Dominion Voting Systems and Fox reach last-minute settlement(cbc.ca)
cbc.ca
Dominion Voting Systems and Fox reach last-minute settlement
https://www.cbc.ca/news/world/dominion-voting-fox-news-trial-1.6813876
8 comments
It is not a problem. The solution to running high-trust elections is:
* Use paper ballots with fill-in-the-oval results. This method has very little chance of user error filling out the ballot (modulo concerns like two-sided sheets, etc.).
* Chain-of-custody the ballot box the ballots get fed into at the polling place. Keep a roster of who voted, which lets you count how many ballots should be in that box. If that count is incorrect for the number of voters, you have issues. (This is rare.)
* Count the ballots with a ballot-reading machine. Verify the machine's counts by doing hand checks of samples. (The US runs too many races not to use machine counts.)
* For mail-in ballots, use envelope-inside-envelope to preserve secrecy. The inner envelope contains the ballot, and only the ballot, while the outer envelope contains the information needed to verify the voter.
At that point, the only real question is determining who is eligible to vote, and it turns out that it's not really a question about the security of the voting process, but rather about how to prevent the undesirables from voting. Aspersions on the security of the voting process are really about trying to justify changes to laws to keep undesirables from being able to vote.
* Use paper ballots with fill-in-the-oval results. This method has very little chance of user error filling out the ballot (modulo concerns like two-sided sheets, etc.).
* Chain-of-custody the ballot box the ballots get fed into at the polling place. Keep a roster of who voted, which lets you count how many ballots should be in that box. If that count is incorrect for the number of voters, you have issues. (This is rare.)
* Count the ballots with a ballot-reading machine. Verify the machine's counts by doing hand checks of samples. (The US runs too many races not to use machine counts.)
* For mail-in ballots, use envelope-inside-envelope to preserve secrecy. The inner envelope contains the ballot, and only the ballot, while the outer envelope contains the information needed to verify the voter.
At that point, the only real question is determining who is eligible to vote, and it turns out that it's not really a question about the security of the voting process, but rather about how to prevent the undesirables from voting. Aspersions on the security of the voting process are really about trying to justify changes to laws to keep undesirables from being able to vote.
You can still safely do touchscreen voting in this system: just use ballot-marking devices that produce human-readable paper ballots. That's what happens in Cook County: you vote on a touchscreen (if you don't request a big cardboard paper ballot) and get a printed ballot that you cast as if you had marked paper yourself.
Is it a print of the vote that was cast, or generated separately from the cast? How do you know?
It prints the ballot you cast. Nothing in the BMD beams a vote to the secret vote-fixing center.
True. But some voting machines generate a print of the vote that was tabulated, and some generate a printout from a separate code path. The problem is that you don't know which it is.
Presumably you could ask any of the humans standing there staffing the election process and they'd tell you.
Or you could assume Skynet's clever plan is mass election fraud and making sure nobody ever finds out or tells.
Or you could assume Skynet's clever plan is mass election fraud and making sure nobody ever finds out or tells.
They don't know.
Not sure why you're dismissing the problems here by referring to fictional movie elements?
Note the "secretly record" element in [https://www.schneier.com/blog/archives/2007/12/more_voting_m...]
Bruce Schneier is not a crank, he's written extensively over the years on the issues and the one I'm pointing out is just one specific one of many. As a software developer yourself, you might be capable of taking these issues seriously.
Note the "secretly record" element in [https://www.schneier.com/blog/archives/2007/12/more_voting_m...]
Bruce Schneier is not a crank, he's written extensively over the years on the issues and the one I'm pointing out is just one specific one of many. As a software developer yourself, you might be capable of taking these issues seriously.
Your link to Schneier got me browsing through his "voting" tag. I found it quite interesting to compare these two posts and comments, from November 25, 2016 [0] and November 27, 2020 [1].
The topic is nearly the same, - some people found some irregularities in some counties - but the tone and treatment of the claims is drastically different. It's worth considering how we discuss election security through a partisan lens.
[0] https://www.schneier.com/blog/archives/2016/11/hacking_and_t...
[1] https://www.schneier.com/blog/archives/2020/11/undermining-d...
The topic is nearly the same, - some people found some irregularities in some counties - but the tone and treatment of the claims is drastically different. It's worth considering how we discuss election security through a partisan lens.
[0] https://www.schneier.com/blog/archives/2016/11/hacking_and_t...
[1] https://www.schneier.com/blog/archives/2020/11/undermining-d...
You don't think the staff at a polling place know whether the thing they're submitting to be counted is the printed ballots, or some other output of the ballot marking device?
The article you linked doesn't seem to have any connection to the flow where a computerized machine helps mark a ballot, drops it into your hands, and you can see and review it before dropping it into a box to be counted.
The article you linked doesn't seem to have any connection to the flow where a computerized machine helps mark a ballot, drops it into your hands, and you can see and review it before dropping it into a box to be counted.
