To Protect Voting, Use Open-Source Software
nytimes.com
nytimes.com
Instead, use open source hardware. Use pen and paper!
:-)
There's no reason to require something that everyone can understand when talking about a different voting system.
IMHO, we should aim to build something (whether using physical machines or using cryptography/mathematical properties) that the various parties in a government can audit and recognize as secure and that leads to a larger portion of the population voting or a cheaper election process.
While many people maybe aren't aware of the security mechanisms of a pen and paper election, essentially everyone can actually understand them if they feel the need to, and that is extremely important. You cannot resolve widespread distrust by putting a bunch of mathematicians on TV who tell the population that everything is fine.
0: https://cseweb.ucsd.edu/~goguen/courses/275f00/abc-chads.htm...
The problem with digital voting is that it needs to be anonymous who votes for what. That makes the problem much much harder.
* it must be anonymous, ie nobody but you should know you you voted for
* it must keep integrity, ie nobody can change your vote
* it must be verifiable by all participants
Paper vote makes it easy to meet all criterions: just keep an eye on the ballot and you will be relatively sure that everything is fine. On the other hand it is impossible to have all those conditions with a digital vote, if only because digital anything isn't easily verifiable by all participants.
One criterion, three criteria.
Same goes with money, these things called crypto currencies are digital money offering various levels of anonymity.
None that don't require printing a paper ballot so the voter can check the correct thing was done. And then taking that paper ballot and putting it in a sealed box. And once you've done that the high-tech bits are irrelevant and you're back to the cheap, safe and easy to use voting system we've been using without issue for decades or even centuries.
"Electronic voting is the reverse FizzBuzz. FizzBuzz tests if you know the absolute basics about technology to implement something extremely simple. Electronic voting tests if you are able to reject the use of technology when it doesn't add any advantage and instead creates very hard to solve failure modes. Voting benefits from the use of the extremely simple ballot and box. It benefits from it not being programmable and from the counting method being something that almost all the population is able to carry out let alone understand."
I have yet to see one that involves a digital voting system. Many of these voting systems are insecure and F/OSS(free and open source) won't fix that. You are giving too many people physical access to these systems at every step of the chain. Many have proposed a "blockchain" based voting scheme, but that takes out the anonymous aspect of voting.
> Same goes with money, these things called crypto currencies are digital money offering various levels of anonymity.
Yes and none of them provides any anonymity since they all at one point or another reveals too much about a given transaction.
With paper ballots, it's really difficult/infeasible to track who voted for whom and is a bit more tamper resistant on a large scale.
edit: a word.
The "trust" of the digital money system is because we can have humans unwind any transactions we deem to be "incorrect".
Unfortunately, we can't "unwind" an electoral transaction without giving up anonymity.
Problems with paper voting:
- Fraud
- Counting time
- Margin of error
Problems with electronic voting: - Hacking
- Cost
- Programming bugs
- Machine error
- Scalability
Actual way voting is handled - Some states use mailed paper ballots
- Some states use paper-free voting
- Some states use a mixture of electronic and paper voting
The biggest risk is not the mechanism, but the way it is implemented: 5,000 independent jurisdictions all have completely independent ways of choosing how to vote, and then completely independent methods of implementing it. [3]This[1] testimony from 2001 includes a good history of the voting process and the reasons why it is handled the way it is. The parent[2] directory contains 16 years of commentary articles.
[1] http://homepage.divms.uiowa.edu/~jones/voting/congress.html [2] http://homepage.divms.uiowa.edu/~jones/voting/index.html [3] http://homepage.divms.uiowa.edu/~jones/voting/PutinTrump.sht...
I remember this in San Francisco in 2001,
http://www.sfgate.com/politics/article/Scavenged-ballot-box-...
With regard to machines, many machines have recorded thousands of extra votes. Some machines run out of memory, and end up losing thousands of votes (those machines did not have paper trails). There's been plenty of problems with these machines - ones that can be fixed. But the fact that every precinct decides independently what to do and how to do it, there is absolutely no way (in the US) to provide a uniform solution to the problems of paperless voting.
This would mean there is a digital record on receipt of the ballot and the ballot itself. This seemingly would reduce the potential for fraud in both systems.
