Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just use paper ballots. The only useful election technology is scantron.

We do not need this. It isn't even a solution in search of a problem it's a problem in search of a place to explode.

A rundown on some of their security: https://mobile.twitter.com/GossiTheDog/status/10266038003653...



I do need this. How can I ever check if my vote was counted by paper ballots?

It seems like blockchain would allow everyone to be able to check that their vote counted, in an anonymous yet totally transparent and verifiable way.


Here's my experience in Germany:

My polling station is less than 200m away. I have never waited more than two minutes to vote. All voting is with a pen on a paper ballot.

Once the precinct closes, you are allowed to stay and observe the counting. Because each polling place serves only a couple hundred voters, it is easy to follow the counting. As long as it is possible to do so without interfering, everyone can observe so closely they can read the actual ballots and verify that they are sorted into the correct piles. You can then watch the counting of those piles close enough to verify the count.

Later, you can go online and look up the row for your precinct in a spreadsheet.

This is end-to-end verifiability, and it is neither expensive nor unable to scale: A national election in Germany will see about 40 million voters.

What's most important: Unlike blockchain or any other online voting scheme, the whole process is easily understandable by everyone.

In times were every institution is suspected to be corrupt, being merely safe is not enough. It needs to be safe in a way that does not rely on experts in cryptography to say so.

I have seen only one valid objection to using this process in the US: It is far more common there to have elections with dozens of individual races and ballot issues. Germany usually has just two individual questions to be voted on, and maybe five when local and national races fall on the same day. Considering this, it would still be possible to use the process for the top X races on a given election day.


Are you suggesting a way to verify your vote was counted correctly is needed? Wouldn't that provide the ability for folks to sell their vote by being able to show someone else?


There are some ways to do this on paper ballots! They aren't foolproof, but provide optional verification of votes without relying on electronic voting.

An example: https://en.wikipedia.org/wiki/Scantegrity


No, you already have the ability to sell your vote.


Without proof that you voted a certain way, people are unlikely to pay you.

That's why some states don't allow you to take a picture of a ballot that you filled out. They're trying to prevent you from confirming that you voted a certain way.


Record a video of you voting. It's pretty easy to conceal it if you want to.

Or have a person follow you and see what you do. Which would've worked all times I've voted here in Sweden.


That's not really scalable though. A few people might be able to get away with those schemes, but a few people generally isn't enough to swing an election.


First, why shouldn't I be allowed to sell or trade my vote?

Secondly, there are states where you can vote by mail. Do you know if vote selling is a big problem in those states?


>First, why shouldn't I be allowed to sell or trade my vote?

It's not about you selling your vote, it's about coercion. If your vote is verifiable, then you can be threatened with bodily harm for not voting a certain way, and/or for failing to verify that you voted a certain way.

Your freedom to sell your vote is worth less than someone's freedom to vote free of intimidation or threat of violence.


I lived in Oregon--which has had exclusively vote by mail for decades--for a while and never heard anyone bring up vote selling as a risk to election integrity. No one (journalists, legislators, etc) ever claimed it was happening.

The state republican party still makes occasional claims of voter fraud, but those are exceedingly rare -- something like 54 ballots out of 4 million in the 2016 election cycle -- and they mostly come down to people voting in Oregon and in another state at the same time.

The only reported case of election fraud I can remember was in 2016 and done by a republican, in which she tossed out a bunch of democratic voter ballots. That's it.

For two decades of elections, Oregon hasn't had a problem with election integrity. They do, however, have a consistently high turnout, which they attribute to vote-by-mail.


Oregon has a scheme to allow you to replace your mailed in ballot is why.

And this is a real issue, vote buying and cohersion has historically been the most common voter fraud mechanism in the US. It's a major part of how the Boss Tweed and his associates ran New York.


In the two states with vote-by-mail I've lived in, you can always hand-submit a paper ballot that takes precedence over your mailed one. The only way someone could be sure you voted one particular way is to monitor your actions for 100% of the time after you mailed the ballot.

This is less ideal than voting in person for everyone, as it still has failure cases like sufficiently abusive relationships. But it's an overall improvement over the previous system. Significantly more of the population votes in practice, making the vote a better measure of the ever-nebulous "will of the people".


