Voting machines pose a greater threat to our elections than foreign agents
thehill.com
thehill.com
The National Academies wrote a report not long ago that gives a nice overview, has lots of detail, and makes specific policy recommendations to Congress: https://www.carnegie.org/media/filer_public/34/9d/349d3207-d...
Honestly, it's actually kind of hilarious that some people think Russian trolls and Facebook ads somehow turned the election and not socio-economic factors (for example, those outlined in the Paul Krugman article and thread).
1: https://www.platformsecuritysummit.com/2019/speaker/chen/
nice to see that this is a bipartisan issue.
I mean, what about elections that you want to steal?
It's a whole lot harder to steal an election without an electronic voting scheme in place.
/sarcasm
Control who counts the votes and report it the way you want.
Stuff the ballots with more votes than people.
Still, with good faith all around, oversight, and decent security that won't happen.
Just hacking the machines seems a lot easier than hiring an army of vote counters or ballot stuffers.
High five!
And that's a good thing. Each state/county/city can implement the election however they want which makes it practically impossible to rig the vote. If we all used the same system/procedures/process then hacking the election could scale much more easily as the same tricks that works in Manhattan would work in Montana.
Also, in the US, hacking a single large state can swing a federal election.
An idea: https://medium.com/@dotnetmike/touch-screen-voting-should-be...
Machines just add more opportunities for fraud.
Combine this with voting machine companies being opaque, not recognizing obvious flaws and their executives promising to deliver states to particular candidates (https://www.commondreams.org/headlines03/0828-08.htm), and you begin to feel that all the suspicion is justified.
Isn't this the core problem with most electronic voting as currently implemented in the US? I mean, that no such guarantee exists?
The real solution is to use paper. There’s no way to fuck with a paper ballot system other than to go to every polling station and fuck with their counts - an expensive and highly visible attack.
Not only are we vulnerable to a few key districts tipping elections, nation state actors should find it absolutely trivial to build a comprehensive program targeting the full spectrum of voting machines used in practice.
Like, you know, observable paper ballots.
There should still be minimum security standards required.
Air gapped counting machines with hand marked ballots is a good start.
https://en.wikipedia.org/wiki/List_of_the_most_populous_coun...
If we used a popular vote, a malicious county could supply an extra 50 million votes. Just one corrupt county could change the election results, even when the results would not have been close, and there is nothing that could be done about it after the election day.
https://www.eac.gov/voting-equipment/system-certification-pr...
Without a verifiable paper trail, why would anyone trust a voting machine?
If we're really concerned about this - get rid of the network connectivity.
Obviously this is over simplified, but just make a simple locally ran app or web application that refreshes once a vote has been cast. Store the vote in a simple SQLite database and at the end of the day, have a voting official go to the machine, and unlock the case, press a button on the back, which prints out or shows vote counts on the back on a small screen or something. They then can report that to whatever commission, committee, or otherwise is monitoring the election.
It's all locally stored, maintained, and under lock and key.
Why does this seem so difficult? We don't need democracy hindered by "network connectivity", just make it more environmentally friendly so however millions of people times the size of the paper ballot isn't wasted needlessly.
What happens when a bug occured and machines need to be updated? Do you bring all machines in for maintenance or does a local IT shop do it? Maybe the manufacturer send a person but can the person be trusted to update multiple machines all over the country?
All electronic voting machines should output a paper human readable 'scantron' type ballot that is safely stored for verifying the internal digital tally.
And then that ballot should be what is actually tabulated and the internal digital tally ignored, or not even kept. The machine should be a device to facilitate creation of accurate, easily tabulated paper ballots, period.
We should just have paper scantron style ballots that people fill out. Then have scantron counting machines to tally them up after all voting nationwide has closed.
All the other issues people are trying to do to "fix" some aspect of voting are fundamentally flawed and those who are advocating for them are either desiring the ability to violate election integrity or don't understand the requirements of voting. Or trying to get money because someone in power sits in one of the two prior camps.
Vote counting machines are just as problematic as voting machines. We should just get rid of all of the machines and both vote and count by hand.
Iranian centrifuges had no network connectivity: https://en.wikipedia.org/wiki/Stuxnet
this is one of the biggest straw men i've ever seen on this site.
you realize that building computers out of various plastic and rare earth materials sourced from all over the world isn't free, correct?
