Monday, January 25, 2010
knowing the players
This is simply an analysis of the players from a computer security standpoint. Three main points are examined:
1. What is their academic background in computer security
2. What are their stated positions about Internet voting or, in the absence of statements, what is their corporation's position on Internet voting
3. If they are providing Internet voting technology, what information is publically available about the security analysis for these systems? It is incumbent for all voting technology providers to address all realistic threats to their systems in an open manner. There is no security through obscurity. A failure to do so shows an unseriousness about security.
I also want to make a key point: elections do not hinge on voter perceptions of security and convenience. Elections hinge on ACTUAL security. Asking members of the public if they think Internet voting is secure enough or if they are comfortable voting online or if it is convenient to vote online does not mean, in any way whatsoever, that the actual vote is ACTUALLY SECURE.
If citizens perceive a bank as (financially) safe but government regulation actually creates a situation where the bank fails (as has happened repeatedly in the United States), then it is clear the citizen perception was meaningless, what was important was the government failure to actually deliver an appropriate level of ACTUAL security.
And again, even if the system was actually secure, which is somewhere between highly unlikely and impossible, it still doesn't mean the system meets necessary requirements for a functioning democracy.
The Players:
* Michael Alvarez, California Institute of Technology (Caltech)
- Dr. Alvarez is a Professor of Political Science at Caltech and Co-Director of the Caltech/MIT Voting Technology Project. His BA, MA and PhD are in Political Science.
- info from CalTech site
The mission of the Voting Technology Project is, not surprisingly, around technology: "All of this research and policymaking activity seeks to develop better voting technologies, to improve election administration, and to deepen scientific research in these areas."
It is important to remember that US elections are much more complicated than Canadian elections, with many more candidates running for many more positions, in addition to (in many states), multiple complicated ballot initiatives (direct democracy issues to be voted upon).
* Kimberley Kitteringham, Town Clerk, Town of Markham
- reported in media as advocating Internet voting
"We definitely think our early voting turnout was a direct result of the increase participation of people in the online voting process because online voting, from our staff and post-election survey, engages the voter that has been typically apathetic or difficult to reach. It offers a convenient solution for them because they can do it from anywhere in the world," Ms Kitteringham said.
yorkregion.com - Internet gateway to election reforms in Vaughan - September 30, 2009
* Andrew Brouwer, Deputy Town Clerk, Town of Markham
- Bachelor of Environmental Studies , Urban and Regional Planning; Master of Public Administration , Local Government Program (from LinkedIn profile)
* Cathy Mellett, Acting Clerk/Manager, Halifax Regional Municipality
- reported in media as advocating Internet voting
"We had people vote from Sri Lanka, from Korea, from over 50 Canadian cities and 25 American states," said Cathy Mellett, e-voting project manager for the Halifax Regional Municipality.
"That's really been the objective from the very beginning, it's about getting voters accessible and participating in the overall election here in the HRM."
Mellett said there were no serious glitches in the system during the voting period.
CBC News - 10% of HRM voters cast e-ballots - October 7, 2008
* John McKinstry, Sales Manager, Dominion Voting Systems
- a company that has literally trademarked the word democracy: "Dominion Democracy™ is our comprehensive yet flexible voting suite, designed to uphold the principles and ideals of the electoral process."
- message is shaped entirely around turnout
Voter turnouts continue to fall even in the face of aggressive communications campaigns at all levels of government. One way to improve turnouts is to give the voters more voting choice; choices that reflect changing technologies. Chief among these alternative choices is remote voting. In taking voting to the voter, you remove one of the barriers to turnout.
Taking the voting booth to the voter
- according to Google search (site:www.dominionvoting.com security) entire site has exactly two mentions of security
1.
Everything before and after the ballot is hosted on computer servers. There may not even paper ballots, as is the case with Internet voting.
Dominion can host your elections on our secure servers to ensure the integrity of your election. We pride ourselves on the security and permanency of our server system.
Hosting your election
In summary: your election, hosted on a private company's servers. How do you know they are secure? Because they pride themselves on security.
2. There is a single instance of the word "security" in their document Democracy Suite EMS Edition 2007 (PDF)
To address the sensitivity of the election process from a security standpoint, the system provides role-based authentication and authorization, while all data transactions are protected for greater confidentiality and data integrity.
While it is good that the system uses authorisation to limit access, and "protection" for data transactions (whatever that means), this assumes that a) the authentication credentials have not been compromised b) the network transmission is a particularly vulnerable and interesting place to attack.
