Votes could be counted as fractions instead of as whole numbers
blackboxvoting.org
blackboxvoting.org
Paper voting (with polling locations distributed to balance load) with hand counting and verifiable addition operations to get the final vote counts is what is needed.
Having voted in person at town hall, and then having helped count the votes, I know that it is doable - just like any other laborious task is doable with enough people involved. Electronic voting just doesn't buy you anything more than risk - all at the cost of verifiability.
The other advantage to hand counting with a neighbor nearby is that there is a strong penalty for manipulating the election - your neighbor will notice. These machines make it way too easy to manipulate elections at mass scale without detection.
The resistance [from several in the industry not just your comment] to making voting happen via software really concerns me.
Voting systems do not have that.
If the voting machine vendor executives faced actual personal serious jail time for botched counts, I might be more inclined to trust it. Then again, I bet you a tenner they'd suddenly have a lot more fail safes in place.
Aligned incentives is absolutely, 100% required for anything to work in our society. It's what we're built on. Otherwise you will always be swimming upstream.
Even with a threat like that, they'd probably still walk free by just using the DMCA to silence the security researcher
[1] https://en.wikipedia.org/wiki/Online_Policy_Group_v._Diebold....
I wish more people understood this simple fact of human psychology. It's astonishing how often people will support some system that incentivizes bad behavior, and then act surprised when people behave badly.
What's more, when faced with this situation, these same people will resort to shaming the bad actors rather than fixing the broken system.
Each and every idea has a logical optimum strategy for the trust to maximise income, and all of them aren't quite what you're trying to achieve. So you really want to blend some of these (and others) together in just the right mix, but without creating hundreds of hours of admin just to support the metrics.
What are the incentives for voting machine manufacturers to do a good job? Engineering a trustworthy system is tough, and it's expensive. If the machines cost twice as much, no one will buy them and it won't matter if they're more secure. And the market itself is unhealthy. If you spend 10 million on voting machines, you won't replace them the next year even if a bunch of security issues surface. You'll "demand" the company fix them, they'll issue some half assed patch, and you'll go on using the junk you bought.
https://people.csail.mit.edu/rivest/voting/papers/Chaum-Secr...
Not sure it beats paper ballots and hand counting in terms of practicality, though :)
OK VLM your boss needs a Trump receipt, your communist college professor needs a Clinton receipt, you need another Clinton receipt for facebook and github or they will delete your accounts, that'll be one R, three D, would you like any complimentary green party receipts? OK here's all your receipts thanks for voting see ya in 4 years!
Heck hand them out with the bake sale goods. Have a free set of pre-printed fake receipts for ALL the candidates with some delicious chocolate chip cookies that fund this schools PTA. "Could I interest you in this cageless chicken egg gluten free organic soy oil brownie with a complimentary fake green party receipt?"
At the bottom of each voter's paper roll entry is a big bar code. This allows quick recounts by running the paper roll through a machine that reads the bar codes. A full manual check is also possible, but slow. The system goes through miles of thermal paper for each election, but works OK.
There's no way voting for candidates can account for vote theft in the same way.
Don't forget that Wells Fargo was able to open millions of accounts without consumer authorization. So maybe financial accounts are less secure than you think.
I'm also surprised by blanket assertions that electronic voting is inherently bad. But I'm equally surprised by assertions that electronic voting is inherently good.
With electronic voting, any method of verifying your vote is incompatible with the principle of a secret ballot.
(edit: additionally, with paper ballots and adversarial scrutineers, every vote will certainly be counted properly as the people who stand to benefit(the politicians) can raise an issue if a ballot is being counted the wrong way. It's much less likely that every individual would verify their own vote).
The resistance for voting via software may really concern you, but the push for it really really concerns me...
When the community is sufficiently engaged, either you have differing political views and thus don't have to worry about conspiracy, or everyone has the same opinion and the conspiracy would just reinforce the true outcome.
Regardless, the possibility of that conspiracy is another great way to encourage participation. Republicans and Democrats both have an interest in the other side not tampering - combined that turns into a pretty strong interest in removing tampering altogether.
The main reason I want to get sane electronic voting is so we can vote online from home. Given the inability of democrats and republicans to come up with any acceptable method of handling voter ID, though, I'm pretty confident that it won't happen for decades if ever. In the meantime at least my state does vote by mail.
https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
Are you saying a recount will be unnecessary if E2E is done properly?
I read the linked article but didn't get it.
I'm not sure where I might have given the impression that a recount would not be necessary. A paper record makes a recount possible and the election system auditable.
The linked Wikipedia article on end-to-end auditable voting systems provides an overview and links to different methods of making voting systems more trustworthy. There's a lot of thought and details that go into it, and if it's something you're interested in, I suggest following up on some of the links and spending more time. I know it's taken me reading a lot of different articles and implementations, and I still need to look up different parts of it.
