Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

481–490 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#481

Earlier quoted context omitted.

In 2020 a number of states were sending out mail-in ballots to every single registered voter, even if they didn't request it. Those states were CA, CO, DC, HI, NJ, NV, OR, UT, VT, and WA. [1] [1] - https://www.brennancenter.org/our-work/research-reports/voti...

And that's completely fine , because each mail-in ballot is associated with one voter, and the system is designed to make fraud very obvious and difficult to scale. If thousands of people were told "you already voted" when they showed up, then that would be very very obvious. They also really do look at signatures and contact voters to cure ballots if they're unsure.

Mail-in ballots tend to be counted (and received) after in person ballots, so you don't need to worry about in-person conflict. If we go the other direction (mail-in ballot rejected because the person had already voted), it was indeed in the tens of thousands. In 2024 about 584k ballots were rejected. [1] 11% of those, more than 64k, were because the person had already voted.

[1] - https://ballotpedia.org/Election_results,_2024:_Analysis_of_...

Re: Internet voting is insecure and should not be used in public elections

#482

Earlier quoted context omitted.

So the question(s) to ask are: 1. why did absentee voting/vote by mail expand? What was the claimed intention and purpose? What has been the actual result (and based on what evidence) ? 2. who has an interest in underming confidence in vote by mail and why? What evidence do they offer that it actually is a problem?

those are not questions I have, nor answers I feel that I am lacking, and it fits a familiar online debate technique of bogging down discussions when you don't like the direction they are going in, wasting the time of your interlocutor. are you really so unimaginative and out of touch that you don't know the answers to your questions? legitimately elected politicians cheat left and right all over the place, and there…

The reality is that in the USA there just isn't any evidence of widespread election fraud, and lots of evidence to support the claim that our voting systems, while not perfect, are secure enough to trust the results.

So unless you believe there's a whole layer of election fraud that nobody - not the losing party, not pro publica, not the FBI, not state investigators, not reddit - has been able to even detect, there's just really nothing to talk about here.

Re: Internet voting is insecure and should not be used in public elections

#483

Earlier quoted context omitted.

I'm not American, so I don't understand the older republican comment, but except in exceptionally adverse circumstances (astronauts on the ISS or submariners, etc) the military can provide ballot boxes to it's personnel.

Military and overseas voters vote in their home state elections, even federally (all elections are held by states, even for federal candidates). You would need to ensure that there is a ballot box representing each state that has an eligible voter at a given site, and then need to figure out logistics for getting thousands of sealed boxes back to the vote counters in each state within the allotted deadline. You would…

> Or, you could have a central, federally run organization that takes responsibility for delivering sealed ballots to the respective states in a timely manner. Which is what we call voting by mail.

No, postal voting is not the same as bringing ballot boxes to voters in exceptional circumstances and does not have the same set of tradeoffs. Postal voting in particular certainly does not solve the voter manipulation problem.

The fact that so many other countries manage to actually provide ballot boxes to all voters, even to voters in much more remote scenarios than US military service and countries with far fewer resources means that the US has no excuses.

Re: Internet voting is insecure and should not be used in public elections

#484

Earlier quoted context omitted.

> If anything doesn't match up it gets flagged. I think that the ability of every party to watch votes themselves means that trust is increased, and they have skin in the game (if they didn't object at the booth why not!?). I mean the same is true in the United States. One of the key issues with the 2020 election was footage from several jurisdictions where the public was physically blocked from viewing the counting…

Unlike the US the elections aren't run by some local arsehat with local rules. they have consistent rules over the entire state or country (depending on election in question) Scrutineers are also not members of the public. They are declared and appointed by candidates and parties for polling oversight and have complete access to the counting and polling area. They're not allowed to touch ballots but they can challeng…

Again, misconceptions abound. US elections are run by bureaucrats with an elected head. There are consistent rules across the entire state for all elections, with some federal oversight. Scrutineers are appointed by both parties, but also from members of the public.

