It isn't. Bruce Schneier has written about how online voting is a terrible idea in general [0], and how real-world attempts at it are often woefully incompetent. [1][2] Voting should remain paper-based.
[0] https://www.schneier.com/blog/archives/2018/04/securing_elec...
[1] https://www.schneier.com/blog/archives/2019/12/election_mach...
[2] https://www.schneier.com/blog/archives/2020/02/voatz_interne...
I would much prefer a seemingly archaic system that, at the cost of annoyances and delays, at least provides us with a reasonable sense of conviction that the results are accurate.
Bruce Schneier's article on this: https://www.schneier.com/blog/archives/2018/04/securing_elec...
The pre-canvass part: opening mail in ballots, verifying them, preparing them for tabulation, can be securely done before the election. Most states with substantial mail in already do this. That means on Election Day, workers merely have to tabulate ballots which is a lot less work.
But in PA specifically the legislature declined to allow pre-canvass before the election.
When done right we have have reasonable speed and security.
I expect the same thing to happen after this election. Once things calm down, several states are going to improve their processes.
I hope so. But the annoying thing about American federalism is that we like to do things 50 different ways, long after the experiment should have been over.
This was how the system was originally designed to work, as specified in the 10th amendment. This is also how the European Union works - a federation of independent states.
That's much better then everyone getting stuck with a federal one-size-fits-all solution that is sub-optimal (or corrupted), which does happen sometimes.
Different states can try different things, and copy what works amongst each other. Once enough states agree on an optimal solution an amendment can be passed forcing any lagging states to the new solution. This could apply to things like civil rights, health care, etc.
For example, before Obama-Care we already had states trying things - Romney-care in Massachusetts guaranteed coverage to all, Vermont was ready to implement a public plan that they had to cancel, NY and California also had significant reforms in the works, etc. Most assuredly the best solutions would have risen to the top and have been copied. But now that can't happen, because for better or worse we are stuck with a contentious law that was passed and is not easy to change. Perhaps the big insurance companies were afraid there profit margins would be reduced, so they negotiated a good deal for themselves with congress? (they get subsidized premiums from the government, and the public gets to pay the deductibles, without the ability to shop, company plans reducing individual choice, etc)
I don't believe it was the intention of our system to allow drastic changes by transitory slim majorities at the federal level. It seems that everyone with an axe to grind would like a federal law (or better yet a Supreme Court case) to force their opinion on the entire country, and that is not right. Our government is an outgrowth of our culture. Tweaks to the system are not going to change what people believe in.
I'd say we have that now, since there may be 50 election systems, but we generally know which 5 are going to be important ahead of time. And that selection of states aren't necessarily the best equipped.
1. Your physical signature witnessed by a poll worker, and your identity and presence physically recorded in several different locations.
2. A physical paper ballot only accessible by poll workers.
3. A locally stored electronic ballot only accessible by poll workers.
4. Multiple physical receipts with your votes, distributed to many different physical locations only accessible to poll workers.
5. A trained poll worker available to help at the time and place that you vote.
6. An easy backup plan if something goes wrong.
Online voting is optimized for the happy path, but handling all the edge cases where something could go wrong is extremely difficult to implement and difficult for voters to understand. With online voting you need to ensure the security of the voter's physical device, operating system, web browser, each link in their internet connection, and all of those for the voting servers as well. After implementing processes to secure all of that, you need to communicate the security in a way that an average voter can understand it. You also need to think about what to do when a voter needs help, or their computer crashes mid-vote, or their power goes out, or someone sends them the wrong link, etc. etc. etc.
Current processes are a little more complicated up front, but processes for preventing and correcting errors are easy to implement and understand.
The manual processes are much better for transparency and verifiability. And we really badly need those qualities right now, when you have to be able to prove to the other side that the vote was legit, and be able to prove that every claim otherwise is false.
Insecure and hackable voting machines were already a problem more than a decade ago, and they're still a problem today.
With voting I think the consideration is a barrier for voting. In many states you do not need to prove it to vote. Some states allow a normal vote and some states make them provisional. Still, no concrete identification is required when voting in most states. The voter is trusted to be who they say they are under possible penalty. This only applies to in person voting. Almost all states allowing mail in voting do not require notarization.
With electronic voting you have a huge barrier in that not everyone has access to the means to vote electronically. You disenfranchise a pool of voters.
It is! Until you try to secure it. Then it isn't.
Online voting could be done securely over the network and could be authenticated with a certificate associated with one's voter registration that's anonymized in a way that doesn't reveal any information about the voter other than whether they have already voted.
Also, it can be an option in addition to voting in person or by mail (like you can do now with taxes).
