기사 메일전송
[Analysis] "Is the Election Commission Safe"... Structural Risks Created by 1990s-Style Security Incidents
  • Kim Young
  • December 11, 2025 at 10:05 PM
기사수정
  • Security is not a barrier, but a structure.
  • Risk originates from within, not from outside.

  • Do not force trust, provide verification.

National Election Commission. Yonhap News

As of 2025, the core issue of the National Election Commission's (NEC) security is not "preventing external attacks." 

 

If data structures, authorization structures, audit log structures, and code verification structures are absent, incidents occur not from external sources, but internally. 

 

The personal information leak incident involving Coupang, affecting as many as 34 million individuals, serves as a case that re-establishes the fact that "security policies must extend beyond mere blocking to encompass verification." 

 

In Korean society, personal information is no longer just data; it is a 'sovereign security asset' where national systems and individual safety intersect. The recent Coupang incident, originating from internal access rather than external intrusion, and revealing a lack of verification structures despite the presence of firewalls, carries significant implications. 

 

At the same time, the National Election Commission, which holds information on all voters nationwide, repeatedly states that it is "safe because it is isolated from external networks." However, technically, isolation and safety are not synonymous. While isolation is akin to a firewall, safety is about structure, and this distinction highlights the fundamental difference between security awareness in the 1990s and security policies in 2025. 

 

Examining the NEC through the lens of 2025 security policy reveals four problems. 

 

Firstly, the fact that the NEC's systems are operated centrally rather than in a decentralized manner exacerbates structural risks. 

 

Key systems such as the integrated voter registry, web servers, and integrated servers are concentrated in a central server. In information security, when data converges at a single point, authority also converges at that point, which is known as a 'Single Point of Failure.' 

 

In other words, incidents do not necessarily originate externally; the stability of the entire system can be shaken by the intent of a single insider or a single mistake in authorization settings. This is not a conspiracy theory but a conceptual definition in information security. 

 

The perception that 'blocking equals security,' centered around firewalls, is anachronistic. 

 

Firewalls are merely devices to block external attacks and do not guarantee internal integrity. The Coupang incident clearly demonstrated this. Internal access, insider collusion, modifiable audit logs, and code changes without verification are all outside the protection of firewalls. The explanation that "it is safe because it is isolated from the outside" is merely political rhetoric lacking technical grounding. 

 

The core of security lies in a structure that controls "who can do what." 

 

Secondly, modern security operates under an RBAC (Role-Based Access Control) system. Authority is granted to roles, not individuals, and operational, verification, and auditing functions are separated. Systems lacking an RBAC structure allow a single administrator to perform all functions, including viewing, modifying, deleting, and accessing logs, leading to untraceability in the event of an incident. 

 

RBAC is not an option but a minimum security requirement for 2025; however, there is no indication that the NEC operates this system. 

 

Thirdly, the issue of audit logs is even more critical. 

 

Audit logs must record 'who, when, and what' was changed, and properly designed logs must be immutable. They are only meaningful if administrators cannot modify or delete them. If there are no logs, tracing is impossible; if logs exist but can be deleted, they are as good as non-existent. 

 

While the NEC emphasizes 'isolation from external networks,' there is no explanation regarding the operation of immutable audit logs. 

 

Fourthly, code signing is also crucial for the security of election systems. 

 

Systems operate based on code, not human commands, and modifications must undergo an approval process, signature verification, and be recorded in logs. Financial networks mandate this process, but the NEC does not disclose its code modification procedures. 

 

This suggests not necessarily 'confidentiality' but rather a 'potential for an unpublishable structure,' as code can be directly linked to the processing of voting data. 

 

The Coupang incident was a matter of "access," not "hacking," and system vulnerabilities stemmed from structural flaws, not technical loopholes. 

 

Even if not currently under attack, security experts generally agree that the NEC is in a "structurally vulnerable state." The essence of the problem is that risks originate internally, not externally. 

 

Hankyoreh, JoongAng Ilbo, and The Korea Herald pose three questions to the NEC: 

 

First, does the NEC operate an RBAC (Role-Based Access Control) system? Is authority vested in individuals or in the structure? 

 

Second, are audit logs designed in an immutable form? Can logs be deleted, or are they designed to be undeletable? 

 

Third, do code changes undergo an approval process and signature verification? Are changes recorded, traceable, and designed for external verification? 

 

Security is not about trust, but about verification. Verification is about responsibility, not attack, and that responsibility culminates in improving the verification structure of the electoral system. 

 

Even those who dismiss suspicions of election fraud as conspiracy theories would likely agree with this point. Is there any reason why a single key employee of the NEC should have the ability to destabilize South Korea's elections? This is why the NEC's response is eagerly awaited. 


관련기사
What do you think of this article?
recommend
0
great
0
moved
0

This article has 1comments.

  • Profile
    guest2025-12-11 23:01:09

    국민신문고 문서도 피신고자가 몰래 훔쳐서 유출하는 세상에 공공기관을 믿냐 ㅋ 멍청도 교육청 믿지 마라 ㅋ

정기구독배너
Go to Mobile Site