Live data from Hacker News

In Estonian parliamentary election, 44% of the votes were cast online

zdnet.com

91–100 of 208 posts

Re: In Estonian parliamentary election, 44% of the votes were cast online

#91
post #88

Earlier quoted context omitted.

> This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit. Feel free to point out where you previously discussed receipt freeness. And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt fr…

> Feel free to point out where you previously discussed receipt freeness. I'm not going to go around spelunking on my old comments to prove to you that your attacks on me are unfounded. Do your own homework if you care about this for some reason but this is getting extremely aggressive for no reason. > And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable…

> The scary thing about what I just described is that plenty of it is indistinguishable from what is already happening in some cases in US elections today. I'm willing to hope that the US case is just pure incompetence, but the attack surface is very large and we've seen that foreign state actors are extremely motivated to meddle with elections.

Whether it's incompetence or foreign attack, the damage done will be the same in both cases, so it's a terrible system to use either way.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#92
post #87
post #32

"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…

Typically, the way this is done is through a smartcard, secured and provided by state officials. A vote has to be signed by the key that never leaves this device. So even if you computer is infected by malware down to its USB firmware, it won't be able to fake many things. Just prevent you from voting. My main criticism is that as it is it could still feed the card with the wrong vote to sign. The (state-provided) US…

> a smartcard, secured and provided by state officials [..] The (state-provided) USB reader [..]

are not immune to attack either. Unless you go to the extraordinary lengths of making your own hardware in a facility you secure and keep secured for the duration of your democracy, there is no such thing as a 'secure device'. Not when the prize is something so hugely lucrative and advantageous as control over an entire country.

All assuming you trust your government. With opposition parties monitoring vote counts, that's easy. But what about when they have to look for dopant-level chip defects?

Re: In Estonian parliamentary election, 44% of the votes were cast online

#93
post #92
post #87

Earlier quoted context omitted.

Typically, the way this is done is through a smartcard, secured and provided by state officials. A vote has to be signed by the key that never leaves this device. So even if you computer is infected by malware down to its USB firmware, it won't be able to fake many things. Just prevent you from voting. My main criticism is that as it is it could still feed the card with the wrong vote to sign. The (state-provided) US…

> a smartcard, secured and provided by state officials [..] The (state-provided) USB reader [..] are not immune to attack either. Unless you go to the extraordinary lengths of making your own hardware in a facility you secure and keep secured for the duration of your democracy , there is no such thing as a 'secure device'. Not when the prize is something so hugely lucrative and advantageous as control over an entire…

In Washington state, all voting is via paper ballots mailed or dropped off at a voting location. You sign them. People end up having different ballots because your ballot is customized for the district you live in (unique city, school district, county, state combinations is a reasonable size). They verify your signature. You can track if you ballot was received (it's inside an inner envelope) and if your signature was confirmed or not.

This feels safe, and as they have the original paper, they can revote - but they have all the ones in the district in a box somehow.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#94
post #87
post #32

"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…

Typically, the way this is done is through a smartcard, secured and provided by state officials. A vote has to be signed by the key that never leaves this device. So even if you computer is infected by malware down to its USB firmware, it won't be able to fake many things. Just prevent you from voting. My main criticism is that as it is it could still feed the card with the wrong vote to sign. The (state-provided) US…

> My main criticism is that as it is it could still feed the card with the wrong vote to sign.

In other words: It doesn't help at all against malware on the computer.

> The (state-provided) USB reader should have a small lcd screen to sum up the thing being signed "Vote for Ms.Ryjavik on election #123" "Vote for Yes on vote #432" and a confirmation button.

In other words: If the USB firmware is infected, it's still not secure.

> With these modifications, and the ability to check a cast vote has been received, you can have secure elections on insecure devices.

So, if you are using secure devices ... then you can have secure elections on insecure devices? In this scenario you aren't actually using the insecure device, other than for establishing a connection to the internet.

Or rather, as you described it, it also functions as the input device--but that is a security problem because it can be used to violate the secrecy of the vote, so it's not actually secure that way either. The only way to make it secure (sort-of) is to not use the insecure device.

> However it requires trust in the officials to do their jobs correctly and to not tamper the tally.

And that is the reason why electronic voting is not an option. Elections have to be able to remove a government from power against its will. An election process that depends on the integrity and honesty of the government that you want to remove from power is inherently broken. An election process that only works when there is no conflict is not a useful election process.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#95
post #32

"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…

Really, it strikes me how luddite people are when it comes to voting. In every other case, people welcome technology making stuff easier. But in this area, all I hear is complaints how far the voting booth is, how you need ID, how there is no national holiday and so on. What about absentee ballots? How do you make sure they were mailed by the right person?

