Fraud possible in Brazil's e-voting system
zdnet.com
zdnet.com
You could have the machines tally the votes a few seconds after the last poll location closes, but the election result isn't official until the votes has been counted.
Any trust in the machines at all and you might as well have the election take place in NK.
You can network the scanners in whatever crude or advanced way you'd like.
This is what Wisconsin has done for about a quarter century.
The software itself is very small. They are counting the OS, etc.
The software could be safer. But this whole story about those machines involves ego and fights for notoriety between government-run universities, departments and the opposition in place, which changes from time to time. Not exactly FUD, but an exaggeration of the facts.
But still, the problem is the principle: the system is the only source of truth, and if there is fraud, or a bug, that changes votes, it is undetectable and impossible to prove. TO have the fate of 200M people depend on such premise is absurd.
The electronic system must change, but this will only happen if there is awareness and sound technical discussion by the population.
Possible? Maybe, because computers.
Did this Aranha guy get it right? Probably not, but drama is money.
In 2012 the TSE did call professors to test the system, he did demonstrate an attack that recovered the identity of most of the votes registered at the device's memory, and it was widely published. Since then, there was no other test.
It's clearly an unverifiable system, where we don't have even guarantees that the tested software is the one running on it. And the government is not responding to request of improving the overall system.
What part exactly are you saying he got wrong?
For what it's worth, e-voting isn't verifiable directly, unless it's done in a way linked to voter identities. Even then, it's highly exploitable, but it is verifiable, depending on the implementation.
A trustworthy election embodies these four ideas to the maximum extent possible:
1. Anonymity. Votes cast are not linked to voters who cast them.
2. Transparency. The record of the voter intent, election law, means, methods, processes are visible to all involved and human readable.
3. Oversight. Depends on transparency. The election happens under the public eye, and we've got clear means and methods to resolve issues in a just and true manner.
4. Freedom. Voters are free to vote or not as they will.
The basic problem with electronic voting is this:
We don't record the voter intent. We do record what some device or enabling technology understood the voter intent to be. This is a vote by proxy.
Physical media, such as pencil and paper, present a chain of trust from the voter intent to the record of the vote, verifiable by the voter.
Electrons and computing systems in general depend on the fact that information states change easily and transparently. This is a good thing in most cases.
With voting, it's not a good thing because we do not actually record voter intent! Secondly, a voter cannot ever understand whether or not their vote record cast reflects their intent. They must trust the proxy.
Touching a screen may set a bit and that bit once set can be displayed back to the user. This display can be anything!
Physical media, directly used as the record of the vote, does present the user with a verifiable record they can compare to their intent before their vote is cast.
Human readable records, fed to machines, work reasonably well. There are exploits, mistakes, and such possible. However, the entire election can be litigated, validated as the election process and the people participating in the election deem necessary. While this is painful, it is necessary, if we are to trust the election.
Voter records presented in a court of law in electronic form contain very little other than the interpretation of the voter intent done by the machine at the time. Worse, it's extremely difficult to understand whether or not the machine interpretation actually reflects voter intent, and or if it complies with election law requirements.
A physical record has another property in that the media is actually changed in a material way by the voter as they record their voter intent. Further modifications to this record are very difficult to perform without leaving evidence of said modification on the media right along with the original, uncorrupted voter intent.
Electrons, if modified, changed, corrupted... just present different data states. For an analogy, say the vote count is in your mind, and suddenly you change that count, or manipulate it in subtle ways. The count is just different now, a mere information state.
Electronic voting isn't verifiable and trustworthy without extensive auditing and votes linked to users. For an example of this working reasonably, see banking and how all the records and accounting can work.
Do we want to link votes to people? If so, then e-voting can make some sense. I personally am opposed to this, and as a result, am opposed to electronic voting, but I do believe electronic counting, plus audits, given it's done from human readable records, can make sense.
