siv-org / siv

Secure Internet Voting protocol
https://siv.org
Other
13 stars 9 forks source link

Security concerns with Google Tag Manager #216

Open dglittle opened 3 months ago

dglittle commented 3 months ago

Google’s tag manager is loaded on every page, and can entirely control the election

This JS is just loaded on every page and can therefore entirely control the DOM.

[...]

The goal is not to cast aspersions on the vendor, but to point out that the system is fundamentally trusting them in a way that might not be safe in the case of nation-state level adversaries.

Originally posted by @mspecter in https://github.com/siv-org/siv/issues/195

arianabuilds commented 2 months ago

Entry Summary for HACK SIV @ DEF CON 2024

Thanks again for participating! This submission earned $113.38 from SIV and $60.31 from the Public Vote, for a total of $173.69.

Here's what we noted in our evaluation:

What's interesting about this submission

What takes away from it

Issue to track getting paid: https://github.com/siv-org/hack.siv.org/issues/11