12 ms·
To Protect Voting, Use Open-Source Software
- danirod 9y agoElectronic voting is a bad idea and I'd be suspicious on anyone trying to promote it. How can you know that even if the source code for the voting machine is open, the voting machine is running the exact same source code? How can you know nobody has tampered the code the instance is running? I'm glad my country is still running on paper ballots and glad we require voter ID.
- giancarlostoro 9y agoI agree with you entirely. There is no absolute way that we know of to truly know the code running is the exact code on GitHub. You can fake that it is in many ways, I don't see people running shell commands on the software before and after they vote to make sure it's the correct software. Even IF that software remains uncompromised, who owns the database? Who stops them from- Way too many factors...
- fredley 9y agoOn top of this, we all know that if it was implemented as well as physically possible, there would still be vectors for attack. However, if current voting machine trials are anything to go by, it's usually implemented extremely poorly.
- DarkKomunalec 9y ago> I don't see people running shell commands on the software before and after they vote to make sure it's the correct software. How would you know the shell itself, running on the machine you're trying to verify, isn't lying to you?
- nurettin 9y agoEvery time we vote, there is more talk about the burned ballots, unopened chests, uncounted votes and fraud concerning votes being collected from neighboring countries posing as people from my nation. So yeah. Doesn't really matter whether it's electronic or not.
- zAy0LfpBZLC8mAC 9y agoSo you mean it doesn't really matter whether we even know about the fraud happening?
- richardknop 9y agoMost fraud other than most primitive attempts by idiots goes unnoticed. If voter ID is not required it is not possible to prevent people who don't have right to vote from voting.
- geekamongus 9y ago> Most fraud other than most primitive attempts by idiots goes unnoticed. You know this how, exactly?
- richardknop 9y agoIt is my personal opinion. I think it's logical that it is easier to fraudulently vote if you don't need a voter ID.
- geekamongus 9y agoIt is also logical that voter fraud isn't necessarily an outcome of having no voter ID.
- Accacin 9y agoMy country doesn't require voter ID at all, other than confirming a few details and most studies here has shown that requiring ID didn't cut down on fraud. For me it's important that the barrier to voting is as low as possible, and we don't have a governement issued ID that is free.
- richardknop 9y agoThat should be solved by issuing a free government ID, not by compromising and creating a giant loophole when potentially citizens of other countries can vote in your election and there is no way to verify that.
- gbrown 9y agoIf you're primarily worried about attacks which can modify the result of elections, your threat model is broken.
- richardknop 9y agoWhat should you be primarily worried about? It's like serving your e-commerce website over HTTP because there have been very few security breaches. Why not get a certificate and use HTTPS? It's a massive improvement in security for a very small cost.
- gbrown 9y agoNot analogous,because attacks relying on coordinating large numbers of people (with a high rate of detection) simply doesn't scale. We should be worried about electronic attacks on voting infrastructure, political attacks on districts, political attacks on the registration process etc.
- feintruled 9y agoNot as easy as it sounds. I was in a Government office for some tax related reason and was in line behind some guys trying to apply for their 'electrical card' (sic, electoral). This is in N. Ireland, which unlike the rest of the UK requires ID to vote. They were having to be talked through filling in the form only to hit a roadblock when it came to proof of address. After expressing their voluble disbelief at some length that the handwritten doctor's note they had would not suffice, they eventually left empty-handed. (Incidentally, they were only looking the card to use it for ID for flying, they had no interest in voting). Now these guys were obviously jokers, but it shows you will need a certain degree of application and time to get even the most rudimentary of verifiable ID. Even the conscientious may find themselves not getting around to getting the ID before election and losing their vote.
- TeMPOraL 9y agoWhere is the good old Anonymous when we need them? We need a high-profile hack of some local elections to drive that point home. Something done completely for teh lulz, leading to a result so absurd the elections would have to be redone.
- octalmage 9y agoAt defcon this year they had a bunch of the popular electronic voting booths set up, and they were all hacked within 6 hours. A big problem is having physical access to the booth. All of the hacks involve picking a lock.
- zAy0LfpBZLC8mAC 9y agoGiven that the voting computers sit in some warehouse between elections, that's not really a big hurdle.
- jmmarco 9y agoYep, here's the post from Science Friday: https://www.sciencefriday.com/segments/hacking-the-vote-how-can-we-secure-our-voting-systems/ https://www.sciencefriday.com/segments/hacking-the-vote-how-...