That's almost the solution. Just add this [1], which requires just minor changes to how the ballots are printed and the use of special pens to fill in the ovals, and you gain these properties:
1. The ballots can be published after the vote allowed anyone to verify the counts,
2. Individual voters can, if they want to, note some information when they vote that will allow them to verify when the ballots are published that their vote was counted and it was counted correctly, but will not allow them to prove to a third party that they voted a particular way,
3. Individual voters can check before they vote that the ballot they have been given has probably not been tampered with.
[1] https://www.usenix.org/legacy/events/evt08/tech/full_papers/...
1. The ballots can be published after the vote allowed anyone to verify the counts,
2. Individual voters can, if they want to, note some information when they vote that will allow them to verify when the ballots are published that their vote was counted and it was counted correctly, but will not allow them to prove to a third party that they voted a particular way,
3. Individual voters can check before they vote that the ballot they have been given has probably not been tampered with.
[1] https://www.usenix.org/legacy/events/evt08/tech/full_papers/...
> For mail-in ballots, use envelope-inside-envelope to preserve secrecy.
This would work better if mail-in ballots were only printed on request, and had some kind of one way hashing so that someone who voted by mail could optionally verify their vote was counted correctly.
Otherwise, isn't the count unauditable as soon as ballots are separated from their envelopes? You can only verify that the number of ballots matches the number of envelopes, and perhaps that there exists a bijection between them - but you cannot verify that the same set of ballots that was in the envelopes was the set of ballots which was counted. How can you verify that ballots were not replaced, after removing them from the envelopes but before counting them, with duplicate ballots that contained different votes? An attacker might not even need to duplicate a unique ID on each ballot, depending on how the "verify my vote" system is setup, because the verification is only that you removed a ballot from my envelope. As a voter, I can call my county and offer the ID number from my envelope, and the county can honestly tell me they "processed" it - but I cannot verify that my ballot itself was "processed," nor can I verify that it was counted toward the total votes with the weight I'd expect given the number of voters.
Inversely, it's important that mail-in ballots only be printed on request, and that the (potential) voter receive a unique hash upon requesting the ballot (not just after voting with it). Because that way you can ensure that if someone receives a ballot but doesn't vote, they can call to verify that their vote was not processed. Whereas if they only receive a unique hash after voting, then only those who executed their ballot could verify it was counted, and any unexecuted mail-in ballots could be mixed into the tally with confidence that nobody would call to verify they were not counted.
Surely there is some kind of "accumulator" system that can be used here, but I'm not familiar enough with the literature to identify it.
However, I think it's clear that this is a deceptively hard problem, and worth the effort of our best minds publicly solving it, rather than deferring it to a private Canadian-owned, Serbian-operated corporation that produces proprietary systems and sues anyone who questions their trustworthiness.
This would work better if mail-in ballots were only printed on request, and had some kind of one way hashing so that someone who voted by mail could optionally verify their vote was counted correctly.
Otherwise, isn't the count unauditable as soon as ballots are separated from their envelopes? You can only verify that the number of ballots matches the number of envelopes, and perhaps that there exists a bijection between them - but you cannot verify that the same set of ballots that was in the envelopes was the set of ballots which was counted. How can you verify that ballots were not replaced, after removing them from the envelopes but before counting them, with duplicate ballots that contained different votes? An attacker might not even need to duplicate a unique ID on each ballot, depending on how the "verify my vote" system is setup, because the verification is only that you removed a ballot from my envelope. As a voter, I can call my county and offer the ID number from my envelope, and the county can honestly tell me they "processed" it - but I cannot verify that my ballot itself was "processed," nor can I verify that it was counted toward the total votes with the weight I'd expect given the number of voters.
Inversely, it's important that mail-in ballots only be printed on request, and that the (potential) voter receive a unique hash upon requesting the ballot (not just after voting with it). Because that way you can ensure that if someone receives a ballot but doesn't vote, they can call to verify that their vote was not processed. Whereas if they only receive a unique hash after voting, then only those who executed their ballot could verify it was counted, and any unexecuted mail-in ballots could be mixed into the tally with confidence that nobody would call to verify they were not counted.
Surely there is some kind of "accumulator" system that can be used here, but I'm not familiar enough with the literature to identify it.
However, I think it's clear that this is a deceptively hard problem, and worth the effort of our best minds publicly solving it, rather than deferring it to a private Canadian-owned, Serbian-operated corporation that produces proprietary systems and sues anyone who questions their trustworthiness.
The idea is that the mail-in ballots go into the same kind of chain-of-custody ballot box that happens in a polling place once the identity is verified (same as what would happen at the in-processing table in a polling place). Once your ballot makes it in that box, it's counted. If you've got a competent election system (e.g., Oregon), it's easy to figure out if your ballot has made it into that box or not. You don't need anything fancier than that.
Well, you need an escalation path when chain of custody is broken. It's great to say you depend on chain of custody, but how do you handle the violations of it? Mistakes happen. But so do attacks. It's probably not reasonable to cancel the whole election based on some missing chain of custody documents, and the (mostly volunteer) election workers can legitimately claim human error. But isn't that an ideal environment for an attacker to commit plausibly deniable ballot fraud?