Listen, if an attacker can subvert 30% of the votes, don’t you think they would also be able to subvert 30% of bank accounts which would use the same security? Banks let use an app to withdraw $100,000. Why not for voting which is far less valuable?

Think about it... anyone can just as easily bring a ton of paper ballots and stuff the box that way. If you are concerned about the vote being illegitimate then have everyone submit an encrypted video of themselves saying the vote along with the vote, and the app recognizes what is said, displays it on the screen and the person clicks OK.

EDIT: To the automatic downvoters - why do you trust your bank’s app to manage a lot of money but not an app for voting?

Re: In Estonian parliamentary election, 44% of the votes were cast online

#96
post #95
post #32

"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…

Really, it strikes me how luddite people are when it comes to voting. In every other case, people welcome technology making stuff easier. But in this area, all I hear is complaints how far the voting booth is, how you need ID, how there is no national holiday and so on. What about absentee ballots? How do you make sure they were mailed by the right person? Listen, if an attacker can subvert 30% of the votes, don’t yo…

Banks aren’t anonymous.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#97
post #96
post #95

Earlier quoted context omitted.

Really, it strikes me how luddite people are when it comes to voting. In every other case, people welcome technology making stuff easier. But in this area, all I hear is complaints how far the voting booth is, how you need ID, how there is no national holiday and so on. What about absentee ballots? How do you make sure they were mailed by the right person? Listen, if an attacker can subvert 30% of the votes, don’t yo…

Banks aren’t anonymous.

What does that have to do with anything? Can you elaborate so we can see if your argument holds up?

Re: In Estonian parliamentary election, 44% of the votes were cast online

#98
post #97
post #96

Earlier quoted context omitted.

Banks aren’t anonymous.

What does that have to do with anything? Can you elaborate so we can see if your argument holds up?

Voting requires anonymity, so you lose a lot of the security because of that.

For a bank, you have a PIN that is tied to your identity. You may also have a second factor that is tied to your identity. The bank can use this to positively identify that you are the one making the transaction, and tie it back to you.

You can also verify the transactions after the fact because it isn't anonymous. You can log into your account and check to make sure what the bank thinks happened actually happened. And if it didn't happen the way you say, you can contest it.

Also, the risk is actually lower because the bank assumes liability. If a false transaction is made you can protest it and if you prove that it wasn't you who made the transaction, you get your money back. With voting, you can't get your vote back.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#99
post #95
post #32

"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…

Really, it strikes me how luddite people are when it comes to voting. In every other case, people welcome technology making stuff easier. But in this area, all I hear is complaints how far the voting booth is, how you need ID, how there is no national holiday and so on. What about absentee ballots? How do you make sure they were mailed by the right person? Listen, if an attacker can subvert 30% of the votes, don’t yo…

> What about absentee ballots? How do you make sure they were mailed by the right person?

You have to sign the outer envelope, which can be verified (and is not anonymous).

> Think about it... anyone can just as easily bring a ton of paper ballots and stuff the box that way.

There are a lot of controls in place that prevent that. Number one, the ballot box is never attended by just one person. Number two, the count of ballots has to match the number of people whose identity were verified and voted, and that verification is done by different people.

To stuff the ballot box, you'd have to buy off every poll worker in that precinct, get the list of everyone who didn't vote, pretend to vote for them, and make sure your ballot counts lined up. Since each precinct only serves a few hundred people at most, you'd at best get to put maybe 300-500 ballots in the box. You'd have to do that at every precinct.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#100
post #99
post #95

Earlier quoted context omitted.

Really, it strikes me how luddite people are when it comes to voting. In every other case, people welcome technology making stuff easier. But in this area, all I hear is complaints how far the voting booth is, how you need ID, how there is no national holiday and so on. What about absentee ballots? How do you make sure they were mailed by the right person? Listen, if an attacker can subvert 30% of the votes, don’t yo…

> What about absentee ballots? How do you make sure they were mailed by the right person? You have to sign the outer envelope, which can be verified (and is not anonymous). > Think about it... anyone can just as easily bring a ton of paper ballots and stuff the box that way. There are a lot of controls in place that prevent that. Number one, the ballot box is never attended by just one person. Number two, the count o…

You can cryptographically sign things with your private key on your device also, which is put there when you register to vote. Either way, someone can theoretically forge your signature.

You don’t have to get a list of those who didn’t vote. You just take the pile of punched ballots or whatever and replace them with your pile.

All the matching of counts etc. can be done electronically too.

Post reply on HN