Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

301–310 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#301

Honestly we should just have block chain based PUBLIC voting. This article is right about secret internet voting: it’s fundamentally incompatible with unsupervised devices and global networks. But secrecy is the constraint that breaks everything. If you instead require public, verifiable voting, most of the "unsolved" problems disappear. The core requirement becomes: everyone can independently verify inclusion and co…

You might be interested in some prior work on blockchain voting, it's a bit harder to get right than one might think, and actually introduces some problems [1,2].

[1] https://www.usenix.org/conference/usenixsecurity20/presentat... [2] https://academic.oup.com/cybersecurity/article/7/1/tyaa025/6...

Re: Internet voting is insecure and should not be used in public elections

#302
post #289
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

At this point the main problem here is one of trust either way. Most Americans, of any party affiliation, believe that one party’s officials are presiding over a vast conspiracy to steal every election. The Left thinks the GOP is intimidating real citizens who happen to be immigrants from voting by trying to pass laws for proof of identity, and the Right thinks Democrats are trucking in illegals to stuff the ballot b…

>All these positions are presented without evidence.

What evidence do you need that making it more difficult to vote will result in fewer people voting? Isn't it common sense?

Re: Internet voting is insecure and should not be used in public elections

#303

Which of these vulnerabilities do not apply to any other internet system? And yet all of everyone's money is accessible over the internet and that seems to be working fine. If they really care about security at this level then they should ban all non in person voting methods.

I don't know why so many people in this thread are asking this, but as has been said elsewhere in this thread:

* It does apply to most other internet systems.

* Things like banking fraud can be detected and remedied. Election fraud is much harder to detect and even harder to remedy.

* Voting requires anonymity. Most internet systems are not anonymous: you are identified by your IP address at the very least.

Re: Internet voting is insecure and should not be used in public elections

#304
post #45

The thing about paper ballots is that the ways to cheat with them are well-known ("finding" ballots in the trunk of a car, "losing" ballot boxes on the way to the counting center, counting the ballots behind locked doors with observers not present, and so on), and have been well known for centuries. So the counters to them (ballot boxes sealed with an official seal once full, only sealed ballot boxes will be opened a…

An interesting anecdote, another good example of a reasonably modern example of paper ballots enabling election stealing: https://en.wikipedia.org/wiki/Box_13_scandal Caro covers this pretty extensively in his LBJ biography series, but it's reasonably clear from the evidence that LBJ won his senate seat by some pretty crude paper voting record manipulation after the fact - changing a '7' to a '9' by writing over the…

From the second paragraph of the Wikipedia article: "Six days after polls had closed, 202 additional votes were added to the totals for Precinct 13 of Jim Wells County, 200 for Johnson and two for Stevenson."

Those numbers alone should make anyone suspicious. If you have an urn containing about 20,000 balls in two colors, red and green (this election happened in 1948 and the 1950 census listed that county's population as 27,991; let's assume that roughly 20,000 people would have been old enough to vote in 1948) and you randomly draw out 202 balls (about 1% of the total number in the urn), you would expect the number of balls you draw out to be roughly proportional to the red-blue mix in the urn. (1% of the total is big enough to expect a roughly-unbiased sample). So if you draw out 99% red balls and 1% green balls, then either you have a very very skewed proportion of colors in the urn, or else someone is cheating. Given the TINY margin of victory in that race (87 votes out of nearly a million, 988,295 to be precise), it's very very unlikely that precinct 13 happened to be skewed 99% towards LBJ when the state as a whole was so closely balanced.

Re: Internet voting is insecure and should not be used in public elections

#305

Earlier quoted context omitted.

Minnesota has a better system. You fill in a paper ballot using a pen, and the paper ballot gets optically scanned. Besides avoiding any issues (real or imagined) with touchscreens, it makes it extremely cheap to stand up more polling places with more booths, since only one tabulator is needed; the booths themselves can just be little standing tables with privacy protectors.

>Minnesota has a better system. You fill in a paper ballot using a pen, and the paper ballot gets optically scanned. >Besides avoiding any issues (real or imagined) with touchscreens, Wait... I don't think these are the complaints being made against internet voting at all. The problem is with a computer counting and reporting it, right? Centralized, less transparent, etc. I dont view writing my vote on paper and scan…

> I dont view writing my vote on paper and scanning it to be paper voting if it's just immediately fed into a computer.

