Protecting democratic elections through secure, verifiable voting
blogs.microsoft.com
blogs.microsoft.com
Your electronic voting system can be mathematically perfect, but if nobody average can say from the outside that everything is going by the rules and it makes sense, then it is worthless.
This is why paper works so well: it takes not much skill to count it, it has to have a physical place (harder to make it vanish) and everybody can have their eyeballs glued to it, and if something fishy is going on, it is harder to hide from the average voting helper.
Even I as a programmer with some crypto knowledge would never be able to fully gurantee for the integrity of a voting system, because who knows what software version is running out there in the wild, and whom I have to trust on that one.
Paper has no software version and errors in the process can (and are) catched more easily.
Electronic voting is good for decision were power is not involved, or where the outcome doesn’t really matter. I’d rather improve what we have instead of replacing it with a mathematical sound blackbox that everybody can with perfectly rational reasons distrust when the vote went into the wrong direction.
Replace the whole damn thing with your own one in an identical case running system.out.println("my favourite candidate wins! ");
It may not be an admissible attack in the model within which protocols are proven secure, but it's still an attack that could affect real-world systems.
Of course the trust only comes with understanding of the mathematics.
- You can somehow identify your own vote and thus verify it was properly counted
- Everyone else can do the same, thus fraudsters would have to find a protocol weakness to add additional votes
One attack vector might be whatever you use to identify your vote. Aka find a way to make two people think the same record is their own vote, then use the other yourself. This seems like a tricky problem, since everyone shouldn't just be able to see their own vote was included but also not not be able to show others how you voted. The article seems to indicate they solved this somehow, but I'm not familiar enough with the details / homomorphic encryption to understand that or even just trust that specific kind of encryption.
> ElectionGuard provides a complete implementation of end-to-end verifiable elections. It is designed to work with systems that use paper ballots, supplementing today’s tabulation process by providing a means of public verification of the accuracy of reported results.
This is the most common type of attempt to subvert paper voting. The paper becomes the "recount" which is often challenged in court. See? The numbers match, there is no reason for a hand count.
The whole point of this scheme is to provide strong evidence for when the numbers won't match. This is an advantage over existing optical scan systems, where a recount requires watching every single paper ballot go into the reader.
Hand counted paper ballots.
My impression from fraud reports from Russian elections is that most fraud occured at the local level (where no one was able to precisely quantify it) and from the point the data was inserted into the centralized database everything was squeaky clean.
So maybe some kind of a centralized panopticon surveillance system that the FAAMG are so fond of is just the right fit for elections.
If it was something that was done at local level, not in conspiracy with central government, then why the investigations in cases of election fraud are so ineffective, and even if the case gets to the court, it typically ends with just a fine? If the central government didn't have relation to the fraud, they would prefer to punish local officials, yet they try to avoid doing it.
Instead, they warn heads of regions that the results of election in their region might affect their evaluation.
Regarding things you have described, they are possible with electronic voting as well. Hashes not matching? You probably made a mistake, verify again, our experts say that everything is correct.
Also, for an average person, seeing a video recording with officials throwing a pack of ballots into the box is easier to understand than some difficult calculations with hashes.
Maybe I misunderstood your phrasing but that's precisely what enables large-scale fraud. High-ranking officials can maintain plausible deniability by outsourcing fraud to the local level and doing nothing overt themselves. If low-level officials are caught, they suffer token punishment because some semblance of rule of law must be maintained (but punishment cannot be too strict because they were doing what they were supposed to do).
> Regarding things you have described, they are possible with electronic voting as well. Hashes not matching? You probably made a mistake, verify again, our experts say that everything is correct.
Right, but if you have evidence that say 10% of votes are tainted, it is something worth fighting for and going to the streets for. Whereas if all you have is a recording of a handful of ballots thrown into a box at some poll station in rural Yakutia, well who cares about a few 100s of ballots? You can try to string a few of these videos together to provoke an emotional reaction but it will subside quickly as public attention will be redirected to the next outrage du jour.
Electronic voting can reduce the friction enough to where we can address these issues with common-sense approaches.
