CISA: The November 3rd election was the most secure in American history
cisa.gov
cisa.gov
I actually did my degree thesis on designing electronic voting systems (and built one), and ultimately concluded it was impossible to make them fully secure. The best you can do is paper backups and random audits to detect anything illicit followed by a full audit if that fails. No paper backups results in it being undetectable.
Computers are good at making things more efficient, but in terms of election security the inefficiency is a feature (i.e. it takes more people to alter votes, and the more people you add the harder a lie is to keep).
[0] https://thehill.com/policy/cybersecurity/457168-report-says-...
To me, it’s wild to think all one needs to request a ballot is a name, address and ssn... and on top of all of that, you can get the ballot sent to a different address...
I would say though that "scale matters." If an electronic voting system is compromised the "scale" could be the entire state, and millions of votes, but each time a mail ballot is stolen via identity theft, you're risking it being detected/getting caught, so it ultimately scales to fewer than thousands of potentially problematic votes (which is bad, but not democracy breakingly so, like electronic/computer voting insecurity).
No votes should be cast by people not allowed to vote.
Mail-in ballots are not secret ballots and that's dangerous. There's a reason a workplace cannot be unionized in the US without a true secret ballot.
I’ve knocked on doors in New Jersey and Pennsylvania. Many registered Democrats (usually the wife) denied being Democrats when their partners were around. I thought this was an error in our data until I revisited the neighbourhood. Husband wasn’t home. Wife scolded us. He is an ardent Republican and wouldn’t appreciate how she votes.
Mail-in ballots let voters verify their vote to third parties. That opens them up to external influence, positive (pay for votes) or negative (fired for voting wrong).
We had no choice this year. But there is a real tradeoff in privacy for vulnerable people. We shouldn't lose sight of that trade-off while pushing for turnout.
If a voting system requires zero abusive power dynamics to work, it’s a bad system.
Also, banning mail-in ballots isn’t the only solution. Early voting is an alternative to mailed ballots. Letting someone re-vote a mailed-in ballot at a poll site is a fix to the cited problem, though it introduces complexity.
Or worse the voter gives the other person the empty ballot with a signed envelope.
A secret ballot is one in which each voters vote is anonymous to EVERYBODY.
Spouse, parent, landlord, employer, union boss, social worker.
Case in point https://www.texasattorneygeneral.gov/news/releases/limestone...
So it’s not doubly secret in the way you describe: https://elections.cdn.sos.ca.gov/vote-by-mail/pdf/guidance.p...
> The greatest thing about a democracy is that every idiot is allowed to vote.
> The worst thing about a democracy is that every idiot is allowed to vote.
A proper long-term solution is to have governments invest in critical thinking skills and education, but of course, it's a catch-22 situation.
> Here is what we found. Besides the United States, there are 36 member states in the Organization for Economic Cooperation and Development (OECD). Forty-seven percent ban mail-in voting unless the citizen is living abroad, and 30 percent require a photo ID to obtain a mail-in ballot. Fourteen percent of the countries ban mail-in voting even for those living abroad.
This has nothing to do with the factuality or legitimacy of flaws in the system -- in short, yes, I believe you that there are severe problems with the apparatus we use to conduct elections, but there is strong pressure to ignore and even deny these problems, because doing so helps solve the bigger, more important problem of getting Trump out of office. I don't want Trump in office, but I cannot admit to any legitimacy to the claims of vote irregularity in the 2020 election, even theoretically based on your expertise because even if it were true, it would be a "fact that gives power to the enemy" and thus must be treated as a falsehood. That's why if you post about it on Twitter, a little note will be attached to your tweet with a link that says the U.S. elections were perfectly conducted with no chance of fraud.
The argument about the Electoral College is one about the process, not the mechanisms. By definition, the Electoral College is undemocratic in that for a choice of a national leader, people in smaller population states have a greater say than those in larger states.
You can argue that as the United States of America, that is a majority of the States that get to vote for the President, but not even the original writers of the Constitution thought that. The reason for the Electoral College was to put a break on the possibility of a populist being elected.
So the original purpose has proven to be unachieved, the argument that States should vote for the President instead of people is completely undemocratic.
I heard (discussions with folks online) that in other parts of the state they are still using the older machines, which the voter just has to trust to record their selections correctly. I think I've heard they are transitioning away from these.
You could verify your own vote but nobody else could.