Oregon, Washington and Colorado are vote by mail States, where the voter intent is collected in a human readable way, counted electronically, audited with appropriate sample sizes to insure accuracy within reasonable limits, and the entire election can be verified in court, one vote at a time, if needed.
This is the path forward IMHO. E-votes are a PITA and we can't really trust them. Votes by mail have a lot of advantages and they cost less than full on "go to the polls" elections do.
Finally, voting happens over a period of a week or two, distributing the votes nicely in time, preventing attacks, surprises and other things that can corrupt an election when it's all got to happen in one significant day.
I sure hope Brazil figures this out before they suffer too much from it.
SOAP BOX = 0
You're missing out on the last 20 years of crypto research. I'd say we're not there yet, but people have been thinking hard about things such as verifiability (with vote confidentiality of course!), coercion resistance etc, and have come up with really cool ideas. As with his other work, David Chaum has some stuff that makes you go "WTF?!? oooh", check out things like Pret a Voter or Scantegrity.
I wonder if we will ever get to a point where that kind of crypto is explained enough that we collectively trust it as much as pen and paper.
A machine presents a user with some interface, and they make a selection and they get told something. They have no identifiable way to see the record of their intent is accurate, or even will be used.
With pen and paper, the intent of the voter is what we record and that record is used to arrive at the tally to determine the election.
With a machine, we do not record the voter intent, only what a machine determined that intent to be.
Actually recording the voter intent means being able to evaluate that intent in a court of law, vote by vote, if needed. Given the impact law and government has on us, it's not too much to ask we actually do record intent.
I can counter it with two points, though. First, I don't really understand how the current system in my country works. There are constituencies, preferential voting, overhang seats, etc. Second, what is the process of ensuring transparency? Surely I, as an individual, could not just go and demand to see and count all the ballots myself. I would need to turn to somebody I trust. This would stay the same, except that this time that somebody could be anyone who understands mixnets and zero-knowledge proofs, rather than a select number of political organizations.
Different jurisdiction, different rules, so YMMV (at least in the USA). Sometimes manual recounts are automatically triggered for highly contested races. And sometimes campaigns can pay for a recount.
I would need to turn to somebody I trust.
The system I "trust" is mutual distrust. If all the candidates (campaigns) agree on the count, then I am much more likely to accept the final tally.
Whenever someone in election administration says "trust us", I know I'm being conned.
Anyway mutual distrust is what the proposed e-voting systems rely on. You need to trust k out of n (where k can be tuned between 1 and n) parties involved that your vote privacy won't be compromised. Maybe you're not prepared to trust any single one of them and that's a valid objection.
On the other hand, you do get more verifiability with e-voting - anyone who is able to comprehend how the system works can verify that the votes have been tallied correctly.
This can be done under the public eye, with mutually distrustful parties evaluating the vote intent fairly, and in the open.
That's something electronic systems do not, and are not capable of offering us.
Why?
They do not record voter intent, only what a machine determined the intent to be. A voter must trust the machine, and can never really understand whether or not their vote intent record actually reflects their intent, They cannot understand this because, unlike media which presents an unbroken chain of trust between intent and the record of the intent used for the tally, electronic means are a proxy, and do not use human readable records, which breaks the chain of trust.
A voter can and should be suspect in this case as the creator of the proxy (machine) may well not be compliant with both their intent and the law.
[0] http://electionmathematics.org/em-voting-systems/rivest-stud...
While cool for technophiles, all crypto based systems rely on hash collisions to protect voter privacy. It's a combinatorial problem. Given a typical general election ballot (say 10-30 issues, with 1-6 choices each), the pool of voters (ballots cast) would need to number in the 100,000s.
Alas, elections are administered per precinct, which typically number 1 - 1,000 voters.
To use crypto election administration would require splitting our ballots into a ballot per issue, greatly increasing the size of precincts, or both.
But whatever the case, the burden of proof for this hair brained ideas is on the proponents. And until they (you) assume the responsibility of proving these systems work for real world elections, I'm not interested.
