Buenos Aires Censors and Raids the Technologists Fixing Its E-Voting System
eff.org
eff.org
In comparison only a small percentage of the populace understands programming, fewer still would be able to write a secure voting system and fewer still would be able to debug such a voting system (code is harder to debug than to write).
Given the above and the high stakes of government elections I think we have yet to find a technology superior to simple paper ballots.
Except they have no error correction and admit ambiguity as to a voter's intent. That's all great and theoretical, but the inability of some voters in 2000 in Florida to fully punch a paper ballot led to a recount that under some scenarios would have led to President Al Gore rather than President George W. Bush.
Maybe the occasional hanging chad is worth the other positive attributes of paper, but don't write off all the advantages of an electronic system (error correct, instant results, etc).
https://en.wikipedia.org/wiki/United_States_presidential_ele...
"This is really bad form design, look at this layout" - she said pointing to the piece of paper she was holding. Most people can assess the merit of that argument, and in the case of Florida, have done so in a reasonable manner - whatever their conclusion.
"This is a bad electronic system" - 99% of people have to trust an authority to even begin to form a view on that which makes disinformation and propaganda of the usual kind, ie advertising and lobbying, more effective than it deserves to be based on merit alone. Now that's fine for soda purchases but not good enough to trust your democracy to.
Blame the user?
The fault lies with the election administrator who had not followed procedures and properly cleared the voting machines of chads from prior elections.
> don't write off all the advantages of an electronic system (error correct, instant results, etc)
None of which are true. The sole advantage to electronic voting systems is to expedite the transfer of public monies to cronies. Well, a second advantage is to obfuscate the whole process.
Digital can be used for a quick count, if there are any questions or need for verification the paper trail is there.
*Archival quality, not thermal paper.
Here's a bit of the history of moving from open votes to secret votes:
http://www.bbc.co.uk/news/uk-england-leeds-31630588
This article discusses what should happen to ballot slips after and election, compared to what actually happens, and describes the potential for de-anonymizing votes.
http://www.theguardian.com/notesandqueries/query/0,,-1051,00...
1. The ssl certificates for the transmission of vote counts where leaked.
2. PAPER ballots, which have an rfid chip to HELP the automatic vote counting could be used to duplicate a PAPER ballot.
I don't know about point 1, and I'd like someone with experience in that to check it up, but point 2 is just not an issue.
This is because this isn't really electronic voting, this is an electronic assisted paper ballot. It's just a paper ballot which is printed with the help of a touchscreen. People are supposed to check each ballot in each voting table, but know they have rfid readers to make it faster. When they read a ballot as containing a double vote they just declare it invalid. Also, vote numbers must be equal to the amount of people that voted, you just can't duplicate votes.
1. First, a "white vote" is just an empty ballot
Nothing prevents the card being printed later, and used as if you voted in the first place.
2. there's no way to void your ballot.
You are supposed to write "void" in the card, but nothing prevents the authorities from reading from the chip, or worst writing down "void" to your non-void ballot.
3. The chip can hold multiple votes
Which the software will count, but will raise no warning whatsoever.
Also, in the case of a difference between the chip counter and the paper count, which one should be trust?
Should we throw away the entire table? if so, then a simple vote could then nullify the entire table
2. Yes there is. This last election a friend of mine got his ballot voided because he didn't fold it while putting it in the box, which would reveal the ballot ("voto cantado").
3. Again, counters go one ballot at a time if one turns double it's voided.
But e-voting surely does the reverse: it throws open the playing field, putting power up for grabs to whoever can hack the system, with no way to predict who that will end up being. So why do those currently in power want that to happen? (Not a rhetorical question: I'm actually curious about the answer.)
I would say than an effective electronic system would need to be open from code to monitoring. There is no reason to have the voting machines nor machines which accumulate the vote to be connected to any external network.
You have to start trusting somewhere.
Sorry, I'm fresh out of trust. I made the mistake of learning the mechanics of election administration.
The only "trust worthy" system is one based on mutual distrust. If two or more belligerents (aspirants) agree to the final count, then it's probably satisfactory.
Now that HAVA's touch screen fiasco has played out, the next big push is for vote by mail (postal balloting) requiring all new gear and enabling exciting new business models.
