16M Americans will vote on hackable paperless machines
technologyreview.com
technologyreview.com
In the 2016 Presidential election, a lot of people in North Carolina had trouble due to problems with the electronic poll books they used to keep track of who registered and who already voted.
People would show up at their polling place and either be told, incorrectly, that they had never registered, or be told, incorrectly, that they had already voted.
Oddly, they only had trouble with these systems in Durham County, a heavily blue county, and these same devices in other states are known to have been targeted by foreign hackers--but it wasn't until this year that DHS finally agreed to actually do a proper forensic examination of the equipment to see if anything shady was going on [1].
[1] https://www.npr.org/2019/06/05/729920147/federal-government-...
There is nothing odd or mysterious about it. It's the logical conclusion of being a political minority clinging to power and it's been happening for decades both openly and less openly.
As Andrew Gumbel wrote in Steal This Vote [2005], America experiences recurring amnesia.
https://www.amazon.com/Steal-This-Vote-Elections-Democracy/d...
As a burned out election integrity activist, I've really struggled with the recurring incredulity.
My local newspaper called me a "sweaty paranoid kook", because I dared to explain how our jurisdiction's central count actually worked (per their procedures manual).
And all the risks we identified and tried to mitigate? It all happened. All of it. (Where's my parade?)
--
Some free, unsolicited, hard earned advice from a recovering activist:
Focus on "errors", instead of "fraud". Just because. The moment there's a hint of partisanship, the conversation is over. And really, at the end of the day, fraud is indistinguishable from errors. So just grit your teeth, for the greater good.
Focus on appropriations, aka follow the money. The very minor victories I've had were argued from a framing of good governance. Transparency, accountability, anti-waste, etc.
- Kemp controlled the election and was also a candidate[1]. He refused to recuse himself from his election duties. Why was that?
- Kemp purged more voters than anyone else in history[1]. His office then destroyed the evidence when an investigation was launched[2].
- A judge allowed an external audit of faulty voting systems used in 2018. The Republican Secretary of State objected[4].
1. Can you imagine a lawsuit being fair if the judge is the plaintiff? Or a football game being fair if the quarterback is also a referee? I don't trust any human to have that much honor and impartiality, especially if (in their mind) the lives of many unborn babies and the American way of life are at stake. Wouldn't someone like that think, "The ends justify the means?"
2. https://www.ajc.com/news/state--regional-govt--politics/vote...
3. https://www.apnews.com/877ee1015f1c43f1965f63538b035d3f
4. https://www.ajc.com/news/state--regional-govt--politics/judg...
At the very least, the voter purge and subsequent FBI investigation and lawsuit are not what you'd expect from someone who wants to help people vote, right?
We've also seen federal judges, including the Supreme Court, say that Republicans have been responsible for racial gerrymandering[1][2][3], unconstitutional ID laws to suppress the vote[4], and outright election fraud[5] all over the Southeast. Voter suppression by the minority party is logical and also a decades-old strategy, including a motivation for the war on drugs[1].
Why would Georgia be different? If the election were completely fair, it would have been an exception rather than the rule, and the state govt would reflect the population (majority Democrat) instead of being 100% controlled by Republicans.
1. VA: https://www.washingtonpost.com/politics/courts_law/supreme-c...
2. NC: https://www.theatlantic.com/politics/archive/2017/05/north-c...
3. TX: https://abcnews.go.com/Politics/supreme-court-rules-texas-di...
4. NC: https://www.theatlantic.com/politics/archive/2017/05/north-c...
5. https://qz.com/645990/nixon-advisor-we-created-the-war-on-dr...
This is also the state in which the ruling party committed election fraud in the last cycle, and got caught.
Nothing that is possible is out of the realm of possibility at this point.
This is pretty scary and I didn't know this occurred in other states.
DemocracyNC.org has made it very easy to email the NC State Board of Elections officials with a message in support of this amendment to provide voters with the security of a human-readable ballot. https://democracync.org/news/democracy-nc-ncsbe-decision-to-...
For excellent reporting on election security follow https://twitter.com/jennycohn1
I'm so sick and tired of stories like this framing the issue of election security as a software issue or hardware issue. You can mitigate software flaws with chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency. Most election systems in the United States employ all of these controls, which is why you have few stories of legitimate votes being discarded due to software failure or tampering.
If your argument is that paper ballots are more auditable or harder to hack, they are not. The same access controls above can be applied to paper, and paper is always susceptible to being destroyed, lost, or conveniently found in a clutch race. In Russia, cameras were provided at many election booths in a recent race and caught multiple instances of suspected ballot stuffing [0]. Paper products can be created at will and the requirement for ballots to be anonymous often prevents measures to prevent double voting or outright forging of votes.
Hackable machines are a problem, but they are not the only problem. Ultimately, it's easier to influence an election by discarding legitimate voters from voter registration systems, selectively failing to notify voters of elections, and other indirect interference campaigns that have been known to happen. Not only are hackable machines not the biggest issue, but they turn the camera away from bigger issues like these, which decreases scrutiny on the most vulnerable parts of the system.
Ultimately, if you vote in an election system, you must have something you trust in the system. You need to be able to trust the body running the election, the individuals that makeup the body, or the system elements itself. If you trust the government then you can be certain that collection processes happen correctly. If you can't trust the government, why do you think trusting the terminals that collect votes is any better? It's like trusting your child to bring home important documents from the school about their discipline. Sure, the paper might be tamper proof or tamper evident, but if your child throws it away it's pointless [note 1].
[0]: https://www.youtube.com/watch?v=pH7uXZQsyHI
[note 1] The analogy breaks down if you talk about electronic records, and assumes that the child is the "higher authority" bringing the documents to you. The point is to demonstrate that tampering with reporting is much easier than tampering with the record collection.
They might not be the biggest problem, but they're definitely an _extra_ problem. I don't see what problems they take away, in exchange for bringing this extra problem.
With a paper ballot, I can go to the polling booth, see my vote being counted, and see whether any other funky stuff happens, right there. It's all in the open. This in turn gives you extra trust in the system.
With an electronic system, how do I know what happens behind those layers of abstraction between the user interface and the hardware? How can I in any way verify that my vote has been counted?
What do you mean you see it counted? I don't think I've ever voted with a paper ballot.
> With an electronic system, how do I know what happens behind those layers of abstraction between the user interface and the hardware? How can I in any way verify that my vote has been counted?
The best I've seen is a verifiable electronic system with a paper trail. After a voter records their vote electronically, they're shown a "receipt" of their vote to verify it, and the "receipt" is stored securely and anonymously after the user verifies the vote. If the receipt doesn't match their inputs, a red flag can be raised immediately. After the election, the paper records can be used to run a stop-loss audit to verify the electronic vote count. The redundancy has an added benefit -- you're increasing the surface area of the attack itself, and by adding a physical element, you can capture bad actors on camera.
You can't do this. Probably the most fundamental problem with electronic vote verification is that you cannot give someone physical evidence of how their vote was cast, because it makes voter coercion feasible.
Its why almost all absentee / write in ballots are set up so that if you send multiple ballots only the last one is counted (or an in person vote if you give one). If someone tries to coerce your vote and use the absentee ballot as proof unless they keep you imprisoned until the election is over they can't prove you didn't resubmit / go in person to change your vote.
With receipts for in person ballots the only way to defeat coercion is to make it so you can, at the point of receipt, get issued an intentionally flawed receipt. But if you are verifying votes this way, it would have to be for another legitimate voter voting the exact way your coercer wanted. That sounds like a hugely limiting technical flaw.
There are machines that print paper receipts to voters (presented under glass so voters can verify), and then drop the receipts into a traditional lockable ballot box. The voter cannot access the paper ballot without evidently tampering with the machine; the only issue is that you'd need a way to get poll workers the ballot at issue without identifying the voter.
Some countries try to solve this with an extended voting period and by making votes repudiable / changeable up until the end of the election.
Another solution is generous whistleblower rewards and significant criminal penalties.
There are tools outside the ballot box to prevent crime, and extortion is a crime regardless of whether there's an election going on or not.
(If you bake deniability into your system, you lose the ability to let voters prove to others that their vote was miscounted, so receipts lose a key feature at that point.)
Like you, I would have zero faith in an electronic voting booth that simply said "Yup, you pushed a button." I have no idea what actually gets "written to disk".
And altering the count more than a percent or so is a LOT of alteration.
And that also brings us back to an earlier comment about driving turnout (or lack thereof) is possibly a larger problem than tampering at the polls. If a party (or somebody acting on behalf of a party) can convince a significant block of voters to stay home, that's more likely to have an impact.
There is no difference between making a cross and pushing a button, except that the cross is unique. (There's a case where a guy made a huge anarchy sign on the ballot paper and it was a valid vote because two lines met for a candidate. This is also a thing btw. people should be free to vote as they like. They should be allowed to write in someone else, write "fuck", or draw a huge dick, whatever. Invalid votes are an important part of the electoral process as they signal decidedly uncontent voters.)