Go ahead, work it out for yourself, manually, like I did.
I'll wait.
You're right, of course. I conflated Pret a Voter with another hare brained scheme: Chaum's Punchscan, which at least makes a token attempt to protect voter privacy. My apologies. (It's been a few years since I studied this nonsense.)
Pret a voter does not throw information away (a la secure one-way hash), it merely obfuscates the process. It's just a more fancy kabuki.
Electronic systems do not actually record the voter intent, just an interpretation of it.
Note, the confidentiality is not the same as anonymity. This is a link to voter identities. It's just not made public, but it's there.
A nice, robust, human readable, court room compatible vote by mail works very well, and it embodies the four basic ideas I mentioned above. It can be manually done, or electronically counted and audited too. Whatever works.
Really, e-voting is a solution looking for a problem. Making fancy systems really isn't getting at the core issue; namely, turnout and suppression.
Not a one of those cool ideas will work out, unless it's linked to people like we do bank transactions. Even then, the voter will be in a forced position of trust as they must allow the technology to interpret their intent instead of recording their intent directly onto a trusted record.
And as an extension to this: It is important that it is not possible to prove what you voted for.
This means not only that the link from voter to cast vote must be absent even for the voter, but also that the actual physical circumstances when the vote is cast is subject to the transparency and oversight mentioned above.
Anything else (voting from home, or being presented with a slip linked to your cast vote, or any other such system) is subject to buying and selling votes and the result of such vote would never (and should never) be legitimate in the public eye.
These physcial factors must also be taken into account when designing e-voting systems. It is a hard problem to solve these things in a way that the general voter would understand and therefore should accept.
Vote buying is a MUCH lesser problem than fraud by those running the ballot box. It's expensive; it's hard to do without being detected and on a large scale it becomes almost impossible.
Furthermore, it is impossible to create a system that simultaneously lets you prove that your own vote was counted correctly AND prevents vote buying (where the buyer can verify you voted correctly). If you can verify your vote was counted, so can the vote buyer. If you can't, you're trusting the person running the (electronic) ballot box instead.
Bearing that in mind, any fair electronic open source voting system should absolutely NOT prevent people from verifying their own votes. The person running the ballot box software is inherently less trustworthy than the person casting the vote.
Let the police deal with vote buyers. They can set up stings and catch them easily. The voting system should be primarily protected against the people who are running it.
If it is, it's either because 1) you don't know it's there, or 2) there are easier ways to cheat the system.
Please take note that buying votes does not need to be large scale to put the legitimacy of the outcome in question. It is enough if, for example, it is possible for abusive patriarchs to vote for family members.
> Furthermore, it is impossible to create a system that simultaneously lets you prove that your own vote was counted correctly AND prevents vote buying
Impossible is a strong word to use. There are several interesting theoretical systems proposed that make this possible. But are they practical?
> Let the police deal with vote buyers. They can set up stings and catch them easily.
You don't seem to understand why vote secrecy is desirable.
It is not (primarily) to protect against criminal gangs, but serves to make voting legitimate in the democratic system. Part of that is to make sure no one can prove how they voted for their bosses, husbands etc.
> The voting system should be primarily protected against the people who are running it.
Not traditionally. That is normally achieved through transparency. When anyone and everyone can participate on equal means in the voting process, and that process is transparent to everyone involved, that is enough to guarantee legitimacy.
No, it is difficult because it doesn't scale. After a certain (relatively low) point it becomes prohibitively expensive and your likelihood of being caught approaches near-certainty. This (along with enforcement) is why it is rare.
>Please take note that buying votes does not need to be large scale to put the legitimacy of the outcome in question.
Please also note that you do not have to be able to verify the outcome to be able to successfully offer a bribe and get a vote in return. It simply makes it somewhat easier.
Policing and enforcement of the law is the answer to this problem - not clever cryptography. That should be used to prove that the people running the voting machines didn't corrupt them.
