Maryland will audit all votes cast in general election
baltimoresun.com
baltimoresun.com
It could work like this: you get the private/public key pair provided in your passport, or on a special social-security-type card. The public key is also on a website registered to your name, so anyone can look up your public key. However, in order to be allowed to sign anything, you have to be in the presence of a government agent who can verify your identity via a second means (e.g., at the DMV, your driver's license + social), and then the government agent signs it as well. So there's no _less_ verification of your identity in the system as before, but anyone can quickly verify the authenticity of your documents.
http://www.id.ee/public/The_Estonian_ID_Card_and_Digital_Sig...
Voting in the USA must be preserve the secret ballot and be publicly verifiable.
I've studied a few crypto voting systems. None so far satisfy these requirements.
Further, any future perfect voting tech will only be provided by vendors, vs done in house, and I oppose the outsourcing of our election administration.
Build a system that can handle public keys for 100K people for more than ten years and then I might think about letting you start working on a pilot system to work out the additional failure scenarios, but absolutely nothing that the tech industry has produced in the past thirty years provides me with any sense of confidence that they would not screw this up horribly (and then those same people would complain bitterly on some future HN equivalent about what a waste of money this effort was.)
https://security.stackexchange.com/questions/46709/can-a-zer...
http://www0.cs.ucl.ac.uk/staff/J.Groth/ACNS05VoteProofFull.p...
Oh, and the people assigned to do the task (checking the ID, marking the stuff, later on counting the ballots) are randomly chosen from the local census. Accredited people from the political parties can be part of the counting (but not touch anything until the first count is done).
I understand and fully sympathize with the spirit of this idea, but it is very important to understand that it cannot be the government who assigns a key pair. It has to be you who generates the key pair, and registers the public key -- and only the public key -- with the government. And the registration process has to be such that no one can register a key that they have generated on your behalf. Getting such a process to really work can be quite tricky, even trickier than conducting an election the old fashioned way.
Since it's a system of great complexity (anything involving programming, crypto, networking and any electronic is, really), you can't guaranty that.
The government would publish an auditable non-repudiatable key registry, i.e. a public ledger similar to a blockchain (except you wouldn't need miners because the government would serve as a trusted third party) which maps keys onto their owners and vice versa. Anyone can then at any time look up their key in the registry to make sure that it really is their key. The initial registration process would involve some sort of identity confirmation similar to what you have to go through to get an official government ID issued nowadays. To register a key you would go to a notary who would take a photo of you and attest to the fact that the key being registered is the person in the photo. The photos would not need to be published (though they could be). They would be used mainly when someone alleges identity theft. That would make it highly likely that anyone attempting to falsely register a key would be caught. That would remove a lot of the incentive to attempt it.
- The network can be hacked;
- the client can be hacked;
- the server can be hacked;
- people managing the server can be corrupted or forced to do things;
- the system could have a subtile bug in either the client, server or network;
- the system could have a failure in either the client, server or network.
- how are persons suppose to be able to audit them ? Go to the server ? The network node ?
- how much time a citizen must spend studying the system before he or she can start to even begin to assess the sanity of it.
- how much time and persons to assess the entire system ?
There is NO WAY an average citizen can even start to comprehend the full extend of all that, if you couldn't even see all those problems.
Paper is simple. It sill can have it's problems, it's not perfect, but people can understand it and audit it quickly, easily, without being trained. It has less single point of failure, less complexity, more accessibility.
Technology is NOT the answer here.
So, like, just a ledger?
But wouldn't using a blockchain be a better idea for something like this?
Blockchains are useful in financial systems because there are strong incentives to cheat, and hence it is much more difficult to find a trusted third party to keep the ledger.
It should also be noted that blockchains only protect their direct participants. Secondary actors can still be cheated every bit as easily as they can in traditional financial systems. And even the direct participants are not fully protected. Bitcoin is by far the biggest blockchain in terms of mining capacity, and well over 50% of that capacity is in China. If the Chinese government wanted to attack the Bitcoin network it very likely would succeed.
