Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

211–220 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#211
Honestly we should just have block chain based PUBLIC voting.

This article is right about secret internet voting: it’s fundamentally incompatible with unsupervised devices and global networks. But secrecy is the constraint that breaks everything.

If you instead require public, verifiable voting, most of the "unsolved" problems disappear. The core requirement becomes: everyone can independently verify inclusion and correct tallying.

That’s where blockchains are a genuine game-changer: - They provide a public, append-only, tamper-evident system of record.

- Anyone can recompute the tally from first principles — no trusted servers, no “checker apps,” no special dispute resolution.

- Server compromise or insider attacks stop being catastrophic; fraud becomes immediately visible rather than silently scalable.

- Malware can still affect an individual’s vote, but it can’t secretly change the election at scale — the main failure mode highlighted in this post.

If trust is the goal, opacity is the wrong primitive. The secret ballot is mistaken path solving a non existent and purely theoretical problem of vote buying.

In a world where we expect everything to be easily accessible, the hardships placed by all the steps required to vote (registration, confirming residency location, waiting in line for polling booth) is seriously impacting voter participation. We need to get with the times and modernize this voting infrastructure.

Re: Internet voting is insecure and should not be used in public elections

#212
post #45

The thing about paper ballots is that the ways to cheat with them are well-known ("finding" ballots in the trunk of a car, "losing" ballot boxes on the way to the counting center, counting the ballots behind locked doors with observers not present, and so on), and have been well known for centuries. So the counters to them (ballot boxes sealed with an official seal once full, only sealed ballot boxes will be opened a…

An interesting anecdote, another good example of a reasonably modern example of paper ballots enabling election stealing: https://en.wikipedia.org/wiki/Box_13_scandal

Caro covers this pretty extensively in his LBJ biography series, but it's reasonably clear from the evidence that LBJ won his senate seat by some pretty crude paper voting record manipulation after the fact - changing a '7' to a '9' by writing over the number with a pen - almost certainly with LBJ's knowledge. Given that his senate seat eventually put him in the presidency, it's probably the most consequential voter fraud ever committed in American history (that we know about, I suppose).

Re: Internet voting is insecure and should not be used in public elections

#213
post #178
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

> The most important feature of public elections is trust. Agreed. However, in some states, such as California, mail-in voting has become the default. What's used to verify identity and integrity? Your signature from your voter's affidavit of registration, a signature from any past voter form, or literally an "X"[1]. Your signature doesn't even need to match, it just must have "similar characteristics". You can print…

Do you not have in-person early voting?

In Australia you can postal vote if necessary, but "prepoll" voting is much more popular (I believe 37.5% of registered voters, 90% of which actually voted, in 2025). It's just so convenient, with the same crowd of volunteers and officials as actual polling day.

Re: Internet voting is insecure and should not be used in public elections

#214
post #127
post #53

I think this relies on the old argument that anything connected to the internet is potentially insecure. While it might have some truth, practically we all do very sensitive stuff securely while connected to the internet. The risk is there, always, but you put all the measures to mitigate it and even prevent it. The idea that a malware could be on a phone “altering things automatically” feels like a 90s FUD cliche. I…

Why is it FUD? It's a real thing any competent programming team could implement.

Well it isn't primarily the technicality aspect but rather the same risks that apply to end users are also applied to the people working at the polling station and their equipment, bringing it up when you are talking about one side only is just a tactic to discredit it. That being said, modern phone OSes are also unlike before, app isolation among others prevent such attacks, I don't think I came across a new attack that just altered another app on the fly, otherwise, we would have hundreds of cases of people getting their bank accounts compromised. In fact, I think from a technical standpoint, the risks of having such malware on end users' devices are harder to implement compared to infecting say the Android OS running on the voting screen at the polling station, or anywhere else in the process. Because in the end users' ones you can restrict the app to run under certain criteria similar to banking ones, and independent security researchers can check it for potential vulnerabilities, meanwhile an internal app used in the polling station won't have these measures, and you can even assume the OS/packages are outdated and vulnerable, making it far less secure, something like how flock cameras Android OS is a security nightmare for example.

Re: Internet voting is insecure and should not be used in public elections

#215
post #99
post #88

Earlier quoted context omitted.

> I would prefer a system where even in 20 years I can go online and check how my vote was counted in older elections - this way stealing my vote would be impossible. Understandable, but then vote-buying becomes possible. The reason vote-buying is impossible in a secret ballot is because you can't prove how you voted to anyone else. If you can look up your own ballot even five minutes after it's dropped into the box,…

Vote buying and worse 'vote for me or I'll shoot you'. Buying is the more common scam but there are worse options for evil people

A related issue is “vote for my preferred candidate, or I’ll abuse you” as a way for husbands to control wives. That’s especially relevant when one party is favored by a majority of men while the other party is favored by a majority of women.

Re: Internet voting is insecure and should not be used in public elections

#216

Voting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1.…

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

> Want counting in a day? That's xenophobia. Want to limit certain time window for counting?

Why do either of these matter? If you assume paper voting in-person is secure, then there is zero reason to also limit the time spent counting or the time window for counting. Anything past that point is clearly trying to fill some sort of agenda for the sake of disenfranchising people who cannot adhere to the times you're trying to set.

Re: Internet voting is insecure and should not be used in public elections

#217
post #196

Earlier quoted context omitted.

I don't understand the critique. Nobody has ever made these claims. I don't mean this as an ad hominem, but was this comment generated with AI or something?

You'll find those claims in sibling comments to yours, so they are clearly pretty real! (At the time of writing this comment there's a sibling claiming that the comment cannot possibly understand this POV because they are not "an American POC.")

> You'll find those claims in sibling comments to yours, so they are clearly pretty real!

Really, where? In the sibling comments (including mine) people are pointing out that those claims are specious.

Re: Internet voting is insecure and should not be used in public elections

#218
post #76

Earlier quoted context omitted.

Not necessarily. In Colorado they handle this by putting the ballot in a blind envelope inside a trackable envelope. I can verify the details of the receipt of that trackable envelope to the tallying center where it is verified as untampered and opened under video with multiple people present. The unmarked envelope is added to all the rest of the ballots to be counted.

So then you can verify your vote reached the tallying center, but not that it was tallied correctly. Someone can look at your vote and count it wrong. I think that's fine and the best we can do, but the person I replied to said you can verify your vote is tallied correctly. That implies checking what the actual vote was.

All true, but this is no different than any other ballot in the state. At a certain point you can choose anonymous ballots or you can choose trackable ballots.

Re: Internet voting is insecure and should not be used in public elections

#219

Earlier quoted context omitted.

[flagged]

You don't think those 8 people you stole votes from might ask some questions? This is a self-correcting problem, as evidenced by the fact that the few voting fraud cases that do happen (generally nutbag conservatives convinced they are 'balancing out' fraud by commiting it) are usually quickly found and prosecuted l.

those 8 people could sell their votes and show proof of it before mailing in their ballots, that's a lot more difficult to do with in person voting.

Re: Internet voting is insecure and should not be used in public elections

#220

Earlier quoted context omitted.

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

Are you American? Are you white? There are historical factors that contribute to those things you brought up. American minorities are disproportionately affected by things like limited hours, for example. You'd know that if you were an American POC.

GP has also taken these issues and personalized them. They're about impact and access, not whether the person raising the idea is racist or a xenophobe or whatever.
Post reply on HN