Modern Australian
The Times

‘Anonymous’ voting software used by some of Australia’s biggest companies is flawed, new investigation reveals

  • Written by Priya Dev, Lecturer, Research School of Finance, Actuarial Studies & Statistics, Australian National University
‘Anonymous’ voting software used by some of Australia’s biggest companies is flawed, new investigation reveals

Secret ballots have long been fundamental to democracy, ensuring the integrity of elections in both government and corporate settings. Traditionally, votes are cast on physical paper, creating a clear separation between the voter’s identity and their choice. This anonymity protects individuals from vote-buying, intimidation or retaliation.

But what happens when the system moves online? Recently the Australian National University opted for an online ballot to decide a contentious vote that could significantly impact staff pay. Staff were assured their vote would be anonymous.

The online voting system used by the university is provided by a company called CorpVote, which says “all votes submitted through our secret ballot process are guaranteed to be anonymous”. The system is also used by some of Australia’s largest organisations, including Woolworths, Coles, Telstra, Westpac, BHP, Bunnings, the Australian Federal Police, the Department of Home Affairs, the Fair Work Commission and the ABC.

We decided to investigate whether the claims about voter anonymity were accurate – and made some troubling discoveries.

A three-step process

The CorpVote website claims:

The only way that a response in any of our ballot or election processes can be identified as coming from you is if you disclose this information yourself.

The CorpVote voting process has three steps.

First, each voter receives a unique “voter access code”, similar to a single-use pass code. The voter enters this code on the CorpVote website, along with their employee number. The code and employee number are sent to a CorpVote server to verify the voter’s identity.

Second, once CorpVote verifies a voter’s identity, an online ballot is displayed on the website.

Third, the voter casts their vote on the online ballot. The vote, along with the voter’s unique code, is then sent to the CorpVote server.

Australian National University sign on a wall in Canberra on a cloudy day.
The Australian National University recently held an online ballot using CorpVote’s e-voting software. Cromo Digital/Shutterstock

A flawed system

The “voter access code” is the connective link that allows an observer of this voting process to connect each vote to each voter’s employee number. At the university, the unique “voter access codes” were also sent to employee email addresses, automatically linking each “voter access code” to each person.

A well-designed voting system makes it difficult to link votes to voters, even in the face of collusion by multiple parties. Some e-voting systems use sophisticated cryptography such as homomorphic encryption or verifiable mixing to break the link between a person’s identity and their vote. However, there are still compelling reasons why e-voting should not be used in government elections. For example, it carries a risk of electoral fraud or error because it makes it difficult to verify each person’s vote is accurately recorded.

Nevertheless, e-voting has been used in state and territory elections, in addition to corporate elections. E-voting is often adopted by organisations for the convenience of allowing stakeholders to cast their votes remotely.

In the case of CorpVote, we did not have direct access to its systems. Instead, we asked volunteers to examine the network activity – how their vote data travels online – while votes were being cast during the Australian National University’s election.

Using freely available developer tools in their web browsers, volunteers recorded the three-step process we previously described.

Who can observe or access the vote data?

Anyone with administrator access to the CorpVote server can inspect or alter the voting data. Additionally, third-party internet proxy servers used by CorpVote could also inspect or alter the data as it transits to the server.

The system relies on “transport layer security” encryption – a standard internet security measure designed to protect data as it moves across the web. While this effectively secures the connection between the user and the server, it does not protect the data once it arrives at the server.

An attacker with unauthorised access to any of these systems could exploit this flawed design, enabling data tampering or leaks.

Some systems, such as iVote, used during the New South Wales state election, add an additional layer of encryption that the server cannot remove.

This ensures that when the server decrypts the incoming network traffic, it only reveals an encrypted vote. This is similar to how secure messaging apps such as WhatsApp or Signal protect your messages from being read by their servers.

While encryption does not prevent tampering, it ensures those with server access cannot read the votes.

CorpVote strongly rejected our results, telling The Conversation the investigation was “based on several incorrect assumptions” because we did “not have technical access to [CorpVote’s] systems, policy frameworks, or cybersecurity posture”.

A spokesperson for the Australian National University declined to comment, saying any questions about CorpVote’s systems should be directed to CorpVote.

A significant impact

Corporate elections have a significant impact on economies, industries and millions of lives.

In Australia, for example, one in three workers can vote in elections that shape their employment conditions, such as enterprise agreement ballots. As happened recently at the Australian National University, workers often cast their ballot through the CorpVote system.

Meanwhile, about one in three Australians is an investor in a publicly listed company, giving them a direct vote on decisions that influence corporate futures and the value of their investments. For example, shareholders vote to elect directors to the boards of companies such as Woolworths and Coles.

