25 ms·
Internet voting is insecure and should not be used in public elections
- pepa65 9mo agoMy take: this is a paid-for hit piece to discredit a way of voting that makes total sense and is not all that hard to secure and make verifiable.
- tantalor 9mo agohttps://xkcd.com/2030/ https://xkcd.com/2030/
- randomcatuser 9mo agowhat about crypto voting schemes? zero knowledge and all that if we assume the user connection is secure (ie, about as secure as banking), can we have secure internet voting?
- burnt-resistor 9mo agoNot exactly. Centralized transactions on a blockchain ledger using hierarchical aggregation of tiers of voting collection points where each municipality includes their digital signature. And receipts for all voters that are easily verifiable against a publicly-readable ledger.
- pokstad 9mo agoWhile we’re on it, I don’t want the internet on my stove or car either.
- rexpop 9mo agoWe're actually not on that subject.
- MarkusQ 9mo agoIt's as close to on-topic as most of the other comments. "The internet isn't secure enough to trust for voting" could be generalized to "The internet isn't secure enough to trust for _____" just a reasonably as it could be to "______ isn't secure enough to trust for voting" as most of the other commenters have chosen to do. The fact that one of the generalizations is more popular doesn't make the other wrong, and addressing both (as, say, the GP or people talking about internet banking do) adds both depth and breadth to the discussion.
- FeistySkink 9mo agoIs this just an abstract and is there more to this post? I found it quite shallow.
- tamimio 9mo agoI think it’s just twisting the facts to reach a predetermined conclusion.
- ggm 9mo agoI live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your paper or walk away but we enforce with a fine, participation in the one obligation of citizenship) -I have been offered voting remotely in elections for my home economy of the UK and I would have welcomed some kind of homomorphic encrypted, secured voting method, given I have done KYC with the UK government to get my pension paid, I don't see there is a problem with them knowing who I am online. I therefore do not totally agree with the headline, but I'm willing to be convinced by the article, because comparing the land of hanging chad to my own, I think paper and pencil is just fine. BTW we have a senate election which demands ballot papers cut from A0 paper in long strips. Hundreds of boxes to be filled in. What we don't have is the vote for every judge, official, proposition on the table, we just elect representatives and senators, but we have a complex vote method. It just works. We do machine reading, but every single paper is reviewed by people, and parties have rights to monitor the vote, in secured spaces. We do not have a serious concern with the integrity of our vote, and the question is regularly asked and tested. (it's not just because we believe its secure and don't check) Its a great list of signatories, includes people I respect. I would think that the prime question for americans is "how much worse or better than the current approach could this be?"
- BurningFrog 9mo agoAustralia really uses erasable pencil markings to vote? I would feel much better if they required ink.
- b112 9mo agoIt's pencil in Canada too. Pencil works. Ink pens stop working, and are far more expensive than pencil in bulk. Voting is old. Using fountain pens, and quills to vote, is far more annoying than pencil when it just works. The mark of vote being indelible or not is irrelevant. The monitoring and protection of the ballots is far more important. For example, representatives of all political parties are involved in the count, oversight by an agency, etc. If you had time to erase and re-mark ballots, you could swap out paper ballets too.
- irjustin 9mo agoTom Scott made a solid video on this years ago[0]. I would love to go back to paper elections, even with all its problems (hanging chads anyone?). Let's make attack scaling as difficult as possible. [0] https://www.youtube.com/watch?v=LkH2r-sNjQs https://www.youtube.com/watch?v=LkH2r-sNjQs
- recursive 9mo ago"Go back to"? How are you voting now?
- nonethewiser 9mo agoA paper that gets scanned by a computer
- gpt5 9mo agoThe most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further deteriorate the election process, and could move us to a place where we completely lose control and trust of the election process. We should move back to paper voting.
- numbsafari 9mo agoPorque no los dos?
- travisgriggs 9mo agoWhat if some level of efficiency (not necessarily internet) improves turnout and participation?
- earleybird 9mo agoA question we all have to ask ourselves. What would I trade for efficiency?
- deathanatos 9mo agoAt least in the US, I think there are a number of suggestions that are made repeatedly each cycle here. Like "it should be a paid federal holiday", and not putting onerous requirements on voters. Automatic registration. The list goes on. But I what is written over and over is more on the lines of "I don't trust the process". I cannot blame anyone for not trusting Internet voting: I am a professional SWE, and it would be impossible for me to establish that any such system isn't pwned. Too much code to audit, hardware that's impossible to audit. But it's pretty trivial to demonstrate to the layperson how paper voting works, and how poll observers can prevent that process from being subverted.
- bikelang 9mo agoWe have mail voting as a default in Colorado. When you get your license you are registered to vote and opted in automatically. The one piece that might improve it further is if it came with a stamp to mail back. Otherwise you just drop it off at a drive-up ballot box. You can also vote in person if you want. Hardly anybody does it so there’s never a line. You get text messages each step of the process too. “Your ballot has been mailed”/“your ballot has been delivered”/“your ballot has been received”/“your ballot has been counted - thanks for voting”.
- Kim_Bruning 9mo agoEstonians seem to have funny ideas on this. They're very VERY digital-forward.
- TazeTSchnitzel 9mo agoAnd their system has the same problems as all the others: https://estoniaevoting.org/ https://estoniaevoting.org/
- Kim_Bruning 9mo agoLooks like. More recent papers still find vulnerabilities too. Steelmanning: They're putting the effort in so we don't have to. Either they find a way and it'll be awesome, or at some point they become an object lesson. edit: Or third path: They muddle along just well enough with a system that can't work in theory, but ends up nearly working in practice, stochastically? (see also: email, wikipedia, or a hundred other broken things that can't possibly work but are still hanging on. )
- DJBunnies 9mo agoI believe the piece we're missing is the government (citizen?) service which issues (manages, replaces, revokes) constituents' cryptographic tokens for use with such things. Then our voting systems could be electronic, secure, open, verifiable, and mostly private; assuming effective oversight / this organization does not issue fraudulent tokens or leak keys or identities (big assumption, but I don't think it's impossible.)