Again, 5,000 independent districts, and every single district manages itself independently. There is no way whatsoever to ensure proper implementation.
> have no significant fraud possibilities
We have a ton of provisions implemented to curtail significant attempts at fraud of paper ballots. And in paper ballot and absentee voting, there are large numbers of problems virtually every election cycle in various jurisdictions.
> and convince whoever lost the election that he indeed lost
This isn't even close to accurate. If there is a wide margin in a result, it isn't officially contested, even when we have evidence of corruption. When the margin is small, and a recount could possibly swing the vote, then the electee becomes unconvinced and demands a recount. (Or when the election result is simply too extreme, and the necessity of a recount is obvious)
Right, so the evidence that the US sucks at implementing paper elections should be used to advocate the implementation of an incredibly more complex system that somehow will implement itself?
>We have a ton of provisions implemented to curtail significant attempts at fraud of paper ballots. And in paper ballot and absentee voting, there are large numbers of problems virtually every election cycle in various jurisdictions.
Most of the world runs these kinds of elections regularly without issue and electronic means only makes this worse. You not only don't make the count any more accurate you also add complexity and enable a bunch of denial of service opportunities.
>This isn't even close to accurate. If there is a wide margin in a result, it isn't officially contested, even when we have evidence of corruption. When the margin is small, and a recount could possibly swing the vote, then the electee becomes unconvinced and demands a recount. (Or when the election result is simply too extreme, and the necessity of a recount is obvious)
All of that is true in the US yes, but again that's because the process is poor enough. Other places have extremely close elections that don't require this. You have such poor confidence in your election process you sometimes have legally mandated recounts on a low enough margin.
Using both electronic and paper means we get the benefits of both, and each side's downsides are managed by the other mechanism. According to every expert on the subject it's the most effective means we have right now.
If you would like to compare countries and voting systems, I welcome that discussion, but unless it works specifically for the US, it's not relevant.
Citation is needed for this. I know of no expert that recommends this and no argument for this. I've already pointed out how an electronic+paper system would be extremely vulnerable to attack. All you need is for the count to be different between the two for no one to trust your election.
>If you would like to compare countries and voting systems, I welcome that discussion, but unless it works specifically for the US, it's not relevant.
There's nothing about the way elections are properly run everywhere else that wouldn't work in the US. Implement enough voting booths properly staffed and you'll have no issues. If you can't do that you also can't implement any complex electronic system so this discussion is pointless.
The gold standard is precinct-based tabulation of paper ballots, counted the moment the polls close.
Saying we should ignore US elections as an example is totally ridiculous.
The US fails to do this and then has a problem counting fast enough. We should ignore the fact that the US is incapable of running proper elections since we have plenty of examples across the world of well run elections.
>failed to complete counting their votes in time for an election to be called for a particular candidate
This is another example of not running a proper election. If you haven't counted the vote the election is not over. There is no such thing as "not calling in time". In time for what? The news cycle?
I'm not even sure what “failed to complete counting their votes in time for an election to be called for a particular candidate”; are election results perishable such that of a count takes too long it no longer counts? Specific examples of the phenomenon you are discussing would perhaps be useful.
Isn't there a logical fallacy named for nitpicking (concern trolling) while ignoring the whole picture?
My comment was merely in support of that.
- Change - Privatization - Centralization - Digitization
We geeks focus mostly on the voting computers. We need to focus more on stability and the appropriations process.
* 100% mail-in paper ballots, like Oregon -- no long lines, no games about which districts get which machines, no polling place intimidation
* Mandatory random-sample hand recounts (this has been shown to only need to be on the order of thousands of ballots out of millions for most races, given the statistical confidence you get with it)
You wouldn't want your colleagues at Google knowing you voted for Trump now would you...?
Husbands can coerce their wives into registering for a postal ballot and then vote on their behalf. Religious leaders can coerce their followers into registering for a postal ballot and handing it over to a chosen candidate. A corrupt care home worker could register dozens of residents for postal voting, then sell their ballot papers. Migrants with a poor grasp of the English language can be tricked into giving up their ballot paper. Poor people can be offered cash for their ballot paper. Postal ballots can be stolen from postboxes and sorting offices.