Yes, multiple times for multiple different candidates because there is no way to prove who you voted for. There is a reason nobody does this in practice.


Please explain? It's not currently technically possible to provide proof that you voted for a specific person and thus making it impossible to buy votes.

The fact that you cannot personally verify whether your vote gets counted is a feature, not a bug.


You're making this false assumption that proof of voting a certain way is a requirement to sell or buy a vote in the first place. It's not.


But not the means to prove you’ve held up your end of the deal.


You can't meaningfully sell your vote unless you can prove you voted a certain way.

I'm certainly not going to pay you to vote the way I want without proof of delivery.


There's no way to verify you voted a certain way, making buying votes less reliable.


Yes, but the question was about the ability to sell, not verifying the reliability of people who engage in this type of illegal activity.


> How can I ever check if my vote was counted by paper ballots?

You can watch if you want, or even be a part of the counting. IIRC most paper ballot schemes have the counting be public in some form or another, so that opposing factions can call each other out if someone is cheating in some way.


To a degree you have to put your trust in the system and build enough checks in so that no one part of it can be corrupted. The issue with electronic voting is that it's easy to scale attacks.


Their backend is printing out PDFs for the county election workers to count. You still have to trust someone, you'll always have to trust someone.


You could count the results yourself to double check the outcome with a blockchain-based solution


With a paper-based solution, you (or your organization) can also count the votes yourself. With the added advantage that it's harder to manipulate, less prone to failure, and easier for non-technical people to understand.


Multiple people can't get access to the paper documents at the same time. And when they do get access there's no guarantee that they are getting the actual papers that citizens submitted. Even if you got citizens to individually sign each one with their private key and write the signature on the paper, you still couldn't prove that votes weren't removed


You're right, which is why the paper solution is accompanied by a process of handling involving all of the interested parties.

If you want to, you can go to the polling place and observe the box with the ballots all the way through to counting and registering the totals.


It doesn't involve all the interested parties and there's no way it could. That's what I'm trying to say. Maybe it's feasible for one watchdog organization to audit one polling station using your method. But it's not possible for every citizen to independently audit every polling station across the country, like you would be able to with the blockchain approach.


Agreed, honestly out of all the different potential blockchain uses this particular solution has always struck me as having the most potential.


A number of end-to-end verifiable voting systems have been proposed and fielded! See [0].

The key issue they try to solve is how to let you check your vote was counted without being able to prove who you voted for to anyone else, thus preventing coercion attacks.

Most of them rely on paper, but some [1], provide reasonable guarantees about online voting.

None of it involves blockchain.

[0]: https://en.wikipedia.org/wiki/Scantegrity [1]: https://heliosvoting.org/


Counting in public is the solution. You can attend the count yourself, or you can trust that the loser of the election will have people there to challenge any questionable moves made in the counting process.


Using a blockchain cannot (ever) tell you if your vote was counted.

Blockchains for election administration are a digital form of physical chain of custody. Like when you move boxes between locations.

You're thinking of crypto voting schemes. None of which have proven feasible in the wild.

The Australian ballot form of election administration means private voting, public counting. For example, dropping your ballot into a box at a poll site.

Any process enabling any kind of post mortem verification is more akin to accounting, eg open ledger with credits and debts. That's the opposite of a secret ballot.


> "Using a blockchain cannot (ever) tell you if your vote was counted."

What.

By voting you commit a change to the blockchain. The system should report back your "commit hash". Said hash is public (as is the entire blockchain), guaranteed to be unique, and counts towards the overall balance.

In contrast - a paper ballot can disappear. Your vote can be manipulated. All without any trace.


It's hard to directly compare the attack surface area of various systems. And yes, ballots have been disappeared, injected, etc. One of the prerequisites of Australian ballot election administration is having sufficient observers. But the same is true of any "trustworthy" process.

Having studied this stuff for over a decade (now inactive), I believe, but cannot definitively prove that paper ballots cast at poll sites is the most robust against attack. FWIW, the election integrity community concurs.

Security research and knowledge has progressed a lot in the last decade. It'd probably be worthwhile to circle back and apply the state of the art to this domain.