Mail voting has the downside that it invites the kind of problems where some guy tricks elderly people into giving them their vote etc. But all in all it works quite well.
The US has had vote-by-mail for as long as I can remember [0]... So what is an example of a "mostly solved problems in all western nations (except for the US)" other than an example that you posted that is inaccurate?
I'm not arguing that we have solved all election problems, but it's unfair to say we haven't solved something and share a solution that your country has that our country has too. Maybe Austria does something different with their vote-by-mail system than what the US does, if so please share what that is.
[0]https://dos.myflorida.com/elections/for-voters/voting/vote-b...
[0] http://www.ncsl.org/research/elections-and-campaigns/all-mai...
[1] https://www.sos.state.co.us/pubs/elections/FAQs/mailBallotsF...
Per the link I cited above as a sample reference to vote-by-mail in the US - "Vote-by-mail refers to voting a ballot received by mail or picked up by or for a voter instead of going to the polls to vote during early voting period or Election Day. Except on Election Day, no excuse is needed to vote a vote-by-mail ballot (see Who Can Pick Up a Vote-by-Mail Ballot below)."
The key phrase being that last one, "no excuse is needed to vote a vote-by-mail ballot". There is no verbiage about it being a "last resort" and that you can only vote-by-mail if "you're unable to vote in person". The Florida Division of Elections even titles the page "Vote-by-mail".
https://dos.myflorida.com/elections/for-voters/voting/vote-b...
- With electronic voting the identification problem is at least as hard as with paper ballots, so Voter ID is at least as hard (an honestly, I've never heard of any problem of this kind outside of the US)
- Electronic ballots could be simpler than paper ballots, but they can also be a lot more complicated. Under the assumption that voter suppression is taking place we have to assume that the electronic ballot would be more complicated than the paper equivalent
- Electronic voting still requires voting booths, meaning you can still overload polling stations. Voting from home is equivalent to mail voting (already a thing) and has a lot of problems if it's how the majority votes
Also all these problems have common sense solutions already:
- If the nation for some reason doesn't have a ubiquitous national identity system the government should take some of that tax money and hand out free Voter ID cards (perferably delivered by certified mail or similar)
- Designing ballots that are not complicated is a solved problem in most of the Western World
- Have enough polling stations that queue times never exceed 10 minutes. If queues are too long take note to make that polling station bigger in the next election.
Although there are downsides to vote-by-smartphone, an advocate would argue you should compare it to vote-by-mail rather than vote-in-person, given that almost every election allows vote-by-mail.
However, I can tell you what someone who was an advocate of smartphone voting would say.
To (a) they would say we already allow postal votes, so the pressure/vote-selling is already with us; and furthermore although the pressure/vote-selling is bad for democracy, low turnout and voter suppression like making polling stations hard to access are worse.
To (b) they would say if Apple Pay can be secure, so can online voting. Maybe even more secure! I mean, in my country the ruling party doesn't have enough members to put an activist in each polling station watching the ballot box, even if they worked a 15-hour shift without toilet breaks. So it's not like the current system offers total protection against fraud.
I know it's unpopular to say, but I don't think it's a bad thing that voting requires personal (strictly personal; no corporation should get in your way) effort.
But I also don't see why the first sentence is inherently bad. Why is it good to police what type of people may vote? Why is it good to police the reason for voting?
Just so the results of voting can be displayed on TV a bit earlier, we are supposed to accept substantial risks to democracy posed by blatantly insecure endpoints, blatantly insecure company infrastructure, insecure network communications and devices (routers, etc.), private companies that often have a track record of insecure and sloppy programming, voting machines that have been shown to be hackable easily (people from CCC and similar groups do that routinely when they get hold of a machine), voting program code that has been improperly audited and/or cannot be verified by the public, flawed patching mechanisms, flawed and insecure operating systems of voting machines, and on and so forth. The list of flaws of electronic voting systems is nearly endless, and, what's worse, there is no mathematical proof that the encryption used in those systems cannot be broken. (There are lots of proofs in cryptography, but almost all of them are based on very strong idealizing assumptions. In the end, only OTPs are provably secure. We do not even have a proof that P!=NP yet.)