- Iv 9y agoIf all that was at risk was a night in police jail and a slap on the wrist, it would be done, but reading the sentences one faces for election tampering is really chilling. I would not risk it for a million, I will certainly not risk it for the lulz. Plus, in most cases, it involves (laughably weak) physical security. I am less confident on how to hide my tracks there and I suppose many would-be hackers feel the same.
- Chardok 9y agoUnfortunately it would need to be a hack that purposefully gets itself caught in order to drive any point home. I can imagine the risk vs reward on something like that would be very undesirable.
- 9y ago
- JorgeGT 9y ago> and I'd be suspicious on anyone trying to promote it. It's just a former CIA Director signing the op-ed. It's not like they have a collection of zero-days and other exploits is it?
- drdaeman 9y agoThere are attempts to create an end-to-end auditable voting systems. Where you don't have to trust the organizers or machinery to not trick you, and you can validate that your vote was counted correctly. https://en.wikipedia.org/wiki/End-to-end_auditable_voting_systems https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy... Sadly, as far as I know, none is without issues (older systems were found to have various problems, and newer stuff is still bleeding edge that wasn't yet reviewed thoroughly).
- pjmorris 9y agoThe trick is that you don't just have to convince somebody (a security expert) that the system is trustworthy, you have to convince everyone (voters) that the system is trustworthy. Anything more complicated than paper ballots counted in public will leave room for doubt.
- drdaeman 9y agoThere are systems that are essentially paper ballot and by no means remove the "classic" experience, but have extra properties that allow audit, e.g. https://en.wikipedia.org/wiki/Punchscan https://en.wikipedia.org/wiki/Punchscan
- octalmage 9y agoPaper ballots leave a lot of room for doubt in my mind. How you can you recount the ballots and come up with a different number? This shouldn't be possible, but it happens all the time: https://en.m.wikipedia.org/wiki/Election_recount https://en.m.wikipedia.org/wiki/Election_recount Thinking out loud here, how about a blockchain based solution? Each user gets a new address, and that address is printed on a receipt after you vote. This way you can verify your vote at anytime, and the votes can be counted in public.
- vertex-four 9y agoThe entire point of a recount is that when the votes are close enough to swing the balance of an election, they're recounted, potentially repeatedly until we can be sure they're correct. They're essentially never more than a few votes off either way. If it's not close enough to swing the balance of the election, it doesn't really matter that a dozen votes were miscounted - we'd prefer that not to be the case, obviously, but not by breaking the other properties of the system. Short of some very very clever cryptography, you really, really don't want to be able to verify your individual vote, because that means you can verify it to others - the entire point of this process is to avoid coercion, or else there's much simpler solutions. (Pull everyone into the polling station at once and have a show of hands, for example.) You want to verify that one ballot was given to each person registered to vote, and that all votes were counted correctly, but you don't want to verify that an individual person's vote was counted correctly.
- vmateixeira 9y agoNot just the software we should be concerned about, hardware too.
- joseppe 9y agoOne word: blockchain
- Iv 9y agoCame here to say that. Transparent voting boxes, ballots in envelopes, manual redundant counting done by people, usually voter who were nicely asked if they can come help back in the evening. That's what we use in France, you get the official result a few hours after the closing of the voting stations. The whole process is watchable, from the sealing of the box the morning to the count in the end and parties send observers in random stations to check nothing fishy happens. An official log book is open for anyone to notice if they feel something fishy happened (you were not allowed to vote, the counting was unfair, etc...) Oh, and make voting day a holiday, or just put it on Sundays. I used to wonder how US could not even get that last part right, but then I understood that a whole party thinks it is in its interest to have less voters.
- _Codemonkeyism 9y agoSame in Germany.
- creaghpatr 9y agoAbout the author of the article: R. James Woolsey is a former director of the Central Intelligence Agency. Sums it up.
- cortesoft 9y agoOr make voting last multiple days instead of just one.
- Iv 9y agoThat makes it harder to keep an eye on the voting process from A to Z, which people do in the current process. If the box containing the ballots stay alone, trust is lowered. Seriously, is it harder to make a daily holiday and a transparent process than landing a man on the moon with tech from the 60s?
- EugeneAZ 9y agoThe most funniest thing is who is just eligible to be a candidate (not mention his chances to win). And how the chosen legislation, which is the result of those elections, is far from the most fair - one approved by score voting in direct democracy.
