• jonne@infosec.pub
    link
    fedilink
    English
    arrow-up
    5
    ·
    5 days ago

    Yeah, not 100% sure how it’s implemented, but if you compromise a mobile app with the right permissions you could probably send the SMS from what’s essentially a botnet.

    • zaphod@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      5 days ago

      Voting is exlusively via SMS, the voting app also just sends an SMS and so does the website. The only country not doing televoting is San Marino, too small and relies on Italy, if you send an SMS from there it’ll be probably counted as Italy. SMS is a crappy system and you can put whatever you want as sender (sometimes for codes you get an SMS not even from a number, but from a name because there’s no restriction on that). You can pretend to be someone else relatively easy and the receiver has no way of checking if it’s even a real number.