Programmer under oath admits computers rig elections
youtube.com
youtube.com
You can envision a system as complicated as you want, but it'll always have some sort of flaw because, well, bits are bits. I've had this discussion with many people and the same solutions arise again and again... but most are useless.
You could get the source code for the voting program... what if your compiler is backdoored? You could compile the compiler yourself, with which compiler? The backdoored one?
And even if the compiler is trustworthy... who's guaranteeing that the real binary is installed in the machine? You could download it in an USB drive and check yourself or get a hash from the machine but... how can you be sure the machine is reporting the binary that's actually running and not just a fake reply? Could you trust the reported MD5/downloaded binary from the machine?
Easy! - you say - You could upload the binary yourself to the machine! But how would you be sure you're running the uploaded binary and not a fake one?
And what if any of the machines inbetween are rigged?
Then cryptoguys come in: you could digitally sign your vote (forget secrecy) with a state-issued certificate (we have those in Spain with our NID). Maybe encrypt it so that only the far end could read it. You'd then check if your vote's been cast fine online. But how'd you be sure you got the real result?
Once the data left the machine you have to trust that everything's fine on the receiving end. What if the vote count just ignores votes and just does whatever it wants?
And the worst of all... how's your granny supposed to check it herself?
There are some advanced cryptographic techniques relevant to e-vote (some are quite clever) but even the best cryptographers will tell you: do not trust electronic voting!
My advice is: keep with pen and paper! It's easy to tamper with too, but more people know how it works and it's easy to see the inner workings compared to bits over the wire.
Good call about the disabled. What are the current systems doing for them?
There are many systems for the disabled -- it was a big priority of the Help America Votes Act, which is what prompted this wave of computerized voting machines. The Auto
Real cryptographic voting systems use verifiable protocols. You don't trust the machine, you force it to follow a protocol that involves proving its actions are correct at every step.
You can verify basically everything except destruction of information (i.e. there's no way to prove with cryptography that a video camera didn't record the voter).
Video with an example of a verifiable voting protocol: http://www.youtube.com/watch?v=ZDnShu5V99s
Last time I checked the protocols had several drawbacks (including the "destruction" problem, vulnerable to collusion, etc.) Maybe I missed good protocols? Could you please point me to good papers? (a video is too slow and hard to skim over).
Thanks! I'll check the video ASAP and report back if I have questions!
I mainly commented to remind people that computer voting systems don't have to be glorified counters. You can actually use their strengths (crypto), instead of only inheriting their weaknesses (malleability).
It probably should be about the data. The data should be openly available to everyone.
But there are some requirements to the data that make this tricky (understatement).
With the data in your hand it should be possible to independently verify the results. It should be possible to individually verify that your vote is somehow in there. But it should NOT be possible to link votes to individuals, it should be completely anonymous.
This is not a problem that is likely to be solved by software engineers. If there is a solution, it is in crypto and math more than software.
I do think this is an important problem to solve. It would enable the ultimate democratization. Instead of voting for representatives it would become feasible to directly vote on issues by referendum. If tech is about anything, it's about democratization and cutting out the middle man.
This doesn't mean that you couldn't or shouldn't have a paper trail as well. As long as you have a single end-point, then yes, the issues you brought up are valid.
Super easy, you should go shopping.
If this problem were so trivial, then I think some of the big names in crypto would not have wasted their time on studying solutions. As it is, though, I don't think there are any convincing arguments for why this problem is "trivial." Instead, there's a laundry list of properties you want a good voting protocol to have, and developing a cryptographically secure protocol that satisfies those properties is highly nontrivial.
My opponent did not question particular properties of this scheme but instead went on the tangent of properties, which none of voting methods currently has. Hence, she or he could as well request cancer cure.
Unless you know how to use this huge product of primes to verify that votes have been counted correctly.
That said, in my opinion, Clint Curtis is not a credible witness. What he claims is certainly plausible. But he doesn't have the technical chops to pull it off.
For something more reality-based, check out voteraction's lawsuit in New Mexico. http://voteraction.org/legalaction
VoterAction proved that Kerry won NM in 2004. What happened in NM certainly happened elsewhere. Especially Ohio, which had so much going on in so many directions, there's no way to summarize other than to say "death by a thousand cuts".
Briefly, in NM, spanish language touchscreens did not count votes cast for Kerry. Further, "faulty" storage devices (memory cards) were sent to back vendor HQ to be fixed, totally mooting the chain of custody, etc.
The whole election integrity thing is like a jumping down the rabbit hole. Things are so ridiculous, it's hard to believe. And when you try to explain to people what's happened, you're dismissed as a "sweaty paranoid kook" (that's a quote).