Like... what do you think American elections are actually like? Do you think some democrat/republican counts them in secret somewhere?

Re: Internet voting is insecure and should not be used in public elections

#485

Earlier quoted context omitted.

To manually count by hand every ballot would mean not finding out a complete tally well until after Jan 20. When election day and inauguration day was selected, the number of ballots to count were a mere fraction of today's count. Manually counting votes is so error prone that I'd have less confidence in it than a scantron type of ballot. At this point, I'm more in favor of giving each voter a ball/bead/chip to drop…

Hand counts are kind of obnoxious but they can't be beat for transparency. There's no reason it has to be done at once either. Ideally people would be able to vote over several days and counting can start right away. Balls/tokens aren't a bad idea either though, but it sounds like people pocketing a ball/token would force a manual count even if they kept them since the total weight of all buckets combined would be of…

Transparency comes much more from repeatable results than manual process. You run the same stack of 1,000 ballots through 2 optical scanners, they will give the same result unless one is busted (in which case do it with 3 or 4). This takes very little time and is reliable. Do it by hand and you are guaranteed to get a different result almost every time, and it will take forever.

Re: Internet voting is insecure and should not be used in public elections

#486

Earlier quoted context omitted.

those are not questions I have, nor answers I feel that I am lacking, and it fits a familiar online debate technique of bogging down discussions when you don't like the direction they are going in, wasting the time of your interlocutor. are you really so unimaginative and out of touch that you don't know the answers to your questions? legitimately elected politicians cheat left and right all over the place, and there…

The reality is that in the USA there just isn't any evidence of widespread election fraud, and lots of evidence to support the claim that our voting systems, while not perfect, are secure enough to trust the results. So unless you believe there's a whole layer of election fraud that nobody - not the losing party, not pro publica, not the FBI, not state investigators, not reddit - has been able to even detect, there's…

you keep trying to change the subject. Here's how the to understand the difference in our positions:

if security researchers find vulns in network software, should they be fixed, or should a hypothetical researcher PaulDavidThe2ndSmartestPersonInThisThread quash the discussion by saying "there is no evidence that these vulns are being exploited"?

fsckboy thinks they should be fixed

https://thegeorgiasun.com/government/your-vote/inside-the-fu...

https://thegeorgiasun.com/government/your-vote/inside-the-fu...

understand that politicians who would benefit from fraud would also control the investigation, making your "see no evil" monkey brain's position as questionable as the election system security is

Re: Internet voting is insecure and should not be used in public elections

#487
post #401

Earlier quoted context omitted.

In the sort of scenario you're talking about the dictator doesn't care how people vote. 'The people who cast the votes decide nothing. The people who count the votes decide everything.' If he has such a lack of control that a mere election, which is to be counted fairly, could have him leave power, then it'd be somewhat farcical to declare him a dictator with all the connotations such a term implies.

Yes but no. The looks are also important. They want 80-99% to stroke their ego and nice pictures to claim legitimacy. The latter seemingly being useful both internally and externally.

Clearly, you haven’t lived behind the iron curtain. Checking up on what people do, and how they vote, would factor in promotions, school access for kids etc. this is by no means hypothetical.

I encourage everyone to look up the relevant sources, easy to find.

Re: Internet voting is insecure and should not be used in public elections

#488
post #20

paper & pen has tremendous value as a recording mechanism. Although it's slower at counting and indexing, it is far better at reproducibility and durability: * records last > 500 years with no electricity . corruption is obvious at first glance. ( bad records don't appear to be good). * counting is easily distributed by number of workers * readily visually inspected with no special tools . ideal for auditing * record…

My state uses a system that I think is the best of most worlds. You check in at one table, they give you a "receipt" that you give to another table who trades that for a little card. The card isn't linked to you at all and it gives you access to a voting machine. You enter your choices into the machine, which prints out a paper ballot that you can review and verify before putting it into the box as you leave. So, you…

It’s a great idea , though the counting machine becomes a threat vector .

