Live data from Hacker News

Internet voting is insecure and should not be used in public elections

blog.citp.princeton.edu

521–530 of 532 posts

Re: Internet voting is insecure and should not be used in public elections

#521
post #403

Earlier quoted context omitted.

Where I live we vote by mail by filling in little bubbles with a pen. the counting is done by simple photoelectronic tabulators and there is a built-in, human readable record that can be checked by hand. It is very economical and hard to compromise at a scale that has any effect. i hate the idea of using internet voting. I also don’t trust the electronic voting booths where the whole action is virtual or the older me…

> Where I live we vote by mail The problem with this, like internet voting, is that you can be coerced. e.g. a family member or your boss can tell you who to vote for and force you to submit that vote. Whereas a polling both is utterly private; you are alone and free from coercion. Nobody else knows who you voted for and they have no way of telling. In the UK, our voting is also done by paper and pencil. The votes ar…

If you limit your perspective to the people who can do it, yes. If you feel it’s important to enable everyone to participate, it doesn’t “just work”

Given the ample attention recently, with no evidence of impactful fraud, it sounds like disenfranchising citizens for no reason other than unrealistic fears.

But now that one party sees their voters increasingly use mailin, I expect to see a shift in opinions quickly. (Recent evidence suggests democrats benefit from low turnout more)

Re: Internet voting is insecure and should not be used in public elections

#522
post #510

Earlier quoted context omitted.

> It can be reduced to scanning a QR code in an app. It is a bit of a mystery to me why you think that isn't easy, practical or is susceptible to coercion. Because "scanning a QR code in an app" would lead to: 1) integrity loss, ie reduction of peers in the secret sharing concept. and/or 2) privacy loss, ie vote coercion, "show me you voted for our dear leader or something bad happens". You can either confirm your en…

> Because "scanning a QR code in an app" would lead to ... > 1) integrity loss, ie reduction of peers in the secret sharing concept. > 2) privacy loss, ie vote coercion, "show me you voted for our dear leader or something bad happens". Following your instincts instead of doing the work required to understand Prêt à Voter will lead you to that conclusion. Your instincts are wrong in this case. Neither of your claims a…

> Following your instincts instead of doing the work required to understand Prêt à Voter will lead you to that conclusion. Your instincts are wrong in this case. Neither of your claims are true. The first paragraph of the Wikipedia page makes that plain.

This is from the actual paper, not wikipedia:

> C. Audit of ballot forms Voters may wish to check that the order of candidates claimed to be encrypted on the right-hand side does indeed correspond to the list printed on the left-hand side. If this were not the case then a vote cast for one candidate may be considered after decryption as a vote for a different candidate. To provide such reassurance, voters may elect to ‘audit’ a ballot form. This involves removing the left-hand side of the ballot form, and asking the system to decrypt the candidate list from the onion on the right-hand side. The voter can then check that the decrypted list matches the list of candidates printed on the left-hand side. In principle, this audit can be carried out as often as the voter wishes. This gives the voter confidence that the ballot forms have been correctly constructed.

> However, the voter is not allowed to cast a vote on a decrypted ballot form. Once the candidate list associated with a onion is known, vote privacy, and hence resistance to coercion and vote-selling, is lost. The audit process gives an individual voter confidence that the ballot forms are correctly constructed, but does not allow her to check the ballot form that she is using to cast the vote.

What I said in GP is that you can't verify WHAT you voted for AFTER the fact, because the concept of coercion hinges on being able to threaten or pay for something the victim can provide. It's a logical proof, you can't design that away. I'm not saying it's not a valid trade-off.

Re: Internet voting is insecure and should not be used in public elections

#523

Earlier quoted context omitted.

It's not. Plenty of people do none of those things.

Not a problem. We should pay for them to get proper identification. This is likely an infinitesimally small percentage of the population qualified to vote. As the other commenter said, you need identification for most important things in life. Yet, again, if someone does not have ID and they want to vote, it should be easy and free. If they can't drive, we pay for an Uber. If they don't understand the process, we pay…

Voting is much more fundamental to a democracy than Uber lmao, therefore it's worth it to make the effort to make sure as many people as possible can participate.

We have essentially ~no voter fraud in the US, so the only reason to change it is because you want to prevent other people from voting for selfish reasons.