It could be very simple to use, like a qr code that links to a public api showing the encoded ballot data, and a second qr code that you scan to decrypt it.
If there's no way to verify your specific vote you can just lie about who you voted for.
That's by design, it's an important feature to prevent people from being pressured into/persecuted for voting a certain way, or selling their vote.
If there's no way to verify your specific vote you can just lie about who you voted for.
If you could only see the bank’s final balance with no insight into how much each person deposited and no cash in the vaults, the bank’s reported balance would be pretty meaningless for audit purposes.
We might know which 10 people put money in a bank, but without transaction amounts, it still doesn’t help with the audit.
Why doesn't/wouldn't this work in the US? My guess is the complexity of your ballots -- we typically vote for one person and every couple of years there might be a referendum question.
Presumably you’re thinking of Florida in 2000, where the margin of victory was 0.0092%, and thus exceptional care in counting was merited. As far as I can recall other national elections have been timely in the last 20 years.
There last election wasn't particularly close and from my understanding the mathematics of someone other than Trudeau + Liberal party winning were pretty much set.
The only thing that I can think of is that your elections staff are grossly under-allocated?
It obviously takes far longer to count ballots by hand when you're dealing with a dozen races instead of one or two.
I think one reason for the US system to be this complex is essentially corruption, i.e. funnelling money to the makers of voting machines. The other reason is that the US system highly encourages parties to try to get votes of the other party discounted based on technicalities.
It still boggles my mind that in the US, the first modern democracy the system developed to discourage voter participation
I sometimes wish we had a separate federal / state / county / town vote to keep the practice up and reduce the overhead of individual voting periods.
The US ones can be multiple pages where you end up voting for a dozen candidates across multiple federal, state and local offices, plus a number of ballot initiatives. It's kind of nuts.
But I agree the old fashion paper and pen is the best system. It doesn't matter how theoretically secure some high-tech digital voting system is - unless every voter can understand how it works you'll always have people who think it's fixed. Actually, even with paper and pen people will think it's fixed, but you at least eliminate a ton of the unknown because of the physical record.
My Washington ballot this year was a double-sided single page bubble sheet. I'm not sure how much easier it's supposed to get.
Generally speaking, in most US states the person certifying the election result is the Secretary of State, an elected official elected while affiliated to a party. There was a whole brouhaha when Brian Kemp was running for governor of Georgia while also the Secretary of State, because that looked like a conflict of interest in a hotly contested election.
Judges shouldn't be appointed by the fed but be randomized by computers for a database of vetted lawyers/judges who could assume the role, and all federal judges only serve for the case they're called in for (basically reverse jury duty).
Municipal elections do occur on a schedule here, but I don't think that's relevant since it's hyper local.
Pretty much without fail, any election that isn't a presidential one has lower turnout if not also scheduled with the presidential one, since many Americans will only show up for the presidential elections. Which is why the ballots tend to be long.
Granted, I don't think this makes them very complicated; my ballot had plenty of offices this year, and it was essentially a one-page double sided bubble sheet, with accompanying voter guides sent in the mail. It's not very hard.
I took the CISA statement to be relative to this progress, not a statement of absolute quality.
The best technology was probably the big mark-sense forms, where you filled out a huge paper ballot on card stock, and then took it to the ballot box and put it in a slot on the side. The box pulled the ballot in with rollers, scanned it, and dropped it in the sealed translucent box underneath, where you could see it, blurred. So there was an immediate electronic tally, and paper ballots for re-counting.
Ballot printing was a big cost with that system, but the machines were cheap.
"Pennsylvania, Georgia and South Carolina are on course to replace all paperless voting machines by 2020, while Arkansas, Virginia and Delaware have already completed this process."
We're lucky; they made it just in time. Imagine if this was a potential concern for Georgia or Pennsylvania right now.
To save you a click, the 8 remaining states are Texas, Louisiana, Tennessee, Mississippi, Kansas, Indiana, Kentucky and New Jersey. I hope Texas and Indiana, at least, follow suit soon.
Layers, more of them, help to secure a system.
It makes me wonder how a statement like this can be proved.
> There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised
When it comes to something as important as elections the mantra should be: don't trust. verify.
There's room for asymmetric errors in input, in the direction of a favored candidate. Still way better than the kinds that are electronic only, but not as good as paper-first.
The key thing with closed Vs. open source isn't simply the ability to find defects (design & bugs), but also right now election officials/security experts in some cases aren't allowed to verify election software per the software licenses! That's an untenable position to be in.