Speaking for myself, I used to think that I mail my ballot and it gets counted, what could be more simple? The more I learned, the more my confidence was shaken.
I could go on and on and on about this topic...
[1] Yes, I've studied the crypto proposals. They're included. Briefly, crypto schemes rely on a secure one-way hash to hide your ballot in the herd of ballots. Alas, US elections are administered per precincts (1-1000 voters) and typically have a dozen or more issues per ballots. Meaning combinatorially there's no way to hide an individual's ballot. Crypto works for simple ballots with thousands of voters.
Of course such a system will never be implemented because doing so requires the cooperation of those in power including those who stand to lose from such a change, so it is in the pile of things like real lobby reform that just about every citizen (who isn't a lobbyist or directly benefiting from the corruption) can agree should happen but never will.
These ballot boxes are installed on some small percent of polling stations(like 5% or 10% - I don't remember the exact number). But statistical analysis shows that electoral fraud is commited considerably less often on such polling stations. I don't know, whether it is actually more difficult to cheat on such stations(at least there is a physical limitation - you can't put more than one ballot at a time, because it is needed to be scanned, - as opposed to normal ballot box where you can easily put 10-20 ballots at once), or whether they decided to install such automated boxes on polling stations where they had no intention to commit fraud. But my point is: 1) "Paper-voting" is no guarantee of fair elections. 2) Sometimes "hi-tech" may even help you, if you use it properly.
You make a fair point about electronic voting(and I wholeheartedly agree with you), but it looks like you overestimate the reliability of old-fashioned methods.
To summarize, I'm calling you "not-enough-paranoid kook". :)
http://homepage.cs.uiowa.edu/~jones/voting/optical/
I agree with your point, and only would add that the consensus among the election integrity experts is that poll-based ballot scanners which tally onsite immediately after the polls close are the most correct answer. This system has the lowest error rate. It is the easiest to audit (eg conduct a manual recount). Tampering with the results would be the most difficult (largest attack surface area).
The crucial trait of paper ballots cast and tabulated at poll sites is that such as system CAN be done correctly. Meaning enable the public vote count while ensuring the secret ballot. No electronic ballot system can make those guarantees, under any circumstances.
PS- I worked as a poll judge and poll inspector for a handful of elections. The jurisdiction where I reside had the same system as you described. It worked fabulously well. It was cheap. We've since moved to all postal ballots (vote by mail). Central count is a sausage factory. I fought against the transition, lost but was able to get some concessions, such as improved accounting (ballot processing) procedures.
Without that context, this is pretty meaningless.
Several comments so far have discussed ways to improve voting. Good cryptographers have already solved this problem. See http://scantegrity.org
I think a startup to fix voting would actually be a really cool (anyone here doing that already?), although I imagine it would be fraught with danger.
I think we need to step back to first principles here. In an ideal voting system, we need two properties:
1.) The vote must be anonymous (to remove the possibility of persecution) 2.) There has to be some way to detect if a vote has been tampered with.
Here's the thing... we can solve BOTH those problems with common cryptographic algorithms. Problem #1 can be solved with a hashed identity, problem #2 can be solved with a checksum.
Right now we try to solve that with a "paper trail". That's one solution, but it's very problematic. First, you're putting a lot of trust in the people doing the counting. Second, we can't trace those pieces of paper back to people to ask them "is this really who you voted for?"
I'm not claiming these are /easy/ problems to solve. There are a lot of considerations. But I will claim that we already have the required cryptographic toolset to make it possible, and that simple counting machines are entirely inadequate.
As a counter-example of having to trust the receiving end, consider zero knowledge proofs [1]. Even if you don't trust the prover, you become convinced of what they're trying to prove to you (if it's true).
The basic trick to proper cryptographic voting machines is zero-knowledge-proving that they are working correctly. Any tampering, whether it be in the source code or at the hardware level, will either not affect the tally or break the zero knowledge proofs.
Everybody understands paper voting and there are several (more or less) trustworthy protocols for paper-based vote count.
Maybe I'm pessimistic, but I can't picture a near future where the populace understands computers enough to be able to trust e-voting.
All the 'did I vote for the person I tried to vote for?' happens either in the voting booth, or by choosing unused ballots to audit at random.
If vote is secret you just know that someone voted X. Who is that someone? Is he even real?
Since we need secrecy we need to know X, but not who is "someone", so we're blind there.
If you can't prevent fake voters from registering, you've failed before the election even begins.
(Yes, this does allow you to coerce people with known preferences into not voting in order to affect the result. This issue, and many others, are discussed in the video.)
