An algorithmic failure beneath the secret ballot
blog.citp.princeton.edu
blog.citp.princeton.edu
So they were never secret in the first place.
I have never understood the desire to have voting machines when a paper ballot works just fine. We tried electronic voting in three municipal elections in 2008 and courts ended up invalidating the results due to horrible usability issues.
Some states do quite the opposite, e.g. seal ballots after the election and only allow inspection by court order. This has obvious benefits for secrecy, but then creates a lot of objections when people/organizations that doubt the election outcome are told that they cannot review the actual ballots (without meeting some threshold to justify such an order, which can be quite high since these rules were often put in place to try to counter pay-to-vote or voter intimidation schemes).
The existence of such a ledger isn't even required, but it makes it radically easier to audit the count process to detect errors. US election administrators demand a very high level of accuracy in vote counts (higher than what is typical in a lot of other countries), so in hand-count processes it's common to tabulate each ballot multiple times, and with machine tabulation there is usually some kind of automatic recount or risk limiting audit, either by retabulating with separate machines or hand-counting a sample. All of these are much easier processes when you can correlate a ballot to the previous time it was counted, so that errors discovered in auditing can be tracked to the specific ballot that was miscounted and corrected. Otherwise, if you count a batch of ballots twice and get different results (which is virtually guaranteed with hand counting), you will have to recount the entire batch over and over until you get satisfactory convergence. There are several different methods of doing this: some jurisdictions serialize ballots when they are printed so that tabulation can be tracked by that serial number. Other jurisdictions avoid this potential secrecy hazard by only serializing ballots after initial tabulation (e.g. ballots pulled for a sample audit have sequence numbers added on stickers or hand-written). Some tabulating machines can add sequence numbers as they run. All of these have different considerations as far as reliability and secrecy, but unfortunately there is next to zero funding or political interest in researching these issues and applying the resulting knowledge. The result is that everything is highly variable from state to state and some states continue to use processes that are known to have significant defects, most famously Louisiana with its ongoing use of non-auditable DRE machines (the only state that continues to do so).
Incredibly resistant to influencing at scale, resistant to voter coercion, transparent, and invokes a sense of occasion and community spirit.
The problem with electronic systems is the public can't see the piles of votes, can't get involved in the count, and ultimately it's the perfect system for being able to tip the scales subtly.
Even vote counting machines for paper ballots are a mistake in my view.
The need to balance voter security, with auditability, rapid Ness of results, with ease of setup/teardown of the voting place, is hard to beat with scanners.
(Within reasonable limits, I mean.)
There are elections in India and the US to control billions of people and some very aggressive military people armed with weapons capable of ending modern civilisation. This is one of the most fundamental social technologies we have to keep the whole system stable (up there with limited liability corporations and courts). The downside of one of those elections failing because of voting machine trickery is stupendous.
Frankly, I'm not sure even auditability is that important as a design goal compared to voter security. If the election is close enough that an audit matters the two candidates are pretty similar. In practice, if there is any meaningful gap in preferences then the outcome of the election should be clear enough that an audit isn't that meaningful. It's nice to have and it is cheap enough to include in a paper ballot.
Because it is a low-frequency, high-importance activity that uses public facilities.
We close the polls at 1900 and have a Collector Officer run one copy of the data on a thumb drive to the County.
The Chief gets to deliver a backup a couple hours later.
Hand-counting the ballots instead of scanning would be expensive in terms of time and money, and error-prone.
I'd argue that Fairfax County, VA is about optimal, all factors considered.
As I'm fond of saying: "Virginia is for lovers...of elections."
In Blighty, we have paper voting. The polls close at 10pm, the manual count takes place overnight, and the result is typically known the next day.
How much more rapid do you need?
In the US, the election is in November and the president doesn't get sworn in until January. It could take a couple of weeks to count the votes and it would be fine.
Unless those volunteers are all die-hard fans of a particular party/candidate and thereby intimidating everybody that has a different opinion. (Not openly of course, but if everybody knows everybody, the mere presence suffices to sway people.)
