Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

501–510 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#501

Earlier quoted context omitted.

> There's absolutely nothing to prevent me from filling out all eight of them as I see fit and mailing them. Nothing. Until the other seven people try and cast votes.

Think that through for a moment. Hint: They never see the ballots. My point wasn't to paint a water-proof scenario. It is to illustrate just how unreliable and dangerous mail-in voting can be. There are other vectors for manipulation.

Not seeing the ballots won’t necessarily stop them from trying to vote. They might ring up to complain that they never got them. They may try and go in vote in person. Trying to vote using someone else’s name or ballot can very easily land you in hot water.

Re: Internet voting is insecure and should not be used in public elections

#502

Earlier quoted context omitted.

The US overwhelmingly uses paper voting (often paired with electronic tabulation). We can't "move back", it's where we are. Electronic tabulation introduces little risk when the ballots are paper.

As we learned from Dominion... depends who manufactures the machine.

> As we learned from Dominion... depends who manufactures the machine.

Dominion, the company that doubled it's net worth by winning a defamation suit against Fox over claims their machines had been compromised?

That Dominion?

Re: Internet voting is insecure and should not be used in public elections

#503
Agree with everything being said here.

However, it is no longer even remotely paranoid to be concerned that the current administration plans to do one or more of:

1. Put its thumb on the scale by "guarding" urban polling places with paramilitary forces on election day,

2. Declare mail-in ballots illegitimate and seize them,

3. Seize voting machines or attempt to stop vote counts before all votes are counted,

4. Intimidate state legislatures by threats or economic blackmail to disregard results.

I don't see an alternative to trying to figure out how to make online voting secure. That won't solve (4) but it will at least mitigate some of the more direct methods of election fraud.

Re: Internet voting is insecure and should not be used in public elections

#504

It’s not that it’s impossible - it’s that the established players are already questionable. And any new entry would require more than any simple company could provide. Heavy investment and collateral is required. Our livelihoods are increasingly (almost entirely) digital and endure great efforts to abuse. But banking and/or retail operate on a different spectrum. For one they make money. The costs associated allowing…

Prediction: In 2026 the Trump administration will attempt to ban all other forms of voting and will claim that it is in the interests of election security, because the Democrats can't be trusted to count votes (remember the 2020 election was "stolen"?), so we need to mandate all votes be counted electronically using some sketchy electronic voting system, which a company that is very politically friendly to Trump just…

Yes - thank you for reminding me a voting machine system was also bought recently (too long a process to get in? Just pay more)

https://abcnews.go.com/amp/US/dominion-voting-systems-sold-c...

Re: Internet voting is insecure and should not be used in public elections

#505
post #127

Earlier quoted context omitted.

Why is it FUD? It's a real thing any competent programming team could implement.

Well it isn't primarily the technicality aspect but rather the same risks that apply to end users are also applied to the people working at the polling station and their equipment, bringing it up when you are talking about one side only is just a tactic to discredit it. That being said, modern phone OSes are also unlike before, app isolation among others prevent such attacks, I don't think I came across a new attack…

Everything needs to be on paper.

Re: Internet voting is insecure and should not be used in public elections

#506

Earlier quoted context omitted.

Military and overseas voters vote in their home state elections, even federally (all elections are held by states, even for federal candidates). You would need to ensure that there is a ballot box representing each state that has an eligible voter at a given site, and then need to figure out logistics for getting thousands of sealed boxes back to the vote counters in each state within the allotted deadline. You would…

> Or, you could have a central, federally run organization that takes responsibility for delivering sealed ballots to the respective states in a timely manner. Which is what we call voting by mail. No, postal voting is not the same as bringing ballot boxes to voters in exceptional circumstances and does not have the same set of tradeoffs. Postal voting in particular certainly does not solve the voter manipulation pro…

[deleted]

Re: Internet voting is insecure and should not be used in public elections

#507

Earlier quoted context omitted.