I would agree that there's no reason to have e-voting instead of paper ballots. The only possible excuse I might imagine for e-voting is that it lets people vote from home which enfranchises more voters, but that would just lead to a wave of vote selling so...
The Help America Votes Act, which spurred much of this new voting technology, specifically says voting places and ballots should be accessible by voters with disabilities such as the blind. This is very hard to accomplish in a secure, protected way without a machine. Some polling places have paper ballots for most, and machines reserved for the disabled.
Less is demanded of our voting system than of our ATM system. The irony is that it is the same system. People vote with their money every day. Western democracy is realized through the market system on a national level. Locally it is still in tact as a function of voting ballots and money.
Governance is largely about the use of limited resources and less about civil liberties. Civil liberties are largely a function of popular majority and politicians just reflect the popular opinion of the day.
The only "people" who "vote with their money" are the corporate interests, as most of us are far too poor to do to so.
I highly doubt that the current domestic surveillance program is a reflection of the popular opinion, nor do I believe that drone attacks on the other side of the world are supported by the majority of the populace.
Imagine a system where every individual has their own public/private key pair (backed by tying it to their SSN). You then have two SQL tables:
CREATE TABLE voterVote (
id INT,
category VARCHAR(255),
vote VARCHAR(255),
PRIMARY KEY (id,category)
);
CREATE TABLE voterVoteId (
voter_id INT PRIMARY KEY,
voter_city VARCHAR(255),
vote_id INT FOREIGN KEY REFERENCES voterVote(id)
);
Both tables are published. The one thing I forgot to mention though is that the vote_id is encrypted with the users public key. This way any individual voter can check that his vote is what is should be and people on the whole can check that votes were tallied properly. Furthermore, we dont need to worry about hacking compilers, etc. because this can be done on the internet. The last thing we need to worry about is that the machine is lying to people when they go to check their vote. The only solution to this is to have the code which decrypts the persons row in the voterVoteId open source, but still since the protocol is open source and the data is open source, we can bet that there exists one honest person to build a tool to check. One more thing: how can we tell that extra rows werent added to VoterVote? We can check that the number of people in a city matches the number of keys issued to every person in that city (which again is backed by SSN).This will probably fail miserably at something simple I've overlooked, but it was fun to dream up :)
Furthermore, voters shouldn't be able to prove how they voted - otherwise somebody could pay people who can prove having voted for him or threaten people who can't.
hmm, thats interesting. I never thought about that.
While in the video, Mr. Curtis has a point that voting code should be reviewed by independent experts... even if the code has been vetted there could be code injection through the operating system or compiler, however unlikely. And that's not even considering anything malicious with the network or databases. There's simply too many moving parts in electronic voting for it to ever ensure 100% honesty. Possibly making it law to require a hand count of all receipts/ballots to ensure a match would catch the fraud afterwards, when time is no longer such a factor. Or better yet, running paper ballots through two separate electronic voting systems by each voter and comparing counts.
But to answer your question, no I don't believe anything has been done.
We are working with academics in Surrey, UK, and elsewhere on the cryptography and verifiability of the election. So I can't answer any of the hard questions, but can point you at some of the documentation that Surrey has developed, shown below.
Using Pret a Voter in Victorian State elections http://epubs.surrey.ac.uk/726039/1/EVT.pdf
Software Design for VEC vVote System http://www.computing.surrey.ac.uk/personal/st/S.Schneider/pa...
When you vote, you get a piece of paper saying your name, your vote, voter-id, and the machine's salt.
Whenever a vote is counted, it is added to a public website of HASHES. Thus anybody can verify the totals.
If anybody's recorded vote on the website (taken by hashing their info) doesn't match their receipt, fraud is caught (thus removing votes or changing votes isn't possible). Also, if I didn't vote or am dead, and my info is entered, we can verify no tally appears for my hash.
If the hashes don't match up with all the registered voters via registration forms, then votes have been added. Thus in order to add fake votes, fake voter registration forms must be filled out manually [leaving a paper trail to catch the perpetrator].
Then your boss threatens to fire you unless you give him/her a copy of this paper such that he/she can verify that you voted how he/she told you to.
Also it would be nice to know what the forum was where these statements were being made. Just because they are in a fancy looking room does not indicate it is actually meaningful that the statements are "under oath".
That said you can definitely rig almost any large scale election. There are just too many way to attack the process. In theory computers could help make elections more reliable but in practice they just add new and powerful ways to attack the process.
The problem is, how can we as programmers/IT field guys react when we are e.g. coerced into rigging systems?
Refuse?
I also saw Hacking Democracy[1] recently that shows about the 2004 elections.