For example: Swap a pile of mail-in ballots (recently separated from their envelopes) with an equally sized pile of pre-filled malicious ballots. Or, take a bag of ballots from rejected envelopes, mix them with uncounted ballots from accepted envelopes, and then replace some of them with prefilled ballots. Or commit any other uncorrectable chain of custody violation that allows you to introduce new ballots into the count, but that could also feasibly be an accident. When challenged, don't admit to introducing additional ballots, but openly admit to the tainted chain of custody, and claim it was a mistake.
It's unlikely you'll face any real consequence, and you can accuse your opponents of being election deniers. Yet you had the chance to intentionally introduce phantom ballots into the counting process while increasing the expected error margin of any potential audit.
Note that you can still process every legitimate ballot, and confirm to any voter that you processed their ballot. And maybe you can even confirm to any non-voter that you did not process their pre-mailed ballot. But you cannot confirm that you processed only legitimate ballots.
In other words: one plausibly inconsequential broken chain of custody is sufficient opportunity to introduce new ballots unassociated with any real voters.
For example: Swap a pile of mail-in ballots (recently separated from their envelopes) with an equally sized pile of pre-filled malicious ballots. Or, take a bag of ballots from rejected envelopes, mix them with uncounted ballots from accepted envelopes, and then replace some of them with prefilled ballots. Or commit any other uncorrectable chain of custody violation that allows you to introduce new ballots into the count, but that could also feasibly be an accident. When challenged, don't admit to introducing additional ballots, but openly admit to the tainted chain of custody, and claim it was a mistake.
It's unlikely you'll face any real consequence, and you can accuse your opponents of being election deniers. Yet you had the chance to intentionally introduce phantom ballots into the counting process while increasing the expected error margin of any potential audit.
Note that you can still process every legitimate ballot, and confirm to any voter that you processed their ballot. And maybe you can even confirm to any non-voter that you did not process their pre-mailed ballot. But you cannot confirm that you processed only legitimate ballots.
In other words: one plausibly inconsequential broken chain of custody is sufficient opportunity to introduce new ballots unassociated with any real voters.
> It's unlikely you'll face any real consequence, and you can accuse your opponents of being election deniers.
https://en.wikipedia.org/wiki/2018_North_Carolina%27s_9th_co...
Due to possible voter mail fraud, the election results were not certified and the election was redone.
Chicanery in vote counting doesn't happen in the US. There's just too many eyes on the system, and the system is just too distributed, for it to be effective. If you look at the way that political parties try to manipulate the elections, it's by attempting to prevent people from voting in the first place (and those attempts are much, much more successful than they should be).
https://en.wikipedia.org/wiki/2018_North_Carolina%27s_9th_co...
Due to possible voter mail fraud, the election results were not certified and the election was redone.
Chicanery in vote counting doesn't happen in the US. There's just too many eyes on the system, and the system is just too distributed, for it to be effective. If you look at the way that political parties try to manipulate the elections, it's by attempting to prevent people from voting in the first place (and those attempts are much, much more successful than they should be).
This is it.
> cannot verify it contributed to the total votes received by the candidate for whom you voted
Isn't this by design? If you can verify this, then someone else can force you to verify it in front of them to make sure you did what they told you to do, and then we don't have a secret ballot anymore. It's not obvious to me that the risk of fraud from miscounting is worse than the risk of fraud from voter intimidation or bribery.
Imagine everyone you know is posting screenshots of their verification on social media, and you voted for someone or something considered controversial in your community. If you post that verification you get harassed, if you don't post anything then everyone knows what that means and you get harassed anyway. That's the type of voter intimidation I'd worry about.
Isn't this by design? If you can verify this, then someone else can force you to verify it in front of them to make sure you did what they told you to do, and then we don't have a secret ballot anymore. It's not obvious to me that the risk of fraud from miscounting is worse than the risk of fraud from voter intimidation or bribery.
Imagine everyone you know is posting screenshots of their verification on social media, and you voted for someone or something considered controversial in your community. If you post that verification you get harassed, if you don't post anything then everyone knows what that means and you get harassed anyway. That's the type of voter intimidation I'd worry about.
> If you can verify this, then someone else can force you to verify it in front of them to make sure you did what they told you to do, and then we don't have a secret ballot anymore.
Not being able to prove to someone else that you voted a particular way is called "coercion resistance", and it is in fact possible to design a voting system where you can verify you vote was included and counted correctly but that are coercion resistant.
See this comment [1] from a while back about such a system. Link #3 in that comment is to a paper showing that system is coercion resistant.
There are several systems that provide verifiability but are coercion resistant. The one discussed in that comment is noteworthy because it is an easy add-on to existing optical scan voting systems. The cryptographic cleverness that it depends on is in how the ballots are generated and what is printed on them, with the only modification in the voting booth is that you have to use a special marker to mark the ballots.
[1] https://news.ycombinator.com/item?id=31675726
Not being able to prove to someone else that you voted a particular way is called "coercion resistance", and it is in fact possible to design a voting system where you can verify you vote was included and counted correctly but that are coercion resistant.
See this comment [1] from a while back about such a system. Link #3 in that comment is to a paper showing that system is coercion resistant.
