Software used to count Australian Senate votes is a “trade secret”
61–70 of 100 posts
Re: Software used to count Australian Senate votes is a “trade secret”
#62Visibility of the source code is a side-show in electronic voting systems. Even if the source code is published, there is no way to be sure that that is the code that is running on the hardware, or to be certain that the hardware itself has not been tampered with. Votes need to be printed out on paper, verified by the voter, and counted by hand. Still, when we had the source code for the Irish system (now abandoned d…
Australian elections ARE pen and paper. The ballots are entered (by hand AFAIK) into the AEC's central system to compute the complex preference flows. Realistically, the algorithm isn't that complicated, and the ABC does a good job at guestimating it [1]. This is why it is so surprising they refuse to release it, even after the Senate passed a motion demanding its release [2]. [1] http://www.abc.net.au/news/federal-e…
She did have the opinion though that there was as place for electronic machines in the voting booth, and it was this: register your vote on a machine. It prints out a slip with clear, unambiguous markings against your selected candidate(s). Verify that it has the content you want, then go lodge the slip like any other paper ballot. You now have a clearer, less ambiguous version of the paper ballot, which is more accessible to people with certain kinds of disabilities to boot.
Most of the times that a paper ballot recount differs is not because of inept counters, but because some voters leave ambiguous marks. She said that in Australia, it has about the best system possible (edit: probably 'in current use') in terms of verifying the count: an AEC official does the counting, and the major parties volunteer scrutineers to challenge ambiguous voting slips. As there are mutually opposing witnesses, you get a fairly robust count - the differences come when one set of scrutineers allows one ambiguous mark, but on a recount that same ambiguous mark gets treated differently by another set of scrutineers.
The important thing is the pile of paper though - the evidence that people voted a certain way. In effect, as soon as you don't have the physical evidence, you're at the mercy of "trust us, it's accurate". How do you scrutinise that?
Re: Software used to count Australian Senate votes is a “trade secret”
#63As suggested, releasing the raw data as input would be better than the source code anyway. The raw data should not have any 'trade secret' or 'hack vulnerability'. Vote for it on data.gov.au https://datagovau.ideascale.com/a/dtd/AEC-Raw-voting-data/42...
http://results.aec.gov.au/17496/Website/SenateDownloadsMenu-...
(Down the bottom, under “State Below the Line Preferences”)
I think those files, plus the above-the-line preferences should be enough to re-do the AEC's calculation... I would be interested to know if anyone had ever tried that.
Re: Software used to count Australian Senate votes is a “trade secret”
#64Visibility of the source code is a side-show in electronic voting systems. Even if the source code is published, there is no way to be sure that that is the code that is running on the hardware, or to be certain that the hardware itself has not been tampered with. Votes need to be printed out on paper, verified by the voter, and counted by hand. Still, when we had the source code for the Irish system (now abandoned d…
> counted by hand. By whom? Overseen by whom? Who oversees the overseers? Not to mention people make mistakes, ballots get dumped, and nobody has any evidence their vote was actually counted. Here's a long but fascinating tech talk on a real solution: https://www.youtube.com/watch?v=ZDnShu5V99s
Re: Software used to count Australian Senate votes is a “trade secret”
#65Earlier quoted context omitted.
I don't mean any offense - but your position is not self-consistent. "Showing us the code" does not invalidate "could change it every day to match their whims". For example the entire source code to Linux is public, but looking from the outside, you as an observer have no way to know that a particular copy of the Linux code is what is running on my laptop. Which is why I say it's a side-show. If the source code is sh…
The point, though, is that releasing the source code under the pretense that it is the running code can create a legal obligation that what's released is what's run. No, it doesn't prevent them from running something else, but it at least creates the possibility of audits and consequences if they do so.
Re: Software used to count Australian Senate votes is a “trade secret”
#66Earlier quoted context omitted.