I did find this slide deck from Ron Rivest helpful:
"Auditability and Verifiability of Elections" ACM-IEEE talk March 16, 2016
https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf
Were there particular areas that didn't make sense to you?
That's not to say that other security precautions can be ignored. Ideally I'd think there should be mature open-source software running on secure intranets for each voting station, and transparency at every level of the process, including better transparency in how those physical receipts are transported, handled, and stored.
Step 1) You queue, get a "Temporary Voting Id"
Step 2) Enter the booth, enter your "TVID"
Step 3) Vote
Step 4) The Machine prints your Receipt with your vote clearly visible and your TVID as local proof its you and your vote is right.
Step 5) You fold your printed ballot and put it in a box.
Step 6) You fold your ID Receipt and place that into a "Validation Box" as you leave.
Step 7) All machines keep and print a "Tally" used as the count.
Step 8) All ballots and validation id's are saved in boxes and shipped ready for recounts if needed, ID's can be matched to ballots to validate attendance and votes anonymously.
Bonus Step) ALL vote machine should produce a "Vote Audit" when asked that will show a full history of votes (without times and in random order) and the ID's used and ALL id generation machine should produce all vote id's generated (again without times and in random order)
The UI of a #2 pencil and a pre-printed form is a lot simpler and easier to use and un-jammable compared to an e-voting machine printer. Also cheaper and harder to hack.
If you keep your ID receipt theoretically you could prove your vote and sell it. If you don't keep your receipt, they might toss out your vote and you'll be unable to prove it. There are cryptographically secure-ish ways to work this, mostly involving statistical security (I forget the exact term, the kind that makes engineers pull their hair out because the algo looks inefficient but the inefficiency is the source of the security)
Even worse I assume multiple votes per TVID would overwrite the previous vote to handle user interface mistakes (see above, why must we use a complicated electronic UI instead of a #2 pencil and paper UI?). So any poll worker with access to the unshredded TVID has root password and can change everyones vote at their leisure.
You should have inserted the votes into a networked blockchain so people can ask WTF if 50 votes are changed ten minutes after the polls are officially closed. Or people could ask WTF when district #239 is the only district to have 50 revotes more than five minutes after the original vote. And the blockchain would store the former pre-tampering ballot which might be handy once the corruption is identified.
Of course it'll be fun to link the timestamped blockchain to CCTV cameras everywhere, so if you timestampped blockchain you no longer have anonymous voting, every ballot is now linked to license plates and face pictures, thank you "war on fake terror".
If the TVID is not cryptographically secure you don't need access to the box of stored TVIDs, because I see they handed #200 to me, #201 is next on the table, why shouldn't I type in and "correct" votes for TVID #190, #191, #192, #193 ... while standing in my private booth?
If I walk out the door with a cryptographically secure verified TVID and just toss a blank piece of paper into the TVID disposal box, then I can sell my TVID to someone for money or booze or sex, then dude walks in with my TVID, gets one of his own, votes for the two of us. You'd need to timestamp each TVID for a limited validation time. I could see management at companies requiring people to hand in their TVIDs to get their timecards or paychecks. Or at soup kitchens. Or crooked cops, or especially college professors. Imagine trying to explain you can't give your TVID to your feminist studies professor because your african world heritage professor already took it, which class do you accept the "F" in?
Essentially with TVIDs you're trying to implement Kerberos tickets which is tricky enough for computers, much less 80 year old deaf poll workers who dropped out of high school during the great depression and have never touched a computer. Every security hole or bug thats ever existed in Kerberos needs patching.
There are so many problems I'm kinda bored right now, but I can tell CCTV attacks and cellphone camera based attacks are going to be a very interesting problem. Essentially any security guard with a high res camera pix of the stack of TVIDs has root over your system, I think. If the TVIDs are preprinted any corrupt person with physical access to them before the election or before the recount anyway, who owns a cellphone camera or has access to a photocopier has root. Big data attacks might be possible, "sell" memorized TVID number to the bartender as part of a "I voted so now I get a free shot" sounds very much like democracy boosterism until the employer collects memorized ballot receipt number for their own parallel "I voted so I get a free ice cream cone at work" democracy boosterism, until the data is sold and you're powned because you gave away both parts plus the name your employer knows to "separate" entities who are not "separate" after all.
I'm not sure if you fix everything if you basically end up with optically scanned pencil on paper ballot "scantron" voting or if you end up in a parallel but different rabbit hole of higher complexity, cost, and lower security.
The last step of voting is inserting the ballot into the scantron machine. Valid ballots are eaten, invalid are kicked back out at you.