There are several systems that provide verifiability but are coercion resistant. The one discussed in that comment is noteworthy because it is an easy add-on to existing optical scan voting systems. The cryptographic cleverness that it depends on is in how the ballots are generated and what is printed on them, with the only modification in the voting booth is that you have to use a special marker to mark the ballots.
[1] https://news.ycombinator.com/item?id=31675726
This is super interesting, thanks for posting. What a cool idea.
However, I see two potential problems and I don't think this would satisfy anyone that is concerned about election security in America. First, this is vulnerable to someone accidentally or intentionally writing down the wrong code on their receipt, and then going on TV to display it as irrefutable proof of election fraud. With 150+ million people voting there is basically 100% chance that will happen many times.
Second, this system proves that your ballot was received and uploaded to a government website. That does address a claim of "they threw my ballot in the trash", but it does not address:
1. They're busing in illegal voters
2. Election workers are all corrupt and are just making up the count
3. They flipped my vote
4. Foreign hackers infiltrated the system and added more votes
5. They added a bunch of fake votes last minute when my guy was about to win
6. My guy did 15% better in exit polls than the actual count, something is up
etc. etc. Here's a list of real-life fraud claims, I don't think Scantegrity would resolve any of these: https://www.factcheck.org/2020/12/nine-election-fraud-claims...
To be clear I don't believe any of these things, but this is the sort of stuff you hear from people who are worried or claim to be worried about election fraud. They type of person who would be satisfied by their Scantegrity receipt is not the type of person who is currently making noise about election integrity.
Sorry to move the goalposts, you completely addressed the issue I described in my last comment. I'm just trying to think through if this system would actually fix anything in the US, and I think it would not. I do think it's a good idea though, and it certainly wouldn't hurt.
However, I see two potential problems and I don't think this would satisfy anyone that is concerned about election security in America. First, this is vulnerable to someone accidentally or intentionally writing down the wrong code on their receipt, and then going on TV to display it as irrefutable proof of election fraud. With 150+ million people voting there is basically 100% chance that will happen many times.
Second, this system proves that your ballot was received and uploaded to a government website. That does address a claim of "they threw my ballot in the trash", but it does not address:
1. They're busing in illegal voters
2. Election workers are all corrupt and are just making up the count
3. They flipped my vote
4. Foreign hackers infiltrated the system and added more votes
5. They added a bunch of fake votes last minute when my guy was about to win
6. My guy did 15% better in exit polls than the actual count, something is up
etc. etc. Here's a list of real-life fraud claims, I don't think Scantegrity would resolve any of these: https://www.factcheck.org/2020/12/nine-election-fraud-claims...
To be clear I don't believe any of these things, but this is the sort of stuff you hear from people who are worried or claim to be worried about election fraud. They type of person who would be satisfied by their Scantegrity receipt is not the type of person who is currently making noise about election integrity.
Sorry to move the goalposts, you completely addressed the issue I described in my last comment. I'm just trying to think through if this system would actually fix anything in the US, and I think it would not. I do think it's a good idea though, and it certainly wouldn't hurt.
The UK has the most secure voting system I know. Voting machines are not used, votes are always paper-and-pencil. Your ballot form contains a unique serial number to prevent multiple votes.
Votes are counted at the district level, with only totals being submitted up the chain, in order to protect privacy.
It's simple and it works.
Votes are counted at the district level, with only totals being submitted up the chain, in order to protect privacy.
It's simple and it works.
That doesn’t stop media firms after faster results and American voting machine manufacturers lobbying to change things every time we have an election.
Paper and pencil doesn’t work in the US because of how litigious we are, and because each state operates their own elections. If every state ran elections the same way we could standardize on something like the UK has and have collective faith in it.
When some battleground states routinely come down to less than 1% of voters, incredibly marginal effects matter.
The US still has institutional trauma from Hanging chads.
Just look at all the varied reasons mailed ballots are rejected, especially in tight races.
With paper and pencil, what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled? All of these are questions that will be the subject of lawsuits in a mix of jurisdictions.
When some battleground states routinely come down to less than 1% of voters, incredibly marginal effects matter.
The US still has institutional trauma from Hanging chads.
Just look at all the varied reasons mailed ballots are rejected, especially in tight races.
With paper and pencil, what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled? All of these are questions that will be the subject of lawsuits in a mix of jurisdictions.
I'm in Canada; I can't speak to the specifics of the UK.
> what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled?
When I sit down to vote, there is a very unambiguous set of instructions on how to fill it out: mark an X in the circle.
- we all know perfectly well that pencil erasers aren't perfect
- It's not a Scantron™ ffs! Is that what you're imagining? That's just a voting machine with extra steps! Every single ballot is counted by a human! https://electionsanddemocracy.ca/canadas-elections/canadas-e...
> what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled?
When I sit down to vote, there is a very unambiguous set of instructions on how to fill it out: mark an X in the circle.
- we all know perfectly well that pencil erasers aren't perfect
- It's not a Scantron™ ffs! Is that what you're imagining? That's just a voting machine with extra steps! Every single ballot is counted by a human! https://electionsanddemocracy.ca/canadas-elections/canadas-e...