>Impossible is a strong word to use. There are several interesting theoretical systems proposed that make this possible.
Impossible because it essentially implies a trustless system. Clever cryptographic techniques only go so far and they do not let you run a system where nobody can be trusted.
>You don't seem to understand why vote secrecy is desirable.
I understand why it is desirable, but I also understand that every system must face a trade off between placing trust in the administrators of the voting system and the voters themselves.
>It is not (primarily) to protect against criminal gangs, but serves to make voting legitimate in the democratic system. Part of that is to make sure no one can prove how they voted for their bosses, husbands etc.
If they can't do this then they cannot truly know whether their vote was counted at all. Maybe it was lost, ignored or counted towards the opposition.
>Not traditionally.
What the fuck does tradition have to do with it? This is about security.
Look, vote secrecy is nothing new. Let's not have a discussion about the basic tenets of voting systems unless you have a grasp of the fundamentals.
I'm not saying it is an axiom of democracy that must never be breached. I'm saying if you advocate against it, the very least you must do if you want to be taken seriously is to counter the basic arguments why we have voting secrecy in the current system, and what there is to be gained and lost with an alternative system.
The common vote secrecy is not to protect from large scale manipulation, although it does achieve that as well. It is to gain legitimacy by protecting against many small ones. Only then can it be argued that a vote is truly vox populi.
> What the fuck does tradition have to do with it? This is about security.
Please try to keep it serious.
Security is not a one dimensional variable. Traditionally voting security is designed to obtain legitimacy, not protect against a corrupt voting administrator. The latter is not ignored though, it is merely achieved by other means.
If your system cannot offer voting secrecy, and has no other benefits compared to a publicly auditable pen and paper system, it is overall less secure.
When a voter marks a ballot, there is an unbroken chain of trust between their intent and the record of their intent used for the tally.
When a voter uses a machine, the machine records something it thinks is the voter intent. The voter must trust the machine as they are not capable of seeing the actual record.
Further, the actual record of their intent is never captured, just an interpretation of it. Additionally, this record is copied, not used directly.
There's no reason to believe what's printed is what was cast or recorded.
Having observed the "audit" of the VVPAT, touch screens, etc. in my jurisdiction, when the paper tape was damaged, they just reprinted it. Which verified the printer was still working, at best.
Who will deliver the ballots once the USPS goes away? The push for e-voting will really heat up then.
I encourage you learn how your local jurisdiction handles mail ballots. It's more or less making sausage. The UAA is 1% (both directions). A large percent are challenged during signature verification. Ballots are electronically scanned (like a fax or OCR) as they arrive and pre-counted (which is illegal). Correcting for voter intent is done by modifying the database, which is difficult to "audit" during recount. I could go on and on.
The correct election administration system is the Australian Ballot (private voting, public counting) issued, cast, and counted at each precinct the night of the election, issuing postal ballots as needed to enfranchise people.
The only meaningful future electronic mediated system must be completely transparent, as in immediately posting ballots online as they are received. Sacrificing voter privacy to ensure election integrity.
I'm against all electronic mediated systems, but it seems inevitable, so I advocate a system which can be verified.
It's possible to get a quite good amount of privacy by the use of pseudonyms. You won't get a system with verifiable guarantees of both confidentiality and accuracy, as that's impossible, but there's no reason we can not make it as good as paper ballots.
I can speak to my experience as an election integrity activist.
A very large fraction of people who care about our elections (in the USA) would respond poorly to your proposal of not using real names when voting. You may be aware of the recurring "voter fraud" kerfuffle that gets trotted out every cycle. Scandal worthy shenanigans such as dogs registered to vote and renown critic Ann Coulter falsifying her voter registration.
The only current partial exception to using real names that I'm aware of protecting the identity of vulnerable persons, such as witness protection, victim of domestic violence, and maybe public figures like judges. The idea being to enfranchise those who would be endangered if their identity and location were freely available. So there's separate handling of these person's voter registration and ballot processing. More I can't say, because that's not an aspect that I studied in depth.