The process is quite fair and rigorous.
I think machines are only acceptable if they sort ballots into multiple bins, not if you are using them for the actual count. The bins should be designed so you can casually see that the last ballot to be added is correct for that bin while the machine is working. Something to insert a marker every 100 ballots is probably a good idea, then you can count the number of hundreds, and randomly sample a few of them to check they are correct.
This is the right answer. Using tech as an auditor for batches after manually counting could be useful. Getting everyone together to count votes in a process that everyone can see, understand, and be personally invested in - that process is what is needed far more than efficiency, at this point in time.
In person paper voting, however, only works on a relatively healthy democractic community. What used to happen around here was that whoever was the local hegemonic power, mostly oligarcs, sometimes gangs, would just plant a grunt in the voting halls and coerce people to reveal their votes. That or they would simply have a bag of pre-cast votes and drop them all in the ballot box. Lots of absentees and dead people used to happily cast votes at the time.
So ultimately the full electronic system has been working quite well over here for the past 30-something years. It has only really started to be aggressively questioned since 2016 with the rise of social-media as an election driving powerhouse.
For example, while the software and hardware is audited by a very diverse panel, it's too institutional: you can't inspect it as an independent researcher. It's also not clear which parts of the supply chain are subject to the audits. I trust it's all of them, and these institutions are doing their job of pointing out the parts that they have _not_ audited, but I, as a member of the public, can't verify.
Seems like this is the same mode of failure, which is strange considering diebold made the brazilian machines back then and should have fixed that.
What a bunch of silly clowns with their silly little whoopsies! Maybe they'll get it right someday.
[0] https://www.wired.com/2006/09/e-voting-machine-an-easy-hack/
...
Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."
---------------------
1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.
2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)
I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.
Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.
If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)
This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.
(If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)
> Either upgrade your pseudo-RNG
It seems grossly negligent that a voting machine is using a non-CSPRNG.
> Dominion has not shared any details about the new PRNG.
The machines should be kept air-gapped, not connected to the Internet, and all that. But again, human nature kicks in. There have been some poll workers who swore under penalty of perjury that in their polling place, there had been election machines that got an over-the-wire software update on Election Day. That's just... all kinds of wrong, if those reports are accurate. It doesn't prove cheating, but it does prove that whoever was in charge of that polling place should be fired. Because part of the job is making sure everyone knows the results are valid and accurate, and having voting machines connected to the Internet goes directly against "hey, you can see that no hacking is possible here". Doesn't matter how much the machine's manufacturer promises their machines are unhackable, the machines should not be connected to the Internet at all once they are actively being used for voting.
At this point, I'm ready to go back to paper ballots and a locked wooden box (kept in public view, and publicly verified to be empty before locking it up) myself. The simpler the solution, the better, is what I'm arriving at.
The simpler the machine, the better. As I said in my other comment, I'm about ready to go back to locked wooden boxes myself, opened and counted in full view with cameras rolling.
At least at my polling place (but I'd really hope this is universal), the machine (the ballot box, effectively) is in the middle of the room, and closely watched. You would not be permitted to stuff more than one ballot into it. (Not to mention this would be voter fraud.)
> Easy to do if the voter and the poll worker are in cahoots.
Again poll watchers are the answer.
> The simpler the machine, the better.
The simplicity of the machine does nothing for this attack? In fact a wooden box is perhaps most vulnerable. But, again, this is completely mitigated by poll watchers. (Not to mention such an attack would likely be mitigated by other voters simply going "yo, what are you doing?"…)
> Would be caught on a recount... probably.
… aside from perhaps a discrepancy between the count of voters who voted on the roll, and the number of ballots in the box (on the initial count), a recount isn't really catching this.
I suppose if I wanted to mitigate this, you could put a signed "This is the ballot for the 2026 election" (+nonce, so that if someone duplicates it, we can pick out the duplicates/replays) on the ballot paper, and attempt to control physical distribution of actual ballots. But now we need to generate a nonce, and we're right back to "I'm sure an LCG is sufficient, right?"