That too. But mainly it's because I don't trust the government (or anyone else for that matter) to keep my secret key secret.
Defense secrets are a little different. It's not so much that I trust the government to keep them as that I believe that the government is incentivized to keep them because that advances the government's interests. But even then there are exceptions when the stakes are high, c.f. Ed Snowden.
Australia has a total hand count with machine verification (if they disagree the hand count is redone) and party observers.
Combined with mandatory voting I have total confidence in our system as one of the best in the world.
I don't believe it is an offence to vote informally but even if it was the anonyminity of the ballot woult make it impossible to enforce.
In the last Federal Election the overall informal vote share was about 5.92%. In some electorates it was above 10% [1].
The AEC doesn't distinguish between votes that were intentionally invalid and votes that were unintentionally invalid. I used to work as an electoral officer and in my experience the latter usually far outweighed the former. I saw very few if any ballots that were totally blank, about 10-15 where the person tried to make a statement of some sort and the rest were people who did not understand the instructions and number every box.
As far as I can tell, elections in Australia are seen as something you don't really ignore despite your individual disdain for politics.
[0] http://www.aec.gov.au/voting/informal_voting/
[1] http://www.aec.gov.au/voting/informal_voting/division.htm
TLDR: Greater direct democracy, we vote on everything.
Not any more.
Back when we all used actual real paper ballots, sure, but the new electronic voting machines don't allow for that.
cf. Black Mirror writer Charlie Brooker: https://twitter.com/charltonbrooker/status/74592155647647334...
What guarantees the vote cast matches the vote printed?
I've attended my jurisdiction's VAT (verification and accuracy tests). When the card or paper strip was unreadable, they just swapped parts until it worked. So the only thing verified was the printer was still working.
I accept the fact that someone has been elected, I don't trust that they were elected fairly.
While it's certainly worthwhile to have more competitors, with better wares...
I'll only support open source, citizen owned software. The strangle hold the election system vendors have on our elections is deplorable. And it's not like this stuff is rocket science.
citizens aren't private entities anymore?
Anyone think this election will end on November 8th?
1. votes not being counted properly
2. Improper votes being cast
This seems like it only addresses #1
Reading between the lines...
This will be an audit of their internal bookkeeping. Ballots received equals ballots accounted for, number of signatures verified, that sort of thing. It's worth doing. When I served as a poll inspector, we'd proof each other's work, which is normal.
In my jurisdiction, final result is called the ballot summary report, which is approved by our canvassing board, which ultimately certifies the election.
An audit of the actual votes cast is not practical, certainly not in just two days.
This has been studied. The papers presented at the Election Verification Network conference(s) demonstrate that an audit, which is much like a recount, is expensive and does little to increase the certainty of the results. And when electronic (digital) casting and counting is involved, it's impossible.
https://electionverification.org
The best strategy remains the Australian Ballot (private voting, public counting), paper ballots, precinct-based counting of the votes when the polls close.
[1] http://www.nbcnews.com/news/us-news/study-finds-no-evidence-... [2] https://www.brennancenter.org/issues/voter-fraud [3] http://www.nytimes.com/2016/08/05/us/voter-id-laws-donald-tr... [4] http://www.politifact.com/truth-o-meter/statements/2016/oct/...
To be fair, most of the problems we are currently having seem to revolve around gerry mandering with potential issues arising in the future involving tampering with electronic voting.
That doesn't mean voter supression, identity theft, and other forms of tampering aren't legitimate concerns though.
For example, heres article from MSM that investigates people who have been dead for years are still voting:
https://www.google.com/amp/losangeles.cbslocal.com/2016/05/2...
There is rhetoric now as though most or all voting is subject to this kind of fraud, that the fraud is massive. It just isn't. That doesn't mean it doesn't exist or shouldn't be stopped, but threats must be dealt with proportionally to the degree that they are threatening. Your reaction strikes me as disproportional.
