Election Commission of India throws “open challenge” to hack voting machines
thehindu.com
thehindu.com
If you live in the Bay Area and are interested in securing elections, now is a great time to get involved. There's a public meeting next week (sfgov.org/electionscommission).
I'm also happy to get coffee and catch anyone up on where the effort stands – email in profile.
EDIT: I should have clarified that the new system will remain a 100% paper ballot system. The software involved is to organize, print, tabulate, and tally ballots. There's a strong community that opposes inherently risky approaches involving things like digital storage and the internet (again, reach out if you're interested in joining!).
Decentralized electronic machines that print paper ballots for you (which you can physically verify), and submitting to a tabulator seem to be the safest option. But your paper ballot can be compromised in transit by a worker. I have also heard talks about using a blockchain-esque system for voting and verifying it online with a hash code.
Here's a great video by Tom Scott: https://youtube.com/watch?v=w3_0x6oaDmI
I see this expressed a lot. But the argument always seems to actually be that electronic voting doesn't play nicely with anonymous voting.
It's possible that either might be a better choice than the other.
If you give people a way to prove that they voted a certain way, then the election is robust against rigging, but you've also allowed vote-selling as a side effect.
In Denmark someone made a study and found out that when voting changed from public (everyone could see who voted for who) to anonymous the workers parties gained votes to the tune of double digit percentages.
Presumably what happened before is that the landlords, owners and managers would tell the workers who it would be "best" to vote for if they'd like to keep their job or apartment. If I recall correctly this was around 1910 or so.
> In Denmark someone made a study and found out that when voting changed from public (everyone could see who voted for who) to anonymous the workers parties gained votes to the tune of double digit percentages.
Is that a good thing in itself? How much of one?
I don't see "the workers' parties get more votes" as a worthwhile end in itself, but maybe you're different.
How do you define “make people better off”? Is political self-determination an end in itself, or is the whole political system just a means to material success for the ruling class?
Personally I think having a wider distribution of power in the society is itself a goal worth fighting for. In the long term it tends to make the society more just, more stable, and more prosperous, and bring the political process more into alignment with solving concrete problems affecting the citizenry.
If you think the purpose of elections is to realize the inherent moral virtue of voting your heart, I don't see why I should be encouraged to vote my heart when it tells me that it wants Robin Williams to be president, but not when it tells me that it doesn't really care whether John McCain or Barack Obama is president, but it does want ten dollars.
In my opinion the purpose of elections is to make the political system beholden, responsive, and accountable to the populace; to give the political system legitimacy so that it will be popularly supported; and to guarantee peaceful transitions of power and general political stability.
Those goals are undermined when a small number of powerful people can intimidate, cajole, or trick the public into voting how they prefer (usually against the interests of members of the public, and the nation’s interests in general). For this reason, I believe in constraints on campaign financing, election-season advertising, and believe that free, fair, and accessible elections should be a political priority in my country, alongside robust public education with instruction in civics and critical thinking, and a healthy independent media ecosystem.
I have no idea what “the inherent moral virtue of voting your heart” means. Feel free to vote for Robin Williams if you want, but realize that in most countries (including the USA) write-in votes for dead Americans are invalid.
> vanishingly unlikely that an ironclad one-man-one-vote system is close to the best we can do
I have no idea who you’re responding to, or what your point is. Nobody in this thread ever said anything about an “ironclad one-man-one-vote system”.
Any village idiot can go and observe and verify paper voting. But it requires an expert to observe and verify electronic voting, if it's possible at all.
EVMs are not internet enabled, neither are they "programmed" by sticking a USB in them. They come in huge sealed boxes to the centres, and are carried back the same away. The data never leaves these machines. If my knowledge is correct, the data can only be accessed by a high ranking election official called the RO.
Paper ballots were the norm in India for over 40 years before EVMs were introduced. Election fraud has been non-existent since then.
It's Pandora's box.
Can you provide a source for this please?
There has been no proof of election fraud in Indian elections since EVMs were introduced, apart from the usual whining of the leaders who expectedly lost.