We forgot what it took to be where we are.
"a security vulnerability disclosed back in 2022 shows the shuffle can be reversed, and some states have not applied the software update that resolves it."
"a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots"
"Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing."
I can tell you that before WA went to all-mail voting it wouldn't have happened, because I served as a pollworker and election site inspector. There was a optical scan ballot reader / counter, my confidence is high it only kept running totals. The ballots fell into a bin, at the end of the day the bin was unlocked and the ballots were tossed into bags (no particular order) which were then sealed. As inspector I printed a copy of the tape which went downtown with the bag(s); they would have been able to print a new tape until the machine's memory was wiped (at which point they still had "hardcopy backup"). The ballots were not marked upon by the scanner in any manner. There was an incident where one of the ballot printing / counting companies (because they both typically had to come from the same manufacturer) started printing sequence numbers on ballots (not just ballot styles) and that went to court.
I've not witnessed what happens with all-mail voting, but there is no sequence number on the ballots. ;-) The count is not supposed to start until the polls close. Before that the ballots are ostensibly separated from their identity (the envelope) in an identity confirmation ceremony. My impression is that they're scanned at this point and the scans are utilized for counting / optical scan, but I'm not certain about this or that it's the same everywhere. I don't know what happens to the physical ballots; back in the day what I know is that if a ballot needed to be corrected (defacement or damage renders it unreadable) then a new ballot was prepared under the supervision and adjudication of election observers and the old ballot was destroyed; but that's the exception which proves the rule that physical, anonymized ballots were retained.
The voting process is in the hands of the individual (United) States; in WA it's largely in the hands of the County administrators and varies to a degree Statewide.
Draining it, more like.
There's probably an angle I'm not thinking of here, but imho, it's absolutely not John Q. Public's damned business what a person does or does not do on election day.
But it's such a specific structure, clearly there was an objective in mind when it was imlpemented.
Actually, it does. If the party you are registered with thinks are a voter who might not make it to the polls, and this is a close/important election, then there is a good chance you will receive numerous calls and/or visits reminding you to go out and vote. However, if you show up on the list of people who have voted by mail OR if you appear on the registry of people who have already voted in person, then they will stop reaching out to offer rides and reminders.
It's hard to say how much impact it has, but presumably there's a degree of social pressure when people are seen wearing/posting all those "I voted today" stickers.
Originally, everyone in town knew most everyone else and could see them physically walking into the polling place. So long before electronic records were kept, the question of who voted was public information.
Even today, I run my local polling station and I know and recognize a significant portion of the voters in my precinct.
The fact that the list of who votes is made public protects against several kinds of abuses. It goes a long way to protect against "dead people voting" and other kinds of ballot box stuffing if the list of voters is public so anyone can review it and potentially catch such abuses.
i.e. 'Justice must not only be done, but must also be seen to be done'
Now, in that particular case, the state (I believe it was Colorado though I'd have to find the article I read, and I don't remember where to find it any more) didn't require photo ID, so there was no way to prove that the people showing up on Election Day were the actual voters, as opposed to the cheaters. But this poll watcher's opinion was that they were the actual voters, and the cheating had been done by whoever had submitted ballots in their name days (or weeks) earlier. Given how many people she said this had happened to, I'm inclined to agree with her: it wasn't three or four people, it was (she said) something like one-third of the people who showed up on Election Day at that polling place.
That's a case where the fraud couldn't be repaired by knowing that it had occurred — the fraudulent ballots (if they were indeed fraudulent) had already been accepted, and it was impossible to go pull the ballot allegedly belonging to Joe Smith back out of the ballot box. But the publicly-available list of "who voted" did at least make it possible for the fraud to be detected in that particular case.
I personally do support voter ID, and for the same reason. Members of the public must be able to verify the process is happening fairly. It might be fair without it (fraud truly negligible), but it must also be seen to be fair. This would resolve so many controversies.
Likewise mandatory voting and private ballots (can cast a donkey vote) helps ensure the public people are not being paid to vote and that other biases are not coming into play.