That is incorrect. Voting is a feedback loop for the will of the voters. The slower the process is, the less representative it is. The fidelity of the loop is paramount, but the issue remains.
EDIT: do the downvoters understand that there is setup involved in a paper process and getting results is not the end of the feedback loop (not race)? SMH
If we are talking about months perhaps, but as long as a result is known within a day or two (at most) I'm not sure it really makes that much difference.
For elections every few years even a week of counting would not be a problem.
If the process were extended over a week instead of a night, it becomes correspondingly harder to ensure that there was never an opportunity for someone to tamper.
As things are now I see no reason of sort not to use paper ballots as the main proof of vote. Especially for big nation wide elections.
you sort of lost me here. I will not say it is a bad idea, but it would never work in any country I know. Thee sheer size and cultural innovation required would still need to place an inordinate amount of trust in the system.
Again, it is not that it is evil, as much as there are so many possible problems for so little gain
(IIRC Estonia has a nice program where you have a state-SIM and you can vote via telephone, so there it actually might work)
Bitcoin works this way though. It is a set of tools to manipulate a highly abstract data structure. These tools are developed by a minority of the population, but the rest of the population trusts them.
This works because it has value for the folk.
Now you're speaking about elections. Most of the people speaking of e-elections are _mostly_ trying to get to the public that if you could make the elections work electronically - then there's a bunch of other things that could be done digitally too.
One example - company board voting. What if you could be present at any board meeting because everything that is said over there is cryptographically signed by each party thus providing non-repudiation of whatever they said?
What if every newspaper reporter had to sign their articles with their signature which is linked to a news trust network?
Contract signatures. Inheritance.
This is a reply to your:
>> Again, it is not that it is evil, as much as there are so many possible problems for so little gain
Little gain is only for people who have no idea of what you can do with "digital".
Everyone who wants to be on the ballot registers a few months in advance, which is usually a short enough time. Since people are usually voted into a job they have to do for 4-6 years you don't want hasty decisions anyways.
Getting poll results while the voting stations are open is usually not a desired feature because of how it influences voters.
The delay for counting the votes measures in days, which is a tiny amount in a feedback loop where one iteration takes 4-6 years. Other steps, like forming a government, routinely take an order of magnitude more time in many nations.
I think their argument is precisely that that's too slow of a time to reflect what the voters want and that a faster turnaround time would allow referendums and more of a direct democracy, even when it comes to minor issues, since 'representatives' often don't quite represent.
Such a system does need informed voters, otherwise it opens up to reactionary activism, but that's a whole another debate.
Why should it go on both direction ? Even if it's true, is it a good thing ? You should change your opinion if you hear good arguments and not because you want to vote like the others.
And some may argue that voting is a pretty bad "solution" by itself.
https://reason.com/2018/11/10/libertarian-critiques-of-democ...
https://winstonchurchill.org/resources/quotes/the-worst-form...
Voting today is a complex and costly process. Hence, it cannot be carried out frequently and hence the accountability/ feedback loop is slower.
Imagine if we could conduct voting in a day (even in large democracies). We would be able to remove bad representatives faster.
That would be horrible. "direct democracy" does not work (Switzerland is also a representative democracy), practical policy making requires some domain knowledge, patience and the ability to make compromises that the Internet mob could not possibly deliver. People are generally very good at judging the trustworthiness of other people, however, and at being critical about other people (rather themselves). Both traits work well for a representative democracy.
just have a test we can take to illustrate competence in a domain. Passing the test grants us the right to vote on laws in that domain.
Then, those who represent us are those who have illustrated the intellectual capacity to make good decisions.
You already accept the influence of corporate PACs, which arguably are a much bigger threat to democracy. Not saying you should add another vector, (electronic voting), just that the argument that there's a solid democratic system now is not quite true.
This is leading astray but just to make this clear for anyone looking up this thread later: I do not accept the influence of corporate PACs at all, and believe (but IANAL) that where I live these would be illegal.