I sure hope it's counted by more than one human.
What do you do if someone marks something like a Y and it looks like the ink ran out?
(My local elections are indeed a Scantron-style procedure, incidentally. Bubble in the entire circle.)
What do you do if someone marks something like a Y and it looks like the ink ran out?
(My local elections are indeed a Scantron-style procedure, incidentally. Bubble in the entire circle.)
Obviously. I'll just quote my link directly for you, then:
> First, election officers open the ballot boxes and count the ballots.
Note the plural.
Safeguards for Counting Votes and Reporting on Results: https://www.elections.ca/content.aspx?section=vot&dir=int/co...
> First, election officers open the ballot boxes and count the ballots.
Note the plural.
Safeguards for Counting Votes and Reporting on Results: https://www.elections.ca/content.aspx?section=vot&dir=int/co...
There are 'scrutineers', as well as the election officials: they are representatives of the various parties, monitoring the count.
> With paper and pencil, what happens if a mark got erased? If the circle is half filled? If the circle is quarter filled? All of these are questions that will be the subject of lawsuits in a mix of jurisdictions.
Votes are counted by humans. It's not "fill a circle", it's "draw an X in a box". It's not ambiguous.
Votes are counted by humans. It's not "fill a circle", it's "draw an X in a box". It's not ambiguous.
I wouldn't call it "the most secure", there is no id check (because there is no mandatory ID scheme) so the process to verify your identity is super loose. Also very little constraints on voting by mail, with the only form of authentication being a signature which is weak to say the least.
France has much stronger controls on ID checks at the voting booth and vote by mail (in fact for most elections there is no vote by mail, you can only delegate your vote to a person who cannot act as a delegate to more than two people to prevent ballot harvesting).
France has much stronger controls on ID checks at the voting booth and vote by mail (in fact for most elections there is no vote by mail, you can only delegate your vote to a person who cannot act as a delegate to more than two people to prevent ballot harvesting).
How is the serial number used to confirm that the person using it is who the ballet was issued to?
When your ballot is handed to you, your home address is recorded in a log. It's handed to you inside the voting station, you can't take it back out.
Your ballot is linked to your address? So, someone could link a ballot to the voter? That’s not something we want in the US. It’s intended to be anonymous.
I live in San Francisco, CA, USA. Ballots here are also serialized and many (most?) people vote by mail which means that serialized ballots are mailed to you specifically at your registered address.
After the vote, you can check the status of the ballot's serial number at the appropriate city/county website. It won't tell you who voted or the votes cast, but that it was received.
So while the website won't link you to your votes, the city/county could absolutely make that connection since they control the serialization and the mailing. One hopes that they don't do this, and I'm sure they're not suppose to, but trust and wishes are the best surety we have for vote by mail ballots... there are ways to defeat the loss of anonymity in this case, but they involve not voting by mail or providing false signals (i.e. swapping ballots with someone else in your district).
After the vote, you can check the status of the ballot's serial number at the appropriate city/county website. It won't tell you who voted or the votes cast, but that it was received.
So while the website won't link you to your votes, the city/county could absolutely make that connection since they control the serialization and the mailing. One hopes that they don't do this, and I'm sure they're not suppose to, but trust and wishes are the best surety we have for vote by mail ballots... there are ways to defeat the loss of anonymity in this case, but they involve not voting by mail or providing false signals (i.e. swapping ballots with someone else in your district).
This is, in theory, possible. However, the information remains in your local district, and is not passed up the chain with the results.
It's one of those things that sounds bad in theory but is rarely an actual problem in practice.
It's one of those things that sounds bad in theory but is rarely an actual problem in practice.
How do they verify the answer wasn’t overwritten, since it’s in pencil? I can imagine a lot of potential security flaws in that system.
Once you've recorded your vote, you personally insert it into a sealed box with a slot.
The boxes are opened for counting as part of a public process, with independent observers.
The boxes are opened for counting as part of a public process, with independent observers.
Computer enthusiasts have conflated cryptography and security for so long that simple ballot verification systems like the ones in use for decades around the country are regarded as "insecure" merely because the speaker doesn't really have a clear definition of the term.
My ballot has a tear-off receipt and a bar code. I can verify when and how my ballot was counted. If I suspect fraud at the ballot counting site I can supervise the process myself in person. If my signature doesn't match the ballot office can contact me to verify.
There is no world where cryptography is a requisite for ballot security, and I would not want to live in a world where computers are required for something as basic as democracy.
My ballot has a tear-off receipt and a bar code. I can verify when and how my ballot was counted. If I suspect fraud at the ballot counting site I can supervise the process myself in person. If my signature doesn't match the ballot office can contact me to verify.
There is no world where cryptography is a requisite for ballot security, and I would not want to live in a world where computers are required for something as basic as democracy.
That's it entirely. I live in a VERY rural area, and we have receipts with barcodes that you can track either electronically or in person if you want to. They are not attached to you, they are attached to your vote and have unique ID's on them. In theory anyone can track your vote, but only you know which is yours and whether it's accurate or not.