I mean especially considering the US, it is beyond ridiculous that this is even a discussion. You guys spend upwards of 2 billion dollars on presidential elections anyway, and then get up in big discussions over a few million dollars on election security.
What is your concern with how our country spends its own money? Where do you live, and let's scrutinize that system like you judge ours?
And in this case, he's right. We spend an absurd amount of money on political campaigning, but then get lost in the weeds, and/or hand-wavey, when somebody wants to discuss election security. There are legitimate criticisms of how we process elections.
"Election security," as in mandate, at the federal level, what the states do? Centralizing power (maximizing the possibility of a single point of failures) makes elections more vulnerable. Voting machines are air-gaped. Our elections were influenced by propaganda on social media, just like the Arab Spring.
Evaluating actual 'cause and effect' is helpful when trying to understand situations.
No, that's not campaigning, at least not officially. But, adding those into the mix makes the money spent even more ludicrous.
As for federal mandates, I'm not sure I agree. Right now, states have nearly complete control of the election system, with vastly varying levels of competence. I'm not sure I'd want the federal government mandating which specific machine to use, but I'd love some consistency across states. And also some mandates around vote-by-mail and similar systems.
Air-gapping voting machines only does so much good when nobody outside Diebold knows what the machine does on the inside.
With ballot stuffing and voter manipulation you maybe able to _possibly_ affect votes, but with hacking, you can practically just pick the outcome you want and be done.
We shouldn't be so easily duped anymore, we've seen to much come to light to pretend this isn't completely real, and most likely much, much worse than we know.
As for throwing away ballots, again, in the USA there should be video evidence of such possibilities.
I was helping out in Denver for one of the elections, might've actually been 2012 or 2016. They had cameras everywhere and they should.
Paper > paperless. Seriously, there are reports/studies about this. It's common sense. You don't contrast how paper is better than paperless. Are both flawed? Yes but one is a dumpster fire of issues where the other can be fully audited and accounted for.
Humans have been doing paper document chains of custody since the ancient Chinese and the Romans. It's not rocket surgery.
And people have been figuring out ways to get around these impediments since their advent. It's not as if voter fraud started with computers.
I'm not saying that computer voting is superior but I think you are overstating the security of paper voting systems.
Ballots, whether sealed or unsealed, blank or marked, must have at least two people present (from different parties) for all handling. At the end of the process, it should be possible to account for every ballot, marked or blank, and know who handled it (except for the individual voter), from the moment it was received from the printer to the moment it is eventually destroyed. Counts should match at every level, from the printer to the distribution to the voters to the number of ballots in each locked box. Every box can also be traced to an individual machine.
Assuming this is done, where do you fit fraud in? I see three paths for fraud - adding ballots, removing ballots, and substituting/altering ballots. How do you add or remove ballots without upsetting the counts? How do you substitute/alter ballots without breaking seals? And mind you, the techniques have to be able to a: survive a recount, and b: work at a sufficient scale to meaningfully alter the election results.
The way to break this isn't the weakness of paper security. It's to undermine the chain of custody itself, do have the kinds of sloppy processes endemic to Florida, Ohio, etc.
It might still be possible to interfere with those, but it's much more difficult than electronic voting machines, which can in some cases be manipulated over the internet, or very quickly by a voter who exchanges memory storage units.
And more generally, if you are already trusting said election commission to do the counting by being in a partisan staredown the same principle would apply to said commissions scrutiny over voting machines. If the parties are balanced enough in power to insure no one is stuffing the ballot behind anyone elses back they can probably mutually conclude if an electronic voting machine is safe to use for the both of them.
Its worth mentioning and considering that, even in those coalition election commissions, both parties are incentivized to discredit third parties any way they can. They share a duopoly of power that they are both in their own self interest to protect, and I do not hear often about third party oversight of election commissions. Why do you trust them on that front, then, when their incentives are entirely aligned against being truthful?
I get GP's argument that hackable machines isn't the biggest issue, however it's still a clear and present danger.
Where I'm from, the paper ballots are in a transparent box, you can stay there forever / be the one who does the counting of the ballots, and you need two locks that are given to the two frontrunners parties.
Yet the possible impact of subverting it once is incredibly large. Paper ballots are not unhackable, but they do require a conspiracy. People have to turn up and take physical actions which can be comprehended by most of the general public.
Everything can be manipulated.
https://www.google.com/search?q=ballots+found+to+sway+race
https://www.google.com/search?q=ballots+found+in+dumpster
Name for me one instance where either of these caused a major investigation, other than that one Presidential election count in Florida.
And besides, "countless stories" are just stories. Show me one that's been investigated by responsible, neutral journalists. Just because everyone knows it's true doesn't mean it's actually true.
I'm fine with sources like CNN, NYT, etc. I'd be even happier with Reuters, or the Economist, or something like that.
With these zero paper systems, there is no observability. Even if everything is sealed, you don't know what the software inside is doing. You probably don't even know what software the device is running, because the machines are stored in some warehouse for months at a time, with who knows who having access to them.
1) "... and other indirect interference campaigns that have been known to happen" Curious if you have links for these? The more I've learned about our election systems, the more I've suspected these to be highly vulnerable, but I hadn't been aware of known interference.
2) I believe Colorado has, generally, strong election practices. Given that "chain of custody" occurs at the county level across the US, and that a single county can sway an entire national election, could we not suspect that a single bad actor (or small group of bad actors) could intentionally modify the polling record? And that this is much harder to prevent & detect with purely electronic ballots?
3) Does chain of custody prevent attackers from altering the records of a voting machine in a voting booth? eg; accessing USB, other ports, or wireless connection?
Election security is certainly more than software or hardware. But I'm sick and tired of jurisdictions that permit paperless votes, because by definition they are insecure.
> You can mitigate software flaws with chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency.
Not true; none of these mitigations work. If the software is malicious, it can receive one input and produce a different result. Reviews of source code and even machine code are not enough, because you don't get adequate confidence that what was reviewed is what was run. "Tamper proof" seals don't help, because the malicious code could have been what's installed in the first place, and hardware can easily report "what you expect to see" while running something else in practice on election day. In most cases the source code isn't even available for public review & scrutiny, so there's no possibility of enough transparency even if you could somehow be assured of what code was run.
When I was a kid I liked to do magic tricks. I bought cheap plastic devices that looked like they did one thing, but in actuality did something else. Modern DRE systems are just a magic trick device - they'll do something, but not necessarily what you think they do.
> Most election systems in the United States employ all of these controls, which is why you have few stories of legitimate votes being discarded due to software failure or tampering.
You hear few stories because there is no effective logging, and therefore no way to report failure or tampering.
> If your argument is that paper ballots are more auditable or harder to hack, they are not. The same access controls above can be applied to paper, and paper is always susceptible to being destroyed, lost, or conveniently found in a clutch race.
Paper ballots are subvertible, but because they are physical items someone has to physically be there to do the manipulation. There's also a long history with paper ballots, so the ways they can be subverted are known - as are their countermeasures.
> Hackable machines are a problem, but they are not the only problem. ...
It's true that these machines are not the only problem, but voting systems are systems. For voting systems to be legitimate we must address all parts. Direct Recording Equipment (DREs) subvert the entire voting system, and thus should never be allowed to be part of one.
I take "secure voting" to mean a process where every participant can later individually audit that their vote was counted without betraying the confidentiality of any other voter.
For that, what would you think about a system where the election board published all the votes after the fact without any names, but placing each vote alongside a secret, a key, shared with that voter?
So, as a voter, I could perform a few operations on this published list of results. (1) I could search for my row indicated by my shared secret key to confirm my vote was recorded correctly. (2) I could add all the votes to confirm election officials added all recorded votes. (3) I could confirm that the number of rows is equal to the turnout reported on the day, possibly by district, so no ballot boxes could suddenly be lost or added after the fact.
> If the software is malicious, it can receive one input and produce a different result.
Sure, but all of cryptography is about solving for bad middlemen. The trick to secure multiparty computation is forcing the system to show enough of its work to verify, like above. Just publish the votes with the individual voters strongly masked.
Part of me worries that any voting system without public key cryptography is insecure, but our standards are so low we're just settling for paper, assuming that's the best we can do.
But I'm not sure what attacks paper advocates are trying to prevent, so I'm probably missing something. If I think my local election officials threw out my vote, how do I use my receipt to detect that from home?
But I agree with you if your main points are: 1) Current electronic implementations are terrible. 2) Paper never hurts.
N.b. - Vote selling could be an issue with either paper receipts or my protocol above. The best solution for either is probably outside the system (criminal penalties and significant whistle-blower rewards). You might be able to add deniability to the toy protocol above, but things would get complicated.
A good summary of the problems and how to solve them is here:
If we can't do that, then no system can guarantee us anything. If we can do that, then the system doesn't matter.