Good, but I meant "you" as in the broader society concerned about electronic voting, not "you" as the individual.
Can you share some links?
Election recounts were triggered and entire countries and regions were affected because a recount couldn’t be completed in time.
Take for example Al Gore vs George W Bush: https://m.youtube.com/watch?v=qcz6NSyxrfQ
Because the recount was stopped earlier than it could be completed, Bush became President, stopped watching Bin Laden and we got 9/11, then invaded Iraq and Afghanistan and the entire region was heavily destabilized and overrun with Islamic terrorists. The largest geopolitical disaster of the last 50 years with effects as far reaching as Syrian civil war, Libyan anarchy, and millions of refugees and families broken.
If only a recount could have been done faster...
About 10 years later...
Underhanded V Contest http://graphics.stanford.edu/~danielrh/vote/vote.html
(If I remember correctly, the "Underhanded C Contest" came later.)
http://lcamtuf.coredump.cx/soft/vote.c
Now, a Microsoft SDK with a catchy name, "Defending Democracy".
What next?
There are two ENTIRELY UNRELATED questions. One question is "cryptographic verification." One is "Paper/electronic"
You can have any combination. You can have a crypographical, verifiable, PAPER voting system, for example (and that's what this article is about).
No, because it'll still be counted manually by humans. What the cryptographic layer allows you to do is verify that your vote was properly counted or allow a trusted third-party to verify that for you. It doesn't take anything away from the paper voting system but only adds to it. That said, you'd still have to trust the device that generates your tracker, but maybe they've found a way to deal with that.
But one line stands out as particularly troubling:
Our sample reference will showcase how people can make their selections at home, where they can easily research their choices, then bring a QR code to the polling place to scan and pre-populate their ballot.
On the one hand, I support the goal of making it easier for people to research and select their choices. But the risk of enabling a "scan-to-vote" operation is pretty clear: voters will be given their QR codes pre-populated by some interested third party.
I don't mean this as a what-about, but it's worth noting: any ballots that list the party of the candidates or offer single-action straight-party votes are effectively a subtle form of a ballot pre-populated by an interested party.
If it means it's easier to vote for those overwhelmed by all the various choices out there, then that's a win. If it means you can get your average millennial or Generation-Z friend to vote, someone who cares about social issues but can't be bothered to learn about local judges -- then that's a good thing. It could mean more accurate representation. It's better than letting the richest and most idle determine everything.
I'm not saying it's a perfect solution, but it's more secure than mail-in ballots, which are currently in use and popular in many locations.
Imagine you're very busy and haven't spent the time yet to figure out what to vote for. Someone tells you that if you vote a certain way, it will be great for a certain pet issue that you care about, and they give you (and many others) a QR code. The QR code contains a vote for one candidate who cares about the pet issue, but the rest of the votes in the QR code are all oriented around a different issue that you don't know about, don't care about, or actively care the other way about, but you don't notice and scan it and vote it as-is.
Mail-in ballots don't have that issue.
Does anyone know how such things are implemented? I have read about e-voting in Estonia, but there one has to trust the authorities and cannot independently verify the results.
[1] https://www.nytimes.com/2018/11/04/us/politics/apps-public-v...
Also, even if the list of people who voted is public, and if results were falsified, with electronic voting you cannot estimate the scale of falsification. Did they alter just a hundred of votes or hundred thousands.
And one more scenario: before closing the elections, officials can make a list of people who didn't vote and vote for them. If they didn't vote they probably don't care about elections and won't find out that someone voted for them.
This could already happen today. This is why all major candidates, even in these united states, send their own observers and not simply trust election officials to do their job.
So with electronic voting, it becomes necessary to verify lists of voters.
Either you're responding to the wrong comment or I'm failing to see how this is at all relevant to what I asked. How does tracing your own vote tell you if John Doe was fake?
Paper and pen, such a beautiful straightforward system, sacrificed in the altar of unnecessary use of technology.
(which, while more secure, is also slightly less useful)
> no its not.
As in not related not as in not a bad idea.