- FeistySkink 9mo agoYeah, we have certificates on our ID cards, but they need to be manually renewed every 3 years which necessitates a trip to the designated authority. And then the underlying system gets changed every so often invalidating the card types altogether, so they can be used as dummy IDs only.
- kaashif 9mo agoIsn't a vote being verifiably tied to a person actually a bad thing? Then you can actually check what e.g. your wife or kids voted for and punish them if they vote wrong. Or get people to pay for votes, but doing that at scale is obviously hard. Maybe this isn't what you meant by verifiable, but there are systems with this property and they are bad.
- DJBunnies 9mo agoVerifiable in this context means I can verify my vote was tallied correctly.
- BurningFrog 9mo agoThat would also mean someone could force you to show who/what you voted for.
- dghlsakjg 9mo agoNot necessarily. In Colorado they handle this by putting the ballot in a blind envelope inside a trackable envelope. I can verify the details of the receipt of that trackable envelope to the tallying center where it is verified as untampered and opened under video with multiple people present. The unmarked envelope is added to all the rest of the ballots to be counted.
- thegrim000 9mo agoYou know, kind of an interesting test here. This was posted 13 minutes ago and the comments so far are mostly all supportive of not wanting internet/insecure voting methods, all supportive of pen and paper. I wonder if after an hour or two the propaganda hoses will have been turned on and all the top comments start to have the reverse messaging in them, saying internet voting is perfectly fine, and such initial comments downvoted into oblivion.
- numbsafari 9mo agoWhose bots are fastest?
- terminalshort 9mo agoSo you are saying that the humans are fast and the propaganda bots are slow?
- biglost 9mo agoMore important it should be a right first. Where i live it's not optional
- foolfoolz 9mo ago* “all your money lives on the internet and it’s safe” * “internet voting is insecure” who wins?
- jpollock 9mo agoInternet voting needs to be anonymous and non demonstrable. Internet money needs to be the opposite, and reversible through the courts.
- terminalshort 9mo agoIt can't be anonymous. There has to be some form of IDV to ensure it is a registered voter.
- FeteCommuniste 9mo agoThe vote needs to be anonymous, not the registration + checkin process.
- deleted 9mo ago[deleted]
- phanimahesh 9mo agoWhen digital content can be duplicated with ease, it is difficult to guarantee verified voter but untraceable vote.
- dghlsakjg 9mo agoThe ballot has to be anonymous, or unable to be tied back to the voter once cast. It’s a hard requirement for a variety of reasons
- seanmcdirmid 9mo agoYou have to trust the voting place/ballot receiver in all cases. Like, after they take your name, you need to make sure that they aren't secretly associating your name with the ballot you are filling in. Likewise, if you vote by mail, you need to make sure that they aren't associating your identity on the envelope with the anonymous ballot inside the envelope.
- travisgriggs 9mo agoSo where is the thought on mail in these days? It’s what we have in Washington and I rather like it.
- tonymet 9mo agopaper & pen has tremendous value as a recording mechanism. Although it's slower at counting and indexing, it is far better at reproducibility and durability: * records last > 500 years with no electricity . corruption is obvious at first glance. ( bad records don't appear to be good). * counting is easily distributed by number of workers * readily visually inspected with no special tools . ideal for auditing * records stay in order at rest. * easy to detect & protect against tampering * easy to train new users . CRUD tooling costs pennies per operator * cheaper to scale writes & reads TCO and risk-assessment for paper records exceeds digital on nearly every measure.
- jayknight 9mo agoMy state uses a system that I think is the best of most worlds. You check in at one table, they give you a "receipt" that you give to another table who trades that for a little card. The card isn't linked to you at all and it gives you access to a voting machine. You enter your choices into the machine, which prints out a paper ballot that you can review and verify before putting it into the box as you leave. So, your vote is recorded by the voting machine for quick tallying, but your vote is also recorded on paper that is human and machine readable for verifiable re-counts if needed.
- tonymet 9mo agoIt’s a great idea , though the counting machine becomes a threat vector . Counting votes isn’t really that expensive . Certainly not compared to purchasing , maintaining and securing counting machine hardware I get that we all get paid to digitize things , so paper seems antiquated , but for many applications it’s the best solution
- ss1996 9mo agoI agree with the risks, the overall theme being it's much easier to potentially manipulate a million internet votes than physical. In other worlds, internet vote manipulation scales significantly more than physical. But I could make the argument with any high trust internet system. Let's take another high trust activity we do on the internet - banking. Internet banking gives a hacker the ability to steal millions while sitting across the world. This is the same argument the authors make about changing a million votes. So it really comes down to the pros vs cons. That's the more important discussion imo. Do the benefits of internet voting outweigh the cons?
- bschwindHN 9mo agoInternet banking is not anonymized. Voting should be.
- hydrox24 9mo ago> Let's take another high trust activity we do on the internet - banking. Internet banking gives a hacker the ability to steal millions while sitting across the world. This is the same argument the authors make about changing a million votes. Bank fraud happens all of the time and at scale. However, it is entirely insurable and reversible. Election fraud is not reversible. Trust cannot be restored in the way that a bank account can.
