That's Dominion's statement. They're describing a pretty exceptional situation / distant from what I would think of as security research.
Obviously that's not a legally binding statement or anything but I think that at least illustrates what this situation is about.
This isn't a case of someone being mistaken or putting forth a good faith concern about security.
These accusations are based in nothing at all, disproven, and Giuliani and others just kept at it.
Researchers usually have actual evidence for concerns and so forth. And their motivations usually really is security.
This situation with Giuliani and actual security research seem completely disconnected.
The keys should be secure, but the design of algorithms and implementation of the system should not be.
It's a debate we've had with secure messengers the benefit of having that many eyes on a piece of software outweighs the minor risk of a secret zero day.
If you hide away the source code, then only criminal actors and security agencies can evaluate security flaws. Open sourcing, at least, places legitimate security researchers on equal footing with these groups, so flaws can be disclosed publicly and rectified.
That being said, I think there are sufficient safeguards in the process that effectively mitigate any potential compromising of Dominion software. The software prints out the voters' ballot and the voter is given an opportunity to review the ballot before scanning it with a separate machine and it entering a locked box. This allows for a manual recount to guard against any possible shenanigans.
One additional step they could take, would be for the voter to verify their vote after scanning. This would ensure that they actually read the ballot. Though I could see that causing problems if the voter, for whatever reason, decided to repudiate their vote while travelling between the two machines.
You can see how they work in this video: https://www.youtube.com/watch?v=b9BDiO3JGTs
This is pretty much the gold standard: a paper trail that can be audited every step of the process.
Had this election been entirely hand-counted, the same claims of fraud would have arisen. When a candidate declares in advance of an election that he can only lose if there is fraud, you can be sure he will act in bad faith if he loses.
Incredulity was all he needed to claim fraud - the numerous conspiracy theories explaining the fraud would inevitably surface after the fact. If it's not Dominion voting machines, it's dead voters, boxes of ballots showing up, and hand wavy claims of the opposition being in charge of the counting and abusing that role.
[0] https://www.sciencedirect.com/science/article/abs/pii/S02613...
But hand-counting works because it's virtually impossible to coordinate fraud widespread enough to actually make a difference. Whereas, if your entire voting system is computerized and all the computers are linked together, causing widespread changes are much more possible.
Do let me temper that slightly :
Some states didn't or didn't fully have a paper trail quite yet https://ballotpedia.org/Voting_methods_and_equipment_by_stat...
Also, be aware that Dominion voting systems actually acquired the old "Diebold Election Systems", who were not so secure a couple of years back. (though things may have changed by now, of course) https://en.wikipedia.org/wiki/Premier_Election_Solutions
Since Trump won 7/8 of those states, a conspiracy theorist might suggest that Trump’s team successfully hacked the electronic machines in those states that have no paper trail.
However, there’s really very little reason to believe there was fraud in this election - but those republican states (and New Jersey) should replace their DREs without VVPAT by the next election so that they have a secure paper trail for auditing.
Hand counting remains the golden standard for voting.
What is for sure - with voting machines, there is less validation. Hand counting means - all ballots are counted always (by volunteers with all parties invited) - whereas voting machines means a spot-test (in some states), and only a full manual count is when a recount is demanded.
All this to say - I think Dominion did a thorough job - but this all only happened because the election was close. What about those where the election isn't "close"?
However, a losing candidate may request a recount after the election. In most states, if the margin is outside of a stated threshold, that candidate must pay for the recount. If there is a discrepancy between the two counts, then a hand recount is performed.
If an election isn't close, then the respective Secretary of State will audit (by hand) a random selection of precincts to verify vote totals match, but this is a security check and generally takes place weeks after the election.
Here's the conundrum - what constitutes what's "out of threshold"? If a voting machine, either by design or flaw, pushes a close vote outside the threshold - then that's a way to bypass the checks & balances and can be exploited by the unethical.
36 million votes were cast in France in the last election.
The U.S. is capable of counting 36 million votes by hand overnight as well, and most votes were once counted by hand in the U.S.
What constitutes what's "out of threshold"? If a voting machine, either by design or flaw, pushes a close vote outside the threshold - then that's a way to bypass the checks & balances and can be exploited by the unethical.
That paragraph is disingenuous. A vote that is outside the threshold for an automatic recount is not a close vote; the margin between candidates is thousands of votes (or more).
If a voting machine has a design flaw or other flaw, that would have been discovered during one of the several inspections and trial runs it was put through before being certified for use. Moreover, many states now require paper receipts of all ballots cast (as a result of Russian hacking of election machines in 2016), so if there is any suspicion of manipulated results, the human-legible ballot receipts can be tallied. States with these types of printed ballot receipts will audit the electronic tallies against hand-counts of the printed ballots on a random precinct-level basis.
