Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

171–180 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#171
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

What if some level of efficiency (not necessarily internet) improves turnout and participation?

Efficiency for the voter and efficiency for the vote counting process are totally different things.

Re: Internet voting is insecure and should not be used in public elections

#172

Voting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1.…

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

Re: Internet voting is insecure and should not be used in public elections

#173

Voting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1.…

>Elections like this can be gamed, but the gaming becomes an exercise in coercing people to vote counter to their preference, not "hacking" the system. If that's gaming the system, what even is the point of voting?

Yeah. The weakness in any democracy are “populist” Robin Hood politicians.

Re: Internet voting is insecure and should not be used in public elections

#174
post #163

Premise: there's people that will try to game and cheat on anything that's important, including democratic elections. No matter your voting method, those people will exist. Solution: the basic unit (paper ballot in this case) can be understood by any adult with basic education, which means anyone can detect cheating, not just a technical wizard. The only skill you need is reading. Give me a solution that follows the…

Im not sure all paper ballets means delayed election results. Sure, it used to take days or weeks 100 years ago, but the only factor now is the counting.

Re: Internet voting is insecure and should not be used in public elections

#175
post #145

Earlier quoted context omitted.

[flagged]

> Person who shows up to vote is legally allowed to vote How does that work though? What's the root of trust identifying me as me to a government who, at most, has a written record somewhere of my birth, and definitely not enough information to tie that to any particular face or body.

I have to present my passport to get on a plane, enter into another country, register into a hotel and return to this country. I have to show either my passport card (another passport-like ID in the US) or my RealID-equipped drivers license to fly within the US. They also make me stand in front of a camera.

Nearly every nation on earth does this. It's nothing new. We have the technology and the means. This isn't a problem.

Re: Internet voting is insecure and should not be used in public elections

#176
post #145

Earlier quoted context omitted.

[flagged]

> Person who shows up to vote is legally allowed to vote How does that work though? What's the root of trust identifying me as me to a government who, at most, has a written record somewhere of my birth, and definitely not enough information to tie that to any particular face or body.

In a lot of places, it's a photo ID. Usually that required a birth certificate to get, and often a few more pieces of corroborating information to make it harder.

Re: Internet voting is insecure and should not be used in public elections

#177

Earlier quoted context omitted.

>Internet voting needs to be anonymous and non demonstrable Why? Honestly Internet voting would improve overall turnout, which seems more important. And we probably could accomplish anonymity with some clever cryptography.

Anonymity keeps the government from locking you up if you vote the wrong way. Non-demonstrable keeps you from selling your vote to your boss. That is why you typically show id, get a ballot and there is no relationship between the two.

I could still sell my vote to my boss in the typical system.

And we could use cryptography to vote anonymously after authentication online.

Re: Internet voting is insecure and should not be used in public elections

#178
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

> The most important feature of public elections is trust.

Agreed.

However, in some states, such as California, mail-in voting has become the default.

What's used to verify identity and integrity? Your signature from your voter's affidavit of registration, a signature from any past voter form, or literally an "X"[1]. Your signature doesn't even need to match, it just must have "similar characteristics". You can print your name or sign in cursive, you can even just use initials. They're all accepted.

We're firmly on the "honor system".

Pair that with lack of voter ID laws, and we have a system that's designed to be untrustworthy.

Yes, I agree, a state issued ID should be free...

[1] https://codes.findlaw.com/ca/elections-code/elec-sect-3019/

Re: Internet voting is insecure and should not be used in public elections

#179

In Brazil we have been using electronic voting for decades. See, here we always had issues with corruption, and thats why we had to implement it. The thing is that we always had major issues at the city level elections, because many small groups dominate different regions, and they just controlled the election officials, influenced voters, disappeared with ballot bags, and did all types of crazy stuff. It was pretty…

> but I think Brazil solved this by making sure to control the machine

It's bullshit, we don't control anything. Our voting machines are Linux computers that never survived a public auditing, so the government stopped let the public audit them.

If either China or the US decided to seriously invest into corrupting the hardware, it would be a several years long process but would actually cost less than our presidential campaigns. There are probably several ways to corrupt the machines software without anybody noticing (it a Linux PC, full of opaque firmware), that we won't know about because the details aren't public.

Without a paper confirmation that we could audit, nobody can't claim it's working. What would expect the results to be if it was compromised?

Post reply on HN