Theoretically the machine can output running totals at any time, and if you've never seen an optical scanner in action you'll be surprised how fast it can scan and grade a classrooms worth of multiple guess tests, less than a minute to scan and process perhaps a hundred tests, so a thousand people living in my voting district is not exactly a data processing challenge. The votes can obviously be counted by hand of course, they're just custom printed multiple guess test sheets.
Optically scanned paper tapes and punch cards were contemporary in the 60s and optical scantron machines appeared shortly after. I'd estimate my state converted from mechanical voting machines and mimeograph machines to scantrons and photocopiers about the same time, lets say 1980 although maybe as late as 1984 or earlier in the 70s. I distinctly remember watching my parents vote one last time on an old fashioned voting machine when I was a little kid, probably voting for Nixon, may have been Reagan but I'd have been too old by then, I think. Old fashioned mechanical voting machines were cool and steam punk ish in appearance.
Its such a simple, cheap, reliable system that it almost leads credence to claims that elections are being intentionally rigged. Its hard to explain otherwise why something so cheap simple and logical is being covered up and so few people know about it. Ironically I live in a non-swing state in a gerrymandered district so my vote has never mattered and never will, but at least if I ever get a chance to influence politics via voting, its pretty obvious my vote would be counted fairly.
That what the voting booth and envelopes are for. Its not a random thing. Our voting systems are low tech, but it's well designed.
And in the latest election where the incumbent party lost, It was pretty publicized that they went to a lot of the poorer colonies to try and get their money, cell phones and tvs back. All quickly forgotten as soon as the media got a whiff of it.
Buying votes in a first world country probably isn't possible as most people are somewhat (and probably wrongly) educated on the topic, and hold pretty firm views on it. However, it's a piece of pie on mostly illiterate people. Even then, people get tired, see the latest elections in Mexico.
- internet voting
- touch screen voting
- optical scan voting
Computers can also be used in other roles, such as voter verification, vote tabulation, and results transmission, result verification, and auditing.
With only paper ballots, arbitrary vote verification is likely to be a tedious process, if possible at all. Cryptographic methods such as homomorphic tallying can ensure vote secrecy and vote verifiation. This can also provide stronger guarantees of chain of custody integrity by verifying voter receipts or cast paper ballots are included in the final tally. With only paper ballots, trust that a given cast ballot is included in the result relies on trust in those doing the tallying and the chain of custody of the ballots themselves.
One could imply from the phrasing of your question that you have reservations about any benefits electronic voting might have. What's your take?
Optical scan is the only above mentioned method that can be verified by laypeople.
Also, although a tedious process, paper voting has worked for quite some time. Centuries?
Chain of custody will always be a problem, whether it be source code to a compile runtime, or paper ballots.
However, the potential for abuse seems less likely for a more manual process.
A voter signs in to vote, so we know how many voters to reconcile to the same number of ballots. If we have more ballots cast than signed in votes, we have a problem.
Additionally, ballots are serialized, though not associated with any particular individual. So we know what ballots were used and unused. If we find multiple ballots with the same serial number, we know there is a problem, too.
Voting should not rely on a blackbox algorithm. The majority of the voting public can count pieces of paper, but can they understand and verify code running on a device?
Who cares if it saves time, particularly at the cost of transparency and trust?
My question to you is, what problem did electronic voting solve (as implemented in the US), that needed solving?
- Wait until all electronic ballots are set up in their zones in election day. - Randomly (this can be even done in a public, audited draw) select a few ballots to test. - Remove those ballots from use and replace them with spares. - Now, somebody publicily double votes on the tested ballot: they publicily vote for candaidate X in the ballot, and on paper (although just showing the vote allows any observer to keep count indefinetely). - At the end of the test, print the count from the tested ballot and verify that it is accurate to the publicily counted votes.
What do you think about this?
IMO, while not totally fool-proof, this brings the cost of manipulating electronic elections rather close to paper elections, if the following assumptions hold:
- The draw is fair, so a malicious actor could not program only the selected ballots to be fair; - The chain of custody of the ballot is solid (easy to do if there are party auditors that never lose sight of the ballots), or that the ballot is not moved out of the sight of the public instead; - There's no available method to make the ballot know it's being tested, and change its behavior (like in the VW emissions scandal).
The last point is tougher, although auditable source code, code-signing, and reproduction of as many 'true' conditions as the real election (same duration, same time, same voting frequency, etc, maybe going as far as to randomly select normal voters to participate in the process).
Paper votes work, and they work well. Besides the obvious downside of needing to wait for them to be counted, they are safe, open, they don't break down, they can't be hacked, anyone can verify them, and they are 100% anonymous.