- cmiles74 9y agoThe vote processing chain is lengthy, it is inevitable that a computer system will be inserted somewhere in that chain. Right now the push is to have these systems right at the front, facing the voter, but that isn't the only time the votes are processed electronically. In my district we vote by coloring in little circles with a #2 pencil, we then feed that directly into an electronic machine that tallies the results for my district. While the paper I handled is stored in the machine, I am sure that the results are transmitted to the next link in the chain through some computer system. With so many links in the chain, it's my opinion that it's unreasonable to expect them all to be processed by people. It won't scale and I'm not convinced that it's that much safer anyway. It would be my preference that the pieces of the system that perform this processing are backed with open source software. At the very least, if there is a case where tampering is suspected, officials of the court can compare the software on the machine with the software in the repository. This would prove in a clear and straightforward manner that tampering has occurred. As painful as it is, I think we all need to trust the state, to some degree, to do the jobs that are the responsibility of the state. Once the votes have been tallied for a district, isn't it possible to tamper with them as they are transmitted up the chain to the next link in the processing? Or when regions of the state send their votes up to whatever the next link might be? I think that is possible, the best we can hope for is to push for as much transparency as possible and hope that, if it comes to it, we have enough data to detect such tampering.
- TeMPOraL 9y ago> With so many links in the chain, it's my opinion that it's unreasonable to expect them all to be processed by people. It won't scale and I'm not convinced that it's that much safer anyway. I think the main argument for physical voting is that it's much safer precisely because it doesn't scale well - and so attacks against it don't scale well either. The manpower requirements buy you security. > As painful as it is, I think we all need to trust the state, to some degree, to do the jobs that are the responsibility of the state. I agree, but I think it does not apply to elections - simply because it's the one place where both the ruling party and competing groups have very strong incentives to mess with the process. > Once the votes have been tallied for a district, isn't it possible to tamper with them as they are transmitted up the chain to the next link in the processing? Yes, but again, the argument goes, the less scalable and more manpower-intensive the whole process is, the more difficult is to hack it. > I think that is possible, the best we can hope for is to push for as much transparency as possible and hope that, if it comes to it, we have enough data to detect such tampering. I agree with the call for transparency, but I also agree with the people who point out that inserting electronic systems destroys that transparency (too easy to hack, too complex for general population to inspect).
- rotten 9y agoWhy use a voting machine at all? Isn't the main point of having a polling location simply so you can verify your identity? If we could come up with a system that allowed one's identity to be verified online, or by postal service, then do we really need thousands of machines collecting the votes. Couldn't it be centralized to a handful of more easily audited systems?
- vertex-four 9y agoNo, the point of a polling station is so that there's provably no coercion. You fill out your ballot in secret, you're not permitted to take a photograph of it, and you place it in the ballot box without telling anybody what you've voted for. The more you allow people to vote from their homes, the more likely it is that people can be coerced into voting the way their partner, employer, or otherwise, want them to.
- Spivak 9y agoYou missed one important criterion. After you vote there is no way for you to prove who you voted for. If you could verify it after the fact then it opens up potential for coercion or incentives.
- 0xffff2 9y ago>You fill out your ballot in secret, you're not permitted to take a photograph of it, and you place it in the ballot box without telling anybody what you've voted for. In the US, only one of those is guaranteed [0]. In California, where I can get an absentee ballot just by asking for it, none of those is guaranteed. [0] https://www.bloomberg.com/news/articles/2017-04-03/ballot-selfies-allowed-as-u-s-high-court-rebuffs-new-hampshire https://www.bloomberg.com/news/articles/2017-04-03/ballot-se...
- vertex-four 9y agoYes, well, the US also broadly thinks electronic vote recording is a good idea. Let's not pretend it's any good at designing voting systems.
- lawless123 9y agoI agree, you'd need a way to verify every machine is running the the open source software. The risk are too great you'll fail and the rewards for anyone that can hack the machines too great. To say a machine hasn't been hacked is trying to prove a negative.
- grondilu 9y agoI'd rather say it's a good idea but it also is a technical problem that is not yet convincingly solved. It is clear though that open source by itself is not a solution, for the very reason you mention (how can one be sure about what code is running on a machine one doesn't own?). That being said, from times to times articles show up about someone who claimed to have invented a viable solution. So we should not diss the idea and keep an open mind. Eventually someone will find a solution.
- nobodyorother 9y agopvote.org seems like a decent solution, it's <500 lines of code that needs to be audited. That doesn't handle auditing the machines themselves, but as the 2016 US presidential election recount found in Wisconsin, the tamper-evident machines showed evidence of tampering, so maybe we're closer to knowing whether the trusted systems we use to count votes are trustworthy. Of course, the current machines are still Diebold ("Premier Election Solutions"), so who knows. Ken Blackwell will make sure only the right folks vote, anyway, just like he did in 2008.
