Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

491–500 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#491

Earlier quoted context omitted.

My state uses a system that I think is the best of most worlds. You check in at one table, they give you a "receipt" that you give to another table who trades that for a little card. The card isn't linked to you at all and it gives you access to a voting machine. You enter your choices into the machine, which prints out a paper ballot that you can review and verify before putting it into the box as you leave. So, you…

It’s a great idea , though the counting machine becomes a threat vector . Counting votes isn’t really that expensive . Certainly not compared to purchasing , maintaining and securing counting machine hardware I get that we all get paid to digitize things , so paper seems antiquated , but for many applications it’s the best solution

Yeah, and this solution results in paper ballots. You get three different ways to count them.

Re: Internet voting is insecure and should not be used in public elections

#492

Earlier quoted context omitted.

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

Politicians just use those accusations as cover for conducting fraud or enabling the conditions that they inherently benefit from. There's no reason to not use paper, ID checks, and same-day accounting.

Yeah, I forgot voter ID. All democratic countries mandate voter ID except the US and another couple(?). Yeah, as if only the US has the "voter access" problem

Re: Internet voting is insecure and should not be used in public elections

#493
post #403

Earlier quoted context omitted.

Where I live we vote by mail by filling in little bubbles with a pen. the counting is done by simple photoelectronic tabulators and there is a built-in, human readable record that can be checked by hand. It is very economical and hard to compromise at a scale that has any effect. i hate the idea of using internet voting. I also don’t trust the electronic voting booths where the whole action is virtual or the older me…

> Where I live we vote by mail The problem with this, like internet voting, is that you can be coerced. e.g. a family member or your boss can tell you who to vote for and force you to submit that vote. Whereas a polling both is utterly private; you are alone and free from coercion. Nobody else knows who you voted for and they have no way of telling. In the UK, our voting is also done by paper and pencil. The votes ar…

> e.g. a family member or your boss can tell you who to vote for and force you to submit that vote.

Where i live, you can show up in-person on election day to override a mailed ballot, if you're in a situation like that.

Re: Internet voting is insecure and should not be used in public elections

#494

Earlier quoted context omitted.

It’s a great idea , though the counting machine becomes a threat vector . Counting votes isn’t really that expensive . Certainly not compared to purchasing , maintaining and securing counting machine hardware I get that we all get paid to digitize things , so paper seems antiquated , but for many applications it’s the best solution

Yeah, and this solution results in paper ballots. You get three different ways to count them.

the opportunity to recount is not itself an adequate protection for an online counting machine. in my county for example, recounts are only triggered for close elections. they do zero auditing for normal wins.

The system needs to be secure in the primary case, not only in the audit case.

Now if you're saying the counting machine is offline, so that it's verified during the normal voting process, that would be more acceptable.

Re: Internet voting is insecure and should not be used in public elections

#495

Earlier quoted context omitted.

> This can easily solved be done via letting people forge receipts. Then anyone can forge a vote to give to someone offering to buy them. This is the literal definition of receipt freeness. It’s hard to ensure that the receipt you receive to verify your vote had not already been forged by the malware.

Then that is a confusing definition since the voter literally had a receipt of their vote that they can verify. If the receipt you get says you voted for someone you didn't, then that is a clear sign something went wrong.

The definition is fine. It covers paper ballot security requirement where one shall not get any receipt at all.

Re: Internet voting is insecure and should not be used in public elections

#496
post #403

Earlier quoted context omitted.

Where I live we vote by mail by filling in little bubbles with a pen. the counting is done by simple photoelectronic tabulators and there is a built-in, human readable record that can be checked by hand. It is very economical and hard to compromise at a scale that has any effect. i hate the idea of using internet voting. I also don’t trust the electronic voting booths where the whole action is virtual or the older me…

> Where I live we vote by mail The problem with this, like internet voting, is that you can be coerced. e.g. a family member or your boss can tell you who to vote for and force you to submit that vote. Whereas a polling both is utterly private; you are alone and free from coercion. Nobody else knows who you voted for and they have no way of telling. In the UK, our voting is also done by paper and pencil. The votes ar…

You can be coerced with paper and pencil too. In Sicily mafia gives you a voting paper with a predrawn X on the candidate they want, and you must come out with a clean voting paper so they are sure you did leave the pre-voted one.