I'm familiar with VV. I completely agree with their position that post-election audits are critical to ensuring trust in the system. (That's a weaker version of my own requirement above.)
However, their latest policy recommendation was that we must keep hand-marked ballots, which is just bizarre to me. That's the sort of policy you endorse if you want elections to be decided by teams of lawyers debating stray marks and creative misspellings to deduce voter intent. It's a good way to let money break ties in elections, and makes me question VV's impartiality or judgment on these issues.
They have repeatedly linked to outside teams of researchers covering end-to-end verifiable systems though. A thorough read of the research notes that while there are a number of challenges to overcome, end-to-end verifiable could provide a path to secure elections.
The downside of that is that such systems generally enable bought votes and extorted votes.
> Vote selling could be an issue with either paper receipts or my protocol above. The best solution for either is probably outside the system (criminal penalties and significant whistle-blower rewards). You might be able to add deniability to the toy protocol above, but things would get complicated.
Extortion and bribery work against individuals some of the time, but using it against large groups of people hoping not even one of them will alert reporters or police?
Not to mention, this is a flaw in the current voting system, because people can easily sneak phones into booths to take video of their votes.
Being able to confirm that your specific vote was counted should be considered a basic human right. If you look at it that way, it feels strange to deny people a basic right to protect against some harm we don't currently address now, but could easily address in other ways.
No, not if that means that many people cannot safely vote. At one time it was considered a right in many jurisdictions that everyone could know what everyone else's vote was, and votes were public. This enabled the local landlords to ensure that bad things happened to people who didn't vote the "right" way. Many vote-confirmation systems allow others to verify the vote as well, and the historical record makes it clear that this can be very dangerous.
Currently we can't even verify that votes are counted correctly at all. We currently allow people to press buttons and then have an unverifiable machine report what its owners want the vote to be, without any reasonable way to verify it.
It's great to want much more, but let's start with the basics. Having a way to verify that the counted vote is the actual vote is that basic.
In major cities like Moscow or Saint-Petersburg, there are many activists that work as observers and just their presense helps to prevent fraud. With electronic voting, they wouldn't be able to do anything, except for verifying that reported turnout matches the number of people who visited the polling station.
I think that main threat for elections is the government and election staff. They have uncontrolled access to voting machines and can tamper with them. Maybe in Western countries it is impossible, who knows, but in my country paper voting is more transparent and auditable than electronic voting.
I emphatically do not trust the voting system used locally, but what is my alternative, really? It's not like the people for whom I am voting actually have a snowball's chance in Gehenna in this blood-red state with gerrymandered districts and independent-annihilating ballot-access laws.
Hackable, unauditable machines are just another load of fuel on the fire, when I feel as though I have never been faithfully represented by any elected official. The game is so thoroughly rigged before the voting happens that it hardly even matters how we cast the ballots.
It's also true that errors (aka fraud) happens with the machines.
Just one example: Voter Action proved in court that New Mexico's touchscreens didn't count Spanish language ballots in 2004. Kerry would have won the state.
Paper ballots cast at poll sites tabulated when the polls close is the best available system. Our gold standard (per the Election Verification Network, which is everyone).
By comparison, any digital tabulation system is irredeemable.
" you must have something you trust in the system."
No. You don't.
Our very form of government's balance of power is built on mutual distrust.
The only system I "trust" is when all the belligerents mutually certify the results.
Well, duh, this isn't happening in real democracies. Americans really need to get rid of their delusions regarding the form of governance they live in.
The problem with voting machines is that it makes it so much easier for a single entity to control the election. And that the people organizing the election are completely technologically illiterate as well as the huge majority of the electoral. If you can hide behind techno mumbo jumbo and plausible deniability it gets ever easier to manipulate the electorate in failing to see a problem.
They used admin as a password in voting machiens in the US, and the same company still holds contracts. The whole notion is beyond laughable.
I see it constantly here on HN when there's a story about privacy and there's countless comments suggesting how you as an individual can do some jury rigged thing to protect your privacy.
Politics, policy, and law never enter their brains.
Do you really not see how that’s a big deal?
Does closed source software allow for any of that?
- The chain of hardware custody is difficult: did any components come from China? The chain of software custody is similarly difficult: are the dependencies disclosed at all? Who wrote all the components it uses? At least paper won't surprise you
- Poll watching and judging still involves a handoff to a black box. The poll watcher and judge cannot confirm or deny that the software or hardware performed as expected.
- There is no transparency with closed source software, period. It could be doing <X> and we wouldn't even know it - until it was disclosed, sort of, in an impossible to understand TOS document that was just updated. This is the entire story of the scandals facing tech for the last 10 years or more.
There's no feasible way for a voter to verify that a machine they're voting isn't compromised without giving people ludicrous levels of access to the machines. (Way more than just a USB port) Never mind the fact that almost no-one has the ability to do this verification anyways.
As I’ve mentioned in a previous comment:
This is survivorship bias. Instead:
1. Assume that there are enough high-powered actors to want to rig an election
2. Note that confirmed case of a rigged election happens through paper absentee ballots
3. Note that there are very few known cases of a rigged election happening through electronic voting machines.
4. One probable conclusion is that election rigging is possible and undetectable through electronic voting machines.
In Canada we vote completely anonymously on a piece of paper. ID is verified at the entrance to the voting area, but your identity is _in no way_ associated with the piece of paper you mark your vote on. The ballots are counted by hand with numerous bystanders/observers of whatever affiliation. It just works. We have no need for digital (aka hackable/tamperable/buggy) voting system.
Global News has a decent article outlining why the system is so impervious to abuse: https://globalnews.ca/news/4049932/canada-2019-election-hack...
Voter ID, for example, is contentious because a state can influence election turnout through decisions on where ID offices are located and when they're open.
Edit: I always find it ironic that the Republican party--the party of limited government--wants people to have to go to the bastion of efficiency known as the DMV (!!!) in order to vote.
> The U.S. Supreme Court rebuffed a Republican bid to revive a strict North Carolina voter-identification law that a lower court found deliberately discriminated against black voters, handing a victory to Democrats and civil rights groups.
> The appeals court found that the law’s provisions “target African-Americans with almost surgical precision” and “impose cures for problems that did not exist,” concluding that the Republican-led legislature enacted it “with discriminatory intent.”
[0] https://www.snopes.com/fact-check/north-carolina-voter-id/
P.S. You must have a valid passport when you reach a certain age.
If you cannot make this assumption, then you are actively disenfranchising people.
You can achieve the same result by not requiring an id to vote.
Also, young people cannot buy alcohol and cigarettes without it (to prove that they are adult) so some of them are motivated to get it as soon as possible.
Here is a Wikipedia link in case if someone didn't hear about "internal passports": https://en.wikipedia.org/wiki/Internal_passport
As long as the process and cost is not punitive and targeted it's fine if something costs time and money. We have multiple constitutional rights that are burdened in that fashion. The right to petition the government, to have courts decide arguments, to own a gun, all cost time and money. (Not to mention that I have to have a photo ID and pass a criminal background check every time I buy a gun.)
Keep in mind that DMV and RMV office _assume_ that people have vehicles. In the case of voters this is not the case.
It's like gerrymandering but in this case what's being manipulated is the ability of voters to get these cards. In many cases it is racist.
Getting a photo ID is a infrequent event. That makes gaming the ID acquisition process a means of disenfranchising voters ineffective.
Your next thought might be along the lines of accepting expired ID for voting purposes. That's an interesting idea but unlikely to be accepted. In Massachusetts, for instance, you can't buy even a six pack of beer if you cannot produce a valid driver's license. Expired licenses are as good as no license at all in that case.
Thank you for asking the question, I had assumed these cards lasted as long as a driver's license and that is not the case. :-)
You make a good point in that these voter ID cards might have a longer expiration then a driver's license. To my knowledge the expiration period of the ID isn't a part of the legislation. In that case we can probably expect to see the length of time vary from state to state. In that case I would suspect that state's with a shorter valid period might be trying to manipulate the number of legal voters.
https://blog.massdrive.com/2012/03/26/renewing-your-license-...
Still, the life span of these cards could be managed for political gain. Perhaps if the majority part in the state house changes, the valid lifetime for only the ID cards could be shortened.
The U.S. sounds more and more like a dystopia to me. In Germany having an ID is a matter of fact, you get a new one every few years and they glue an updated adress on its backside when you change your main adress. The times when you can get it updated might be inconvenient but you are required to have a valid one, so you just have to spend a vacation day every few years on it - the horror.
> In many cases it is racist.
How about trying to improve on the current state of afairs instead of complaining while keeping the barndoor wide open so the racists can continue doing as they currently do?
> Germany having an ID is a matter of fact
Having an id as a matter of fact sounds more dystopian than a country where you aren't required to identify yourself at any given time.
