Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

381–390 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#381
post #327

Earlier quoted context omitted.

We do not. Elections here are run very smoothly, with no questions whatsoever about their integrity.

No un-answered serious questions. Serious questions are asked, regularly, as well as un-serious ones by cookers. But, the serious questions, the audit, the sense "did we do ok" is continuously asked. We have an independent electoral commission. I'm not saying its incapable of being reproachable, nothing is "beyond reproach" but I have yet to hear a serious, non-cooker accusation any political party has tried to stuff…

> but I have yet to hear a serious, non-cooker accusation any political party has tried to stuff the electoral commission.

We do get occasional issues with individuals trying stuff, but the AEC is very good at calling it out or prosecuting it.

It's strong enough that the parties don't try anything risky.

Re: Internet voting is insecure and should not be used in public elections

#382

The article talks about being “receipt free” as a required feature of any electronic voting system. Fine. But by that standard, in a world where someone can bring their phone or AI glasses into the voting booth to record the whole voting process, how can any voting system be deemed secure? Anyone can show anyone else how they voted.

> But by that standard, in a world where someone can bring their phone or AI glasses into the voting booth to record the whole voting process

That's why some countries have outlawed that.

Re: Internet voting is insecure and should not be used in public elections

#383

Earlier quoted context omitted.

> but I think Brazil solved this by making sure to control the machine It's bullshit, we don't control anything. Our voting machines are Linux computers that never survived a public auditing, so the government stopped let the public audit them. If either China or the US decided to seriously invest into corrupting the hardware, it would be a several years long process but would actually cost less than our presidential…

It is false your affirmation that they are not audited by public organizations. Entities can register to see the source code in a controlled room. In 2024 for example the party União Brasil checked the code. In 2025 during the official audit 149 entities registered to check the code and attack the machine. Universities, ONGs, political parties, etc. Please check you facts before posting what you think Reference: http…

... and how do you, the voter, prove that the machine you are using to vote is indeed running the audited source code?

Re: Internet voting is insecure and should not be used in public elections

#384

Earlier quoted context omitted.

You haven't in any way prevented this scenario. Somebody could just as well demand that their spouse take a photo or video of their vote. Yeah no cameras allowed in the voting booth is a rule, but it's not like it's enforced or even realistically enforceable.

The solution in Australia is simpler - you don't submit the vote that you took a photo of. You can get a ballot, fill it out the "right" way, take a photo, erase the markings, write on your preferred vote, and submit that. Even if you ignore the pencil they give you and use a pen, you can simply tear or damage the paper, take it back to the elections officer, ask for a new ballot, and fill that out instead. We make i…

Are there no polling stations where you can submit the ballot in a private location, like a drop box inside a booth or whatever? In the US I've only voted electronically, and it's done in a private booth with a curtain preventing external visibility, so somebody can easily video record the entire process with no realistic way of altering their vote.

Re: Internet voting is insecure and should not be used in public elections

#385

Earlier quoted context omitted.

To manually count by hand every ballot would mean not finding out a complete tally well until after Jan 20. When election day and inauguration day was selected, the number of ballots to count were a mere fraction of today's count. Manually counting votes is so error prone that I'd have less confidence in it than a scantron type of ballot. At this point, I'm more in favor of giving each voter a ball/bead/chip to drop…

Hand counts are kind of obnoxious but they can't be beat for transparency. There's no reason it has to be done at once either. Ideally people would be able to vote over several days and counting can start right away. Balls/tokens aren't a bad idea either though, but it sounds like people pocketing a ball/token would force a manual count even if they kept them since the total weight of all buckets combined would be of…

To me, hand counts are beyond obnoxious. How many times does each ballot need to be counted? Just once? Someone with an agenda could cause havoc. Twice? Three times? Majority wins? How many times would non-unanimous count be allowed before the person making the odd result be dismissed/replaced? I can't remember the hanging chad debacle process, but I do seem to remember one person looking at it before handing it to the next person for confirmation.

I like the idea of placing the token into a verifier to validate authenticity before dropping into the bucket. Similar to a coin sorter where invalid tokens get rejected to a separate bin with a light and siren to ID the person trying to cheat. These could get expensive as you'd need one per candidate per position on the ballot.

Re: Internet voting is insecure and should not be used in public elections

#386

Earlier quoted context omitted.

