17 ms·
Software used to count Australian Senate votes is a “trade secret”
- quink 12y agohttp://www.zdnet.com/au/senate-calls-for-release-of-aec-vote-count-source-code-7000031437/ http://www.zdnet.com/au/senate-calls-for-release-of-aec-vote... http://www.brisbanetimes.com.au/it-pro/government-it/vexatious-digital-activist-forces-australian-electoral-commission-to-release-secret-computer-code-20140710-zt27i.html http://www.brisbanetimes.com.au/it-pro/government-it/vexatio...
- mjec 12y agoThe Electoral Commission has since refused to comply with the Senate order to release the source code: http://lee-rhiannon.greensmps.org.au/sites/default/files/ronaldson_response.pdf http://lee-rhiannon.greensmps.org.au/sites/default/files/ron...
- harkyns_castle 12y ago"I am advised that publication of the software could leave the voting system open to hacking or manipulation". Well, if the problems are there, opening up the source to more eyes strikes me as the obvious thing to do; or should those with the knowledge of how to manipulate it as it stands be kept to the bare minimum? :) But in any case, at least the meat of the implementation of the algorithm should be OK to release I would've thought - surely that isn't someone's intellectual property? This is software we paid for and strikes me as pretty important to the democratic process, I'd like to have a bit of a look at it.
- XaspR8d 12y ago> "I am advised that publication of the software could leave the voting system open to hacking or manipulation". Certainly reminds me of this xkcd: https://xkcd.com/463/ https://xkcd.com/463/ It sounds like security...
- harkyns_castle 12y agoI hadn't seen that one :) Someone above mentions its VB6 with embedded SQL Server upgraded from COBOL [1]. Can sort of see how they don't want anyone looking at it now. 1. https://news.ycombinator.com/item?id=8039958 https://news.ycombinator.com/item?id=8039958
- evolve2k 12y agoIt seems to be an ongoing misconception in the public, that part of good security is obstification. Know of any simple clear articles I could point people to when they make these sort of ("because Hackers might see") claims?
- raving-richard 12y agoA smart cookie could vote in such a manner as that when the information is entered into the system, it crashes it? Maybe that's what they mean by manipulation... Or, is it available online without any authentication other than knowing where it is? So if you know where it is, you could enter votes and then manipulate the election with those fake votes...
- jacques_chester 12y ago> A smart cookie could vote in such a manner as that when the information is entered into the system, it crashes it? "Informal" votes -- ballots where the voter does not correctly fill out the ballot paper -- are rejected from the tally by the counters under supervision from scrutineers. If you use hexadecimal, it will be rejected. If you use a very large number, it will be rejected. If you use weird unicode characters, it will be rejected. If it's anything other than a) a single [1] "above the line" or a fully filled-out ballot "below the line" comprised of numbers from 1-n where n is the number of candidates-1, it will be rejected. If it's crashing on properly filled-out votes, there's a bigger problem.
- quink 12y agoHi mjec, thanks. I didn't know about this latest turn of events! This quote in particular is extremely disturbing... I noticed it in the FOI rejection, but now they're telling this to the Senate: > In relation to the source code for the Senate counting system, I am advised that publication of the software could leave the voting system open to hacking or manipulation. This was after the Senate asking, this argument has nothing to do even with the FOI request. And a previous thread on reddit: http://www.reddit.com/r/australia/comments/29t2q7/aec_threatens_to_have_foi_applicant_declared/ http://www.reddit.com/r/australia/comments/29t2q7/aec_threat...
- quink 12y agoOK, just noticed Josh Taylor posting this article on ZDnet in the same minute as this comment's parent: http://www.zdnet.com/au/government-blocks-aec-source-code-release-on-hacking-fears-7000031646/ http://www.zdnet.com/au/government-blocks-aec-source-code-re...
- zmmmmm 12y agoI'm only replying to say a personal thank you for pursuing this. Australia has such weak individual rights, it is so important that people like yourself put your hand to pursue them on occasions like this when it is important. Keep going!
- cottsak 12y ago@mjec, "I am advised that publication of the software could leave the voting system open to hacking or manipulation" Shouldn't this "advice" demand substantiation or evidence? Surely it's not enough for one to just get "advice" right? If so then any Joe could lie to this officer and they could write the same thing. Also, what does that bit about "commercial-in-confidence" mean?
- mlandauer 12y agoThere is a follow up freedom of information request on trying to get some more information about that advice here https://www.righttoknow.org.au/request/documents_informing_the_response https://www.righttoknow.org.au/request/documents_informing_t...