The last time I had to deal with the police they just asked for my drivers license. Evil dystopian government keeping track of people who drive past red lights. Even in the U.S. you can't escape that.
If you contrast that to a country that has government mandated ids just because, then that's clearly the more dystopic example.
I very much think the right does attempt to exclude certain voters, and does use Voter ID regulations as part of a larger strategy regarding voter disenfranchisement. But it is a relatively easy fix that could be calmly resolved with common sense regulations, like other commenters in this thread have mentioned regarding requirements for physical location and hours of operation for voter registration/id centers. So it sometimes appears people (in this case the left) would rather have something to cry about than just calmly fix the loophole the opposition is trying to exploit.
In brief, the real issue is that actual attempts to cooperate and govern have died, to be replaced by grandstanding (when not in power) and scorched earth practices (when in power). I blame first past the post systems, and think this is an inevitable result. I would welcome the existential requirement for political parties to cooperate which comes with a larger spectrum of parties in power, as a natural effect of more effective proportional representation.
As an aside, in the US, there's a history of not needing papers to get around or prove who you are. My grandfather fought in World War II and this was an important issue for him. There likely are people in the US opposed to a national ID card for similar reasons, fear that police will start demanding you carry your card at all times. I have no idea if they might be numerous or not.
It's easy to forget that about one in seven or eight adult americans don't have a driver's license.
I'm not an American and while I rarely have to produce an ID, going without one entirely would be impossible. Also illegal here in Poland but this law is not enforced because it's hugely impractical long before you run into any legal issues.
Even worse is that there is wide bi-partisan support to require people to go through the DMV for the ability to drive on public roads, something that impacts a person's day to day life far more than voting. This is especially true of the poor who cannot afford to uber and those located in areas without public transport.
I actually agree that requiring an ID that may require significant effort to obtain for voting is not reasonable.
If one accepts the argument with regards to a voter id, then why would they reject it with regard to a license?
Is it ironic? Republicans aren't calling for the abolishment of the DMV for driver's licenses. Requiring ID to vote is inline with requiring ID to drive.
I find it interesting the Democrats seem to idolize European governance, except for the part where requiring ID to vote is the norm.
edit: fixed typo - requiring id to vote is inline with requiring id to drive
Voter ID laws are simply an attempt to keep poor people and minorities from voting and honestly it's sickening.
Which is not a problem. There were less than 100 cases of voter fraud in the last twenty years: https://www.washingtonpost.com/news/the-fix/wp/2014/10/13/th...
Preventing ineligible voting is red herring for suppressing legitimate voters, by creating extra hoops to jump through for certain classes of citizens.
Republicans aren't calling for the abolishment of the DMV for driver's licenses. Requiring ID to vote is inline with requiring ID to drive.
Until then, IDs are a poll tax — and to put it mildly, that's a problem.
Sure.
>and mandatory for all citizens
And what are the consequences if you don't get this now mandatory (federal?) ID? Presumably some sort of passport card like thing that doesn't actually let you travel across borders. What if you don't have the documentation you need? What if you don't have the time to go to the offices that provide these IDs?
For a lot of people, the cost of getting the Equivalent ID to a driver's license isn't the big issue. All the other things are.
The reason should be obvious, people without ID are likely poor, and likely to vote for Democrats. Voter fraud is just misdirection on the part of Republicans.
Voter ID is required to register. At which time it is verified and eligibility is adjudicated.
Identity is confirmed when a ballot is issued. For postal balloting, which is not opposed by Republicans, your address is proxy for identity. One exception is North Dakota; no ID is required, because presumably poll workers know their neighbors.
The issue is what forms of ID are required to be issued a ballot.
Pro democracy persons who support enfranchising their fellow citizens are content to accept many forms of official ID to confirm identity.
Anti democratic persons who openly advocate wide spread disenfranchisement demand restoring unconstitutional poll taxes.
That is not necessarily true in the US. If I vote in person on election day in my town (I usually vote by mail or earlier at town hall) I give my address but do not have to present an ID.
You replied: "That is not necessarily true in the US."
Yes, yes, yes. There are always exceptions in the USA. No one person can know them all.
Because every jurisdiction is a snowflake. And everything keeps changing. Causing us all to talk past each other. No small part of the challenge talking about this stuff rationally.
For your jurisdiction, the powers that be determined that your signature was sufficient verification, which can be compared against the signature on file (your registration), just like with postal ballots.
Satisfied?
Which is just one state as you say. But, if you follow the news, requiring ID is a very contentious topic that's often associated with disenfranchising voters so I assume it's not the norm.
Universal automatic voter registration. Like every other mature democracy.
We now have a handful of complete rosters. Of everyone living and dead. Updated in near real-time.
We know with complete certainty if someone is eligible to vote.
We could just use any of our existing national demographic databases (NSA, Planitir, Facebook, LexisNexus, ChoicePoint, etc) for good governance. Instead of 50+ mutually incompatible chaotic mutant voter registration databases.
(Related: Just do a query, instead of walking around with clipboards every 10 years and doing a partial head count.)
Why don't we use the resources we already have to moot this issue?
Discuss.
Exactly this. Every citizen should be automatically able to vote without any effort on their 18th birthday. I personally think it shouldn’t even require being 18, but should be permitted if elections are happening during your 18th year, but you haven’t hit your birthday yet—nobody turning 18 in 2020 should be unable to vote for the next president just because their birthday is after Election Day. We should be doing all we can, on the public dime, to the point of begging and dragging people to the nearest booth to participate in their government.
I think post offices are the perfect first place to look to for handling this. Far more citizens live in close proximity to a post office than a dmv. And as needs require and areas permit, we can look to libraries, state universities, and community colleges as additional points where one can handle voting needs—even casting ballots.
One of those things is an inherent right of citizenship. The other is a privilege that requires proving one has allegedly mastered the skills and knowledge required to safely practice it.
What is the overlap between people who drive and people who can vote? How were the location of DMV and RMV offices chosen, were they selected to be accessible to every citizen? Who trains people at the voting locations to validate ID cards? Is there a physical device that scans and helps validate these ID cards? What does that cost?
Post offices make much more sense, they tend to be accessible by nearly everyone. But there has been no talk of providing these cards through post offices. Partly because of cost, training and the increased workload on the post office. Partly because the goal is to prevent voters from lawfully voting.
Even if you feel that the DMV or RMV is a reasonable place to issue these cards, where is the pushback from states who have to staff up in order to provide these cards? How long will these cards last before expiration? In MA, a driver's license only lasts two years, ID cards last five.
The whole thing, in my opinion, is an obvious sham.
"Your Massachusetts driver’s license is valid for five years, unless it is your first license which expires on your fifth birthday after the date of issue, or until the end of your authorized stay in the U.S. (whichever comes first)."
https://www.mass.gov/files/documents/2019/04/02/chapter_1.pd...
Also the verification process itself can be often biased or outright discriminatory (ie, registration polls being inaccurate).
https://www.youtube.com/watch?v=yW2LpFkVfYk
https://www.realclearpolitics.com/articles/2019/06/20/calif_...
Assuming it based on no evidence would be a form of prejudice.
Concluding that such a disadvantage exists bases on ample empirical evidence plus occasional statements of policy makers cheering themselves for preserving or advancing that disadvantage is not.
In Spain everybody has a mandatory ID, and it is very easy and cheap or even free to get it. In that context it makes sense to require an ID. In the US, for cultural reasons, there is a lot of reluctance toward a national ID.
While a driver’s license is the most common form of ID in the state, Bentley said anyone without a driver’s license can go to any county register’s office and have a photo ID made and the closing of the DMV offices will not change that fact.
Bentley also pointed out that every probate judge in the state has the authority to renew driver’s licenses and the closing of the DMV offices will not change that fact.
Bentley said not only is the state not engaged in any effort to curtail voting, it is doing all it can to make sure anyone who wants to vote will be able to register to vote.
“We will go to people’s houses to have their picture made if they don’t have a photo ID in the state of Alabama,” said Bentley. “We’re not ever going to do anything to keep people in the state of Alabama from voting. And for them to jump to a conclusion like that, that is politics at its worst.”
No it is not.
There have been less than a hundred voter impersonation cases in the last two decades: https://www.washingtonpost.com/news/the-fix/wp/2014/10/13/th...
Anyone saying that ID verification is a big issue is using it as a red herring, to create more hoops to jump through for citizens who have a right to vote.
In Canada, you don't actually even need an ID to vote. [0]
Two pieces of paper like your voting information card (that is mailed directly to you) and a utility bill with your name and address will suffice.
https://www.elections.ca/content.aspx?section=vot&dir=ids&do...
Now, same state, I get the ballot mailed to me, it has my name on it, it's bar coded, I vote, put it in an envelope, mail it back or drop it at a collection box for this purpose, and I get an email telling me I've voted. That kind of tracking gives me a frowny face. I don't know that they have a way to associated my vote with me, but they know whether or not I've voted, same as before.