- zAy0LfpBZLC8mAC 9y ago> pvote.org seems like a decent solution, it's <500 lines of code that needs to be audited. Quoting from the website: "Pvote is small. The current version is 460 lines of Python. It uses Pygame for graphics and audio." So, add to that 130000 lines of pygame, 1.5 million lines of cpython, 14 million lines for gcc, 20 million for the linux kernel, ... and you haven't even begun to list all the stuff you would need to audit?
- specialist 9y ago"Eventually someone will find a solution." First define the problem. I demand the Australian Ballot: private voting, public counting. After studing this extensively, I believe there is no way to digitize elections and preserve the Austalian Ballot. Because there is no digital equivalent of the physical secure one-way hash (shuffle) of dropping ballots into a box. Any crypto- blocko- based system has to design for the whole election. Not just the voting. Including pollbooks, which record when ballots are issued to voters. Including precinct-based election counts, because every single precinct gets a different ballot (say 500 voters). Maybe someone will prove me wrong. Cool. Then show me. The burden of proof is one them, not me. Otherwise, stop wasting everyone's time with technophilia sideshows. We've got real democracy with real work to do. --- Alternately, any proposal has to replace the Australian Ballot with something new. Some ideas which would simplify the problem space: - replace winner takes all with Approval Voting; - issue separate ballots for federal, state, county, and local elections; - decide that time-boxed privacy, where the secret ballot is preserved until an election is certified and then made public, is sufficient - supplant our current loose voter ID regiment some kinda of U2F futuretech.
- specialist 9y agoThere's a lot more to elections than tabulation. Mapping, voter files, candidate filings, canvassing reports, ballot artwork, translations, ballot tracking, etc. All of it should be open source. The way it used to be. Before the vendors smelled blood. (Especially after HAVA.) I traveled my state advocating "citizen owned software". Everyone gets that phrasing. Overwhelming support.
- xroche 9y ago> the voting machine is running the exact same source code? Or the processor is trustworthy ? Many voting machines are using old processors, such as 68000, and it would not be too hard to emulate a a rogue processor that will have a different behavior, whatever the source code is. You can also change the behavior of the voting machine at a certain time, or in certain conditions (such as detecting a voting session has started) The problem is not that voting machines are vulnerable to one or two attacks. There are thousands of ways of compromising them. The only answer to this is that cryptography specialists do not have any answer to a secure electronic voting not involving a physical element (a bulletin, a receipt, etc.). This means that there is no THEORETICAL solution.
- fredley 9y agoTo protect voting, use paper ballots.
- Shivetya 9y agoValid ID should also be required. With paper ballots how do we guarantee those with a right to vote who cannot travel to a secure voting location have the ability to do so?
- dsr_ 9y agoID is only necessary if you haven't already established the right to vote in a particular location. After that, you're on the list and it's remarkably difficult to get you off of it; as it should be. ID requirements are frequently used in order to deny voting to people who are poor or otherwise find it difficult to get particular documents.
- richardknop 9y agoPaper ballots without voter ID requirement are ridiculous.
- dghf 9y agoThe UK seems to manage OK (ID is only required in Northern Ireland). 2015 saw 37 allegations of personation out of 51.4 million votes cast (https://www.ncpolitics.uk/2016/12/how-big-a-problem-is-voting-fraud-in-uk-elections.html/ https://www.ncpolitics.uk/2016/12/how-big-a-problem-is-votin...).
- richardknop 9y agoYes. My point would be allegations of personation is a meaningless number. Because if there is no voter ID you would not get many of these allegations either way.
- dghf 9y ago
- danhardman 9y agoI'd like to reference Tom Scott's video[0] here. There is no need for an electronic voting system, paper ballots work perfectly. [0] https://www.youtube.com/watch?v=w3_0x6oaDmI https://www.youtube.com/watch?v=w3_0x6oaDmI
- fredley 9y agoDepends on what your need is. If you need to alter votes, it's an extremely good system!
- TeMPOraL 9y agoThis video is absolutely an amazing summary. Thanks for linking it!
- warcode 9y agoUntil you want to scale due to using rapid direct democracy. Paper ballots will still WORK perfectly, but the workload will be massive.
- zython 9y agoWhich is something you can justify IMO for a direct, just, free, equal and confidential election.
- specialist 9y agoThe gold standard is paper ballots cast at a precinct, counted the moment the polls close. In the USA, average precincts are 500 voters. Totally doable. In fact, that's how many jurisdictions did it.