Open source isn't some panacea, but it puts you into that position where "verify" is even conceptually possible. I still believe we need paper backups and random audits, but we can do multiple things at once and should.
How do you know the machine is running the program whose source code you're looking at, instead of some other program that looks superficially like it?
If a machine produces convincing evidence of what it has done, e.g., a print-out that (1) the voter can meaningfully check before depositing, and that (2) is audited with at least spot checks or formal recounts later, why does it matter whether it is open or closed source?
https://www.politico.com/news/2020/11/04/georgia-election-ma...
If you want to project security, you don't do this kind of thing. It's insane. It's like the plot of a Hollywood movie.
[1] https://www.wsbtv.com/news/local/spalding-county-experiencin...
"vendor for the machines notified them at 7:05 a.m. that there was a problem with an overnight update to the system"
"They just said it was a glitch in the system"
In/around my hometown, for example, the voting machines are "securely" stored in between elections, until just before an election, when they get 'em out to set them up, test them, etc.
Whether they installed updates an hour before an electiion or two weeks before an election, it can still be made to sound "fishy" by anyone who wants it to.
"Why were they installing a so-called 'update' an hour before the polls open?" versus "Why were they installing so-called 'updates' on the voting machines two weeks before the election?"
Obviously, they were installing hacked firmware in either case, right?
Its probably easy for us to think from where we are sitting that counting votes must be one hell of an easy application to write. Let me try.... ah yes, it indeed was very easy. The funny about ones ignorance is that one doesn't notice it even when one notices it.
Assuming it was a legitimate update I wonder what that dude felt like when he realized it was needed.
Yes. It's very wrong, and possibly fraudulent, but I suspect more likely someone screwed up (or possibly a vuln was found). Likely someone had a cold chill down their spine when they realized what was needed.
Firmware updates should be done by the election officials, not the company. If my mom can update her router firmware, then I think an election official can do it.
The fact that remote updates are even possible point to a much, much bigger problem. Do we really believe the devs working for Dominion (or whatever company) can outsmart the elite teams working for nation-state intelligence services?
Also, this software should be open source and auditable by any concerned citizen.
This is the only way for secure elections.
The companies involved can only be described as utterly incompetent in security. [2]
[1] https://www.nytimes.com/2018/02/21/magazine/the-myth-of-the-...
[2] https://en.wikipedia.org/wiki/Election_Systems_%26_Software#...
>> There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised
I suppose it might depend on how you read that statement. One person might read it as "There is no evidence (that exists/that will exist) that any voting system deleted or lost votes, changed votes, or was in any way compromised", in which case some backing would be desirable. Another person might read it more like "There is no evidence (that we're aware of) that any voting system deleted or lost votes, changed votes, or was in any way compromised", in which case proof technically doesn't need to be provided, as one can truthfully state that they are not aware of evidence of an event independently of whether that event occurred or not.
Cynical me just assumes they decided to leave out the rest of the sentence, "... because we didn't actually go looking for any such evidence", therefore they can ("honestly") "plead ignorance".
Making a claim like this reeks of partisanship.
And no problems. Really?
FEMA, also a gov-based entity, has had multiple "practice rounds" and it still can't get it right. Rare does the gov get it right, let alone first time.
I have to stick with the tried and true: Trust but verify. And self-verification isn't good enough.
Ah, yes, CISA, that noted partisan Democrat-loving group:
> The Cybersecurity and Infrastructure Security Agency (CISA) was established on November 16, 2018 when President Donald Trump signed into law the Cybersecurity and Infrastructure Security Agency Act of 2018 [..] > On November 13, the United States House of Representatives voted unanimously to pass legislation creating the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security (DHS).
Very partisan, assuming you accept that the Democrats and Republicans are one party.
[1]: https://www.forbes.com/sites/alisondurkee/2020/11/12/pennsyl...
While I disagree with throwing out any vote, the ballots were thrown out because they didn’t comply with the law, not because a third party interfered or hacked the election system.
You can disagree with the law (and disagreeing in this case is reasonable!), but that doesn’t mean our elections are insecure.
