This sounds great: paper trail, no chance of "hanging chads" or bad handwriting, verifiable by the voter at the moment before scanning and hand-countable if necessary.
This sounds great: paper trail, no chance of "hanging chads" or bad handwriting, verifiable by the voter at the moment before scanning and hand-countable if necessary.
I do agree that the paper trail is a great thing. I'm not fundamentally against electronic voting, but I haven't heard of a system that can really compete with the simplicity and verifiability of the immutablility you get from paper ballots inside ballot boxes being watched over by interested parties on all sides.
I don't think that's dismissive at all. That's what it is, and it sounds good to me. Basically the computer is a scribe with perfect handwriting that fills out the paper ballot for the voter while the voter watches. Absolutely any voter is qualified to assert whether the ballot contains the votes they intended to cast.
From there, you could have the voter carry the ballot and drop it in a box that's being observed by any number of interested parties, providing old-fashioned accountability. Counting by scanner is an optional time saver, with hand counts as the alternative / double-check.
Having these machines do a preliminary tally gives you a more accurate forecast of the votes cast than exit polls.
1. You cannot know whether the device leaks your vote, i.e., whether your vote is secret. Mind you that in addition to an attack inside the device, this can also happen via simple electromagnetic side channels inherent in the device--as has been demonstrated quite a while ago for Nedap voting computers by the dutch campaign against voting computers, where you could distinguish selected candicates by tuning an AM radio to the right frequency.
2. When the device malfunctions, whether due to a defect or sabotage, and only particular candidates can not be selected, that creates a side channel where the voter is effectively forced to unveil who they want to vote for.
Neither of those failure modes exist with paper ballots.
Paper ballots stop secret cameras in the ballot room? I mean, they really don't. It depends on your threat-model. A lot of things will come down to trust.
> 2. When the device malfunctions, whether due to a defect or sabotage, and only particular candidates can not be selected, that creates a side channel where the voter is effectively forced to unveil who they want to vote for.
See Butterfly ballots. Paper ballots in USA (Florida specifically) which basically had this flaw. It was confusing to know which circles and lines were going to the correct candidate you wished to vote for. Asking for help on the ballot would leak information on who you wanted to vote for.
A poorly done paper-ballot has its own set of issues.
And neither do touchscreens. Paper is better if it's not done comically wrong.
And even the worst paper ballots have a much smaller attack surface for plain old analog rumors than the best possible electronic system. The most powerful way to undermine a democracy is not flipping some votes to one candidate in perfect secrecy, it's making all candidates/camps believe that the other did. This could destroy a democracy even without a single vote having actually been tampered with.
Electronic voting, only understood by experts, is perfect soil for such rumors and no amount of open sourcing can change that. The many human counters involved in a hierarchical paper vote counting scheme are not just an unfortunate inefficiency left over from a time when machines could not count yet, they also serve as witnesses, not only for keeping their peers in check but also for dampening any unfounded rumors that might come up. They increase trust even when they are not actively speaking up against rumors, just by being there, in numbers, as passive dampening elements like the moderator rods in a fission plant.
Ballot rooms are just about as decentralised and non-standard as it's possible to get your head around. Voting machines are the exact opposite.
Are we actually discussing that someone could or would roll out a (nationwide?) network of hidden cameras across church halls, schools, and other places[0] where people go to cast paper ballots. Undetected?
Distributing compromised software - or designing your attack into the hardware - for voting machines would be child's play by comparison.
[0] https://www.theguardian.com/politics/gallery/2015/may/07/wei...
The electronic voting machine never is granted your identity. But I'll grant it's possible that records of the voter identity with the ballot identity exist and could be used to map the voter's vote.
And I like it. The simpler the design, the better. Sometimes it takes a billion dollars and a couple of smart researchers to invent the "obvious" solution to a problem.
We've got butterfly ballots, confusing electronics-only machines, and a variety of bad standards as the basis of our current voting infrastructure. Telling everybody to use a damn PDF + printer would be a gross improvement.
Give America an idea, and SOMEONE in America will royally screw it up. Its a big country filled with lots of smart people, but also filled with lots of dumb people.
DARPA is working to come up with the standard that the whole country should follow. That's good and useful research. Even if it comes out to be the obvious solution (a paper ballot off of a damn printer), there's benefit to one of the major research institutions of this country telling the rest of the country how things should be done.
They were particularly badly arranged punch card ballots; the solutions to both the bad arrangement (“don't do that, like most people didn't do previously”) and the punch card (”use optical scan”) related problems are not only well known but pretty widely adopted.