- mjec 12y ago> Shouldn't this "advice" demand substantiation or evidence? I think so, and evidently so do others. Already a gentleman by the name of Brendan Molloy has put in an FOI request for the documents on which this advice was based: https://www.righttoknow.org.au/request/documents_informing_the_response https://www.righttoknow.org.au/request/documents_informing_t... > Also, what does that bit about "commercial-in-confidence" mean? The AEC does conduct some elections on a fee-for-service basis - things like union elections. They use a version of the same system to tally votes in those elections too. They say that the two systems are totally inseparable, to the point where you can't just cut out the code used in industrial elections. They also say revealing the code (though keep in mind it would still be copyrighted, so couldn't be used by any other organisation) would cause them significant commercial disadvantage. Because they have particular efficiency in the way their software operates which causes them to be more competitive. As you might suspect, I disagree with pretty much every part of what they claim there.
- josephg 12y agoThats appalling. As an Australian citizen, who should I call about this to voice my objection?
- cheald 12y agoThat's a trade secret.
- bobbles 12y agoThe process is proceeding as it should regardless. Anyone is able to put in a GIPA request, and they are allowed to refuse the information. As stated in the post an appeal of that decision is underway. We need to start caring if the appeal is also refused. Edit: GIPA is the NSW equivalent: http://www.ipc.nsw.gov.au/privacy/gipa_act.html http://www.ipc.nsw.gov.au/privacy/gipa_act.html
- robzyb 12y agoAs a fellow Australian citizen, I would also like to know this.
- mjec 12y agoWrite to your Senator, say the AEC's refusal to comply[1] with Senate Order 330[2] is wrong and you'd like it challenged. (Note that while it was moved by a Greens Senator, I'm not affiliated with the Greens and this is not a party political thing that's going on) Failing that, maybe consider donating to my fund to fight this decision in court: http://pozi.be/easycountaat?ra=247325 http://pozi.be/easycountaat?ra=247325 [1]: http://lee-rhiannon.greensmps.org.au/sites/default/files/ronaldson_response.pdf http://lee-rhiannon.greensmps.org.au/sites/default/files/ron... [2]: http://lee-rhiannon.greensmps.org.au/content/news-stories/update-public-release-secret-senate-voting-system http://lee-rhiannon.greensmps.org.au/content/news-stories/up...
- quink 12y agoYou have a set of questions for this Abbott-led government regarding technology backed up by legitimate concerns? Save your time, I already know the response to that. It's 'Get Fucked'. And that was before the election. http://delimiter.com.au/2013/08/07/get-fucked-turnbull-staffer-turns-on-blogger/ http://delimiter.com.au/2013/08/07/get-fucked-turnbull-staff...
- colmmacc 12y agoVisibility of the source code is a side-show in electronic voting systems. Even if the source code is published, there is no way to be sure that that is the code that is running on the hardware, or to be certain that the hardware itself has not been tampered with. Votes need to be printed out on paper, verified by the voter, and counted by hand. Still, when we had the source code for the Irish system (now abandoned due to our efforts) analyzed by a commission, it was found it had actual counting errors. http://www.stdlib.net/~colmmacc/www.cev.ie/htm/report/part4_2.htm http://www.stdlib.net/~colmmacc/www.cev.ie/htm/report/part4_... Amazing!
- mlandauer 12y agoThe Australian software is not used for recording votes. It's used to assist the counting of physical ballot papers because the Senate vote counting system is extremely complicated. In this environment it's more straightforward to ensure the integrity of the software (as long as it's open and verifiable of course)
- colmmacc 12y agoIn that case a simpler fix would be to allow any independent party (within reason) to supply and use their own software and render their own tally. If the parties are mutually distrusting, and their tallies still agree, that can be enough to trust the outcome. Auditing the source code has no real utility; it's worthless because you can't be sure that the code you've audited is the code actually running. "Open and verifiable" means nothing in that context.
- mlandauer 12y agoI would prefer if the input to the software was published and anyone could verify the outcome. Unfortunately, currently none of this information is published and the whole system is based on trust.
- colmmacc 12y agoLet's say that the software is published, and the code is audited and it looks ok - it seems to implement all of the intricacies of the transfer system and so on correctly. Then what? What if the operator forgets to use the latest version? or puts a different piece of software entirely on the counting system? Having audited the source code really doesn't help; it won't remove the need to perform independent verification. Similarly, merely publishing the input won't help much either; how do you verify that the published input corresponds to the actual votes? It won't remove the need for independent parties to observe the raw input (paper votes) and to make their own tallies; in which case those parties can publish their own copies. Asking for the input to be published and the source to be published is just scraping the surface and won't add meaningful security. You need independent observation by mutually distrusting parties.
- sergiotapia 12y agoA counting algorithm is a trade secret? How did this even come to be?