- iamnothere 9mo agoUnless you’re talking about crypto, your internet banking hacker will not get away with anything significant. You can’t just “hack the bank” and take a million dollars. Banks only transfer funds digitally to one another by agreement through systems like SWIFT, and these transactions are traceable and reversible. Changing some ones and zeros in your account and then attempting to withdraw it all would raise a ton of flags, and you would need to breach an unrealistic number of systems and processes to make it possible. At best you might be able to scam someone into sending you a few hundred dollars via Zelle. Some scam centers do this 24/7, but it isn’t that easy, and apparently they rely on human trafficking to acquire free labor. The complex systems backing internet banking (including the people and processes) are immense in scale. They evolved over decades and were honed and improved as real problems occurred. Needless to say, there is no room for iterative trial and error in elections. If you hack the bank you get very little, at least today. If you hack an election you get everything. No thanks. No to electronic voting.
- Panzer04 9mo agoTo some extent, I think the cost of paper voting is almost a feature. It takes more work and effort to corrupt a paper voting system enough to change an electoral outcome, it helps more people gain familiarity with the electrical process and places an additional weight on the decisionmaking,
- terminalshort 9mo agoWhich of these vulnerabilities do not apply to any other internet system? And yet all of everyone's money is accessible over the internet and that seems to be working fine. If they really care about security at this level then they should ban all non in person voting methods.
- GuB-42 9mo ago> If they really care about security at this level then they should ban all non in person voting methods. Many countries do exactly that, sometimes with a few exceptions (ex: expats, disabilities, ...). One problem with internet voting that does not apply to money is the "receipt-free" aspect. That is, a voter should not be able to prove that he voted for a particular candidate, as it would allow for vote buying, threats, etc... And it is a hard problem. With money transactions, you generally want the opposite, which is an easier problem.
- creata 9mo agoI don't know why so many people in this thread are asking this, but as has been said elsewhere in this thread: * It does apply to most other internet systems. * Things like banking fraud can be detected and remedied. Election fraud is much harder to detect and even harder to remedy. * Voting requires anonymity. Most internet systems are not anonymous: you are identified by your IP address at the very least.
- rmunn 9mo agoThe thing about paper ballots is that the ways to cheat with them are well-known ("finding" ballots in the trunk of a car, "losing" ballot boxes on the way to the counting center, counting the ballots behind locked doors with observers not present, and so on), and have been well known for centuries. So the counters to them (ballot boxes sealed with an official seal once full, only sealed ballot boxes will be opened and counted, neutral observers present at all times when ballot boxes are being transported and/or counted, and so on) are also well-known. If those anti-cheating counters are in place, that gives you quite a lot of trust in the results. And if observers get thrown out and then ballot counting continues behind closed doors, you can have a reasonable suspicion that cheating is going on, and can make a stink and demand a redo of the vote. With Internet voting, the ways to cheat are not all that well-known among the general population, and even among an audience like HN I bet we couldn't come up with all the ways to cheat. (That's not a challenge!) So there's going to be fundamentally less trust in the election process than with paper ballots, even if the Internet-voting system was actually made completely secure. (And I'm not persuaded it can be made completely secure, given that secret ballots are a fundamental requirement of the process). So yes, paper ballots are very much the way to go.
- rmunn 9mo agoOh, and if the election is on something so polarizing that there are no "neutral" observers, then rather than neutral observers you can have observers from both (or all) parties/sides present, with cameras rolling, while the counting is going on.
- john_minsk 9mo agoI strongly disagree. If the system is transparent enough and provides mechanisms for verification and control - No reason to distrust it. I would prefer a system where even in 20 years I can go online and check how my vote was counted in older elections - this way stealing my vote would be impossible. The issue is how to preserve privacy...
- rmunn 9mo ago> I would prefer a system where even in 20 years I can go online and check how my vote was counted in older elections - this way stealing my vote would be impossible. Understandable, but then vote-buying becomes possible. The reason vote-buying is impossible in a secret ballot is because you can't prove how you voted to anyone else. If you can look up your own ballot even five minutes after it's dropped into the box, then you can show your screen to someone else who then hands you $100 for voting the right way, and elections change from being "who has persuaded the most voters?" into "who has the most money to buy votes with?"
- tamimio 9mo agoI think this relies on the old argument that anything connected to the internet is potentially insecure. While it might have some truth, practically we all do very sensitive stuff securely while connected to the internet. The risk is there, always, but you put all the measures to mitigate it and even prevent it. The idea that a malware could be on a phone “altering things automatically” feels like a 90s FUD cliche. If an online voting system existed, it won't be like a poll that you see on Twitter, for instance; it will be far more involved. For example, we can have blockchain as the network, and not just transparent to all, but even after you vote you can still check your vote and see if it was potentially altered, and a proper electronic chain of custody can also ensure that the vote was counted per the process, and all of that is visible to anyone who would like to check and even count ALL the votes yourself, again, just like how transparent blockchain is. And saying paper voting is more secure isn't true at all, because these votes will be counted electronically at some point, either by a machine or just a simple Excel sheet, opening the same risks as the previous one except here, if it would happen, you will never know and you as a voter can't trace the vote from when you voted all the way until it was counted. The voting process should be designed in a way with zero trust in mind, just like how secure systems are designed now, like storage, encryption, vpn, etc., and voting should too. I personally believe that we can build a very secure, robust, and trustworthy system that can be used for voting online, but I think no one wants that for all sorts of political purposes, either by actually altering the results that could go unnoticed, or at least keeping the window open to blame the results on a faulty system.
- Vecr 9mo agoWhy is it FUD? It's a real thing any competent programming team could implement.