I am sorry but I never said or implied anywhere that a secure electoral system means it cannot be interfered/hacked. You don't need to hack if you have insiders do the bidding for you. But let us keep conspiracies aside for a minute. The issue is not even someone attacking the system. The system is weak in and itself. Why? There have been many "software glitches" that switch votes from one candidate to another literally overturning the election result. Be it Antrim County or Oakland County. These "glitches" or in some cases "human errors" show the elections are not secure. How can you call something "secure" when you have 6000 votes switching from one candidate to another? You don't even need a foreign actor to destabilize the elections when the system is so poorly designed that it can screw up on its own!
https://www.freep.com/story/news/local/michigan/oakland/2020...
Quoting:
“Apparently, there was a technical glitch in Rochester Hills. And so I actually ended up winning by a little over 1,100 votes,” said a chuckling Kochenderfer.
The margin was 1,127 votes, to be exact. That gave him a 51.67% share of the total (with 48.23% going to his opponent, Hartman).
The fresh result buoyed the incumbent’s spirits but also had him worried about how to prevent future election errors, he said.
“I’m very grateful to the officials who caught the error, but we need to ensure that we catch these issues, or prevent them entirely,” Kochenderfer said.
"People are acting like fixing our elections is a partisan thing when it shouldn't be partisan," he said, adding, "we do have a very, very good clerk in Rochester Hills."
“A computer issue in Rochester Hills caused them to send us results for seven precincts as both precinct votes and absentee votes. They should only have been sent to us as absentee votes,” Rozell said in a text message.
Not remotely 'random', moreover, nobody doubts that there can be flaws, the issue is the degree to which they happen and relevant impact.
Voter rolls will never be perfect, the issue is 'how close' they need to be, and what other elements are in place.
https://www.politico.com/news/2020/11/12/cyber-official-chri...
I have a few comments going back a couple of years predicting how electronic voting will cause civil unrest because it is so vulnerable to being discredited. Edward Snowden even recently tweeted a prof's video about the same thing. Everybody who had given the issue any serious thought at all already knew it was an inevitable problem. Luckily, the U.S. has a process for dealing with contested election results, and the parties will litigate it to its final state.
I'm just hoping for a very cold winter to keep people inside.
You haven’t been paying attention, then. Trump has been screaming fraud for days. This statement is a direct response to a completely baseless, evidence-free claim he made earlier today that 2.7 million votes for him were destroyed.
Perhaps not if you read reputable outlets but if you take a look on Facebook, Twitter (including the President’s account) and YouTube you’ll find a frenzy of conspiracy theories about voter fraud. None of it with any real evidence attached, but it’s spreading like wildfire in many social circles.
Of course, this statement won’t really do anything. If you were the “Deep State” rigging an election this is exactly what you’d order CISA to say!
https://apnews.com/article/election-2020-ap-fact-check-joe-b...
https://apnews.com/article/ap-fact-check-election-dead-voter...
https://apnews.com/article/election-2020-joe-biden-donald-tr...
https://apnews.com/article/election-2020-joe-biden-us-news-m...
https://apnews.com/article/election-2020-ap-fact-check-joe-b...
Original: AP claims there's no evidence of "dead voters", but this list seems to indicate otherwise: [redacted] It's obituaries matched with returned absentee ballots. I've inspected a dozen or so entries and it seems legit.
I’m curious where you got a link to that. Looks like it’s from an account that was registered only yesterday... so there’s really no evidence (at least on the repo itself) that it’s “crowdsourced”.
IIRC the original list was a pastebin with ~8000 identities and this list was the final result after testing each identity individually on a state of Michigan website.
As evidence: I spot-checked three random entries. In all three cases, I could find a Whitepages.com entry for a person with the same first & last name, in or near the zip code where the ballot was for; but the obituary was for a different city.
Entry 962: The voter is registered in zip code 48602 (Saginaw, MI). Whitepages.com lists a resident of Saginaw, MI with the same name and age as the voter. But the obituary is for someone who lived in Eastpoint, MI, which is 100 miles away. Howmanyofme.com estimates there are 6,000 people in the United States with this same name.
Entry 302: The voter is registered in zip code 48076 (Lanthrup Village, MI). Whitepages.com lists a resident of Southfield, MI (which is a city surrounding Lanthrup Village, MI) with the same name and age as the voter. But the obituary is for someone who lived in Detroit, MI, which is 17 miles away. Howmanyofme.com estimates there are 1,600 peple in the United States with this same name.
