An analysis of the security and privacy issues of the Neovote online voting system

Résumé

This article provides the first security and privacy analysis of the Neovote voting system, which was used for three of the five primaries in the French 2022 presidential election. We show that the demands of transparency, verifiability and security set by French governmental organisations were not met, and propose multiple attacks against the system targeting both the breach of voters’ privacy and the manipulation of the tally. We also show how inconsistencies in the verification system allow the publication of erroneous tallies and document how this arrived in practice during one of the primary elections.

publication: “International Joint Conference on Electronic Voting, E-Vote-ID 2022” url_source: “https://link.springer.com/chapter/10.1007/978-3-031-15911-4_1" url_slides: “slides.pdf”