Norway tightens IT security to prevent ballot tampering
reuters.com
reuters.com
Voting is one of the few things that shouldn't be computerized. It's far easier to swing an election by hacking a few voting machines than to forge thousands of ballots.
No matter where you live, do yourself a favor and vote only on paper.
Millions of ballots.
You can go further. Australia has independent electoral commissions which run the elections. Voting is compulsory and preferential. The entire process is overseen by scrutineers -- individuals appointed by candidates -- so there are always multiple mutually-suspicious observers in the room. Many of the most subversible steps in the voting process, for example replacing a ballot box that is full, have to be cross-signed by an electoral official and at least two scrutineers appointed by different candidates.
A hand count is performed three times, again under the supervision of scrutineers.
If there is a arithmetical doubt about the outcome of the election, it can be voided and is re-run from scratch. This has actually happened once when several ballot boxes for the Western Australian senators were lost during a federal election. It was very unlikely, but possible, that those votes could have changed the outcome of the final senate position.
The High Court voided the entire Senate election and it was redone.
Elections must be trustworthy. Cumbersome, people-intensive systems are paradoxically better at this. The odds that a malicious attacker could replace millions of hand-written ballots, subvert hundreds of independent professionals, subvert thousands of independent volunteers, subvert thousands of mutually-hostile scrutineers and also fool thousands of journalists is low.
I would say substantially lower than the odds for being able to subvert a single programmer or sysadmin.
If governments were actually serious about electronic voting, they need dedicated committees and bureaucratic entities whose sole responsibility is the maintenance and security of these systems.
I expect the United State to be absolutely crippled by cyber-warfare in the coming decades. On a state level, our government is simply incapable of recognizing the many vulnerabilities their systems have and compensating for them.
While personally I think electronic voting is a trash idea (couldn't we instead still vote via paper, and then read the results via ML? This would give us a "margin of error" of votes, but we would always have the paper ballots to fall back on), I think that tightening IT security is a good thing for governments to do. Especially considering just how poor computer security is for government entities.
[1]. Just want to mention I'm not a security guru. This is just my interpretation after visiting many government websites, reading stories, etc
You just move the single point of failure to an even more difficult-to-prove location.
- Open the ballot box. - Separate the ballots in packs of 100. - Make tables of 4 volunteers. Each gets a pack. - One person opens the envelop - One person reads the ballot - Two persons tally the score on a sheet - Compare both tallies at the end. If they are not in sync, do over. - Compare the sums to the envelopes in the pack. If it is not 100, do over.
All of these tasks are really easy, so you don't have to be smart of even literate to participate. Also, everybody can check what everybody is doing. The person reading the ballot shows it, so they can't change the name. The person opening the envelope sees the names and you can easily follow the counting too.
If people come as a group to volunteer they are typically spread around several tables.
That way, you have triple check of the count, and actually in the end I think the people responsible for the voting station also compare the voting registers (you sign next to your name after voting) to the tallied total of envelopes and votes. So that would be quadrupled checked in the end.
We typically get official results the evening of the day the voting stations closed.
To this day I don't see any practical reason to switch to electronic voting unless someone wants to fraud.
The problem is this: we don't have any machine that simplifies vote counting while being as trustworthy as having many people count marks on many sheets of paper. And since that is prone to errors and manipulation as well, so the bar is actually much lower than "perfection".
Can we really not do trustworthy vote counting better than humans? Can we not make a computer that defeats a human at reliable counting? If we cannot do that, we should reconsider our craft and wonder why. I am not enough of a computer scientist to come up with a good verification plan, but I'd be very surprised if we couldn't do it.
Gullible or corrupt government officials, sneaky sales people and shady politicians are a very different problem. Our job should be to make the machine so good and reliable that these people are driven out of the game.
When the votes are counted by a group of humans, one person making a mistake (maliciously or not) isn't a big deal because nobody expects humans to be perfect. There are checks in place to catch those mistakes. It would take a huge conspiracy to compromise the entire system.
I suppose there could be a solution in the future, maybe with blockchains or something. Until then, manual counting is the best option.
Except there's no problem. Hand counts work fine.
Impatience is not a reason to substantially weaken the foundations of democratic legitimacy.
(sidenote: direct democracies aren't always pleasant..)
All digital makes me nervous.
Ballots are deniably secret to prevent vote buying and menacing for votes.
https://www.nrk.no/norge/teller-opp-stemmer-i-valget-pa-data...
Like are we gonna read about the U.S. power grid being shut down, or an entire state / nation wide election tampering?
It's absolutely terrifying how incompetent these folks are. Why is there no one marketing their skills to governments who have actual skills? Why aren't governments hiring employees with actual skills?
We used to have the most talented structural, mechanical, and industrial engineers in government positions or as government contractors. Is tech simply too young for that to have happened yet? Or are governments failing to adequately respond to their massive skills' gaps?
I heard rumors of people thinking there could have been problems, but nothing more than rumor came of it.
https://twitter.com/pati_gallardo/ (most links are in Norwegian, but Google translate does a reasonable job).
Was a big deal earlier this week that the keys and stuff for some municipalities were posted online on their web pages. Edit: it was certificates you had to install in the browser to verify that you were in the position to enter the total amount of votes in your municipality. The url for download were unique and random, but got indexed by search engines because they spy on urls you visit.
https://www.nrk.no/norge/sensitive-valg-filer-for-tre-kommun...
Edit, hmm, downvoted?
Yes, rather than "recounting" votes on the same/similar machine - you now need a large conspiracy for large scale election fraud, rather than a single software exploit...
Microsoft taking a page from Google, how quaint.
Yes. So if you instead of attachments of large files in email send an URL such as https://acme.pri/?id=cafe-babe-deadbeeff00d, which is not secured by any other method than obscurity, then Edge will submit it to Bing, which indexes it and then the content is available if you can come up with some keywords that match.
It is fairly well known in Norway, due to having been in the national news earlier this spring, but I have no reason to think it doesn't apply universally.
If you remember the invisible dots that printers add, so the government can track where something was printed. ( https://news.ycombinator.com/item?id=14501894 )
I wonder if some government did/are/could use this technologies to deanonymize voters.
For example they would print your SSN on the piece of paper that you are voting on.
But If I remember well, I had to actually vote at a specific place.
The part I don't remember well is if they were giving me a specific sheet of paper, or just take one on the top of a stack.
I remember they were looking for my name, and I have a souvenir that they detached the side of the sheet (but this is vague).
I guess it was a stack :)
I might be wrong, but I don't think paper ballots have any identifying information on.
Edit: Hmm, ballot papers do apparently have a unique ID on, which I hadn't noticed before.
You receive an election card (valgkort) in the mail to bring to the polling station containing all your info. ID is also required.
If you forget this card, they can print it out for you.
Then you enter the booth containing party lists. You can't "punch" the wrong party as each have their own ballot. You can erase/add/reprioritize names on the party list you choose though.
Then you put this ballot into an anonymous envelope. This envelope is then put into another envelope along with your election card.
When they count it, they pull out the ballot envelope and the election card, register that you have voted, then someone else will open and count the actual vote.
It seems to me to be pretty secure and anonymous.