Moreover, even a cursory search of electoral frauds in India throws up a huge gamut of complaints, ranging from 'ghost voters' to missing ballot boxes (and EVMs). Parking aside an another unsubstantiated claim that leaders who lost are just 'whining', I will still contest the claim that 'there have been no electoral frauds' since EVMs were introduced, as your original comment implied.
http://www.livemint.com/Politics/fIKiRvhaDSieYz25Lm8vRM/EVM-...
It's important to have skilled engineers play a part in the design of the system to help identify and avoid these problems.
The city is putting together an Advisory Committee as we speak for this very purpose. I'd encourage anyone interested to apply.
"Security is a process. For software, that process is iterative. It involves defenders trying to build a secure system, attackers -- criminals, hackers, and researchers -- defeating the security, and defenders improving their system. This is how all mass-market software improves its security .... Smart security engineers open their systems to public scrutiny, because that’s how they improve. The truly awful engineers will not only hide their bad designs behind secrecy, but try to belittle any negative security results."
A couple of things to note here,
- This is not the first time. It was done before in 2009.
- It is in a physical location, and will be monitored by people.
- There are various "stages" involved, and I'm guessing anyone who's invited will be vetted.
So we have a monitored, time bound, physical access to device hack-day, open to people to try and break a system to learn it's possible flaws - if anything, the system is only going to get better not worse.
The likelihood of someone finding a vulnerability and not disclosing it is much more troublesome when they were the only people doing this. If the system is opened up to a large number of people, it is more likely that the vulnerability in question __will__ be found and fixed.
It's possible to hide exploits in so many places - consider the obfuscated C contests, or the trojans that have been found in SSDs, or that hack a while ago where someone compromised a RNG by undetectably tweaked the dopant levels on a chip.
It takes very little to swing an election if you're strategic, sometimes less than 1% of the vote, and having the head of a state owe you a favour (not to mention the blackmail material), is well worth compromising one or more of the people involved in the production of the machine.
To make a demonstrably exploit-free voting machine, you'd have to design and manufacture every chip yourself and write every line of software (including the OS) yourself. Not only that, but everyone involved would have to be trusted to not be bribed, and to not make any mistakes that could lead to an external exploit. That's completely unrealistic, so countries are essentially saying "it's OK if there's a possibility for someone to take control of our country through fraud, because even though we know for sure that it's possible, we don't think it will happen to us".
Elections are too important to let the fools and charlatans who say things like "unhackable" to have influence over anyone with the the power to make decisions about electronic voting machines. Everything is hackable, given the resources and the motivations. Gaining control of an entire country is sufficient to have both.
Good points. I'd add that the potential attackers include national intelligence agencies and other very well-resourced groups, including criminal organizations, corporations, and others. For them, the value of controlling the outcome of an election can be many billions of dollars or existential.
It doesn't matter if it takes a little or a lot; the cost is unlikely to be a deterrent to those types of attackers.
Can there be process that can be guaranteed "unhackable". The paper based Ballot Box election in India were subjected to an even higher degree of reported rigging/hack then EVMs.
You'd then require a hack to comprise entirely different systems of hardware & software simultaneously. No one hardware vendor could control it?
The bigger problem is that it can be used to verify that a coerced voter cast their ballot the way that the coercer wanted.
My question is: why go through all this incredible effort, and take such huge risks, when paper ballots do the job just fine?
The electronic voting machines are not much different from a paper ballot system in that they are just boxes that hold vote counts, in bits rather than bits of paper. They are not network connected and to my knowledge they are not easily programmable once deployed in the field. i.e, they would require collusion of a large number of local officials, including that of the central election commission officer deployed in order to facilitate reprogramming.
Elections if rigged are done so by people, so the threat comes from the vast numbers of government employees who are deputed from their day jobs to perform election duty. These people hold the power to rig elections by miscounting the paper votes. If the counting process is digitized using dumb machines, then that would maybe take care of the malicious counting problem.