Ultimately: the administrators weren't thinking about ballot issues. Palm Beach, Florida, was understaffed and underpaid, under-invested. They had other things on their mind when they deployed their machines.
They needed to move off of the punch-card system ASAP, but they couldn't afford to. They had the same issue in 1996 before the famous year 2000 issue. It was known, but not much could be done about it.
----------
I guess this printer methodology from DARPA might be too expensive. Or maybe the scanning machines can be owned by the state, so that poorer areas won't have to invest into the machines. Etc. etc.
There's a lot of issues aside from "use paper ballots". The entire voting system needs to be considered. I hope that DARPA's challenge will include these issues in their design process.
Sure, but moving money around to deal with that problem is easy (and mostly doable intrastate, but, a federal role isn't unreasonable.)
But this isn't a problem calling for novel technology. (As has already been demonstrated by the move to e-voting that happened in many places after 2000, though some people got the wrong message and decided that we just chose the wrong technical solution—but a lot of that is due to lobbying by the people selling technical solutions.)
More specifically - it's a big country with a fantastic amount of decentralization. Elections are run and ballots are designed not, by national governments, not by state governments, but by county governments. The chance that someone will mess up is a lot higher.
(Of course, this does have the advantage that centralized tampering with the ballot is harder.)
I've always wondered why nobody suggests doing that in the US to help prevent or ease people's concerns about potential voter fraud. It's simple, low-tech, and hard to screw up.
Unless if I'm missing something, which of course is possible. Can someone tell me what the downsides are to an idea like that?
I dont get how people can just shrug off reports of dead people and non-citizens being registered to vote as a non-issue.
How many of those dogs registered to vote showed up and cast a ballot?
--
If anyone actually cares enough to have a mostly accurate cost effective voter registration database, they'd reuse any one of our existing national demographic databases. But they don't. Because the recurring drama caused by our existing fragmented poorly funded more error prone system is too useful.
In this case, Occam's Razor beats Hanlon's Razor: The simplest explanation is malice, not stupidity. The groups who are the most hysteric about hypothetical voter-fraud are dishonest. Their actual goal is not to prevent vanishingly-rare crime, but to suppress legitimate voters in a partisan fashion.
Finger-inking at the poll-site does not offer them a useful tool for skewing the election results. It imposes no special discouragement or advantage to a particular group, and it also does not create a system for arbitrary "enforcement." (In contrast, consider poll-taxes or name-similarity databases with insanely high rates of false-positives.)
___
Some might retort: "I don't suggest finger-inking because it won't stop someone from impersonating another voter." True, it won't stop that from happening the first time, but it limits it to once. This means N improper votes require N humans, and as N gets large the odds of keeping it secret go to zero.
I have been informed by social scientists that requiring voter ID is racist, so it seems that fingerprint checks would also be racist via the same logic.
Do you have a personal opinion on that? I don't see it as racist in any way, because it applies equally to everybody.
We have a few basic rules for voters in this country, one is that they are citizens, two is that they are registered. Being able to demonstrate that you are the registered voter you claim to be seems to me to be essential to a fair election process.
“The law, in its majestic equality, forbids the rich as well as the poor to sleep under bridges, to beg in the streets, and to steal bread.”
In practical terms, there are a lot of people in the US that simply cannot afford to buy an ID - both because of the actual cost and because of the logistics and documentation required. Trying to get a certified birth certificate from another state when you are homeless is, I imagine, pretty damn hard and relatively expensive to do.
If the US had a system where ID was available to all completely without cost (and only taking a trivial amount of time) then I’d agree with you more.
If requiring the ID is really so discriminatory, then it has to go away for bearing arms as well. Is this something you want?
BTW, in terms of potential hazard, voting is a lot worse. Voting can lead to wars.
12 states have constitutional carry laws. I can buy and carry with no ID needed.
As for voting and issues in obtaining valid ID, I can guarantee if you're on HN, you are not the group being talked about getting an ID.
I had to obtain a birth certificate from my state. I had to drive 3 hours away, and pay $25, and drive 3 hours back to get it. And for someone who doesn't have a car, lives in the city, and lives week to week, they won't be getting a valid ID anytime soon.
Oh yeah, and they're primarily black and poor. That's why the racist claims are made.
https://www.citylab.com/equity/2018/11/voter-suppression-rac...
To build a little on what the other commenters are saying, I recently watched a talk about equity and how it compares to equality. There's a famous image of people of different heights looking over a fence[0] that shows well how equality does not always lead to justice. I have found it worthwhile, every time I see "equality" featured, to ask about how this is different than equity. In this case, it's inequitable (to a degree) because it is disadvantageous for the poor or other marginalized groups to jump through these hoops even if they're the same hoops that the advantaged groups have.
