In Georgia, a legal battle over electronic vs. paper voting
washingtonpost.com
washingtonpost.com
The votes can be tallied instantaneously through the electronic system, but if there's any irregularities the lockboxes can be opened and manually counted as verification. And you can open a small number of randomly selected lockboxes every election anyway, even absent any suspected wrongdoing, just as a check to verify that the electronic counts are working as expected.
How is this not the standard everywhere? Yes, there's more paper (and thus expense) involved, but surely having a non-hackable paper trail is worth it to protect our democracy?
I was at DEF CON the first time they did the voting machine hacking. Those did not fill me with confidence.
If there is anything wrong found in that first series of audits, then a full audit should be requiered by law and there should be severe prison punishments for those state officials failing to start and finish those audits in the specified time after the election.
Corrupt state officials should not be able to create any sort of delays or use them as an excuse.
If there are any differences in the count then additional locations are required to also do a manual count, and if more than two locations have differences, all electronic numbers are trashed and the whole election is counted manually.
The key to all of this is involving as much of the public as possible though: democracy is government by the people for the people, the people need to be involved in its operation. The only way you dispel the idea of rigging is by ensuring a large plurality of your population was involved each time and would attest to their neighbors that they saw no misbehavior.
Electronic voting is based on trying to take people out of the process - it misses the point.
The inclusivity of paper voting is amazing. It doesn't matter if you are young or old, black or white, highly educated or illiterate, rich or poor, just about everyone can count ballots.
And if you think someone is trying to fuck you over, you too can go count along or watch that ballot box all day to ensure nobody is tampering with it.
Get a few hundred people in the same room that all don't trust one another and all count along. That's how you run an election.
Don't let something that feels wrong steer you away from much more severe and likely problems.
But by introducing voter ID systems you are very likely to skew elections away from the people least likely to possess accepted ID, i.e. the lowest socio-economic groups.
But how do you know. That's the issue. If P is the probability of getting caught, and C is the number of people caught then N ~= C/P. With our current system it seems like P is close to 0 so even with C = 0 there could be a lot of successful attempts.
Rigging a polling place is not viable because it would require coordination between multiple people and leave a clear mathematical trail after. So I would say that, including detection after the fact, that P > 0.5 and that the fact that it hasn't been caught means that N = 0.
> But by introducing voter ID systems you are very likely to skew elections away from the people least likely to possess accepted ID, i.e. the lowest socio-economic groups.
This is pretty much separate from my point but I am also skeptical about this. If someone can get to the polling place, stand in a line, and do paperwork to vote, then why could they not do pretty much the same thing to get an ID?
My polling place is two blocks from my house. I can walk there, vote, and be home in 20 minutes. Last time I had to renew my license, it was a three hour ordeal that cost me money and an afternoon of work, and the nearest station is miles from my house (in a dense city).
This argument is sounds great but doesn't match reality
https://i.redditmedia.com/NITi8srtcW0xIfOQXPZda6zJNrpb_jRbwg...
Edit: Link to the paper: http://www.pnas.org/content/pnas/early/2012/09/20/1210722109...
Consider the Minnesota example. In MN, all physical ballot handling, whether marked or unmarked, sealed or unsealed, must be done in the presence of members of at least two different political parties. Since the only ways to rig an election at the polling place are to either add, remove, or substitute ballots, this makes such fraud extremely difficult to do, especially at scale.
As I've said, about 1.5M people vote in Minnesota alone. Altering the outcome by 1% would require 15,000 additional votes. And this would need to be completely one-sided, so the "anyone can do it" threat you bring up should cluster around the mean - about the same number of "extra" votes are cast for each side.
Don't get caught up in scope issues. The problem we are trying to solve here is the legitimacy of elections. Does a little noise around the edges actually undermine the legitimacy of the outcome? Can it do so?