All of these frauds have taken place in the UK; local election results have been nullified on more than one occasion due to endemic fraud.
http://www.telegraph.co.uk/news/uknews/law-and-order/1156001...
http://news.bbc.co.uk/1/hi/england/west_midlands/4406575.stm
http://www.bbc.co.uk/news/uk-england-london-32428648
http://news.bbc.co.uk/1/hi/england/berkshire/7302809.stm
https://www.electoralcommission.org.uk/__data/assets/pdf_fil...
It's much easier to prevent that kind of thing rather than repair the damage after the fact, similar to the problems we've seen with gerrymandering.
An option considered in one state (Utah?) was to allow mail-in voting, but the mailed ballot could be invalidated if you stopped into a polling place and voted. It adds some complexity but reduces the absolute chance of coercion.
Only you know who you actually voted for. That's the point.
I'd guess mail-in ballots increase participation at the expense of some coerced ballots. Surely the net outcome is positive. On top of that, it helps to remove the chance for the use of intimidation at the polling stations. I remember that being an issue last election.
Somebody else mentioned that some areas have a system where if you show up in person, your mailed ballot is invalidated. That seems like a good safeguard.
The bottom line for me is that I think the option of mailing ballots increases participation. There may be an increased number in coerced ballots as well, but I think the net result is postitive.
Canceling mailing or e-voting ballots when voting in person can be countered by requiring that the person hand over his ID card for the vote duration.
The idea that a vote might have been bought is a dangerous one. It's dangerous even if votes buying are not proven. I'm still not convinced about e-voting for this reason. There should be absolutely no doubt on the sincerity of a vote.
In most states this is illegal. In, GA, the SOS posted a reminder. (follied by the President's picture)
Long lines or inability to get to the polls on time has contributed to my not voting. Plus it's great to be able to sit with a ballot over the course of a night or two and really think about what you are going to choose. Being at the polls with people waiting behind you applies some pressure to pick the fastest option - ie choose all Democrats or all Republicans (the machine I was on had a shortcut button for that).
Last election I voted in Texas as people voted quickly. It seems like they either are only voting for one or two races or they are just pressing the button that selects all Republican (I live in a red area) candidates.
Except that mail-in ballots mean that some generally significant chunk of the electorate can't react to new news in a dynamic election.
I don't like mail-in ballots. I do think that Election Day should be a holiday.
Returning to paper ballots means less cheddar for cronies. Happily there's a workaround. Postal balloting (close the poll sites)!
Ballots are digitally scanned as they're received at central count. So it has all the downsides of the touchscreens with all new vulnerabilities (undetectable alterations, signature mismatches, preview election counts, voter coercion...). But voters get the comfort of paper and it keeps the cheddar flowing for the cronies.
I traveled my state advocating open source software. I called it "citizen owned software). It's a slum dunk with voters (tax payers). And it's how things used to be.
The gatekeepers (blockers) are the election admins who outsource to their cronies. They even invent make-work just to have more cheddar for their cronies. Like signature verification and ballot tracking.
True, but it is significantly (as in several orders of magnitude) harder to hack paper at a national scale than it is to hack an electronic voting record at a national scale.
Hacking paper requires people physically interacting with that paper to subvert it. That amounts to 1+ person per box of paper votes.
Electronics just needs the one person who discovered and exploited the vulnerability.
And it quickly becomes unmaintenable, "three can keep a secret, if two of them are dead".
Making a conspiracy like that work at US scale would require a small country's worth of conspirators which really, really wouldn't be able to hide from the light of day for very long.
It would take an immense amount of reorganization of trust, but open hardware verifiable (both in person and on some kind of trustless ledger akin to a blockchain) voting systems would be more secure against such national actors, because there would be no back room to burn the paper in. If the machine is public and you can trust it, and you can trace the results nationally to insure the results were accurate, you have more security than you have now.
To hack the U.S 2016 votes you'd only need to flip a few counties in Pennsylvania, Michigan, and Fl.
If you hack election software, you can change thousands or millions of votes as easily as one. The physical nature of paper means you have to work for each ballot.
Even for the paper side. Most paper ballets are counted by machine so they could easily be tampered with at the count or when they're printed having a similar scale.
Do you have a source for that statement? In Germany, ballots are counted by people making tally marks on paper.
