Why a Data-Security Expert Fears U.S. Voting Will Be Hacked
wsj.com
wsj.com
No other system has this property. Even if you had a formally verified election system, it and the proofs of it could perhaps only be understood by less than 100 people in the world.
The system has to be comprehensible to voters.
Six hours later, I checked the spreadsheet on the official website, scrolled to the row for my polling location, and verified these two numbers were identical to my count.
Sure, I can only check 1/3rd or so in one of 50,000 polling places. But get just 20 people you trust to do the same, and it becomes statistically unlikely that there is widespread fraud.
You can hang out in the polling location for the whole day if you want. If you get there before any voters, you can also check that the ballot box is empty. Each location serves less than 1,000 voters with three volunteer workers, so you’ll always be able to know everything that’s going on. Oh, and the longest wait I’ve ever had to endure myself was less than 5 minutes
The only possible problem (aside from Republicans) in the US would be the large number of individual races and ballot initiatives. It works well with five or so. But if you’re voting for ten deputy dog-catchers of the peace, it might get tricky.
I'm not against paper voting at all, just saying that they aren't automatic tamper proof.
I serve as an election officer in my county and have yet to hear of a compelling alternative.
paper ballots, really?
when I can apply for a mortgage, car loan, credit card, and all kinds of other financial legally binding contracts online in complete security?
I enter my SSN, my credit report is pulled.
Why can't I enter my SSN, it gets validated in a database on whether I'm alive/have already voted/am currently a legal citizen eligible to vote, and vote?
We have achieved problems way, way, way harder than "securely identify a person based on their SSN and allow them to vote A, B, or C on a subject"
Notably, none of these things require the actual data to remain anonymous like voting does. That's where all complexity comes from.
Assuming I’m not alone why not give people the choice and increase voter turnout?
Your idea is a shortcut to tyranny, and must be peacefully opposed by all holding liberty dear.
Come back once only you can do all those things on your behalf, and not anyone else having your SSN or other PII.
In my state you walk into the polling place, give them your name and address, sign your name, and that’s it. Your polling place is even listed publicly online for anyone who knows your name.
I think what the parent poster meant by "scan" was "tabulate". ie. you fill out a paper ballot, you put it into a scanner which scans it and records the result, and the ballot itself drops into a ballot box. It's still possible to hack the scanner to give a fake result, but it's easily auditable/detected since you still have the original ballots. You can even have the tabulators be entirely offline (since all they do is spit out a number), and their results can be easily cross-checked by random sampling.
There can always be tiny nits in the numbers, but the delta between the pollbook, the unused ballots, and the counts will be vanishingly small.
With enough people involved, and small enough pollbooks (local county maxes out ~4k per polling place) there is a good tradeoff between:
- maximizing participation
- keeping the integrity of the process
- minimizing fraud
As with encrypting data, there really isn't any way to make the process completely bullet proof; the task is to make real fraud infeasible.
> All of the states replaced these with secret ballots around 1890, popularly called "Australian ballots."
I'd be a lot more concerned if large numbers of ballots didn't "go missing".
https://www.realclearpolitics.com/articles/2020/04/24/28_mil...
https://www.whitehouse.gov/sites/whitehouse.gov/files/docs/p...
Coordination on that scale is completely impossible to pull off without detection. This just isn't a feasible attack.
There's a virtually zero chance that a group effort involving thousands of people isn't uncovered before the attack happens.
But that is getting ahead of ourselves. The problem isn't how do you solve duplicate voting, it is how do you detect it. That is a solved problem, already, and the answer is that there are very few attempts at voter fraud in a vote-by-mail system.
Now, the electronic machines are a whole 'nother matter. I would fight hard against my state implementing such a disaster. Vote by mail is great.
Of course cyber hacking is likely easier, but it’s not fair to fully dismiss even possibility of other attacks.
Election hacking is an actual, imminent national security threat. Intelligence agencies are scrambling to prevent or mitigate it right now.
In-person voting fraud on the other hand, as a meaningful threat, is entirely hypothetical.
Imagine if, at the height of the Cuban missile crisis, someone said “ok Soviet missiles within reach of the east coast is a threat; but what if vegan extremists blew up the white house tomorrow? Theoretically it could happen, so let’s not dismiss the threat!” That’s how different those two threat profiles actually are.