Also...
I learned the hard way that any critic of the current system (e.g. proposing alternatives) will be dismissed out of hand by administrators and policymakers if they don't have complete mastery of the current system. Conspiracy theorist, gadfly, crank, kook, paranoid, etc. And you will be tested.
If you develop your idea further, please cc me. Protecting voter privacy is very important to me, and I'd welcome a solution.
A possible protocol for using pseudonyms could be that people create a random IDs at home, and get them signed under a public setup very like our current setup for voting - several people sign it, and each person signs a limited number of IDs. Those people then give the signatures to the voter, and mark in a control that he got the ID. An ID is valid if it has all the signatures.
Ideally we should assure that no data lives the setup after the procedure - but just lighting everything on fire will never feel good enough to be implemented, so I'm out of ideas here.
This protocol still has a grave flaw, the electors can prove how they voted. Impossibility of proof is at odds with verification, but I still think there must be a way to make the proof physically hard.
Unless we want to amend to remove it from service, having it deliver votes is a perfectly fine use of an excellent service the public benefits from daily.
Actually, Oregon elections can be 100 percent verified. Every single ballot is available for recount activities, which can be done manually, under court and multiple party supervision.
Audits are performed and the stats on these and margins of error are well understood. We do use electronic counting, and where those do not match audit records, work is performed until they do.
There isn't a fully transparent electronic system, without also personally identifying voters to their votes.
I realize you guys do it differently. That's fine. In the US, we do not link voters to votes and we have strong reasons for that.
Frankly, I've always maintained e-votes are possible to do in a trustworthy way if we surrender anonymity.
I don't see that happening in the US. So long as that is true, we really do need to record voter intent in such a way that it can be used directly for the tally and reviewed under the public eye.
Which means e-voting is not trustworthy in the US. VBM is trustworthy, and it delivers very high and consistent turnout rates too.
That's another difference. You guys use mandatory voting. We don't. I personally wouldn't mind if we did, but we don't.
E-voting really hasn't done us any good on turnout as the machines, placement, performance, record keeping and a host of other factors make it a bigger mess than ballots currently are.
VBM sidesteps nearly all of those problems nicely. Every year, another district or another state picks it up because it works.
Replying to this separately.
I disagree.
By greatly increasing the window size of the election, vote by mail greatly increases the cost of running campaigns. Leading to the money chase. So the barrier to entry for aspirants is higher. Which is just another form of corruption.
It's called ballot chasing. I both door bell and phone bank for campaigns I support. Every campaign does it. It's not cheap. And I believe (but cannot prove) it ultimately suppresses voter turn out by alienating voters by constant harassment.
The US has a very grave money in politics problem. We've got movements in place to check those problems, and if they are successful, the campaign cost will be just fine.
Here in Oregon, there are efforts to help people vote. Lots of different efforts, some funded, some not. Voting is not hard, and the vast majority of voters simply vote.
The nice thing about having it distributed over time is it eliminates caging efforts, challenges, and all sorts of fuckery at polling places.
I voted both ways here and have observed turnout consistently improved over polls.
The solution is clear to me, make it open-source, give bounties for issue-fixing. If the current software is crap hire RSA and/or some nice software shop to refactor and audit it, then open-source it.
Paper ballots issued, cast, and counted per precinct, the night of the election is the most robust system existent. Compared to any other system, corruption would require more participants, increasing the cost, difficulty, and risk of detection.
Further, it also enables verifying the physical chain of custody, which is very, very difficult with electronic systems.
RSA? Why would I trust them?
Behold, readers, the brazilian inferiority complex.
ps downvoter.: Sorry if it's too agressive but the point I'm trying to make here is that ignorant opinions and defeatism aren't going to take us anywhere, people really need to get over this IMO. As the quote of "a little learning is a dangerous thing", shallow knowledge intoxicates the mind, but drinking it largely sobers us again ;)