(Alas, saving democracy doesn't pay very well, so it's unlikely that it'll be me doing the work this time around.)


> "I believe, but cannot definitively prove that paper ballots cast at poll sites is the most robust against attack"

Here's how a Blockchain voting system can work:

1. Person casts vote using a voting machine.

2. Voting machine commits a change to a publicly available blockchain. The commit includes metadata such as the actual choice you made. It can optionally include even more metadata, such as "place of vote", "timestamp", "gender", "age".

3. Your vote has been cast, and the blockchain has been been modified.

4. The voting machine prints a "receipt". Your receipt includes a "commit hash". You can use the hash to see, identify and verify your record has been registered with the blockchain. So can everyone else.

5. When the voting is done - a simple python scripts traverses the blockchain - counting how many votes were given to each candidate.

This design ensures transparency and security. No compromises. You as an individual can know for a fact that your vote has been cast, and has been counted. As a society, we can finally verify and make sure our elections were fair game.


Our current system is the Australian ballot. Private voting, public counting. It's a battle hardened, field tested design which best balances the needs of society with the needs of the individual.

Some future system may find a new balance. Perhaps that new system no longer demands a secret ballot. Because the risks changed. (Note that some jurisdictions require a secret ballot, so YMMV.)

So if you want to supplant the Australian ballot with a different system, please start there. Explain the context, assumptions, risks, tradeoffs.

Because piecemeal changes to our existing system, without regard for the whole, has caused a mountain of heartache.

FWIW, I've been pondering "temporary privacy". Perhaps an embargo on all the election data for the critical time span. A friend of mine proposed (draft legislation) making all of the materials and documents available after an election is certified. For post mortem inspection. So you could feed all the ballot images into your own tabulator software. Or do your own signature comparisons. A huge change, because right now election data will be destroyed after certification (exactly when is per jurisdiction).


The problem, I think, is that you couldn't prove votes weren't _added_, unless there's some smart way to solve this problem. Obviously you couldn't inject too many votes or the total would seem suspicious. But considering US election turnout varies you could probably get away with a few percent, which could easily swing a close election.


Common solution with existing precinct tabulators: each voter is issued both an anonymous ballot and a permit with identifying information. After marking the ballot, the ballot is inserted into the tabulator and the permit is retained in a file with the tabulator. At the end of each day, the number of votes recorded by the tabulator should match the number of permits, which contain the identifying information and so can be audited against the pollbooks.

This same model can be extended to the blockchain approach, but isn't using a blockchain to solve the ballot-stuffing problem - just using a conventional paper technique.


Not a fan of the secret ballot?


Not in the system they used, it was private. As has been noted elsewhere, it would be trivial to have the majority of peers could be under nefarious control


That's a failure of their implementation. That doesn't discount every implementation. I feel too many here are too quick to dismiss alternative.


I was actually able to verify that my vote was counted in the last European Parliament election. I voted for an obscure candidate from an obscure party, and my vote sure shows up on https://data.val.se/val/ep2019/slutresultat/E/rike/index.htm...


The optical system in Minnesota is great.

I fill out the paper ballot, so no matter what I've voted. It is really clear how to use the system, and I'm not waiting on technology no matter what happens next.

Then I roll it into the machine itself and it goes into a locked box attached to the machine.

There is always a paper record.

The machines and votes are tied together so auditing is straightforward.


The system you describe is currently the gold standard for election administration.

In "electionese":

Ballots issued, marked, and cast at a poll site.

Ballots tabulated at poll site the moment the polls close.

All materials and gear distributed from and to a central count.

All handling done in public in the presence of reps of all significant stake holders, election observers.

Receipts, logs, seals for everything.

Source: Was a poll inspector for years.


It really seems like it would be hard to have a system that is "better".

It's all the security of physical ballots, with the speed of electronic, and very specific / targeted auditing ability that benefits both the electronic and physical domains.


FWIW, learning about this stuff completely burst all my preconceptions.

Even as a geek utterly opposed to most all use of computers for tabulation, I came to believe the biggest threat to election integrity is change. We just have to stop shaking the ant farm every few years. Whatever changes are warranted, they need to be slow, deliberate, methodical. Because it all really comes down to the people (admins, voters, candidates, observers, etc), their domain knowledge, expectations, and experience.