- jk563 9y agoA lot of talk about securing voting machines/verifying that they run the correct software. Why do we have to have physical machines? If it's electronic, surely a website would do if you have the correct means of ID? NB: this is not an indication of which side I fall on the debate, it is an observation. [EDIT] Also, I'm aware similar issues exist with a website, but it seems a lot of focus goes on the actual machine.
- fredley 9y agoIn case anyone can't see why this is a whole heap more terrible on top of the terribleness of electronic ballots... Verifying actual real identity over the internet is impossible. Even if you did webcam-based biometric authentication of identity - these are fooled by a photograph. Going to a polling station and verifying your identity to a human being is much harder to fake, and almost impossible to scale. The web is an untrustworthy delivery mechanism. What say if a nation state wants to disrupt your election, and starts DDoSing the hell out of it all. Protecting against such attacks at that scale would be extremely difficult. Also on the topic of state-level disruption, it is well known that orgs such as GCHQ, the NSA etc. hoard zero-days. How do you know your extensively tested system isn't vulnerable to a zero-day that another state has and you don't?
- jk563 9y agoLast time I voted I took a driving licence. All they did was check my face matched my card, and the name and address matched my registration no real check on whether or not the card was genuine. When I created my government account I provided passport and driving licence numbers on top of the above. I feel this invalidates your veracity point, and probably the scaling point too? The second and third points seem more viable and are potential issues. Especially the third, this would be the main concern IMO. Though I'm sure there are protections against this too (thinking virtually distributed).
- scaryclam 9y agoAll that, in addition to the problems that would arise from voter coercion and threats to vote a certain way.
- pjmorris 9y agoTo protect voting, use paper ballots and count them in public (OK, and voter ids if you insist).
- vowelless 9y agoSomeone needs to start a campaign: "Say No To Electronic Voting"
- r721 9y agoRecent discussion: https://news.ycombinator.com/item?id=14920513 https://news.ycombinator.com/item?id=14920513
- clarkevans 9y agoThis past election has shown that it's not just the voting software, but the software/systems that control who is permitted to vote.
- boomboomsubban 9y agoAs someone who is a firm supporter in free software as the best option in every area, this feels like a subversive attack. Voting software is bound to fail, no bug bounty is big enough to offset the billions that could be made off of hacking an election. It is bound to fail spectacularly, and then for the rest of time people can point at the election and say "the ability to see the source code let this happen."
- ai_ja_nai 9y agoThis is plain bullshit. Opensource gives no guarantee that the vote won't be altered by whoever runs the machine. What we need is a zero-knowledge proof: we need the entire voting dataset to be publicly downloadable and some kind of checksumming so that, while maintaining anonimity, I can 1)check that my vote is the same 2)run whole the counting in a blink on my PC. This gives much better guarantees of no tampering
- cmiles74 9y agoI think this make a lot of sense. I'm not sure a checksumming method that can indicate tampering can be devised, but my hope would be that by making the data publicly available for every stage of the processing pipeline, auditors or interested parties might be able to detect fraud.
- zAy0LfpBZLC8mAC 9y agoBut the data is worthless if you cannot trust the way is has been acquired.
- cmiles74 9y agoI'm not sure there's a way that a skeptical person can ever trust that data, short of physically handling each piece of paper and manually summing up the totals. People are as much of a black box as any software. I suppose the only benefit of people is that they are more difficult to coordinate.
- zAy0LfpBZLC8mAC 9y agoThe point is not using people in place of machines as trust anchors. The point is that you remove the trust anchor (or move it to the public at large, really). In a properly run paper election, there is no individual that you have to trust. In principle, anyone can go and watch, and usually there are representatives of many/all parties in every polling place, watching every step of the process. It's not just that people are more difficult to coordinate or control in general, it's that if someone distrusts you, they can come and watch for themselves.
- greggeter 9y agoPros and cons of paper ballots. Go!
- ivanbakel 9y agoPrevious discussion (5 days ago): https://news.ycombinator.com/item?id=14920513 https://news.ycombinator.com/item?id=14920513
- alkoumpa 9y agoto protect voting, audit your software/system extensively. Openssh is open-source and we all know the story..
- fredley 9y agoBut how can I (a voter), audit it in the voting booth? How can I verify that the extensively audited software is actually running on the machine in front of me?
- Sholmesy 9y agoYou can't. Especially at scale (every person validating the software before voting). Paper ballots with a anonymised ledger of votes placed is, in my opinion, the best method.
- fredley 9y agoPaper doesn't scale well, attacks on paper are extremely difficult to scale well, which is why paper is a good system for voting.