At worst, you'd need many people to collude to stuff a single ballot box in a single district, and even that can be thwarted by a single person watching the ballot box all day.
So what's the gain with electronic?
Many programmers know about the "beauty" of encryption and secure voting algorithms. They know that open source works, and it's really tempting to try and think up a system that is "perfect" and can't be gamed by anyone.
But this is an instance where messier and less "perfect" is better, because the absolute worst case scenario of being able to actually change the election is so much harder with paper, and anything less than that worst case scenario doesn't change anything (and still has all of the risks and downsides).
The reason I want this is because it allows much more fine-grained voting. My ideal democracy is a direct democracy where every voter can, if he/she chooses, to vote on arbitrary issues, but _delegate_ their vote to someone else by default. As an example: "I politically align with Bernie Sanders, so I want by default my vote to delegate to whatever he's voting for, but for issue X I vote Y."
In an ideal world you could even delegate votes based on "tags", e.g. for Internal Affairs you choose X, and Economy Y, etc. But that seems fairly easy to manipulate by whoever is assigning the tags to issues.
I am sure that there are ways to improve citizen participation in the democratic system, but directly voting on issues is not going to give us the sensible behaviour you might hope for. Representational democracy exists in part to prevent minorities from abuse by any majority — with direct democracy you eliminate that protection.
Not so sure, the paper ballot system may been hacked in 2000 US election. The other criminal activities of the Bush family make it more suspect, IMO.
It's certainly more work to count those votes, but on the other hand, everybody is entitled to go check the vote count and everybody can do so with no technical knowledge needed. Any system that requires the observer to be firm in a given piece of technology is not a superior system since it removes peoples ability to exert their right to check the public vote.
Also frankly more people are familiar with the UI of "#2 pencil and piece of paper" than any electronic UI I can think of or imagine, which is somewhat damning for cultural reasons on this site resulting in it being double plus ungood badthink to imply anything could be superior to contemporary trends in web and phone app UIs.
"Fill in the correct bubble" was very new technology when I was a young adult, apparently its still in use.
One handy thing about the ballot eater machine, as a voter, is I feed it a valid ballot and it emits a happy cartoonish beep song while eating and storing my ballot for later hand recounting, and feed it an invalid or questionable ballot and it immediately kicks it back at you with musical accompaniment indicating R2D2 is clearly not amused. The OCR contrast settings can be messed with such that anything even slightly questionable (erasures, etc) will simply not be accepted. The paper ballots being cheap and the technology being easy to understand, the poll workers simply give the voter a new ballot.
My ideal system would have a voting machine that handles the complexity and fills in the bubbles for you. Then prints it out and let's you inspect it, and turn it in like a normal ballot.
I also have other issues with them. Like runoff voting systems drop a moderate candidate that most people would prefer in a 1 on 1 election, but isn't listed as enough people's second vote. Resulting in more extreme, less liked, candidates getting elected. It's better than FPTP, but not by much.
This makes voter intimidation real easy. Just say: "if anyone's vote is made public and not for candidate X, I will murder them and their family". That basically turns voting for candidate Y into gambling with the life of your entire family.
This helps with ballot stuffing, if 200 voters in the district verified their vote and election monitors counted about 200 people walked thru the door but the corrupt system published half the ballots online and theres 500 of them implying 1000 voters, well, someone faked an extra 800 voters.
The problem is complicated and you can't actually use DnD dice because most disenfrancised voters fill out straight ticket ballots and are therefore not part of the decision making fraction of the population, so someone could pay or punish based on votes exactly half their victims who don't have a ballot that looks like it was made by a purely random dnd dice roller. So you actually have to figure the percentage of people last time around who voted like whatever logical scheme, then make the poll worker fill in ballots that look like a reasonable ballot from last time around. "VLM you get serial number 200 and I as poll worker fill out serial number 201 and looks like your "random" historical voter for 201 is straight ticket R"
Also you can't let the voter pick the ballot he fills out because then Mr bad guy can kill any odd serial numbered voter for Trump because he told his employees or students or whatever they must select and vote the odd one never the even one, so half the random ballots being odd means trouble for half the voters. Face down pick one might be OK.
Note that under this scheme it might be safe to even publish the name of both ballots, just so long as a random half get shredded.
Any individual poll worker with a photographic memory could theoretically sell a list of ballots he filled out vs the voter filled out but its purely he-said-she-said and the poll workers memorization job will be hundreds of times larger than a voters memorization job so I think it incredibly likely the voter will be trusted to lie as best serves him rather than the poll worker be trusted to tell the truth.