Entry 707: The voter is registered in zip code 48162 (Monroe County, MI). Whitepages.com lists a resident of Carleton, MI (a city in Monroe County, MI) with the same name and age as the voter. But the obituary is for someone who lived in Novi, MI, which is 48 miles away. Whitepages.com also lists at least three other individuals in various parts of Michigan with the same name and age range.
I've filed this as an issue on the Github repo: https://github.com/votesunshine/votesunshine.github.io/issue...
It's very irresponsible for you to be spreading these rumors. You should make it right by spreading the truth instead: go back to wherever you found out about this page, and let them know that it's actually just a case of different people with the same name.
If you are interested in the issues, of course there is no limit to the depth of the rabbit hole you can run down, but the media position here has been its usual expression of disgust for anything outside its perceived status quo. Mainstream news is like listening to teenagers reading out texts from their dad with eyerolls.
It's literally on every page of the news.
The Trump campaign is trying to discredit the results of the election by any means possible.
The issue of 'electronic voting' is only a concern were there to be an election among regular people, interested in determining the actual truth.
It's much worse when people in positions of power just make up the truth 'because they can'.
Whatever Trump says, evidence or not, maybe 20% of the US population will believe.
If he Tweets it, it's 'true'.
This is why we're really concerned about information propagation - now the vast majority of people will 'believe' what's on the news because it's the job of journos to determine the truth - we don't have time as individuals to hunt down every little irregularity. That's why integrity in the media system is really important.
Social Media has no institutional integrity whatsoever - and there's absolutely no amount of 'evidence' that will convince certain people against what their 'Dear Leader' said.
Any random person can start a meme, and that meme becomes 'truth'.
'The Stolen Election' meme is a populist ploy, not one based on any real evidence of systematic problems, it's a fabricated narrative.
'Both sides' are guilty of a lot of bad narrative-making but this one is particularly pernicious.
No, the 20% not 'believing' just the 'Anon. Official' - they are believing the information on the basis of verification by a journalistic institution with supposed credibility.
'Anonymous Sources' are a mainline source of journalistic information, and journos basically put their entire credibility on the line when they vet info and then communicate said information.
The press didn't lie when representing 'anonymous officials' in 2016 rather, they communicated the information. Where the press did a 'bad job' was misrepresenting the nature of Russian-Trump relations, which basically were nill.
The MSM seriously cast doubt on the legitimacy of Trump for a long time, frankly I think 'everyone actually believed it' and it was a surprise when it turns out Trump and his ragtag team were lying to the FBI for really no good reason at all and in fact had really no direct connections to Russia. Too clownish even to be actually corrupt, unless they actually were in some cases - as remember some major figures in Trump's campaign were eventually indicated. Trump's campaign manager, buddies, personal lawyer - all ended up in jail. That's not 'nothing'.
Ironically, if Trump & Co. acted responsibly during the Mueller investigation - his pleas of 'Unfair!' might have actually worked, but he's such a liar that he only makes himself look guilty.
But Trump's lies, in contrast to media spin, are a whole other level of falsity - he literally invents facts without any basis whatsoever.
He's not 'spinning' the facts, he's literally inventing them.
On election night when he said 'If they count the good votes, I win, the fake votes, they win' - this was probably the most dangerous statement he's ever made, he was verging on plunging the US into a garbage African Republic. At that moment it was clear that he had to go, he's a greater threat to the Republic than any foreign invader. He's willing to destroy democracy for his own power and vanity.
His world view is literally: "If I win it's because I'm great, if they win, it's because they cheated" irrespective of any reality.
Fox News, in the lat few days, has had to pull away from his statements quite a few times, it's shocking.
You got that wrong, that absolutely not their job.
https://www.eff.org/deeplinks/2020/11/election-security-when...
Trump is advocating the idea that this is actually super super widespread and tons of his votes were given to Biden, not just temporarily, but permanently:
https://twitter.com/realDonaldTrump/status/13269262268885442...
The company who claims they cannot be used to manipulate machines has a laundry list of serious security lapses and incompetence. [2] Including remote-access to voting machines?!?! uncovered by the New York Times in 2018. [3]
[1] https://apnews.com/article/voting-machines-voting-custodio-e...
[2] https://en.wikipedia.org/wiki/Election_Systems_%26_Software#...
[3] https://www.nytimes.com/2018/02/21/magazine/the-myth-of-the-...
Here's my prediction: None of these excellent ideas will be implemented by either party, and so people will continue to be baffled by the US system. "How is it possible that the US has such chaos every election season?"