- Sholmesy 9y agoIt scales "well enough", in that we currently do it, and pay for people to verify the results. In Australia a lot of this work is done by volunteers from the major parties. Edit: I agree, its difficult to scale an attack on paper :)
- Findeton 9y agoYou can audit your ballot in some systems. For example https://nvotes.com https://nvotes.com (open source software here https://github.com/agoravoting/ https://github.com/agoravoting/). You could even create your ballot offline, even by hand.
- mtgx 9y agoYou can't. And even if the software is open source, it doesn't guarantee that state or election officials will set aside budgets to deploy such patches swiftly, or even care to deploy them.
- wu-ikkyu 9y agoWhy is it that electronic voting is so vehemently opposed here on HN and by many technologists in general when virtually every other existentially vital system they rely on is run electronically?
- zAy0LfpBZLC8mAC 9y agoBecause it doesn't work.
- wu-ikkyu 9y agoDoes a system have to be 100% free of security concerns to "work"?
- zAy0LfpBZLC8mAC 9y agoNo, but it has to be free of devastating vulnerabilities.
- wu-ikkyu 9y agoThe electronically run global financial system is not free of devastating vulnerabilities, and yet it "works"
- zAy0LfpBZLC8mAC 9y agoSo, what is your point? The financial system is actually going to collapse, and that's not a problem? Or the vulnerabilities aren't actually devastating, just bad? Or what?
- wu-ikkyu 9y agoThat many technologists are being hypocritical by wanting to prohibit electronic voting because of "security concerns" while at the same time developing and using other institutional systems with equal or greater attack surfaces and consequences.
- kome 9y agoMy first job was an ethnography of electronic voting in a wealthy region in northern Italy. By our observations electronic voting added several layers of complexity that are difficult to justify.
- nkohari 9y agoI'm not a crypto fanboy or anything, but I feel like voting is a great application of blockchain technology. It seems like the system could be made to be both anonymous and publicly verifiable, and the vote count would return more or less immediately.
- drdaeman 9y agoUh. Blockchain is just a doubly-linked list with hashes. And a set of rules how the peers validate blocks and come to a consensus. Not some magic crypto pixie dust that brings anonymity or prevents fraud. It could come useful, e.g., for keeping census data to avoid some forms of fraud. E.g. prevent rouge organizers loading elections with "dead souls" voters (Gogol-style). But I don't see any immediate use for election themselves. Say, the blocks would store anonymized votes (nothing about blockchain itself implements the anonymization). One immediate issue I see is that blockchain only verifies integrity of the blocks after they're in there and out to the public, so it could be verified. Sending them too early would skew election results (observers would be able to see the intermediate results and bias their votes accordingly), and sending them too late would probably make blockchain mostly pointless.
- tiku 9y agowhy not blockchain voting. everyone receives 1 voteCoin, and transfers it to the correct wallet address of the person he or she votes for?
- tiku 9y agoand it could even help with vote counting per city, if they originate from a "city" wallet, that came out of a "region" wallet and so on..
- zAy0LfpBZLC8mAC 9y ago1. Because it lacks anonymity? 2. Because the average voter cannot possibly understand and verify the security properties of that setup.
- marcelsalathe 9y agoGeneva has made its e-voting software public: https://republique-et-canton-de-geneve.github.io/chvote-1-0/index-en.html https://republique-et-canton-de-geneve.github.io/chvote-1-0/... I'd much prefer electronic to paper. Last year I voted on 24 initiatives, and that is just the federal level. It also does not include elections.
- noja 9y agoA child can understand paper ballots and why they work. There are probably less than a hundred people in the world who can understand an electronic voting system at every level down to and including the silicon.
- specialist 9y agoBingo. And those of us who've studied voting computers extensively have concluded they're to be avoided.
- cletus 9y agoTo protect voting don't use electronic voting. Paper ballots (the kind with marks read optically, not the ridiculous punch cards at the center of the Florida 2000 debacle) are easy to use and understand with a very low error rate and keep a paper trail, being the actual ballots. I don't understand why anyone other than the companies who sell e-voting machines actually want electronic voting.
- specialist 9y agoYou have to hang out with election administrators to grok that. Their motivations are not the same as the voters. Their election night prayer is "Please God, don't let this election be close." They want certainty more than any thing else. For decades, computers were regarded as more accurate, impartial, certain than human tabulators. Second factor is appropriations. Elections are big money. And like all industrires, there's a revolving door between government and industry. Admin also want control. Their impulse is to centralize, simplify. Think of the logistics of running 100s of voting sites, 1,000s of precincts. All the training, people, materials, gear that has to be stored, shuttled around, repaired, etc. Moving to voting computers, reducing head count, moving to central count seemed like a huge win. (But you and I people computer people, we know they just traded problems.)