- tamimio 9mo agoWell it isn't primarily the technicality aspect but rather the same risks that apply to end users are also applied to the people working at the polling station and their equipment, bringing it up when you are talking about one side only is just a tactic to discredit it. That being said, modern phone OSes are also unlike before, app isolation among others prevent such attacks, I don't think I came across a new attack that just altered another app on the fly, otherwise, we would have hundreds of cases of people getting their bank accounts compromised. In fact, I think from a technical standpoint, the risks of having such malware on end users' devices are harder to implement compared to infecting say the Android OS running on the voting screen at the polling station, or anywhere else in the process. Because in the end users' ones you can restrict the app to run under certain criteria similar to banking ones, and independent security researchers can check it for potential vulnerabilities, meanwhile an internal app used in the polling station won't have these measures, and you can even assume the OS/packages are outdated and vulnerable, making it far less secure, something like how flock cameras Android OS is a security nightmare for example.
- davidmurphy 9mo agoI agree.
- deleted 9mo ago[deleted]
- alanwreath 9mo agoIt’s not that it’s impossible - it’s that the established players are already questionable. And any new entry would require more than any simple company could provide. Heavy investment and collateral is required. Our livelihoods are increasingly (almost entirely) digital and endure great efforts to abuse. But banking and/or retail operate on a different spectrum. For one they make money. The costs associated allowing their business online may never make sense for a non-profit based activity like voting. Do we have any examples of internet activity as tempting to infiltrate/pervert that is secure and doesn’t extract value? Anyways it seems greater damage will be done before we even reach a provably secure system. So paper/pencil voting would be better. But fear not - even if we abolish voting machines we aren’t out of the hole just yet. We have good company with concepts like Citizens United as well as activities like sweepstakes that try to sway the populace to throw away a vote for a chance at a million. Illegal - sure - but that won’t stop the ostensible infinitely wealthy from enduring a slap on the wrist - or more appropriately a verbal reprimand (which is all that happened last time) for their part in electioneering. And if that didn’t work we have an onslaught of reAlIty and bots that poison our conversations in order to form our world views. I’m jaded. I’m overly pessimistic. I’ll go now.
- nerdponx 9mo agoPrediction: In 2026 the Trump administration will attempt to ban all other forms of voting and will claim that it is in the interests of election security, because the Democrats can't be trusted to count votes (remember the 2020 election was "stolen"?), so we need to mandate all votes be counted electronically using some sketchy electronic voting system, which a company that is very politically friendly to Trump just so happens to be ready to provide. It will get immediately shot down in several courts but it will take months to resolve all the lawsuits, and SCOTUS won't hear the case. This will cause the election to be held in some places but not others, and overall delay final vote tally by several months. Some kind of data breach will occur but details will not be reported. Neither party will trust the election results but won't go so far as to call fraud lest public trust in the system completely unravel.
- alanwreath 9mo ago
- tedk-42 9mo agoVoting is one of those things that people care very little about but it's extremely important as it can determine who is the head of state (a position that has a lot of power an influence). A single compromise once can have incredibly bad long term consequences for the majority of a ruling elite gain power indefinitely.
- burnt-resistor 9mo agoIn person and by mail voting with a blockchain ledger-based receipt is how to prove one's vote is counted anonymously. There must always be a paper trail and a blockchain ledger provides the most reliable and secure means to maintain integrity.
- nerocap 9mo agoIf we can’t create a secure online voting system why do we use it for passports, banking, medical records, drivers licenses, criminal and law record keeping. This is just an attempt at control using the majority of cases that most websites and applications are insecure. If enough effort and time is invested of course we can create a fairly robust and secure voting system.
- iamnothere 9mo agoErrors in these other areas are typically reversible without undermining trust in electoral processes, leading to (in the worst case) wide scale violence and death. We use the internet for too much, more systems should be airgapped. It’s a miracle that there hasn’t been a tragedy yet from a hack of critical infrastructure. Even things like water treatment and energy systems can be vulnerable: https://www.cnbc.com/2024/10/08/american-water-largest-us-water-utility-cyberattack.html https://www.cnbc.com/2024/10/08/american-water-largest-us-wa...
- charcircuit 9mo agoElections are reversible too. A recount can reverse an election.
- iamnothere 9mo agoAs long as the chain of custody is maintained, a recount of a paper election is repeatable and can be verified with physical artifacts (ballots). Unlike a paper election, there is no tangible evidence that records have been maintained securely. Additionally, even if a box of ballots is stored insecurely or somehow goes missing, in most cases it isn’t a showstopper as the margin of votes is still comfortable enough to have a clear winner. Except in very close elections, traditional paper elections are almost impossible to manipulate successfully if the custody and counting process includes representatives from opposing political parties. (Week long counting periods that accept a million delayed votes are another story, but that is a process issue and a deliberate decision to weaken electoral integrity.)
- 9mo ago
- zwranadikos 9mo agoSo my internet banking is secure for my funds, but internet voting is not for my vote. Right... OK, we got the message.
- deleted 9mo ago[deleted]
- autoexec 9mo agoInternet banking is not secure. People's accounts get hacked all the time. Your bank transactions aren't a secret from your bank though. There are a lot of eyes on your accounts (including your own) and corrections can be made after the fact. No one (including yourself) can be allowed to look up how you voted later.
- nonethewiser 9mo agoBanking errors are detectable and reversible. You also arent anonymous.
- anon291 9mo agoIf you had enough money such that reversing fraud would become a huge hindrance for your bank, you probably cannot initiate any major monetary moves without the involvement of a real person, likely one you actually know. Online banking is for amounts which the bank will just compensate you for should something happen; just a cost of doing business.
