times - Estonian News . Baltic News Service . 2 May 2020 . en . 13 December 2019.
  44. Web site: 6 March 2023 . Online votes make up two-thirds of Reform, less than third of EKRE votes . 6 March 2023 . Eesti Rahvusringhääling . en .
  45. Web site: 5 March 2023 . Riigikogu valimistel on hääle andnud rekordarv inimesi . 5 March 2023 . Postimees . et . 5 March 2023 . https://web.archive.org/web/20230305233505/https://www.postimees.ee/7725235/valimisblogi-riigikogu-valimistel-voidutses-reformierakond . live .
  46. Web site: Voting results in detail.
  47. Web site: Voting results in detail.
  48. Web site: Valimistulemus valdades ja linnades.
  49. Web site: Statistics about Internet Voting in Estonia.
  50. Web site: Statistics about Internet Voting in Estonia.
  51. "Verifiable Internet Voting in Estonia" http://research.cyber.ee/~jan/publ/mobileverification-ieee.pdf
  52. News: Estonia to vote by mobile phone in 2011. USA Today. 2008-12-12 . Jari Tanner, Associated Press.
  53. Web site: E-hääletanute arv tõusis üle 100 000. 2009-10-14. https://web.archive.org/web/20091017112220/http://www.epl.ee/artikkel/480270. 2009-10-17. dead.
  54. Web site: Internet Voting in Estonia.
  55. http://news.bbc.co.uk/2/hi/europe/6407269.stm Estonia claims new e-voting first
  56. https://archive.today/20120713045721/http://news.com.com/Estonia+pulls+off+nationwide+Net+voting/2100-1028_3-5898115.html Estonia pulls off nationwide Net voting