To a layperson, statements like the one below raise a flag. If I can track it electronically, is it also possible for someone else to see who voted for whom?
"After the election is complete, the tracker codes can be used by voters to confirm that their votes were not altered or tampered with and that they were properly counted"
Again, to a layperson the above statement seems potentially at odds with the one below at first blush (because I don't understand the technology):
"With homomorphic encryption, individually encrypted votes can be combined to form an encrypted tabulation of all votes which can then be decrypted to produce an election tally that protects voter privacy."
So we have privacy but electronic traceability to the individual voter? To the uninitiated like myself, it seems like we'd have to choose between electronic traceability and anonymity.
The idea is that you can have a public, verifiable "ledger" of voters. You can verify that you are on the list with your encrypted vote. I.e. you verify that your vote counts. You can match it to the receipt you received when voting. You do not, however possess the key to decrypt your vote or the vote of anyone else.
The public list can also be used (more work) to verify that only real people voted: They could presumably be contacted.
Homomorphic encryption allows the votes to be tallied while still encrypted. The result is an encrypted tally.
At this point someone with the decryption key can decrypt the final tally and reveal the result. Presumably this can happen per polling place.
From that perspective, it seems analogous to the system in use but perhaps more efficient. In other words, does this actually introduce any new features or just translate the existing features of the current system to a new medium?
> does this actually introduce any new features
Well, the current system doesn't allow you to verify that your vote was counted, so that's what it adds.
And the Galois post here: https://galois.com/blog/2019/05/protecting-election-integrit... (via https://news.ycombinator.com/item?id=19840683)
Here's a case from last week of a spoiled ballot giving someone a majority of one: https://www.theguardian.com/politics/2019/may/03/ballot-pape...
Was that the result the voter intended? Probably not, but who knows? :)
This was a constituency where the previous incumbent had had some problems with his younger GF
Not bothering to show up at all doesn't give any clear message.
Microsoft shall I send you my resume ?
The main items I don't see represented are all roughly related to auditability for ballot chain of custody. I think issues/irregularities with the ballot chain of custody are probably good proxies for triaging hand-audit efforts.
The goal is knowing when ballots go missing, or turn up in unexpected places (but I'm not sure where the sweet spot is for securing that chain without making individual votes unmaskable). I think it's a similar process, with lots of identifiers, and lots of scanning. It would live or die by rapid, simple, reliable scanning.
This means scanning identified ballots into shipping boxes, and generating an identifier for the box based on which ballots were scanned in. A pallet gets an identifier based on the boxes that went in. Shipments get identifiers based on whatever combination of boxes/pallets they contain. Scan in boxes at the polling station and accumulate identifiers for the polling place. Perhaps per poll worker. Scan ballots out of the boxes, back into the completed-ballot boxes and/or trash. Cumulative identifiers for completed-ballot boxes, trashed ballots, and unused ballots are scanned back out of the poling place and at each step back up the chain again.
As long as you can verify that the final tally is correctly calculated from all the public encrypted votes, that those encrypted votes include yours, and none are by fake voters, who cares how the encrypted votes are transmitted to the body that officially calculates the final tally?
But I don't see how the ability of individuals to verify that their own vote was counted can sum, at scale, to verifying that real-but-fraudulent ballots aren't also in the total.
It seems like you could verify this if everyone who voted proved that their vote was included in the count and the full count was explained by everyone who proved they voted. In practice, that seems unlikely?
Sure, you can't verify every single vote, but it doesn't take that much time/money to call up, say, 100 people (relative to the expense of running this whole system). If you contact 100 random people from the public record of who voted, and all 100 say "yes, I did actually vote", then the real result (excluding fraudulent votes) is unlikely to differ from the recorded result by more than 1%. And, obviously, you can drive that probability down as far as you want with more expense, but that'd only be important for rare close elections.
I'm not sure what the contact rates would look like if you tried, but retroactive sampling should have a good chance of spotting systemic abuse if response rates are sufficiently high. I guess you could even legislate random audit sample sizes based on the number of votes and victory margins.