I'll also note this equality-equity distinction is making its way into mainstream American politics. On page 6 of the Green New Deal[1] is a provision that the federal government has the duty of promoting equity and justice for people oppressed because of their race or circumstance. This is noteworthy because (as far as I'm aware) federal law has only been providing equality so far, but now there's a shift in policy to provide equity and not ask for equality.
[0] http://interactioninstitute.org/illustrating-equality-vs-equ...
[1] https://www.congress.gov/116/bills/hres109/BILLS-116hres109i...
Would you say the same thing about poll taxes?
The idea of ID laws is not inherently racist. It's the implementations that are problematic.
For example, one jurisdiction that got in trouble for its voter ID law (I forget which one) was found by the courts to have, when writing their law, did a study of what forms of ID voters had, found out which of those had the biggest differences between prevalence among whites and among blacks, and then picked as the allowed forms of ID those that would most favor whites and disfavor blacks.
Places that aren't as blatant about it (or at least aren't dumb enough to actually talk about it in legislative committees for which subpoenable records are kept...) often leave hints that their motive is racial. For example, they might limit the number of places that can issue IDs, and reduce their operating hours, so that a poor person without a car (more likely to be black than white) has to take a long bus ride there and back, and has to take time off work to do so. This can be a serious hardship. (Worse, it might take more than one trip if there is any problem with the supporting documentation for the ID application. Unsurprisingly, it has been found that minor errors that tend to be overlooked when a middle class white person applies are much more likely to derail things for a poor black person).
Another hint that their motives are suspect is that such efforts are usually accompanied by efforts to make it harder for minorities to vote that have nothing to do with ID, such as closing polling places in minority neighborhoods and limiting voting hours, or reducing the number of voting machines at minority neighborhood polling places so that lines will be long.
If voter ID laws were actually about preventing voter fraud rather than about suppressing legitimate votes from poor and minorities, they would be accompanied by changes to make it cheap and easy for people to get the appropriate ID.
Also, they would be about registration ID, not voting ID, since what little fraud there actually is usually takes place via absentee ballots.
In MN, we use paper ballots with Scantron readers for excellent results. I'm not sure what problem this new system is supposed to solve that the Scantron model doesn't.
My preference is for plenty of machines available to fill out paper ballots, but give voters the option of filling out by hand.
If you live in a place like I do, we’re a one party place where primary elections are the real elections, and you don’t have the competitive pressures that are inherent to a multi-party contest.
We also had a huge upsurge in “write in” votes, as the paper forms are difficult to interpret.
After a vote we get to watch the news go from counting station to station to announce the results.
There are usually a few recounts etc but it rarely takes longer than a day or two and tbh which is more important done right or fast?
I don't think you're being dismissive enough, it's an expensive pencil and paper.
So ballot marking technologies have marginal utility. Expensive fix for a non-problem.
For complying with HAVA mandated accessibility, the Automark is slightly less bad than the others. The only solution which actually fulfilled all the requirements and was preferred by the disabled community is a non-electronic protective ballot sleeve called the Vote-PAD. Alas, it hasn't been available for quite some time. Being cost effective, meaning less pork, it didn't have any champions.
Fortunately, a new ballot marker, twenty years too late, doesn't help with the increasingly fashionable postal balloting, so there's no danger this latest noble effort will have any benefit.
If you have to fill something out by hand, it makes it hard to do this.
People consistently overestimate the reliability of that solution, especially for older voters with mobility challenges. Pushbuttons or levers that demand macroscopic elbow/shoulder motion are easier for that demographic to use than sensitive screens requiring fine motor control.
And that's all to say nothing of what happens when the screens become miscalibrated and accept taps a few pixels off. I'm fairly confident most of the "It switched my vote" reports we hear are actually this category of "user-error" (which should really be counted as "machine malfunction").
In general, getting elderly people, low-income populations and other late adopters of technology to use touchscreens correctly has been much easier than getting people to use a mouse. The mouse is less physically intuitive than "poke the thing you want." For most of us, though, we hardly notice a difference.
- since there's only one screen, and it's all touchscreen, users get consistently confused between pictures of buttons describing what the buttons do and the buttons themselves
- the touchscreen is itself a peripheral and prone to wearing out. When it does, the fact it's wearing out is difficult to observe during the election day; there's no cursor indicator, so a poll worker can't check calibration.
- users with fine-motor-coordination issues have to brace against the box to steady themselves to touch the tiny targets they want. There's nowhere to brace against a touchscreen that isn't also touch-sensitive input, and the screens don't accept multi-touch.