- mlandauer 12y agoThe algorithm is public. It's the Australian Electoral Commission's implementation of it, their software, that's used in public elections that they're calling a trade secret.
- mjec 12y ago> The algorithm is public Clearly so -- except the AEC explicitly say "The algorithm is the trade secret."[1] Which to me says they don't know what algorithm means. [1]: http://easycount.mjec.net/2013-12-09-aec-to-mjec.pdf http://easycount.mjec.net/2013-12-09-aec-to-mjec.pdf at paragraph 57.
- retroencabulato 12y agoIn their defence, in Section 15 of the FOI rejection letter, they mention the software is used for several fee-for-service industrial elections.
- pan69 12y agoIsn't that a conflict of interest? I mean, who or what pays for the development of the implementation?
- harkyns_castle 12y agoI'm uneasy about that... presumably they get funded from our taxes. I'd have to guess any profit they make is put back into the pockets^w system, but not responding to FOI's on the basis of a commercial interest strikes me as weird. Must be some impressive VB coding in any case.
- michaelhoney 12y agoThey still have copyright on the software: copying it and, say undercutting the AEC on the fee-for-service would be illegal. Far more likely that the AEC don't want to have their software open to scrutiny by politically-motivated geeks.
- Tloewald 12y agoI've always though the Hare Clark system is intrinsically I democratic (even though it produces reasonable results) because no one seems to understand it (certainly the people who claim to can't explain it). It's also non deterministic -- the outcome can change hassle on the order in which votes are counted (although the impact will be very small in all probability)
- jcrawfordor 12y agohttp://en.wikipedia.org/wiki/Single_transferable_vote#Counting_the_votes http://en.wikipedia.org/wiki/Single_transferable_vote#Counti...
- sgryphon 12y agoSTV used in Australia is deterministic. It does not change depending on the order in which votes are counted.
- Tloewald 12y agoYou don't understand the system. Surplus votes are distributed based on preferences, so order does matter because preferences will be different from one ballot to the next. Which ballots fill a candidate's quota determines which preferences don't get assigned.
- jlangenauer 12y agoThe preferences on quota surplus votes are transferred at a fractional value, so every ballot is counted. It didn't always used to be though - prior to computers, to establish the fractional vote transfers, a "sample" of surplus votes to a quote used to be randomly selected.
- Tloewald 12y agoOk, thanks for the correction then. My knowledge of the system was out of date (as is the article I checked it against). But the fact almost no voter understands it remains an undemocratic feature.
- thrush 12y agoProfessor Alex Halderman from Michigan has performed a few studies on Electronic Voting and Electronic Voting Machines, and essentially has proven that it is insecure. At one point, he hacked an American EVM to play the Michigan Fight song on every submission. You can read a few of his papers here: [1][2] The challenge of creating anonymous and secure voting systems is still an area of constant research, and I do not believe that the Australian gov't has solved these problems yet. Should we view the source? If we know it's insecure because it's basically unbelievable to think that otherwise, what good will seeing the code do? The fact that it is not being shown basically confirms the insecurity (if it was truly secure, we'd be able to see it without having a negative effect on the system). It seems the right thing to do is to fight this method of voting until EVMs are more secure, but maybe we should hedge our bets. Maybe we're going to be stuck with these EVMs in the interim, and we should avoid leaking the source to prevent people who have difficulty viewing the source. [1] https://jhalderm.com/pub/papers/evm-ccs10.pdf https://jhalderm.com/pub/papers/evm-ccs10.pdf [2] https://jhalderm.com/pub/papers/voting-wecsr11.pdf https://jhalderm.com/pub/papers/voting-wecsr11.pdf
- colmmacc 12y agoThe Dutch group "We don't trust voting computers" [1] hacked up a machine to play chess [2]. It could easily beat a novice. [1] http://wijvertrouwenstemcomputersniet.nl/English http://wijvertrouwenstemcomputersniet.nl/English [2] https://www.flickr.com/photos/colmmacc/sets/72157594312701166 https://www.flickr.com/photos/colmmacc/sets/7215759431270116...
- Unit327 12y agoAustralia doesn't use EVMs, all voting is done on pen and paper and counted manually. This is just the software used to input those results, tally them, do preference flows, and declare the outcome.
- 3rg0s4m 12y agoThe algorithm used is fairly complicated, being both preferential and proportional. (The lower house is preferential but not proportional). Here is a nifty visualization of the senate vote flows in NSW: http://www.grwpub.info/senate/nsw.svg http://www.grwpub.info/senate/nsw.svg. Essentially you need a certain number of votes to cross the line and win a seat. After winning the seat, those votes are subtracted from the party. Eventually when no parties have enough votes, the lowest voted party is eliminated and its votes are redistributed by preference.