The outcome of such elections can impact how these companies are governed, ultimately influencing how much we pay for groceries at the counter.

Top of a building featuring the ABC symbol against a blue sky. CorpVote’s system is also used by some of Australia’s most influential organisations, such as the ABC. Adam Calaitzis/Shutterstock

Rigorous scrutiny of e-voting systems is needed

Since 2014, employees of the ABC and members of the Construction, Forestry, Mining and Energy Union have raised privacy concerns about the CorpVote process.

At the core of their unease is the requirement for voters to provide sensitive personal information, such as payroll numbers and birth dates, to verify their identity in the e-voting system.

Our investigation adds to these concerns.

Trust in institutions is already declining in both corporate and government settings. If people think their votes can be traced — such as their boss knowing how they voted — they might not vote at all. Worse, they might not vote honestly. This would lead to unfair outcomes and make others doubt the results.

Organisations and individuals must adopt a “verify, don’t trust” philosophy when voting online, even in corporate settings. This approach demands rigorous scrutiny of e-voting systems, no matter their reputation or assurances.

Authors: Priya Dev, Lecturer, Research School of Finance, Actuarial Studies & Statistics, Australian National University

Read more https://theconversation.com/anonymous-voting-software-used-by-some-of-australias-biggest-companies-is-flawed-new-investigation-reveals-244181

How Business Advisory Services Help Companies Achieve Sustainable Growth

Every business owner aims to build a profitable and sustainable organisation. While dedication, innovation, and hard work are important, achieving l...

Why Body Contouring Has Become A Popular Cosmetic Treatment

Many people maintain healthy lifestyles through regular exercise and balanced eating habits but still struggle with stubborn areas of fat that are dif...

How to Choose the Right POS Hardware for Your Business in Australia

A lot of Australian business owners spend weeks researching POS software but buy hardware almost as an afterthought. That's a mistake. The wrong har...

Why Material Handling Hose Is Critical for Industrial Efficiency

A high-performance material handling hose is an essential component in industries that transport abrasive, dry, or bulk materials on a daily basis...

How to Choose the Right Lawyer in Melbourne for Your Situation

Choosing legal support can feel difficult, especially when the stakes are personal or business-related. The right lawyer in Melbourne should underst...

Hoteliers Look to Clever Value Adds to Increase Revenue

The Australian hospitality industry is still in recovery mode after a notoriously rough patch in recent years. While there has been a post-COVID tra...

Moving to Queensland? Here’s How to Prep Your Car for the Big Move North

There’s no sign of the northern migration slowing down, with thousands of southerners fleeing from chaotic lifestyles and cooler climates for a brig...

Diesel Shortage to Impact Trades and Contractors

Strait of Hormuz blockage affecting all major parts of trades and construction Trades and construction across residential, commercial and industria...

Why Holiday Home Owners Turn to Rental Management Agents

The Allure — and the Reality — of Renting Out Your Property Owning a holiday home is a dream for many Australians. Whether it's a beachside sha...

Why Finding Reliable Doctors In Bundoora Is Important For Long-Term Health

Access to quality healthcare plays an important role in maintaining overall wellbeing and managing health concerns early. Trusted Doctors in Bundoor...

Understanding the Different Types of Car Services: Minor vs Major

When it comes to car maintenance, one of the most important things every vehicle owner should understand is the difference between a minor and a maj...

How Superannuation and TPD Insurance Work Together

Superannuation is an essential part of financial planning in Australia. It is designed to provide individuals with income during retirement, helping...

Tiny Towns funding granted for Mt Hotham and Mt Buller upgrades

Alpine Resorts Victoria (ARV) has welcomed funding support from the Victorian Government’s  Tiny Towns Fund, with both Mt Hotham and Mt Buller se...

Locksmith Services: Why Professional Security Solutions Matter More Than Ever

Security is a critical concern for homeowners, businesses, and vehicle owners alike. Whether it involves protecting a property, replacing damaged lo...

Why Tooth Fillings Are Important For Protecting Damaged Teeth

Cavities and minor tooth damage are common dental problems that can worsen if left untreated. Professional tooth fillings help restore damaged teeth, ...

The Connection Between Visibility and Driver Confidence

Operating a vehicle safely requires an immediate, uncompromised stream of visual information from the surrounding road environment. A driver's decis...

Important Things To Know Before Starting An SMSF Setup

Planning for retirement requires careful financial decisions, and many Australians are now looking for more direct control over how their superannua...

Why Retail Cleaning Plays a Key Role in Customer Experience and Business Success

Professional retail cleaning services are an essential part of maintaining a welcoming, safe, and professional environment for customers and staff...