My personal opinion is that if people think they can benefit from cheating, a certain number will do so. It's just human nature. We're seeing more and more of this with LLM cheating on the rise in universities. So there's always going to be a certain number of people who want to vote fraudulently — after all, if the right person gets into office, it'll probably benefit you. Your taxes might be lowered, or your government handouts might be increased, or whatever other reason you have for preferring one politician over another. Preference alone does not mean that people will vote fraudulently: after all, most legitimate voters also prefer one politician over another. But the easier you make it to cheat, the more people will cheat successfully: among those who wanted to cheat but didn't, usually the only reason they didn't is because they couldn't see how to get away with it.
So photo ID to vote just seemed like common sense to me, along with other measures like ballot boxes kept in a publicly-visible place until they're opened, to help prove that nobody has tampered with them. (Read up on the 1946 elections in Athens, TN sometime — there, the fraud was being done by the sheriff and his cronies who would take the ballot boxes away, "count" them in private with no outside observers present, and announce that surprise surprise, the sheriff's crony had won the election again).
In the last general election 16,000 people were prevented from voting because they didn't have the correct ID - despite there being mechanisms for them to get suitable ID for free ahead of an election.
Sometimes the fix is worse than the actual problem you're trying to solve.
Also, without a photo ID the fraud rate is near impossible to measure - people can just sell their votes to imposters, fabricate voters, etc. It would be undetectable in your stats. A similar concern applies to postal votes, and there have been high profile cases of this in the UK.
As a concrete example The Tower Hamlets Scandal saw Luftur Raham's election declared null 'on the grounds of corrupt and illegal practices by him and his agents, and general corruption so extensively prevailing so to reasonably supposed to have affected the election' despite a similar number of low hundreds of allegations of fraud. That's a proven-in-court example showing you are wrong to dismiss the concern based on the data. The methods used are clearly not detectable by the system you endorse, and that system has demonstrably lead to the unjust disenfranchisement of your fellow countrymen.
That is why I like voter ID if it relies on documents provided for free with minimal fuss.
However, every US state I'm aware of (if you know of exceptions, please let me know) has some form of photo ID you can obtain for free. Usually it's in the same format as a driver's license, and obtained from the same place (the Department of Motor Vehicles, Department of Land Transportation, the name varies). There's a fee to obtain a driver's license, but a photo ID card (in the same format as a driver's license but marked "NOT LEGAL FOR DRIVING" or similar wording) can be obtained for free, by going through the same process as getting a driver's license (bring something to prove your identity, get your photo taken, wait for the card to be printed) but without taking a driving-skills test.
And before someone asks "what about the people who can't prove their identity"? Well, I can actually give an anecdote. I know someone who ended up in that situation: away from home for college, couldn't get her birth certificate or anything else, and needing to replace her passport that was lost. (She is American but had grown up overseas because of her parents' job, hence why she had a passport but no driver's license when she went off to college). She had quite a time of it at first, since every "prove your identity" requirement circled back around to another form of ID. But she was eventually able to get a fishing license just by swearing under penalty of perjury that she was indeed (name). With that in hand, she got another form of ID (I think a library card, though there my memory is iffy), then with two forms of ID she could get something else, and then eventually she was able to get that non-driver's ID card... and then was able to prove who she was to get her lost passport reissued.
That all happened nearly 30 years ago so I can't swear to the details. But the point is, photo ID cards are widely available, and it's normal to be asked for one. So as long as the law specifies that acceptable forms of photo ID include X, Y, and Z (where X, Y and Z are forms that most people would already have, and that are normal and in common use), and as long as at least one of those forms can be obtained without a fee (which as I said, is true in all U.S. states that I'm aware of, please mention any exceptions you know about because I'd like to know) then it will pass Constitutional muster.
And you have some memory of some account from someone 12 years ago in a state you can't remember saying that a third of voters had someone pretend to be them?
If this were close to true, it wouldn't be some blog post that you can't remember; it would have been a national scandal and it would have been something that we would never forget because the election stealer conspiracy theorists would never let it go.