This is not the difficult problem. The difficult problem is that we have thousands of systems, depending on where you live, and politically, getting anyone to agree on any one system is probably impossible.
But I am with you, cryptography is absolutely not required, and computers should not be fundamental to the process. Hell, electricity should be optional as well, just in case the shit hits the real fan.
This is not the difficult problem. The difficult problem is that we have thousands of systems, depending on where you live, and politically, getting anyone to agree on any one system is probably impossible.
But I am with you, cryptography is absolutely not required, and computers should not be fundamental to the process. Hell, electricity should be optional as well, just in case the shit hits the real fan.
> In 2017, Democrats recognized it as a problem
In 2016, Hillary beat Sanders by up to ~12% more than exit polls would have suggested in states without paper trails. [0]
The fact that this only happened in states without paper trails raised some eyebrows among Sanders voters, but "Democrats" bent over backwards to explain how this was just a quirk, and 'probably the fault of Bernie Bros somehow anyway, who gives a shit about them, they're not Real Democrats TM'.
And then we stopped doing exit polls at all. Because apparently that's a sensible thing to do when there's no paper trail, and indications of systemic fraud - remove the only remaining tell-tale sign.
So, yeah - this is a problem, will continue to be a problem, and will be completely ignored by media unless it serves them to associate questioning voting machines with the far-right.
0 - https://www.snopes.com/fact-check/stanford-study-proves-elec...
In 2016, Hillary beat Sanders by up to ~12% more than exit polls would have suggested in states without paper trails. [0]
The fact that this only happened in states without paper trails raised some eyebrows among Sanders voters, but "Democrats" bent over backwards to explain how this was just a quirk, and 'probably the fault of Bernie Bros somehow anyway, who gives a shit about them, they're not Real Democrats TM'.
And then we stopped doing exit polls at all. Because apparently that's a sensible thing to do when there's no paper trail, and indications of systemic fraud - remove the only remaining tell-tale sign.
So, yeah - this is a problem, will continue to be a problem, and will be completely ignored by media unless it serves them to associate questioning voting machines with the far-right.
0 - https://www.snopes.com/fact-check/stanford-study-proves-elec...
The paper is suspect at best. Your own link enumerates the problems. Also, there are many reasons why exit polls don't match votes. And they have to do with votes being anonymous and exit polls not being anonymous.
Did you read your own link?
Did you read your own link?
Yes, I read the link. I felt it was only right to allow the best of both sides to be heard on this one.
"Suspect at best" is really not a fair takeaway, unless you're cherry-picking quotes at face value. Myself, I found the responses to the paper rely on bluster and don't hold much water at all.
If you want to see the responses taken apart, with more on the abysmal state of voting machines and the untrustworthy sounding electoral folk responsible, you can read this: https://www.counterpunch.org/2016/05/16/clinton-does-best-wh...
"Suspect at best" is really not a fair takeaway, unless you're cherry-picking quotes at face value. Myself, I found the responses to the paper rely on bluster and don't hold much water at all.
If you want to see the responses taken apart, with more on the abysmal state of voting machines and the untrustworthy sounding electoral folk responsible, you can read this: https://www.counterpunch.org/2016/05/16/clinton-does-best-wh...
I agree with your first paragraph here, but that's about it.
I know that the userbase on a site like this one tends to want to solve these types of issues with technology, but that's just because all we've got here on HN is a hammer, ya know?
Pencil-and-paper works. Anything else is a solution in search of a problem.
I know that the userbase on a site like this one tends to want to solve these types of issues with technology, but that's just because all we've got here on HN is a hammer, ya know?
Pencil-and-paper works. Anything else is a solution in search of a problem.
> Pencil-and-paper works.
Paper has its own issues, effectively illustrated by photos from 2000: https://imgur.com/a/lpDhmQP
Paper has its own issues, effectively illustrated by photos from 2000: https://imgur.com/a/lpDhmQP
"Hanging chads" is a fundamentally difference system than 'put an X in the circle', and your screenshot here demonstrates a potential issue with accessibility, but not with ballot integrity.
"Is that an X?"
https://www.theguardian.com/politics/2015/may/06/vote-with-a...
> The official body supervising the British general election on Thursday has said votes should be counted if support is expressed by the drawing of a smiley face, instead of a cross, as is requested at the top of the ballot paper.
> Also permitted is writing “yes”, and drawings that may well be accepted are those of a flower, and sketches of naked people, though best if they are smiling.
https://www.revisor.mn.gov/statutes/cite/204c.22
> If a mark (X) is made out of its proper place, but so near a name or space as to indicate clearly the voter's intent, the vote shall be counted.
> If the names of two candidates have been marked, and an attempt has been made to erase or obliterate one of the marks, a vote shall be counted for the remaining marked candidate. If an attempt has been made to obliterate a write-in name a vote shall be counted for the remaining write-in name or marked candidate.
https://www.theguardian.com/politics/2015/may/06/vote-with-a...
> The official body supervising the British general election on Thursday has said votes should be counted if support is expressed by the drawing of a smiley face, instead of a cross, as is requested at the top of the ballot paper.