- AngryData 9mo agoInternet banking has security breaches and errors more often than you might think, it is just much easier to track down and retroactively fix any problems. The problem with elections is retroactively fixing a voting problem doesn't always happen and some of the most powerful people and groups have interests in preventing it and the common people have little real recourse when the cards come down other than rioting and potentially insurrection before they know the true results.
- GJim 9mo agoBaking and voting have a completely different set of requirements and security risks. To suggest a direct comparison is idiotic.
- uptownhr 9mo ago2 factor vote. Vote in app, still go in person to validate result.
- manoDev 9mo agoImagine that: thinking the technology used to cast votes is how elections get manipulated.
- quilombodigital 9mo agoIn Brazil we have been using electronic voting for decades. See, here we always had issues with corruption, and thats why we had to implement it. The thing is that we always had major issues at the city level elections, because many small groups dominate different regions, and they just controlled the election officials, influenced voters, disappeared with ballot bags, and did all types of crazy stuff. It was pretty common at the eighties exchange votes for gas, dentures or even tubal ligation. For all this reasons, a specific voting registry was created in 1985, and an electronic voting machine was used for the first time in municipal elections in 1995. This solved most issues, and elections started to be a lot easier, there was A LOT of confusion in the past. After it was available in all cities in the country, they started to do national elections. The main idea here is that this is a government endeavour, not a private company. There are so many security layers that I think that only another external government actor would have resources to attack it. These machines have special hardware, the encryption keys are loaded at the election day by the government, the machines are there only for the 8 hours of voting, then came back to a government deposit, they account for every machine, they are audited before and after, they randomly choose the election officials, the machine prints a receipt for the voter and the stats of votes of that machine. Each person has an election location and room/machine, so schools are used. If a machine has problems, they have to on the fly generate new keys for a substitution. In 2024 they used 570.000 machines at the election. When the election day finishes, they place at the door of the room the machine receipts, so any ONG or international organization can verify. After it they take the machine to a central place where they connect to them and trasmit the data, and in one hour we know the president. During these decades we had presidents from the right and from the left, and all cities and states, so you can say it works just by seeing all this power cycling all the time. I agree with the article in the sense that we need paper confirmation, and that we cannot trust the voter machine, but I think Brazil solved this by making sure to control the machine, and printing receipts and making then available to any public organization. I particularly think that only one thing is missing in this technology, technically speaking, I would like to have a personal key with an ecc key created by me, that would allow me to insert this card when voting, so it would encrypt my vote, store and send to the server, so I could, using my card (even online) check for my voting history, connecting all the endpoints. It is still anonymous, but verifiable by me. More information here: https://international.tse.jus.br/en/electronic-ballot-box/presentation https://international.tse.jus.br/en/electronic-ballot-box/pr...
- niteshpant 9mo agoAnd Nepal elected its current interim prime minsiter using Discord, apparently...
- oskenso 9mo agoI came here to mention this. At the end of the day it's a circle of trust that keeps things moving in a positive direction
- legutierr 9mo agoThe article talks about being “receipt free” as a required feature of any electronic voting system. Fine. But by that standard, in a world where someone can bring their phone or AI glasses into the voting booth to record the whole voting process, how can any voting system be deemed secure? Anyone can show anyone else how they voted.
- maxerickson 9mo agoIt's not about showing how you apparently voted, it's about not being able to prove it. You can record a picture of a ballot and then spoil it and things like that.
- crote 9mo ago> But by that standard, in a world where someone can bring their phone or AI glasses into the voting booth to record the whole voting process That's why some countries have outlawed that.
- GJim 9mo agoFilming or recording in a ballot booth is very illegal in Blighty. (Granted, nobody is going to see you do it in a private booth with the curtain pulled across).
- elbasti 9mo agoVoting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1. Everyone votes, on paper, in their local polling station. The polling station is manned by volunteers from the neighborhood, and all political parties have an observer at the station. 2. Once the polling station closes, votes are counted in the station, by the neighborhood volunteers, and the counts are observed by the political party observers. 3. Vote counts are then sent electronically to a central system. They are also written on paper and the paper is displayed outside the poll both for a week. The central system does the total count, but the results from each poll station are downloadable (to verify that the net count matches), and every poll station's results are queryable (so any voter can compare the vote counts displayed on paper outside the station to the online results). Because the counting is distributed, results are available night-of in most cases. Elections like this can be gamed, but the gaming becomes an exercise in coercing people to vote counter to their preference, not "hacking" the system. ** Edit: Some people are confused about what I mean by "coerced." Coerced in this case means "forced to vote in some way." The typical way this is done is as follows: - The "coercer" obtains a blank ballot (for example, by entering the ballot box and hiding the ballot away). - The blank ballot is then filled out in some way outside the poll station. - A person is given the pre-filled ballot and threatened to cast it, which they will prove by returning a blank ballot. - Rinse and repeat. This mode of cheating is called the "revolving door" for obvious reasons.
- nonethewiser 9mo ago>Elections like this can be gamed, but the gaming becomes an exercise in coercing people to vote counter to their preference, not "hacking" the system. If that's gaming the system, what even is the point of voting?
- idiotsecant 9mo agoAre you suggesting that voting is pointless because some people can be convinced to vote for stupid things?
- artyom 9mo agoPremise: there's people that will try to game and cheat on anything that's important, including democratic elections. No matter your voting method, those people will exist. Solution: the basic unit (paper ballot in this case) can be understood by any adult with basic education, which means anyone can detect cheating, not just a technical wizard. The only skill you need is reading. Give me a solution that follows the same principle and I'd consider it. Nobody cares about results coming faster except journalists that have to fill 2-3 TV hours with nonsense until there's some numbers. No engineer that's worth of the title would advocate for electronic voting -- unless they're in the business of selling electronic voting. See the Premise.