Edit: Here you go. I couldn't find research or a study regarding it but this is probably good enough and was always my experience when I voted by paper: https://www.wired.com/2016/11/vote-counts-ballot-get-counted...
And recount-able by hand in case there is doubt.
One reason is that Americans vote a lot more than Swedes. Here in California I have probably ~100 elections to vote in for each I had in Sweden.
Not necessarily. I'm not cryptography expert, but I suspect some kind of proof-of-work system can be used for ballots.
http://www.dailymail.co.uk/news/article-3796116/Putin-s-part...
It's quite common to drop handfuls of paper. And really, the grouping comes down to transportation issues as well; when you move ballots in boxes and trucks, 0(n) becomes less accurate.
There were numerous issues with the security, packing, and handfuls of paper in 2000.
Yet, there are ways to make digital voting auditable. There is an inherent conflict between a system being auditable and anonymous. You can't completely satisfy both, but paper satisfy none, so there is plenty of margin for improvement.
First, you've omitted a major downside of digital vs. paper systems, scalability. Attacks on paper systems are much harder to scale, are more easily detected and more readily audited by staff who need no IT training/experience. There are other downsides, but scalability is a good example.
Second, the "plenty of upsides" are mere niceties. I don't know of any must-haves unique to digital voting systems. What do they offer that is worth their diminished security compared with paper ballots?
I put security of our electoral process at top priority. Given the difference in attack surfaces of digital systems vs. paper ballots, I can't see a case for the former.
The continuing parade of breaches of supposedly super secure systems indicates we don't yet know how to code systems for large-scale public applications where security is absolutely essential. Paper ballots are the best we have for now.
We saw with the Wisconsin recounts that only a couple cities had questionable issues and not enough to change the outcome (this time).
We saw in Michigan and Pennsylvania recounts that something more troubling was going on with Detroit and Philly and the real truth got hidden from public view when the recounts were abruptly ended in those places. I think there was evidence for fraud in certain Detroit precincts, but since that fraud involved Democrats, the media was silent on the issue. It got swept under the rug very fast.
I bet if we look harder we find fraud in Dade County, the state of Nevada, the state of Colorado, and also likely Arizona. Lastly, if we are going to be completely honest, California is allowing illegal immigrants vote in large numbers. Mind you, I'm not anti-Democrat, I'm just anti-fraud.
Verifying ID is a huge step towards ending most of the problems we have. The rest is stopping ballot stuffing and corrupt poll workers tossing out ballots.
In what place in the US can you vote without ID? Where? Point it out to me. You can't.
To vote, you already have an ID. It's called a Voter Registration Card. To get one, you generally have to cough up a bill, lease, etc. originally and then vote continuously over the years.
At this point, relative to "voting fraud" (the only thing "ID" will solve), you have:
1) No evidence of significant voting fraud anywhere (we lose more ballots to mismarking)
2) Significant evidence of partisan disfranchisement
3) Leaders having been caught ON AIR saying that disfranchisement was the whole purpose
Do you need someone to run up, kick you in the nuts, and yell "IT'S ABOUT DISFRANCHISEMENT" 3 inches from your ear before you get the message?
Now, if you want to talk about election fraud where the counting of the ballots is suspicious, we can chat.
"Under non-strict requirements, a voter who does not have the necessary identification may still vote without casting a provisional ballot.[1]"
Sure, it's almost everywhere.
For example, I recently voted in the 2016 presidential election. I voted in San Francisco. I didn't have to provide ID. I was allowed to vote despite claiming not to remember my own address. (Which I didn't, because I hadn't lived there for a few years. Voting continuously is certainly not a requirement.)
The normal procedure is that you go to the polling place, they ask you to point yourself out on their list of registered voters, and then you vote without authenticating your identity in any way.
Is this detailed/concrete enough for you?
I assume we don't want to keep track of who voted for whom (secret ballot).
President Obama was right when he said the fix to problems in our democracy is more voter participation. Imagine if close to 100% of those eligible to vote, registered and voted. Voter fraud would be insignificant.
I really like the systems where there is an original easy to use paper ballot, that gets fed into a scanner for immediate counting with the ballot being stored securely in a box below the machine. It seems that the ballot could also have a scanned image stored for posterity.
At that point all the digital information can be immediately backed-up, replicated, and so on. It seems like it's the best of both worlds...