> Also permitted is writing “yes”, and drawings that may well be accepted are those of a flower, and sketches of naked people, though best if they are smiling.
https://www.revisor.mn.gov/statutes/cite/204c.22
> If a mark (X) is made out of its proper place, but so near a name or space as to indicate clearly the voter's intent, the vote shall be counted.
> If the names of two candidates have been marked, and an attempt has been made to erase or obliterate one of the marks, a vote shall be counted for the remaining marked candidate. If an attempt has been made to obliterate a write-in name a vote shall be counted for the remaining write-in name or marked candidate.
First, most US paper ballots are fill-in-the-bubble, with pen, and any sufficient mark counts. This is so the large number of ballots can be counted quickly. Multiple marks for the same race is immediately rejected and you have the opportunity to correct the ballot. Ability to follow basic directions is the responsibility of the voter. Or, the voter can ask for assistance.
Hand marked paper ballots allow for an audit trail. Paper allows the voter to check before submitting the ballot. Paper allows easy correction by trading for a replacement. Paper works well. As is confirmed in audit after audit after audit.
Hand marked paper ballots allow for an audit trail. Paper allows the voter to check before submitting the ballot. Paper allows easy correction by trading for a replacement. Paper works well. As is confirmed in audit after audit after audit.
Election commission of India conducts elections really well, given the scale of 800M+ voter. despite of isolated incidents booth capturing in remote or ungovernable areas, overall results reflects the mood of public. It super super hard to manipulated system at scale.
roughly the way it works is - there is standalone electronic voting machine (EVM). it is NOT connected to network at all. for each vote, a receipt gets printed and vote puts that receipt in ballot box. the EVM count is used to aggregate over vote count. it speeds up counting process. Some percentage of randomly selected voting machines vote counts and corresponding printed vote ballot is cross verified.
During the whole process, a representatives from all the parties are present in all election activity
roughly the way it works is - there is standalone electronic voting machine (EVM). it is NOT connected to network at all. for each vote, a receipt gets printed and vote puts that receipt in ballot box. the EVM count is used to aggregate over vote count. it speeds up counting process. Some percentage of randomly selected voting machines vote counts and corresponding printed vote ballot is cross verified.
During the whole process, a representatives from all the parties are present in all election activity
> You either cannot verify your vote was counted, and/or cannot verify it contributed to the total votes received by the candidate for whom you voted.
That would break the privacy of the vote. It would allow for actors to oblige or coerce people into voting in a candidate and then forcing them to prove their vote.
That would break the privacy of the vote. It would allow for actors to oblige or coerce people into voting in a candidate and then forcing them to prove their vote.
It's been a thing every since I can remember. Whichever side losses claims some sort of voter fraud.
Fraud exists and should heavily be punished but I think its effects are overstated by everyone.
Fraud exists and should heavily be punished but I think its effects are overstated by everyone.
It would have been nice if this went to trail, though I can understand why they decided to settle. It would have been a mud fight.
Still, it would have been nice to get some light on both parties.
It would also be nice to know what the final settlement ended up being.
Still, it would have been nice to get some light on both parties.
It would also be nice to know what the final settlement ended up being.
I was hoping FOX would be forced to retract their lies on their news channel in a long and noticeable segment on prime time.
But with the settlement I doubt that will happen.
But with the settlement I doubt that will happen.
It's possible the settlement will require public retractions and apologies. The hefty payout - $787.5M - seems to demonstrate Dominion had the upper hand in this negotiation, as does the judge's sanctioning Fox and appointing a special master to look into misconduct.
Dominion in recent days has said they wanted an equivalent effort retracting the lies as was spent spreading them.
We’ll see if that was just posturing with what the settlement terms end up being.
We’ll see if that was just posturing with what the settlement terms end up being.
In theory a settlement deal could also include such an apology/retraction, it's whatever both parties agree to.
Wow the guys in the newsroom didn’t believe what they were saying and still said it. If there was a word for journalistic non-integrity, I’m searching for it now.
Just a periodic reminder that if you're interested in how voting works where you live, every election administration probably badly needs volunteer election judges (EJs). You'll get trained up on all the machines and processes they're using to collect votes, and get paid for the experience. At least where I live, there's a lot of subtlety to the process that make obvious-seeming "attacks" pretty untenable in reality; maybe you'll learn something different about yours.
It will be interesting to see what the terms of the settlement are.
I’m always amazed that firms go right to the brink of trial before settling. Sometimes the judge issues certain rulings that may lead a party to realize their odds are lower than hoped. But otherwise it seems like both parties wasted the court’s time when a settlement could have been reached at any prior point.
Settling often deprives the country of useful case law, or prevents bad actors from having to admit guilt. Totally understandable for the parties involved to take the sure thing rather than risking it all on a trial but it does negatively impact our society.
I’m always amazed that firms go right to the brink of trial before settling. Sometimes the judge issues certain rulings that may lead a party to realize their odds are lower than hoped. But otherwise it seems like both parties wasted the court’s time when a settlement could have been reached at any prior point.
