Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek
  • Home
  • Nation
  • Politics
  • Economy
  • Sports
  • Entertainment
  • International
  • Technology
  • Auto News
Reading: Critical Security Failures in ECI’s Voter Portal Exposed After Aland Mass-Deletion Attempt
Share
Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeekBreaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek
Search
  • Home
  • Nation
  • Politics
  • Economy
  • Sports
  • Entertainment
  • International
  • Technology
  • Auto News
© 2024 All Rights Reserved | Powered by India News Week
Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek > Featured > Critical Security Failures in ECI’s Voter Portal Exposed After Aland Mass-Deletion Attempt
FeaturedNation

Critical Security Failures in ECI’s Voter Portal Exposed After Aland Mass-Deletion Attempt

September 24, 2025 5 Min Read
Share
SHARE

The recent Aland mass-deletion incident—where thousands of voter registrations were allegedly deleted in a single coordinated action—has laid bare catastrophic security deficiencies in the Election Commission of India’s (ECI) digital infrastructure. In response, I conducted an urgent security review of the Voter Helpline App (VHA) and the official voter portal at voters.eci.gov.in. The findings are not just alarming—they are indefensible for a system entrusted with the integrity of India’s democratic foundation.

A Failing Grade: Mozilla Observatory Score of 15/100 (F)

The Mozilla Observatory, a respected industry-standard tool for evaluating web security posture, awarded the ECI voter portal a dismal 15 out of 100—an outright F. This isn’t a minor oversight; it’s a systemic collapse of basic web security hygiene.

Key failures include:

  • Invalid Content-Security-Policy (CSP) Header: The CSP—a critical defense against cross-site scripting (XSS) and data injection attacks—is syntactically broken. In effect, CSP is disabled, leaving the portal wide open to client-side exploits.
  • No HTTP Strict Transport Security (HSTS): Without HSTS, users are vulnerable to SSL-stripping and man-in-the-middle attacks, especially on public Wi-Fi networks.
  • Session Cookies Lack SameSite Attribute: This omission enables cross-site request forgery (CSRF) attacks, where malicious sites can silently trigger actions (like voter deletion) on behalf of authenticated users.

Compounding Risk: WebView Embedding

Both the Voter Helpline App and the portal rely heavily on embedded WebViews to render web content inside mobile applications. This architectural choice magnifies every server-side vulnerability. A single XSS flaw—already likely given the broken CSP—can be weaponized to steal session tokens, manipulate voter data, or execute mass-deletion scripts with the user’s full privileges. In the context of voter registration, this isn’t just a bug—it’s a potential vector for electoral sabotage.

A Betrayal of Public Trust

This is not merely a technical failure. It is a profound breach of public trust. The ECI handles one of the most sensitive civic functions in the world: the management of voter identity and participation. Yet, the commission has deployed systems that fail to meet even baseline security standards expected of a basic e-commerce site—let alone a pillar of democracy.

Using public funds to build and operate such a fragile, half-baked digital infrastructure is unconscionable. There is no evidence of a pre-deployment security audit, no adherence to OWASP Top 10 practices, and no apparent incident response readiness. The Aland incident may be the tip of the iceberg.

Immediate Actions Required

Take Voter Enrolment and Deletion Services Offline Immediately
Until a full, independent security audit is completed and all critical vulnerabilities are remediated, these services must be suspended. The risk of further mass manipulation or data compromise is too high.

Preserve All Forensic Evidence
The ECI must immediately:

  • Export and preserve logs from CDNs, load balancers, application servers, databases, and SMS gateways related to the Aland incident and the preceding 90 days.
  • Generate and publish SHA-256 hashes of all exported datasets.
  • Issue a Section 65B certificate under the Indian Evidence Act to authenticate these digital records for potential forensic examination by the Central Investigation Department (CID) or other competent agencies.

Commission an Independent Penetration Test
Engage a globally recognized, independent cybersecurity firm (with no prior ties to ECI vendors) to conduct a full-scope red-team exercise. The complete report—including vulnerabilities, exploitation scenarios, and remediation timelines—must be published in full transparency.