As Alistair Cockburn wrote, good people can make even bad processes workable.

PS- Belatedly response, sorry. Got rate limited yesterday.


> It isn't even a solution in search of a problem it's a problem in search of a place to explode.

I won't knock blockchain completely, because I don't believe I'm smart enough to, and it likely has many useful applications, but I feel like half the time I hear about blockchain, this quote is applicable.


Yep. Paper totally rules here.

1. like paper money, anonymous - my vote should be secret.

2. Hard to do large scale fraud or manipulation - not being efficient or automatable is a feature guys...

3. Physically going to the polls, voting in public, yet private at the end really makes it hard to put pressure on people to vote one way or another. Compare that to voting electronically at home or in church or at work....


3b. You can spoil paper ballots during in-person voting, which means a photograph of your ballot is insufficient proof that you actually cast that particular ballot.


This is a solution to the problem of more pork for vendors.

Any one wanting to understand why any of these changes occurs will be illuminated by better understanding the business models of the vendors and the appropriations (budgets) of the jurisdictions.

During the HAVA bonanza, which brought us the touchscreens, vendors envied high tech valuations, so repackaged themselves as product companies.

When that fad went bust (market saturation), vendors repackaged themselves as service companies. With a big difference from their prior incarnation. Changing from time & materials to charging a fee for every task for every voter every election.

Before, you'd buy ballots for expected turnout plus 10%.

Now, (with vote-by-mail) you buy the whole ballot packet, for every voter every election.

Before, you'd pay 10 cents for every voter signature verified.

Now, you pay for signature verification services for every voter every election.

It's astonishing how each and every step of the process has been monetized (rent seeking).

--

Huh. It just now occurs to me there's probably a better way to summarize the business practices of the vendors:

Just imagine what IT vendors like Oracle do to maximize revenue applied to election administration.


Many people can't afford to take the day off for voting. And even mail ballots are allowed, making the process easier would encourage more participation. Is this not a problem worth solving?


It's not as clear-cut as you would think. https://www.eac.gov/documents/2017/02/23/will-vote-by-mail-e...


Sure, but can't that be solved for most people by holding elections on a Sunday and keeping the polls open from 08:00 to 20:00? That way it is only a small percentage who are unable to vote.

Sweden has this plus early voting and we have between 85% and 90% participation in our elections. The early voting of course make it easier to manipulate votes.


Yes, it's worth solving. Here's another suggestion - make voting day a holiday.


That's not actually possible in the sense that declaring a day a holiday doesn't actually prevent employers from giving people shifts. If anything, restaurants and stores actually retain more staff during holidays. The only people a holiday would affect would be people working high end jobs that probably wouldn't have issues voting anyways.

Vote by mail and extended voting hours are much more effective solutions for people who otherwise couldn't find the time to vote.


Fine, bring out the heavy law-making artillery then. Make it mandatory to give staff time off to go voting with heavy penalties for non-compliance and some kind of nice carrot for compliance.


As well as early voting, and vote by mail.


Doesn't work either. In some districts, one candidate got more votes than actual ballots because some were 'accidentally scanned more than once.' In those situations, since the counts are off, the original vote stands.

So, just make sure you throw out all your extra ballots and you're fine.

Edit: 2016 US General


Why simply deride electronic voting as a solution in search a problem? There are many problems it solves.

1. How about low voter turnout, so elections aren’t representative of what the people want. An app would increase voter turnout by a lot, especially the younger vote.

2. How about letting less mobile people to vote. Or people who are not able to take off work that day. (https://www.vice.com/en_us/article/zm9j85/i-couldnt-vote-bec...)

3. How about being able to count elections in time to call them, instead of things where Bush gets elected because some guys ran out of time, and then it turns put Gore would have won?

Aren’t these important enough problems for a democracy to solve?

Instead of simply downvoting, why not actually address what I am saying! I am going to go point by point.

Sure, absentee ballots are a thing, but guess what. People like apps. If it’s secure enough for everyone’s banking needs, why not for a vote?

