Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

291–300 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#291

Earlier quoted context omitted.

The problem, as I understand it, is that if you can prove to yourself that your vote was counted right, you can also prove it to the guy with the sledgehammer next to you saying "it would be a shame if something happened to your family, so prove how you voted"...

Australia has very strict laws about who can be near a polling place, and certainly nobody can be inside other than the few certified officials running the show. Guy with sledgehammer is at least a block waylay, and everyone knows that everyone votes, by law.

Obviously the person with the sledgehammer is a law enforcement officer working for the populist politician.

Re: Internet voting is insecure and should not be used in public elections

#292

Earlier quoted context omitted.

Are there places that don't do paper voting in the US? Ballots are still paper everywhere I've voted (mail in ballots, electronic ballots with printouts, filling in bubbles, etc. It's always been paper). Also, even with paper ballots hand counted people aren't suddenly going to trust elections, at least not some people I know. I had someone say that hundreds of thousands of illegal immigrants voted in the last electi…

Isn't it effectively computers everywhere? Sure, you may write on a piece of paper but there is a computer scanning and reporting it. I dont see a practical difference between that and submitting a form directly on a computer.

With paper ballots you can do hand recounts physically with the paper and it's much harder to change values than digitally (obviously), which is a huge difference. You could switch to hand counting by default for everything but the conspiracy theories are really durable for process changes like that so my experience is it won't make a difference.

To expand on that a bit: I've only found their preferred candidate winning to be a long term convincing argument to them (and even then they still will be suspicious). The scenarios I've heard aren't even possible in the current system but they don't trust the election system as a whole so there's no control they would be satisfied with. Even if they personally counted the paper ballots themselves they would just say the ballots were switched out before they got them. Obviously not everyone who doesn't trust elections is like this but I know a lot of people like this.

Re: Internet voting is insecure and should not be used in public elections

#293
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

> we have compulsory attendance at voting booths for eligible citizens, you can spoil your paper or walk away but we enforce with a fine, participation in the one obligation of citizenship

Then my refusal to vote should be counted. If enough people refuse to vote then the entire election should be cancelled and new candidates found. Otherwise this is a ridiculous catch 22 of state bullying to no actual purpose. Who would even think to create such a law?

Re: Internet voting is insecure and should not be used in public elections

#294
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

Australia really uses erasable pencil markings to vote? I would feel much better if they required ink.

Someone needs to gain physical access to the ballot after voting in order to erase it. If they can do that they can just as well make it invalid using a pen, or they can just tear it up.

On the other hand, disappearing ink has been around for a long time.

Re: Internet voting is insecure and should not be used in public elections

#295

Earlier quoted context omitted.

By that logic we have to get rid of mail-in voting as well because there could always be a sledgehammer guy standing next to someone in their own home.

Some do think so, but there is also a material difference in needing to be intimidated at the time of the vote being cast vs any point in the future as well.

For me the problem with mail-in votes is that they are (in many jurisdictions) allowed to come in long after the in-person voting is closed, and the preliminary results are annouced. So it creates the space for manipulations, where you count the in-person votes first, and, if the score is close, then a week after the election day half a million of mail-in votes mysteriously comes in and swings the vote one way or another.

Re: Internet voting is insecure and should not be used in public elections

#296

Earlier quoted context omitted.

Some do think so, but there is also a material difference in needing to be intimidated at the time of the vote being cast vs any point in the future as well.

I think the bigger concern is that mail in ballots lead to fake ballots being submitted. Though I've seen no convincing evidence of this happening at any meaningful scale and the arguments seem unconvincing since you don't get a ballot unless verified with a state ID and your ballot has a unique ID associated with your name, preventing a double spend. Personally, my concern is that with mail in ballots some nutjob th…

> I can take my time to actually look up all those random candidates' policies

But you can already do that, regardless of mail in voting or not?

Re: Internet voting is insecure and should not be used in public elections

#297

In Brazil we have been using electronic voting for decades. See, here we always had issues with corruption, and thats why we had to implement it. The thing is that we always had major issues at the city level elections, because many small groups dominate different regions, and they just controlled the election officials, influenced voters, disappeared with ballot bags, and did all types of crazy stuff. It was pretty…

> but I think Brazil solved this by making sure to control the machine It's bullshit, we don't control anything. Our voting machines are Linux computers that never survived a public auditing, so the government stopped let the public audit them. If either China or the US decided to seriously invest into corrupting the hardware, it would be a several years long process but would actually cost less than our presidential…

It is false your affirmation that they are not audited by public organizations.

Entities can register to see the source code in a controlled room. In 2024 for example the party União Brasil checked the code.

In 2025 during the official audit 149 entities registered to check the code and attack the machine. Universities, ONGs, political parties, etc.

Please check you facts before posting what you think

Reference: https://www.tse.jus.br/comunicacao/noticias/2025/Dezembro/te...

Some of the attacks performed: https://www.tse.jus.br/eleicoes/arquivos/relatorio-parcial-d...

One thing I agree with you. It would require another big country effort to break it.

Re: Internet voting is insecure and should not be used in public elections

#299
Hey all, coauthor here. Interesting to see it on Hacker News.

I'm a professor in Georgia Tech's CS dept that works on problems related to security, privacy, and public policy. (CV: https://mikespecter.com/)

Happy to answer any questions you all have.

Re: Internet voting is insecure and should not be used in public elections

#300

>Voters should not be able to prove to anyone else how they voted – the technical term is “receipt-free” – otherwise an attacker could build an automated system of mass vote-buying via the internet. But receipt-free E2E-VIV systems are complicated and counterintuitive for people to use. This can easily solved be done via letting people forge receipts. Then anyone can forge a vote to give to someone offering to buy th…

I'm not sure if there's a way to make forging work.

You can't forge a new ballot, because ballot IDs are necessarily public, and are cryptographically tied to a voter ID in order to ensure votes are valid and that everybody only votes once.

But it seems like nothing is stopping you from looking up ballots at random until you find the votes you want, and then claiming that was your vote. And if someone else got paid for the same one, then claim they're the one lying, not you?

Post reply on HN