That these new systems are unverified, unreliable, and easy to subvert (undetectably) is just a happy side effect.
You can be a poll inspector, a poll judge, a poll observer, watch the central count, attend the public certification hearings.
Different jurisdictions have different rules, so YMMV.
But the basic ideas are a) Australian ballot system b) verify the physical chain of custody c) private voting, public counting.
Happy hunting.
What's even worst is to see the parallels between what happens in Argentina and the US political system only to see Americans fall prey to some of the same sick politics and not see the reality of what politicians are doing to us. That's another topic.
Indeed, the money rains from the sky to a lot of people. This is basic clientelism and works very well for the politicians.
I've never really followed an Argentine election closely, but I'm curious is they have options. In other words, Is there often a significantly better political representative that is overlooked, or is it more of a "lesser of all evils" situation?
But this is Argentina. The vulnerabilities were most likely put there deliberately by the security services, of course they don't want them exposed.
So when the government put forward a voting machine, it became illegal to question the validity of its workings.
1. It's not illegal to "challenge" goverment statistics, everybody does it: private agencies do it, provincial goverments challenge the federeal goverment's stats, etc. Some official said some time ago they'd prosecute some agencies that provided statistics but nothing happend.
2. Goverment kind of "forced" (and not really directly) many companies to leave the price of some products fixed amidst inflation and devaluation, so Big Mc were pretty cheap for a while (that's been over since like 1.5 years).
3. The goverment didn't really crack private agencies from reporting data, they kind of tried and the courts didn't follow. There are lots of agencies reporting inflantion, just check it up.
4. Yes, they fixed the inflation data to fix the inflation-tied bonds (look for "cupon pbi"). But argentina isn't "selling those bonds". Those bonds where issued to funds after the 2002 default, it's a little messy but most funds like these have been nationalized by now, the only people who trade those bonds now are high risk gamblers.
The machine also prints the vote on the ballot, and because of the known bugs in the system people are still counting them by hand.
And even if they address that particular bug, because of the inherent nature of the political process, parties' representatives will always want to count the ballots by hand to prevent fraud.
EDIT: As of this moment there is no way an argentine political party would accept black-boxing an election.
That said, this system prevents chain voting (a mechanism to make sure the votes that parties buy from low-income people are not changed).
it's a relatively trivial matter to use a printer attached to a voting machine to create a paper-trail.
even something like "choose your candidate, get a receipt, verify it yourself, and put it in the box"
the election results would be instantaneous, and the paper trail would still exist for irregularities.
But pretty much all the software suffers from shortcuts one after another, ridden with bugs and backdoors. Someone will most certainly get to exploit the state of affairs before these systems are solid enough for good.
I wonder if there are methods for mixing identities. Bitcoin mixing services have many people put coins into a pool, then outputs balances to new addresses. It isn't a 1:1 comparison at all, but I wonder if there are methods that could be used.
If more than one identity service is used I wonder if the multiple keys could be mixed to create a unique key that only the voter knows.
[1] https://www.eleccionesciudad.gob.ar/uploads/resoluciones/ade...
[2] https://www.eleccionesciudad.gob.ar/uploads/OAT%20n%203-15-0...
Unfortunately, even after the actual report si finished, the university will not have permission to make it public. So we may never see the real results.
Having a report on the security of a system be issued months _after_ it is used is completely stupid. This is not simply his fault, it's the entire arrangement which is stupid.
The report shows that Righetti had access to the source code. Unless you are trying to say that he did not have access to the files in which _actual_ security vulnerabilities were found, or that the source code he was given was _different_ from the source code which was leaked, which contained egregious vulnerabilities.
Keep in mind he pockets hundreds of thousands of dollars in this arrangement. That's the part that adds insult to injury. Further, he does not teach information security or anything similar at university (he teaches networking), when there _are_ people teaching such things at UBA (FCEyN), who would have been better suited for the task.
If we can't have complete transparency and confidence in voting systems we might as well just give up.
The main issue was a security flaw that allowed somebody to directly download the SSL certs of the voting system from an URL.
Voting systems are sacrosanct.
Disclosing an election can be rigged with all the supporting evidence is your absolute duty. Doing anything else is not just irresponsbile, it's morally evil.
Covering it up by not disclosing is the action of someone who is LITERALLY an enemy of democracy and freedom.