Paper ballots are a superior technology.
I think it's funny that people are freaking out on HN about this. The hacks at Defcon all took a long time to do, and I believe all required keys to the machines, and all were done on older voting machines. There has been no evidence of people hacking machines during the elections. Stuffing ballot boxes and other forms of voting fraud have been around for a long time, and nothing we do is going to stop it 100%.
Also voting machines generally have paper copies that print off the back of the machine that are anonymized but can be matched if foul play is called into question, at least in my area. Couple that with monitors that stand near machines or walk around and I feel pretty comfortable with electronic voting.
The only plausible hack would be an inside job, but I too find this difficult to believe. It would takes tons and tons of people to hack the machines if it required physical access. You'd have to hack ever machine, and even when you were done there are so many districts it would be nearly impossible to swing the election in any meaningful way.
Some things don't need a technological solution. Pen and paper and thumb dye generally work just fine.
Any school teacher who's collected tests from naughty 10 year olds can imagine all of them. These are the people who volunteer to show up and watch the process, in every district.
It's not enough to have a very low rate of cheating. The legitimacy of the process depends on this fact being clear to everyone. The fewer over-educated specialists you have to trust to be sure of this, the better.
You'd need to put enough ballots in the box to sway the count in your favor, while being watched by multiple people from both "sides" who all don't trust one another.
But let's assume you are able to do that somehow (hey, maybe you paid them all off?). Great! You've swayed the counts in one precinct... In 2012 there were 2712 voting precincts in Virginia... So to sway one state, you'd need most likely thousands of people working together and not one of them can reveal the whole plan. And that will get you one state, so multiply it by 50 to really sway an election (yes, i know you wouldn't need all 50, but ether way it's still way beyond realistic). At that scale it seems like it would be easier to just convince people to vote with you.
And you'd need to do all of that without leaving any kind of paper trail. Paper costs money, printing costs money, it's not going to be cheap or easy to hide making all those ballots. Someone is going to notice. And all it takes is one slip up, and it's all over.
Nobody is saying pencil+paper voting is perfect, just that it's the best thing we have at scale, and it's extremely difficult to "hack" without someone noticing.
Increase by 49 or multiply by 50, no?
Even so, I’m in favor of paper ballots - I think voting machines are nothing more than rent seeking by their manufacturers.
[1] http://www.nytimes.com/1990/02/11/us/how-johnson-won-electio...
With something electronic, at the very best you end up needing the same number of people at the same amount of locations. But this time instead of having to stuff a bunch of ballots into a box without anyone seeing you, you just need time alone with a machine at any point before voting or even during voting. (and I'll honestly admit I don't know which of those is easier, but that's before we get into all the other issues with electronic voting)
I think there is a possibility that electronic voting could be better at some point in the far off future, but in reality and right now, the benefits don't even begin to outweigh the negatives.
90 minutes or less, from unprepared attendees, some of which didn't even know they would be seeing a voting machine that day [1].
> Also voting machines generally have paper copies that print off the back of the machine
This wasn't always the case, and a few bad elections happens from 2004-2006 as a result. There is also not a guarantee the voter has checked/understood the paper receipt. Overall the concept helps quite a bit.
> The only plausible hack would be an inside job
Polling station staffers are volunteers, and there are lots of them. Not particularly difficult.
Voting machines themselves are known to store results in unencrypted, easily editable MS Access databases. This allows editing/suppression of votes en masse with no trail. If said attacker can find a way to also tamper with the paper receipts (print a different result that the voter doesn't notice, or don't print at all, or make the printout unreadable), mass shenanigans could ensue.
All this just to say, "hey, it uses paper for verification on the backend, so it's fine." But we're paying companies to develop insecure machines, training voters to trust them, and bringing the integrity of our democracy into question along the way.
Just fill out a piece of paper. It's not that hard to count the votes.
1. http://fortune.com/2017/07/31/defcon-hackers-us-voting-machi...
Canton of Geneva have open sourced their voting app. https://github.com/republique-et-canton-de-geneve/chvote-1-0
Of course there will never be a perfect way. However, I have a feeling that by multiplying voting methods, fraud impact can be contained. Mail vote increases the number of people voting and have the same positive effect (drowning a fraud in valid results).