I've been thinking about the values of end-to-end auditability as deterrence and public relations, but I agree that you could capture the majority of that benefit for a fraction of the cost and complexity with regular sample-based audits.
I don't think there's any need to legislate random audit sample sizes; in practice, independent groups will do so. (And it's crucial to legitimacy that it's possible for independent groups to do so in the first place, of course.)
Lazy thinking, on my part. The thought was that mandatory audits would help maintain long-term confidence by avoiding erosion of confidence in long gaps where no specific evidence triggered audits. Minimum sample sizes would help protect the mechanism from undersized propaganda-audits that ultimately undermine trust in the audits themselves.
But you're right; it would probably be easier and more pernicious to do a sufficiently large audit but give the reins to partisans, ideologues, or incompetents. Fairly open access would be better, thouguh I'm sure there are still plenty of "interested" outside parties willing to perform propaganda audits for cheap. Not sure how to solve that.
As far as I know, controversies over audits or the independent observers themselves being corrupted aren't really a problem in the US at least, so I'm not too worried about this.
If it takes 3 days instead of 1h to get the votes, I think it's worth the wait since elections are pretty important and with paper you can do a recount, find physical paper that's been thrown in the trash (happens every time in Italy), etc.
Also, these corporations seem to have a strong political bias, and how do we know they're not injecting their software with backdoors that would allow to manipulate results..?
> ElectionGuard provides a complete implementation of end-to-end verifiable elections. It is designed to work with systems that use paper ballots, supplementing today’s tabulation process by providing a means of public verification of the accuracy of reported results.
The paper becomes the recount, which gets challenged in court and might not even happen.
So what's preventing vote-buying schemes?
But such scheme is still vulnerable: for example, imagine if a large state-owned or having close ties with government company forces their employees to vote online under supervision. If the employees are not very good with computers or don't own one, they cannot change their vote online later, and employer can set their shifts to a voting day so that they cannot visit the polling station.
If I understand correctly schemer could agree to pay for votes, but had no way to verify the ballot was indeed cast for that candidate. With this system they could first verify the vote before paying. It's made possible by the information which is used to verify the vote. It's supposed to be kept secret by the vote, but could be shared with the schemer in order to get paid. This would make vote-buying schemes much more manageable.
However, there seems to be considerable risk to the voter. What's to prevent the schemer from not paying up? The vote is already cast, and what can the voter do? Sue the schemer? For not paying for a bought vote?
If you're willing to assume the attacker is into the voting booth, you're no worse off with this.
That's the "verifiable" step in here.
The only way for you to know who I voted for is if you were in that booth with me.
> The combination of the tracker – which allows individual voters to verify that their votes have been accurately recorded – and the verifier – which allows anyone to verify that the recorded votes have been accurately counted – enables full “end-to-end verification” of the correctness of election results.
I understood this to mean that I am able to use the tracker to verify that my vote was cast for a particular candidate.
This Numberphile video explains the process a bit more: https://www.youtube.com/watch?v=BYRTvoZ3Rho
It's worth noting that Microsoft has discouraged the use of embedded Windows on voting machines in the past: https://www.infoworld.com/article/2680658/gates-undaunted-by...
> “We ourselves are not going after the e-voting market or the nuclear reactor control market,” Gates said.
I don't think Gates words from 2004 can be seen as policy statement for today's Msft. Apparently, a lot has changed.
I'm not sure how much stronger of a statement they can make than that. There's no money in voting machines for Microsoft.
I'd actually be more worried if there wasn't a clear incentive for MSFT to work on this project.
> ElectionGuard provides a complete implementation of end-to-end verifiable elections. It is designed to work with systems that use paper ballots, supplementing today’s tabulation process by providing a means of public verification of the accuracy of reported results.
> ElectionGuard provides a complete implementation of end-to-end verifiable elections. It is designed to work with systems that use paper ballots, supplementing today’s tabulation process by providing a means of public verification of the accuracy of reported results.
Incrementalism is a powerful technique.
https://www.bundesverfassungsgericht.de/SharedDocs/Pressemit...