Ultimately any system would rely on the integrity of the actors involved to function properly. In a country with levels of corruption that India faces, it is easier to keep an eye on the few direct employees of the election council rather than every person deputed for election duty.
I have had countless discussions with my colleagues and not one of them understands the gravity of closed EVM machines instead believe in security by obscurity. It makes me sad that if the very people who work in technology are like ostriches with their heads buried in sand, how can you expect the lay person to understand the argument for implementing a verifiable system. Its an anathema.
Anyone who argues for this is either a case of sour grapes or anti-government/anti-democracy.
Also can anyone please clarify how one one can go about taking part in this process, wasn't clear to me from the article.
The govt will invite some unknown or well paid experts, and get a clean bill of security. Simple.
This purported "open challenge" is an response to the current political drama staged by the opposition parties crying foul over lost elections.
In UP, the current ruling party sweeped with a thumping majority. (325/403)
But, the same Congress and AAP that were defeated to nil in UP, got significant and in fact leading number of seats in Punjab - 77/117 and went on to form the government. AAP got to form the Govt in Delhi in the last elections.
In Manipur and Goa - Congress got 28 and 17 respectively and was the single largest party. It is another story that they were not able to muster enough strength to form the government. [1]
So, basically, they cry foul in UP accusing the machines were rigged. But, they happily accept the same machines' verdict in Punjab and form the govt and conveniently ignore the fact that in two other states the same machines gave them the single largest party status.
What election commission is trying to do is to prove their parity across parties, which you can see from the above results. Election Commission is an independent body in India and cannot be influenced or rigged towards one or other party of which the opposition is accusing them of unfairly.
Having said that, yes, any system is hackable may be, people can try. But, hey, at least EC is open about it and cannot be accused of favouring any one entity. It can be thought of as a hackathon and if someone finds a bug, they will fix it.
Political parties crying after losing elections is nothing new in India. BJP cried after the 2009 Lok Sabha results. See this speech in the matter by Subramanian Swamy (a senior BJP leader): https://www.youtube.com/watch?v=AXpPRbQx1WI
For Subramanyan Swamy, if I remember correctly, he did not stop at crying foul. he went to Supreme court and got the VVPAT installed. It is another matter if VVPAT makes it foolproof though, but definitely helps.
I am not supporting this party or that party - all I am saying is that - 1. EC cannot be blamed for partiality as it is made out by the opposition parties and media 2. This is more of a politically driven issue than a majorly technical exercise.
I have no dog in this fight, so this is not political but purely a response on the reasoning.
Questioning the security of a system doesn't mean you believe all such systems have been compromised.
Does such a body truly exist anywhere?
Of course it is possible to go to great lengths to rig the system to destroy this situation as well but any sensible person/group will understand that the impartiality of the EC is in the larger favour of everybody.
In a national law to introduce voting machines nation-wide the law sets up to five years IRLC if someone does an unauthorized audit. Luckily the law was repealed last year but the current government is still pushing voting machines province by province.
http://www.argentinaindependent.com/currentaffairs/analysis/...
Given the logistics, introduction of EVMs have reduced these kind of election day events, even though Election day violence is more clashes between supporters, the polling booths are much safer now than couple of decades ago.
I won't say voting machines are the magic to it all, but it did help a country with labor and service delivery issues to manage it better.
EVMs were always hackable, but the critical man power and tech orientation in political parties to take advantage of this hasn't been there.
This may only recently have changed. Even then I doubt it, there's other ways to win elections.
Sorry that's absolute bull. Apart from an exception or two ECs have been sycophantic puppets, ever ready to grovel. It seems you weren't born yesterday, neither was I, so you would know this.
Even if EC intends to do good, he/she cant do much until there is a formal complaint raised by the district magistrate (many are simply bought out). So even if the opposition cries itself hoarse, EC does zilch.
I am not making any claims about the EVMs, just that the electoral process is no where close to as clean many of its proponents claim it to be. Tech alone cannot solve this problem. What we have here is the analogue of rubber hose decryption.
I strongly disagree with your assessment. The mechanics of what happens when polling starts as I remember it,
- The EC assumes complete control over all civil services, including transferring people in response to independent assessment and complaints.