Anyway, other states are different, where they have onerous ID requirements, including government issued photo ID, because the like that sort of thing. There's not much to be done about it.
are discrepancies between exit polls and election result valid reason?
A better option is human-readable paper ballots, as you can manually compile results from batches of ballots and run stop-loss audits on them.
https://www.kingcounty.gov/depts/elections/about-us/security...
it's angering to realize that some people will accept election fraud if it benefits them (while simultaneously decrying other unsubstantiated election fraud), regardless of moral or ethical concerns.
cheating to win is losing in my book. hopefully the long arc of the moral universe corrects the harms eventually, if not soon.
There are also more people in the US (around ten times more). You could still count votes by hand in US, but it would take more people or time to do it.
[0] https://electionsbcca.blob.core.windows.net/electionsbcca/re...
https://www.theroot.com/exclusive-thousands-of-black-votes-i...
Or how about a federal district court ruling?
https://electionlawblog.org/wp-content/uploads/georgia-dre-d...
We should really just go back to paper ballots, which are not perfect but are a lots less hackable at scale and are much more trackable than electronic machines are.
Still, better than touchscreens, if you can mandate audits and that recounts actually mean counting the physical ballots themselves.
This is not a vote of confidence for this particular method.
But you'd need mandatory random audits, and a legal requirement to keep the paper originals for up to years.
There's been cases of the paper ballots being destroyed while legal action was ongoing, and a never audited system cannot be trusted (because there's implied trust, not tested trust).
Routine double counting all votes would be controversial due to the high cost.
If the result is 49.999% vs. 50.001%, you cannot conclude anything meaningful about the will of the people. Maybe the weather was just slightly worse in a neighborhood supporting the losing candidate and it tipped the result slightly.
So even if the voting process is perfect, that close of a result is totally random for other reasons.
Most people don't seem to be capable of thinking about non-determinism like this, though. Witness the huge number of Americans who think the presidential election is illegitimate because Trump got 46% of the vote to Clinton's 48%, when honestly 46 vs. 48 is very little difference in terms of what they mean about the general will about Americans.
On the other end of the political spectrum, witness the amount of Brits who think a 52-48 vote to leave the EU is somehow relevant.
In calculus/analysis terms: this is why proportional representation parliamentary systems are better -- because the function from "how many people support which parties" to "what policies you end up with" is not discontinuous.
If the UK ran on a proportional system, they'd be getting some sort of very soft, Norway model Brexit. If the US did, a center-right Democrat like Clinton or Biden would be PM.
Paper ballots that are hand counted. Ideally, streamed live.
More seriously, France has paper voting, yet results are published at 8:00:00pm, closing time of the last voting offices. How? Statistics. And only takes the night to confirm, when we’re on a 50,3% kind of results. And it’s already 60m voters; If it works for 60m people, it will work for 300m (especially if only 120m vote in USA).
Or you publish all the marked ballots, so that anyone who wanted to could do their own count to verify the results.
You can also design this so that any individual voter can check to see that their ballot was included in the count, and counted correctly, without being able to prove to someone else that they voted for a particular candidate (so that vote buying schemes aren't enforceable).
See Scantegrity [1] for a specific system with these properties, which can be implemented on top of existing optical scan vote counting machines. For a more general look at securing voting, see end-to-end auditable voting systems [2].
[1] https://en.wikipedia.org/wiki/Scantegrity
[2] https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
Mandatory random audits are part of the system. We get automated counts from the Scantron machines, but those are unofficial, preliminary. On election night, there are random audits of some number of voting machines for hand-counts, to detect systematic fraud. And the total number of ballots in each machine is hand-counted to make sure it matches the totals given by the machine.
To use a metaphor, it's not having 2 locks on your front door, it's having 2 different keys that open the same lock.
Say you have a hybrid system, and the numbers come in and the electronic and paper counts disagree. Which one is used as the true vote?
If you take the paper, then what was the point of the electronic? If you take the electronic what was the point of the paper? If you throw out all votes where the paper and electronic disagree, you just enabled any "fraudster" the ability to disenfranchise any subset of votes by breaking either system.
You also can't exactly pick and choose which to accept per instance (could you imagine the abuse that could come from that!?), and methods of "averaging" them don't really solve the problem as much as they make it marginally harder to pull off (to sway 1% of votes in a 50%/50% weighted system, you'd only need to hack 2% of the electronic machines). And of course using a significant "disagreement" between paper and electronic to trigger re-doing an election isn't a solution either because if they hacked it the first time, chances are they can do it again. Not mention that having a second voting day because the first was taken over by fraud is going to be a logistical nightmare, it will change who can come out to vote, and it may even change who/what people will vote for.
If what you want is an audit or a second count, then call for more exit polls or an explicitly secondary system. But this whole dual-voting idea isn't really a good one when you really dive into the dirty details of how it would work.
I went to watch a count for the local elections in May in the UK (I was a candidate)
The papers were counted in front of me and dozens of other people from the various parties. I could see each one going into each pile of ten, each pile of ten being bundled as a pile of 100 and put into a basket, the ambiguous ones (blank, voting for multiple candidates, writing "WANK" next to all candidates but one (which had "NOT WANK" written next to it), went into a separate pile.
At the end of the counting the returning officer went through the ambiguous ones with the candidate or agent and explained if he would accept it or not.
This doesn't take long - it scales, and is fully repeatable by completely different people if needed. The problems that seem to occur are not in the count, but in the returning officers (who tend to be doddery old men) writing the wrong result down, and for some reason this result is final, but that's the same whatever the counting method.
Reminds me of the line from some American tv show where one character says "I don't vote, I just write down Jesus," and another says "we count that as a Republican vote."
https://www.joe.co.uk/politics/voter-writes-wnk-all-over-bal...
[0] https://www.google.com/amp/s/amp.cnn.com/cnn/2019/07/26/poli...
That's not complicated -- just post each vote in a different box (paper can be different colours) and count them separately. OK it may take a day or two to find out who your local parish councillor is. Whoopee.
You probably start to get fuzzy about your state rep/senator. And are pretty much clueless about the county Sheriff, Board of Selectmen, and Register of Deeds.
In practice, a lot of the positions lower down on the list are running unopposed or have been in their position and seemed to have done fine for a while. Of course, this being Massachusetts, a lot of these seats are pretty much Democrat locks anyway.
We tend to have 5 or 6 layers of government too so I don’t see the problem there.
I have no issue with European countries sovereign decisions, but when Europeans project their ideas on Americans I take great offense.
The whole electronic voting movement started because people had difficulty with ballots in Florida; a _good_ UI would help alleviate this.
You get the speed of automation with a paper trail in case you have to go back and audit.
EDIT for those replying that you feel voting should be anonymous. With anonymous voting, how do you stop the "hey we just found this box of filled in ballots" ala Broward County Florida every election? If you can't tie a ballot back to a voter, how do you know the ballot is legitimate?
Without a massive outreach program intended to reach all voters and supply them with convenient, free of charge voter IDs, and a system that can continuously and quickly resolve errors, such a "strong voter ID" would be unconstitutional (for good reason).
It's ridiculous to assert that it doesn't exist in practice due to lack of evidence when in reality pretending to be someone else to vote leaves virtually no evidence. You can't even begin to analyze the problem so its laughable for you to assert such things.
How often do any of these things actually happen? It’s all public record. The data is there for analysis. And yet nobody can point to more than a handful of examples.
It's especially ironic.
If it's happening at any significant rate, without perfect knowledge of which eligible voters won't vote (or have someone else try to steal their vote, which is just as bad for the prospective vote thief), it leaves quite tangible evidence in the form of people presenting themselves to vote under names that have already voted.
The absence of this occurring fairly strongly indicates that vote stealing by impersonation isn't a thing that happens at any meaningful rate.
If there was more than what vote theft operation in the same area, you'd still expect them to have collisions.
> 2 out of 3 people don't vote.
Wrong. A majority of the voting-eligible population votes in Presidential elections.
> If you have ever volunteered at a precinct you would know that it's literally just an excel sheet of names
A printed paper sheet, sure. Whether Excel is used in making it or not is immaterial (I assume it's generated straight from the voter database, which I hope isn't Excel.)
> and you're supposed to check someone off.
California state law requires the actual voter to sign in on the list; I would think that this is normal.
> It's very easy to check the wrong line
If it was a just a check off, maybe it would be easy.
> It's very easy to check the wrong line and your failsafe is easily explained away as a mistake instead of raising any sort of alarm.
Even if it was just a check box, you'd also need to have extremely lax procedures that all the poll workers and any observers were all in on for this basic integrity check to be routinely ignored.
Given the political factions interested in selling the idea of rampant voter fraud, you'd expect them to raise a ruckus if there were actual instances of this going on routinely.
You'd also have to either randomly mark off some non-voter (potentially creating a new instance of the problem) each time this happened or turn in a tally sheet where the count of marked voters didn't match the ballot count. The former would magnify the visibility of the casual disregard of integrity, the latter would definitely raise an alarm in counts.