Ignore intent and focus on prevention, like a QA/test person would. I'm kinda thick headed, so it took me too long to figure this out on my own.
It doesn't matter why something happens, only that it happens.
One side assumes the problem is huge, especially when they lose, and wants to take effective measures to prevent it. This side sees opposition to common-sense security as confirmation that fraud is actually occurring and is actively supported by the other side. The refusal to solidly secure things may or may not actually matter to the results, but it sure fuels suspicion. After all, why allow doubt about correctness unless you actually are doctoring the results?
We'd be better off if we could clearly demonstrate to the losing side that the loss is legit. Our low-security situation encourages the loser to claim that victory was stolen from them. That isn't good for keeping things peaceful.
The sources I provide clearly demonstrate that it is not an unknown problem. I would agree that it is a problem whose scope is not fully understood, but when you have something that doesn't seem like a big problem to most people, it's hard to argue that you should spend lots of time investigating it/divert resources to it. Since people's perceptions of the system are changing now, maybe that'll change, too. It would be one of the few good things to come of this election cycle if so, provided the money spent and time invested are reasonable/proportionate.
> After all, why allow doubt about correctness unless you actually are doctoring the results?
Like another poster said in this thread: Because you don't know better. Because you don't care. Because you don't think it's necessary. Because you can't afford to. Because it's not what the law says to do. Malice should be the last, not the first assumption.
You use the term "refuse" a lot in your comment; I don't think this is a matter of "refusal," so much as it is a matter of "nothing/nobody is telling us to." The government doesn't do things unless the people force it to do things, or unless those things are absolutely and unquestionably in the best interest of the people in government (and even then, it doesn't always act until the law compels it to).
Generally, I just think this issue is less sinister and more typical of the American political system than people think it is these days.
Second, you're statement "Malice should be the last, not the first assumption" is fundamentally incorrect. You shouldn't make any assumptions, you should look at the facts. While the intent may be benign, the effect is wide spread distrust, which is not and should be addressed accordingly.
I do not buy your narrative about media bias. I think it's ironic that you are standing on "we need hard facts and data" while providing none to support the idea that media is as biased as you say, only innuendo and an appeal to "the tech community."
You claim to be data driven, but when I provide data, you summarily throw it out, do not replace it with any of your own (or even an assertion that none exists), and make vague assertions about media bias instead.
> Second, you're statement "Malice should be the last, not the first assumption" is fundamentally incorrect. You shouldn't make any assumptions, you should look at the facts. While the intent may be benign, the effect is wide spread distrust, which is not and should be addressed accordingly.
I'll address this in concert with your reply above:
> It doesn't matter why something happens, only that it happens.
It does matter why, because if you want to fix it, you have to know the cause. If the problem is a problem of perception, that is fixed differently than if the problem is with the system itself. Data is meaningless without context.
Facts and figures and studies can be produced, but unfortunately that's not enough to convince people -- and that's on both sides. As much as we'd like to be, we're not perfectly rational actors, and much less so in aggregate. The existing system isn't simple or transparent enough for people to trust. That's what we need to work on.
There exists today a large group of people who will disregard anything the government or "mainstream media" says as false, regardless of who says it or what the statement is. What do we do about those people?
I want to believe that it's solvable, because the vast majority of people I meet day-to-day are good people. I'm not willing to accept the alternative.
I do think a big part of it has to do with figuring out how to talk about contentious issues, of finding common ground (no matter how narrow), with people we might disagree with on other issues. We can't let our disagreements get in the way of making progress on our common goals.
Security Requirements
• Only eligible voters may vote, and each eligible voter votes at most once.
• Each cast vote is secret, even if voter wishes otherwise!
-- No vote-selling!
-- No receipt showing how you voted!
• Final outcome is verifiably correct.
• No "trusted parties" – all are suspect! Vendors, voters, election officials, candidates, spouses, other nation-states, ...
Full slide-deck:
https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf
Lots of other great stuff in there, addresses each of these points.