- Courts in India can't interfere with the EC. The government is disallowed interference as well. The constitution guarantees this and has been upheld by judgments in the past years.
- The chief EC commissioner can only be removed by impeachment in Parliament. The other two election commissioners can only be done so by the CEC's recommendation.
- Senior officials from different states are election observers in other states - and they are liable to be suspended even if phone calls are recorded between them and a political appointee.
- All paramilitary and police forces come under the command of the EC. As a result, they are free of machinations from the home ministry which is usually responsible for their control.
- Candidates make multiple reports during the campaign process and the EC does strict accounting for all this. It bans liquor sales and drafts banks to report any overt cash transactions.
I don't know where you're getting your information from, when you were born, why you think the EC is sycophantic, or how that would even help - but the EC's role in the Indian elections is more like a safe maker trying to hoodwink the safe cracker - it will never be perfect, but given its many constitutionally guaranteed rights, it is agile enough to try and stay a few steps ahead of the curve. It is this very flexibility via which the ECI can even think about opening something like this up to a challenge.
Using eyes and ears and just being aware of my surroundings.
Trivial counterpoint. Pickup a state, say West Bengal. Count the number of egregious incidents of violence and intimidation reported by competing political parties and the media, including live videos. What action has the EC taken and what has that changed.
> - The EC assumes complete control over all civil services, including transferring people in response to independent assessment and complaints.
... and then does what ? You are being completely naïve in the open bedfellows relationship with IAS and politicians. There are exceptions, but rare.
Hmm, not quite the best sources of information then. Have you talked to anyone on the ground? Have you been an election observer or volunteered in any? Have you read the independent reviews of the EC? Talked in any detail to senior officers in any branch of the executive who may offer perspective?
> Trivial counterpoint. Pickup a state, say West Bengal. Count the number of egregious incidents of violence and intimidation reported by competing political parties and the media, including live videos. What action has the EC taken and what has that changed.
Hardly trivial. This is a law and order situation, and is dealt with appropriately.
> ... and then does what ? You are being completely naïve in the open bedfellows relationship with IAS and politicians. There are exceptions, but rare.
Naïveté is an easy thing to call upon in cases when information isn't easily accessible. Your statement, to me, makes it appear that not only could you have wrong or incomplete information shaped by public media - you're not willing to even consider that this may be the case!
Well, when I am standing in a queue to vote, I trust my eyes and ears more than what some report says about things that happened while I was standing there.
> This is a law and order situation, and is dealt with appropriately.
All that law and order violations were a means to an end and the end is tampering with the mandate and that is exactly where the EC has to step in. If all they can do is pass the buck and let the tampered mandate be counted as real, well it is not serving its one and only purpose. I am being charitable here in assuming goodfaith on EC's behalf.
> Have you talked to anyone on the ground?
yes many
> Have you been an election observer or volunteered in any?
volunteered yes, but not formally as an election observer and not as a part of any political outfit.
> Have you read the independent reviews of the EC? Talked in any detail to senior officers in any branch of the executive who may offer perspective?
some of it runs in the family so I do have some insiders perspective plus volunteerism does give me opportunities to interact with IAS officers in the field.
And public media especially TV is crap, newspapers are somewhat better. There are one or two decent ones that I treat with some respect, rest are tabloid'ish garbage. But to the larger point, no, my opinions have very little to do with what goes on the popular media.
I dont have as much a respect for the EC as you seem to have. My disdain is targeted less towards "EC the institution", more towards the lack of a functional vertebra of the chief ECs that we have had (barring exceptions of course)
However, we are still far far away from the ideal that every election in the country are free and fair.
...and finally thanks all for the discussion we had here.
Edit: similarly with the SC. Both of these were institutions which were beyond reproach, and I pretty clearly remember the times they both got dragged into the political limelight. The issues were largely to deal with their growing power over the political class. And this is something which you'll see had support on all sides of the political aisle.
People are playing with fire, and damn the consequences.