Re: Internet voting is insecure and should not be used in public elections

#524

Earlier quoted context omitted.

This is 100%, completely absolutely untrue. Stop repeating this propaganda. The system is actually really well designed and safe, I was a poll observer. You cannot "fabricate" votes, because all mail-in ballots are associated with a voter. Or rather, you put your ballot in an envelope and the envelope is associated with you. When your ballot is received, you are marked as voted and other ballots are invalid. The enve…

Claims of voter fraud have shifted to mass voter registration occuring for people that are not eligible to vote, then ballots being sent out without being requested. How is this concern addressed?

Yeah, and those claims are made up to scare people who don't know how it works.

The government knows who is a citizen and who isn't lol, they literally have the records.

Voter rolls are very closely scrutinized. Dead people are, in fact, taken off the rolls. There is essentially ~no voter fraud and ~no instance of non-citizens voting in this country. Yes, it's audited and studied. Yes, they keep the data and you can audit it.

You're literally complaining about it being easier for people to participate in democracy, and you should stop.

Everything's a conspiracy when you don't know how anything works.

Re: Internet voting is insecure and should not be used in public elections

#525
post #522

Earlier quoted context omitted.

> Because "scanning a QR code in an app" would lead to ... > 1) integrity loss, ie reduction of peers in the secret sharing concept. > 2) privacy loss, ie vote coercion, "show me you voted for our dear leader or something bad happens". Following your instincts instead of doing the work required to understand Prêt à Voter will lead you to that conclusion. Your instincts are wrong in this case. Neither of your claims a…

> Following your instincts instead of doing the work required to understand Prêt à Voter will lead you to that conclusion. Your instincts are wrong in this case. Neither of your claims are true. The first paragraph of the Wikipedia page makes that plain. This is from the actual paper, not wikipedia: > C. Audit of ballot forms Voters may wish to check that the order of candidates claimed to be encrypted on the right-h…

> What I said in GP is that you can't verify WHAT you voted for AFTER the fact

Agreed, you can't prove you voted in a particular way in any system that prevents vote buying. I'm struggling to see why that is relevant to this discussion.

What Prêt à Voter does is allow you to confirm that your vote was counted accurately. Its magic is it does that without revealing how you voted. You've now read the paper and you didn't contest that, so I'm guessing you concede it's true.

My point above was the two claims you made, ie scanning a QR code in an app would somehow lead to integrity loss, and/or privacy loss in Prêt à Voter system are wrong. You don't seem to be contesting that either, so I guess you now concede they are indeed wrong.

You made those incorrect claims after I pointed out your earlier claim that checking your vote in a Prêt à Voter system is so difficult no-one would do it was also wrong, as it boils down to scanning a QR Code with an app. I guess you had to concede that is indeed pretty easy, so you invented those incorrect "facts" to prove scanning a QR Code couldn't work for other reasons. But it does work.

It's not a good track record, is it? One invented fact after another, all in an effort to prove end-to-end verifiable voting is somehow worse or less secure than our current paper systems.

That's also wrong of course, but worse than that many of our current systems aren't the "secret ballots cast in a secure polling place" system you are assuming we use. They are postal, or electronic, or worse the combination of the two we call internet voting. These electronic systems are particularly susceptible to wholesale attacks, and in my view they need something like Prêt à Voter to have a hope of being as secure as the old paper systems.

I will concede one thing. Personally I doubt in an election everyone thought was well run that many people would bother checking their vote was counted correctly, but that's not because it's hard, it's for the same reason we don't recount every paper ballot if it isn't close - why bother? But if there was a whiff of fraud in the air, it seems likely a lot of people would do the check, particularly if the Prêt à Voter receipt was recorded on their phone when they voted. That way they would not even have to scan a QR Code. They just feed the receipt to the checking app when the election results are published.

Re: Internet voting is insecure and should not be used in public elections

#526
post #522

Earlier quoted context omitted.