Counting votes isn’t really that expensive . Certainly not compared to purchasing , maintaining and securing counting machine hardware

I get that we all get paid to digitize things , so paper seems antiquated , but for many applications it’s the best solution

Re: Internet voting is insecure and should not be used in public elections

#489

Earlier quoted context omitted.

The reality is that in the USA there just isn't any evidence of widespread election fraud, and lots of evidence to support the claim that our voting systems, while not perfect, are secure enough to trust the results. So unless you believe there's a whole layer of election fraud that nobody - not the losing party, not pro publica, not the FBI, not state investigators, not reddit - has been able to even detect, there's…

you keep trying to change the subject. Here's how the to understand the difference in our positions: if security researchers find vulns in network software, should they be fixed, or should a hypothetical researcher PaulDavidThe2ndSmartestPersonInThisThread quash the discussion by saying "there is no evidence that these vulns are being exploited"? fsckboy thinks they should be fixed https://thegeorgiasun.com/governmen…

Nobody, certainly not myself is suggesting that discovered vulnerabilities should not be fixed.

However, vulnerabilities that have demonstrably led to the wrong person being elected are entirely different to vulnerabilities that are invoked only in hypothetical scenarios for which there is no evidence that they've ever happened.

There are lots of things in this world that ought to be "fixed", but I'd prefer we prioritize the ones that are actively, demonstrably causing harm rather than the ones which "could cause harm if A, B & C even though A, B & C have never been observed to occur together".

So sure, fix the vulnerabilities, all of them, but don't lie about their status or impact on actual elections.

Re: Internet voting is insecure and should not be used in public elections

#490
post #443

Earlier quoted context omitted.

You could try reading the Wikipedia article on the end to end voter veritable system called Prêt à Voter. https://en.wikipedia.org/wiki/Pr%C3%AAt_%C3%A0_Voter It's not that hard to grok how it works because there is no complicated math involved. It allows any voter to verify their vote was accurately recorded in the reported total. The usual argument against is you need a lot of people to verify, and most won't. That…

> You could try reading the Wikipedia article on the end to end voter veritable system called Prêt à Voter. https://en.wikipedia.org/wiki/Pr%C3%AAt_%C3%A0_Voter It's not that hard to grok how it works because there is no complicated math involved. > It allows any voter to verify their vote was accurately recorded in the reported total. The usual argument against is you need a lot of people to verify, and most won't.…

> Yes, but only by using as much verification as paper ballot casting

I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems. Using these systems they can.

There are two kinds of attacks: typically classes as retail and wholesale. Retail attacks happen at the front end: stuffing ballot boxes, coercion, vote buying. As the effort involved roughly corresponds to the number of votes altered changing a large enough volume of votes to alter the outcome will be detectable using robust social systems, which boils down to teams of people watching each other.

Wholesale attacks happen when the vote is processed after they have been cast. An example is altering vote counting machine to lie about the votes counted. As they can systemically alter large numbers of votes they can be very difficult to detect even using statistical megtods. They are impossible to pull off when everything is done manually as teams watching teams still works, and you have to corrupt a lot of people. But when you introduce automation and machinery they voting system becomes vulnerable to this sort of manipulation.

Yes, "just continue to do everything manually using pencil and paper" does mostly eliminate wholesale attacks. But the reality is we are ditching pencil and paper for more automated processes. A famous example is a Diablo voting machine in some USA state, failed before regurgitating it's vote count (the "Volusia Error"). A man with a screw driver duely arrived, modified things, and handed over what he said was the correct vote count.

We are automating voting with voting machines and vote tabulators for good reasons. They are easier to use, particularly for the disabled, they are faster, they are cheaper than redundant teams of people, and they more accurate than manual methods. They are already arrived, and their use will only grow over time. Pleas like yours to "just use paper" are having little effect on their inceasing adoption.

The other option is to insist these machines and systems are end to end cryptographically verifable. That makes wholesale attacks these automated systems facilitate detectable. Currently we are deploying these systems without such safeguards. IMO this is insanity.

Post reply on HN