Cybersecurity Podcasts
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityPodcastsThe IACR Can't Decrypt with Matt Bernhard
The IACR Can't Decrypt with Matt Bernhard
Cybersecurity

Security Cryptography Whatever

The IACR Can't Decrypt with Matt Bernhard

Security Cryptography Whatever
•December 31, 2025•56 min
0
Security Cryptography Whatever•Dec 31, 2025

Key Takeaways

  • •IACR election failed due to lost decryption key.
  • •Helios uses finite‑field ElGamal homomorphic voting.
  • •No threshold decryption implemented; single key loss blocks tally.
  • •Cryptographers debate Helios’s security, verification, and modern alternatives.
  • •Real World Crypto bridges academic research and industry deployment.

Pulse Analysis

The International Association for Cryptologic Research (IACR) recently made headlines when its internal election could not be decrypted because a trustee misplaced the USB key holding the decryption secret. The organization, which runs flagship conferences like Crypto, Eurocrypt, and AsiaCrypt, relies on the open‑source Helios platform for online voting. The failure highlighted a surprising irony: experts in cryptography were unable to apply their own tools to a simple key‑recovery problem, prompting a wave of commentary across the security community and even a brief New York Times mention.

Helios implements a classic finite‑field ElGamal scheme that is additively homomorphic, allowing encrypted ballots to be multiplied together for a private tally. While the protocol supports homomorphic aggregation, the IACR deployment omitted a true threshold decryption mechanism; instead it stored a single secret split across three physical shares. When one share vanished, the entire tally became unrecoverable. This design choice underscores the practical challenges of key management in cryptographic elections and illustrates why threshold cryptography, despite its theoretical elegance, must be correctly integrated to avoid single points of failure.

The episode sparked a broader discussion about the state of secure e‑voting. Researchers cited newer systems such as ElectionGuard, StarVote, and Scantegrity, which incorporate zero‑knowledge proofs, mix‑nets, and robust secret‑sharing to improve verifiability and resilience. For business leaders and security professionals, the incident serves as a cautionary tale: adopting cryptographic primitives without thorough operational safeguards can undermine trust. As the cryptographic community continues to refine online voting standards, organizations must prioritize transparent audit trails, independent verification tools, and fault‑tolerant key distribution to ensure that even the most technically sophisticated elections remain reliable.

Episode Description

The International Association of Cryptologic Research held their regular election using secure voting software called Helios…and lost the keys to decrypt the results, leaving them with no choice but to throw out the vote and call a new election. Hilarity ensues. We welcome special guest Matt Bernhard who actually works on secure voting systems to explain which bits are homomorphically additive or not.

Watch on YouTube: https://www.youtube.com/watch?v=euw_yqAQFI8

Transcript: https://securitycryptographywhatever.com/2025/12/30/iacr-helios

Links:

  • NYT: https://www.nytimes.com/2025/11/21/world/cryptography-group-lost-election-results.html

  • IACR Memo: https://www.iacr.org/news/item/27138

  • https://www.iacr.org/elections/

  • https://vote.heliosvoting.org/faq

  • https://github.com/Election-Tech-Initiative/electionguard

  • https://www.usenix.org/legacy/events/sec08/tech/full_papers/adida/adida.pdf

  • https://www.iacr.org/elections/eVoting/about-helios.html

  • https://www.iacr.org/elections/eVoting/

  • https://crypto.ethz.ch/publications/files/CrGeSc97b.pdf

  • https://electionguard.vote/

  • https://eprint.iacr.org/2025/1901

  • https://freeandfair.us/blog/open-free-election-technology/

  • https://www.starvoting.org/

  • https://mbernhard.com/

"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)

Show Notes

0

Comments

Want to join the conversation?

Loading comments...