How the random half get shredded is likely going to be a sticking point. It has to be visually enforced the entire voting period that each voter puts one ballot in one pile and one in the other and when polls close the observers do a coin flipping cryptographic protocol and immediately shred one random stack. You can't shuffle them all and then shred or whatever. Someone putting both ballots in one pile will screw things up. There are trivial ways to enforce this of course.
A list of all my historical published votes would after decades provide a random signal and a pattern of my own voting. However my own voting makes a random signal for some other dude, and today any goofball who wants to discriminate can pull the district records and know the couple hundred of us who vote here always vote about 80% R so although discrimination would be possible it wouldn't be any easier or more effective than it is today anyway. Go ahead, knowing nothing other than I live in an 80% R district take a guess what I usually vote...
Technically this scheme disenfranchises a completely random half the population. Well, since only half the population votes you only disenfranchised a quarter. Only half the population votes anyway is a good justification for tossing out a random half the actual votes and replacing them with cryptographically strong noise. I suppose to satisfy dumb people who don't understand statistics you could run two elections and tell the dumber people that half their votes got tossed each time so ta da now all your votes got counted once across the two, but thats numerically unethical.
A weakness I see in both your system and ThreeBalot, is the need to trust in some decision maker to act correctly. You need the poll worker to actually work randomly (and not have awesome memory), ThreeBalot needs a way to confirm ballots are entered correctly.
I think the biggest sticking point with your system is the random aspect. We are essentially introducing noise into the votes. The noise might be negligible, but it impacts people's perception massively. There is also the challenge issue, because you'd need some arbitrary cut-off on the probability of the noise being to large. After all, the chance is technically nonzero that all random votes went the same way, and only the random votes were counted.
Anyone can count along with a ballot box. Anyone can stand there all day and watch the box to ensure there is no tampering, they can count, recount, and recount again. Anyone can do this. Plumbers, programmers, doctors, the unemployed, the elderly, and even the illiterate. It can be counted by one person, or 100.
But when things go electronic, the number of people that can even understand it is cut down to programmers. And the number of those that could accurately vet the security of a program is even smaller. And even a perfect electronic system needs loopholes (you can't just disenfranchise voters because they forgot their password or don't have a computer), which means the ability of fraud is still there.
Paper works, and takes a LOT of resources to sway even one precinct (even just the fact that it requires purchase of physical materials ups the amount of cover up required), let alone a county, state, or the federal levels. And because of the number of people involved, if someone did try the chances they would be found out is pretty damn high.
Better yet, do mail-in voting. It works fine for several states already, and all of them see strong correlation with voter participation, unsurprisingly. It's also cheaper. And keep a few basic polling locations around as a fallback for those unable or unwilling to deal with mail.
And then there's the cases of voting papers being dumped rather than delivered to constituents. And the possibility of tampering with the votes in the mailing system. It wouldn't be hard for malicious actors to toss out papers in majority Republican or Democrat areas to attempt to sway the election.
And having "a few" polling stations would mean that they are further apart and less accessible for people, especially poorer people who don't have the same means and time for transport.
Yeah I bet. Your boss will trade your mail in ballot for your paycheck this week. Turn it in with your calculus exam for 5 bonus points. Don't forget to take your ballot to Bible study group this Sunday, we're going to fill them out together to make sure we do it correctly. If you're in a nursing home just hand it to your favorite nurse, after all she's in charge of your medication so you have motivation to keep her happy. Your postman will simply toss it out if he doesn't like your vote but he does have a bid out for $5 if you'd like to sell, because one of the local parties is buying from him for $10 per ballot. On the other hand the gas station clerk down the street is offering $9 because his margins are lower and he paid off the cops like he paid off the health inspector and he's easier to get in touch with.
I suppose if all the dollars are concentrating in ever fewer hands, we need some kind of paper currency, and if they'd allow early voting up to perhaps 3 years and 364 days before the next election... Its possibly the only way we'll ever see the government getting a form of currency into the general public's hands to boost economic activity rather than just bailing out the bankers as usual.
Mail in is fairly banana republic tier. Its kinda like drug legalization, yeah that stuff isn't good for you, but at least if its above board and semi legalized then at least we can observe and track it, kinda, rather than underground and out of control. Actually its more like a red light district, the only way to make it worse would be to drive it underground. At least looking at vote totals we can tell how corrupt an election is based on level of mail in voting rather than knowing its bad but not how bad in total.
At the same time, I'm not aware of literally a single complaint about this kind of thing in US states that practice mail-in voting...
And drug legalization is "banana republic tier", really? No. It's a recognition that "this stuff isn't good for you" is not a sound basis for passing laws, for one thing - and for another, it turned out that a lot of "isn't good" was just plain out lies and misdirection.
I mean, seriously, are you saying that WA and OR are banana republics?
