Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

221–230 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#221
post #178

Earlier quoted context omitted.

> The most important feature of public elections is trust. Agreed. However, in some states, such as California, mail-in voting has become the default. What's used to verify identity and integrity? Your signature from your voter's affidavit of registration, a signature from any past voter form, or literally an "X"[1]. Your signature doesn't even need to match, it just must have "similar characteristics". You can print…

Do you not have in-person early voting? In Australia you can postal vote if necessary, but "prepoll" voting is much more popular (I believe 37.5% of registered voters, 90% of which actually voted, in 2025). It's just so convenient, with the same crowd of volunteers and officials as actual polling day.

In 2020's national election, nearly 87% of California votes were by mail[1].

California offers day-of in-person voting, and has ballot-drop boxes (unmonitored) and drop-off (monitored) locations for at least several weeks (I believe it was a full month in the past election).

[1] https://abc7.com/post/election-2024-21-californias-registere...

Re: Internet voting is insecure and should not be used in public elections

#222
post #137

Earlier quoted context omitted.

[flagged]

Do you have a citation for voting by mail being demonstrable problematic? None of the things you describe are even true. We’ve been voting by mail in Oregon for decades and the demonstrated instances of voter fraud are effectively zero. The Heritage Foundation, which is opposed to vote by mail, has a great list here: https://electionfraud.heritage.org/search?state=OR . I encourage you to click the ‘Read’ tab to see t…

Apropos of nothing, Oregon has over 800,000 inactive voters [0] on the voter roll that should have been removed but weren't. So there's room for improvement.

[0] https://www.oregonlive.com/politics/2026/01/facing-trump-adm...

Re: Internet voting is insecure and should not be used in public elections

#223

Voting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1.…

That's pretty much the same in France

Re: Internet voting is insecure and should not be used in public elections

#225

Earlier quoted context omitted.

I suppose I'm an optimist. I believe it is possible to create a secure online voting system. My life savings might be held at Fidelity, Merrill, or elsewhere, my banking is online, 90% of my shopping is online and it all has "good enough" security. Plus most banks seem to be well behind the state of the art in security. I believe with the technologies we have available today, we could create a secure, immutable, audi…

We have ID.gov and we have blockchain. If we can ensure that the person submitting the vote is indeed that person, would it matter whether it was online, in a booth, or by mail?

I'm told people of color have a hard time getting IDs.

Re: Internet voting is insecure and should not be used in public elections

#226

Voting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1.…

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

Politicians just use those accusations as cover for conducting fraud or enabling the conditions that they inherently benefit from. There's no reason to not use paper, ID checks, and same-day accounting.

Re: Internet voting is insecure and should not be used in public elections

#227

Earlier quoted context omitted.

The ballot has to be anonymous, or unable to be tied back to the voter once cast. It’s a hard requirement for a variety of reasons

You have to trust the voting place/ballot receiver in all cases. Like, after they take your name, you need to make sure that they aren't secretly associating your name with the ballot you are filling in. Likewise, if you vote by mail, you need to make sure that they aren't associating your identity on the envelope with the anonymous ballot inside the envelope.

Please do yourself a favor and volunteer at a voting location. These are essentially solved issues, and you seem completely unaware of that fact.

Re: Internet voting is insecure and should not be used in public elections

#228

Voting is not a monolithic process. It's actually a combination of 3 things: - How votes are cast - How votes are counted - How votes are custodied In order for an election to be trusted, all three steps must be transparent and auditable. Electronic voting makes all three steps almost absolutely opaque. Here's how Mexico solves this. We may have many problems, but "people trust the vote count" is not one of them: 1.…

What I failed to understand is why only in the US the voting procedure is so controversial. Want paper vote? That's racism. Want counting in a day? That's xenophobia. Want to limit certain time window for counting? That's definitely racism. It's funny that the US criticized that EU countries were getting less democratic. Well, at least those countries have a much more sane voting process.

I think these claims are badly miscontrued at best, and match one party's outlook. The Republican Party has tried inhibiting voting in ways that benefit them, often by making it more difficult for minorities to vote.