- nonethewiser 9mo agoIm not sure all paper ballets means delayed election results. Sure, it used to take days or weeks 100 years ago, but the only factor now is the counting.
- SilentM68 9mo agoWith the world the way it is now a days and software/firmware being insecure, it is difficult to see Internet Voting as a secure means of voting. Paper ballots with multiple biometric tools or AI to measure a voter's physiological state of mind, honesty, confirm identity may be something that should be considered.
- plasticeagle 9mo agoI applied for my passport online. If it's secure enough for that, then it's secure enough for voting.
- GJim 9mo agoDifferent use cases with different requirements.
- kayamon 9mo agoThis is an alarmist headline and should be reconsidered before being posted anywhere.
- protocolture 9mo ago>Malware on the voter’s phone (or computer) can transmit different votes than the voter selected and reviewed. Voters use a variety of devices (Android, iPhone, Windows, Mac) which are constantly being attacked by malware. Yeah see this is where I thought this was going. Phones can be insecure, but in aggregate they are secure enough for literally every other component of life to be conducted on them. >Malware (or insiders) at the server can change votes. Internet servers are constantly being hacked from all over the world, often with serious results. Again, great point. Accepting this point will the government erase all the private identifiable data it has collected on me from its systems? Probably not, because they have made a cost/benefit analysis that suggests the risk is middling compared to the reward. >Malware at the county election office can change votes (in those systems where the internet ballots are printed in the county office for scanning). County election computers are not more secure than other government or commercial servers, which are regularly hacked with disastrous results. This seems like a weird seppo thing. Currently the risk of an election being seen as fraudulent is high, and the reward of online voting is low. But we dont have to conceptualise the modern boring election when we look at online elections. We can look at alternative models, closer to real time use and other gains that tip things back in its favor. Actually the biggest issue I see with online democracy is apathy and minimum quorum sizes.
- arjunchint 9mo agoHonestly we should just have block chain based PUBLIC voting. This article is right about secret internet voting: it’s fundamentally incompatible with unsupervised devices and global networks. But secrecy is the constraint that breaks everything. If you instead require public, verifiable voting, most of the "unsolved" problems disappear. The core requirement becomes: everyone can independently verify inclusion and correct tallying. That’s where blockchains are a genuine game-changer: - They provide a public, append-only, tamper-evident system of record. - Anyone can recompute the tally from first principles — no trusted servers, no “checker apps,” no special dispute resolution. - Server compromise or insider attacks stop being catastrophic; fraud becomes immediately visible rather than silently scalable. - Malware can still affect an individual’s vote, but it can’t secretly change the election at scale — the main failure mode highlighted in this post. If trust is the goal, opacity is the wrong primitive. The secret ballot is mistaken path solving a non existent and purely theoretical problem of vote buying. In a world where we expect everything to be easily accessible, the hardships placed by all the steps required to vote (registration, confirming residency location, waiting in line for polling booth) is seriously impacting voter participation. We need to get with the times and modernize this voting infrastructure.
- whimsicalism 9mo agoof course, then you get vote bribing and retaliation. i'm generally in favor of public or provable voting because i think it is the best solution - but you do have to sort of how eyes wide open.
- arjunchint 9mo agoWe are a society of adults and complex individuals that don't need to be moralized to or nanny'ed. You can easily bring up bribing and retaliation as excuses why we shouldn't have jury trials either. These were never really fundamental problems with open democracy, like Andrew Jackson didn't bribe everyone in the country to become president. TBH if a politician offered me $100 to listen to his pitch, I would take it but I would still vote based on the thousands of dollars of lifetime impact of their policies on my income and assets.
- 9mo ago
- TacticalCoder 9mo ago[flagged]
- deathanatos 9mo ago> Not requiring a proof with a photo of the person and a proof that he's legally in the US should not be allowed in public elections. This is essentially (esp. once combined with the rest of your comment) misinformation: fraudulent voting by non-citizens effectively doesn't occur[1]. To sum it up, > A Brennan Center for Justice study of 2016 data from 42 jurisdictions found an estimated 30 incidents of suspected noncitizen voting out of 23.5 million votes cast (or .0001% of votes). I.e., a rounding error. > How comes the democrats try to block every single voter ID act? Sounds to me there's something to hide. Generally, the counter argument is that further requirements stifle voters, while not solving any real problem, since the above concern is not backed by actual facts demonstrating it to be a valid concern. > There has also been some very shady counting happening in 2020: where during the last hours suddenly 100% of the votes coming in in some states where all for Biden. You're assuming the vote is uniform, and it's pretty trivial to show it's not; look at any vote-by-county map, and you'll see urban centers are far more Democrat heavy. Expecting the tallying to then be uniform is illogical. > Note that Trump, […], said His words are beyond bereft of trust[2]. > I'd add that, in my opinion, bringing in millions of illegals then trying to regularize them and allow them to vote is also a form of election rigging, even if it's legal. [citation needed], but this isn't a thing. No jurisdiction I know of permits non-naturalized immigrants, legal or otherwise, to register to vote. If they've been naturalized, voting is their right, same as it is mine. [1]: https://en.wikipedia.org/wiki/Electoral_fraud_in_the_United_States#Noncitizen_voting https://en.wikipedia.org/wiki/Electoral_fraud_in_the_United_... [2]: https://en.wikipedia.org/wiki/False_or_misleading_statements_by_Donald_Trump https://en.wikipedia.org/wiki/False_or_misleading_statements...
