Live data from Hacker News

DARPA Is Building a $10M, Open-Source, Secure Voting System

motherboard.vice.com

11–20 of 303 posts

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#12
post #2

Open source, open hardware? What a joke. Neither are resistant to chip/compiler level attacks such as https://www.schneier.com/blog/archives/2018/03/adding_backdo... and https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html That's all assuming the voting machine is actually running the software/hardware they tell you - how would a voter check? The article briefly mentions "That receipt does not permit you to prove…

> That's all assuming the voting machine is actually running the software/hardware they tell you - how would a voter check?

Have dedicated hardware compute a hash from the content of program ROM on demand with a button press and present it on an auxilliary 7-segment display. Compare against the hash of the vetted image. No software need be involved.

At some point in the process, machines will be used for tabulation. You have to trust the hardware to some extent. Just keep it as simple as possible to minimize confounding complexity that an attacker can hide in.

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#14
post #4

My ideal voting system would allow me to have a real time feed of votes as they come in, so that at the end of the night I can check my records vs the "official" records. Names can be detached, all I need is a Ballot id. BallotId can be something as simple as the hash of RegisteredVoterId + password + Salt + ElectionId. As long as the voter remembers their password, they can look up their record, and the record can b…

A feature/detriment of per vote verification is that it opens up the entire system to vote buying - are you describing verifying that your vote happened, or who it was cast for?

Not necessarily. Systems that allow you to verify that your vote was included and counted toward the candidate you selected in the booth, but do not allow you to prove to a third party who you voted for, are known, such as Scantegrity [1].

It sounds like the new system has this feature, and also another key feature of Scantegrity which is that the tallying can be done publicly and independently verified. From the article:

> The optical-scan system will print a receipt with a cryptographic representation of the voter’s choices. After the election, the cryptographic values for all ballots will be published on a web site, where voters can verify that their ballot and votes are among them.

> “That receipt does not permit you to prove anything about how you voted, but does permit you to prove that the system accurately captured your intent and your vote is in the final tally,” Kiniry said.

> Members of the public will also be able to use the cryptographic values to independently tally the votes to verify the election results so that tabulating the votes isn't a closed process solely in the hands of election officials.

> “Any organization [interested in verifying the election results] that hires a moderately smart software engineer [can] write their own tabulator,” Kiniry said. “We fully expect that Common Cause, League of Women Voters and the [political parties] will all have their own tabulators and verifiers.”

[1] https://en.wikipedia.org/wiki/Scantegrity

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#15
post #2

Open source, open hardware? What a joke. Neither are resistant to chip/compiler level attacks such as https://www.schneier.com/blog/archives/2018/03/adding_backdo... and https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html That's all assuming the voting machine is actually running the software/hardware they tell you - how would a voter check? The article briefly mentions "That receipt does not permit you to prove…

I think it's unfair to say there is no point in e-voting besides malice.

e-Voting could make it easier / cheaper to deploy polling stations, collect ballots faster, and potentially to use more complex (but more fair and accurate) voting methods like Ranked Choice or others.

As for the "We won't tell you how you voted but you can validate it", my first guess would be some kind of PKI where you are given the equivalent of a private key, and your results are signed.

There are issues trusting hardware vs. trusting the sight of paper and two humans, I get that. But it's worth researching.

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#16
post #3

>The systems Galois designs won’t be available for sale. But the prototypes it creates will be available for existing voting machine vendors or others to freely adopt and customize without costly licensing fees or the millions of dollars it would take to research and develop a secure system from scratch. I guess the devil is always in the details. "freely adopt and customize" to me says that the code will not be veri…

Isn't there a law in the US prohibiting public institutions from competing with private businesses? This may provide a cause for not rolling it out, but rather handing it over to private enterprises for implementation.

Edit: I recall the US having to withdraw from the Human Genome Project because of this as soon as a private enterprise claimed it as a field of business.

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#17
I don't believe that putting a price tag on a piece of software legitimizes it for a given use case.

I get this same feeling from posts that say "Product X written in language Y". While I agree that there exists a right programming language for a given task, it is not in itself a reason to use product X.

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#18
post #4

My ideal voting system would allow me to have a real time feed of votes as they come in, so that at the end of the night I can check my records vs the "official" records. Names can be detached, all I need is a Ballot id. BallotId can be something as simple as the hash of RegisteredVoterId + password + Salt + ElectionId. As long as the voter remembers their password, they can look up their record, and the record can b…

Your ideal voting system is vulnerable to coercion ("log in and show me who you voted for or else") and phishing. Voting systems should provide confidence to voters that votes are counted correctly, but not permit anyone, including the voters themselves, to learn how they voted after the ballot is cast.

Yes, thank you. People frequently forget critical lessons from history :p

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#19

> Kiniy said Galois will design two basic voting machine types. The first will be a ballot-marking device that uses a touch-screen for voters to make their selections. That system won’t tabulate votes. Instead it will print out a paper ballot marked with the voter’s choices, so voters can review them before depositing them into an optical-scan machine that tabulates the votes. Galois will bring this system to Def Con…

I hate being outright dismissive but it sounds like an expensive html/pdf form with a printer attached.

I do agree that the paper trail is a great thing. I'm not fundamentally against electronic voting, but I haven't heard of a system that can really compete with the simplicity and verifiability of the immutablility you get from paper ballots inside ballot boxes being watched over by interested parties on all sides.

Re: DARPA Is Building a $10M, Open-Source, Secure Voting System

#20
post #2

Open source, open hardware? What a joke. Neither are resistant to chip/compiler level attacks such as https://www.schneier.com/blog/archives/2018/03/adding_backdo... and https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html That's all assuming the voting machine is actually running the software/hardware they tell you - how would a voter check? The article briefly mentions "That receipt does not permit you to prove…

I think it's unfair to say there is no point in e-voting besides malice. e-Voting could make it easier / cheaper to deploy polling stations, collect ballots faster, and potentially to use more complex (but more fair and accurate) voting methods like Ranked Choice or others. As for the "We won't tell you how you voted but you can validate it", my first guess would be some kind of PKI where you are given the equivalent…

> e-Voting could make it easier / cheaper to deploy polling stations, collect ballots faster, and potentially to use more complex (but more fair and accurate) voting methods like Ranked Choice or others.

In Australia we use IRV (what you call ranked-choice) and we don't have any forms of electronic voting for federal elections, and the overwhelming majority of votes cast in state elections are paper ballots (which are hand-filled). You don't need e-Voting to solve that problem.

Post reply on HN