People were being unknowingly registered to vote, even if they weren't eligible to vote when they would get IDs. People move. They get sent ballots. Now you have tons of ballots that aren't really valid, but they're out there and usable. It makes illegal ballot harvesting a lot easier as well if there's no active step where the ballot must be requested. I have to request my ballot every election. it takes 5 minutes,…

Why couldn't a ballot harvester send a ballot request on your behalf?

it depends on the state and how thorough their verification system is. I can only speak for IL, but in order to request a mail in ballot, you must be registered to vote first. Even if you register online, you must at minimum provide a DL number or SSN, and the state will associate a signature with your registration. Which is then cross referenced to the signature on your ballot envelope. If you don't have a signature and you try to vote by mail, and in the slim chance your registration is actually approved, you are now a first time non signatures voter, and your mail in ballot will be provisional at best.

This is why many of the election fraud claims focused on lax signature verification of ballots as well as the lax mail in ballot address locations. I feel that IL elections are probably more secure, but only because the state is solidly one party and comically gerrymandered anyways.

But technically, yes, a ballot harvester could send ballots on your behalf if they have enough information about you.

Re: Internet voting is insecure and should not be used in public elections

#508
post #499

Earlier quoted context omitted.

> Yes, but only by using as much verification as paper ballot casting I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems. Using these systems they can. There are two kinds of attacks: typically classes as retail and wholesale. Retail attacks happen at the front end: stuffing ballot boxes, coercion, vote buying. As the effort involved roughly corresponds to the nu…

> I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems. In the current paper systems you don't have to, as you know what you put on it before it got anonymized and counted as one vote by the teams watched by teams. > Using these systems they can. In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion. In gene…

> In the current paper systems you don't have to,

True. But the "secret ballot in a polling booth using paper" systems are disappearing. 32% of Australian votes aren't done that way now.

> In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion.

It can be reduced to scanning a QR code in an app. It is a bit of a mystery to me why you think that isn't easy, practical or is susceptible to coercion.

Re: Internet voting is insecure and should not be used in public elections

#509
post #496
post #403

Earlier quoted context omitted.

> Where I live we vote by mail The problem with this, like internet voting, is that you can be coerced. e.g. a family member or your boss can tell you who to vote for and force you to submit that vote. Whereas a polling both is utterly private; you are alone and free from coercion. Nobody else knows who you voted for and they have no way of telling. In the UK, our voting is also done by paper and pencil. The votes ar…

You can be coerced with paper and pencil too. In Sicily mafia gives you a voting paper with a predrawn X on the candidate they want, and you must come out with a clean voting paper so they are sure you did leave the pre-voted one.

In the UK, you are handed a ballot paper in the voting room by an official immediately before you go to the polling booth; the ballot paper has an official mark on it, meaning no pre-printed or duplicate ballot papers are possible.

This makes the attack you described impossible (short of having every official in the voting room being corrupt).

Re: Internet voting is insecure and should not be used in public elections

#510
post #499

Earlier quoted context omitted.

> I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems. In the current paper systems you don't have to, as you know what you put on it before it got anonymized and counted as one vote by the teams watched by teams. > Using these systems they can. In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion. In gene…

> In the current paper systems you don't have to, True. But the "secret ballot in a polling booth using paper" systems are disappearing. 32% of Australian votes aren't done that way now. > In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion. It can be reduced to scanning a QR code in an app. It is a bit of a mystery to me why you think that isn't easy, pract…

> It can be reduced to scanning a QR code in an app. It is a bit of a mystery to me why you think that isn't easy, practical or is susceptible to coercion.

Because "scanning a QR code in an app" would lead to:

1) integrity loss, ie reduction of peers in the secret sharing concept.

and/or

2) privacy loss, ie vote coercion, "show me you voted for our dear leader or something bad happens".

You can either confirm your encrypted ballot is present, OR you can decrypt it before being cast, in which case it can't be cast anymore. Unless I'm missing something they're mutually exclusive. The entire premise of the mix net is not being able to verify what you voted for, only that your vote is there, right?

Post reply on HN