Same but different issues. Now you have to know that the dots were filled in correctly to be readable. Having someone make an obvious attempt at selection but not readable by the reader is also problematic. No reason to not count their vote. You may laugh about not being able to do it correctly, but it happens. Only if the scantron shows that each position on the ballot was counted and the voter is not allowed to lea…

Checking each ballot for completeness sounds like a good improvement to the system. Right now people are just expected to mark carefully and double-check their work before feeding their ballot into the machine and request a new ballot if they mess up. It might slow things down a little bit, but making sure that the machine can detect a vote for each race/question (even if it's just "Abstain") would make sure people d…

I like the idea that "abstain" should be an option for each position on the ballot to remove the ambiguity of it just being skipped mistakenly. Require every position on the ballot to need a response from the voter regardless. That would definitely simplify the tally process even if it does require the voter to go back to fill in additional spots. Better to be right on even if it takes 30 more seconds.

Re: Internet voting is insecure and should not be used in public elections

#387

Earlier quoted context omitted.

> open to abuse. This claim is frequently made and never backed job with any compelling evidence.

you don't need to have "compelling evidence" to show that something is "open to abuse", you simply need to point out the threat vectors as we know from all over the internet and from various financial frauds, rug pulls, insurance frauds, etc., if there is something to gain, there is no shortage of people who will abuse any system.

If you don’t have compelling evidence, you have hand-waving, which is all the concern trolling about massive absentee voting fraud always ends up doing.

Mail-in voting has been operating for decades. Nobody fear mongering about for all these years has ever delivered a shred of evidence to back their claims. It’s flat earth-grade conspiracy nonsense.

Re: Internet voting is insecure and should not be used in public elections

#388

Earlier quoted context omitted.

Where I live we vote by mail by filling in little bubbles with a pen. the counting is done by simple photoelectronic tabulators and there is a built-in, human readable record that can be checked by hand. It is very economical and hard to compromise at a scale that has any effect. i hate the idea of using internet voting. I also don’t trust the electronic voting booths where the whole action is virtual or the older me…

>Where I live we vote by mail by filling in little bubbles with a pen. >It is very economical and hard to compromise at a scale that has any effect. Vote-by-mail creates unnecessary opportunities for cheating, irregularities, and all sorts of foolishness. If you can fill in the bubbles, you could theoretically fill them in for other people. People living with parents suffering from dementia could fill out their ballo…

These problems are all theoretical. If you actually tried to implement them at the scale you'd typically need to sway a federal election you'd find it pretty unworkable. And in close elections, the recount process is pretty intense, so it's even less likely that you'll be successful.

You'll probably want more detail. Ballot harvesting can't work because data analysis shows weird patterns like this ("huh this nursing home went 95% Biden whereas every other nursing home in the county went 55%"). Recounts do signature validation and lawyers from either party can challenge any ballot they want. Voters are contacted to cure their ballots. I've worked on the Democratic side and been heavily involved in doing all of this. We had armies of lawyers, software and data engineers, and organizers.

Most of the pointing out opportunities for fraud comes from a place of like, reasoning from first principles. But elections are huge undertakings involving tons of people. It's hard to successfully commit election fraud at a large enough scale to sway a federal election. It's why foreign adversaries prefer to swarm social media with bots: it has a chance of working.

Re: Internet voting is insecure and should not be used in public elections

#389

Earlier quoted context omitted.

Yep. Physical voting places are great, but they're also an easy target for voter suppression. There should be a requirement that there be a nearby polling location, we should also have multiple days to vote there and employers should be required to give every one of their employees at least one of those days off.

Georgia made sure African Americans had crowded long line voting locations with no access to water. It wasn’t hard to figure out why they were doing that. The South is still pretty racist.

I observed this in New England while living in a city with evenly distributed population. The polling locations were more abundant in the wealthier side of the city. This may not have been straight racism; there was no way for me to determine why this was the case. Looking at a map of median income and polling locations made it pretty obvious to me at least that polling location choice was biased.

Re: Internet voting is insecure and should not be used in public elections

#390

Earlier quoted context omitted.

If you’re willing to do away with the secret ballot, you can eliminate a lot of the need for transparency in the mechanics. If people are able to check their own vote for discrepancies and speak to others to confirm their validity, you only really need to confirm that the final vote count is tabulated correctly (which again, is relatively easy to independently verify).

> If you’re willing to do away with the secret ballot We're not willing to do that. No modern democracy has public ballots. The reason is simple: secret ballots make it effectively impossible to buy votes, as there's no way to prove how any person actually voted.

I would simply say speak for yourself.

You’re making a choice between making it impossible to buy votes and impossible to verify votes. Both come with tradeoffs that can be mitigated, whether that be investigating and prosecuting attempts at bribery in one case or maintaining a strict chain of custody in the other. The decision ultimately comes down to a judgement call on regarding your priorities. I don’t think eliminating the secret ballot should be dismissed out of hand, given most voting was conducted without it prior to the late 19th century.

Post reply on HN