Also, remember there ain't no such thing as a free lunch. Any mechanism that detects multiple votes by the same individual will produce a number of false positives - thus denying people who are not cheating of their vote. This is actually the pernicious, immoral logic of Voter ID laws in the US. They're marketed as ways to prevent fraud, but the actual intent is to reduce turnout in certain (mostly poor) communities. This is why support for these laws is so deeply partisan - one party is pushing for them, and one is fighting them, and the party pushing for them isn't actually that interested in fraud. Their political interest is partisan advantage, and their mechanism is misleading citizens about their intent, so people will tolerate what should be intolerable.
A system that ties each registered voter to a unique ID which is basically implemented for you if you require ID at the polls will have a false positive rate of ~0 much lower than our current system. This is actually a side benefit.
The other great thing not mentioned here is that elections are run by the AEC, a non-partisan commission.
They are also in charge of redistricting.
So you don’t have gerrymandering and you don’t have BS going on like what happened in Georgia where they “accidentally” wiped all the data 3 times when subpoenaed by the FBI.
Add to that compulsory voting, elections always run on weekends, and a thousand other small things and it’s like one country wants you to vote and the other does not.
And you'll probably have to ask someone who's not in the room about what went wrong. With human hand-counts, the person you need to ask is already sitting there. No mystery, no confusion.
Some places already do partial recounts. It is expensive. Most jurisdictions don't have the budget.
It's not a perfect idea, but I like the upsides more than the downsides.
That said, there are some really interesting non-interactive zero-knowledge proofs for elections that accomplish what you're intending without this flaw. Their main downside is that, compared to tallying, they're complicated.
Largely because election officials are also not computer security experts (or even serious amateurs). Therefore when "big corp" comes knocking with their newfangled electronic touch screen voting system that promises fast, effortless tallies and "security" (it's, right there, the box is checked on the ad brochure...) the election officials have no background with which to be skeptical of "big corp"'s products re. security. And with the promise of "effortless, instant, tallies" (vs. a long overnight counting paper manually) they see the newfangled thing as an improvement over that which they do understand (the long overnight counting paper).
This is IT. When have the technical experts been empowered to make purchasing decisions?
If you are buying IT and you aren’t sure about some spec, security apparatus or venerability, then you can’t be considered knowledgeable.
No one can be expected to know everything but then they should be surrounding themselves with experts and counseling with them ad nauseam
Something you don't mention but is another nice bit is they have poll observers from each major party watching at each elction site.
One thing they don't have but I wish for is that, after the machine-count totals are in, each party represented should be able to name a small number of precincts for an audit/hand recount. Parties at this point have pretty good modelling of expected results at a precinct level. That would give a cheap way to get lots of certainty against tampering of the machine vote counting.
Also, how are you going to scan all these ballots after voting has closed? That would require opening up the lockbox, which tampers with the security of the system. Plus, you're no longer getting results instantly; you'd have to wait until the polling place is closed down, and then open up the box and scan all the ballots. What possible advantage does this have? It'd just slow everything down.
Oh yes, it would be awfully hard to make this switch in a matter of weeks. But this time crisis was created by negligence, since it's now been 2 years since officials were made aware of the problem.
> The unsecured server that Lamb exposed in August 2016 is part of an election system — the only one in the country that is centrally run and relies upon computerized touch-screen machines for its voters — that is now at the heart of a legal and political battle with national security implications. > > “I was absolutely stunned,” Lamb said of his discovery of the exposed data. And he was angered when six months later, despite warning officials at Kennesaw State University’s Center for Election Systems (CES), which housed the server, the data was still publicly accessible online.
Whoops, there aren’t enough paper ballots in some precincts? I wonder which ones. Boy, we were forced to do this in such a rush I guess we made some mistakes.
Anyone know what "ballot proofs" refers to? I hope that's not just a fancy terminology for a tab-delimited text file that contains the voting totals. I wonder what "Dropbox-like" site actually refers to -- a cloud site created in-house by the state government? Or by a contractor that ostensibly specializes and is authorized (i.e. fills out the paperwork and background checks) to sell a file-transfer app that's basically a wrapper around a commercial cloud service?
But even if these details about ballot proofs isn't relevant to the main point, Mr. Barnes's testimony is still concerning. He's the director of the state's centralized elections system, after all. Last year, when Lamb notified the state of the data breach, Barnes "wrote of blacklisting Lamb from accessing the website before changing his mind and ordering scans of the system". [0] That the vulnerability stemmed from Drupalmageddon is even more troubling, because it's not as if Lamb's claims were hard to verify, given how well-publicized Drupalmageddon had been at that point.
It's also worth noting that I haven't seen any read about how the elections center receives the actual vote data. The stories I've read so far -- including this WaPo article -- have only referenced voter registration data. Having this data breached via arbitrary code execution is still a big deal, if the site is used to verify voter eligibility, but AFAIK, it's (hopefully) not the same system and database that holds vote data.
(Voter registration data contains personal info, but some states actually publish it online. in machine-readable format even)
[0] https://www.mcclatchydc.com/news/politics-government/article...
If his desktop becomes infected with a virus of some kind, isn't it straightforward for that virus to infect the thumb drive and then to infect this server that builds the ballots? My understanding is that most "air gapped" machines lack USB ports or have those ports plugged so as to discourage their use.
In terms of what they should be using to transfer data, that is outside of my wheelhouse. But the current system seems ripe for exploitation by a third party dedicated to gaining access to this machine that builds the ballots.
Maybe not "straightforward", but, yes, absolutely, that would be a very likely vector. As I understand it, this is how the Stuxnet worm was designed (the one that sabotaged the Iranian centrifuges).
In short, as long as the ballot could be reliably corrupted only by the locals who'd been bribed the device manufacturer in the first place, the corruption was stable. But now there's an outside player.
Electronic voting is bad, and Ireland gave up on it, but it's not the only issue in election integrity. See also: gerrymandering/redistricting, voter roll purges, etc.
ON-SITE OBSERVERS.
If any person wants to check the vote they should be able to stand there and watch the whole thing and then demand a manual count on-site immediately afterwards. No bringing ballots somewhere else to be counted.
Democracy is how we stop violence from deciding resource allocation. It will be undermined if it is at all possible.
Also, I really hate how electronic voting machines instant tally elections. We had that here in Ontario[0] and completely aside from my security concerns over e-voting, having the night end in a single minute ruined the normally fun nail biting as the results came in on CBC.
[0] Which, by the way, did not allow me to be an on-site observer. Do I distrust Elections Ontario staff? No, but I shouldn't have to trust people. This is a fucking election. I ran the last federal one as a DRO. All paper ballots are 100% secure. The fucking e-voting lobby is evil.
I understand the sentiment, but I dont think entertainment should be any kind of factor in this decision.
> I shouldn't have to trust people.
Verification systems are great (I fully endorse the electronic-for-convenience-backed-by-paper system), but ALL systems require that you trust people. The key is to have sufficient verification, both instant and later, to make fraud difficult, detectable, and provable.
Please sign up to be a poll worker. Then you'll see first hand how it works.
I was going to say that I can't sign up as a poll-worker because I'm in a mail-in-ballot state, but it appears I'm wrong. I'll look into that - it's definitely an accessible (for me) form of civic service. Thanks for the suggestion!
Basically even the extremely conspiratorial can trust the election if there are observers that can be there from start to finish. Saying "just trust our government's employees" is not a real solution.
Note that the above poster was talking about Ontario. Canada has a different relationship with election results. It is illegal for Canadian results, including entrance/exit polls, to be announced prior to closing. In the US this would be seen as a radical freedom of speech issue. In Canada it is normal. In the US it is normal for people to see initial results and perhaps rush in to vote, or stay home if their candidate is leading. US politicians also regularly concede defeat based on preliminary results. So someone fiddling with the display of preliminary electronic results can, in the US, directly impact the final tally.
That isn't a thing in Canada. We don't expect to know anything until after polls close. So we have no need of "instant" tallies. Counting happens during the day but results are not published. Electronic voting might speed it up a little bit, but never would we get close to the instant feedback possible in the US.
Is it? I was under the impression that most everyone had adopted a voluntary policy of not reporting exit polls prior to closing, at least since 1980, so that's just shy of 40 years of not doing as you describe. I've certainly been ignorant of results until polls close. I recall estimations of "turnout by party" and "what issues motivated you" prior to closing, but not how people ended up voting.
> It certainly doesn't have anything to do with entertainment.
How do you think the OP meant about the "normally fun nail biting" experience that is electronic voting "ruined" by ending "in a single minute"?
What do you mean by this? It seems to be a claim that election fraud wasn't possible before the development of electronic voting?
Of course election fraud is possible in any system, but it is really easy to make it practically impossible in a paper system by simply allowing observers at any stage of the process. The system is so simple that anyone can detect wrongdoing. That is of course not true with all-electronic voting.
Further, each precinct has to be tabulated separately. The poll site I ran for years had 5 precincts, roughly average. We'd have 400-800 ballots per election, depending.
One change that would make manual counting more feasible would be to split our ballots into federal, state, local.
Every election administrator I've ever met opposed manual counting. Mostly because it's a lot of work.
A group of intended to run experiments to determine the effort, cost, accuracy of manual counts. Simulate a real election, eg print up marked ballots where the totals are predetermined but not known to the counters. Alas, we never got our act together before every one burned out.
PS- Any tabulation method has to accommodate marking errors, aka adjudicating voter intent.
While I almost never vote for a winner, since I'm an outside middle-ground voice in this extremely conservative state (on the whole), I at least want the confidence that my vote wasn't tampered with. Right now, I have no such confidence. Yet I will still vote because it is my right and not voting is not the answer to this problem.
I never voted in the US, but the system seems overly complex for such a simple exercice. Here in Canada, we have a paper ballot (http://www.elections.ca/vot/yth/stu/gui/images/dxsmp1-e.jpg), which is pretty simple. The vote is done, the stub is tallied and 2 people need to verify the vote before dropping it in a sealed box. When the polls close, the votes are counted, by multiple persons, by hand. Nothing electronic.
... and there is a single vote at a time, no votes on laws when electing representative, etc. That is just non sense.
I believe that a well designed paper ballot system is superior to any paper-free system. Furthermore, I think the concerns of the general public about what is actually problematic in elections (and what solutions can work) are generally wrong. I'm basing this on my experience as an election judge in Minnesota. I'll describe the system, and you can decide for yourself.
Minnesota uses paper ballots read by Scantron machines - the sort of bubble-marked sheets you used for tests as a kid. We have same-day registration and provisional ballots available for unregistered or incorrectly registered voters. We do not require ID for ordinary registered voters. There have been two statewide recounts in recent years - the 2010 governor's race, and the national-profile 2008 Franken/Coleman Senate race recount.
Now, the process. First and foremost, all activities that require handling ballots, whether marked or unmarked, sealed or open, must be done in the presence of representatives of at least two political parties. It is flatly illegal for one party to handle ballots alone. This prevents all sorts of fraud - either adding fraudulent ballots, or removing marked ballots.
Second, a simple paper tally is kept of the number of ballots cast in each precinct. At count time, the number of votes counted by the machines must exactly match the number of ballots given to voters. A mismatch triggers a hand recount of the precinct and a bunch of other validation bureaucracy. This checksum also prevents the addition/subtraction of ballots at the precinct level.
Voter machine tallies are spot-checked by hand counts of individual machines - not enough to slow down the process, but enough to insure that there was no large-scale alteration of machine behavior.
Registered voters are on paper rolls. When a registered voter arrives, their name is marked off the list and they are given their ballot. If someone tries to vote twice as the same person, it's caught (and triggers bureaucracy). Their ID is not checked. Same-day registration requires ID and proof of precinct residency; the valid documents are well specified (utility bills, etc).
Political parties are invited to have poll monitors at any and all precincts, to keep an eye on the process. The poll watchers do not touch ballots or participate in the count, but are welcome to observe. They can also challenge individual voters, which makes ballots provisional and may lead to ID requirements. (I remember in 2004, the Democratic poll monitor was convinced the Republican monitor would challenge every single brown-skinned person in the precinct, and the Republican was convinced the Democrats would bring busloads of fake voters in from Wisconsin or something. Needless to say, both were wrong.)
The result of all of this is that highly accurate informal counts are available on election night, thanks to machine voting, but manual recounts are always available, thanks to the paper. And the integrity of paper ballots is strongly protected by process.
The only even arguable gap is the idea of fraudulent voting by using other people's registrations, or fake registrations. But actually doing this at a scale large enough to matter is difficult and risky. Minnesota presidential elections draw about 1.5M voters. To alter the results by 1% would require 15,000 fraudulent votes. If someone could vote once an hour, they could maybe vote 15 times. You'd need a thousand people, with training, transportation, and written data. It's hard to keep conspiracy at that scale secret.
So yeah. This is trustworthy. And it's simple. It doesn't require exotic technology. It's mostly just good bureaucracy.
I'm sure the Great State of Minnesota would be happy to host representatives from other states, offer them our laws and process documentation as a model, and advise them in joining the world of effective and trustworthy democracy.
https://medium.com/@jennycohn1/georgia-6-and-the-voting-mach...
Kathy Rogers was GA election director, now has a golden parachute at the company who manufactures electronic voting machines for GA. She came to my attention for writing a menacing-but-technically-incompetent letter to DEFCON vote hacking village attendees.
Skeptical because only published on medium, but seems like Cohn might be onto something.
Considering that the US is a federation, would it not make sense for the federal government to run local elections as a service?
This is on the back of another idea that has been floated around for elections in regions where "free and fair" is an aspirational goal. I stead of an international body certifying elections, it might be better to have a 3rd party run the elections, and make all the implementation decisions.
..just to keep a separation of powers between election system and candidates running within that system. Similarly, as referendums are increasingly important in many European locales... we need a more nonpolitical body empowered to finalize the wording. A president perhaps, for "westminster-like" systems.
> fed·er·a·tion
> a group of states with a central government but independence in internal affairs.
Your conclusion from "Federation" seems off; importantly, this upcoming election is solely for internal affairs (Governor, SOS).
Beyond that, it's important to note that each state can have their own way to assign electoral votes for presidential elections, some are winner take all, a few split on percentages.
I'm also not sure I see the advantage to centralizing this. It's a case of "many hands make light work". There's a lot to do to conduct an election. Breaking the task among lots of basically autonomous units, made up of local individuals instead of some faceless Washington bureaucrats (see, there's that latent suspicion ;) gives some resilience -- and helps voters feel connected to the process.
Also worth noting that although the structures of the various intra-state governments are broadly similar, there's plenty of differences that would be a pain in the neck for a federal administration.
- Paper ballots and Risk limiting audits do not actually constitute a perfect solution to this problem. They do not constitute what is considered an End to End verifiable voting system. You cannot actually definitively know that your vote was counted in the final tally, and cast as intended. The Risk limiting audits as currently structured can only verify that a computer counted a small sample size of votes as a human would. It cannot confirm all the votes were counted, or that your vote was not tampered with.
- Paper ballots also do not address the needs of folks voting over seas, or those affected with disabilities.
- When current election systems are often described as easy to hack, the systems referenced are often hardware that is 10-20 years old. If you look at the landscape of the Election's industry, there are only 3 vendors that account for over 90% of the public election market share in America. These system's were put through certification many years ago, and continue to operate through those certifications. The result of an inability to innovate in this space, is that we will continue to use those systems (that many perceive as vulnerable) for the foreseeable future.