Just on the second point: HTTPS encyrption of web transactions is essentially like using an armored car to transport money between two completely unsecure endpoints, between a house with no locks on its doors and a bank vault with no lock or security system. Attackers target system weaknesses. Since the Democracy Suite uses Windows computers, isn't an attacker more likely to attack the servers themselves using known Windows vulnerabilities, than to try to intercept the data in transit? The document does not address these issues. You have to secure Internet voting systems END-TO-END, from keystroke on the desktop to calculated results on the datacentre servers. This is impossible to do with anything approaching a high level of security (a high level of risk mitigation) for an election threat model.
* Alexander Trechsel, European University Institute, Florence
- Professor of Political Science and the first full-time holder of the Swiss Chair in Federalism and Democracy at the European University Institute (EUI) in Florence, Italy.
- info from EUI site
- PhD in Political Science (from LinkedIn profile)
* Tarvi Martens, Development Director, Certification Centre, Estonia
- MSc IT, Tallinna Tehnikaülikool (from LinkedIn profile)
- Program Manager for Internet Voting at Estonian National Electoral Committee (currently)
- Development Director at SK (currently)
- SK is a company that provides "provision of different certificates to physical persons and organisations. Currently, the largest project handled by SK involves issuing authentication and digital signature certificates to Estonian ID cards." - http://www.sk.ee/pages.php/0203
That is, SK is a private company in the business of providing certification technology.
* Urs Gasser, Harvard University
- Dr. Urs Gasser is the Berkman Center for Internet & Society's Executive Director.
- graduate of the University of St. Gallen (S.J.D. 2001, J.D. 1997) and Harvard Law School (LL.M. 2003) (Note: these are all law degrees)
- info from Berkman Center site
* Tom Hawthorn, The Electoral Commission
Remote electronic voting via the internet and telephone was once the future of British elections. But trials held in the 2003 local elections found it made little difference to turn-out and raised concerns about security, privacy and transparency.
Tom Hawthorn, electoral modernisation manager for the Electoral Commission, says that remote e-voting is unlikely this decade, although he believes the idea may return. "In the short- to medium-term, there's things about the existing voting system - voting stations and postal ballots - which can be improved," he says.
guardian.co.uk - Voting searches for the x-factor - Nov 23, 2005
- 2006 presentation "What voters expect from a voting system" indicates high degree of concern about "my vote being private" and "my vote being safe from fraud and abuse" (in terms of percentages these are the top two concerns expressed)
* Adam Froman, President, Delvinia Interactive
- corporation that promotes Internet voting
- "Internet voting made a positive impact on the election results." from blurb on page for their report "Understanding the Digital Voter Experience"
* Dean Smith, President, Intelivote Systems Inc.
- corporation that provides Internet voting
- eight results for site search on "security" (site:www.intelivote.com security)
* Jason Gallagher, Open Source Software Developer
- I don't actually know who this is. The most likely match appears to be: "Lead Open Source Software Developer for McMaster University, Dept. of Family Medicine" (from PCHRI 2006 participants)
* Peter Wolf, International Institute for Democracy and Electoral Assistance (IDEA), Stockholm
- MSc., GraZ University of Technology (from IDEA site)
I welcome corrections and clarifications and I will update this posting if more information becomes available.
Labels: canada, elections canada, internet voting, ivotecan
Thursday, January 21, 2010
http://twitter.com/papervote
No hashtag has been declared that I can find. I'm proposing #ivotecan
For electronic voting in Canada in general I have been using hashtag #evotecan
and there's an aggregator / discussion group on FriendFeed: Electronic Voting Canada.
Labels: elections canada, internet voting, twitter
Ottawa Jan 26, 2010 Elections Canada event on Internet voting
The Canada-Europe Transatlantic Dialogue (Strategic Knowledge Cluster)
Internet Voting: What Can Canada Learn?
This workshop brings together practitioners and scholars to explore issues involved in the development of Internet voting. Speakers include experts from various jurisdictions where Internet voting has been used, and prominent researchers who have studied models of Internet voting. Speakers will detail the development of Internet voting in Canada at the municipal level by examining the cases of Markham, Peterborough and Halifax, and in Europe nationally and sub-nationally by exploring the experiences of Estonia, Switzerland and the United Kingdom. The workshop will consider rationales for the implementation of Internet voting, various features and models of its application, advantages and disadvantages, public acceptance, effects on accessibility and voter turnout, and security issues. Experts will share advice regarding technical considerations such as cost, legal requirements, software and security.