Last elections were decided by 80k votes, in a country with 250M eligible voters. With such a tight margins we have a lot of valid attack vectors, not only most obvious hacking ones.
Effective organizations are (and should be) able to deal with many risks at once. Do you think that during Cuban missiles crisis all other investigations stopped, and 100% of CIA, FBI, Police, Army etc focused on Cuba?
In person voter fraud--the kind stopped by requiring poll workers to check ID--isn't one of them. You would need thousands of coordinated attackers to change 80k votes. It's just not a feasible attack.
Why is the standard of evidence for one different than the other?
And more to the point, since when does patching a vulnerability require evidence of exploitation. We wouldn't accept Microsoft saying "There's no evidence of this Outlook vulnerability being exploited in the wild, we're not going to fix it". We certainly shouldn't accept that reasoning for our elections.
Because hacking one voting machine potentially allows one person or a small group of people to alter thousands of votes.
That person (or persons) has no way to alter anyway near that many votes through in person voter fraud. The amount of effort it would take to alter the results of an election through in person voter fraud makes it extremely difficult to pull off--particularly without detection.
Additionally there are downsides to voter id laws. The most troubling is demonstrably lower minority turn out. There are no similar downsides to methods like requiring paper receipts for voting machines.
Basically the cost benefit analysis is in favor of hardening electronic voting, but not in favor of voter id laws.
Youtube, twitter, facebook will pick a side. And whoever loses will fume with resentment. Maybe they pick up weapons. If they are right that the election was stolen and that fact is suppressed, they will certainly be justified. If they are right - which is a big hypothetical. Because the detection will be drowned in noise.
You can't involve that many people in something and keep it secret.
Even in the best case were we don't find out until elections day, an enormous increase in double votes will be all over the news the same day, and arrests will start happening shortly after.
Assuming some people decide to take them up on it, they have to coordinate or they'll end up voting as people who have already voted. Double voting is very easy to spot and many of them will be arrested at the precinct.
Plus you'd need an accurate list of close to 100k dead voters who haven't already been purged (more in a less tight election), and thousands of people willing to drive to the right precincts to match the list.
And we didn't know which states would tip the election until election night in 2016, so you'd need to duplicate your efforts several fold.
This idea is pure fantasy.
It shouldn't be possible for a liberal kid's conservative parents who know he doesn't vote to vote for him. But it's trivially possible, right now. There is literally nothing stopping anyone from doing that.
Other than the fact that it's a serious felony.
Additionally how are voter ID laws going to change this? It already requires some level of cooperation by the kid in that they don't show up and vote themselves.
If you're talking about absentee ballots, whatever you're using to identify the kid, the parents likely have access to--copy of id, birth certificate etc... So voter ID isn't going to stop this either.
>But coordination attacks are not the only thing that matters.
Coordination of some kind is required to change the results of an election. If even a few thousand random parents around the country decide to risk jail time to vote for their kid, it isn't going to impact the results of the election, so hardening against this kind of attack is a very low priority. Particularly when there's no cost effective means to stop it.
Secondly, we have no reliable data on how often it occurs, precisely because it's more or less undetectable. There are documented cases of it, that have been caught by luck. And people have tried to do surveys that are probably worthless and unreliable.
https://www.nytimes.com/1998/10/29/us/18-are-arrested-in-199...
https://abcnews.go.com/Politics/OTUS/voter-fraud-real-rare/s...
Indeed, the incidence is low. But it is importantly not zero, and the numbers we know are only the ones who got caught.
Most democracies require ID to vote. It's an anomaly that we do not. There is no good reason not to require it.
There is a good reason not to require it. Not everyone who is eligible to vote has an id, or a straightforward way to get one.
Sure. But in most cases where someone would do this, they'd do it knowing the person, and knowing they weren't going to vote, for whatever reason.
https://www.realclearpolitics.com/articles/2020/04/24/28_mil...
https://www.whitehouse.gov/sites/whitehouse.gov/files/docs/p...
Also people keep claiming that over iD is somehow suppressing voting for low income and minority voters are delusional. US is one of the only countries which doesn’t have voted id. India which has very strict voter iD laws and yet out of the 900 million eligible population, over 600 million votes were counted with voter iD few months ago which was also the largest turnout ever for any democratic election in the world. So no, voter iD and efforts to combat voter fraud are not suppressing votes. That’s just a talking point with zero backing.