> Following your instincts instead of doing the work required to understand Prêt à Voter will lead you to that conclusion. Your instincts are wrong in this case. Neither of your claims are true. The first paragraph of the Wikipedia page makes that plain. This is from the actual paper, not wikipedia: > C. Audit of ballot forms Voters may wish to check that the order of candidates claimed to be encrypted on the right-h…

> What I said in GP is that you can't verify WHAT you voted for AFTER the fact Agreed, you can't prove you voted in a particular way in any system that prevents vote buying. I'm struggling to see why that is relevant to this discussion. What Prêt à Voter does is allow you to confirm that your vote was counted accurately. Its magic is it does that without revealing how you voted. You've now read the paper and you didn…

I haven't been inconsistent, nor invented anything, I would suggest getting a third party to read this thread if you believe so.

However, I would also suggest reading the guidelines, specifically these:

> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.

> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."

> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.

> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".

Re: Internet voting is insecure and should not be used in public elections

#527

Earlier quoted context omitted.

Claims of voter fraud have shifted to mass voter registration occuring for people that are not eligible to vote, then ballots being sent out without being requested. How is this concern addressed?

Yeah, and those claims are made up to scare people who don't know how it works. The government knows who is a citizen and who isn't lol, they literally have the records. Voter rolls are very closely scrutinized. Dead people are, in fact, taken off the rolls. There is essentially ~no voter fraud and ~no instance of non-citizens voting in this country. Yes, it's audited and studied. Yes, they keep the data and you can…

From the mail-in ballots from 2024 alone, tens of thousands were returned because somebody had already voted. If you're generous that is 'accidental attempts at voter fraud'. If you're realistic those are going to largely compose a small percent of all successful efforts at voting on behalf of other individuals.

And this for elections which are increasingly decided (in terms of flipping the electoral college one way or the other) by votes in the tens of thousands to low hundreds of thousands. So the scale of fraud in US elections is likely greater than the minimum margin of electoral college victory in them.

--

You also are substantially overstating the degree of organization of voter rolls. Voting in the US is heavily decentralized by design, which is what enables various states to have completely different electoral systems. But more specifically voter rolls are maintained by the states themselves and that, in turn, is typically further decentralized down to counties themselves.

This leaves a significant degree of inconsistency. In general I do not think that double voting or completely ineligible voting is a significant factor - nowhere near as much as voting on the behalf of others, but it certainly happens. For instance thousands of mail in votes were rejected because they came from dead people, and it is highly unlikely that 100% of these attempts were caught.

Re: Internet voting is insecure and should not be used in public elections

#528

Earlier quoted context omitted.

> Just as there is nothing to prevent a person threatening or physically coercing 8 members of their household to vote as they direct. You are wrong. In person voting in the sanctity of the private voting booth prevents this.

You arguing with the wrong person. I am saying that we need to go to in-person paper ballots. The comment you responded to was about the scenario of someone getting a bunch of ballots and filling them out at home or making their household fill them out at home the way he or she might want to.

Sorry for the misinterpretation.

Re: Internet voting is insecure and should not be used in public elections

#529
post #452

Earlier quoted context omitted.

Years ago in Argentina, a corrupt politician forced a small community to vote for them using a clever trick. They instructed the voters to fold their ballots into a specific shape or figure. Since the paper wasn't torn or damaged, the votes remained legally valid. This allowed the politician to ensure the exact number of promised votes were in the ballot box during the count

But votes aren't counted by how the paper is folded. Any one of the voters could stamp/mark another name (or no name at all) and still fold the paper as instructed. So, how does that work?

Because there was no unique ballot where you mark a name. Each party has it own ballot.

Re: Internet voting is insecure and should not be used in public elections

#530
post #190

Earlier quoted context omitted.

Because you can’t make me sign my ballot? Because without my signature the ballot is void. I can also show up in person to cure my vote if you force me to sign it at home btw. It’s not impossible - I won’t deny it. But we haven’t had any substantial evidence despite the current administration trying to claim otherwise. If we are to roll back mail in ballot, let’s also make voter ID free and easy, and also make Electi…

> But we haven’t had any substantial evidence despite the current administration trying to claim otherwise. Take politics out of it. My comments are not at all based on politics or ideology. It's purely a matter of process issues. It's like saying that short passwords are insecure. With regards to your lack of evidence observation, this is actually one of the problems with mail-in voting. There is now way at all to k…

> Take politics out of it. My comments are not at all based on politics or ideology. It's purely a matter of process issues. It's like saying that short passwords are insecure.

When there're people with unlimited resources who are actively looking for evidence to back up the claim, it makes sense to bring that up because they haven't found anything.

Post reply on HN