Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

421–430 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#421
post #404

Earlier quoted context omitted.

Because they operate in a non good faith model where discouraging voting and gerrymander is normalised. The electoral commission is politicised, not neutral and independent. Because voting is held at times and dates which disadvantage working poor, because voter ID rules are capricious and partisan.

>because voter ID rules are capricious and partisan. Can you elaborate?

When looking at supporters of voter ID laws, look at whether they support free IDs, expansion of DMVs/issuers of IDs, etc.

Similarly, opposition of mail-in-voting typically ignores or supports closing down polling places (in strategically partisan areas), making it difficult for groups of people to vote.

These issues are always (by design) discussed in isolation, while ignoring the intrinsically related issues.

TL;DR: Voter ID laws are fine, only if, coupled with universal free IDs for citizens. And no mail-in-voting would be fine, if voting occured on a national holiday, and polling places were reachable by all eligible voters. This is not supported by any (elected) proponent of voter ID laws or opponent of mail-in-voting.

Re: Internet voting is insecure and should not be used in public elections

#422
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

The problem, as I understand it, is that if you can prove to yourself that your vote was counted right, you can also prove it to the guy with the sledgehammer next to you saying "it would be a shame if something happened to your family, so prove how you voted"...

As soon as a system gives you a receipt, a cryptographic proof, or even a reliable way to re-verify later, you've created something that can usually be repurposed as evidence for a third party

Re: Internet voting is insecure and should not be used in public elections

#423
post #45

The thing about paper ballots is that the ways to cheat with them are well-known ("finding" ballots in the trunk of a car, "losing" ballot boxes on the way to the counting center, counting the ballots behind locked doors with observers not present, and so on), and have been well known for centuries. So the counters to them (ballot boxes sealed with an official seal once full, only sealed ballot boxes will be opened a…

With online systems, you can follow every visible procedure and still have no idea whether anything went wrong

Re: Internet voting is insecure and should not be used in public elections

#424
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

One thing I'd add is that paper voting's strength isn't nostalgia, it's public verifiability

Re: Internet voting is insecure and should not be used in public elections

#425
post #403

Earlier quoted context omitted.

Where I live we vote by mail by filling in little bubbles with a pen. the counting is done by simple photoelectronic tabulators and there is a built-in, human readable record that can be checked by hand. It is very economical and hard to compromise at a scale that has any effect. i hate the idea of using internet voting. I also don’t trust the electronic voting booths where the whole action is virtual or the older me…

> Where I live we vote by mail The problem with this, like internet voting, is that you can be coerced. e.g. a family member or your boss can tell you who to vote for and force you to submit that vote. Whereas a polling both is utterly private; you are alone and free from coercion. Nobody else knows who you voted for and they have no way of telling. In the UK, our voting is also done by paper and pencil. The votes ar…

>The problem with this, like internet voting, is that you can be coerced. As an example against coercion, on belenios faq they say that they let voter vote several times (and they count just the last vote).

Re: Internet voting is insecure and should not be used in public elections

#426

Earlier quoted context omitted.

The problem, as I understand it, is that if you can prove to yourself that your vote was counted right, you can also prove it to the guy with the sledgehammer next to you saying "it would be a shame if something happened to your family, so prove how you voted"...

There are some really clever systems that let you prove that you voted without leaking how you voted. Unfortunately, explaining them to Joe Q. Public in such a way that he's going to trust your election is a very tough sell, whereas counting paper is a much easier process to explain. And that's before you begin worrying that the developer of your whizz-bang mathematically-provable voting system is a) going to win the…

I have had this discussion many times before, with people smarter than me, and I have not yet reached a counter argument to the idea that if you can only prove that you voted (and not couple each vote to a voter), how can you prove that innumerable votes were added to the record, or that your vote is correct?

You can either couple every vote to a voter and risk oppressive monitoring of votes at scale or coercion at micro level, OR you can have decoupled voting proving that your vote was counted, but not have convincing proof that your vote or anyone else's are accurate.