The potential for bumping up "our guy" in a close race is way too appealing to the party in power. When the reigns change hands, the new party could take the time to tighten election security, but to what benefit? They are now in control. Making things more fair to the other team would only hurt their chances.
Election fraud is deeply ingrained in the long democratic political history of the US, from the very beginning. Direct democracy was an untried, unknown concept when the country started. No one but a few ivory tower eggheads who read dense philosophy books really understood what it was all about: "You mean if our guy gets more pieces of paper into that box than the other guy, we can award ourselves all of the government contracts?" It didn't even necessarily start out as nefarious or unethical, just clueless.
[1] https://www.lawfareblog.com/2020-election-security-success-s...
[2] https://www.schneier.com/blog/archives/2020/11/2020-was-a-se...
You vote in a 'machine' and it prints a 2 receipts - one for the 'backup' and one that you keep with some kind of encrypted/encoded data for non-repudiation.
You go online with your private receipt number and it can validate your vote.
If the electronic count is not accepted, the physical 'receipts' are coded so they can be counted very quickly by laser scanner.
What precisely do you mean by "validate" here? Would this scheme make the ballot non-secret?
This seems somewhat contradictory. The voter retaining possession of the ID creates a link between the ballot and the voter, doesn't it?
Then again, it does open the door to plausible deniability, though correctly pulling that off could introduce new complications and/or avenues of attack.
> and check that number online to verify their vote was tallied as expected.
"as expected" is the key phrase here. If it includes seeing what candidate(s) the voter voted for (i.e., trying to verify that the ballot was read correctly), then that seems like it would break the secret ballot. If it means just checking that the ballot was included in the count without revealing precisely what candidate(s)/issue(s) the vote was for, then that might work.
Yes, but it's only known to the voter. If they choose to dispute the results, then they give up that anonymity, but I think that's worth it. What other option do you have? As a voter, I should be able to verify that my vote was recorded correctly.
One of the more common complaints I've seen with similar schemes is that it opens the door to vote selling and/or voter intimidation.
> As a voter, I should be able to verify that my vote was recorded correctly.
I agree that this can be a desirable property for a voting system to have. Unfortunately, it has to coexist with other desirable properties (e.g., a secret ballot), and at least from what I can tell it appears that some of those properties can be mutually exclusive [0, 1, 2 with 1 being the PDF of 0].
(Fair warning, the literature is well over my head for the most part, so I wouldn't be surprised if I misinterpreted something.)
> What other option do you have?
I honestly don't know, off the top of my head. Presumably there's continuing research into different voting systems, but in the end it'll come down to what combination of desirable properties and ease of implementation people will be willing to live with.
[0]: https://link.springer.com/chapter/10.1007/978-3-642-12980-3_...
[1]: https://www.lsv.fr/Projects/anr-avote/PUBLIS/CFPST-08.pdf
How does it open the door to voter intimidation? Someone steals my ballot receipt and checks who I voted for?
Depends on your point of view, I suppose. Some might argue that it distorts the democratic process, some others could argue that it's merely an extension of exchanging promises for votes.
Unfortunately, this is not an area I'm very familiar with, so you'll probably have to look elsewhere for well-reasoned analyses.
> Politicians get to do it. Why can't I do it?
Someone else doing something wrong is rather poor justification for you being able to do something wrong.
Of course, this is contingent upon you believing vote selling is wrong; if you think it is acceptable, then the unequal treatment can be something worth addressing.
> How does it open the door to voter intimidation? Someone steals my ballot receipt and checks who I voted for?
It basically boils down to someone with power over you sitting you down in front of a computer and asking you to prove who/what you voted for, with some kind of negative consequence if you refuse or picked the "wrong" candidate/issues.
Stealing a ballot receipt in lieu of asking you to show the result yourself is another way to go about it.
If you've ever worked in an environment where money was changing hands (banking, trading, etc) or where security was the real deal (three-letter agencies), or even in the insurance industry, you know that election integrity controls are a half-baked freshman project by comparison.
(For myself, I don't care who wins. I don't believe it matters. But don't piss on me and tell me it's raining.)
“Where I come from, when the government says someone's guilty that's how you know they're innocent,” she says. “It's different here?”
Is this at odds with secret ballots?
I suppose it depends on what precisely is to be verified. The scheme you describe allows for verification that a ballot has been received/sent/counted, depending on details, which may or may not be verifiable enough depending on who you ask.