Also, here in Russia, voters put a signature in the voters registry when receiving a ballot.
The common reply to this is that you need these documents anyway to work, to drive etc. This is true but ignores all the peripheral people you don't see. People whose roles in their family are support or who themselves are in need of support because of illness. Not all of them drive or work and they are citizens too.
It seems to me that the easier solution is to make public records free. Let the taxes you already pay serve to pay the salary of the peon at the printer. Then the people clamoring for us to check ID's to keep the "illegals" from voting can be happy and those people can be enfranchised.
There's no way to do that without tying the voter to the vote somehow. Why not hash the voter ID + a secret of your choosing and store that with the vote? Then, even if counting by hand, you can verify your vote was indeed cast for X candidate.
I would rather be able to verify that my vote was cast to the desired candidate than to have a strictly anonymous (but unverifiable) voting system.
EDIT: Mail in voting is skimmed with little to no risk. Oops, lost 1% of that zip code...
Assume a million votes are cast in an election. To move the needle 1%, you need 10,000 votes. And let's assume a single fake voter can realistically cast ten votes in different precincts, considering vote time and travel time (they can't just keep coming to the same precinct, for fear of recognition).
So you need 10,000 fake registrations, that must match real addresses, and you need 1000 people working all day at fake voting. One voter out of every thousand would be working for this conspiracy.
Now, you need to do this in complete secrecy. Nobody can talk. Nobody can gather evidence. They can't go to the police, or the media. Even one leak is enough to not only ruin the scheme, but create a nationally known scandal. And if it can be connected in any way to a particular political party, that party's name would be dragged through the mud across the country.
It's insanity. No one could safely pull it off.
You know what can be pulled off, though? Voter suppression. Make it much more difficult for certain categories of voters to actually vote. Such as poor people who might not have ID (or might hesitate to use it). Then, convince a large swath of the public - people like you - that this is about security, not suppression. That form of election manipulation is now seen as patriotism, not corruption.
I can see that happening maybe a few times, but it seems ineffective on a large scale.
If they already voted? "Oops, I forgot."
If they haven't voted and come in later, so what? You're long gone.
This may sound laborious and slow but it should be enough to block repeat voting, IMHO.
Edit: thanks for all these clarifications!
Thus, if they audit they can be sure the ballot was cast by a legitimate voter.
If you don't tie ballots to voters, you go full Florida where they just keep "finding" boxes of prefilled ballots.
You MUST tie a ballot to a voter if you want your elections to have any integrity at all. There is no other way to prevent double voting, voting out of precinct, etc.
Broward county, 2016 election. They found a box of filled out ballots at the airport return in a rental car trunk... never a word about it again. Same county, defying a judges orders, the police stopped anyone from entering/auditing the count under direction of then admin Brenda Snipes.
Guess who oversaw Bush / Gore recount? Brenda Snipes.
What is the definition of insanity again?
A lock generally needs to be stronger than the motivation of a would be thief. In this case we are talking about controlling the disposition of trillions of dollars so there probably isn't a lock in the world that is good enough.
Based on prior stories many of the machines aren't merely not good enough they are quite laughable and indeed often so old that no parts can be sourced anywhere because they haven't been made in decades.
Hand counted paper ballots are the only way to be sure, and elections are important enough to be worth it.
Nope. Ballots need to be anonymous. Otherwise you can be coerced into voting a particular way.
With anonymous ballots, you can just "Find a box of ballots" and have no way to authenticate that they came from actual voters vs fraudsters.
It continues to be implausible and easily prevented without de-anonymizing the vote or resorting to strong voter ID.
We regularly get precincts reporting more votes than are even possible given their total number of eligible voters.
Fraud in anonymous voting states is rampant here.
It was across both parties in multiple states wherein the "found" votes were heavily favoring one party or the other (a few were well outside 3 standard deviations from the current votes, even in areas that were normally not heavily favoring one side).
Any precinct reporting more votes than possible given the numbers of eligible voters is recounted. If the recounts can't manage to arrive at results that make any sense at all the entire precinct is ignored. Where's the problem?
Voter ID is entirely orthogonal to this issue. Tying ballots to a voter is not desirable, since it opens the door for voter intimidation.
Edit to respond to the "hey we just found this box of filled in ballots" comment: anonymous voting means you don't know how someone voted, but whether or not they voted is still public record. The number of ballots counted still needs to match up with the number of votes cast.
> Paper ballot tied to a voter via a strong voter ID + electronic counting is the best of both worlds.
Finally, the punishments need to be strong, swift, and decisive if something does come up as being wrong. You can't just be "oh well, mistakes were made with the hundreds of thousands of mis-counted votes/purged voters. What can you do?!"
No way. None of that. All the people responsible in such a situation should be investigated, and if found guilty punished. Otherwise, there will be no fear of trying to steal the elections, especially if the upside is big.
And those IDs usually require proof of residency and/or a copy of a US birth certificate, which can be problematic to acquire or prove in their own ways for the more vulnerable to disenfranchisement (such as the homeless) in our society.
If an election method cannot be audited, it cannot be trusted.
Note I said nothing about whether recountability is a good thing. It's clearly a good thing. Hence we should stick with hand counted paper ballots since machine counting introduces trivial ways to game the vote.
Just because Florida is unwilling to do it doesn't mean it can't be done.
To be fair, I believe that is not the case across the state, just certain areas (i.e. county level).
Florida's electoral incompetence and corruption (probably) handed the 2000 presidential election to Bush. Because of that, we wound up with the Iraq war, and a mind-boggling amount of American blood and treasure (not to mention Iraqi lives) wasted on lies. Florida's inability to conduct free and fair elections has tangible consequences on me as a Minnesotan. So yes, I want to impose some standards and values on their elections, because their elections lead to MY president.
I'm not suggesting a federal takeover of elections. I am, however, pointing out that some states, like Florida, are running elections so badly that it harms other states.
https://www.quora.com/Why-does-India-not-use-ballot-papers-f...
Paper ballot boxes are just as hackable at scale with those requirements.
For that to be any consolation, we’d have to unconditionally trust those who have physical access to the machine and tools/keys.
Such trust is not necessary with paper ballots because they can always be hand-counted with supervision from both sides of a disputed election.
A vote count given by an electronic machine has no such auditability.
> Paper ballot boxes are just as hackable at scale with those requirements.
“Hacking” a stack of paper, e.g. ballot stuffing or destroying ballots, is something people can see happen. It’s not impossible, but it is very difficult to do out in the open with security cameras and the public there to watch. Not to say it doesn’t happen, but you tend to make a much bigger mess doing it.
That assumes they aren't replaced at some point. For a nation-level election this is probably too difficult to significantly influence an election but at even a state level it's relatively doable with a little coercion and/or carefully placed individuals even in 2019 in the United States.
You also have the option to do voter impersonation in states without voting ID laws, again this would mostly only work at a more local level.
https://www.heritage.org/voterfraud documents 1052 CONVICTIONS of voter fraud in the United States with 1,216 proven instances.
Outside of the United States there are all sorts of examples, including standing out the polling places with force to let people know vote our way or we'll shoot you.
Have you never heard of bribes or threats? It happens with juries, I imagine it happens with poling places, and I imagine some of those convictions involved exactly that.
If you've reached a point where you are willing to tamper with an election, greasing some palms or finding something to threaten key people with is not going to make you lose a single wink of sleep or have any mental reservations or other hesitations. People like money, like a lot, and if you haven't the funds to bribe them with the 21st century offers a horde easily discoverable information about people and those close to them.
Also, with presidential elections in 2018, there were no prior notifications and the government didn't know who was going to become an observer before the voting day, which was nice.
Sadly, you cannot become an observer by yourself, I don't like that.
I haven't heard about bribes or threats, but there were cases when an observer was taken away by police for allegedly being too loud and obstructing the voting. In recent elections, independent observers used a Telegram chat for coordination, so that they could ask for consultation or ask someone else to come to the polling station if something happened.
In Russia fraud is usually committed by election staff who often are public school employees, social care or government workers, people who are paid by the government. And typically they prefer to falsify results when there is no observers, they don't want to appear in Youtube videos.
Of course, in other countries the situation may be different.
The Russian Revolution established a control-freak government that hated freedom; Lenin was a self-annointed genius. The USSR failed because the incentives were misaligned.
My grandparents immigrated from Russia when their parents saw the pogroms in the 1890s. Using scapegoats, promising free stuff, and fear mongering is over 100 year tradition. Emotion and anecdotes over data.
[0] https://www.nytimes.com/2019/07/27/world/europe/moscow-prote...
But this allows us to see what measures to ensure transparency work in such circumstances and what don't. We see that independent observers and paper voting at polling stations help to prevent fraud and electronic voting would be completely opaque and uncontrollable.