- tzs 9mo agoIt is possible to have a system that works as follows: 1. People vote on paper ballots by filling in an oval next the candidate they wish to vote for. They fill the oval with a marker provided by the election officials. 2. These ballots can be counted by hand, but they can also be counted by optical scan machines to get fast results. Optical scan machines do not have to be computerized--they have been around since the 1950s long before there were computers small enough and/or cheap enough to use for this. No computer means no software to get hacked. Almost half of registered voters live in districts that already use that kind of ballot and already count it with optical scan machines. 3. By the use of some nifty chemistry and some clever cryptography an end-to-end auditable voting system can be overlayed on this. End-to-end auditable voting systems (also called end-to-end voter verifiable systems) have these properties: • Individuals can verify that their ballot was included in the final count and they vote was attributed correctly. • Any third party can verify that the ballots were counted correctly. The candidates, the parties, news organization, civil rights groups, and anyone else can check. • Voters cannot prove to third parties who they voted for. This is called coercion-resistance. Here is such a system, developed by several well known cryptographers including David Chaum and Ron Rivest [1]. Here's a paper in HTML with the details [2]. Here's a PDF of that paper [3]. Here's a paper showing that it is coercion-resistant. This is compatible with existing optical scan machines, so the places already using them don't need new machines. The magic happens in printing the ballots. Inside each oval they print a code in a special invisible ink. When the special marker provided by the election officials is used to fill in the oval that code becomes visible. If you want to be able to later verify that your particular vote was included and counted correctly you memorize or write down that code. If you don't care about this you can ignore it. After the voting is done officials can publish all the codes that were revealed and voters can check to make sure their code was included. They officials publish other information that through the use of clever cryptographic techniques allows anyone to use the published codes to verify the totals for all the candidates without revealing the mapping from codes to candidates. This gives us all the good points of paper systems that can be hand counted, plus fast machine counting that can be done with simple single purpose machines that have no software to be hacked, yet with the kind of end-to-end auditing that usually requires computerized voting systems to achieve. And it is inexpensive to implement and operate. [1] https://en.wikipedia.org/wiki/Scantegrity https://en.wikipedia.org/wiki/Scantegrity [2] https://www.usenix.org/legacy/event/evt08/tech/full_papers/chaum/chaum_html/index.html https://www.usenix.org/legacy/event/evt08/tech/full_papers/c... [3] https://www.usenix.org/legacy/event/evt08/tech/full_papers/chaum/chaum.pdf https://www.usenix.org/legacy/event/evt08/tech/full_papers/c... [4] https://eprint.iacr.org/2010/502.pdf https://eprint.iacr.org/2010/502.pdf
- JanisErdmanis 9mo ago> It’s difficult to make an E2E-VIV checking app that’s both trustworthy and receipt-free. The best solutions known allow checking only of votes that will be discarded, and casting of votes that haven’t been checked; this is highly counterintuitive for most voters! Actually, Benaloh's challenge also does not offer receipt freeness. The adversarial strategy in such a model is to outsource the challenger itself in a hash function which decides whether to accept or discard the vote. It may look impractical at first, but one can build an app that could do that efficiently. It can be said that all existing end-to-end verifiable remote e-voting systems compromise individual verifiability when reconciling it with receipt-freeness by introducing an assumption about the hardware-based protection of voters' secrets. If they leak or are predetermined by a corrupt vendor implementation, the malware on the voter's client can manipulate the vote at submission, and the adversary later fakes verification for the voter by exploiting that knowledge. Still, I believe it's a solvable problem which needs more attention. Bingo evoting system is almost there, for instance, with verifiably random generated trackers, but needs a voting booth with a Bingo machine taken at home.
- vvpan 9mo agoAnd a favorite Phrack article on the same topic - Internet Voting: A Requiem for the Dream [1] [1] https://phrack.org/issues/69/11 https://phrack.org/issues/69/11
- jcynix 9mo agoElectronic processes are way to easy to rig one way or the other.: Tom Scott: Why Electronic Voting Is Still A Bad Idea https://youtu.be/LkH2r-sNjQs https://youtu.be/LkH2r-sNjQs Sure, there are ways to cheat with paper votes too. But counting paper ballots should always be open to watch for voters interested in observing the process. And voting should be done in secret, disallowing photos, to make it hard to "prove" the vote to possible buyers.
- ronbenton 9mo agoThis is usually a smart crowd. I’m utterly mystified at the number of comments in this thread confidently stating that the US must go back to paper ballots when 99% of the country already uses them. It just takes a quick google search to know this.
- charcircuit 9mo ago>Voters should not be able to prove to anyone else how they voted – the technical term is “receipt-free” – otherwise an attacker could build an automated system of mass vote-buying via the internet. But receipt-free E2E-VIV systems are complicated and counterintuitive for people to use. This can easily solved be done via letting people forge receipts. Then anyone can forge a vote to give to someone offering to buy them. The receipt is in fact the best part of such systems as with paper voting it is impossible to verify if your ballot was counted or if it got "lost."
- lacunary 9mo agothen it's not a proof of who you voted for
- charcircuit 9mo agoYou would know which would be the real one and which you forged. Obviously when checking that your vote was properly counted you wouldn't use a forged one.
- crazygringo 9mo agoI'm not sure if there's a way to make forging work. You can't forge a new ballot, because ballot IDs are necessarily public, and are cryptographically tied to a voter ID in order to ensure votes are valid and that everybody only votes once. But it seems like nothing is stopping you from looking up ballots at random until you find the votes you want, and then claiming that was your vote. And if someone else got paid for the same one, then claim they're the one lying, not you?
- charcircuit 9mo agoYou don't forge a ballot. You are forging the proof of your vote.