Properly done, a voting machine doesn't need to do anything more than count and tabulate. You press a button, and it adds a new vote to it's table. The vote could be printed out on paper. It could even be done via punch cards first, and then fed into the voting machine (which makes the process more inspectable by humans.)
The voting machine need not know what each candidate even is, what party they are, just assign them numbers. And it doesn't need to receive updates, or have any method of input other than reading punched cards or a voter pressing a button. It certainly doesn't need to be based on windows XP and have usb inputs. It certainly shouldn't send votes over wifi.
I think pushing for "superior voting systems" is really allowing the best to be the enemy of the good here. STV is perfectly doable by hand. AMS is only fractionally more complicated than FPTP. But most US elections (and the UK parliamentary ones, although none of the other kinds of election in the UK) are FPTP.
Let's not allow the desire for better voting systems to be tied to untrustworthy technology.
Edit: the barrier for getting a system adopted has to be "can you explain this to a partisan of the opposing faction with a high school education, and get them to agree that it's fair?"
I really dislike instant runoff voting and similar systems like STV. They are better than FPTP, but not by much. One big issue is discussed here: https://www.youtube.com/watch?v=7Q7rzqJ0YS8 But my main concern is they might tend to elect more extreme candidates, because they quickly drop candidates that don't have enough first votes, even if they are everyone's second vote.
The problems of actual existing electronic voting are a microcosm of bigger problems. We get insecure, ineffective voting machines because procurement is difficult and tends to be captured by lobbyists.
Condorcet superiority seems not all that important in practice: http://www.fairvote.org/why-the-condorcet-criterion-is-less-... , and if you have suitable multi-member constituencies for STV then you tend to end up with a couple of "extremists" and a large group of moderates in the middle.
Again, let's not let the best be the enemy of the good.
Don't throw the baby out with the bath water. Just because current electronic voting is bad, doesn't mean it has to be.
http://scorevoting.net/BayRegsFig.html
There is even a theorem that, under plausible models of voter strategy, Approval Voting will tend to elect Condorcet winners (i.e. candidates who beat all rivals by a head-to-head majority).
http://scorevoting.net/AppCW.html
Clay Shentrup Co-founder, The Center for Election Science
* Count and record our money
* Operate and monitor medical equipment
* Monitor and control planes, trains, ships, and cars
* etc
To think that we cannot use a computer to record votes is insane.
I think recent history has shown this hasn't worked out quite that well in many cases, and that in other cases was easily manipulated for purposes of fraud. There are entire sections of various law enforcement agencies that focus on this very topic.
>> Operate and monitor medical equipment
What would be the benefit of manipulating this?
>> Monitor and control planes, trains, ships, and cars
What would be the benefit of manipulating this?
I would second guess anything that uses a computer to keep a record of something that someone would have a direct benefit if manipulated. It's not a matter of whether it works or not, it's a matter of how easy is it to manipulate for a particular goal.
Killing people. Imagine a StuxNet type attack that targets medical equipment or an attack that can drop planes from the sky (https://www.wired.com/2015/05/feds-say-banned-researcher-com...)
> I would second guess anything that uses a computer to keep a record of something that someone would have a direct benefit if manipulated
Then you better move to the woods. Basic economic principals (scarcity) mean that every resource has value to an interested party.
I can only see the benefit of a targeted assassination for a very specific subset of a subset of a subset of people, not large scale killing of people. Warfare maybe? For fun? Not as obvious as fraud for monetary gain, there is a scale issue to consider.
I worry more over bugs that kill people on the operating table or in the air as opposed to someone manipulating the equipment for some unknown benefit.
>> Then you better move to the woods.
I think you're exaggerating just a bit.
Wars are extremely profitable for some.
> I think you're exaggerating just a bit.
I think you are being myopic. We trust computers with thousands of important tasks. If we can't trust them for voting, we really have to reconsider their usefulness.
That is an excellent point.
But, reading back over the posts I see that I introduced the concept of warfare even though the original points I questioned did not. So, back to my first questions; who benefits from manipulating medical and aircraft equipment on a large enough scale to be compared to potential financial fraud?
Wait, targeted assassination that starts a war... That's been done before, but unlikely.
>> If we can't trust them for voting, we really have to reconsider their usefulness.
It's not that I don't trust the computers, it's that I don't trust people.
I assumed "killing people" was broad enough to include obvious cases such as war :)
> So, back to my first questions; who benefits from manipulating medical and aircraft equipment on a large enough scale to be compared to potential financial fraud
Competing corporations via corporate espionage. A targeted hack against Siemens infusion pumps would force hospitals to consider alternatives.
> It's not that I don't trust the computers, it's that I don't trust people.
Every system in the world has been created by people with their own biases and faults. If we are really going down that path, then you must seriously consider going off the grid.
