33 ms·
Electronic voting is a bad idea and I'd be suspicious on anyone trying to promote it. How can you know that even if the source code for the voting machine is o
by danirod 9y ago
Electronic voting is a bad idea and I'd be suspicious on anyone trying to promote it.
How can you know that even if the source code for the voting machine is open, the voting machine is running the exact same source code? How can you know nobody has tampered the code the instance is running?
I'm glad my country is still running on paper ballots and glad we require voter ID.
- giancarlostoro 9y agoI agree with you entirely. There is no absolute way that we know of to truly know the code running is the exact code on GitHub. You can fake that it is in many ways, I don't see people running shell commands on the software before and after they vote to make sure it's the correct software. Even IF that software remains uncompromised, who owns the database? Who stops them from- Way too many factors...
- fredley 9y agoOn top of this, we all know that if it was implemented as well as physically possible, there would still be vectors for attack. However, if current voting machine trials are anything to go by, it's usually implemented extremely poorly.
- DarkKomunalec 9y ago> I don't see people running shell commands on the software before and after they vote to make sure it's the correct software. How would you know the shell itself, running on the machine you're trying to verify, isn't lying to you?
- nurettin 9y agoEvery time we vote, there is more talk about the burned ballots, unopened chests, uncounted votes and fraud concerning votes being collected from neighboring countries posing as people from my nation. So yeah. Doesn't really matter whether it's electronic or not.
- zAy0LfpBZLC8mAC 9y agoSo you mean it doesn't really matter whether we even know about the fraud happening?
- richardknop 9y agoMost fraud other than most primitive attempts by idiots goes unnoticed. If voter ID is not required it is not possible to prevent people who don't have right to vote from voting.
- geekamongus 9y ago> Most fraud other than most primitive attempts by idiots goes unnoticed. You know this how, exactly?
- richardknop 9y agoIt is my personal opinion. I think it's logical that it is easier to fraudulently vote if you don't need a voter ID.
- geekamongus 9y agoIt is also logical that voter fraud isn't necessarily an outcome of having no voter ID.
- Accacin 9y agoMy country doesn't require voter ID at all, other than confirming a few details and most studies here has shown that requiring ID didn't cut down on fraud. For me it's important that the barrier to voting is as low as possible, and we don't have a governement issued ID that is free.
- richardknop 9y agoThat should be solved by issuing a free government ID, not by compromising and creating a giant loophole when potentially citizens of other countries can vote in your election and there is no way to verify that.
- gbrown 9y agoIf you're primarily worried about attacks which can modify the result of elections, your threat model is broken.
- richardknop 9y agoWhat should you be primarily worried about? It's like serving your e-commerce website over HTTP because there have been very few security breaches. Why not get a certificate and use HTTPS? It's a massive improvement in security for a very small cost.
- gbrown 9y agoNot analogous,because attacks relying on coordinating large numbers of people (with a high rate of detection) simply doesn't scale. We should be worried about electronic attacks on voting infrastructure, political attacks on districts, political attacks on the registration process etc.
- feintruled 9y agoNot as easy as it sounds. I was in a Government office for some tax related reason and was in line behind some guys trying to apply for their 'electrical card' (sic, electoral). This is in N. Ireland, which unlike the rest of the UK requires ID to vote. They were having to be talked through filling in the form only to hit a roadblock when it came to proof of address. After expressing their voluble disbelief at some length that the handwritten doctor's note they had would not suffice, they eventually left empty-handed. (Incidentally, they were only looking the card to use it for ID for flying, they had no interest in voting). Now these guys were obviously jokers, but it shows you will need a certain degree of application and time to get even the most rudimentary of verifiable ID. Even the conscientious may find themselves not getting around to getting the ID before election and losing their vote.
- TeMPOraL 9y agoWhere is the good old Anonymous when we need them? We need a high-profile hack of some local elections to drive that point home. Something done completely for teh lulz, leading to a result so absurd the elections would have to be redone.
- octalmage 9y agoAt defcon this year they had a bunch of the popular electronic voting booths set up, and they were all hacked within 6 hours. A big problem is having physical access to the booth. All of the hacks involve picking a lock.
