Live data from Hacker News

In Estonian parliamentary election, 44% of the votes were cast online

zdnet.com

161–170 of 208 posts

Re: In Estonian parliamentary election, 44% of the votes were cast online

#161
post #125
post #92

Earlier quoted context omitted.

> a smartcard, secured and provided by state officials [..] The (state-provided) USB reader [..] are not immune to attack either. Unless you go to the extraordinary lengths of making your own hardware in a facility you secure and keep secured for the duration of your democracy , there is no such thing as a 'secure device'. Not when the prize is something so hugely lucrative and advantageous as control over an entire…

Who create the security tokens that banks use? I could see few things more lucrative and advantageous than a perfect backdoor into that hardware, especially since here in Sweden you can create electronic government ID from said token which can be used for everything except voting. It is not without reason that most common fraud here in Sweden (around 80%) is someone calling under false pretense asking a victim to use…

Electronic votes can be secured cryptographically. Votes can be counted per precinct instead of centrally, and then summed. The security factors of paper voting can be replicated electronically.

"The authority might just lie about the count or throw away or counterfeit votes, or coerce voters other vote a certain way" is not solved by paper voting either, as seen in Russia and many other places.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#162
post #138
post #117

Earlier quoted context omitted.

Except in Soviet Union terrorizing all the opposition parties/majority of voters was long, costly and brutal process. Online voting makes the whole thing cheap, easy, and undetectable.

And they got caught. Everyone knew the elections were rigged. With electronic vote you can get away with the crime and nobody's wiser.

Vote results are always really close to pre-election poll results. You can't really manipulate the results too much unless you somehow prohibit polling.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#163

Earlier quoted context omitted.

Say I sell my vote. The person picks a party I don’t agree with. I will simply vote for them anyway in the prelimenaries, screengrap my proof, and send to my customer. I can do this multiple times. Each time I void my previous ballot, betraying my previous customer. Then comes election day, then I show up in person and cast a physical ballot for the party that I favor. As a buyer, my customers have no way of knowing…

I can't see a way of that working without breaking down somehow: - If every time you vote you get a receipt for that vote that can be checked if it's still valid then you can send that receipt to the buyer and he can then check that your vote is still according to his purchase - If you can only check that the receipt was registered but not if it's still valid you can't check that your vote was correctly counted becau…

Screencaps are trivial to counterfeit. Every computer has a screen cap editor.

Someone with a paper ballot can photograph their ballot with a phone of spycam, to prove their vote to a buyer.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#164
post #155

Earlier quoted context omitted.

You don’t even need that. In many systems, you can vote multiple times, and only your most recent vote counts. As a buyer you have no way of knowing if your agent didn’t vote after they photographed them self voting for the party you picked.

That's definitely a good improvement over a single final commit, but there has to be some cut-off time and it would be perfectly possible to control the voter's ability to make last moment corrections. Buy/coerce the vote close to the deadline, then keep them occupied until it's over. A countermeasure might be an undisclosed deadline lottery: a guaranteed voting window until some time t, then allow corrections until…

That means my real vote might not get counted, thanks to the random deadline.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#165
post #110

Earlier quoted context omitted.

Those kinds of penalties and worse don't stop organized crime, for instance. Politicians also tend to do all sorts of crazy, risky and/or illegal things to get elected or for personal profit. Nixon and Trump spring readily to mind. If the reward is large enough, someone will risk it. Sometimes the reward doesn't even have to be large at all -- witness rich celebrities shoplifting, for instance. People can also be com…

None of that makes any kind of sense. You can't risk it when the equilibrium is that bad for you. Remember, to make any appreciable dent in an election outcome, you need to convince thousands of people to vote for you, and not turn you in, despite the 100k reward. There is zero chance of that ever succeeding.

If there is a $100k incentive for framing someone for vote buying, people will do it.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#166
post #164
post #155

Earlier quoted context omitted.

That's definitely a good improvement over a single final commit, but there has to be some cut-off time and it would be perfectly possible to control the voter's ability to make last moment corrections. Buy/coerce the vote close to the deadline, then keep them occupied until it's over. A countermeasure might be an undisclosed deadline lottery: a guaranteed voting window until some time t, then allow corrections until…

That means my real vote might not get counted, thanks to the random deadline.

But that only happens when for some contrived, malicious reason you felt pressure to cast a vote that did not reflect your real opinion. The random deadline extension weakens that attack.

People free from interference would simply make their first vote their real one, cast safely before the earliest possible deadline.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#167

Earlier quoted context omitted.