I would make a far stronger claim, its actual non-trivially hard. But when the executive branch has been bought out by the incumbent govt (which is frequently the rule rather than the exception in many states) those technological and procedural hurdles dont amount to much. As I said it is not a technological problem.
> You are obviously a troll with zero intention to contribute to any meaningful conversation
I wish it was that. Sadly these are things that deeply affect human lives and their potential, and I dont know what to do about it
That's a little different than being arrested for finding bugs in the software or hardware. Prima-facie, it does seem like stealing government property without proper written authorization. Arrest still seems excessive, but the circumstances seem to be a bit more nuanced.
The chances of only one person finding them reduces drastically, so even if someone wants to hide a flaw another might expose it...
If only to keep their credibility.
For ex., On election day, mock voting and counting is done in the presence of all party representatives - the results are then erased before the actual counting. And representatives of all parties are mostly around when these machines are moved around and counted. Also, the way party symbols are listed is not pre-determined etc. and hence cannot be predicted by someone wanting to add votes to a particular party.
Source - my mom has been a presiding officer during elections a couple of times, and I've looked at the training manuals..
Here is an example: Is NOTA ("None of the above") option's location also randomized? If not, a backdoor would listen for this sequence: NOTA, NOTA, NOTA, X, NOTA, NOTA, NOTA, X. And then it would start re-assigning votes in favor of X with say 60% probability. It doesn't matter where X is located. The backdoor might trigger only after a few 100's or 1000's votes have been given. How will mock voting or randomization help here?
The sad thing is that all these weaknesses have already been detailed in Hari Prasad's original paper. But EC continues to dish out the same flawed defense: https://indiaevm.org/evm_tr2010-jul29.pdf
Can a single EVM be hacked? when its not connected to internet - With sophisticated tech (and engineers) - Yes. Its digital electronics after all
Can that be done consistently across machines under different ambient environments? - Higher than 50% accuracy, but not 100%.
Can it be done at scale? No - that would be too costly even for the political parties with a higher probability of it becoming a widely known technique
But the answer to the first question is enough for the opposition political parties to force India into paper ballot voting. And paper ballot in India is easily hackable for political parties - just spend money, hire bullies and prevention is ensured not to work at this scale.
As HN readers know, even if you know your systems have been penetrated it can be very difficult to detect the extent of the damage: Which records have been changed? Deleted? Added? And what authority decides? We can expect that every party will produce experts who make claims in their parties' interests.
Probably, we wouldn't know the accurate election results. What then? Rerun the election?
* Is there a legal provision for that? What authority gets to decide that the democratic will of the people, the ultimate authority, is invalid and should be tested again? That is a very dangerous path to go down.
* If the results change, you can imagine the response from the new losers and their supporters.
* Who is to say the second election is valid? If the same machines are used, will the public trust them? Is there time to create a new national election infrastructure?
Reporting a possible attack to the public could destabilize democracy and have no real resolution. As has been reported, intelligence agencies such as the Russian FSB may be more interested in destabilizing things than in a particular result. They could even purposely leave evidence of an attack, without carrying through with it (and of course hiding the true perpetrators).
Based on that reasoning, it is absolutely essential that we prevent attacks. My very strong opinion is that a purely paper election is the only solution.
No one can hack them, or nobody has had long enough with just "a week or 10 days". Hardware and software reverse engineering can take significantly longer, depending on the complexity of the machine. It's likely they will also be limited in what they are allowed to use. If they are so confident, open source the designs and let researchers take a look.
Another reason for why their claim may be false, is the value of somebody freely giving their hack away. Sure, a moments national glory as you get a targeted painted on you for publicly embarrassing your government - or - lots of bit coin on the black market to the highest bidder.
Ideas:
* Simply place a piece of pink paper over the top to change the details, so the buttons no longer correlate to their correct vote. Enough people in enough provinces would make a serious difference. At the end of the day, have somebody take the paper back off before the poll closes so that the evidence of tampering is gone.