The paper ballots are retained for recounts, and most places with this system automatically recount a random subset of the paper ballots to ensure it matches the computer totals. This guards against both shenanigans and mistakes. For security the scanning machines are not networked! A person carries around a little SD card (not USB as it's too hackable) to collect the totals.

The paper ballot with in-precinct immediate scanning system is the best system I've seen. It reports results quickly and leaves a full paper trail for recounts and accountability.

Re: Internet voting is insecure and should not be used in public elections

#306

Earlier quoted context omitted.

Verifiable in this context means I can verify my vote was tallied correctly.

That would also mean someone could force you to show who/what you voted for.

No, because they have no idea what your true ballot ID was.

They can force you to show them a ballot, the idea is that all ballot ID's get made public. You could be showing them anybody's and they'll never have any way of knowing.

Re: Internet voting is insecure and should not be used in public elections

#307
post #245

Earlier quoted context omitted.

>Similar obligations are present wherever election integrity is taken seriously. The flip side is even more true. If someone is claiming they care about election integrity and isn't willing to pair that with funding of an equivalent ID system that is both free and easy for voters to acquire, they don't actually care about election integrity.

This needs to be said loudly from the rooftops. If your voter ID system isn’t 100% free and absolutely effortless for voters to obtain, it’s a badly disguised vote suppression scheme. It’s pretty much always a vote suppression scheme.

I’d like to respectfully challenge you on this. There is no chance anyone can ever create an effortless-to-get ID. Even if it was like the census where they sent someone to your house repeatedly to try to find you, take your picture and print an ID on the spot, it wouldn’t be effortless because you might not know where your passport or birth certificate are.

Some people probably are so badly organized and/or ignorant that they can’t manage making and keeping one single DMV appointment even once every 15 years so that they could get an ID (I think we can all agree that an “expired” ID would do fine, as long as the picture isn’t so out of date it can’t be verified).

Anyway, it’s only those people who would be “disenfranchised” under a voter ID system and I’m not convinced our government would benefit from incorporating the opinions of someone so unserious. It’s ok that some things in life are reserved for people that have invested a tiny amount of effort once in their lives. There’s also not a free and effortless way to feed or bathe yourself.

By the way, a state ID costs $15 in Mississippi and $9 for “eligible people” in California.

Re: Internet voting is insecure and should not be used in public elections

#308

Hey all, coauthor here. Interesting to see it on Hacker News. I'm a professor in Georgia Tech's CS dept that works on problems related to security, privacy, and public policy. (CV: https://mikespecter.com/ ) Happy to answer any questions you all have.

Voting needs to be auditable and verifiable by the lowest common denominator, to the last voter. As such anything that involves anything more complicated than counting by hand is out.

Re: Internet voting is insecure and should not be used in public elections

#309
post #271

Earlier quoted context omitted.

> It sounds like their Election Commission takes their job very seriously. A key part of India's system is the Elector's Photo Identity Card (EPIC), required to cast ballots. Similar obligations are present wherever election integrity is taken seriously.

Australia, as far as I know, doesn't require voters to show identity documents, and they seem to take election integrity very seriously.

We do not. Elections here are run very smoothly, with no questions whatsoever about their integrity.

Re: Internet voting is insecure and should not be used in public elections

#310

>Voters should not be able to prove to anyone else how they voted – the technical term is “receipt-free” – otherwise an attacker could build an automated system of mass vote-buying via the internet. But receipt-free E2E-VIV systems are complicated and counterintuitive for people to use. This can easily solved be done via letting people forge receipts. Then anyone can forge a vote to give to someone offering to buy th…

I'm not sure if there's a way to make forging work. You can't forge a new ballot, because ballot IDs are necessarily public, and are cryptographically tied to a voter ID in order to ensure votes are valid and that everybody only votes once. But it seems like nothing is stopping you from looking up ballots at random until you find the votes you want, and then claiming that was your vote. And if someone else got paid f…

You don't forge a ballot. You are forging the proof of your vote.
Post reply on HN