They (generally) aren't.
(Almost) every demo of voting machine hacking involves physical access to the machine, tools, and keys/lockpicks.
This is a very important issue, certainly. There is no excuse for voting machines not to be air-gapped. But that's not the only very important issue with voting machines.
Block-chain seems to be a failure for money so far, but voting seems like the killer application. The technology is there, well understood, there are even companies that offer a solution along those lines. Why don't we use them? Isn't it so much better than electronic voting machines in every way?
That raises the question of how do you avoid double-voting or voting for people who didn't vote. I think there's technical solutions to both.
Maybe have a separate record for "this person voted" and another record for "1 vote for X", with encrypted references back and forth? Then you could at least verify that there are an equal number of both records, that all the identities are valid and only used up to once, and tabulate the final results. It would still be possible for someone who didn't vote to have a false vote logged, but that is a more narrow attack.
I would add that (at least in my state), validating a sample of votes to provide an indication of a problem has been done for at least as long as I've been alive, so we already have that. But my state doesn't use electronic voting machines.
But, of course, voting by mail is even worse, and most of the US seems to not care about it a slightest bit.
I'm sure there's solutions to that though, either technical or legal.
How many states matter in the presidential election? It's insane disgrace that number is not always exactly 50.
Every other threat is trivial in comparison.
It sounds like there was a more-or-less professional election rigger involved:
"According to prosecutors, McCrae Dowless, a contractor for the Harris campaign, oversaw extensive election fraud in Bladen County, in the district’s rural east, affecting potentially hundreds of votes."
Details about McCrae Dowless: https://www.charlotteobserver.com/news/politics-government/a...
He sounds extra sketchy.
A lot of these rules and restrictions are constructed in such a way that the dominant language/culture/homeowners don't have any problems meeting them, thus offering an easily defensible reasoning behind them. It seems totally reasonable to assume everyone has ID - but if you don't drive, and are well established in a community you probably won't need ID to conduct life.
The reality with the importance of the chief federal executive office and how the election swings on such narrow margins in certain states, this is a problem that constitutional we just aren't able to easily solve - deliberately so, that is the constitutional order constructed on purpose.
A single Tuesday in November seems like an awfully thin window to measure the sentiments of a nation of ~350MM, no?
Why are we married to such an archaic idea of what is a reasonable time to cast a vote?
Even the most basic version of this, a ballot-marking system, is pretty much infeasible unless you have formally verified hardware as well, which is not even possible even for commercial vendors. At least for them, selling sealed units that are somewhat resistant to physical modification is possible, but even there physical compromises have been demonstrated.
Ballot scanning machines (for hand-marked ballots) are a pretty good balance of time/accuracy/simplicity, with the auditability being a big bonus for both random checks and for disputed elections.
To take New York state as an example, it has manually marked ballots now with ballot scanners for tabulation, and I'm reasonably comfortable with the tabulation and placement aspects; where NY fails is largely in usability -- ballot design is worse than terrible, and borders on misleading. That plus the inscrutibility of NY's ballot initiative system (trying to find the actual text of the ballot measures is nearly impossible) makes the whole system a little shakey. And part of that as well is the scope of elected positions for minor things (what the hell is a Comptroller and why are we voting for one); they basically are a power transfer from the executives to the party machine to allow them to essentially give positions to people favored by the (unelected) party apparatus, which give toeholds to higher positions.
Why is it not possible? Formal hardware verification is probably more common than formal software verification.
"Unhackable" is an unachievable goal.
There are enough checks in the system (bipartisan counting and validation committees) that a pure digital compromise of an election that would not be flagged and detected is very small.
There are much more pressing matters, like access to voting stations (both distance and time), voter roll purging, ballot design flaws that make voting fundamentally error prone, and (controversially) a lack of identification requirements for elections that make certain classes of fraud difficult to detect.
I think on balance, all-remote elections, like Oregon has had for a while, and I think Washington now too, are the best balance here. There are certain vulnerabilities around buying, compelling, and selectively harvesting votes, but with universal cell phones, "proof of vote" is too easy to obtain anyway so those ships have mostly sailed, and it seems like a reasonable tradeoff to make.
If you have paper ballots, sure, but the US does not have paper ballots in some states and won't by the next national election. And even if they did (as many do), few states have a uniform system of random vote audits.