Settling often deprives the country of useful case law, or prevents bad actors from having to admit guilt. Totally understandable for the parties involved to take the sure thing rather than risking it all on a trial but it does negatively impact our society.
What new case law is needed? Fox lied about Dominion and caused provable harm to their business.
I agree that happens a lot but this may not have been an instance of it: Fox might've genuinely liked their odds before the judge slammed them for lying about Murdoch's role and ordering a special investigation. They might've re-evaluated based on the new disclosures they had to do and an angry judge who now would've assumed bad faith from them, and decided to bail.
[deleted]
787.5 Million
The fun is not yet over:
> another U.S. voting technology company, Smartmatic, is pursuing its own defamation lawsuit against Fox seeking $2.7 billion US in damages in a New York state court.
> Fox Corp. shareholders are demanding company records that may show whether directors and executives properly oversaw the Fox News coverage of Trump's election-rigging claims, sources told Reuters, in what could be a prelude to lawsuits seeking to make directors liable for costs.
> another U.S. voting technology company, Smartmatic, is pursuing its own defamation lawsuit against Fox seeking $2.7 billion US in damages in a New York state court.
> Fox Corp. shareholders are demanding company records that may show whether directors and executives properly oversaw the Fox News coverage of Trump's election-rigging claims, sources told Reuters, in what could be a prelude to lawsuits seeking to make directors liable for costs.
“In total, 28 states used Dominion voting machines to tabulate their votes during the 2020 United States presidential election, including most of the swing states.”
https://en.wikipedia.org/wiki/Dominion_Voting_Systems
However you feel about the claims made during the 2020 election, that should terrify every American that closed source computerized voting machines from a single company counted enough votes to potentially decide the presidential election. I’m not saying that any of Trump and his supporters claims have any substance, but the optics of that stat do not look good.
Voting machine software should be public record and produce a fully auditable paper trail.
https://en.wikipedia.org/wiki/Dominion_Voting_Systems
However you feel about the claims made during the 2020 election, that should terrify every American that closed source computerized voting machines from a single company counted enough votes to potentially decide the presidential election. I’m not saying that any of Trump and his supporters claims have any substance, but the optics of that stat do not look good.
Voting machine software should be public record and produce a fully auditable paper trail.
Voting machines are typically purchased at the county level, so that means at least one county in 28 states bought them. They're a big vendor, but they're not the largest, and not as big as that stat implies.
The fact that voting is administered at the local level is one of the biggest fraud protections we have. It drastically reduces the damage that can be done, and makes outliers much harder to hide.
The fact that voting is administered at the local level is one of the biggest fraud protections we have. It drastically reduces the damage that can be done, and makes outliers much harder to hide.
The problem is that due to the concentration of population within a handful of cities, and therefore counties, you only need to win in just a couple of counties per state to take most states. This has been the Democrat strategy for a long time now, focusing on issues that matter to urban voters.
Hypothetically, (again, I’m not saying this is actually what happened in 2020), compromised voting machines could easily sway a national election by being installed in a relatively small number of counties.
See the below voting map by county for the 2020 election…
https://www.nytimes.com/interactive/2021/upshot/2020-electio...
Hypothetically, (again, I’m not saying this is actually what happened in 2020), compromised voting machines could easily sway a national election by being installed in a relatively small number of counties.
See the below voting map by county for the 2020 election…
https://www.nytimes.com/interactive/2021/upshot/2020-electio...
I don't know anything about Dominion's, but Cook County's touchscreen electronic voting machines all produce a human-readable, auditable paper record.
Do they produce something that a voter would read and see prior to actually casting the vote or is it just an internal log?
If it’s the former then the voter can actually verify that the machine cast their vote as intended. If it’s the latter, there is literally nothing stopping the machine from changing votes as they are cast.
To clarify I’m not saying that is actually happening, just that there is nothing stopping your vote from being switched by the machine either through malice or a software bug if the machine doesn’t generate a physical slip of paper that you actually put in a ballot box.
If it’s the former then the voter can actually verify that the machine cast their vote as intended. If it’s the latter, there is literally nothing stopping the machine from changing votes as they are cast.
To clarify I’m not saying that is actually happening, just that there is nothing stopping your vote from being switched by the machine either through malice or a software bug if the machine doesn’t generate a physical slip of paper that you actually put in a ballot box.
The fact of the matter is our elections are not secure, in the sense that their results cannot be cryptographically verified. You either cannot verify your vote was counted, and/or cannot verify it contributed to the total votes received by the candidate for whom you voted. In aggregate, we can rarely verify that "all legitimate ballots were counted," and can never verify that only legitimate ballots were counted.
This is a problem, it's been a problem, and it will continue to be a problem. Our election infrastructure is only secure insofar as people trust it's secure, and people can only trust what they can verify. Otherwise, the winning party is asking the losing party to commit an act of faith in "trusting" a system that cannot be verified for correctness.
In 2017, Democrats recognized it as a problem, just like Republicans did in 2021. Yet we have so much whiplash from back and forth politicization of the issue that it's impossible to have a sane discussion about it.