- joseppe 9y agoOne word: blockchain
- deleted 9y ago[deleted]
- CapsUnLock 9y agoWell, IMHO a good way to digitize voting would be to give out a USB-drive-like (NFC) device with an option to set a value and lock it in the read-only mode using voter ID. How it will work: A person gets this device in the voting center enters/gets his voter ID, does the voting (anonymously), presses the read-only lock and throws it into the bin. After all the voting these device are scanned and voting data is retrieved. A voting database is populated in each center in a transparent way, to prevent tampering (several parties can be allowed to read this data separately and then all data variants can be compared against each other, just in case). After consensus on the voting data, each voting center sends the results for counting. And the voting is completed. In the end, these devices are reset and the cycle continues. Well, I'm sure that there must be some problems when voting the aforementioned way. But I guess it could work out, with some modifications. EDIT: Grammar.
- castis 9y agoThe only winner in that scenario is the company manufacturing the NFC devices. That system is too complex.
- scaryclam 9y agoThat sounds a whole lot like paper voting to me...except more expensive and more complicated. What's wrong with giving everyone a pencil and a ballot paper, at the polling station, in place of the NFC device?
- jjawssd 9y agoRelated comment to a related thread https://news.ycombinator.com/item?id=14921935 https://news.ycombinator.com/item?id=14921935
- blackkettle 9y agoNo. To protect voting, don't use software. Everyone needs to be able to _understand_ as well as be able to verify that they successfully voted. Besides the issues with what software the machine is actually running, most people cannot comprehend or understand that software - even if it is open source. That is not acceptable for an open democratic society, or to sustaining it. In this particular situation it should not be necessary to rely on an expert to explain whether the vote counting mechanism is reliable. This only adds to the problem of unreliable or scheming officials - it doesn't improve anything in terms of transparency.
- eksemplar 9y agoI think you could do some secure voting software if all your citizens had a secure two factor signature and you used block chain. I'm not sure why you would do it in a non-corrupt country though.
- beat 9y agoWhy do something simple, when we can do something complicated instead?
- eksemplar 9y agoWell if your country is doing digital elections without citizen signatures and block chain, then chances are you live in a corrupt country. :p
- pgeorgi 9y agoThe point is to do pen&paper elections instead. It's the ultimate "open source" solution since everybody who can hold a crayon in the right direction can participate in the verification of the process.
- eksemplar 9y agoThe problem with pen and paper elections is that they rely on honest counting. It's true that it's easier to manipulate a terrible digital system but that doesn't mean pen and paper is safe. Block chain technology would offer an open record that couldn't be manipulated, something paper does not. I mean, I live in Denmark, one of the least corrupt countries in the world and we've had politicians caught changing votes with a pencil and an eraser during the count.
- tzs 9y agoTo protect voting, use this or something similar: https://en.wikipedia.org/wiki/Scantegrity https://en.wikipedia.org/wiki/Scantegrity
- scierama 9y ago"The blockchain is an undeniably ingenious invention – the brainchild of a person or group of people known by the pseudonym, Satoshi Nakamoto." It isn't even definitively known who invented blockchain, it is behind the pyramid scheme known as bitcoin and no, no way should that ever be used in voting system computers.
- huhlig 9y agoIf you consider Bitcoin a pyramid scheme I would love to hear your treatise on fiat currency, fractional reserve banking, and capitalism in general.
- JumpCrisscross 9y agoI'll bite. What's the failure mode for a paper-money based fractional banking system with deposit insurance that makes it a pyramid scheme?
- cgmg 9y agoI don't think you know what a pyramid scheme is. How about learning the definition of the words you use before throwing them around?
- scierama 9y agoHow about you learn some manners, learn to Google, learn to read the results that will appear on your screen.
- cgmg 9y agohttp://lmgtfy.com/?q=pyramid+scheme http://lmgtfy.com/?q=pyramid+scheme "A pyramid scheme is a business model that recruits members via a promise of payments or services for enrolling others into the scheme, rather than supplying investments or sale of products or services." http://lmgtfy.com/?q=bitcoin http://lmgtfy.com/?q=bitcoin "Bitcoin is a worldwide cryptocurrency and digital payment system. The system is peer-to-peer, and transactions take place between users directly, without an intermediary... Besides being created as a reward for mining, bitcoin can be exchanged for other currencies, products, and services in legal or black markets."
