Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

371–380 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#371
post #178
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

> The most important feature of public elections is trust. Agreed. However, in some states, such as California, mail-in voting has become the default. What's used to verify identity and integrity? Your signature from your voter's affidavit of registration, a signature from any past voter form, or literally an "X"[1]. Your signature doesn't even need to match, it just must have "similar characteristics". You can print…

I wonder how correlated is this to how (un)contested California results are (?). I think the main test will be whenever a case like Bush vs Gore happens.

Re: Internet voting is insecure and should not be used in public elections

#372
post #307

Earlier quoted context omitted.

This needs to be said loudly from the rooftops. If your voter ID system isn’t 100% free and absolutely effortless for voters to obtain, it’s a badly disguised vote suppression scheme. It’s pretty much always a vote suppression scheme.

I’d like to respectfully challenge you on this. There is no chance anyone can ever create an effortless-to-get ID. Even if it was like the census where they sent someone to your house repeatedly to try to find you, take your picture and print an ID on the spot, it wouldn’t be effortless because you might not know where your passport or birth certificate are. Some people probably are so badly organized and/or ignorant…

The main problem with obtaining ID is that is takes time, and it's not evenly distributed. In the US its not folklore that people of color are less likely to have ID, it's a statistical fact.

This can be fixed, but you will notice the people who champion voter ID never bother trying. Naturally, the only reasonable conclusion is they like it that way. They're not stupid, after all.

Re: Internet voting is insecure and should not be used in public elections

#373

Earlier quoted context omitted.

> We can't "move back", it's where we are. vote by mail (and similar ballot harvesting, bulk ballot dropoffs with hazy chain-of-custody as from a nursing homes and immigrant communities) are new, based on paper, and open to abuse. It's not where we were. traditional absentee balloting was a small scale thing used by college students, military personnel, etc. and if it was messed up, it was not likely to change outcom…

So the question(s) to ask are: 1. why did absentee voting/vote by mail expand? What was the claimed intention and purpose? What has been the actual result (and based on what evidence) ? 2. who has an interest in underming confidence in vote by mail and why? What evidence do they offer that it actually is a problem?

those are not questions I have, nor answers I feel that I am lacking, and it fits a familiar online debate technique of bogging down discussions when you don't like the direction they are going in, wasting the time of your interlocutor. are you really so unimaginative and out of touch that you don't know the answers to your questions?

legitimately elected politicians cheat left and right all over the place, and there is every reason to rhink illegimate election is just as attractive to them as the fruits of the power they seek, it's human nature, it's in the bible, it's in the koran, it's why we have laws. I would prefer a voting system that was guaranteed as secure as we can because the power to vote them out of office is our best hope.

Re: Internet voting is insecure and should not be used in public elections

#374
post #45

The thing about paper ballots is that the ways to cheat with them are well-known ("finding" ballots in the trunk of a car, "losing" ballot boxes on the way to the counting center, counting the ballots behind locked doors with observers not present, and so on), and have been well known for centuries. So the counters to them (ballot boxes sealed with an official seal once full, only sealed ballot boxes will be opened a…

I strongly disagree. If the system is transparent enough and provides mechanisms for verification and control - No reason to distrust it. I would prefer a system where even in 20 years I can go online and check how my vote was counted in older elections - this way stealing my vote would be impossible. The issue is how to preserve privacy...

> If the system is transparent enough and provides mechanisms for verification and control

That "if" is doing an awful lot of work here!

You can literally explain paper voting to children - it was part of my mandatory Civics classes. On the other hand, I'm pretty sure you need a cryptography PhD to even begin understanding why the various digital protocols are supposed to be secure. Even worse, as a software developer I am aware that things like "how do I know the compiler is trustworthy" and "how do I know the computer is in fact running the right binary" are very much open problems in the industry, so I know that any computer is untrustworthy.

Sure, if it's transparent and verifiable there's no reason to distrust it, but we don't live in a world where a transparent and verifiable digital voting system has been invented yet, so there are plenty of reasons not to trust them.

Re: Internet voting is insecure and should not be used in public elections

#375
post #99
post #88

Earlier quoted context omitted.

> I would prefer a system where even in 20 years I can go online and check how my vote was counted in older elections - this way stealing my vote would be impossible. Understandable, but then vote-buying becomes possible. The reason vote-buying is impossible in a secret ballot is because you can't prove how you voted to anyone else. If you can look up your own ballot even five minutes after it's dropped into the box,…

Vote buying and worse 'vote for me or I'll shoot you'. Buying is the more common scam but there are worse options for evil people

You can also do this today by telling someone to take a picture of their vote by smartphone or you'll shoot them. Millions post a picture of their ballot on high-energy political forums every 2 years already. This hypothetical is unhelpful.

Re: Internet voting is insecure and should not be used in public elections

#376

Earlier quoted context omitted.

> Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. This characterization is reductive and basically a straw-man. The principle underlying opposition to "counting in one day" is basically that every vote that is correctly placed in time should be counted, and as many people as possible should have access to voting. Mail…

> voter turnout Make voting mandatory and on public holiday. Problem solved.

The people championing one day voting don't propose this, because they would prefer to bias voting towards people with lots of time off.

Re: Internet voting is insecure and should not be used in public elections

#377
post #243

Earlier quoted context omitted.

The normal person has no knowledge of stats. I am a professional physicist, and I struggle with stats. The methods you suggest can convince a stats professional that the tally is correct. It cannot convince a normal person of the same.

> It cannot convince a normal person of the same. But you don't need everyone to be convinced of it first-hand. You just need everyone to trust someone who is convinced of it.

Election security should not hinge on a "trust me bro" - especially when people are being convinced the other way by Russian propaganda talking heads on social media.

Manual counting requires zero trust. In my country anyone is welcome to observe the entire process from start to finish, if they wish to do so. A few years back a fringe far-right party tried importing the voting integrity distrust over here, and recruited people to watch their local polling stations to "expose the fraud". Which was totally fine because they were always allowed to do so, and it fizzled out because zero evidence of fraud was found, and that party still didn't get a significant number of votes.

Re: Internet voting is insecure and should not be used in public elections

#378

Earlier quoted context omitted.

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

Politicians just use those accusations as cover for conducting fraud or enabling the conditions that they inherently benefit from. There's no reason to not use paper, ID checks, and same-day accounting.

There are many reasons not to do those things, "lalala not listening" isn't an excuse.

It's usually very simple, too. For voting ID: ID isn't evenly distributed, and that's not an opinion, that's a fact.

So if you require ID, then obviously you will suppress some demographics more than others. That creates a bias. Again, not opinion.

This can be solved. You will notice none of the people championing voter ID make even a thinly-veiled attempt to solve it. Instead they say stupid things like "oh wow so black people can't get ID now? Uh, buddy, I think YOU'RE the racist one!"

Re: Internet voting is insecure and should not be used in public elections

#379

In Brazil we have been using electronic voting for decades. See, here we always had issues with corruption, and thats why we had to implement it. The thing is that we always had major issues at the city level elections, because many small groups dominate different regions, and they just controlled the election officials, influenced voters, disappeared with ballot bags, and did all types of crazy stuff. It was pretty…

> but I think Brazil solved this by making sure to control the machine It's bullshit, we don't control anything. Our voting machines are Linux computers that never survived a public auditing, so the government stopped let the public audit them. If either China or the US decided to seriously invest into corrupting the hardware, it would be a several years long process but would actually cost less than our presidential…

As the other reply noted, there were audits by multiple entities and parties, although I agree that it would be preferable for the code to be open sourced.

I do disagree with your other points. Paper confirmation is not necessarily the only way to audit, and may in fact introduce risks of voter reidentification and coercion (voto de cabresto). The other way of auditing the machines is the parallel voting procedure, which already takes place at every election and is honestly a brilliant piece of security engineering.

For those not aware, the parallel voting procedure works as follows:

1) the day before the election (when the software has already been loaded and locked into the machines for several days), a random sample of machines is selected for the procedure

2) those machines are then removed from the polling place they would ordinarily be assigned to, and replaced with a backup machine

3) the removed machine is then installed in a different room, and booted up normally on electionday. Since it is fully offline, the machine doesn't "know" it is being used in this mode

4) this room is setup so that there are cameras pointed to the machine, and people from all observing parties (and common citizens as well) are invited to "mock vote" in this room.

5) at the end of the day, the machine is closes, its report printed, and the result is checked against the known mock votes

Pretty solid method if you ask me, and much cheaper than upgrading the entire fleet to enable printing.

Re: Internet voting is insecure and should not be used in public elections

#380

Earlier quoted context omitted.

I agree with the other comment about dictators and similar threatening voters, but at a mundane level: domestic violence. People do, in fact, threaten or coerce their spouse and that extends to voting. Being able to audit from a secure counting room and being able to produce an always-available-online permanent record is different.

You haven't in any way prevented this scenario. Somebody could just as well demand that their spouse take a photo or video of their vote. Yeah no cameras allowed in the voting booth is a rule, but it's not like it's enforced or even realistically enforceable.

The solution in Australia is simpler - you don't submit the vote that you took a photo of. You can get a ballot, fill it out the "right" way, take a photo, erase the markings, write on your preferred vote, and submit that.

Even if you ignore the pencil they give you and use a pen, you can simply tear or damage the paper, take it back to the elections officer, ask for a new ballot, and fill that out instead. We make it as hard as possible to coerce a vote while maintaining secret voting (noting that it is definitely still possible, just hard).

Post reply on HN