A row of buttons along each side of the screen, not unlike the solution used at many ATMs, would ameliorate all these problems. These boxes are already custom hardware jobs, so switching out touchscreens for a couple of button banks would be cheaper, equally usable for most voters, and more usable for mobility-impaired voters. It would improve all three observed problems.
Wishes and horses though; the machines we have are the ones we use.
What we saw in 2016 was that even if a candidate were to contest a result, none of the election committees were willing to commit to a full hand recount; instead, the only options were to retabulate through the very same tabulation processes and machines that had produced the questionable results in the first place.
Without low barrier to recount by hand, the electronic systems production of paper trails is worthless. Arguably worse than worthless, because it leaves everyone thinking there is a usable backup, when there isn't.
I don't see how any system can work if nobody is willing to double-check it.
The best example of this is a Risk Limiting Audit (RLA). You only have to re-count a smaller number of ballots until the overwhelming probability is that the vote is confirmed, or that the vote is rejected. Depending on the disparity between the ballot options, this count can actually be very small.
See: https://www.stat.berkeley.edu/~stark/Preprints/gentle12.pdf
This system is perfect for this kind of an audit -- essentially a ballot marking device written by an organization known for formal verification.
I'll read the paper you linked, but know that it's contrary to the received wisdom, and I'm very skeptical of any claims that auditing elections are feasible or worthwhile. By audit, I mean anything short of a full manual recount.
--
Okay. I lightly read that paper.
First, it specifically says to only audit the VVPR, meaning the actual ballots, not the VVPAT, which is just what the computer says it recorded. So there might be some miscommunication. I assumed #bdamm was referring to the VVPAT.
Second, the meat of the paper is refinements for calculating the confidence that the official result is correct based on recounting a sample. All of the caveats with audits, not within the scope of this paper, remain the same.
Colorado successfully performed an RLA, and didn't have to recount every ballot. If you really want to read more, Free and Fair (IIRC, the same group bidding on the DARPA grant) has open source software and instructions on how to perform RLAs: https://github.com/FreeAndFair/ColoradoRLA
Frankly the cost of elections doesn't seem to be a serious problem for any government. They're choosing to fix some roads instead of boosting the quality of elections. Frankly I'll take the election over potholes or whatever else the government is spending money on, because if I can't trust the election, I can't trust the government.
Best as I can tell, the only thing determined from the audit was that the machines still powered on and the printers worked.
In the USA, federal, state, and local contests are all on the same ballot. Where I live, general election ballots have 30+ items.
For manual counting to be feasible, we'd have to split into separate ballots.
Of all the people I've spoken with over the years, there's been no objections to this. But it is a big change and there's been no advocacy.
"We want you to vote for Jim Totes-Legitimate for President. But so that we can recognize your ballot paper and we can verify that you voted for him and we don't have to break your kneecaps, please also mark your other ballot races as follows: Fred Also-Ran for First Assistant Flangedoodle, Sheila Plausible for Second Assistant Flangedoodle, Hazel Placeholder for Junior Hog Counsellor."
Not hard if you've got 10 or so multi-way contests or 20 or so ballot measures.
Which is also why the cryptographic voting systems cannot protect voter privacy. Those systems require hash collisions to hide your ballot in the herd of ballots. But the combination of precinct size and complicated ballots means any particular ballot is utterly unique (no hash collision).
I'd be far more charitable towards crypto advocates if they also specified the conditions required for their system to work correctly.
Similarly, with postal balloting (vote by mail), your ballot is batched (upon receipt), so will be mixed with ballots from other precincts, therefore more easily tied back to its voter.
That seems backwards. Touch screens suck. Why not build a validation machine that voters can feed manually-completed optical scan ballots into, before they go to the tabulator? Clear feedback would help catch incorrectly filled out votes before they're cast, no touch screen required.
The validation machine could have a very clear and user-friendly display, which candidate pictures are large type. That would definitely be easier to verify than a computer-generated optical scan ballot.
Although I would favor a screen with physical buttons next to it (not like the garbage you see on ATMs and gas pumps though)
What don't you like about these buttons? As mentioned elsewhere in the comments, this is a proved design that works well for a great number of people. Plus, the elderly / tech averse are likely to already know how it works.
That's precisely how poll-based opscans work.
Central count (for postal ballots processing) is necessarily different, because that sanity check cannot be done, so voter intent must be adjudicated when ballots (or individual votes) are unreadable. It's a sausage factory.
I know, we have them in my district, but they don't do all the validation I was talking about. I think all that the current machines do is validate that there were no overvotes, etc. I was proposing a separate machine that would let the voter validate that the ballot would be read as they intended.
Does this system address that concern?