{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T22:08:11Z","timestamp":1757628491646,"version":"3.44.0"},"publisher-location":"Cham","reference-count":15,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032050359","type":"print"},{"value":"9783032050366","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T00:00:00Z","timestamp":1757548800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T00:00:00Z","timestamp":1757548800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>We propose two novel voter authentication attacks in\u00a0the context of the 2022 Ontario Municipal Election, which offered online voting to almost four million voters in over 200 municipalities.\u00a0One attack exploits a misconfiguration in one of the voting portals\u00a0used by up to one million voters. It was mitigated through a successful coordinated vulnerability disclosure that we conducted with\u00a0the affected vendor during the election period. The other attack exploits widespread and insecurely discarded login credentials.\u00a0This attack affects the vast majority of the deployments examined, and\u00a0we study and quantify the risk for each city individually. In\u00a0both cases, the risks were aggravated by unique, context-dependent factors, which we detail. Finally, toward quantifying this risk,\u00a0and absent the availability of this data elsewhere, we present\u00a0a comprehensive census of online deployments used in the province.<\/jats:p>","DOI":"10.1007\/978-3-032-05036-6_9","type":"book-chapter","created":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T07:22:42Z","timestamp":1757488962000},"page":"141-157","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Credential Attacks in\u00a0Ontario\u2019s Online Elections"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9799-2314","authenticated-orcid":false,"given":"Eric","family":"Klassen","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9018-5106","authenticated-orcid":false,"given":"James","family":"Brunet","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8607-2595","authenticated-orcid":false,"given":"Nicole","family":"Goodman","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0228-0371","authenticated-orcid":false,"given":"Aleksander","family":"Essex","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,9,11]]},"reference":[{"key":"9_CR1","unstructured":"Association of Municipalities of Ontario: 2022 Municipal Election Results Website. Accessed 30 Aug 2024. elections2022.amo.on.ca"},{"key":"9_CR2","doi-asserted-by":"crossref","unstructured":"Juels, A.,\u00a0Catalano, D.,\u00a0Jakobsson, M.: Coercion-resistant electronic elections. In: Proceedings of the 2005 ACM Workshop on Privacy in the Electronic Society, pp.\u00a061\u201370 (2005)","DOI":"10.1145\/1102199.1102213"},{"key":"9_CR3","doi-asserted-by":"crossref","unstructured":"Kusters, R.,\u00a0Truderung, T.: An epistemic approach to coercion-resistance for electronic voting protocols. In: 2009 30th IEEE Symposium on Security and Privacy, pp.\u00a0251\u2013266. IEEE (2009)","DOI":"10.1109\/SP.2009.13"},{"key":"9_CR4","unstructured":"Delaune, S.,\u00a0Kremer, S.,\u00a0Ryan, M.: Coercion-resistance and receipt-freeness in electronic voting. In: 19th IEEE Computer Security Foundations Workshop (CSFW 2006), p.\u00a012. IEEE (2006)"},{"key":"9_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-642-27576-0_4","volume-title":"Financial Cryptography and Data Security","author":"J Clark","year":"2012","unstructured":"Clark, J., Hengartner, U.: Selections: internet voting with over-the-shoulder coercion-resistance. In: Danezis, G. (ed.) FC 2011. LNCS, vol. 7035, pp. 47\u201361. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-27576-0_4"},{"key":"9_CR6","unstructured":"Kula, T.: Challenge to Lambton Shores election dismissed, The Observer (Sarnia) (2019). https:\/\/www.theobserver.ca\/news\/local-news\/challenge-to-lambton-shores-election-dismissed"},{"key":"9_CR7","doi-asserted-by":"publisher","unstructured":"Cardillo, A., Akinyokun, N., Essex, A.: Online voting in ontario municipal elections: a conflict of legal principles and technology? In: Krimmer, R., Volkamer, M., Cortier, V., Beckert, B., K\u00fcsters, R., Serd\u00fclt, U., Duenas-Cid, D. (eds.) E-Vote-ID 2019. LNCS, vol. 11759, pp. 67\u201382. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30625-0_5","DOI":"10.1007\/978-3-030-30625-0_5"},{"key":"9_CR8","unstructured":"Vallis, M.: So you gave personal info to a company caught in a data breach. Now what?, CBC News (2023). https:\/\/www.cbc.ca\/news\/canada\/cybersecurity-consumer-protection-tips-1.6900450"},{"key":"9_CR9","unstructured":"Griffin, T.: Data breach exposed health info on pregnancies and births of 3 million Ontarians. National Post (2023). https:\/\/nationalpost.com\/news\/canada\/perinatal-child-registry-data-breach-affects-3-million-ontarians"},{"key":"9_CR10","unstructured":"Abedi, M.: LifeLabs hack: what Canadians need to know about the health data breach. Global News (2019). https:\/\/globalnews.ca\/news\/6311853\/lifelabs-data-hack-what-to-know\/"},{"key":"9_CR11","unstructured":"Ohio secretary of state: Statewide voter files download page (2024). https:\/\/www6.ohiosos.gov\/ords\/f?p=VOTERFTP"},{"key":"9_CR12","unstructured":"Town of Atikokan: How to vote online in the 2022 Election (2022). url: https:\/\/www.facebook.com\/atikokantown\/videos\/1265289370957760\/"},{"key":"9_CR13","doi-asserted-by":"publisher","unstructured":"Cardillo, A., Essex, A.: The threat of SSL\/TLS stripping to online voting. In: Krimmer, R., Volkamer, M., Cortier, V., Gor\u00e9, R., Hapsara, M., Serd\u00fclt, U., Duenas-Cid, D. (eds.) E-Vote-ID 2018. LNCS, vol. 11143, pp. 35\u201350. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00419-4_3","DOI":"10.1007\/978-3-030-00419-4_3"},{"key":"9_CR14","doi-asserted-by":"crossref","unstructured":"Brunet, J., Pananos, A.D.,\u00a0Essex, A.: Review your choices: when confirmation pages break ballot secrecy in online elections. In: Electronic Voting: 7th International Joint Conference (E-Vote-ID), vol.\u00a013553, LNCS, pp.\u00a036\u201352 (2022)","DOI":"10.1007\/978-3-031-15911-4_3"},{"key":"9_CR15","unstructured":"Online Voting \u2013 Part 1: Implementation of Online Voting in Canadian Municipal Election (CAN\/DGSI 111-1). Digital Governance Standards Institute (2024)"}],"container-title":["Lecture Notes in Computer Science","Electronic Voting"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-05036-6_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T07:22:47Z","timestamp":1757488967000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-05036-6_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,11]]},"ISBN":["9783032050359","9783032050366"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-05036-6_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,11]]},"assertion":[{"value":"11 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"E-Vote-ID","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Joint Conference on Electronic Voting","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nancy","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"evoteid2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/e-vote-id-2025.inria.fr\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}