I'm sorry to report that I feel your government is at war with my country.
Holy whataboutism. Yes Russia is a far cry from a healthy democracy but that has no bearing in any way on paper ballots. You seem to have just changed the subject entirely.
So simple, so effective.
Hack paper ballots: bribe the multiple people, including representatives from each party who cares to send one, to look the other way while you steal a box full of paper ballots and substitute your own.
It’s not impossible, but it’s much harder to mess with paper ballots at scale and much easier to secure them.
How can you trust that the machine will behave as you expect in a "real world" setting, when the results truly count?
IMHO, the biggest risk from electronic voting machines isn't some rando swinging the elections with their 1337 haxx0r skills: the biggest risk is that the machines basically come "pre-hacked" from the factory - either intentionally, or unintentionally (bugs happen).
Unlike electronic voting, paper ballots are much more difficult to manipulate. If a voter has marked a box for candidate X, you cannot change it or ignore it if there are observers. An observer can verify that voting goes according to the rules and votes are counted properly. The most popular way to "hack" paper voting is to organise groups of people and ride them on a bus from one polling station to other so that they can vote multiple times, but it is more difficult to do, and easier to spot than simply replace the firmware in a voting machine.
In the case with an electronic machine, you cannot see what's happening inside.
You have the option to mail in your vote or to vote in an advance poll, but these options close a week before the main poll, so if your name appears on the list at your polling station, they're pretty confident you haven't voted yet.
Assuming there is no external IO such as USB or Ethernet, someone would have to disassemble the machine and solder a programming header in order to re-flash the device.
> to disassemble the machine
Is it that difficult?
A successful voting process both accurately counts the votes, and is trusted by the people. Computers can count, but they are not seen as trustworthy by the people. Paper is more understandable and trustworthy. Even as a computer programmer I'm not sure I can trust electronic voting.
Thus, even in the absence of any actual hacks or fraud, electronic voting is inferior at a primary objective of the voting system, being understandable and perceived as trustworthy.
No they arent. You need one guy with physical access to to a machine, at any time, to screw an election, with manual counting you need everyone in the room conspiring to rig the election during the voting hours. With the possibility to volunteer to count votes and publishing the voting numbers for each voting station, you just dont get those situations.
I know its an unpopular statement, but having a democratic election is not a new problem to solve. Most western countries do it just fine. This is not a problem with the concept of paper ballots but a absurdly broken system.
Let's say your parks department were headed by a libertarian guy who vehemently opposes using public funds to fill a landfill and turn it into a park and he finds out his deputy voted for the ordinance to spend the money on said park. He could retaliate.
Another hypothetical could involve your local councilman finding out which members of his district voted for him and which didn't, and using that knowledge to influence who's streets get priority when plowing snow this winter and which don't.
Any voting system, including those based on blockchain, should be designed in such a way that disclosure of someone's vote is entirely up to them.
in-person paper voting doesn't suffer from that problem, because you walk into the voting area, write your vote on a piece of paper, then you yourself place it into the box, and you can then stand there and watch the ballot box with your own eyes until they are counted, at which point you can count along.
There are bound to be loads - Facebook comes to mind. If you think of human rights and climate change the list of technologies is going to be long. Energy production and the arms industry are some standouts.
If it was like voting machines, you’d have massive initiatives to run everything on plain HTTP and any suggestion that we should all use HTTPS is completely ignored.
North Carolina currently is facing two issues:
1) the state Board of Elections will vote on Thursday to increase the standards for certification which will hopefully lead to hand-marked paper ballots for all (except those with disabilities).
2) HB 19, which will delay decertification for insecure voting machines that roughly 1/3 North Carolinians use. This bill passed unanimously in the House.
If you live in North Carolina and care about this issue, please email Damon Circosta (damon.circosta.board@ncsbe.gov) with your viewpoints as he is the new, tie-braking vote on the board.
Additionally, call your state Senator and tell them to oppose HB 19. The bittersweet news is that it doesn't look like it will get taken up this year because of the budget standoff, but it's better to start fighting this battle now.
I strongly believe using the postal system for everyone’s votes is an ideal solution. It’s distributed, already exists, is convenient, etc. Oregon’s voting is great.
10 years ago when I was in school, we took standardized tests using Scantron forms (https://www.scantron.com/). It's basically a piece of paper that can be run through a machine so the results of the test can be measured.
Something like this would still retain the benefits of an electronic system, while also leaving behind a paper receipt that can be stored separately from the electronic results in case votes need to be audited / recounted, etc.
Paper ballots (with electronic tallying) is also not susceptible to things like power outages, networking issues, software bugs, etc, since you'd always be able to fallback to the paper ballots if a component of the electronic system fails.
Side note: if I had to guess, the biggest risk with paperless machines is the possibility of software bugs that skew the results in unexpected ways. I would love to know what kind of quality checks + testing goes in to voting machine software... can't imagine how to test a system that's only used at full capacity on 1 day every 4 years.
Average Joe can understand, easy to audit. It seems like the best way to do it.
This is comical FUD.
What makes people think paper is safer? The paper copy you have is worthless since you can counterfeit it, and the one in storage can be replaced or falsified just the same. A secure system can be designed regardless of the storage media - i.e. a digital one can be as safe or safer than paper. Brazil has used electronic voting for decades now, and despite accusations (by the winning party!) there has been no proof of tampering or exploitable security flaws.
Attempts to insert extra ballots will be detected by the count. Attempts to substitute ballots would have to match counts exactly, and somehow be done without being seen in a room with multiple other judges and other people.
I bring this up not to criticize, but to put those who think that paper ballets are impractical in a bit of context. Of course you'll be begging for electronic systems when all of your voting is done on a single day and you vote for who gets to be the janitor.
Too much to vote on doesn't seem to be a thing.
With that a fraudsters model have to deal with random checks by any voter.
Are you going to rely on the same system or perhaps another equally compromised system to "randomly" select votes for you to check and how do you propose to check them if you don't know how the person voted?
I would go so far to say that there exists mathematically no solution to this problem that doesn't violate voter anonymity.
It's absolutely imperative that after you leave the ballot box, noone has the ability to verify what your particular vote was, and you don't have the ability to prove to someone else that you really voted that way, or that ability will be abused on scale, by local "influencers", employers, etc requiring the people to demonstrate that they voted "correctly". The mixing up of ballots in the ballot box is a very important feature for the elections.
Not at all; the parent said "taken into account in the final tally", not "see that their vote was counted as they intended".
This is very similar to the system for paper ballots, with a tear-off receipt. If you type in the ID number, you can verify that that ballot was counted. There is no association between identity, vote choice, or ballot ID.
And it's not just a theoretical possibility to observe - I don't know how USA does it, but for my area the counting at each district is generally observed by multiple people, including (but not limited to) the representatives of all serious parties.
Everyone has different levels of trust, and I'm sure generally the chance of some grand voting conspiracy is very low; however, for me to fully trust the system I would need to be able to verify the count myself, and verify that my own vote was recorded correctly.
Personally this feels more important than some issue around buying votes etc. That is mostly illegal, and plenty of people find ways to indirectly achieve the same effect anyway...
I am not suggesting we vote on fuel pumps. I am simply pointing out that this appears to be an artificially created problem and not a technical problem.
I'm already not a fan of allowing places to do freebies for people who have an "I voted" sticker. If it takes a freebie for you to go out and vote, I really don't think you should be voting. And it's incredibly likely they'd just vote blindly for whoever is advertising more in the area.
Unlike donuts, I can imagine a situation where I would like to prove that my vote happened. We print out receipts for donuts, coffee, parking, all kinds of inconsequential things, ten times a day. But when it comes to voting - one of the most important transaction I'm going to do in a given year - suddenly, people are pushing hard for no receipt, no paper trail. It's transparent bullshit, obviously in bad faith, and when people start making bad faith arguments I start questioning motives.
Or maybe its just so obvious to technical people because we know how vulnerable and unreliable software can be. This XKCD cartoon sums it up pretty well:
A ballot is printed. It is then packaged, along with many of its siblings, in a stack. That stack of ballots is placed in a sealed package, and that package is given a serial number.
The state election officials receive this sealed package from the printer and record its serial number. It is then put in locked storage.
At election time, the package is taken from the warehouse and delivered to a polling place. At the polling place, at least two election judges, from different political parties, accept the package and sign for it.
The package is taken to a table staffed by at least two election judges, along with folders, pens, and "I voted" stickers. It is opened, the contents validated, and custody signed off by those judges.
Another table has printed rolls of all registered voters for the precinct, and at least two judges. When a voter arrives, they give their name (no id needed), and the judges look them up. They sign their name next to their registration, and go to the ballot table. Meanwhile, the judges increment the count of how many voters have signed in.
At the ballot table, our ballot (remember our individual ballot?) is handed to the voter in a folder, along with a pen and a sticker. The ballot is now in the custody of the voter, who signed for it in the registration book.
