Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

411–420 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#411

The article talks about being “receipt free” as a required feature of any electronic voting system. Fine. But by that standard, in a world where someone can bring their phone or AI glasses into the voting booth to record the whole voting process, how can any voting system be deemed secure? Anyone can show anyone else how they voted.

Filming or recording in a ballot booth is very illegal in Blighty.

(Granted, nobody is going to see you do it in a private booth with the curtain pulled across).

Re: Internet voting is insecure and should not be used in public elections

#413
post #377
post #243

Earlier quoted context omitted.

> It cannot convince a normal person of the same. But you don't need everyone to be convinced of it first-hand. You just need everyone to trust someone who is convinced of it.

Election security should not hinge on a "trust me bro" - especially when people are being convinced the other way by Russian propaganda talking heads on social media. Manual counting requires zero trust. In my country anyone is welcome to observe the entire process from start to finish, if they wish to do so. A few years back a fringe far-right party tried importing the voting integrity distrust over here, and recrui…

Don't these two situations (watching vote counts; understanding a complicated statistical argument that the vote is tamper-free) require the same kind of trust?

1. In both cases, everyone is theoretically capable of checking it themselves; they're theoretically zero-trust. In the former scenario, I'm theoretically capable of attending the vote count, and in the latter scenario, I'm theoretically capable of learning the statistics needed to verify the argument.

2. In both cases, most people cannot (or will not) practically check it themselves, and is trusting that someone they trust is doing the checking for them.

I'm not saying they're the exact same situation, but they both ask for a large amount of trust from most of the voters.

Re: Internet voting is insecure and should not be used in public elections

#414

Earlier quoted context omitted.

I think the bigger concern is that mail in ballots lead to fake ballots being submitted. Though I've seen no convincing evidence of this happening at any meaningful scale and the arguments seem unconvincing since you don't get a ballot unless verified with a state ID and your ballot has a unique ID associated with your name, preventing a double spend. Personally, my concern is that with mail in ballots some nutjob th…

In 2020 a number of states were sending out mail-in ballots to every single registered voter, even if they didn't request it. Those states were CA, CO, DC, HI, NJ, NV, OR, UT, VT, and WA. [1] [1] - https://www.brennancenter.org/our-work/research-reports/voti...

And that's completely fine, because each mail-in ballot is associated with one voter, and the system is designed to make fraud very obvious and difficult to scale.

If thousands of people were told "you already voted" when they showed up, then that would be very very obvious.

They also really do look at signatures and contact voters to cure ballots if they're unsure.

Re: Internet voting is insecure and should not be used in public elections

#415

Earlier quoted context omitted.

> open to abuse. This claim is frequently made and never backed job with any compelling evidence.

you don't need to have "compelling evidence" to show that something is "open to abuse", you simply need to point out the threat vectors as we know from all over the internet and from various financial frauds, rug pulls, insurance frauds, etc., if there is something to gain, there is no shortage of people who will abuse any system.

No, that's just fear-mongering and spreading propaganda.

Our elections are designed to handle everything you said. I wrote another comment explaining, but you can also literally go watch it done yourself.

Everything's a conspiracy when you don't know how anything works.

Re: Internet voting is insecure and should not be used in public elections

#416
post #258
post #239

Earlier quoted context omitted.

> There's also nothing to prevent bad actors from destroying ballots in large quantities. Around here (WA state), you can check to see if your ballot was received and accepted. If a bad actor destroys ballots in large quantities on their way to voters, many voters will notice and complain. If a bad actor destroys ballots in large quantities on their way to to the counting facility, some voters are likely to notice an…

No one has trouble getting an ID. You need an ID to drive, to work, to open a bank account, to buy liquor or tobacco, etc. The idea that someone can’t get an ID is absolute nonsense.

It's not. Plenty of people do none of those things.

Re: Internet voting is insecure and should not be used in public elections

#418

Honestly we should just have block chain based PUBLIC voting. This article is right about secret internet voting: it’s fundamentally incompatible with unsupervised devices and global networks. But secrecy is the constraint that breaks everything. If you instead require public, verifiable voting, most of the "unsolved" problems disappear. The core requirement becomes: everyone can independently verify inclusion and co…

You might be interested in some prior work on blockchain voting, it's a bit harder to get right than one might think, and actually introduces some problems [1,2]. [1] https://www.usenix.org/conference/usenixsecurity20/presentat... [2] https://academic.oup.com/cybersecurity/article/7/1/tyaa025/6...

These sources still presume SECRET blockchain voting as the goal.

Re: Internet voting is insecure and should not be used in public elections

#419
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

Paper systems fail locally and noisily; internet systems fail silently and at scale

Re: Internet voting is insecure and should not be used in public elections

#420

Honestly we should just have block chain based PUBLIC voting. This article is right about secret internet voting: it’s fundamentally incompatible with unsupervised devices and global networks. But secrecy is the constraint that breaks everything. If you instead require public, verifiable voting, most of the "unsolved" problems disappear. The core requirement becomes: everyone can independently verify inclusion and co…

of course, then you get vote bribing and retaliation. i'm generally in favor of public or provable voting because i think it is the best solution - but you do have to sort of how eyes wide open.

We are a society of adults and complex individuals that don't need to be moralized to or nanny'ed.

You can easily bring up bribing and retaliation as excuses why we shouldn't have jury trials either. These were never really fundamental problems with open democracy, like Andrew Jackson didn't bribe everyone in the country to become president.

TBH if a politician offered me $100 to listen to his pitch, I would take it but I would still vote based on the thousands of dollars of lifetime impact of their policies on my income and assets.

Post reply on HN