- timv 12y agoI once attempted to implement the Senate counting algorithm (mostly so I could force myself to truly understand it). I can say with great confidence that it is hard to implement correctly, and it would take more than a single external audit to give me confidence that the AEC's implementation is flawless.
- nmrm 12y agoWhat's up with the yellow lines going from already-excluded parties?
- makomk 12y agoApparently http://www.grwpub.info/senate/ http://www.grwpub.info/senate/ is the description that goes with that animation. The yellow lines are votes for parties that were already eliminated getting redistributed again because the party their votes had gone to is being eliminated too.
- sgryphon 12y agoAs suggested, releasing the raw data as input would be better than the source code anyway. The raw data should not have any 'trade secret' or 'hack vulnerability'. Vote for it on data.gov.au https://datagovau.ideascale.com/a/dtd/AEC-Raw-voting-data/42018-26233 https://datagovau.ideascale.com/a/dtd/AEC-Raw-voting-data/42...
- pwc 12y agoYou can download the 2013 Senate below-the-line preferences from here: http://results.aec.gov.au/17496/Website/SenateDownloadsMenu-17496-csv.htm http://results.aec.gov.au/17496/Website/SenateDownloadsMenu-... (Down the bottom, under “State Below the Line Preferences”) I think those files, plus the above-the-line preferences should be enough to re-do the AEC's calculation... I would be interested to know if anyone had ever tried that.
- Maxious 12y agohttp://blog.angrygoats.net/2014/01/25/counting-the-west-australian-senate-election/ http://blog.angrygoats.net/2014/01/25/counting-the-west-aust... uses those files I think and is cited in the FOI review as an example of how someone could reproduce their "trade-secret" algorithm using publically available information.
- DigitalSea 12y agoIf releasing the code is an issue, how about a compromise instead? How about releasing the code to a handful of independent third party firms and academics to determine for themselves if the code is safe. Does the AEC have an audit process in place where the code is checked and is there a testing environment of which the code is strongly tested for issues? Given the undeniable complexity of such an algorithm, it would take more than a single audit to verify that it is secure. I don't doubt there is something up in the process somewhere, when it comes to vote redistribution I believe if not done correctly and properly tested, there could be some issues in that part alone. Or better yet, release the data and allow academics from multiple institutions to independently run their own counts and then see if the results match up with that of the AEC's. I think that could be another way without releasing the code and verifying the results are accurate.
- cmrn 12y agoA review of the EasyCount software is currently out for limited tender: https://www.tenders.gov.au/?event=public.cn.view&CNUUID=53E31E1A-E681-11E3-D447B0A5C9424137 https://www.tenders.gov.au/?event=public.cn.view&CNUUID=53E3... However that's still a far cry from any real scrutiny and transparency…
- mlandauer 12y agoIf you want to help solve this please contribute to @mjec's campaign to raise money for representation by a barrister at the AAT appeal http://www.pozible.com/project/183015 http://www.pozible.com/project/183015
- EGreg 12y agoI propose someone sponsors a bill whereby any voting software used to count votes by the public must be open sourced and have several signatures (md5, sha1, etc.) which each voting center must verify before deploying it. The voting centers would just have generic computers (perhaps with special peripherals for voting) which would load the software from a file and they could verify the signature of the file. There could be software that does this automatically. Such as the Apple app store. That way, if any data centers detect an anomalous signature, they'd report it and it would raise a stink. This is similar to the Apple App store except instead of Apple owning the ecosystem it would be their government. There are even better ways without all this crap -- either use an existing App Store from Google or Apple (or all) or have a browser extension and distributed app store from a distributed social app platform ;-)
- doctorKrieger 12y agohow hard is to add numbers?
- GhotiFish 12y agoImagine if the principa mathmatica was decided upon by democracy. That hard.
- doctorKrieger 12y agostill i cannot comprehend that, the software simply has to measure the number of votes...
- GhotiFish 12y agoforgive me for being snarky. The real challenge is surviving voter manipulation. Parties would intercept communication, and compromise machines. Voting machines have to remain secure, despite opponents having physical access to the machine, and currently security doctrine is basically "Once your opponent has physical access, you lose."
- josephschmoe 12y agoHonestly, the only way to prevent election rigging is to associate each vote with a key, make the key-vote-district database public and give each voter a copy of their vote keys. If each vote is verifiable to the voter and the whole database is public, then we can have independent analysis done on the votes and no vote rigging is possible, except for creating additional fake keys. And we can fix that problem simply by making the keys associated with a voter registration, which requires an ID. Same way we do now. Granted, that's still limited by the issues with paper ballots.