Enforce Accountability

  • If these failures stem from negligence or incompetence, the responsible officials and contractors must be immediately removed. They have demonstrated they are unfit to manage critical democratic infrastructure.
  • If there is evidence of deliberate sabotage or collusion, a criminal investigation must be launched without delay.

The Stakes Could Not Be Higher

India’s electoral system is the world’s largest and most complex. Its digital extensions must be held to the highest standards of security, resilience, and transparency. What we have uncovered is not a “glitch”—it’s a systemic failure that undermines the very legitimacy of voter rolls and, by extension, election outcomes.

The ECI must act now—not with press releases, but with concrete, verifiable security actions. The public deserves nothing less than absolute confidence in the sanctity of their vote.

Democracy cannot run on broken code.

Share This Article
Twitter Copy Link
Previous Article Baby food law’s violations abound in face of government inaction Widespread Violations of Baby Food Regulations Persist Amid Government Inaction
Next Article Family of IIM Udaipur student found dead urges CBI probe in letter of CM, rejects suicide theory Family of Deceased IIM Udaipur Student Demands CBI Investigation, Disputes Suicide Theory
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

InCred Holdings files confidential IPO papers with SEBI: Eyes ₹3,000-4,000 cr via issue

InCred Holdings files confidential IPO papers with SEBI: Eyes ₹3,000-4,000 cr via issue Rewrite this headline into a unique, engaging, SEO-friendly news title. Use only English. Maximum 12 words. Output only the new title.

November 9, 2025
As Super Typhoon Fung-wong nears, Philippines on edge

As Super Typhoon Fung-wong nears, Philippines on edge Summarize this tweet into a catchy, SEO-friendly title in English. Max 12 words. Output only the title.

November 9, 2025
India's forex reserves drop further, but still around record high of $704.9 billion

India’s forex reserves drop further, but still around record high of $704.9 billion Rewrite this headline into a unique, engaging, SEO-friendly news title. Use only English. Maximum 12 words. Output only the new title.

November 9, 2025
Crude oil futures rise as US product inventories decline

Crude oil futures rise as US product inventories decline Rewrite this headline into a unique, engaging, SEO-friendly news title. Use only English. Maximum 12 words. Output only the new title.

November 9, 2025
Rashtriya Swayamsevak Sangh (RSS) Chief Mohan Bhagwat

Mohan Bhagwat rubbishes RSS registration row — ‘Even Hindu Dharma not registered’ Rewrite this headline into a unique, engaging, SEO-friendly news title. Use only English. Maximum 12 words. Output only the new title.

November 9, 2025
Kerala CM, LoP slam Southern Railway for making students sing RSS song at Vande Bharat Express flag-off

Kerala Leaders Condemn Southern Railway for Enforcing RSS Song at Vande Bharat Express Launch

November 9, 2025

You Might Also Like

Delhi courts find serious issues in reports filed by police in 2020 ‘riot cases’
Nation

Delhi Courts Highlight Major Flaws in Police Reports on 2020 Riot Cases

3 Min Read
Israel says Gaza ceasefire back on after killing 44 Palestinians in deadly attacks
Nation

Ceasefire Restored as Israel Strikes Gaza, Resulting in 44 Palestinian Deaths

4 Min Read
Political tensions rise in Karnataka over alleged contractor suicide
Nation

Karnataka Political Turmoil After Allegations Surrounding Contractor’s Tragic Suicide

2 Min Read
Nagpur violence: What about instigators, asks Congress as Fadnavis orders 'UP-style' action
Nation

Congress Questions Instigators in Nagpur Violence as Fadnavis Calls for ‘UP-Style’ Response

4 Min Read
Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek
Breaking India News Today | In-Depth Reports & Analysis – IndiaNewsWeek

Welcome to IndiaNewsWeek, your reliable source for all the essential news and insights from across the nation. Our mission is to provide timely and accurate news that reflects the diverse perspectives and voices within India.

  • Home
  • Nation News
  • Economy News
  • Politics News
  • Sports News
  • Technology
  • Entertainment
  • International
  • Auto News
  • Bookmarks
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • Nation
  • Politics
  • Economy
  • Sports
  • Entertainment
  • International
  • Technology
  • Auto News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by India News Week

Welcome Back!

Sign in to your account

Lost your password?