Re: Internet voting is insecure and should not be used in public elections

#497
post #324

Earlier quoted context omitted.

France is an example. They allowed mail in voting, had issues with fraud, then banned it. https://politics.stackexchange.com/questions/57152/why-isnt-...

… in 1975. I have EXCELLENT, current news for you, comrade. Since then, I can point you to six States in the USA that have implemented mail-in voting that is demonstrable secure and gives far more people the ability to vote than mandatory in-person voting. Isn’t that simply wonderful to hear? And, to boot, lest you worry about volume, one of those States alone (sunny California) is nearly the same population as Franc…

There are open accusations of mail-in fraud in California, not a settled issue. France is an interesting example because there was fraud, settled issue.

It seems obvious, no?

1: Vote in person, with ID

2: Mail ballots out, mail ballots in

Which will have more fraud?

Re: Internet voting is insecure and should not be used in public elections

#498

Earlier quoted context omitted.

Where I live phone use is not allowed in the room where the voting is

And "sharing proof of your internet vote" would not be allowed either. Doesn't matter, they have the same problem.

Pole watchers will see you with a phone. They won't see 'the evil person' in the room watching you vote

Re: Internet voting is insecure and should not be used in public elections

#499
post #443

Earlier quoted context omitted.

> You could try reading the Wikipedia article on the end to end voter veritable system called Prêt à Voter. https://en.wikipedia.org/wiki/Pr%C3%AAt_%C3%A0_Voter It's not that hard to grok how it works because there is no complicated math involved. > It allows any voter to verify their vote was accurately recorded in the reported total. The usual argument against is you need a lot of people to verify, and most won't.…

> Yes, but only by using as much verification as paper ballot casting I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems. Using these systems they can. There are two kinds of attacks: typically classes as retail and wholesale. Retail attacks happen at the front end: stuffing ballot boxes, coercion, vote buying. As the effort involved roughly corresponds to the nu…

> I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems.

In the current paper systems you don't have to, as you know what you put on it before it got anonymized and counted as one vote by the teams watched by teams.

> Using these systems they can.

In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion.

In general, I agree with everything you write except for this paragraph:

> We are automating voting with voting machines and vote tabulators for good reasons. They are easier to use, particularly for the disabled, they are faster, they are cheaper than redundant teams of people, and they more accurate than manual methods. They are already arrived, and their use will only grow over time. Pleas like yours to "just use paper" are having little effect on their inceasing adoption.

The only "good" reason would be cost, but I wouldn't agree that it's a worthy trade-off. They could be easier to use, but it seems generally to be prone to UI issues making it unclear who/what you're voting for.

I'm sure their use will grow over time, but it won't be for any reasons that are good for democracy.

Re: Internet voting is insecure and should not be used in public elections

#500
post #421

Earlier quoted context omitted.

When looking at supporters of voter ID laws, look at whether they support free IDs, expansion of DMVs/issuers of IDs, etc. Similarly, opposition of mail-in-voting typically ignores or supports closing down polling places (in strategically partisan areas), making it difficult for groups of people to vote. These issues are always (by design) discussed in isolation, while ignoring the intrinsically related issues. TL;DR…

My proposal: - Free FEC federal voter ID (requires proof of citizenship) to be used ONLY for voting - Voter ID can be obtained early (age 16?) but DOB is connected to ID and you can’t vote before the legal age - Funded FEC program to register students for voter IDs at schools and colleges and teach them about voting - FEC to work with agencies like social security and IRS to determine if a voter is deceased (messy pr…

Yes, which is why no politician who supports stricter voter ID laws or limiting mail-in-voting would support those proposals, because those issues aren't about strengthening democracy/participation but about voter suppression.
Post reply on HN