I'm not sure what they do if someone has taken a ballot but not put it in the box.
Suppose they do build a hack-proof voting terminal - how can you tell that's what you're voting on, and not a compromised machine with identical appearance? De-cap all the chips and put them under an electron-microscope?
I work in hardware verification and have worked in software verification in the past.
I still wouldn't trust voting machines that I had verified myself. How could I tell my program apart from software that "looked" right?
I can't fathom why anyone who is honest wants to bring electronics into this.
The thought was, that even though a system like this could not be understood by current people, future people would have a reason to learn the technology, as they learned about vehicles and the web, because it shapes every facet of their society, in real time. It would also give us a clear case for legislating software and hardware security standards. Not my area of expertise, but do you think that standards could be devised and mandated to make hardware verification feasible, at least for medium-tech applications?
So, that's how honest people desire technological progress in the voting system. Now, I can see that we need to keep these endeavors low-key, while we cross the gap of failure between "interesting" and "robust". It could take us generations to cross that gap. Let's just keep all this experimental stuff in the digital currency / digital contract field, for now, and tell the dreamers to be patient, rather than insisting that we abandon the whole idea.
Definitely not as Open as Linux, but not closed source either.
But this issue is never as black and white as "open-source is more secure." There are many other factors that go into the security of a product beyond its source code being readable. Deciding which factors matter largely depends upon your unique threat model.
If I trust an organization to put the resources towards properly auditing their software, that's often far more important then whether or not I can personally do an audit. The majority of people and organizations do not have the time or technical skills to properly evaluate software. Whether the software they use is open-source won't ultimately matter.
The "many eyes" argument often falls apart because most of the time there simply aren't that many eyes dedicated to a project. What is the practical difference between Microsoft hiring 100 people to perform security audits and an open-source project that has 100 volunteers? Resources and trust. If you trust the open-source project to dedicate resources to security, and their software fits in your threat model, then use it. Or the inverse, if you don't trust MS and their software doesn't fit: avoid it. The vast majority of the time open-source vs closed-source should not be the main differentiator, but rather a smaller element of an informed decision.
Even in the case of inspecting software, you'd have to guarantee that the systems are secured after inspection and not tampered with. That's an even more difficult problem.
The systems are simply too complex.
It also doesn't need to be "simple enough" for anyone to do it. You just need a system in place to enable voters to verify the authenticity of the machine (a relatively easy way is a public voting ledger where the voter can match the id the machine shows with what shows up in the ledger a minute later) and those with the know-how will do so.
It's disturbing that a major corporation has the lobbying power to back that kind of unsafe position for its own gain, though.
It's not an exact metaphor, I admit, but it's relevant to the fears of OSS - people think leaving all your public information on the table is enough to compromise the system, because in a physical model, it effectively is.
Additionally, if you really wanted to protect voting and still use computers, use an open ballot and also allow voters to audit their own vote.
The public ballot is much easier to secure, since you can just use a trustless ledger. Spinning up a ton of processing power to protect the voting process day-of elections isn't infeasible.
(1) Why doesn't our electoral system require public disclosure of each voter's record? What would the ramifications of publishing each voter's identity & ballot online be? My thinking, like other comments here, is that a transparent voting system would make results more easily verifiable, if not easy to verify.
(2) At what point could we transition toward more of a democracy (in contrast to the representative, republican system) through the use of digital voting, which has a lower "barrier to entry" than turning out to a polling center? Particularly on nationwide issues like healthcare, I presume there are relatively few technological barriers to letting every citizen vote individually on a bill and immense political and social consequences. I can't fathom the outcomes -- do you know of any discussion of such a system?
Non sequitur: I've always wanted to see a "name brand" professional sports team run, down to the minutiae, by online fan voting. I know it's out there in small leagues already.
(2) Probably not in a long time in the US. The system is built under the assumptions that you can't trust voters know what is good for them, let alone what is good for the country overall.
Not allowing people to photograph their ballots, to vote in public, etc. is a protective measure for the voter making it difficult to prove how they voted.
It's a real issue. There are lots of people who have jobs that they use to support their families where they have to deal with organizations that they disagree with politically. Currently they can pay lip service in public, but vote their conscience in private. Making how people voted public record would affect a lot of people. Substantially more than, for example, the number of people who would be inconvenienced by universal voter id laws.