UPDATE 2010-01-25: I just realised I forgot to include a link to the event itself. Here is the Elections Canada link - Elections Canada: Media: Special Events and Conferences: Internet Voting and the Carleton link - Canada-Europe Transatlantic Dialogue (CETD) Events: Internet Voting. ENDUPDATE
Look at the issues they're examining:
* cost
* legal requirements
* software
* security
Let's revisit what I have called the "Democracy Requirements" for voting:
* preserving the secret ballot
* retaining the right to an uncoerced vote
* the integrity and accuracy of the vote count (all votes gathered and correctly counted)
* the simplicity of the system (can voters understand how the entire voting system works?)
Do you see the problem? They're talking about voting, but as usual, they're talking about it as if it were any other government "service" that is "delivered", rather than the single foundational element of our democratic society. This is what they always do, focus on the technology rather than the actual requirements for the integrity of the vote.
I can guarantee what the Internet voting presenters will discuss is three main things: convenience, turnout, and security. They will make a bunch of abstract claims about encryption and secure networks that will sound good but that, if you are an actual computer security expert, are actually nonsense.
You CANNOT, as in impossible:
* use technological security to ensure perfect end-to-end chain of custody for Internet voting
* construct a system in which the ballot is actually secret and anonymous
While it is true that there are theoretical computer constructs that can accomplish this, they run on theoretical computers over theoretical networks to theoretical servers. They do not run on Windows 7 computers on an ISP Internet connection to a bunch of servers in an actual datacentre.
Just think of the thousands, probably millions of phishing attempts every day, and the large number of these attempts that are successful. Just think of the recent security attacks on Google. Just think of the endless litany of lost passwords, lost user accounts, compromised commercial organisations. The home computer and the public Internet is one of the LEAST SECURE possible places I can imagine to hold an election.
Just off the top of my head I can list numerous possible compromises:
* if the password is sent in the physical mail, requiring at most some publically-discoverable extra piece of information (e.g. the user's birthdate), then I can attack the password distribution, in the same way that people steal credit cards and identities
* if it's not sent by mail, how do you solve the huge problem of secure key distribution to 30 million people? (secure key distribution is one of the single hardest problems in computer security)
* If your machine is already on a botnet, and millions of compromised machines already are, I have basically unlimited freedom to alter and compromise the election. I can watch your keystrokes and record who you voted for. I can watch your keystrokes and then, behind the scenes, CHANGE who you voted for. I can decide I don't like the parties running and use my botnet to attack the election servers (if you say "well, the datacentre can just block the attack" - yes, but the attackers are CITIZEN COMPUTERS)
* I can skip the end user and compromise the physical security of the data centre. And/or I can insert code into the servers that counts whatever votes for whatever candidates I want.
Even if the security is done well, there are insurmountable issues.
But even worse, the security is almost never done well. Because it is about cost, it goes often to the lowest bidder. Do you seriously want your entire election run by some private company that was the lowest bidder? Or consultants for Elections Canada that gave the best price? What "best price" means is, as was shown repeatedly for Diebold, the elections technology provider takes off-the-shelf technology (how could they not, and still provide the lowest cost), hacks together some amateurish backend with a somewhat pretty frontend, and then serves that up as a secure elections solution, leaving NOT ONLY all the security issues with e.g. running on Windows, but introducing ADDITIONAL security issues with code that is almost always woefully insecure, badly designed, and not available for review by outside computer security experts.
And even if, by some miracle, none of these things happens, ok we run an election.
It ends like the 1995 Quebec Referendum, 50.58% "No" to 49.42% "Yes" (note: elections are razor close ALL THE TIME).
So you say, all settled then, 50.58% "No".
And I say: PROVE the computers, the Internet, and the data centre were not compromised. PROVE the votes were not coerced. PROVE that it was actually Canadians voting, once, and not stolen accounts anywhere in the world voting multiple times.
You cannot prove this. Goodbye decisive elections. Hello endless battles.
Do you think this is abstract? There was ALREADY a fiasco with electronic voting machines in Quebec, which as terrible as they are, are at least in observable physical space. It was so bad, they had to investigate it, and:
On October 24, 2006 the Chief Electoral Officer of Quebec released a report (in French only) "Report on the Evaluation of New Methods of Voting" (Rapport d'évaluation des nouveaux mécanismes de votation). In a press release, three root causes of problems with electronic voting machines in the 2005 municipal elections were identified:
* an imprecise legislative and administrative framework
* absence of technical specifications, norms and standards
* poor management of voting systems (especially lack of security measures)
He recommended that the current moratorium on the use of these systems be maintained, and leaves it up to the provincial legislature to decide whether or not to use electronic voting in future.
