Dominion Voting Systems and Fox reach last-minute settlement
cbc.ca
cbc.ca
The fact of the matter is our elections are not secure, in the sense that their results cannot be cryptographically verified. You either cannot verify your vote was counted, and/or cannot verify it contributed to the total votes received by the candidate for whom you voted. In aggregate, we can rarely verify that "all legitimate ballots were counted," and can never verify that only legitimate ballots were counted.
This is a problem, it's been a problem, and it will continue to be a problem. Our election infrastructure is only secure insofar as people trust it's secure, and people can only trust what they can verify. Otherwise, the winning party is asking the losing party to commit an act of faith in "trusting" a system that cannot be verified for correctness.
In 2017, Democrats recognized it as a problem, just like Republicans did in 2021. Yet we have so much whiplash from back and forth politicization of the issue that it's impossible to have a sane discussion about it.
* Use paper ballots with fill-in-the-oval results. This method has very little chance of user error filling out the ballot (modulo concerns like two-sided sheets, etc.).
* Chain-of-custody the ballot box the ballots get fed into at the polling place. Keep a roster of who voted, which lets you count how many ballots should be in that box. If that count is incorrect for the number of voters, you have issues. (This is rare.)
* Count the ballots with a ballot-reading machine. Verify the machine's counts by doing hand checks of samples. (The US runs too many races not to use machine counts.)
* For mail-in ballots, use envelope-inside-envelope to preserve secrecy. The inner envelope contains the ballot, and only the ballot, while the outer envelope contains the information needed to verify the voter.
At that point, the only real question is determining who is eligible to vote, and it turns out that it's not really a question about the security of the voting process, but rather about how to prevent the undesirables from voting. Aspersions on the security of the voting process are really about trying to justify changes to laws to keep undesirables from being able to vote.
Or you could assume Skynet's clever plan is mass election fraud and making sure nobody ever finds out or tells.
Note the "secretly record" element in [https://www.schneier.com/blog/archives/2007/12/more_voting_m...]
Bruce Schneier is not a crank, he's written extensively over the years on the issues and the one I'm pointing out is just one specific one of many. As a software developer yourself, you might be capable of taking these issues seriously.
The topic is nearly the same, - some people found some irregularities in some counties - but the tone and treatment of the claims is drastically different. It's worth considering how we discuss election security through a partisan lens.
[0] https://www.schneier.com/blog/archives/2016/11/hacking_and_t...
[1] https://www.schneier.com/blog/archives/2020/11/undermining-d...
The article you linked doesn't seem to have any connection to the flow where a computerized machine helps mark a ballot, drops it into your hands, and you can see and review it before dropping it into a box to be counted.
1. The ballots can be published after the vote allowed anyone to verify the counts,
2. Individual voters can, if they want to, note some information when they vote that will allow them to verify when the ballots are published that their vote was counted and it was counted correctly, but will not allow them to prove to a third party that they voted a particular way,
3. Individual voters can check before they vote that the ballot they have been given has probably not been tampered with.
[1] https://www.usenix.org/legacy/events/evt08/tech/full_papers/...
This would work better if mail-in ballots were only printed on request, and had some kind of one way hashing so that someone who voted by mail could optionally verify their vote was counted correctly.
Otherwise, isn't the count unauditable as soon as ballots are separated from their envelopes? You can only verify that the number of ballots matches the number of envelopes, and perhaps that there exists a bijection between them - but you cannot verify that the same set of ballots that was in the envelopes was the set of ballots which was counted. How can you verify that ballots were not replaced, after removing them from the envelopes but before counting them, with duplicate ballots that contained different votes? An attacker might not even need to duplicate a unique ID on each ballot, depending on how the "verify my vote" system is setup, because the verification is only that you removed a ballot from my envelope. As a voter, I can call my county and offer the ID number from my envelope, and the county can honestly tell me they "processed" it - but I cannot verify that my ballot itself was "processed," nor can I verify that it was counted toward the total votes with the weight I'd expect given the number of voters.