How will you know if an electronic voting system produces a wrong result, except by running a paper voting system in parallel?
Do municipalities choosing voting machine contractors have incentives aligned to promote election integrity? Can they critically evaluate security properties of what they're being sold?
I don't think so.
The republic is experiencing significant harm. If it was not, people would not be talking about it.
> How will you know if an electronic voting system produces a wrong result, except by running a paper voting system in parallel?
Audits? Open Source? Checksums? Hashes? We have many tools to verify the integrity of electronic data (I also never claimed it had to 100% digital)
> Do municipalities choosing voting machine contractors have incentives aligned to promote election integrity? Can they critically evaluate security properties of what they're being sold
If the choice is federally verified company A or federally verified company B, then yes.
The last part is related to the electronic counting of the votes. Here what Fritz Scheuren, the 100th President of the American Statistical Association, had to say on the Democratic primaries “as a statistician, I find the results of the 2016 primary voting unusual. In fact, I found the patterns unexpected [and even] suspicious. There is a greater degree of smoothness in the outcomes than the roughness that is typical in raw/real data […] the difference between the reported totals, and our best estimate of the actual vote, varies considerably from state to state. However these differences are significant—sometimes more than 10%—and could change the outcome of the election”
That's probably when this feature went in.
[1] http://www.sourcewatch.org/index.php/Diebold_Election_System... [2] http://www.nytimes.com/2003/11/09/business/machine-politics-...
It sounds like this is something you're interested in. I encourage you to take a look at what's being done. I've shared a couple of links elsewhere in this thread, which if nothing else can provide a starting point.
I been thinking a blockchain based system would be interesting, but it'd have to be really easy to use for everyone. People who have no computer or phone all the way to the computer expert.
https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf
I think he does a pretty good job of covering the history of modern voting and how technology can be properly applied.
You might find this Google Tech Talk by Ben Adida "Verifying Elections with Cryptography" interesting as well:
On top of that, they claim that there's also specific functionality to deal with rounding in the output results - why would anyone do it if they honestly thought that votes are always integer. In fact, they even present an email discussing the implementation of this, so it wasn't exactly under the radar.
There's stuff like 'some code I found an FTP server one time' which add considerable amounts of doubt and ambiguity.
That said, such objections merely highlight the root cause of the problem - the software and process is not auditable. If it was I could just go and check for myself. Without that access neither I nor anyone else can verify the claims, nor the counter claims that everything is legit (though see also Thompson hack, reproducible builds, etc)
I'm not a 'closed source = evil' kind of a person but here it seems like an absolute no brainier.
Second reading those emails in part 2 it seems they are discussing that the per candidate numbers in weighted elections (when the machines are used for those) then adding them they show totals with one less digit. But that only matters if they have fractional parts which they haven't shown to have happened in a real election.
There doesn't seem to be any proof of actual fraud here. Just a bunch of suppositions.
if wrongVote && rand() < X:
FlipVote()
This would have the same effect as fractional voting, even if you store as integers.Once you have thoroughly owned the voting machine system and can set weights why not, I don't know, just ignore the counted ballots entirely and report the totals as whatever you want?
I assume it adjusts the proportionality so the sum total remains the same, and ballot questions that the hijacker is not concerned with are not skewed.
Since you have no idea how many people will vote until the conclusion, if you wait until after the conclusion to modify results, it would be more obvious and difficult.
The paper ballots that were marked and optically scanned caused no problems and were easy and fast to recount.
Some counties in FL had the old punch card ballots, some had the optically scanned. All of the problems were with the punch card ballots. And with the lawyers arguing over hanging chads and other nonsense.
And how do you know someone's just not adding to the total when it's collated?
The rationale is to allow anybody to audit the system, so that soundness of the design can be proven against an adversary with perfect knowledge of it.
And yet Americans let companies enforce intellectual property rights over systems whose security (flaws) could change your vote...
update: Bruce Schneier on security of electronic voting: https://www.opendemocracy.net/media-voting/article_2213.jsp
There are mechanisms by which one could both keep the ballot secret and allow a public tally. But to avoid hacking, like the floating-point vote-value in GEMS outlined in another story, the system does require bullet-proof crypto.
Regardless of how the ballots are counted, I do believe there should always be paper backups, scanned, and filed so that citizens can examine them digitally and in person if necessary. With that system one could spot-check any suspected irregularity. Only with such physical redundancy would I trust digital voting systems at this point.