Really, you should just delete this post as it's irresponsible and lacks any data.
The idea that if we had paper ballots with walk-in only, ID-verified votes, that Trump and Fox News et al wouldn't have launched a coup attempt, or wouldn't have gotten nearly as far, is pretty laughable. In fact we have Trump on the record saying as much: "It doesn't matter whether you win or lose, you have to fight like hell."
Let's take your scenario. In fact there is a way to verify which vote was correct (and it's used already) which is to match the signatures between the voter registration and the ballot.
This is sufficient except in cases where the registration itself was fraudulent, which would have required 1) having someone's ID at time of registration and 2) intercepting the mail sent to their ID- or utility-bill-confirmed mailing address.
An attacker who could achieve that could also have achieved just walking into the polling place to achieve the same false vote.
Any attack is extremely expensive to do at any meaningful scale, and all scaled attacks are detectable by simple statistical sampling.
If meaningful amounts of tampering were detected by statistical sampling then you can obviously re-run elections with tighter controls, more burden, lower turnout, and a generally-less-representative result, which is why we start with a more inclusive system. This can and does actually happen. Whether it's necessary is literally 100% statistically knowable through basic sampling.
But you did that by making a big, surprising claim for which you haven't provided any evidence. You might not intend for that to be the main thing people focus on, but they are right to be both interested and skeptical! If true, it's a big deal.
The closest thing I could find is this (https://www.thenation.com/article/archive/voters-predominant...), which was attributed to 'human error' rather than fraud, and was resolved by allowing the affected voters to cast provisional ballots. 'Human error' is a vague explanation, and for all I know it was a coverup -- but the onus is on you to provide some positive reason to believe that. Surely there were plenty of people motivated to investigate this, so it would be surprising if a bullshit explanation was just quietly accepted and no further public attention paid.
Not sure why your OG post is still up.
Voter ID solves a non-existent fraud problem and does so by making voting harder.
Quite a few husbands believe they should have control over their wives' votes. I guess you'd say they should have the courage to leave them and wreck their children's lives and be ostracized by their family and community?
And it's not hard to imagine certain employers having a strong opinion on how you vote on specific measures. Of course they couldn't compel anyone to reveal their votes, but it could be made customary enough that refusing to would be enough of a signal. I guess you'd need the courage to quit and take a lower paying job?
As for what happens in marriages or other social settings, yes, wives can coerce their husbands, fathers can coerce their adult daughters, friends can coerce one another. If your counterpart is the kind of person who would threaten to blow up your relationship over how you vote, yes, I would suggest maybe that tells you something about who they are and whether or not you want them in your life. But if the relationship means that much to you, you can always go along to get along and let them tell you how to vote. I think that says something about how much you value your vote though. And at the societal level, I don’t think this would have a meaningful impact on governance
I don't think they can be dealt with. But I'm willing to listen to your ideas. How would you deal with vote buying? How would you stop the scenario where a guy says "I'll give you $1,000 if you vote for candidate X" (or "I know where you live, I'll break your kneecaps if you vote for candidate Y")?
Of course it's pretty impractical that a bunch of concerned citizens might gather together and check the published data against how they each remember voting. But preserving the possibility in principle makes it easier to trust the published results. It gives a would-be deceiver yet another thing to worry about.
Its a trade-off I'd have opted into had I been asked. Though I'd feel a lot better about it if I had been asked.
The biggest problem I see related to that is the marked haziness over what exactly has been accomplished. As best I can tell, this paper claims to have deanonymized primary election ballots that were cast during the early voting period. But it's written as if it was deanonymizing general election ballots cast on election day.
> Tied to a specific ballot is the stronger claim and requires one additional public record.
clearly a claude-ism
I guess the author went back and forth running pangram and slightly tweaking the text until it read "0% LLM text"
This is in the site guidelines: https://news.ycombinator.com/newsguidelines.html.
> HN is for sharing between humans
My (and others’) comments are knee jerks when that guideline gets violated.