Inversely, it's important that mail-in ballots only be printed on request, and that the (potential) voter receive a unique hash upon requesting the ballot (not just after voting with it). Because that way you can ensure that if someone receives a ballot but doesn't vote, they can call to verify that their vote was not processed. Whereas if they only receive a unique hash after voting, then only those who executed their ballot could verify it was counted, and any unexecuted mail-in ballots could be mixed into the tally with confidence that nobody would call to verify they were not counted.
Surely there is some kind of "accumulator" system that can be used here, but I'm not familiar enough with the literature to identify it.
However, I think it's clear that this is a deceptively hard problem, and worth the effort of our best minds publicly solving it, rather than deferring it to a private Canadian-owned, Serbian-operated corporation that produces proprietary systems and sues anyone who questions their trustworthiness.
For example: Swap a pile of mail-in ballots (recently separated from their envelopes) with an equally sized pile of pre-filled malicious ballots. Or, take a bag of ballots from rejected envelopes, mix them with uncounted ballots from accepted envelopes, and then replace some of them with prefilled ballots. Or commit any other uncorrectable chain of custody violation that allows you to introduce new ballots into the count, but that could also feasibly be an accident. When challenged, don't admit to introducing additional ballots, but openly admit to the tainted chain of custody, and claim it was a mistake.
It's unlikely you'll face any real consequence, and you can accuse your opponents of being election deniers. Yet you had the chance to intentionally introduce phantom ballots into the counting process while increasing the expected error margin of any potential audit.
Note that you can still process every legitimate ballot, and confirm to any voter that you processed their ballot. And maybe you can even confirm to any non-voter that you did not process their pre-mailed ballot. But you cannot confirm that you processed only legitimate ballots.
In other words: one plausibly inconsequential broken chain of custody is sufficient opportunity to introduce new ballots unassociated with any real voters.
https://en.wikipedia.org/wiki/2018_North_Carolina%27s_9th_co...
Due to possible voter mail fraud, the election results were not certified and the election was redone.
Chicanery in vote counting doesn't happen in the US. There's just too many eyes on the system, and the system is just too distributed, for it to be effective. If you look at the way that political parties try to manipulate the elections, it's by attempting to prevent people from voting in the first place (and those attempts are much, much more successful than they should be).
Isn't this by design? If you can verify this, then someone else can force you to verify it in front of them to make sure you did what they told you to do, and then we don't have a secret ballot anymore. It's not obvious to me that the risk of fraud from miscounting is worse than the risk of fraud from voter intimidation or bribery.
Imagine everyone you know is posting screenshots of their verification on social media, and you voted for someone or something considered controversial in your community. If you post that verification you get harassed, if you don't post anything then everyone knows what that means and you get harassed anyway. That's the type of voter intimidation I'd worry about.
Not being able to prove to someone else that you voted a particular way is called "coercion resistance", and it is in fact possible to design a voting system where you can verify you vote was included and counted correctly but that are coercion resistant.
See this comment [1] from a while back about such a system. Link #3 in that comment is to a paper showing that system is coercion resistant.
There are several systems that provide verifiability but are coercion resistant. The one discussed in that comment is noteworthy because it is an easy add-on to existing optical scan voting systems. The cryptographic cleverness that it depends on is in how the ballots are generated and what is printed on them, with the only modification in the voting booth is that you have to use a special marker to mark the ballots.
However, I see two potential problems and I don't think this would satisfy anyone that is concerned about election security in America. First, this is vulnerable to someone accidentally or intentionally writing down the wrong code on their receipt, and then going on TV to display it as irrefutable proof of election fraud. With 150+ million people voting there is basically 100% chance that will happen many times.
Second, this system proves that your ballot was received and uploaded to a government website. That does address a claim of "they threw my ballot in the trash", but it does not address:
1. They're busing in illegal voters
2. Election workers are all corrupt and are just making up the count
3. They flipped my vote
4. Foreign hackers infiltrated the system and added more votes
5. They added a bunch of fake votes last minute when my guy was about to win
6. My guy did 15% better in exit polls than the actual count, something is up
etc. etc. Here's a list of real-life fraud claims, I don't think Scantegrity would resolve any of these: https://www.factcheck.org/2020/12/nine-election-fraud-claims...