Labels: canada, elections canada, internet voting
Friday, December 18, 2009
Canadians support online voting?
In the poll, released exclusively to CBC: Power & Politics, Canadians were asked if Elections Canada offered a safe way of voting on the internet, how likely is it that they would use it.
Around 49 per cent of respondents said they were very likely and 15 per cent said they were somewhat likely.
Here's the comment I left:
Information on the Internet is just a click away. This issue has been well-studied by computer security experts. One part of it comes down to this magic phrase "a safe way of voting on the internet". That is probably impossible in the real world, outside of the confines of computer science theory. I know some will respond "online banking is already secure" but 1) it isn't & 2) banking has a completely, totally different set of threats and necessary security measure from voting
One good starting point is the Computer Technologists' statement on internet voting http://www.verifiedvoting.org/article.php?id=5867
"Election results must be verifiably accurate -- that is, auditable with a permanent, voter-verified record that is independent of hardware or software. Several serious, potentially insurmountable, technical challenges must be met if elections conducted by transmitting votes over the internet are to be verifiable. There are also many less technical questions about internet voting, including whether voters have equal access to internet technology and whether ballot secrecy can be adequately preserved."
I want to draw attention to that phrase: "potentially insurmountable". Given that paper voting works well now, is easy to understand, and is quick to count, would you rather stay with that, or try a system that computer experts say may be impossible to create? One which even if it solved the technical problems, would still have no solution for the secrecy of your ballot, a sacred right of democracy. Voting integrity is not theoretical. We know that votes were compromised in Iran and Afghanistan. Now imagine instead of paper votes and people in the streets, it had all taken place electronically? You would never know if the results reflected the votes cast.
Labels: canada, electronic voting, internet voting
Monday, July 06, 2009
Norway Internet voting
The Ministry of Local Government and Regional Development is now working on a plan to test the possibility for allowing Norwegians to cast their vote from the home PC at the municipal elections in 2011.
The Minister of Local Government, Magnhild Meltveit Kleppa, is eager to introduce reforms which will increase the interest for elections and for voter participation.
The Norway Post - Electronic home voting next - July 7, 2009
Labels: electronic voting, internet voting, norway
Saturday, June 27, 2009
say no to Elections Canada online voting idea
Allowing Canadians to vote electronically may be the remedy for the ever-dwindling percentage of voters who bother to exercise their democratic rights, Elections Canada suggests.
In a report released late Friday, the independent electoral watchdog says it will push this fall for legislative changes that would allow it to implement online registration of voters.
And it wants parliamentary approval to conduct an electronic voting test-run in a byelection by 2013.
Elections Canada backs online voting - June 26, 2009
(It's not actually clear to me if they're talking about electronic voting machines, or voting online. Both approaches have huge flaws.)
As readers of this blog will already know, I favour the traditional in-person enumeration, and voting on paper in public. These are simple processes that are critical to the integrity of our democracy.
I've already written a critique of the idea that electronic voting will help with voter turnout - citizen engagement and e-voting. I have also outlined many, many times the security risks associated with electronic voting.
Electronic voting is a very bad idea based on incorrect assumptions.
And if you don't think having total confidence in the results of an election is important, check out the current situation in Iran. Elections matter.
This blog started in 2004 before the days of hashtags and such, but I'm suggesting hashtag #evotecan and tag evotecan for this issue.
There are also a few searches that should pull up references to this particular article:
Twitter - Elections Canada backs online voting
Twitter - bit.ly link to Toronto Star article
Google News - articles related to "elections canada" electronic
Labels: canada, elections canada, electronic voting, evotecan
FriendFeed discussion room
http://friendfeed.com/electronic-voting-in-canada
Labels: meta
the linkroll bookmarks
In the meantime if you want to see the actual, non-spammy e-voting links, they're at
http://www.linkroll.com/index.php?action=links&user=papervotecanada
UPDATE: Linkroll is displaying spam links when you pull their RSS feed or use their JavaScript widget. Goodbye Linkroll.
Labels: meta
Sunday, February 01, 2009
Behind the Freedom Curtain - 1957 film about mechanical voting machines
I tried to embed it, but the embed code was too complex, you can see it at
http://www.archive.org/details/Behindth1957
For those of us not experienced with US elections, it's also a reminder of their incredible complexity.
My favorite part is when they talk about how the machine cannot make an error, and is protected by the incredible security of... a key.
Another gem from the Prelinger Archives, the video was on the front page of Archive.org today.
