1. Fire up Chromium in incognito, and once you've voted once, just close it again and open it again to vote once more. Rinse and repeat.
2. The ip choice is smart, but there are ways to get a dynamic ip every [insert time interval].
One could perfect this to an art really. Get your ip to start changing, have Chromium open on a hotkey, use ctrl+shift+n to go incognito (or just have it auto-load in incognito), have the poll set as your homepage. You can clock alot of votes this way.
Logins are best.
If someone's willing to go to that far of an extreme to game a vote, I don't think a login system would do much to stop them either. You can just as easily create new accounts with the new IP and a fake email address.
The difference is that with a login method, it takes significantly more effort and time. This is pretty straightforward once you have it setup.
A couple years ago, some university friends and I went to an engineering competition in Ontario. It was an event spread over four or five days, and on the last night a dance was held. This information was given to the participants a couple of weeks in advance.
The DJ for the dance had set up a website to allow people to request songs from off of a giant list. Each person got five or six "votes", and the system stopped them from voting any more after that. It was a cookie-based system. (It didn't bother with IP stuff).
One of my friends ended up using the macro system on his Macbook to vote for the song he wanted until he ran out of votes, delete his cookies, refresh the page, and repeat. He ran this macro overnight for a couple of days.
By the time we got to the competition, "Never Going to Give You Up" had three or four thousand votes. There were about two hundred people attending.
Is there ever a situation where a bunch of legitimate users have the same IP? I'm thinking at a university maybe, corporate firewall, or AOL?
Even so this compromise might be worth it to remove the login hurdle.
If you become Digg or something and people start actively trying to get around it, do you think this would be about as secure as logins? Could be a high quality problem to have.