At the same time, perhaps such a system reduces the surface area for bad actors. Now, perhaps, just the registry/database of UUIDs is a primary target.
Retribution.
Think about it, it's easy for an employer to say that he will only employ people who voted for X, a landlord that will only take in tenants that voted for the right party, or even family members that will make sure that everyone votes along party lines.
There's a very good reason why voting is secret.
(2) Tyranny of the majority is a living hell.
1. Electronic machines powered by OSS - Provides fast counting, and potentially better UX in scenarios with large number of items to vote on - Ability for the public to review the code 2. Machines print copy of ballot that voter can verify before being placed in a secure ballot box - Provides auditable backup record 3. Machines give the option to print a second copy of the ballot with a unique code. This code can be used to verify selections later via some kind of online interface. - Gives the user one more check on ballot integrity - Allows voter to keep voting record anonymous if they choose
I think this would balance pros/cons of pure paper vs. electronic voting systems
They're not actually that hard to count, they leave a hard to alter record, they require more effort to fake, etc.
The under investment in voting and the focus on mechanizing it has been a disaster in the US and is teetering on the edge of being incredibly dangerous to the well-being of the country.
Electronic voting has none of the features we want and all the failure modes we don't. Return to entirely paper.
(For what it's worth, my area seems to basically use those test scanning systems on paper mail-in ballots. That's still more electronics than I like involved in the process, but is much better than fully electronic and we might be stuck with that as long as we use mail-in ballots -- which is a separate debate.)
Years ago there was a push for online voting. The state commission came away from that study suggesting a return to paper ballots, recommending to ditch even the new electronic voting machines that were becoming popular, because of the lack of credible, verifiable security. I think paper ballots are effectively required by law, now, with exceptions for accommodating people with disabilities.
I think most places that use these will use an additional count-by-hand pass afterwards. If someone is tampering with these count-only machines it's likely that they will be discovered and prosecuted.
Look at Scantegrity [1]. It provides end to end independent verifiability of elections and lets voters check to see if their vote was counted correctly, without depending on the voting software functioning correctly.
All user get a receipt which they can verify is same during vote counting. They themselves can vote count using all others receipt. At the same time, they can't sell their vote as it's encrypted.
A major point of the polling booth is that nobody can see what you put on you ballot, and you can lie to anyone about it. No family member can pressure you to vote in a certain way, and if somebody offers you money in exchange for your vote you take their money and vote for somebody else. And if your employer threatens to fire anyone who votes for the wrong person, you just tell them you voted for their favorite candidate, they can't tell the difference.
Mail-in voting is nice for people who physically can't visit a voting booth, either due to disability, sickness, or scheduling problems. But it should never become the norm.
Label the online results by voting site. Keep a count at each site of the number of people that voted. Verify this count more or less matches the results posted online.
As for the counts, where I vote my name is recorded in a book and then I cast my ballot. So it should be possible to verify that the book tally and vote tally match.
You can write your identifier down, but you could also go online and look up any other identifier you want and use that one instead. The public ledger results could be timestamped so you can correlate your vote with the on chain results, but given a large enough election thousands of votes should be coming in every <unit of time the ledger uses> and you could pick any one that voted the way your sponsor wanted to claim to be your own.
It is only a problem if results don't come in in real time I think. Trying to photograph the display would be just as much of a problem as taking a picture of your ballot today. The broad point is to convey the UUID in the only untrustable memory store, the human brain.
Unfortunately, this system is neither trustworthy nor correct, as adding new UUIDs to the rolls defeats the system.
A voting system is a security system that has to work in the presence of bad actors.
If you add new UDIDs, you'll throw off those numbers.
P.S. You keep writing "UDID", but you really mean "UUID". The UDID is a specific implementation of unique device identifiers. They have nothing to do with individual people.
i tried to fix two things with my proposal: changing votes and adding votes.
let’s hear some concrete criticisms and suggestions.
i dont feel like the current systems are particularly thoughtfully designed. we could probably do better in this HN thread. :)
If you don't present a design, you won't find anyone to critique it. My suggestion is to design something and then present it.
No. You will need to perform a lot more work at system details, algorithms, interactions, interfaces, components, etc.