To be clear I don't believe any of these things, but this is the sort of stuff you hear from people who are worried or claim to be worried about election fraud. They type of person who would be satisfied by their Scantegrity receipt is not the type of person who is currently making noise about election integrity.
Sorry to move the goalposts, you completely addressed the issue I described in my last comment. I'm just trying to think through if this system would actually fix anything in the US, and I think it would not. I do think it's a good idea though, and it certainly wouldn't hurt.
Votes are counted at the district level, with only totals being submitted up the chain, in order to protect privacy.
It's simple and it works.
When some battleground states routinely come down to less than 1% of voters, incredibly marginal effects matter.
The US still has institutional trauma from Hanging chads.
Just look at all the varied reasons mailed ballots are rejected, especially in tight races.
With paper and pencil, what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled? All of these are questions that will be the subject of lawsuits in a mix of jurisdictions.
> what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled?
When I sit down to vote, there is a very unambiguous set of instructions on how to fill it out: mark an X in the circle.
- we all know perfectly well that pencil erasers aren't perfect
- It's not a Scantron™ ffs! Is that what you're imagining? That's just a voting machine with extra steps! Every single ballot is counted by a human! https://electionsanddemocracy.ca/canadas-elections/canadas-e...
What do you do if someone marks something like a Y and it looks like the ink ran out?
(My local elections are indeed a Scantron-style procedure, incidentally. Bubble in the entire circle.)
> First, election officers open the ballot boxes and count the ballots.
Note the plural.
Safeguards for Counting Votes and Reporting on Results: https://www.elections.ca/content.aspx?section=vot&dir=int/co...
Votes are counted by humans. It's not "fill a circle", it's "draw an X in a box". It's not ambiguous.
France has much stronger controls on ID checks at the voting booth and vote by mail (in fact for most elections there is no vote by mail, you can only delegate your vote to a person who cannot act as a delegate to more than two people to prevent ballot harvesting).
After the vote, you can check the status of the ballot's serial number at the appropriate city/county website. It won't tell you who voted or the votes cast, but that it was received.
So while the website won't link you to your votes, the city/county could absolutely make that connection since they control the serialization and the mailing. One hopes that they don't do this, and I'm sure they're not suppose to, but trust and wishes are the best surety we have for vote by mail ballots... there are ways to defeat the loss of anonymity in this case, but they involve not voting by mail or providing false signals (i.e. swapping ballots with someone else in your district).
It's one of those things that sounds bad in theory but is rarely an actual problem in practice.
The boxes are opened for counting as part of a public process, with independent observers.
My ballot has a tear-off receipt and a bar code. I can verify when and how my ballot was counted. If I suspect fraud at the ballot counting site I can supervise the process myself in person. If my signature doesn't match the ballot office can contact me to verify.
There is no world where cryptography is a requisite for ballot security, and I would not want to live in a world where computers are required for something as basic as democracy.
This is not the difficult problem. The difficult problem is that we have thousands of systems, depending on where you live, and politically, getting anyone to agree on any one system is probably impossible.
But I am with you, cryptography is absolutely not required, and computers should not be fundamental to the process. Hell, electricity should be optional as well, just in case the shit hits the real fan.
In 2016, Hillary beat Sanders by up to ~12% more than exit polls would have suggested in states without paper trails. [0]
The fact that this only happened in states without paper trails raised some eyebrows among Sanders voters, but "Democrats" bent over backwards to explain how this was just a quirk, and 'probably the fault of Bernie Bros somehow anyway, who gives a shit about them, they're not Real Democrats TM'.
And then we stopped doing exit polls at all. Because apparently that's a sensible thing to do when there's no paper trail, and indications of systemic fraud - remove the only remaining tell-tale sign.
So, yeah - this is a problem, will continue to be a problem, and will be completely ignored by media unless it serves them to associate questioning voting machines with the far-right.
0 - https://www.snopes.com/fact-check/stanford-study-proves-elec...
Did you read your own link?
"Suspect at best" is really not a fair takeaway, unless you're cherry-picking quotes at face value. Myself, I found the responses to the paper rely on bluster and don't hold much water at all.
