So practically (ethically) speaking, why don’t we see physical ballot collection as equally risky? Is there a good solution?
So practically (ethically) speaking, why don’t we see physical ballot collection as equally risky? Is there a good solution?
I can't speak to the US system, but here in New Zealand every political party is entitled to appoint scrutineers to each polling place. They cannot speak or interact with anyone but they watch the whole process from checking voter entitlement, through transporting the ballots and then counting.
The idea is each party distrusts the others so won't let them get away with rigging the ballot. Mutual distrust produces a trustworthy outcome.
As long as attacks don't scale it seems safe to assume corruption will be localised and the integrity of the system will hold. The risk is that IT is used to centralise democracy to bring down costs, then becomes compromised in an unrelated attack.
This has changed in modern times, as a number of parties disappeared after electoral reforms; and the risk of tampering and shenanigans has increased substantially.
(In this state, observers and challengers are different, with challengers specifically serving the purpose of challenging individuals that may not actually be qualified to vote. Since the pollbooks are electronic today challengers are rarely seen, they were generally only able to challenge clerical errors that are no longer seen with computer pollbooks)
If someone wants to screw with physical votes, they have to access the boxes which hold them. Easily detectable.
Electronic ... you can have the software changed to modify votes and few would be the wiser - even have the changes hide themselves if you are smart.
In physical, it isn't enough to protect where the votes are done. They have to be transported back and ultimately counted somewhere. At any point in that process, they are vulnerable. No?
With a computer, you flip a bit and there's no record. Votes are miscounted? Tough, those numbers are a real as any other numbers. And how much time does it take to swap a vote? Less than a microsecond?
That’s a turn of phrase I didn’t expect on HN.
Do we work in a field where programs don’t have logs, gateways don’t exist, checksums and securing data integrity is not a thing ?
The closest parallel we have is DRM, and the track record there is.. less than stellar.
Personaly I don't think I do, yet even at my personal level I have anecdotes of ink just fading out of paper, or countless of widespread voting frauds from decades ago.
I have the feeling we are putting paper and physical media handling to a higher standard because we don't know as much about it.
It takes a concerted effort to change paper ballots.
For instance some paper elections in Africa have crazy high voter prticipation when not so many people showed up.
That’s an extreme and we could point the finger at blatant corruption. We’re not at these extremes, but where are we on the spectrum?
For instance we don’t have any clear idea of how much corruption we have, to the point that “perceived corruption” is the best approximation.
What I’m going at is, to evaluate how much trust we put in an electronic voting system, we’d need better views at the current system than “paper is better because it’s physical” (that’s not your argument, I take a less nuanced position as example)
Yes, that's the field of voting machine construction - it's lowest-bidder garbage built by and sold to people with no concept of reliability.
No, they don't. At least in my country they are counted in place.
All the observers sit next to the ballot for the whole process, and when the voting ends, the box is opened and the votes are counted. The observers being several people appointed at random (like a jury) to check vote credentials and count the votes at the end + appointed representatives from each party present.
Everything is recorded on paper, the votes are stamped and kept, and the tally is then reported for that voting district.
Even if the people appointed at random wanted to tamper, they'd have to work all together + get the party representatives to agree with it, because it all happens in the open, ("reading vote #N, says party X, do we agree it says party X? (shows the vote around) registering vote #N for party X (people look as the vote is recorded, two people sign next to the vote's registration)).
Usually after the ballots are closed (election ends), it takes 5-10 hours for those people to count all the votes for a district. Then the number is announced. All country districts are announced publicly, so any individual party representative or "jury" member of any district can challenge if the numbers announced (and used for the final country-wide tally) are not accurate.
They are not allowed to leave the room, and there's also a policeman present outside.
I'm not claiming they are impossible to harden. Just not as easy as people are claiming. And super expensive. Such that if you were truly intent to defrauds place, you would focus on poor sections first.
And our best method of defense is probably our extensive polling tests nowadays. The more we have, the more corroborating evidence we have to an outcome. This protects both forms of counting.
Which proves that "votes have to be transported to be counted" is not some inevitable byproduct of the paper-voting process as the parent made it sound like.
Perhaps Chicago could adopt counting in place?
It's mind-boggling we don't do that already -- most voting districts would need only a few random ballots, and you can gradually increase your sample size and check again before needing to trigger a full recount.
Edit: should read articles before commenting..
Because you don't automatically throw out votes even if the seal is tampered.
You have other means of cross-verifying authenticity. You can look at the voter roll signatures to see if the vote totals match. You can do statistical analysis versus the expectation and look for anomalies. You can ask observers if they saw anything untoward. etc.
Paper is secure NOT because it is untamperable. Paper is secure because we can bury it a whole host of interlocking cross-checks--of which tamper seals is one of.
It's much easier to remotely and anonymously mass-rewrite electronic records than to physically move the atoms of paper and ink.
How do you prove that an electric system wasn't tampered with? How do you verify the voting machines actually run the verified code? How do you verify that some sub-component didn't hack the RAM?
Winning an election is too valuable and the risks to myriad for me to ever trust electronic voting. Especially as as you mentioned tampering with paper on a large scale will likely leak something went wrong, whereas electronic tampering might never be discovered and can be accomplished at large scale.
Consider for example using blockchain for this. Every eligible citizen gets a "VoteCoin" from the voting officials and deposits it in the official "VoteWallet" of their party of choice. At some cutoff point no more transactions are allowed or considered.
Each voter could verify that their vote went to the right party, and the voting officials could easily verify the votes (no unknown VoteCoins for example).
However now everyone knows which party else everyone voted for...
In general the issue seems to be that if someone voting uses an electronic system they cannot rely on what that system reports back to them. It could be hacked to show whatever. And in order to remain anonymous the person voting has to be the one that verifies that their vote went to the right party.
1. https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
Exactly.
Hacking paper doesn't scale.
(Source: am volunteering for the second time working the physical polls.)
So, forcing a revote might be a way to swing a marginal seat in your favour.
Not really an easy attack but still a possible one, and these machines have not established a strong reputation for protection against something like a firmware implant
This state uses and retains paper ballots, so it would be yet more difficult to design an attack that would withstand an audit of the paper ballots. But some states don't...
An electronic voting machine could be tampered with well ahead of voting day. Verification hashes and the like are only aggregates that are open to trickery on the way to the humans checking them, the ground truth is impossible for a human to process. We cannot sense the state of a computer without its help. In contrast to this, the initial emptiness of a physical ballot box is very much in the realm of human senses, it's perfectly safe to leave them unattended until voting starts.
I don't know what the procedure/ or law would be but being that they know who voted i would think there would be some sort of attempt to allow them to revote.