Live data from Hacker News

In Estonian parliamentary election, 44% of the votes were cast online

zdnet.com

171–180 of 208 posts

Re: In Estonian parliamentary election, 44% of the votes were cast online

#171
post #167

Earlier quoted context omitted.

Paper voting is hundred times more secure than electronic. With paper voting observers can see all the ballots and verify the results; these results are usually published so if you have observers at all polling stations you can verify that all votes have been counted correctly. With electronic voting nothing stops sysadmin from doing UPDATE votes SET vote = 'Good Candidate' WHERE vote = 'Bad Candidate'.

Except the sysadmin's inability to generate valid signatures for those votes.

Except the sysadmin can update the database of valid signing keys as well?

Re: In Estonian parliamentary election, 44% of the votes were cast online

#172
post #167

Earlier quoted context omitted.

Except the sysadmin's inability to generate valid signatures for those votes.

Except the sysadmin can update the database of valid signing keys as well?

Do you mean the public database of everyone's public keys? Tampering with that would get noticed really fast and anything like that would greatly erode the trust in the system and wreak havoc on the economy since most stuff is signed digitally.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#173
post #139
post #136

Essentially, Estonia gives 44% influence of their country to a system that cannot be verified to have almost any relation to what people actually have voted for. The people have will just look at the results and have to think "well, I hope weren't hacked this time" and move on. Rest in peace, democracy in Estonia.

>The people have will just look at the results and have to think "well, I hope weren't hacked this time" and move on. Well, no they the main proponents of e-voting figured a long time ago that it's easier to eliminate those concerns using propaganda. For example if you are against e-voting media will brand you as a backwards russkie who hates Estonia.

That's not true. Estonian Conservative National Party is against e-voting also and nobody is calling them "russkies".

Re: In Estonian parliamentary election, 44% of the votes were cast online

#174
post #167

Earlier quoted context omitted.

Paper voting is hundred times more secure than electronic. With paper voting observers can see all the ballots and verify the results; these results are usually published so if you have observers at all polling stations you can verify that all votes have been counted correctly. With electronic voting nothing stops sysadmin from doing UPDATE votes SET vote = 'Good Candidate' WHERE vote = 'Bad Candidate'.

Except the sysadmin's inability to generate valid signatures for those votes.

The signatures are generated by government-issued cards. Doesn't it mean that it can issue any number of new cards and generate signatures using them?

Also, they cannot store signatures with votes because that would disclose voter's identity and their choice. They have to store signatures separately from the votes and it means that the votes can be freely modified.

Here is what Wikipedia says [1]:

> This criticism was underscored in May 2014 when a team of International computer security experts released the results of their examination of the system, claiming they could be able to breach the system, change votes and vote totals, and erase any evidence of their actions if they could install malware on the election servers.

Of course, the government can install enything on its servers.

Here is a quote from a report on vulnerabilities [2]:

> The e-voting system places complete trust in the server that counts the votes at the end of the election process. Votes are decrypted and counted entirely within the unobservable “black box” of the counting server. This creates an opportunity for an attacker who compromises this server to modify the results of the vote counting.

> ...

> The attack’s modifications would replace the results of the vote decryption process with the attacker’s preferred set of votes, thus silently changing the results of the election to their preferred outcome.

Read: the government can "draw" any outcome they would like. Maybe they already did it, who knows.

[1] https://en.wikipedia.org/wiki/Electronic_voting_in_Estonia

[2] https://estoniaevoting.org/findings/summary/

Re: In Estonian parliamentary election, 44% of the votes were cast online

#175
post #168

Earlier quoted context omitted.

As if they had one - https://www.osce.org/odihr/341596?download=true

That's some nice Russian propaganda you have there. With some pretty serious factual mistakes. It claims that non-citizens can't vote in local government elections, but this is false. Citizenship isn't a requirement to vote in local elections. > former USSR citizens who lived in Latvia and Estonia and were deprived of the right to receive its citizenship after the collapse of the USSR What right? Merely living in Est…

While the situation in ex-USSR republics is complicated, it is not a good idea to force someone to learn and use some other language.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#176
post #160

Earlier quoted context omitted.

You can check that the reporting app tells you that you voted for who you think you voted for. You have no way of asserting that that was the vote that was actually counted in the reported result.

I don't know what Estonia does, but there are ways to publish the votes in a secure way that prevents anyone from decrypting a single vote, but lets anyone verify their vote was correctly counted using their own secret key. httpp://news.mit.edu/2009/rivest-voting Of course you need monitors from all interested parties to prevent ballot stuffing, but that's true in every election. It's up to monitors to read the voter…

According to this report [1], they published the source code and provided a video recording of installing the software (sounds like a joke):

> Despite positive gestures towards transparency — such as releasing portions of the software as open source and posting many hours of videos documenting the configuration and tabulation steps — Estonia’s system fails to provide compelling proof that election outcomes are correct. Critical steps occur off camera, and potentially vulnerable portions of the software are not available for public inspection.

[1] https://estoniaevoting.org/findings/summary/

Re: In Estonian parliamentary election, 44% of the votes were cast online

#177
post #139
post #136

Essentially, Estonia gives 44% influence of their country to a system that cannot be verified to have almost any relation to what people actually have voted for. The people have will just look at the results and have to think "well, I hope weren't hacked this time" and move on. Rest in peace, democracy in Estonia.