- beat 9y agoFirst and foremost, use paper ballots. Before anything else. The paper ballots are the System of Record. If ever in doubt about downstream results, paper ballots can be hand-counted. (Additionally, use paper voter rolls. Mark registered voters when they vote, and track any same-day registrations on paper. The exact number of ballots cast can be extracted from the voter rolls.) Second, never allow paper ballots to be handled by just one person, or by only members of one party - whether blank or used. Require that members of at least two political parties be present any time the ballots are physically touched. Third, if using machines to read the ballots (ScanTron, etc), conduct spot counts of random machines, to make sure the machine results match the paper ballots. Conduct spot counts of entire polling stations randomly to make sure result totals match voter roll totals. Although this isn't 100% certain, it doesn't take a lot of spot checks to detect any sort of large-scale fraud effort. Do these things, and it's exceedingly difficult to do statistically meaningful vote fraud, because we have a high degree of trust in the paper ballots and their surrounding process. From there, you can use automatic ballot reading and tallying to get fast results - the vote counting/tallying automation is derived data, not the System of Record.
- Zigurd 9y agoFirst, you have to understand the problem: 1. You don't need to commit widespread election fraud to throw an election if you can predict where a small fraud will matter. 2. Not all election fraud is a miscount of ballots. Throwing out minorities' registrations is also election fraud, and you can't fight that with more-reliable ballots. 3. The best solution might not be a technology solution. Paper ballots make it hard to scale fraud. But that's not enough, since fraud doesn't always need to scale. 4. Early voting and absentee voting need to be taken into considerations and are a growing part of voting in the US. 5. If software systems are used in voting, tallying, or anything connected to election results, the systems should be open to inspection and to pen testing.
- wnevets 9y agoUse open source software that prints a paper ballot then count the paper ballot.
- a_imho 9y agoRetire voting in favor of sortition.
- davidgerard 9y agoTo protect voting use paper. Why did anyone ever think computerising voting was a good or useful idea?
- ApolloFortyNine 9y agoWhy can't you have everything set up so that when you vote, you get what amounts to a JSON Web Token to be able to later verify that you did in fact vote? You could use the governments publicly available key to verify that your vote reached the central service, and part of the JWT could contain your vote as well as your identifying information (SSN in USA). Obviously everything could have fancy UIs created for end users so they don't see that really all have is a JWT (maybe a QR code printed out when they vote? And all the info easily human readable?). Verification could be handled by a .gov address and also through manual use of the public key (so other services could be set up to verify votes as well). And internet connectivity wouldn't be a problem as they could just require T1 lines at polling locations (I assume if phones went out across the country the election would be delayed regardless). You could likely tell if someone had stolen the private key (the only way I can think of breaking this system), if you have a service to verify someone's vote, and it doesn't show up there, even though you have a signed JWT containing your vote. That would prove someone had stolen the private key, allowing for a makeup election. Am I missing something basic of how this would be hackable? I'm one of those who finds it odd that many elections around the world are susceptible to simple human mistakes/purposeful malicious actions when it comes to counting ballots.
- thescriptkiddie 9y agoThe amount of anti-free-software FUD in this thread is staggering. Did Microsoft buy off all of you?
- cortesoft 9y agoWait, what? I haven't seen a single anti-free-software comment in this thread; most people are against electronic voting entirely, whether it is open or closed source. Why would Microsoft be anti-electronic voting?
- ruffrey 9y agoThere's got to be some way to put votes on a blockchain. More important than voting electronically is being able to verify your own vote was not tampered with, and that all the votes add up as reported.
- peterwwillis 9y agoThis story has been posted four times now. Click the 'past' link at the top.
- return0 9y agoTo what extent is voting fraud an issue in the developed world and why is Nytimes upset about it?
- xealgo 9y agoSecurity may not ever be 100% with e-voting systems, but it can be secured enough to where the probability of any hack attempt would have minimal impact on the overall outcome. I can think of several ways to a secure, verified registration could work just off the top of my head. I think the issue is more, where's the incentive for the government to make this happen?
- Arkanosis 9y ago“R. James Woolsey […] former director of [CIA]. Brian J. Fox, […] develop open-source voting systems” — even if I had no opinion on the matter, it'd seem to me that there's a clear conflict of interest there. To protect voting, do NOT use software. At all. Open-Source software is no more trustable than paper, and is orders of magnitudes more complex to set up and audit. If you can't explain a 5 years old how it works, your voting approach is not trustable.