EDIT: Based on comments - this is a video that records the president stating that people in the country illegally (non-citizens) should not fear any repercussions from voting in the election.
It's also against HN guidelines to comment on downvotes as it generally doesn't add anything to the discussion.
Also, if you watch his entire response it's clear he interpreted the question as a person legally able to vote, but has family members who are undocumented and are afraid of voting for that reason.
That said, it does sound really bad. Especially how nonchalant the president is about breaking immigration laws.
I'll update with a time link to the section in question in a moment.
https://www.youtube.com/watch?v=oLLt-a6dI_0&t=3m20s
I personally am quite sure they mean to talk about citizens with undocumented relatives voting, but the exchange is not well done, it sounds like they are talking about non citizens voting (of course undocumented people probably aren't registered to begin with).
She wants to know if immigration is going to go through voting records and discover the place she lives may also have undocumented immigrants living there.
At least in San Jose / Santa Clara county where I went to cast an early vote, there's no verification of who you say you are. They only ask for your name and address (pretty easy to get). Maybe they have access to DMV records (a recent photo of you) on the computer they're looking at, when you provide them you're info? If so that's a good step, but I doubt they do that (what about for people who don't drive)? They also do zero checking when you're dropping off someone else's ballot in person. There's a spot on the back of the envelope where it's required to put the name of the person who's dropping of the ballot if it's not the person who cast the ballot, and no one even checks that.
Let's start with that. To reduce forgery, match the ID against an image of it on a computer. Better yet, scan it into a computer and have the computer do the matching.
Also, take a new picture. This can be used to help catch and prosecute any remaining fraud. More importantly, such fraud would be strongly discouraged by the increased possibility of being caught.
GP wrote:
"...the only fraud happening in our elections are a) gerrymandering and b) racist voter suppression laws..."
You wrote:
"That's an extremely strong claim to back up with no evidence."
I asked:
"What measure of proof do you require?"
Honestly, I expected something related to proving gerrymandering, disenfranchisement, or something.
The idea is the state will no disenfranchise you for making a mistake while making the cost (risk) of bulk voter fraud higher as to be infeasible.
Is this the case across the US?
Whether the voter registration rolls are up-to-date, that's another matter as well. And double voting is only one type of fraud.
Nobody with sense would try, it carries severe punishment (it's a felony) for virtually no benefit to the person taking the risk, and really virtually no effect on the election either.
https://www.washingtonpost.com/news/post-nation/wp/2016/10/2...
Because it doesn't fucking matter? Also going to need to see some receipts for that.
Most of these kinds of "fraud" are actually voter registration "errors", where someone votes in the wrong jurisdiction. Like Ann Coulter did.
As for postal ballots, ya. The voter signature and proxy name are mostly for after the fact investigations if problems need to be resolved. You should attend your canvassing board meetings to hear all the nonsense. Husband and wives swapping envelopes. A couple putting two ballots into one envelope to save a stamp. Ballot from a prior election. Soiled ballots. Missing ballot, so voter just used another piece of paper (still legal). Etc, etc.
That spouses, job bosses, church leaders, command officers "help" others vote (the correct way) is established and well documented. But society seems to have decided that the benefits of enfranchisement outweigh the downsides.
Remarkably, comparatively, there's very little abuse of postal ballots. We're talking 10s and 100s vs 1,000s and 100,000s who are disenfranchised by other means. Caging, gerrymandering, underprovisioning voting machines and polls sites in key areas, not counting any votes on spanish language ballots, calling in a bomb scare and shutting down the central count which then has a mysterious miraculous election result, ad nauseam.
There's no shortage of problems with our districting, campaigning, elections, voting, tabulation, vendor relations, etc. If you only care to look. But please don't make the mistake that retail voter fraud is a significant factor.
As for why people downvoted you, probably because watching some shakey-handed screen recording and presenting it as some great revelatory fact predisposes the reader to thinking this has to be a joke.