- zAy0LfpBZLC8mAC 9y agoGiven that the voting computers sit in some warehouse between elections, that's not really a big hurdle.
- jmmarco 9y agoYep, here's the post from Science Friday: https://www.sciencefriday.com/segments/hacking-the-vote-how-can-we-secure-our-voting-systems/ https://www.sciencefriday.com/segments/hacking-the-vote-how-...
- Iv 9y agoIf all that was at risk was a night in police jail and a slap on the wrist, it would be done, but reading the sentences one faces for election tampering is really chilling. I would not risk it for a million, I will certainly not risk it for the lulz. Plus, in most cases, it involves (laughably weak) physical security. I am less confident on how to hide my tracks there and I suppose many would-be hackers feel the same.
- Chardok 9y agoUnfortunately it would need to be a hack that purposefully gets itself caught in order to drive any point home. I can imagine the risk vs reward on something like that would be very undesirable.
- 9y ago
- JorgeGT 9y ago> and I'd be suspicious on anyone trying to promote it. It's just a former CIA Director signing the op-ed. It's not like they have a collection of zero-days and other exploits is it?
- drdaeman 9y agoThere are attempts to create an end-to-end auditable voting systems. Where you don't have to trust the organizers or machinery to not trick you, and you can validate that your vote was counted correctly. https://en.wikipedia.org/wiki/End-to-end_auditable_voting_systems https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy... Sadly, as far as I know, none is without issues (older systems were found to have various problems, and newer stuff is still bleeding edge that wasn't yet reviewed thoroughly).
- pjmorris 9y agoThe trick is that you don't just have to convince somebody (a security expert) that the system is trustworthy, you have to convince everyone (voters) that the system is trustworthy. Anything more complicated than paper ballots counted in public will leave room for doubt.
- drdaeman 9y agoThere are systems that are essentially paper ballot and by no means remove the "classic" experience, but have extra properties that allow audit, e.g. https://en.wikipedia.org/wiki/Punchscan https://en.wikipedia.org/wiki/Punchscan
- octalmage 9y agoPaper ballots leave a lot of room for doubt in my mind. How you can you recount the ballots and come up with a different number? This shouldn't be possible, but it happens all the time: https://en.m.wikipedia.org/wiki/Election_recount https://en.m.wikipedia.org/wiki/Election_recount Thinking out loud here, how about a blockchain based solution? Each user gets a new address, and that address is printed on a receipt after you vote. This way you can verify your vote at anytime, and the votes can be counted in public.
- vertex-four 9y agoThe entire point of a recount is that when the votes are close enough to swing the balance of an election, they're recounted, potentially repeatedly until we can be sure they're correct. They're essentially never more than a few votes off either way. If it's not close enough to swing the balance of the election, it doesn't really matter that a dozen votes were miscounted - we'd prefer that not to be the case, obviously, but not by breaking the other properties of the system. Short of some very very clever cryptography, you really, really don't want to be able to verify your individual vote, because that means you can verify it to others - the entire point of this process is to avoid coercion, or else there's much simpler solutions. (Pull everyone into the polling station at once and have a show of hands, for example.) You want to verify that one ballot was given to each person registered to vote, and that all votes were counted correctly, but you don't want to verify that an individual person's vote was counted correctly.
- vmateixeira 9y agoNot just the software we should be concerned about, hardware too.
- cmiles74 9y agoThe vote processing chain is lengthy, it is inevitable that a computer system will be inserted somewhere in that chain. Right now the push is to have these systems right at the front, facing the voter, but that isn't the only time the votes are processed electronically. In my district we vote by coloring in little circles with a #2 pencil, we then feed that directly into an electronic machine that tallies the results for my district. While the paper I handled is stored in the machine, I am sure that the results are transmitted to the next link in the chain through some computer system. With so many links in the chain, it's my opinion that it's unreasonable to expect them all to be processed by people. It won't scale and I'm not convinced that it's that much safer anyway. It would be my preference that the pieces of the system that perform this processing are backed with open source software. At the very least, if there is a case where tampering is suspected, officials of the court can compare the software on the machine with the software in the repository. This would prove in a clear and straightforward manner that tampering has occurred. As painful as it is, I think we all need to trust the state, to some degree, to do the jobs that are the responsibility of the state. Once the votes have been tallied for a district, isn't it possible to tamper with them as they are transmitted up the chain to the next link in the processing? Or when regions of the state send their votes up to whatever the next link might be? I think that is possible, the best we can hope for is to push for as much transparency as possible and hope that, if it comes to it, we have enough data to detect such tampering.
- TeMPOraL 9y ago> With so many links in the chain, it's my opinion that it's unreasonable to expect them all to be processed by people. It won't scale and I'm not convinced that it's that much safer anyway. I think the main argument for physical voting is that it's much safer precisely because it doesn't scale well - and so attacks against it don't scale well either. The manpower requirements buy you security. > As painful as it is, I think we all need to trust the state, to some degree, to do the jobs that are the responsibility of the state. I agree, but I think it does not apply to elections - simply because it's the one place where both the ruling party and competing groups have very strong incentives to mess with the process. > Once the votes have been tallied for a district, isn't it possible to tamper with them as they are transmitted up the chain to the next link in the processing? Yes, but again, the argument goes, the less scalable and more manpower-intensive the whole process is, the more difficult is to hack it. > I think that is possible, the best we can hope for is to push for as much transparency as possible and hope that, if it comes to it, we have enough data to detect such tampering. I agree with the call for transparency, but I also agree with the people who point out that inserting electronic systems destroys that transparency (too easy to hack, too complex for general population to inspect).
- Iv 9y agoCame here to say that. Transparent voting boxes, ballots in envelopes, manual redundant counting done by people, usually voter who were nicely asked if they can come help back in the evening. That's what we use in France, you get the official result a few hours after the closing of the voting stations. The whole process is watchable, from the sealing of the box the morning to the count in the end and parties send observers in random stations to check nothing fishy happens. An official log book is open for anyone to notice if they feel something fishy happened (you were not allowed to vote, the counting was unfair, etc...) Oh, and make voting day a holiday, or just put it on Sundays. I used to wonder how US could not even get that last part right, but then I understood that a whole party thinks it is in its interest to have less voters.
- _Codemonkeyism 9y agoSame in Germany.
- creaghpatr 9y agoAbout the author of the article: R. James Woolsey is a former director of the Central Intelligence Agency. Sums it up.
- cortesoft 9y agoOr make voting last multiple days instead of just one.
- Iv 9y agoThat makes it harder to keep an eye on the voting process from A to Z, which people do in the current process. If the box containing the ballots stay alone, trust is lowered. Seriously, is it harder to make a daily holiday and a transparent process than landing a man on the moon with tech from the 60s?
- EugeneAZ 9y agoThe most funniest thing is who is just eligible to be a candidate (not mention his chances to win). And how the chosen legislation, which is the result of those elections, is far from the most fair - one approved by score voting in direct democracy.
- rotten 9y agoWhy use a voting machine at all? Isn't the main point of having a polling location simply so you can verify your identity? If we could come up with a system that allowed one's identity to be verified online, or by postal service, then do we really need thousands of machines collecting the votes. Couldn't it be centralized to a handful of more easily audited systems?
- vertex-four 9y agoNo, the point of a polling station is so that there's provably no coercion. You fill out your ballot in secret, you're not permitted to take a photograph of it, and you place it in the ballot box without telling anybody what you've voted for. The more you allow people to vote from their homes, the more likely it is that people can be coerced into voting the way their partner, employer, or otherwise, want them to.
- Spivak 9y agoYou missed one important criterion. After you vote there is no way for you to prove who you voted for. If you could verify it after the fact then it opens up potential for coercion or incentives.
- 0xffff2 9y ago>You fill out your ballot in secret, you're not permitted to take a photograph of it, and you place it in the ballot box without telling anybody what you've voted for. In the US, only one of those is guaranteed [0]. In California, where I can get an absentee ballot just by asking for it, none of those is guaranteed. [0] https://www.bloomberg.com/news/articles/2017-04-03/ballot-selfies-allowed-as-u-s-high-court-rebuffs-new-hampshire https://www.bloomberg.com/news/articles/2017-04-03/ballot-se...
- vertex-four 9y agoYes, well, the US also broadly thinks electronic vote recording is a good idea. Let's not pretend it's any good at designing voting systems.
- joseppe 9y agoOne word: blockchain
- lawless123 9y agoI agree, you'd need a way to verify every machine is running the the open source software. The risk are too great you'll fail and the rewards for anyone that can hack the machines too great. To say a machine hasn't been hacked is trying to prove a negative.
- grondilu 9y agoI'd rather say it's a good idea but it also is a technical problem that is not yet convincingly solved. It is clear though that open source by itself is not a solution, for the very reason you mention (how can one be sure about what code is running on a machine one doesn't own?). That being said, from times to times articles show up about someone who claimed to have invented a viable solution. So we should not diss the idea and keep an open mind. Eventually someone will find a solution.
- nobodyorother 9y agopvote.org seems like a decent solution, it's <500 lines of code that needs to be audited. That doesn't handle auditing the machines themselves, but as the 2016 US presidential election recount found in Wisconsin, the tamper-evident machines showed evidence of tampering, so maybe we're closer to knowing whether the trusted systems we use to count votes are trustworthy. Of course, the current machines are still Diebold ("Premier Election Solutions"), so who knows. Ken Blackwell will make sure only the right folks vote, anyway, just like he did in 2008.
- zAy0LfpBZLC8mAC 9y ago> pvote.org seems like a decent solution, it's <500 lines of code that needs to be audited. Quoting from the website: "Pvote is small. The current version is 460 lines of Python. It uses Pygame for graphics and audio." So, add to that 130000 lines of pygame, 1.5 million lines of cpython, 14 million lines for gcc, 20 million for the linux kernel, ... and you haven't even begun to list all the stuff you would need to audit?
- specialist 9y ago"Eventually someone will find a solution." First define the problem. I demand the Australian Ballot: private voting, public counting. After studing this extensively, I believe there is no way to digitize elections and preserve the Austalian Ballot. Because there is no digital equivalent of the physical secure one-way hash (shuffle) of dropping ballots into a box. Any crypto- blocko- based system has to design for the whole election. Not just the voting. Including pollbooks, which record when ballots are issued to voters. Including precinct-based election counts, because every single precinct gets a different ballot (say 500 voters). Maybe someone will prove me wrong. Cool. Then show me. The burden of proof is one them, not me. Otherwise, stop wasting everyone's time with technophilia sideshows. We've got real democracy with real work to do. --- Alternately, any proposal has to replace the Australian Ballot with something new. Some ideas which would simplify the problem space: - replace winner takes all with Approval Voting; - issue separate ballots for federal, state, county, and local elections; - decide that time-boxed privacy, where the secret ballot is preserved until an election is certified and then made public, is sufficient - supplant our current loose voter ID regiment some kinda of U2F futuretech.
- specialist 9y agoThere's a lot more to elections than tabulation. Mapping, voter files, candidate filings, canvassing reports, ballot artwork, translations, ballot tracking, etc. All of it should be open source. The way it used to be. Before the vendors smelled blood. (Especially after HAVA.) I traveled my state advocating "citizen owned software". Everyone gets that phrasing. Overwhelming support.
- xroche 9y ago> the voting machine is running the exact same source code? Or the processor is trustworthy ? Many voting machines are using old processors, such as 68000, and it would not be too hard to emulate a a rogue processor that will have a different behavior, whatever the source code is. You can also change the behavior of the voting machine at a certain time, or in certain conditions (such as detecting a voting session has started) The problem is not that voting machines are vulnerable to one or two attacks. There are thousands of ways of compromising them. The only answer to this is that cryptography specialists do not have any answer to a secure electronic voting not involving a physical element (a bulletin, a receipt, etc.). This means that there is no THEORETICAL solution.