Sometimes there's no substitute for good old dead trees.
https://en.wikipedia.org/wiki/Secret_ballot
Article 21.3 of the Universal Declaration of Human Rights states, "The will of the people...shall be expressed in periodic and genuine elections which...shall be held by secret vote or by equivalent free voting procedures."[19]
Article 23 of the American Convention on Human Rights (the Pact of San Jose, Costa Rica) grants to every citizen of member states of the Organization of American States the right and opportunity "to vote and to be elected in genuine periodic elections, which shall be by universal and equal suffrange and by secret ballot that guarantees the free expression of the will of the voters".[20]
Paragraph 7.4 of the Document of the Copenhagen Meeting of the Conference on the Human Dimension of the CSCE, obligates the member states of the Organization for Security and Cooperation in Europe to "ensure that votes are cast by secret ballot or by equivalent free voting procedure, and that they are counted and reported honestly with the official results made public."[21]
Article 5 of the Convention on the Standards of Democratic Elections, Electoral Rights and Freedoms in the Member States of the Commonwealth of Independent States obligates electoral bodies not to perform "any action violating the principle of voter's secret will expression."[22]
And if I'm understanding correctly (and I might not be), you can confirm that the printout is accurate.
Edit to add: If you can confirm that all of the ids are unique and that the total number of ids are correct, that would go a long way towards verification, along with checking arbitrary receipts against the results, regardless if the ids are pre-printed or printed afterward.
I'd prefer not having any printers involved though. Pre-printed ballots would work just fine and there's one less piece of equipment involved during the actual vote.
BTW, thanks for engaging in this discussion. It's important and it's helping me rethink through all of this.
Another option is making a fake ballot. The local newspaper used to helpfully publish their suggestion of how a devout left wing progressive would fill out their ballot. They're currently the establishment, so they're likely to be the largest problem, and its solved right there.
[0]: https://en.wikipedia.org/wiki/ThreeBallot
It can't be that hard. A git repo per machine, recording an audit trail further verified by the block chain, could be the start of a solution, for example.
This is just a list of technologies. It's not the start of a solution, and it isn't even really clear what problem you are trying to solve.
I'm not implying anything, but an anonymous vote for Trump was registered into the blockchain at 9:55:01 at XYZ elementary school, and at 9:55:23 a hacked gas station security camera across the street shows a dude walking out the door and into a car license plate WTF-123 that seems to be registered at the same address as drivers license number 1234-XYZ which happens to be VLM and his rather studly DL demographic data (height weight race gender) seems to match the dude in the video... Meanwhile VLMs phone, which is powned by the NSA, KGB, and god knows who else, records VLM's GPS coordinates as in the voting booth at 9:55:01 and shows him driving the car back to the coordinates of his house. And of course VLM's kids went to that elementary school when they were little. So it could just all be a coincidence, but I think I might know who VLM voted for ...
You could take steps to separate the name from the vote of course. e.g. After the person confirms their identity somehow, give them a random number that only they see/have access to, associate the vote with that number.
The "repos" could be made public and you could confirm your vote afterwards. No vote could be "changed" if it was in a chain of hashes...
Your point about timestamp is true. And although I personally think we could stand to be more open about how we vote (and also more accepting of others) I agree anonymity is important.
Perhaps a system like this would be efficient enough to greatly reduce the voting time window. Make it harder to determine who voted by timestamp due to "noise". (or perhaps, can't vote unless there are 5 people present... not a perfect solution, just throwing some ideas at the wall.)
Should really be
> PART 1: VOTES COULD BE COUNTED AS FRACTIONS INSTEAD OF AS WHOLE NUMBERS
Existence of the feature doesn't indicate it's use, although it is obviously worrying.
Now I understand the core beef: that a schema change to this voting software caused all votes to be stored in their relational DB as doubles instead of ints, and a good way for observers to verify that an ordinary election isn't behaving as a weighted one behind the scenes was never added, which makes this voting system insecure and not what a reasonable person would consider "observable".
The article you linked, on the other hand, made me feel patronized, skeptical of the author's central premise, and a little bit uncomfortable.
> They allow “weighting” of races. Weighting a race removes the principle of “one person-one vote” to allow some votes to be counted as less than one or more than one.
This is extremely inflammatory language. What I think they mean is:
> They allow “weighting” of electoral contests. Weighting an electoral contest removes the principle of “one person-one vote” to allow some votes to be counted as less than one or more than one.
However, what they wrote seems to heavily imply a racial bias to electronic elections. Why they would choose to use such racially charged language around such a benign topic at this time seems only to drive links to their site over such a non-controversial issue.
"The “Summary” vote tally, which provides overall election totals for each race on Election Night"
and
"Presidential race in an entire state switched in four seconds"
Granted, they could have chosen other language that's less likely to be misconstrued. As for the choice of language, I don't think the article is all that well written (for another example, mixing "fractional" and "decimal" to mean the same thing). I don't think there was that much thought put into the language.