The voter goes to a booth, fills in their ballot, and inserts it in a ballot box. (This may be a Scantron-type machine that also reads the ballot.) Assuming automation, the box reads the ballot, tallies the results, and drops the ballot itself in a locked internal box.
At the end of the day, the judges write down the total number of ballots in the machines. They compare this to the number of voters who signed the registration. If these numbers do not match, these results are hand-counted again.
Assuming everything matches, the judges report the preliminary results from the machines (or if they are not machines, the judges count the results of the ballots). The locked ballot boxes are removed from the machines by at least two judges, and signed off.
Unused blank ballots, both opened and sealed, are also counted.
The locked ballot boxes are then delivered to state election officials, who sign off on receipt.
In case of an audit or a recount, each box can be traced to the individual machine and compared to the machine count.
So... what security problems do you see with this model? And what solution do you propose for the problem you see?
2. Publish results to the public Internet using the ID as an anonymizer.
3. Anyone who wishes to report that their vote was improperly counted or not counted at all can simply present their receipt to verify their identity.
Why is this hard?
Edit: obviously there are complexities when it comes to people who either misremember their selections, but I also see no reason you couldn't also have a copy of your ballot emailed or printed out for you from the voting precinct.
Polling places are extremely busy and people pull out their phones all the time. All you have to do is record you voting and you have the proof.
Someone called out above, unfortunately accurately, that a receipt with you voted for will greatly simplify vote buying. And with 30% of people not even bothering to vote, vote buying would probably be incredibly cheap.
1. https://jagranjosh.com/current-affairs/what-is-vvpat-machine...
We had a Secretary of State, whose job it is to secure and maintain the integrity of voting, run for governor but never stepped down from his office due to an obvious conflict of interest, insisted everything was fine, and of course he won.
How can we even remotely trust voting in my state when the impropriety is so thick, we can’t breathe. To this day, I do not trust his election or any in Georgia.
We could have done that with PCs and punch card machines, which have been around forever. No network required.
But companies wanted to make money and elected officials needed campaign contributions. So they decided on over-complicated solutions that we don't need.
Who are they? I'm not the one for deep state conspiracy or "our corporate overlords" stuff...but what is wrong with paper ballots? What is going on in American democracy?
Is it because it cost more money? It's a fcking election. One of the most important events in a functioning* democracy. Spend. The. Money.
Unfortunately, the US is NOT a functioning democracy in any sense of the word.
* Disgusting party gerrymandering
* Packed politicalized court system (esp. the Supreme Court)
* A broken voting system
* A broken Senate
* No limit corporate donations
* Anonymous super PACS
That's a long and hard list to fix. I doubt we will do it.Paper is the only way to do secure elections.
* Prior to election, all registered voters get a personal "voting card" sent to their home address. The letter also tells you which polling station you have been assigned.
* On election day, each voter goes to the polling station they have been assigned. You need your ID but not necessarily your voting card.
* Staff verify your ID and you go behind a blind where you put paper ballots (with the option to vote for a party, and, optionally, for a candidate in that party) in sealed envelopes, one for each level you are voting on.
* You go back to the staff with your sealed envelopes, staff mark you as having voted and put the envelopes in boxes.
* At the closing of election day, doors are closed, boxes are opened and ballots are counted at the location with multiple people overseeing each step in the process. The results of this counting is announced the day after as a preliminary result.
* Ballots then get put in tamper-proof bags and transported (again, with oversight) to a hub per district where counting is done again. Final results are announced about 10 days after election.
* Voters who can't vote on their assigned location on election day can vote in advance at any location. The process works the same, except the sealed envelopes are put in another envelope, together with the voter card mentioned above. These ballots are saved for election day, when they are counted together with the normal votes.
* There are also mechanisms for voting via mail (arguably less secure) or at embassies in foreign countries. The process is similar as for advance votes.
* The public is invited to be physically present to monitor the counting of votes.
There's zero machinery involved. The votes are anonymous, yet double-voting is prevented. Counting is done more than once by default. I understand from here that the U.S. is exceptional in that you can't expect registered voters to have a strong ID. I am sure some kind of strong voter IDs could be issued (for free, obviously) that can accommodate for that.
I can not imagine that doing manual recounting of votes and ensuring integrity with manual labor is significantly more costly than the contracts with voting machine suppliers. If it is, it's worth it. In my opinion, provably fair, free and anonymous voting is the killer app for blockchain. It is still a theoretically unsolved problem, however, and until we get there (if we ever do), machine-less paper voting is strictly better than both electronic voting and electronic counting of votes. If anything, the manual counting can be supplemented by electronic counting machines.
You think the U.S. is unique and this won't work because of federalization? We still somehow manage to pull off voting for European Parliament.
More info for the curious here: https://www.val.se/servicelankar/other-languages/english-eng...
remember it's not a popularity contest, it's electoral college
Of course they're also pro gerrymandering and disenfranchisement, so it does make sense...
In NYC recently I did some ecommerce. I paid for 5 delivery meals and 4 of them were stolen by the drivers. Amazon is full of fraudulent products. Banks in the US are full of loopholes, like ACH not providing sufficient auth. Trust in commerce and finances online are low. Systems fail frequently, and "only money" is lost by big corps usually, so it's not considered a big deal to the general public. I would not use that as a model for elections.
However, i-Voting does have the benefit of making it much harder to cause voter supression (assuming there's free ($) access to whatever provides access to voting).
I'm not sure electronic voting convenience is worth the privacy implications of having a full public ledger of who everyone voted for.
In my home country Bolivia, we are required to present a valid national ID to vote.
Others like you worry that, without ID, there will be lots of fraud. I keep hearing that there is not very much fraud, but I don't know how they know without a baseline that's verified with ID.
I also don't know why voter ID is too much of a burden, but IDs for gun purchases are not. If they are both rights shouldn't they have similar standards for checking eligibility?
Elections are audited and fraud is found in only very, very rare cases, hence the widespread confidence that voter fraud is a minuscule issue. Other election issues are very real. By any metric, the number of eligible voters who are denied the right to vote dwarfs the number of people who cast ineligible votes.
And how do they verify citizenship, or other elligibility requirements? Can you just specify a bugus address so they don't catch you?
https://www.realclearpolitics.com/articles/2019/06/20/calif_...
If we want voter ID laws, why not make it easier for everyone to get an ID first, and then enforce voter ID once that effort has succeeded?
Why would anyone be for this if not to subvert our Democracy?
I find it odd you are so concerned about a non-problem but not concerned about the actual problem of eligible voters being actually disenfranchised.
I also don't think that there are that many people that don't have IDs. I have seen absolutely no statistics on the topic, but I have seen multiple groups survey different parts of various cities and nobody had issues getting an ID. It's pretty much needed in almost any aspect of life.
You can't even get welfare or government assistance without some form of ID, so you can't tell me you can't get one to vote.
My point still stands.
Millions of eligible voters do not have state-issued ID. Estimates put it at 10-20 million Americans. The primary utility of a state-issued ID is to drive on public roads and there are 10's of millions of Americans who do not drive on a regular basis.
The suggestion you make, that we should make it easier for people to get IDs, falls apart when we recognize that every state sets up their own system of issuing IDs. It would take a very strong federal law to bring states in line to the point where we could have confidence that every eligible voter in America could obtain an ID for free and regardless of individual circumstances.
As for Russia "subverting our Democracy", there is zero evidence that Russia or any other foreign entity used the lack of voter ID laws in some states to influence any elections.
1. Create a blockchain app that runs as a web app. 2. Tie it to a persons Social Security Number. 3. Allow folks to download the app. Prove citizenship through a set of questions and cast a vote.
It's pretty clear what is happening. Given the obvious international attacks on US democracy in the last elections, it seems like a no-brainer that we'd have a bi-partisan effort to secure our elections. But we don't, and the side that doesn't want better election security is also the side that "won" the last election, while it was being hacked by foreign adversaries and while publicly asking the very same adversaries for assistance in hacking the Democrat's emails.
It's beyond suspicious.
I'm fine with a debate on the specifics but paperless voting machines have no place in the world. What you're giving up far outweighs the marginal benefits.
Just to note, please don't read politics into this, I've attached my own leanings clearly in case anyone thinks I favor one side or the other but I am trying to state this without it being partisan in nature.
1. And while I'm a progressive, I'm not in this camp.
Regardless, your whataboutism doesn't matter here. Presently, the Democrats "as a whole" are united on election security, and the Republicans "as a whole" are united against it.
The quicker he leaves office, the better off all Americans will be.
He is all about Republican Power at all costs. Nothing else matters to him. Nothing. He is pleased as poop that the current sitting nincompoop President is resetting the bar lower for what the average American will tolerate from an elected official.
Oh, wait. That's not how Congress works. There must be someone else blocking that bill?
[0] https://gabbard.house.gov/sites/gabbard.house.gov/files/Secu...