ECINET flaws were flagged to poll body, cyber-security agency CERT-In in July: Researcher

ECINET flaws were flagged to poll body, cyber-security agency CERT-In in July: Researcher

A security researcher has said he warned the Election Commission of India (ECI) and the country’s cyber-security agency, CERT-In, about flaws in the Commission’s voter-services website and its ECINET app back in July. He said they could expose election officials’ contact details and let attackers read or forge data in the app.

The issue assumes significance given concerns, first flagged in an Indian Express investigation, that ECINET blocks access of Electoral Registration Officers and their deputies to the voter roll database — preventing local government officials responsible for additions and deletions in the database from effecting these changes. To be sure, none of the flaws highlighted by Adhikary were directly related to this. HT also asked what his cVIGIL test returned and whether he had reason to think real citizen or incident data was reachable. But an organization like ECI ignoring reports is really problematic.

Because i handle a lot of security reports and this is a really old report, he said, “I don’t remember that vulnerability.

In an email to Adhikary, a screenshot of which HT has seen, CERT-In’s incident response desk said “the concerned organisation” had confirmed that one reported vulnerability, labelled “Client-Side Static Response Encryption (Hardcoded AES Key)”, was fixed. It said the rest were under progress and asked Adhikary to verify the fix and confirm.

He describes it as an extra layer of protection that actually offered none, since the connection is already encrypted, and mainly serves a weakness in layered defences. The poll body launched ECINET on January 22, integrating over 40 apps and web services. Announcing the platform in 2025, it said it would subsume apps including cVIGIL and Suvidha 2.0, which together had over 5.5 crore downloads, and that trials were testing cybersecurity.

His email to ECI and CERT called this “live-confirmed” on July 8 and said he used a non-existent location to avoid retrieving real data. The flaw CERT-In said was fixed is the one Adhikary rated of least concern among the issues raised in his email. He says the website’s servers scrambled their responses with a key also embedded in the site’s public code, so anyone who read the code could unscramble them. He also said it amplified his more serious finding by removing an obstacle to reading the data.