Former Vice President Atiku Abubakar has questioned the decision of the Independent National Electoral Commission (INEC) to continue using the Bimodal Voter Accreditation System (BVAS) on an operating system he described as obsolete ahead of the 2027 general elections.
Atiku, the African Democratic Congress (ADC) presidential candidate, said the alleged use of Android 10 on BVAS devices could create cybersecurity and operational vulnerabilities capable of affecting the integrity of future elections.
His concerns were contained in a statement issued by his Media Office in Abuja on Tuesday.
The statement followed reported technical difficulties during the mock accreditation exercise held in Osun State on August 1, as well as comments attributed to INEC’s Director of ICT, Dr Lawrence Bayode.
Bayode reportedly said during an interview on Arise TV on Monday that the BVAS devices, which were introduced into the electoral process in 2021, currently operate on Android 10.
Reacting, Atiku noted that Android 10 reached its end-of-life status in 2023 and no longer receives regular security updates and patches.
He argued that operating a critical component of the electoral process on unsupported software could leave the system exposed to cyber threats and technical failures.
Atiku questioned why INEC had not upgraded the operating system before the 2027 elections, particularly given the commission’s budgetary resources.
He also asked why the forthcoming off-cycle elections, including the Osun governorship poll, could not serve as an opportunity to deploy and test an upgraded BVAS platform.
The former vice president described INEC’s handling of the issue as “suspicious”, warning that weaknesses in the technology could undermine confidence in the electoral process.
According to him, vulnerabilities in obsolete software could potentially be exploited to gain unauthorised access to BVAS devices and interfere with voter accreditation information or polling unit results before transmission.
He also raised questions about the security of results transmitted through public telecommunications networks to INEC’s Result Viewing (IReV) portal.
Atiku said outdated security and cryptographic components could increase the risk of cyberattacks targeting the transmission of polling unit data, including attempts to intercept, disrupt or manipulate information.
The ADC candidate further expressed concern about the biometric functions of BVAS, which uses fingerprints and facial recognition to authenticate voters.
He argued that weaknesses in an outdated biometric framework could affect the accuracy and reliability of voter verification and potentially make the system more vulnerable to attempts to bypass its security mechanisms.
Atiku also warned that defects associated with legacy software could trigger application crashes under heavy usage, particularly on election day, resulting in delays in voter accreditation.
He consequently endorsed calls from cybersecurity experts for an independent and comprehensive audit of the BVAS hardware and software ahead of the 2027 elections.
Atiku said such an assessment was necessary to determine whether the technology was sufficiently secure, reliable and capable of handling the demands of a nationwide election.
He maintained that running critical electoral infrastructure on an end-of-life operating system could unnecessarily widen its exposure to cyber threats and create risks that could otherwise be prevented.

Leave a Reply