So I'm not sure what you're referring to with this:
> There are enough checks in the system (bipartisan counting and validation committees) that a pure digital compromise of an election that would not be flagged and detected is very small.
I literally read the Diebold Voting machine source code (and tabulator) that was leaked (twice). There's nothing remotely like that in there. There's no facility to do that. And while most of those are now retired, there's similar machines that work exactly the same way still in usage.
This isn't true universally, in fact, fair to say it is rarely true [1]. Often the vote is tabulated electronically, but there is always a bipartisan committee overseeing random re-tabulations and recounts as a matter of course. In the process of rolling up results, there are cross-checks with voter rolls that make certain types of ballot stuffing infeasible (that is, an attack would have to be a read/modify/write).
There are also state departments that are tasked with overseeing the general quality of elections that will spot outliers and investigate. It's always possible that corruption or partisan efforts will bypass scrutiny (and there have been several iffy cases of precincts in previous election cycles) but that has been a problem even pre-electronic equipment.
[1] https://ballotpedia.org/Voting_methods_and_equipment_by_stat...
EDIT: the parent post has been modified to be slightly less aggressive in its claims, including limiting the scope to "some states". Also added "And even if they did (as many do), few states have a uniform system of random vote audits", but can easily be refuted [2].
[2] http://www.ncsl.org/research/elections-and-campaigns/post-el...
Some of those states are now, or will become swing states. As we saw in 2016, where the presidential race was decided on a 400k margin of error across 3 states, it doesn't take much.
The non-pure ones (that is, paper + DRE w/o paper trail) only include one swing state, Pennsylvania, which is switching to paper ballots for the next election cycle.
So I guess voting machines pose a hypothetical threat, if they were adopted more broadly, but the opposite is the trend.
Go on, because let me tell you what this looks like in practice here in NC. Here, you currently have to register and then provide your name to a poll worker, then sign that you voted. The only plausible fraud I can imagine if I wanted to vote more than once is to give the name of someone else and hope they don't show up to vote. There's no way I can imagine to do this at a significant scale without it going undetected. (You'd have to somehow get a bunch of fake names registered or figure out names of people who aren't likely to vote, then find people who are willing to commit fraud to vote under those names and get them to do so during early voting I guess.)
Beginning next year, we need to present ID to vote, but the acceptable IDs are fairly restrictive[1,2]. In particular, my college aged daughter who will be voting for the first time next year is not able to use her state college issued ID[3]. Nor can she use her expired DMV learner's permit. Now fortunately, she has a passport and she'll use that. But otherwise, she'd have to get some form of acceptable ID.
This is not well-publicized, and I guarantee there will be first time student voters next year who will be surprised to learn they can't vote with their college ID, and must instead to submit a provisional ballot.
I am certain this will suppress many many more votes than fraudulent votes, if fraudulent votes even exist.
1. https://www.ncsbe.gov/Voter-Id
2. "Of the approximately 850 universities, colleges, state and local employers, including charter schools, and tribal entities that were eligible to have their identification cards approved, 81 institutions submitted requests to the State Board of Elections. We do not in all cases know why the majority of institutions chose not to request approval, but in some cases institutions raised concerns that they believed they could not meet the current statutory requirements."
https://s3.amazonaws.com/dl.ncsbe.gov/Voter%20ID/Corresponde...
3. https://s3.amazonaws.com/dl.ncsbe.gov/Voter%20ID/Student%2C%...
The attack vector for signature-based roll verification is mostly along the lines of submitting votes for non-voting eligible voters, whose names can easily be harvested from voter rolls and looking at historical voting records (coupled, of course, with inside knowledge of which identities have already been used in previous election cycles, so appear to be active even though the agent in question knows that they are actually inactive). I don't know how common this is -- nobody does -- because it's almost impossible to detect without more information about who is voting. You may be right, and it may be insignificant.
It is easy for voter id to verge into voter suppression territory, but to throw an old meme on its side, "voter id is impossible to implement, says only country that does not implement voter id".
And most school IDs, including all but two of the UNC schools, are not eligible. I assure you my daughter's school ID is not.
The voter ID laws are a pretty transparent attempt to suppress Democratic votes. I'd be okay with IDs if they created zero additional friction in the voting process, but they do not.