Considering Estonia's history, paper voting isn't exactly amazing either. The Soviet era showed that election fraud happens anyway. The problem with paper voting is that mistakes in counting happen very often. During the election that just happened in Estonia officials wrote the candidate number into the box that said how many votes they got.[1] In the 2016 US presidential election officials basically typod the elect…

Paper voting is hundred times more secure than electronic. With paper voting observers can see all the ballots and verify the results; these results are usually published so if you have observers at all polling stations you can verify that all votes have been counted correctly. With electronic voting nothing stops sysadmin from doing UPDATE votes SET vote = 'Good Candidate' WHERE vote = 'Bad Candidate'.

Except the sysadmin's inability to generate valid signatures for those votes.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#168
post #136

Essentially, Estonia gives 44% influence of their country to a system that cannot be verified to have almost any relation to what people actually have voted for. The people have will just look at the results and have to think "well, I hope weren't hacked this time" and move on. Rest in peace, democracy in Estonia.

As if they had one - https://www.osce.org/odihr/341596?download=true

That's some nice Russian propaganda you have there. With some pretty serious factual mistakes. It claims that non-citizens can't vote in local government elections, but this is false. Citizenship isn't a requirement to vote in local elections.

> former USSR citizens who lived in Latvia and Estonia and were deprived of the right to receive its citizenship after the collapse of the USSR

What right? Merely living in Estonia doesn't give you any right to citizenship. What's more, it's not that difficult to get citizenship. The main obstacle is learning the local language, as that's part of the test to gain citizenship. All these non-citizens refuse to do so. They take pride in being Russian and speaking Russian. They are openly talking about how great Russia is and how they are waiting for Russia to unite them with the motherland.

Estonia gained independence in 1918. Just because USSR occupied us [1] and transported a bunch of people here doesn't give them any rights to citizenship. The Russian population in Estonia grew from about 23,000 people in 1945 to 475,000 in 1991. [2] Now making up for a whopping 30% of the whole population! This is due to systematic transporation of people as part of Russification [3] where the Russians attempt to eradicate native cultures.

After the collapse of USSR it was possible for them to go back to Russia and/or get a Russian citizenship. Some did that, but all of these non-citizens still left are people who decided that life with fewer rights than citizens in Estonia is better than becoming a Russian citizen and living in Russia.

--

[1] https://en.wikipedia.org/wiki/Occupation_of_the_Baltic_state...

[2] https://en.wikipedia.org/wiki/Russians_in_Estonia

[3] https://en.wikipedia.org/wiki/Russification

Re: In Estonian parliamentary election, 44% of the votes were cast online

#169
post #37

Think of what this means for voter representation. You just made it much easier for people with computer access to vote, compared to those without who still must trek to the polling place. I doubt the demographics represented in this vote were the same as the last comparable one.

90% of Estonian households have access to the internet. [1] The percent is still increasing. On top of that, it's possible to request the government to send an official to your home if you wish to cast a paper vote from home.

--

[1] https://ec.europa.eu/eurostat/tgm/table.do?tab=table&init=1&...

Re: In Estonian parliamentary election, 44% of the votes were cast online

#170

Earlier quoted context omitted.

> My main criticism is that as it is it could still feed the card with the wrong vote to sign. In other words: It doesn't help at all against malware on the computer. > The (state-provided) USB reader should have a small lcd screen to sum up the thing being signed "Vote for Ms.Ryjavik on election #123" "Vote for Yes on vote #432" and a confirmation button. In other words: If the USB firmware is infected, it's still n…

Considering Estonia's history, paper voting isn't exactly amazing either. The Soviet era showed that election fraud happens anyway. The problem with paper voting is that mistakes in counting happen very often. During the election that just happened in Estonia officials wrote the candidate number into the box that said how many votes they got.[1] In the 2016 US presidential election officials basically typod the elect…

> Considering Estonia's history, paper voting isn't exactly amazing either.

So, could you point to any one election in Estonia's history where electronic voting would have been any better?

> The Soviet era showed that election fraud happens anyway.

That's just bullshit. Just because a solution for a problem is not perfect, does not mean it's useless and that every non-perfect approach is equally bad.

> The problem with paper voting is that mistakes in counting happen very often.

Which is irrelevant to the discussion of security. Mistakes are a very different thing from intentional manipulation, both in how you can prevent them and in the effects. In particular, mistakes tend to average out, which is why they usually don't matter for elections as long as they happen at a reasonably low rate.

> In the 2016 US presidential election officials basically typod the election results in the town of Hazelhurst in Wisconsin, where almost half the votes went missing until a citizen volunteer noticed the mistake. The party officials nor election officials caught the mistake.

... which is why we should employ a voting process where only the election officials have any insight into what is going on, so we minimize the chance that a citizen discovers any errors?

> If mistakes like that can happen then how often do they go unnoticed? How often are these mistakes deliberate?

... and how would an election process that is completely opaque to the public possibly help with any of that?

Post reply on HN