You can make the same argument about money — that banking apps are a honeypot for thieves etc. And yet we have made banking apps so so secure that you’d use them to move thousands of dollars.

If everyone voted from their phone, it could be anonymous and cryptographically secure. And a Merkle tree would record all results.

What is the issue? Every problem you point out with electronics can be done with paper ballots, too.

The interface can lie to you? Has been done with butterfly ballots and others.

The vote counting process is rigged? Have different groups audit the process.

In fact, having cryptographically secure receipts makes it extra easy and fast to verify votes. Al Gore would have won, because they wouldn’t have has to take so much time for a recount:

https://m.youtube.com/watch?v=qcz6NSyxrfQ

Instead of throwing our hands up and saying “oh, X is an issue!” why not simply work on fixing the issue?

So let’s run down the issues:

1. Not enough access to phones and computers

Fine, people without phones can still vote the old fashioned way.

2. Stealing a phone

A very inefficient way to fake a vote

3. Interfaces that lie to you

Ignoring the fact that machines already do this (https://youtu.be/EV_c1-YTk8M) the interfaces would need to be audited by different groups using each other’s interfaces in an anonymous manner (not like when Uber’s greyball https://amp.theguardian.com/technology/2017/mar/03/uber-secr... ). This is the general problem of the Trusted Computing Base.

4. Anonymity

Listen, should we know how every person voted?? We do now! Thanks Government. Best Voting System Ever (https://www.forbes.com/sites/leemathews/2018/10/16/millions-...)

Erm sorry. The solution. Token mixing. You get one token per person, but then they go through a cryptographically securd mixer before being used to sign your vote. Kind of like with Monero rings.

5. Accountability

How can we prove the votes happened the way you wanted them to?

Well, YOU still have your token on YOUR phone (no one else does) so your app can audit the Merkle tree.

Zero-Knowledge Proofs would be overkill here because proving how you voted to someone else is important (See #3, above). In addition, ZK proofs are a bit ivory-tower idealistic since most people don’t have the knowhow to “produce a fake alternative vote”.

The Merkle Tree can consist of smaller branches, one for each district. The results can be tallied in near real time, and verified by anyone. Results would be known in real-time.

6. But realtime reporting will affect voters!

Yes, and it currently already does, with Ohio, Michigan, and so on. The current system makes some states way more important than others:

https://www.nationalpopularvote.com/campaign-events-2016

Why not require all states to have primaries at the same time and not reveal the results til the end? This is a political, not technological, solution.

The only one major problem I see with electronic voting is #3, the trusted computing base. I listed the main solution above, but I am sure there will be many improvements on it.


Here's the problems such a system would create.

- Voting in private on a phone app. The opportunity for coercion is huge. The brilliant thing about putting a cross on paper in a booth on your own and dropping into a box, is no-one knows how you voted - so no comeback.

- Anything in software has the opportunity for a large scale attack. The incentive for doing such attacks is large. Look at all the energy put into gerrymandering etc today - Why risk it?

- the ability to do a sensible audit is beyond most people - auditing a pile of paper is easy - anyone can participate. Software you'd need to trust a small priesthood - that's not democracy, and it's totally dangerous ( forget algorithms, the weak points are people ).

I'd also question your premise that low voter turn out is largely due to inconvenience. Sure for some, but I'd argue lack of participation is largely riven by other factors - like nobody worth voting for....

Finally paper system is easily adaptable - want a box for write ins? Move to single transferable vote? Just print different paper and people doing the counting can adjust - no software re-writes.


- Voting in private on a phone app. The opportunity for coercion is huge. The brilliant thing about putting a cross on paper in a booth on your own and dropping into a box, is no-one knows how you voted - so no comeback.

How is that true, when I just posted that voter database have been leaked

https://www.zdnet.com/article/us-voter-records-from-19-state...

and they contain (per Wikipedia):

Personal data frequently included in a voter database:

Voting history (including federal, sub-national, primary, municipal, or special election voting history)

Name

Physical address

Mailing address

Phone number

Party membership or affiliation

Absentee or military voter designations

Source of voter registration, i.e., DMV/MVA, Public Assistance Office, etc.