Please prove me wrong because I would love it if it was possible.

Edit: Booth/paper-voting solves this by:

* linearly scaling cost of multi-party verification of identity at time of voting

* your vote being anonymous and being decoupled from you at time of deposit

* you trust the system at scale since each step in the chain-of-custody has many-eyes-verification

* vote amount is grouped by location so vote insertion can't happen at scale without coordinating with each involved polling place to fudge each of their numbers

* you can't insert into one area without having a random 100k population increase in a polling place overnight

Re: Internet voting is insecure and should not be used in public elections

#427

Earlier quoted context omitted.

I agree with the other comment about dictators and similar threatening voters, but at a mundane level: domestic violence. People do, in fact, threaten or coerce their spouse and that extends to voting. Being able to audit from a secure counting room and being able to produce an always-available-online permanent record is different.

You haven't in any way prevented this scenario. Somebody could just as well demand that their spouse take a photo or video of their vote. Yeah no cameras allowed in the voting booth is a rule, but it's not like it's enforced or even realistically enforceable.

The "no cameras/no phones" rule is absolutely enforced in Harris County, Texas, although as an election worker I have never seen this escalate beyond "Please put away your phone". Workers are to ask the voter to put it away and if not done so immediately they are to notify the election judge (top official for that location/precinct). Judge will approach and ask again and cite the actual Texas law and show the voter a posterboard with the law printed in at least 4 different languages.

At this point, if the voter has not checked in yet, we can refuse to do so. Either way, if the phone/camera is still out after the judge has asked and shown them the law, judge is to immediately call the constable's office (police), who have been positioned nearby (but never directly at any vote center, due to possible intimidation). The constable can and will remove the man from the vote center. (It's never escalated that far!) (arresting that voter for any length of time might be problematic on election day for obvious reasons).

The most common complaint is "but I wrote up all my selections on there!" and for these voters we can provide a paper "sample ballot" and even a pen and they are free to mark their selections outside of the room and then come back to vote on the machine. One location was a church that was even gracious enough to allow a gentleman to AirPrint his notes.

Also of note, we do not have any kind of a "booth", however, the machines are typically placed rather far apart, and no one is allowed to queue at or near the machines, or linger there after voting, so I believe that privacy is effectively maintained. (Workers including judges are not even allowed to linger there unless assisting a voter who has specifically asked for help, and even then, there's more rules - if the voter needs help actually making the selections for candidates, now you need at least one judge and one clerk, one of whom must observe and ensure that the voter's selections were made correctly.)

We also got rid of the problematic "digital only" machines several years ago, but this post is too long already.

Re: Internet voting is insecure and should not be used in public elections

#428
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

> it just works

And the pieces of paper with votes for the wrong candidates are easy to dispose of. See, for example, russia.

Re: Internet voting is insecure and should not be used in public elections

#429

Earlier quoted context omitted.

I could still sell my vote to my boss in the typical system. And we could use cryptography to vote anonymously after authentication online.

In the current system how do you sell your vote? You go into the voting booth alone.

"I give you $50 if you vote for me, you'll get it when I win the ballot"

If someone is willing to sell their vote in the first place, they have zero incentive to vote for another candidate. They only have to trust the buyer to follow up on his promise (which is required in any other scenario also).

Re: Internet voting is insecure and should not be used in public elections

#430

>Voters should not be able to prove to anyone else how they voted – the technical term is “receipt-free” – otherwise an attacker could build an automated system of mass vote-buying via the internet. But receipt-free E2E-VIV systems are complicated and counterintuitive for people to use. This can easily solved be done via letting people forge receipts. Then anyone can forge a vote to give to someone offering to buy th…

> This can easily solved be done via letting people forge receipts. Then anyone can forge a vote to give to someone offering to buy them.

This is the literal definition of receipt freeness. It’s hard to ensure that the receipt you receive to verify your vote had not already been forged by the malware.

Post reply on HN