8 ms·
Is it really impossible though? I feel like we could eventually figure it out.
by d0lph 8y ago
Is it really impossible though? I feel like we could eventually figure it out.
- dillonb 8y agoThere's no such thing as a fully secure system.
- eganist 8y agoThat's never the goal with securing a system, though. The goal is to mitigate risk to a level acceptable to the various stakeholders involved based on what said stakeholders value.
- d0lph 8y agoIncluding paper ballots?
- Retric 8y agoPaper can easily get 'lost' or 'replaced.' The advantage of paper is it's bulky so it's hard to swap out if people from multiple parties and observers etc are paying attention. PS: Remember the oldies, "Vote early, Vote Often" and "It's Not the People Who Vote That Count, it's the people that count the Vote"
- beat 8y agoPreventing "lost or replaced" with paper ballots is a straightforward exercise in good human process. There are states that do not have good human process to manage their ballots, despite the example of other states that do have good process. Those states are incompetent/malicious.
- donarb 8y agoSome systems that use paper ballots photograph each ballot before it is counted. This helps with auditing counts later on since every count must exactly match.
- teddyh 8y ago> Is it really impossible though? Yes, it really is: https://www.youtube.com/watch?v=w3_0x6oaDmI https://www.youtube.com/watch?v=w3_0x6oaDmI
- Avamander 8y agoI'd love actual proof/research instead of an Youtube video, plus it doesn't differentiate between e-voting (with machines mentioned in the video) and i-voting (with public key crypto, like in Estonia) which further reduces the video's trustworthyness.
- howard941 8y agoTechnically possible, politically impossible in large part because there are just too many local jurisdictions with final say over the selection of vendors and their ballot machinery.
- kozhevnikov 8y agoI feel like it's possible to write secure voting software to the same level as NASA's software is bug free [1] following a similar rigorous development and testing process. It's just not worth it for any commercial profit-driven company. [1] https://news.ycombinator.com/item?id=421555 https://news.ycombinator.com/item?id=421555
- germinalphrase 8y agoIn which case, a strong argument could be made for an investment in the standardization of election voting machines? It is purely a fear of federal vs state control that this hasn’t already happened?
- mmt 8y ago> It's just not worth it for any commercial profit-driven company. I don't think that conclusion follows. Rather, I think that conclusion is too narrow. In this situation, the astronomic overall cost of such software would overshadow any other impediments, such as profit movite. Why would anyone task even a public entity with this, if using paper ballots and manual counting is vastly cheaper?
- 3pt14159 8y agoIt's impossible to secure without giving up the secrecy of the ballot or having a fully redundant paper system with on-premise checks by humans with observers: In which case, why bother?
- d0lph 8y agoWhy is it impossible without doing those things?
- 3pt14159 8y agoBecause you need to both know the value of an action (ie, which politician the vote is counted for) and you need to hide who did the action (to keep the ballot private) and you need to ensure every voter only does the action at most once and you need to ensure that if the machine is replaced or subverted physically that the vote can't be silently switched. No matter how you dice it, one of those things gives with electronic voting, even if you had electronic voting machines with no state (all pure circuits, say), but especially with votes on machines like personal computers, where a myriad of systems need to be trusted for the vote to register. It isn't worth it. Paper ballots are intelligible to everyone, and even when we vote by mail there is such a paper trail it is hard to fake.
- euyyn 8y agoHow is vote by mail secured?
- henrikschroder 8y agoGenerally, by sealed envelopes, and by having groups of people inspect mail votes at counting time to ensure the envelopes haven't been tampered with. There's also usually a paper trail from the post office that receives the votes so you can't just show up with a couple of thousand "mail votes" and send them in. It is obviously less secure than voting in person, but it's good enough, and your in-person vote supersedes your mail-in vote.
- 8y ago
- michaelt 8y agoThe threat model is corrupt election workers, who have unmonitored access to the machines. And if you find problems after the winner is declared? “Only the losing side cares, and they’re just sore losers” Or an adversary could not commit fraud, just trip the fraud alarms in areas their opponent is strong. So it’s very, very difficult to secure.
- TangoTrotFox 8y agoI think that's setting a very unreasonable standard as the exact same could be said of election workers in e.g. a paper balloting system. Votes get miscounted, votes go missing, a new box of 'votes' is added into the mix, etc. Electronic systems can provide a much better level of security than this through not only all the regular security techniques you'd apply to regular workers (no individual access, surveillance, etc) but also a wide array of electronic means including logging, 'ballot' validation, and much more. And you can also burn everything including the operating system and election software onto a non-flashable ROM meaning software modifications become all but impossible, and even if somehow achieved, would be trivial to detect.
- deleted 8y ago[deleted]
- blacksmith_tb 8y agoI am also not optimistic, but all of those are also failings of traditional voting methods. So one could offer the standard defense of self-driving cars, "it doesn't need to be perfect, as long as it's better" (but it may never be better...)
- benchaney 8y ago> but all of those are also failings of traditional voting methods This isn't true at all. There is not way to tamper with paper to make it change its properties that isn't obvious and easily detectable. And once votes are cast the ballots are handled with significantly more care.
- 8y ago
- the8472 8y agoThere are several conflicting requirements. Generally we want only those eligible to cast one vote each and yet the votes must be secret, anonymous and repudiable. But we also want the counting to be auditable by the public and traceable by the individual voter.
- mulmen 8y agoIt is absolutely impossible. There is no conceivable way to secure an electronic voting machine, especially one wired to a network. These machines solve a problem that does not exist with methods that are not necessary or well suited to the task.
- legohead 8y agoGovernments, credit bureaus, and banks haven't figured it out. You want to trust some random third party nobody the State contracts?