Ethnicity or emerges race hypothesis

Gender

Birth date or age range

https://en.wikipedia.org/wiki/Voter_database

Not only that, but some states consider this public information!


I assume the voting history is only if they voted or not, which is sensitive for sure, but not that vital since with paper ballots you can put in an invalid vote or a vote for another candidate if coerced and there would be no way to check what you voted. With an app it would be possible to force people to prove what they voted for.


I don’t understand how being able to prove who you voted for is going to lead to more negative than positive. Can you walk me through how, realistically, a large scale voter coersion operation would even work?

If you know how a district voted, why not coerce the entire district? After all, if you have access to unlimited coersion powers, you’d be wasting them on a couple individuals.

I say if someone has the power to coerce others to that extent, we have bigger problems in our democracy. They can, for example, coerce members of the opposing party to stay home and not vote.

In short, I think this is a fantasy problem. There are far easier ways to fake a vote (like this: https://beta.washingtonpost.com/politics/2018/12/06/gop-was-...) and the app would prevent those.


"All employees who submit proof of their casted ballot for X will receive a $50 gift card. Employees who fail to do so may see a reduction in hours."


“All registered Democrats who submit proof they voted will receive $50 gift card”

“All registered Republican voters who submit proof they were home that day will receive $50 cards”


Election back-end security is important. However, that has little to do directly with the discussion at hand about voting security.


It means people know how you voted and also your identity


All it means people know that you voted. Party registration isn't destiny. Maryland has a ton of registered Democrats but Republican Governor Larry Hogan is pretty popular there. West Virginia has a lot of ancestral Democrats, but it's a far cry from being competitive at the presidential level, though Democratic Senator Joe Manchin manages to survive.


Well you can simply outlaw/fine the kind of threats or rewards that you mentioned. And before you ask how one would prove it, it is more provable than sexual harassment or advancement for sexual favors, since it involves proof.


Outlawing that sort of behavior isn’t mutually exclusive of building sensible election systems that maintain ballot secrecy. It’s really unclear what you’re arguing for when you keep jumping around various aspects of elections (and sexual harassment?) in a totally incoherent manner.


You'd get better rates buying this information directly from the state.

The most additional information you can glean from this is what primary a person voted in anyways. These are just participation history and registration information. Do explain how I can figure out which candidate someone voted for in the general from this information?


Only two things have been proven to increase voter participation (in the USA):

Peer pressure, culture of voting (your neighbors noticing they didn't see you at the poll site).

Competitive races.

On the flip, there are many things which counteract vote suppression:

Universal, automatic voter registration (just like all other mature democracies).

Reenfranchise felons.

Fair redistricting.

Adequate funding for election administration.

--

I've not seen any data suggesting that digital voting schemes have or may boost voter participation. And there's numerous cases where such systems disenfranchised voters.


> 1. How about low voter turnout, so elections aren’t representative of what the people want. An app would increase voter turnout by a lot, especially the younger vote.

Improved accessibility from the status quo has minimal marginal effect on turnout. https://www.eac.gov/documents/2017/02/23/will-vote-by-mail-e...

> 2. How about letting less mobile people to vote. Or people who are not able to take off work that day.

Paper mail-in ballots are a well-established way to accomplish this, though they do have their own risks---specifically vote-buying and coercion. My county in California also allows curbside voting by appointment, which is pretty great for elderly voters.

>3. How about being able to count elections in time to call them, instead of things where Bush gets elected because some guys ran out of time, and then it turns put Gore would have won?

This is already a solved problem with precinct-counted optical scanned ballots.

I highly recommend you volunteer to be a poll worker the next time there's an election in your state. You'll learn a lot about the real problems on the ground. For example, in my precinct during the 2018 midterms, we encountered an issue with the voter rolls: the city had recently renamed a street but a lot of people's registrations still reflected the previous name, which slowed things down significantly.


well here is the rub, paper ballots are useless unless you can prove who is voting and yet we have nearly the same people yelling about how unfair it is to require people to prove who they are to vote.

you cannot have one without the other if your intent is to protect the system and to be honest you only need paper ballots as a receipt to allow verification in case of suspected interference. we have already seen that some paper ballot designs are more prone to fraud than others.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: