Seals Used to Protect Voting Machines Can Be Opened With a Shim from a Soda Can
motherboard.vice.com
motherboard.vice.com
So practically (ethically) speaking, why don’t we see physical ballot collection as equally risky? Is there a good solution?
I can't speak to the US system, but here in New Zealand every political party is entitled to appoint scrutineers to each polling place. They cannot speak or interact with anyone but they watch the whole process from checking voter entitlement, through transporting the ballots and then counting.
The idea is each party distrusts the others so won't let them get away with rigging the ballot. Mutual distrust produces a trustworthy outcome.
As long as attacks don't scale it seems safe to assume corruption will be localised and the integrity of the system will hold. The risk is that IT is used to centralise democracy to bring down costs, then becomes compromised in an unrelated attack.
This has changed in modern times, as a number of parties disappeared after electoral reforms; and the risk of tampering and shenanigans has increased substantially.
(In this state, observers and challengers are different, with challengers specifically serving the purpose of challenging individuals that may not actually be qualified to vote. Since the pollbooks are electronic today challengers are rarely seen, they were generally only able to challenge clerical errors that are no longer seen with computer pollbooks)
If someone wants to screw with physical votes, they have to access the boxes which hold them. Easily detectable.
Electronic ... you can have the software changed to modify votes and few would be the wiser - even have the changes hide themselves if you are smart.
In physical, it isn't enough to protect where the votes are done. They have to be transported back and ultimately counted somewhere. At any point in that process, they are vulnerable. No?
With a computer, you flip a bit and there's no record. Votes are miscounted? Tough, those numbers are a real as any other numbers. And how much time does it take to swap a vote? Less than a microsecond?
That’s a turn of phrase I didn’t expect on HN.
Do we work in a field where programs don’t have logs, gateways don’t exist, checksums and securing data integrity is not a thing ?
The closest parallel we have is DRM, and the track record there is.. less than stellar.
Personaly I don't think I do, yet even at my personal level I have anecdotes of ink just fading out of paper, or countless of widespread voting frauds from decades ago.
I have the feeling we are putting paper and physical media handling to a higher standard because we don't know as much about it.
It takes a concerted effort to change paper ballots.
For instance some paper elections in Africa have crazy high voter prticipation when not so many people showed up.
That’s an extreme and we could point the finger at blatant corruption. We’re not at these extremes, but where are we on the spectrum?
For instance we don’t have any clear idea of how much corruption we have, to the point that “perceived corruption” is the best approximation.
What I’m going at is, to evaluate how much trust we put in an electronic voting system, we’d need better views at the current system than “paper is better because it’s physical” (that’s not your argument, I take a less nuanced position as example)
Yes, that's the field of voting machine construction - it's lowest-bidder garbage built by and sold to people with no concept of reliability.
No, they don't. At least in my country they are counted in place.
All the observers sit next to the ballot for the whole process, and when the voting ends, the box is opened and the votes are counted. The observers being several people appointed at random (like a jury) to check vote credentials and count the votes at the end + appointed representatives from each party present.
Everything is recorded on paper, the votes are stamped and kept, and the tally is then reported for that voting district.
Even if the people appointed at random wanted to tamper, they'd have to work all together + get the party representatives to agree with it, because it all happens in the open, ("reading vote #N, says party X, do we agree it says party X? (shows the vote around) registering vote #N for party X (people look as the vote is recorded, two people sign next to the vote's registration)).
Usually after the ballots are closed (election ends), it takes 5-10 hours for those people to count all the votes for a district. Then the number is announced. All country districts are announced publicly, so any individual party representative or "jury" member of any district can challenge if the numbers announced (and used for the final country-wide tally) are not accurate.
They are not allowed to leave the room, and there's also a policeman present outside.
I'm not claiming they are impossible to harden. Just not as easy as people are claiming. And super expensive. Such that if you were truly intent to defrauds place, you would focus on poor sections first.
And our best method of defense is probably our extensive polling tests nowadays. The more we have, the more corroborating evidence we have to an outcome. This protects both forms of counting.
Which proves that "votes have to be transported to be counted" is not some inevitable byproduct of the paper-voting process as the parent made it sound like.
Perhaps Chicago could adopt counting in place?
It's mind-boggling we don't do that already -- most voting districts would need only a few random ballots, and you can gradually increase your sample size and check again before needing to trigger a full recount.
Edit: should read articles before commenting..
Not really an easy attack but still a possible one, and these machines have not established a strong reputation for protection against something like a firmware implant
This state uses and retains paper ballots, so it would be yet more difficult to design an attack that would withstand an audit of the paper ballots. But some states don't...
An electronic voting machine could be tampered with well ahead of voting day. Verification hashes and the like are only aggregates that are open to trickery on the way to the humans checking them, the ground truth is impossible for a human to process. We cannot sense the state of a computer without its help. In contrast to this, the initial emptiness of a physical ballot box is very much in the realm of human senses, it's perfectly safe to leave them unattended until voting starts.
(Source: am volunteering for the second time working the physical polls.)
So, forcing a revote might be a way to swing a marginal seat in your favour.
Because you don't automatically throw out votes even if the seal is tampered.
You have other means of cross-verifying authenticity. You can look at the voter roll signatures to see if the vote totals match. You can do statistical analysis versus the expectation and look for anomalies. You can ask observers if they saw anything untoward. etc.
Paper is secure NOT because it is untamperable. Paper is secure because we can bury it a whole host of interlocking cross-checks--of which tamper seals is one of.
It's much easier to remotely and anonymously mass-rewrite electronic records than to physically move the atoms of paper and ink.
How do you prove that an electric system wasn't tampered with? How do you verify the voting machines actually run the verified code? How do you verify that some sub-component didn't hack the RAM?
Winning an election is too valuable and the risks to myriad for me to ever trust electronic voting. Especially as as you mentioned tampering with paper on a large scale will likely leak something went wrong, whereas electronic tampering might never be discovered and can be accomplished at large scale.
Consider for example using blockchain for this. Every eligible citizen gets a "VoteCoin" from the voting officials and deposits it in the official "VoteWallet" of their party of choice. At some cutoff point no more transactions are allowed or considered.
Each voter could verify that their vote went to the right party, and the voting officials could easily verify the votes (no unknown VoteCoins for example).
However now everyone knows which party else everyone voted for...
In general the issue seems to be that if someone voting uses an electronic system they cannot rely on what that system reports back to them. It could be hacked to show whatever. And in order to remain anonymous the person voting has to be the one that verifies that their vote went to the right party.
1. https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
Exactly.
Hacking paper doesn't scale.
I don't know what the procedure/ or law would be but being that they know who voted i would think there would be some sort of attempt to allow them to revote.
Machines that can be readily tampered with and reprogrammed in undetectable ways likely sell better under the assumption leaders would rather stay in power and have ceremonious democracy than risk being ousted or overthrown.
Regardless, if someone was upstanding and wanted to run a fair election with the machines, they can do that as well. Ones that can be altered, preferably only by the election committee to change an election without getting caught, is likely a highly sought after device.
That's likely why we keep finding them over and over again. Every few months another trivial exploit that a fairly incompetent people could discover is found on yet another device.
No receipts, audits, paper trail or any verification ... just a bunch of readily reprogrammable devices that anyone with a USB stick or an sd card or the edge of a housekey could use to change the votes however they please. Again and again and again.
It's very likely intentional.
1. The president is not picked based on the people’s vote. The US is a republic, not a democracy, where government officials cast the deciding votes.
2. The voting infrastructure can be easily tampered with, likely by design as pointed out above.
3. There is no limits on campaign spending, enabling billionaires and corporations to own the winning candidates that got the most airtime.
4. Two private entities have a duopoly on the presidency. They’ve established rules that prevent any new parties from serious consideration.
5. As surfaced by the Wikileaks DNC dump, at least one (if not both) of these parties actively sabotage some of their candidates to ensure the party’s pick a spot in the final national election.
Yes, the US President is. It's not a straight referendum but that doesn't mean it's not based on people's votes.
> The US is a republic, not a democracy
It's both.
> where government officials cast the deciding votes
No they don't.
> The voting infrastructure can be easily tampered with
The machines appear to be. That's quite a way from saying that the infrastructure is. That would require the tampering to be easily achievable. There's little evidence of that.
> There is no limits on campaign spending
Yes there are. They're not very effective but they exist.
> Two private entities have a duopoly on the presidency
Effectively yes.
> to ensure the party’s pick a spot in the final national election
This would be way more convincing if Trump wasn't the President. He clearly wasn't the pick of the Republicans establishment. Or anywhere near. If anything, his election shows that the parties don't have the control that they'd like you to think they have.
The US presidential elections are far from a joke. Not perfect by any means but internationally important events and, in historic terms, beacons of democracy. And in case it need saying, I'm not American and have no interest in being American.
Is that a form of leaving your wifi open so you have plausible deniability later?
It would be easy to mistakenly use these if you werent 'in the loop' as far as cargo shipping is concerned because theyre cheap and nobody in your wheelhouse complained about them. The problem is they are brittle, weather poorly, and as evidenced can easily be bypassed by shimming. Every MPT style seal can be bypassed with a soda bottle or pop can AFAIK.
the trucking industry has moved away from them for chain-of-custody purposes. What the voting machines should be using is the Cambridge PTS series or similar. Not only does it reveal tampering, but even tampering attempts will cause the plastic to turn white/red from stress.
if you really wanted to knock it out of the park: CT-PAT Bolt seals. in vitro locking with spin protection and ISO certified. These can get pricy though, and require bolt cutters to open when necessary.
How can we either a) learn to stop fixing it as it seems quite far from broken, or b) achieve something that's actually an improvement?
The issue is different for direct-recording electronic (DRE) or "paperless" machines, but this article pertains to digital tabulators that are actually a voting machine and ballot box in one: they scan the ballot and then retain it in a box for later audit. The seals pictured are actually used to secure the ballot box, not on the machine itself which sits on top of the box.
Paper ballots have attack surfaces, to be sure. It's just that they don't scale well, and that greatly limits the damage.
I really don't need to know the vote count 9 µsec after the polls close. I really do need to know the vote count is accurate or can be audited if need be.
I think it's not about security per say. It's more about scrutability. While it may be possible to build a system that is more secure in principle it's a lot harder to build a IT-based voting system that a person from the street can comprehend and scrutinize in a days work.
Well, bad news there too:
>But a security researcher in Michigan has shown in videos how he can defeat plastic security ties that counties across his state use to protect ballot bags, the cases that store voting machines and the ports that store the memory cards on optical-scan machines—electronic voting machines that record paper ballots scanned into them. He can do so without leaving evidence of tampering. [Emphasis added]
FTA: "Bernhard, however, said that although voting machines may be locked when they are stored in the county clerk's building, they are left unattended for days at polling places—high school gyms, churches, and community centers—prior to elections. "
I mean, your honor, she was just asking for it!
Honest question, not rethoric. I don't see how paper ballots get any safer than electronic, it just seems to change what's the easiest approach to tampering.
Using both methods to verify one-another sounds decent though.
2: People watch the box to make sure it's not tampered with as people put their ballots in. (This works to a point with voting machines, although a attacker interacts with a voting machine for much longer than the ~6 sec it takes to drop a paper ballot in a box.)
3: The ballots are taken out and counted, with more watching. Due to physical laws like conservation of mass, it's very hard to make the number of ballots coming out differ from the number that went in, and even changing existing ballots is nontrivial. (Voting machines can silently delete, alter, or add ballots matching arbitrary criteria.)