If you want to see the responses taken apart, with more on the abysmal state of voting machines and the untrustworthy sounding electoral folk responsible, you can read this: https://www.counterpunch.org/2016/05/16/clinton-does-best-wh...
I know that the userbase on a site like this one tends to want to solve these types of issues with technology, but that's just because all we've got here on HN is a hammer, ya know?
Pencil-and-paper works. Anything else is a solution in search of a problem.
Paper has its own issues, effectively illustrated by photos from 2000: https://imgur.com/a/lpDhmQP
https://www.theguardian.com/politics/2015/may/06/vote-with-a...
> The official body supervising the British general election on Thursday has said votes should be counted if support is expressed by the drawing of a smiley face, instead of a cross, as is requested at the top of the ballot paper.
> Also permitted is writing “yes”, and drawings that may well be accepted are those of a flower, and sketches of naked people, though best if they are smiling.
https://www.revisor.mn.gov/statutes/cite/204c.22
> If a mark (X) is made out of its proper place, but so near a name or space as to indicate clearly the voter's intent, the vote shall be counted.
> If the names of two candidates have been marked, and an attempt has been made to erase or obliterate one of the marks, a vote shall be counted for the remaining marked candidate. If an attempt has been made to obliterate a write-in name a vote shall be counted for the remaining write-in name or marked candidate.
Hand marked paper ballots allow for an audit trail. Paper allows the voter to check before submitting the ballot. Paper allows easy correction by trading for a replacement. Paper works well. As is confirmed in audit after audit after audit.
roughly the way it works is - there is standalone electronic voting machine (EVM). it is NOT connected to network at all. for each vote, a receipt gets printed and vote puts that receipt in ballot box. the EVM count is used to aggregate over vote count. it speeds up counting process. Some percentage of randomly selected voting machines vote counts and corresponding printed vote ballot is cross verified.
During the whole process, a representatives from all the parties are present in all election activity
That would break the privacy of the vote. It would allow for actors to oblige or coerce people into voting in a candidate and then forcing them to prove their vote.
Fraud exists and should heavily be punished but I think its effects are overstated by everyone.
Still, it would have been nice to get some light on both parties.
It would also be nice to know what the final settlement ended up being.
But with the settlement I doubt that will happen.
We’ll see if that was just posturing with what the settlement terms end up being.
I’m always amazed that firms go right to the brink of trial before settling. Sometimes the judge issues certain rulings that may lead a party to realize their odds are lower than hoped. But otherwise it seems like both parties wasted the court’s time when a settlement could have been reached at any prior point.
Settling often deprives the country of useful case law, or prevents bad actors from having to admit guilt. Totally understandable for the parties involved to take the sure thing rather than risking it all on a trial but it does negatively impact our society.
> another U.S. voting technology company, Smartmatic, is pursuing its own defamation lawsuit against Fox seeking $2.7 billion US in damages in a New York state court.
> Fox Corp. shareholders are demanding company records that may show whether directors and executives properly oversaw the Fox News coverage of Trump's election-rigging claims, sources told Reuters, in what could be a prelude to lawsuits seeking to make directors liable for costs.
https://en.wikipedia.org/wiki/Dominion_Voting_Systems
However you feel about the claims made during the 2020 election, that should terrify every American that closed source computerized voting machines from a single company counted enough votes to potentially decide the presidential election. I’m not saying that any of Trump and his supporters claims have any substance, but the optics of that stat do not look good.
Voting machine software should be public record and produce a fully auditable paper trail.
The fact that voting is administered at the local level is one of the biggest fraud protections we have. It drastically reduces the damage that can be done, and makes outliers much harder to hide.
Hypothetically, (again, I’m not saying this is actually what happened in 2020), compromised voting machines could easily sway a national election by being installed in a relatively small number of counties.
See the below voting map by county for the 2020 election…
https://www.nytimes.com/interactive/2021/upshot/2020-electio...
If it’s the former then the voter can actually verify that the machine cast their vote as intended. If it’s the latter, there is literally nothing stopping the machine from changing votes as they are cast.
To clarify I’m not saying that is actually happening, just that there is nothing stopping your vote from being switched by the machine either through malice or a software bug if the machine doesn’t generate a physical slip of paper that you actually put in a ballot box.