- deleted 9mo ago[deleted]
- dogemaster2025 9mo ago[dead]
- casey2 9mo agoIf half the points here were true than internet banking and ecommerce would have already failed. Does the current system prevent fake votes? Did old banking and commerce prevent more fraud? Here is the thing you are missing. With Internet voting we can have votes way more often. Limiting the damage caused by fraud. Yeah you could have malware on your phone that changes your inputs to a sandboxed voting app, and the malware also tracks your real votes so when you request an audit it shows you what you actually voted for. In reality that is extremely difficult to pull off over a long period of time. I don't care about any of the names on the list, as far as I'm concerned they are missing the forest for the trees.
- parentheses 9mo agoThe problem is that nothing is immutable about computing. Software itself is mutable. So is data. The transferability of software makes hardware mutable also. It seems like pen and paper is currently the best verifiable and immutable voting approach.
- themafia 9mo ago> The problem is that nothing is immutable about computing. That's why we have checksums. We've used computing to put people on different astronomical bodies. There is a way, but it comes with a huge cost. Cryptocurrency strongly hints towards a way to make internet voting viable. > It seems like pen and paper is currently the best verifiable and immutable voting approach. The simplest answer is usually the best, but then you shouldn't constrain voting to a single day otherwise it disadvantages large swaths of the population.
- parentheses 9mo agoWith the recent success of AI, I feel the more insidious issue is preventing the use of AI in reading paper ballots. There's a lot of room to engineer bias.
- ripped_britches 9mo agoVoter turnout might increase drastically if we solve security, so it’s a worthy problem to solve
- mspecter 9mo agoHey all, coauthor here. Interesting to see it on Hacker News. I'm a professor in Georgia Tech's CS dept that works on problems related to security, privacy, and public policy. (CV: https://mikespecter.com/ https://mikespecter.com/) Happy to answer any questions you all have.
- stoneforger 9mo agoVoting needs to be auditable and verifiable by the lowest common denominator, to the last voter. As such anything that involves anything more complicated than counting by hand is out.
- kuerbel 9mo agoHave you had a look at the Swiss post e-voting system and how it deals with verification?
- mspecter 9mo agoI have not personally, but there's some fantastic work on the subject: https://ieeexplore.ieee.org/abstract/document/9152765?signout=success https://ieeexplore.ieee.org/abstract/document/9152765?signou... They find a few really bad issues. IIRC, the Swiss Post is looking into improving it, with the consultation of real cryptographers, so we'll see how that goes!
- snvzz 9mo agoVote should be in person at a designated place, based on a census. There's absolutely no justification (or excuse) for anything else. It is much better to have less votes than to allow any avenues for manufacturing the results.
- victor_vhv 9mo agoI live in Spain, and we have paper-based elections. Similar to what I've read from other comments, in our system, people are randomly selected to participate in oversight and counting. Different actors in the elections are able to oversee the process and count. Counts are performed by the randomly selected people and sent to headquarters from the site itself. Then, each ballot box count is available for display right after the counts are completed. Ballots are transported by the police to a safe location in case a recount is needed or randomly selected. I'm leaving out other measures and details, but you get the general idea. I used to flirt with the idea of a digital voting system, but now I clearly see that it is a problem of scale. It's very difficult to interfere with an election at scale when many independent actors and parallel flows are in place. This is what provides the system with its trustworthiness. However, I think fraud is moved elsewhere (with campaign funding, fake news, and other methods...), but that's a whole different topic
- mbf1 9mo agoIf I can photograph a $10,000+ check with my phone and deposit it into my bank via an app, then people can surely create a secure voting app with the same technology. Maybe we should use blockchain technology to store public ballots in an open fashion. Who cast the ballots would be a secret like it always is.
- Gud 9mo agoDifferent use cases.
- ValveFan6969 9mo agoInternet voting in general in not only insecure but an human rights act violation against our species. Look none other than the fascist utopia that is YCombinator where some rando can remove your comments simply because they do not like your joke or opinion.
- kuboris 9mo agoMandatory Tom Scott video why electronic voting is a bad idea: Original: https://youtu.be/LkH2r-sNjQs?si=okd-iy_6JTRmmoqe https://youtu.be/LkH2r-sNjQs?si=okd-iy_6JTRmmoqe Second part: https://youtu.be/w3_0x6oaDmI?si=EpS7SXd7Boe_1jn5 https://youtu.be/w3_0x6oaDmI?si=EpS7SXd7Boe_1jn5
- PeterStuer 9mo agoTrue. Mail in voting suffers from some of the same issues. We go to great lengths (cabins, curtains, no pictures allowed etc.) to ensure people can verifiably cast a free will vote, then open a giant loophole for potentially coerced, non private or transactional voting.
- GrowingSideways 9mo ago[dead]
- KurSix 9mo agoThis feels like one of those cases where the technical consensus has been clear for years, but the policy and media narratives keep resetting to "maybe this time it's different."
- touwer 9mo agoYou need a private, secure booth, as you cannot guarantee really free (of mind, body) voting via internet, because of coersion, threats. Women threatened by their men to vote-anti women. Religious coercion. Internet voting will always be anti-democratic.
- kundejenny 9mo ago[dead]
- kundejenny 9mo ago[dead]
- StoneAndSky 9mo agoAgree with everything being said here. However, it is no longer even remotely paranoid to be concerned that the current administration plans to do one or more of: 1. Put its thumb on the scale by "guarding" urban polling places with paramilitary forces on election day, 2. Declare mail-in ballots illegitimate and seize them, 3. Seize voting machines or attempt to stop vote counts before all votes are counted, 4. Intimidate state legislatures by threats or economic blackmail to disregard results. I don't see an alternative to trying to figure out how to make online voting secure. That won't solve (4) but it will at least mitigate some of the more direct methods of election fraud.