Declaring "UUID" isn't really a design. It's not even a workable idea, yet.
Here is one design for a voting system, which had been posted to HN last year. http://www.economist.com/sites/default/files/nyu.pdf
Some of my review of it: https://news.ycombinator.com/item?id=13144302
Your only actual criticism was
> Unfortunately, this system is neither trustworthy nor correct, as adding new UUIDs to the rolls defeats the system.
Which I explained was defended against by having counts at each voting site which could be compared to the online results.
Your (non) response to that was non-specific attacks on the non-planness of my plan as a whole.
Even non-planness attacks should be able to be made specific. You should be able to point to a specific unaccomplishable thing or missing detail... (Perhaps you could complain that I haven’t specified how to collect and save the voting site voter count tallies, which would be fair, but also seems solvable...)
I'm not going to do your work for you. You might find people willing to work with you, but the odds are slim until you have a unique idea or something more than a single sentence. Literally thousands of people have discussed UUIDs, including the two links that I sent to you.
It's a high-level idea, dude. You made one specific critique, which I refuted, and now you're criticizing the idea as uncriticizable because it doesn't have enough of the details specified.
Thanks for playing, I guess.
Spitballing here: What if you get the receipt with UUID and your choices, then at a separate kiosk only in the polling ststion you can enter your UUID to view the full results as posted online. Along with your UUID and results, a hash of the two is displayed and can be printed onto your receipt. Before leaving the station, you must detach and dispose of the plaintext voting choices, but you can hang onto the UUID + hash.
At any time in the future, you can enter your UUID into the site, which will compute and display only the hash, giving you verification of no tampering but not disclosing any results to nefarious third parties.
You did say "a good clean way" though, so perhaps that analogy is inappropriate :)
Maybe it could be explained in terms of one of those "superhero name generators"[0], where the initials used come from your UUID and the superhero name chunks come from your voting choices. Sure, a hash is a lot more mathematically complicated but the principle remains the same (to the point of the possibility of two different UUIDs and voting choices ending up with the same hash, just as anyone having the initials DJT will become The Incredible Golden Tornado).
[0]http://weknowmemes.com/wp-content/uploads/2013/10/superhero-...
Very relevant to this topic: Ken Thompson's "Reflections on Trusting Trust":
https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thomp...
Please observe a real world example of this: https://www.youtube.com/watch?v=8mBMHPxdljE
But those are both more straightforward with paper ballots than with other systems.
You could put them in sequence and compare the results. If results diverge, you investigate why.
1. You go to your local polling place, show the volunteer your ID, and sign a book next to your name. They check your signature, then walk you to a voting machine and unlock it.
2. You go into the voting booth and pull the operating lever to the right. This closes the curtain, increments a counter, and unlocks the vote levers.
3. You make your vote selections on the voting levers. The machine prevents spoiled ballots with a mechanical interlocking: if the ballot says "pick any two", the other vote levers will be locked out once you've selected two of them.
4. Once finished, pull the operating lever to the left. This increments various counters for your votes, clears the voting levers, opens the curtain, and relocks the machine.
At the end of the night, the election volunteers open the back of each machine and read off the values of each counter, then report the results to the election board. There, the numbers are subtracted from the original counter values (the counters are non-resettable) and cross-checked to ensure validity (casting a vote increments both a vote counter and various 'checksum' counters), then aggregated with the other machines to get the final result.
This system has, in my view, most of the advantages of the other two systems: it is very difficult to tamper with (all the voting machines, once configured, are cross-checked and sealed; the seal is on the side of the machine and can be inspected by any voter to detect tampering), anonymous (all votes are aggregated in-machine), and provides fast counting (all of the counter values are entered into a digital system at the end of the night).
Unfortunately, they were banned by the Help America Vote Act, and are sometimes panned as difficult to use. (I never got a chance to use them myself, as New York replaced them shortly before I became eligible to vote, but I got to go into the voting booth with my parents and even as a nine-year-old they didn't seem especially confusing to me.) Also, the machines are complex mechanical beasts, with some 28,000 moving parts, and they're probably becoming increasingly difficult to repair.
Even if mechanical voting machines are a thing of the past, I think it's important to at least look at them to see how they provided for the important aspects of a voting system, and possibly take some of the ideas to be used in current and future systems.