Australian elections ARE pen and paper. The ballots are entered (by hand AFAIK) into the AEC's central system to compute the complex preference flows. Realistically, the algorithm isn't that complicated, and the ABC does a good job at guestimating it [1]. This is why it is so surprising they refuse to release it, even after the Senate passed a motion demanding its release [2]. [1] http://www.abc.net.au/news/federal-e…
At Ruxcon last year there was a very interesting talk by an electoral systems researcher (I can't recall her name). She went through a number of electronic voting systems, and they all suck. Some more than others. The only case where she found a system that was close to acceptable was in a crypto organisation where everyone was highly technically fluent in the system. Certainly not transferable to the general public.…
Re: Software used to count Australian Senate votes is a “trade secret”
#67If releasing the code is an issue, how about a compromise instead? How about releasing the code to a handful of independent third party firms and academics to determine for themselves if the code is safe. Does the AEC have an audit process in place where the code is checked and is there a testing environment of which the code is strongly tested for issues? Given the undeniable complexity of such an algorithm, it woul…
However that's still a far cry from any real scrutiny and transparency…
Re: Software used to count Australian Senate votes is a “trade secret”
#68Earlier quoted context omitted.
> counted by hand. By whom? Overseen by whom? Who oversees the overseers? Not to mention people make mistakes, ballots get dumped, and nobody has any evidence their vote was actually counted. Here's a long but fascinating tech talk on a real solution: https://www.youtube.com/watch?v=ZDnShu5V99s
I can talk about Ireland, as I've been an election observer there. The way we do it is that ballot boxes are locked and sealed with tamper-evident seals after a polling station has closed. Elections observers; including representatives from the political parties may request to add their own seals. In some particularly contentious districts this is done, but for the most part people are happy with the official seals.…
However, there is still no way for me as an individual to know for certain that my vote has been counted. The best I can do is trust in the physical security practices surrounding the ballot box and the honesty of the volunteers involved. And even with a margin of error of I encourage you to watch the tech talk when you have a spare hour. We have the technology to create a much better and more transparent system.
Re: Software used to count Australian Senate votes is a “trade secret”
#69As suggested, releasing the raw data as input would be better than the source code anyway. The raw data should not have any 'trade secret' or 'hack vulnerability'. Vote for it on data.gov.au https://datagovau.ideascale.com/a/dtd/AEC-Raw-voting-data/42...
You can download the 2013 Senate below-the-line preferences from here: http://results.aec.gov.au/17496/Website/SenateDownloadsMenu-... (Down the bottom, under “State Below the Line Preferences”) I think those files, plus the above-the-line preferences should be enough to re-do the AEC's calculation... I would be interested to know if anyone had ever tried that.
Re: Software used to count Australian Senate votes is a “trade secret”
#70Earlier quoted context omitted.
I would prefer if the input to the software was published and anyone could verify the outcome. Unfortunately, currently none of this information is published and the whole system is based on trust.
Let's say that the software is published, and the code is audited and it looks ok - it seems to implement all of the intricacies of the transfer system and so on correctly. Then what? What if the operator forgets to use the latest version? or puts a different piece of software entirely on the counting system? Having audited the source code really doesn't help; it won't remove the need to perform independent verificat…
Personally I understand your point, but I think auditing the code is a good and important first step.
Technically it's worth noting that a code audit is required in any "perfect solution", so it isn't wasted effort.
Politically it is important to establish the principle that the AEC should be required to respond to reasonable requests to verify how the process is implemented.
Similarly, merely publishing the input won't help much either; how do you verify that the published input corresponds to the actual votes? It won't remove the need for independent parties to observe the raw input (paper votes) and to make their own tallies; in which case those parties can publish their own copies.
Note that in Australia vote counting itself is manual and is already observed by multiple hostile parties. No one is proposing removing that.
Let's say that the software is published, and the code is audited and it looks ok - it seems to implement all of the intricacies of the transfer system and so on correctly. Then what? What if the operator forgets to use the latest version? or puts a different piece of software entirely on the counting system?
Since we already have access to the raw counts the audited code can be run by anyone to verify it outputs the same output as the AEC claims.