It's a scalable method. Yes, the reconfirmation at the regional levels are important.
Your faith in machines is questionable. I leave you with this obligatory xkcd - it's still completely valid: https://xkcd.com/2030/
I don't trust the machines, but I do trust the people doing the counting, especially since the counting process is observed by both sides.
[0] https://ballotpedia.org/Voting_methods_and_equipment_by_stat...
Does the future of voting not belong to online remote voting, like almost everything else? You can even buy a house from your phone now. In the future, we will know the results of the election as soon as the online polls close.
The future is paperless.
I'm not. No one understands as well as technologists how often “novel technology” represents a regression from the tried and true, and how much the cry of “new” is used to sell defective crap.
> You can even buy a house from your phone now.
This is technically partially true in that a lot (not all) home purchase and finance paperwork can be done via electronically signed documents, and if you have a tolerance for extremely bad UI you can sign those on a phone. Typically, you’ll still need some wet signatures (notarized even) at the end of the process.
But that’s, even if it was completely accurate, a different problem domain than voting. (Both have concerns for assurance, but only one also has nonattribution as a critical goal.)
I actually do think that digital voting is theoretically possible, if done cautiously and in an open source manner. (it needs to be fully open source to be verifiable at all)
A remaining problem is that -in an election system- every voter needs to be able to check and perceive that the election was honest. That could still be a bit tricky in a society where not everyone is a programmer.
Another is that by going online you instantly open the attack surface up massively. Currently to steal an election you have to physically move a large number of people to a broad set of voting sites or send in a lot of forged mail votes. Those both require physically doing something in the US where an online system lets anyone in the world potentiall attack the system.
"Antiquated" is a loaded word that smacks of ageism. Restaurants are antiquated, too. Do you never go out to eat?
Does the future of voting not belong to online remote voting, like almost everything else?
Are you trying to say that every other country votes paperless? Because that's simply not true.
You can even buy a house from your phone now
You have obviously never bought a house, and certainly not one from your phone. Just because there's an ad on YouTube doesn't make it true.
In the future, we will know the results of the election as soon as the online polls close.
Why is that necessary? What benefit does it provide?
The future is paperless.
People have been saying that for over a hundred years. Yet, here we are, still with a durable, recordable medium that does things that paperless methods can't.
The modern restaurants is kind of recent, right? It was invented around the same time as the bicycle.
1. Voters vote by marking ovals with a marker pen on paper ballots.
3. The paper ballots can be counted by the optical scan machines that are already widely used in many places.
4. The paper ballots can be hand counted.
5. All the ballots can be published, allowing anyone to independently verify the counts.
6. An individual voter if they choose to can make a note of short alphanumeric code that is revealed when they vote for a candidate, and using that note later can verify that their vote was included in the total and went to the correct candidate.
7. An individual voter cannot prove to a third party that they voted for a particular candidate.
Here is a paper on such a system: https://eprint.iacr.org/2010/502.pdf
Wikipedia article on it: https://en.wikipedia.org/wiki/Scantegrity
Here is a paper showing how it satisfies item #7: https://eprint.iacr.org/2010/502
Almost all of the cryptographic mojo takes place when the ballots are printed, so no modifications are required to the scanners. You do have to use a special marker to mark the ballots.
Doing the cryptographic verification of all the votes would almost certainly be done by software, but as all the ballots are published and the system is completely open and documented, independent parties can easily do their own counts. The software is also fairly simple.
It's funny how things change. Just five years ago, HN was awash in people shouting that paper ballots are not secure and everyone should switch to electronic. Now the conventional wisdom is the opposite. Much like the way that in the 90's, keeping a password on a Post-It note was considered not secure, and now it's the safest thing going.
Instead, time after time, we get shady software from shady people with disturbing political connections (I’m not talking the dominion thing either — this seems true for all voting software). The idea that crooked politicians hire crooked companies to wrire crooked software shouldn’t come as a surprise to anyone.
Subscribing to this kind of "digital bad" dogma is lazy because you don't have to think for yourself.
But when people think elevator software is broken, they don't take the elevator. When (enough) people think voting software is broken, they topple governments and start civil wars.
And some people who disagree with you are still thinking for themselves. That "not thinking for yourself" is lazy argument.
This here is another example, nobody did any voting security research, some Trump associates just made up the idea, and were able to easily spread that messages to millions of people, playing a large part in inciting an attempted coup. The maker of that device is now suing for damages, as they should, and your concern is free speech again.
It seems almost performative.