- Smaller election vendors are encouraging the idea of recurring certification, as well as more stringent certification requirements.
Most people who use these forums are very capable of understanding concepts like Asymmetric encryption, checksums, and other tamper proof methodologies for high value data. If you can trust the idea of an Encrypted e-mail server ( e.g. Lavabit ), or encrypted chat servers (Signal), it should not be hard to imagine that there is a secure way to conduct elections electronically and through the internet.
Finally, given how the past few decades have progressed, it seems that you would be on the wrong side of history to say that electronic voting cannot be done safely in a digital form. The process needs to be secure, but it also needs to be convenient, safe, fast, and trustworthy. Observing a few votes being cast in your polling station is nothing compared to observing every vote being cast for a given election.
It's hard to imagine because it's completely impossible. In most of the world not being able to prove you voted for someone in particular is considered a key characteristic of the vote. No internet based voting guarantees this.
> Finally, given how the past few decades have progressed, it seems that you would be on the wrong side of history to say that electronic voting cannot be done safely in a digital form. The process needs to be secure, but it also needs to be convenient, safe, fast, and trustworthy. Observing a few votes being cast in your polling station is nothing compared to observing every vote being cast for a given election.
Throwing around claims of wrong side of history would be just an insult it wasn't so dangerous. Paper voting is not secure because you "observe some votes being cast in your polling station". It's secure because each polling station is staffed by political adversaries that do the count together of every single ballot. This is much better than the level of systematic verification than you can ever even attempt to do to your huge stack of software and hardware. It's also a kind of verification that everyone understands and so it effectively convinces the losing candidates they actually lost. Which is as much of an important characteristic of a voting system as getting good counts.
So get off your high horse. Apparently you design these systems and don't understand the actual safety characteristics of the paper count. The kinds of attack surface electronic systems add is huge and yet they provide no actual advantages to properly run elections. The thread is already full of examples so I won't add more but it's telling that in most of the world this isn't an issue at all because we just run our simple, cheap, reliable and fast process like we've always done and forget about it.
You'd push a location on the screen, but due to normal wear the location that the press was recorded was wrong, this would get worse the more wear the screen had and the longer between re-calibration.
Eventually people got videos of you'd push one candidate and another candidate to the left or right/up or down would receive the vote, often in different races.
This was a scandal in the sense that the machines were not fit for purpose, overly cheap, and poorly maintained/serviced. But it wasn't a good example of election tampering (just one that fit what a lot of people expected to see when tampering was occuring).
There. Done.
Edit: changed wording, receipt vs record.
Whatever counting method you are using and whatever reporting method you are using, it needs to be verifiable. I still can't believe we had ballots from 2016 that were destroyed after brin subpoenaed, without any consequence for those who had charge of their possession and safety.
This may not make sense intuitively, but counting paper scales quite well by being distributed to the polling locations and physically sorting the paper ballots. The Australian Electoral Commission documents the counting process quite thoroughly [0].
The only time counting paper takes a long time to get a win/lose result is when results are close enough that every vote needs to be counted. This is surprisingly rare in practice.
I mean, the 2000 US presidential election had a recount... that was cancelled. The Brexit referendum had a bunch of spending irregularities... but the result stands. The 2016 US presidential election had allegations of Russian interference... but the result stands.
It's pointless having an early electronic result and a late paper result if the early result always stands - the late paper result gives you nothing except a false sense of security.
In none of those cases was there proof that actual vote counts were altered.
There are still ongoing investigations into Russia's interference, but the side that the interference helped is the on that's currently in power, and there's enough ambiguity for them to avoid taking any direct action. If we'd had a paper ballots that proved that Russia hacked voting machines and actually changed 100k or so votes--I'm 100% confident we'd have had a completely different outcome.