>The people have will just look at the results and have to think "well, I hope weren't hacked this time" and move on. Well, no they the main proponents of e-voting figured a long time ago that it's easier to eliminate those concerns using propaganda. For example if you are against e-voting media will brand you as a backwards russkie who hates Estonia.

I'm not a supporter of i-voting, but it is true that most of the "concerns" given are pure FUD/bullshit. Studies that consider guest WiFi password being vital information, studies that collate e-voting and i-voting and a lot of other shit I can't recall at the moment.

But the very basic problems are not talked about, namely: * Votes should be counted by independent parties while preserving anonymity * Certificate issuance should be actually monitored by CT logs, every vote that is not in a CT log is dismissed and logged * Voting code should be actually readable and audited (only opsec has been audited so far)

There are a few other problems but I've forgotten them for the time being. These are the problems we should be talking about, not some bogus like, "Omg how can ten grannies vote quickly online".

Re: In Estonian parliamentary election, 44% of the votes were cast online

#178
post #168

Earlier quoted context omitted.

That's some nice Russian propaganda you have there. With some pretty serious factual mistakes. It claims that non-citizens can't vote in local government elections, but this is false. Citizenship isn't a requirement to vote in local elections. > former USSR citizens who lived in Latvia and Estonia and were deprived of the right to receive its citizenship after the collapse of the USSR What right? Merely living in Est…

While the situation in ex-USSR republics is complicated, it is not a good idea to force someone to learn and use some other language.

Certainly and nobody is being forced to learn languages in Estonia, as being an Estonian citizen isn't a requirement to live in Estonia. What's more, citizenships often come with language requirements when we're talking naturalization. Indeed you need to speak Russian to get a Russian citizenship via naturalization. [1]

--

[1] https://en.wikipedia.org/wiki/Citizenship_of_Russia#Citizens...

Re: In Estonian parliamentary election, 44% of the votes were cast online

#179
post #140

All these "e-voting can never work" comments just scream ludditism. Estonia has already demonstrated that it works, we have online banking and cryptocurrencies worth billions of dollars in market cap, and people want to say it's not possible. Yeah, ok. Feel free to express your views, but don't pretend to represent the software engineering community.

Online banking and cryptocurrencies are not equivalent technologies. Just because you can solve those problems with software doesn't mean you can solve every problem in the world with software.

Yes they are not equivalent, my point is that if we can handle money online, there's no reason that voting can't. Bitcoin's market cap is something like $80b, yet nobody has ever hacked it.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#180
post #88

Earlier quoted context omitted.

> This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit. Feel free to point out where you previously discussed receipt freeness. And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt fr…

> Feel free to point out where you previously discussed receipt freeness. I'm not going to go around spelunking on my old comments to prove to you that your attacks on me are unfounded. Do your own homework if you care about this for some reason but this is getting extremely aggressive for no reason. > And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable…

> I'm not going to go around spelunking on my old comments to prove to you that your attacks on me are unfounded. Do your own homework if you care about this for some reason but this is getting extremely aggressive for no reason.

You're asking me to prove a negative. I merely said I doubted you knew about receipt freeness because you didn't even mention it as an obvious counterpoint to your claim, which is a reasonable conclusion. If you consider that an “extremely aggressive attack”, fine. It is easy for you to prove me wrong, you just have to point out the comment in question.

In the meantime, I'll continue to assume you either had no idea what receipt freeness was, or deliberately created the false impression that a verifiable voting system cannot be receipt free.

> I wasn't about to go 10 rounds of "but you could do X and then be broken by Y".

You've failed to show that receipt freeness introduces something else that fundamentally "breaks" which wasn't in the original system, despite repeatedly claiming this is so (see also "They fix this issue and introduce others", a claim made with absolutely zero evidence).

> So here's how I attack it if I'm just a skilled hacker working alone:

So you just assume you can achieve all of this for any e-voting system. Fantastic argument. Really convincing. You may as well have said "Here's how I would attack and infiltrate banking networks or current voting systems surreptitiously. See, we can never trust either of these!" That's just laughable.

> At the end there's a very high chance your election is now fully distrusted and the country is in chaos. Even if it doesn't work 100% of the time it only takes one or two successful events globally for people to distrust these systems, whichever they are.

Clearly wrong as evinced by Estonia's voting system, even in the face of its demonstrated security flaws.

> The scary thing about what I just described is that plenty of it is indistinguishable from what is already happening in some cases in US elections today.

...and it hasn't led to the collapse of the voting system.

> If there are no advantages why do it?

Are you asking what the advantages of e-voting are?

> The difference for eCommerce and eBanking is that under any of those attack scenarios you just go to the bank branch and sort things out, including reverting transactions.

You're assuming banks are always aware of attacks, which is just not true.

> At this point it's on you.

It's not "on me". It's been mathematically proven that a system can possess these properties simultaneously. For example, see

https://link.springer.com/chapter/10.1007/978-3-540-24691-6_...

https://link.springer.com/chapter/10.1007/11818175_22

Post reply on HN