4 ms·
I have no idea why people are so fixated on electronic voting. Running elections with paper ballots may be costly, but relative to other costs it's very little
by ecdavis 12y ago
I have no idea why people are so fixated on electronic voting. Running elections with paper ballots may be costly, but relative to other costs it's very little - it's also probably the single most important service the government provides.
It's not even like voting is particularly taxing in Australia. You go to your local school on a Sunday, wait in line for a while then grab a sausage or a lamington and go home. If that's too inconvenient there are pre-polling stations open for weeks ahead of time.[0]
I think any software that has the potential to influence election outcomes should be provably correct (the whole stack), open source and probably have been out in the wild for years before getting used in a real election.
[0] As far as I'm aware, the AEC actually double-checks electronic results by doing a human recount. When they use electronic voting it's so they can declare a winner sooner.
- badsock 12y agoMy point, though, is that it doesn't really matter if the whole stack is open source if the binaries have been compromised, or if the browser/OS it runs on has. There hasn't been a widely used OS without a remote exploit, in fact it's not even infrequent for the biggies. Once you control the voter's OS, the game is over. So the way I see it, if you have a few 0-day exploits (enough to get into the majority of popular OS versions), a talent for covering your tracks, and a few swing-ridings, you can decide an election. It's just such an insane risk, and you're absolutely correct: there isn't even much to gain from moving to online voting.
- ecdavis 12y agoI was including the OS in the stack. Is there any reason why vote-casting or vote-tallying software should be running on a fully-fledged OS? It introduces a massive attack surface in exchange for a benefit that is really only felt at development time (development ease and cost). Write something custom, get it formally validated, audited, etc. and then go through a similar process to ensure the hardware is trustworthy. Of course that won't happen. The only real reason to move to electronic voting is to save money, but that's rendered moot if you have to invest a huge amount upfront just to get something trustworthy.
- badsock 12y agoRight. Given the number of countries and companies and people that are involved as you move up the chain from transistor to application, how complex even the smallest stack is, and how many opportunities there are for inserting code at every level - the effort it would take to do a full audit, and then to prove that it's uncrackable from external sources - it's not even remotely realistic. Again, I can't figure out why anyone takes the assertion that electronic voting can be secured seriously.
- vacri 12y agoHa! I started reading your "how we vote in Australia" and was thinking "don't forget the sausage sizzle"... I remember going to a talk by an electoral research specialist (Vanessa Teague) at a security conference, who had a very interesting talk on the shortcomings of electronic voting (and was particularly dark on the NSW version). I have a longer synopsis in a previous comment here[1], but I should see if there's a video online somewhere, because I don't do her justice. https://news.ycombinator.com/item?id=8040531 https://news.ycombinator.com/item?id=8040531 Edit: I have no sound on this machine to confirm, but it looks like the interview here is Teague on the same topic (the article text describes the lecture I saw) http://corruptednerds.com/pod/c00008/ http://corruptednerds.com/pod/c00008/
- vetler 12y ago> I think any software that has the potential to influence election outcomes should be provably correct (the whole stack), open source and probably have been out in the wild for years before getting used in a real election. Let's remember that even when paper ballots are used, the counting is done electronically. It's not something people often take time to consider. When the ballot boxes are emptied, the ballots are scanned with scanners, and the results put into some sort of software to be processed further. This is how it's been done in Norway for many years, and we're only 5 million people here, so I can't imagine other countries doing it any differently. Norway introduced a new voting system a few years ago, which also included Internet voting, but that has later been put on hold, as it was blocked by political reasons. The entire system was open source (you could read the code, but not allowed to use it), but I don't think it has been released since then, and I'm not sure what the plans were. Fun fact, the settlement algorithm that ranks the candidates is a Postgres stored procedure (http://goo.gl/PPMipF http://goo.gl/PPMipF). There is already a lot of places where there is software that can influence election outcomes, and it's definitely not proved to be correct. Given how trojans have been found everywhere in the recent years, I'd not be surprised if some countries election software stack has been compromised.
- eCa 12y ago> I can't imagine other countries doing it any differently. Just over the border all votes are counted by hand (several times).
- tedunangst 12y agoPeople like electronic voting because they read Applied Cryptography and discovered we can have "provably secure" elections.