In none of those cases was there proof
that actual vote counts were altered.
I was thinking more of the recounts that were cancelled. If you can't recount to check if vote counts were altered without first having proof that vote counts were altered, what's the point?More broadly, I hoped to illustrate the fact winners oppose fishing expeditions to double-check election integrity.
I simply don't believe we have the option of getting the result wrong on the first announcement. It has to be right the first time. And because it has to be right first time, we should apply our most trusted counting method the first time; the addition of an early-but-untrustworthy count is a move in the wrong direction.
But you can. Many states already have automatic recount laws when vote totals are close. In many cases candidates can pay for recounts even if they aren't close.
Recounts are common in American politics, and sometimes they even change the result--Al Franken won in 2008 after a recount flipped the result.
The Florida recount would most certainly have been finished if any of the counties had found obvious cases of voting machine hacking. Every country completed at least 1 recount, and most completed manual recounts.
Even with paper ballots (or a vvpt), you still need regular procedures to audit the record to ensure that the counting and down-stream handling of the counts are correct.
You can automatically verify some random percentage of them and do a full recount if needed.
The ambiguities we had in the 2000 election in Florida were from people improperly marking their ballots (hanging chads, etc.). If the paper ballots are generated by machines, or at least have already been verified as being readable by a machine at the time the ballot was cast, then you will have a much lower margin of error during the manual recount.
There. No.
Voters strictly can't take a record of their receipt; this opens up a whole other level of voter intimidation, where, if you voted for the wrong person you lose your job, lose benefits, get beat up, get killed.
Ideally, assuming you would be voting with a key linked to your identity (SIN), both the IDs of voters and their votes could be entirely public and on your receipt.
The act of counting votes would be for a set of parties to be work with only the public list and given the private key(s) to generate results. The trust there should be similar to counting paper ballots, especially if independent parties combine subsets and arrive at the same result.
> Ideally, assuming you would be voting with a key linked to your identity (SIN), both the IDs of voters and their votes could be entirely public and on your receipt.
What piece of your identity does your employer not have access to? In the U.S. they've typically seen your id, your passport, your pay stubs, your health insurance.
The "receipt" was a perforated piece of paper with a barcode. The votes were cast by connecting lines, and the right half of that line crossed the perforation lines, and was mine to keep. This seemed like a reasonable system, and I could then verify that my vote was counted.
As for voter intimidation, if we really believe that our democracy is worth killing and dying for in foreign wars, then it would logically follow that we must accept the risk of demanding accountability domestically.
If you put them all into a black box machine (or set of machines) that spits out a total at the end, you've recreated all the same issues.
The debate is more than just paper vs. digital. Georgia is interesting not just because it has gone completely paperless (4 other states have done so), but because it is also the only state in which the system is centralized. Delaware, one of the other states to have gone paperless, have systems too old to connect to the Internet: https://www.delawareonline.com/story/news/politics/2018/08/1...
This seeming simplicity, combined with the fact that no one thus far has seemingly gotten it right, lends itself strongly towards all kinds of armchair opinions from anyone at all related to any of the fields involved.
I'm a software engineer, for example. "Design and build me a system that collects votes and produces results." is in the format of the requests I get at my job on a daily/weekly/monthly basis, so I can take it and run with it, as I am trained to do. I can come up with all kinds of additional requirements in my head, tons of edge cases, different scenarios I need to watch out for, etc etc. Basically, as can anyone who does my job, I can turn it from a (immensely vague in this case) business need into a set of technical requirements.
However, I am wholly unqualified to design a ballot device, despite the seeming simplicity of the request, and how it seems to fit nicely into my professional intake. Will that stop me or anyone else in my position from offering an opinion? Probably not!
Thus, you get the constant "re"hashing of "old" arguments, because people see these problems as "simpler" than they actually are, and "re"voice the same ideas and concepts, because it seems like some obvious problems can be solved with "just a little" modification to the existing systems.