* Large electro magnet to device, making all votes erased. Using statistical data from previous elections, as well as popularity polls from previous elections, predict which machines will be worth taking out to sway the vote. These devices are electronic, therefore likely to use some form of memory that is electromagnetically erasable or corruptible.
* Hack the device that retrieves the data from the machines.
* Social engineering, through bribery or blackmail.
Also known as "Plain old electoral fraud"
So your points are not applicable in this case. Hacking machines should be much easily provable than random generic political charges like 'govt/politicians are corrupt' or officialdom is lazy etc.
So paper ballots are nice, but it's certainly not enough. You need a system put in place so that when there's an audit and the numbers don't match, a revote is automatic, and the commission can't just excuse the issue away with "glitches." Or at the very least, you recount all the paper ballots and go with those results.
But this process needs to be guaranteed under the law somehow. You can't leave it up to the those in charge of the elections, who may happen to benefit from a result, to decide whether there should be a recount or revote. And the punishments should be drastic otherwise (we are talking about maintaining the integrity of the democracy after all - slaps on the wrist shouldn't happen punishments need to be handed).
At one particular event[1] an engineer detected RF noise leaking from the keyboard (Van Eck Phreaking) but the government dismissed it as not being a practical attack. In a country where politicians literally buy votes in poor regions, vote secrecy is a big concern.
[1] http://pcworld.com.br/noticias/2009/11/23/perito-quebra-sigi... (in Portuguese, sorry)
That's a bold claim. Makes me wonder about the validity of their tests and how they evaluate results.
Is the source open, and has it been audited? Has the tool chain been audited (eg: the attack described in Reflections on Trusting Trust [1])? Are they using reproducible builds[2]?
This includes not just the software loaded on the machine itself, but the tallying software used to count all the results.
Even if you can verify the code contains nothing like a "defeat device" [3] (eg: detect it's actually election day and only then enable vote-stealing mode), how do you know what's actually being used?
How does a voter verify that the build running on the machine is actually valid and the expected one? Even if the voter has to trust the people running the election, how do those people verify it? If all the polling stations load software onto the machines on election day (to ensure it's the right software), that opens up the possibility of someone injecting their own bad software. If they have to rely on a central organization loading the machines, there's a whole delegation of trust happening and being concentrated in one place -- easier to verify, in some ways, but also easier to compromise.
So the only way to run a valid contest is to provide access to the entire process. Can I modify the software used to tabulate? Can I act like I working at the company providing the software/hardware and have access to the code, build process and signing keys?
If that's possible, and you can still detect cheating, then that's great, but I also fear it's an arms race with no end, and it's just a matter of one-upping the other side.
[1] https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thomp...
Babur was king of Fergana Valley, and half-turkic and half-mongol, who lost his kingdom because of logistic blunder and was invited to India by a Prince and thus started his campaign in South Asia.
He did destroy a Temple (which already survived about 5 centuries of Islamic rulers) and built the mosque, the mosque was not being used since 1949 or so, and Hindus were praying on the grounds since mid-80s.
https://en.wikipedia.org/wiki/Muhammad_bin_Tughluq
I am not arguing here, I am correcting mis-representations made in his comment.
Obligatory Computerphile/Tom Scott video on why voting machines are an awful idea; if you haven't seen it, it's a great watch: https://youtu.be/w3_0x6oaDmI
In effect, your identity card allows you to vote as many times as you wish. You cannot see your vote, but the newest vote overwrites the previous vote.
This means, that if you are coerced to vote a certain way, you can simply make another vote and wipe out the previous one.
The only downside is this would require a national ID program, which many religious extremists are very much against.
That, and knowing the federal government, such a system would cost a ton, be an overwrought mess of spaghetti code created by some Enterprise Software(c) firm, barely work, and most importantly, be rolled out primarily to benefit the government, rather than the citizens paying for it.
No thanks.
¹ Using a single ID for each person is forbidden by our constitution, in the article regarding the usage of IT.
I am not sure that voting machines are unhackable but when today's losing parties were winning in past years they seemed pretty sure that win was all due to overwhelming public support and not some rigged machines.