Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

51–60 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#52
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

You're conflating "efficiency" with "disenfranchising voters."

Mail-in voting enabled citizens who otherwise simply couldn't vote, to vote. Citizens who, more often than not, were from already disadvantaged backgrounds.

Re: Internet voting is insecure and should not be used in public elections

#53
I think this relies on the old argument that anything connected to the internet is potentially insecure. While it might have some truth, practically we all do very sensitive stuff securely while connected to the internet. The risk is there, always, but you put all the measures to mitigate it and even prevent it.

The idea that a malware could be on a phone “altering things automatically” feels like a 90s FUD cliche. If an online voting system existed, it won't be like a poll that you see on Twitter, for instance; it will be far more involved. For example, we can have blockchain as the network, and not just transparent to all, but even after you vote you can still check your vote and see if it was potentially altered, and a proper electronic chain of custody can also ensure that the vote was counted per the process, and all of that is visible to anyone who would like to check and even count ALL the votes yourself, again, just like how transparent blockchain is.

And saying paper voting is more secure isn't true at all, because these votes will be counted electronically at some point, either by a machine or just a simple Excel sheet, opening the same risks as the previous one except here, if it would happen, you will never know and you as a voter can't trace the vote from when you voted all the way until it was counted. The voting process should be designed in a way with zero trust in mind, just like how secure systems are designed now, like storage, encryption, vpn, etc., and voting should too.

I personally believe that we can build a very secure, robust, and trustworthy system that can be used for voting online, but I think no one wants that for all sorts of political purposes, either by actually altering the results that could go unnoticed, or at least keeping the window open to blame the results on a faulty system.

Re: Internet voting is insecure and should not be used in public elections

#54
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

What if some level of efficiency (not necessarily internet) improves turnout and participation?

We have mail voting as a default in Colorado. When you get your license you are registered to vote and opted in automatically. The one piece that might improve it further is if it came with a stamp to mail back. Otherwise you just drop it off at a drive-up ballot box. You can also vote in person if you want. Hardly anybody does it so there’s never a line.

You get text messages each step of the process too. “Your ballot has been mailed”/“your ballot has been delivered”/“your ballot has been received”/“your ballot has been counted - thanks for voting”.

Re: Internet voting is insecure and should not be used in public elections

#55

Earlier quoted context omitted.

Verifiable in this context means I can verify my vote was tallied correctly.

That would also mean someone could force you to show who/what you voted for.

Not necessarily. In Colorado they handle this by putting the ballot in a blind envelope inside a trackable envelope. I can verify the details of the receipt of that trackable envelope to the tallying center where it is verified as untampered and opened under video with multiple people present. The unmarked envelope is added to all the rest of the ballots to be counted.

Re: Internet voting is insecure and should not be used in public elections

#57
post #3

I live in an economy where people vote with pencils on paper in cardboard booths and at scalable cost, it just works. Obviously the cost also has to scale linearly for the 200+m voter economies, and time becomes a factor, but for community acceptance I still think paper and pen/pencil beats machine hands down. (this is Australia. we have compulsory attendance at voting booths for eligible citizens, you can spoil your…

Australia really uses erasable pencil markings to vote? I would feel much better if they required ink.

It's pencil in Canada too. Pencil works. Ink pens stop working, and are far more expensive than pencil in bulk. Voting is old. Using fountain pens, and quills to vote, is far more annoying than pencil when it just works.

The mark of vote being indelible or not is irrelevant. The monitoring and protection of the ballots is far more important. For example, representatives of all political parties are involved in the count, oversight by an agency, etc. If you had time to erase and re-mark ballots, you could swap out paper ballets too.

Re: Internet voting is insecure and should not be used in public elections

#58
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

Just do both like we do here in GA. You vote on a computer, it prints out a piece of paper, you walk the paper over to some kind of scanner, and then it is deposited into a giant trash can. (maybe they keep the paper records, idk) - these are the dominion systems. (memories..) When I lived in NYC there was a giant lever you got to use - it was pretty fun - but positioning the actual paper was kind of tricky. I think…

The New York mechanical machines by the 2000s were all worn out, there was a statistically higher occurrence of certain numbers (I believe 9) because the gearing was worn down.

Re: Internet voting is insecure and should not be used in public elections

#59
post #5

The most important feature of public elections is trust. Efficiency is one of the least important feature. When we moved away from paper voting with public oversight of counting to electronic voting we significantly deteriorated trust, we made it significantly easier for a hostile government to fake votes, all for marginal improvements in efficiency which don't actually matter. Moving to internet voting will further…

The majority of the U.S. votes on paper: https://verifiedvoting.org/verifier/. Most of the rest of the country votes using Ballot Marking Devices that produce paper ballots; less than 5% of the population lives somewhere where the only or default choice is electronic voting.

Re: Internet voting is insecure and should not be used in public elections

#60

Estonians seem to have funny ideas on this. They're very VERY digital-forward.

And their system has the same problems as all the others: https://estoniaevoting.org/

Looks like. More recent papers still find vulnerabilities too.

Steelmanning: They're putting the effort in so we don't have to. Either they find a way and it'll be awesome, or at some point they become an object lesson.

edit: Or third path: They muddle along just well enough with a system that can't work in theory, but ends up nearly working in practice, stochastically? (see also: email, wikipedia, or a hundred other broken things that can't possibly work but are still hanging on. )

Post reply on HN