There's a lot of handwaving in this sentence about what can be done. We can't even secure computers when the fate of the entire world _doesn't_ depend on it. You think we can do a better job when control of a nuclear power with the world's largest economy rests in the balance?
> like you can do now with taxes
I'm not terribly worried about the consequences of someone filing my taxes for me.
This is hyperbole at best. In most cases, international policy does not change all that much regardless of what major party member happens to be president of the US.
> I'm not terribly worried about the consequences of someone filing my taxes for me.
Unless you have taken the time to fine tune your payments such that you don't receive a refund or owe a significant tax payment, then someone else filing can effectively get your refund, or put information in there that can land you legal trouble or have you owe a significant payment when you actually do not. That said, we have been able to file taxes online for many years now. It would be nice if we could get with the times and do the same for voting.
That is impossible to do with computers with the current average level of computer literacy.
The person you're replying to is wishfully handwaving away electronic attacks like we haven't been facing an endless cascading catastrophe of device security breaches since practically forever.
They further keep equating property theft scenarios, where you would easily notice that your money went to someone else, or personal harrassment scenarios, where your first consequence is a human individual audit not a national election outcome, with scenarios where you'd have no idea that your vote was changed unless you start implementing policies that would allow people to sell their votes, which is something that we don't allow for a reason. Paper ballots kept in small batches distributed among thousands of precincts that are counted by hand with opposition observers are hard to systematically rig. Bits in a cloud machine somewhere that lose all connection to your action are not.
They further handwave away the significance of stealing an election because catastrophic harm would only happen _sometimes_.
Which is why I mentioned using certificate based authentication (AKA, client-side TLS certificates). Not only does the client verify that they're connecting to the correct server via the server side TLS certificate, the server can verify the client though the client cert.
This also assumes that those who want to vote online have the knowledge to properly secure their private key.
> They further handwave away the significance of stealing an election because catastrophic harm would only happen _sometimes_.
Has our foreign policy towards Israel, Egypt, Saudi Arabia, Iran, North Korea, Cuba, to name a few countries, changed significantly depending on whether someone from the Democratic or Republican Party is president?
I would say that gerrymandering has done far more to disenfranchise voters compared to theoretical attacks against the personal devices of those who choose to vote online.
"Software has no flaws" is not a strong position historically. I mean, the very fact that we're on TLS version 1.3 and not SSL 1.0 should be clue enough.
> Has our foreign policy towards Israel, Egypt, Saudi Arabia, Iran, North Korea, Cuba, to name a few countries, changed significantly depending on whether someone from the Democratic or Republican Party is president?
This is a strawman meant to distract. You should instead ask "Are there significant benefits and incentives to set up a puppet government?" The answer to that is a very obvious yes. You can then ask "Is doing that easier if you can flip votes easily?" The answer to that is a very obvious yes.
But we still conduct a lot of business online without issue. If we followed the line of reasoning that you're suggesting, then we would still be doing things as they were done prior to 1995. The fact that we're not is testament that these systems largely work. Voting is not a special case that requires us to not make use of tried and tested technology.
> Are there significant benefits and incentives to set up a puppet government?
This is an example of the "begging the question" logical fallacy. You're just assuming the conclusion is true when that's not necessarily the case.
Business has fallbacks though.
If your credit card is compromised, you can disable it, recover the funds, and get a new one.
There is no equivalent for voting, that I know of.
It's not just a matter of writing code with no bugs, though. As I mentioned this another comment, [1] voting is unusual as we must be confident in the correctness of the count, and confident that it's not possible to prove whether a particular person voted a particular way. There's also a trust issue: with a digital system, a single corrupt official will likely be able to do far more damage to the vote than with a paper-based system. Even if the system is somehow structured to resist this, public trust might still be less than in a paper-based system.
I recently had a discussion with a friend who asked me how to implement a write only audit log that will comply with some finra regulation. I asked him how tamper proof it needs to be, and mentioned his system admin could practically stop the log writer, do shady stuff, and start the log writer and there is nothing you can do about it.
As long as someone has access to the system, things can go wrong.
I am hoping zero knowledge proof systems will provide some guarantees here some day.
I can picture several ways to do a hybrid (mail + online) election like getting a code in the mail, voting online, then being able to ensure your ballot was counted correctly by using your code.
It seems to make a lot more sense than having states count for a week.
Voting has a short list of maybe four easily stated requirements. Online voting “solutions” tend to solve one or two, forget about the others, and try to compensate on user experience.
Right. In this case:
> then being able to ensure your ballot was counted correctly by using your code
This fails the voter anonymity requirement. There must not be a database associating each voter with which way they voted.