Many of those tactics existed on a large scale in the South before the Voting Rights Act, and when the Supreme Court recently invalidated the Act, many have returned. For example, reducing voting locations in minority areas so people have to travel far and wait longer. Texas and possibly other states have criminalized errors in voter registration (iirc), making it dangerous to register voters. Georgia, and others, conducted a large-scale purge of voting rolls, requiring people to re-register. Requiring government-issued ID prevents many people from voting, often poor people and immigrants who lack what wealthier people are accustomed to. Florida's voters passed a ballot measure enabling ex-felons to vote; the Republicans added a law requiring full restitution to be paid (iirc) before they could vote, effectively canceling the ballot measure vote. And these days almost any Democratic victory is called fraud; remember the 2000 election, the lawsuits, riots, threats against ordinary citizens working on local election boards and on elections, etc.

Directly addressing the parent's claims: I've never heard of paper votes being called racism - could you share something with us? Calls to limit counting are often accompanied by calls to limit the voting period, invalidate votes received later (e.g., due to US mail delays), and calls to greatly restrict mail-in voting - all things that make it more difficult for people working two-three jobs.

The Democrats have their flaws; I've never seen them try to limit voting. That should be something everyone in the US - and in the world - agrees on: Do all we can to enable everyone to vote.

Re: Internet voting is insecure and should not be used in public elections

#229

Earlier quoted context omitted.

We’re less worried about a low-scale low impact fraud my many people that is unlikely to alter results, than a systematic mass fraud by few people who can choose a result

That's the wrong perspective. The minute votes go into the mail system there is no way to know just how many mail-in votes might be subject to fraud. In other words, your characterization has no basis in evidence. Note that I am not asserting that massive fraud has been committed anywhere. That statement would be as impossible to support with evidence as yours. The only thing you can state with absolute certainty is…

> There's absolutely nothing to prevent me from filling out all eight of them as I see fit and mailing them. Nothing.

Until the other seven people try and cast votes.

Re: Internet voting is insecure and should not be used in public elections

#230
It is possible to have a system that works as follows:

1. People vote on paper ballots by filling in an oval next the candidate they wish to vote for. They fill the oval with a marker provided by the election officials.

2. These ballots can be counted by hand, but they can also be counted by optical scan machines to get fast results. Optical scan machines do not have to be computerized--they have been around since the 1950s long before there were computers small enough and/or cheap enough to use for this. No computer means no software to get hacked.

Almost half of registered voters live in districts that already use that kind of ballot and already count it with optical scan machines.

3. By the use of some nifty chemistry and some clever cryptography an end-to-end auditable voting system can be overlayed on this.

End-to-end auditable voting systems (also called end-to-end voter verifiable systems) have these properties:

• Individuals can verify that their ballot was included in the final count and they vote was attributed correctly.

• Any third party can verify that the ballots were counted correctly. The candidates, the parties, news organization, civil rights groups, and anyone else can check.

• Voters cannot prove to third parties who they voted for. This is called coercion-resistance.

Here is such a system, developed by several well known cryptographers including David Chaum and Ron Rivest [1]. Here's a paper in HTML with the details [2]. Here's a PDF of that paper [3]. Here's a paper showing that it is coercion-resistant.

This is compatible with existing optical scan machines, so the places already using them don't need new machines.

The magic happens in printing the ballots. Inside each oval they print a code in a special invisible ink. When the special marker provided by the election officials is used to fill in the oval that code becomes visible.

If you want to be able to later verify that your particular vote was included and counted correctly you memorize or write down that code. If you don't care about this you can ignore it.

After the voting is done officials can publish all the codes that were revealed and voters can check to make sure their code was included. They officials publish other information that through the use of clever cryptographic techniques allows anyone to use the published codes to verify the totals for all the candidates without revealing the mapping from codes to candidates.

This gives us all the good points of paper systems that can be hand counted, plus fast machine counting that can be done with simple single purpose machines that have no software to be hacked, yet with the kind of end-to-end auditing that usually requires computerized voting systems to achieve. And it is inexpensive to implement and operate.

[1] https://en.wikipedia.org/wiki/Scantegrity

[2] https://www.usenix.org/legacy/event/evt08/tech/full_papers/c...

[3] https://www.usenix.org/legacy/event/evt08/tech/full_papers/c...

[4] https://eprint.iacr.org/2010/502.pdf

Post reply on HN