Labels: video, voting machines
Monday, January 05, 2009
why voting systems matter
Office of the Minnesota Secretary of State: Voting Systems map (PDF)
When a recount is necessary:
* You can see the ballots.
* You can determine for yourself whether they are being unfairly accepted or rejected, and how they should be counted.
* You can determine, therefore, whether you think the results fairly reflect the will of the people.
This is important because the current Senator-Elect, Al Franken, is certified as having won by 225 votes. Out of over 2.8 million votes cast in the 2008 US Senate election in Minnesota.
Voting systems matter because elections can be very close,
which means they will be challenged,
which means you must have VISIBLE EVIDENCE of the votes that can be counted by anyone,
so that the public can determine if the results are fair.
CNN: Minnesota canvassing board certifies Franken win - January 5, 2008
Monday, November 10, 2008
citizen engagement and e-voting
For many people concerned about democracy and about electronic voting, the problems we consider are:
* preserving the secret ballot
* retaining the right to an uncoerced vote
* the integrity and accuracy of the vote count (all votes gathered and correctly counted)
* the simplicity of the system (can voters understand how the entire voting system works?)
I call the above "The Democracy Requirements".
You will very rarely hear advocates of electronic and particularly Internet voting talking about any of the above concerns. What they talk about is:
* efficiency
* modernity
* convenience and customer service
* voter turnout (# of votes cast, % of eligible voters who cast votes)
You will notice this is a completely different set of problems.
I call the above "The Voter Engagement Requirements".
So in a sense, we're talking at cross-purposes.
The computer security experts say "electronic voting can never be secure, and you can never know that your vote was counted properly" and they say "we think security is a non-issue because (other technology with unrelated requirements) is 'secure', and e-voting is modern and convenient and young people will use it".
The Democracy Argument Against Electronic Voting (and some paper voting too)
It should be mentioned, the first set of issues applies to many, many other voting options. As soon as you compromise chain-of-custody and the private-in-public vote, you risk all except simplicity.
For example: mail-in voting.
1. If I can identify the sender (by watching the mail they send, by identifying their handwriting, by some unique identifier on their ballot), then no more secret ballot.
2. There is a huge chain-of-custody issue - anyone in the mail stream can intercept and destroy, replace or alter your ballot
3. Your enemies can stand beside you and force you to vote the way they want
These are not abstract issues and rights. People are injured and even die every year in countries where voting is taking your life into your own hands.
Even just advance voting introduces chain-of-custody issues.
(Battlestar Galactica showed a simple fictional scenario for compromising a paper-based election, by having collusion in the chain-of-custody so that an original ballot box was changed with one stuffed with votes for a particular candidate.)
So let me make it very clear: voting on one day privately, in public, on paper, with a hand-count of ballot boxes that never leave the polling station, with scrutineers from all parties watching the count - this is the most elegant solution I can think of to the key issues of secrecy, non-coercion, integrity, accuracy and simplicity.
A machine-mediated vote, or a machine-mediated count CANNOT do this, because you CANNOT (as in, technologically impossible) know what program the computer is actually running. You cannot meet these requirements with an electronic system. I know this is a world where there are few absolutes, but trust me, any computer security expert can tell you this.
The Voter Engagement Argument for Some (non-voting) Use of Electronic Systems
Ok, assuming you want to engage your citizens in some meaningful way, and not in some Canadian Idol illusion-of-convenience superficial way, then I thought it came out quite clearly in the TVO discussion that you need:
* leadership
* engaging issues
* a real connection with voters, particularly young voters
Do you see any mention of technology in the above three items?
There is no website that is going to make you a leader, there is no social network that is going to make your issues engaging, there is no blog posting that can substitute for actually listening to your constituents. IF you already have addressed those issues, then you can reach your voters using...
* radio
* television
* and maybe you've heard of this Internet thing?
Technology is not a solution. Technology is one channel to communicate your message. You have to have an interesting message, first.
If you want more people to vote, give them something they care about to vote for, convince them that their vote matters, and connect with them before and AFTER the election, to demonstrate that you value them for their opinions, not for their increment to your vote count.
If you do that, they will wait in lines for hours. Voting technology doesn't matter. It doesn't solve a problem that Canada has.
Labels: citizen engagement, electronic voting, internet voting, politics
elections are often surprisingly close
There is another great example going on right now in the Minnesota senate race.
According to Daily Kos, "Today's latest results show [Democratic challenger Al Franken] is now trailing Republican incumbent Norm Coleman by 204 votes."
Wikipedia currently shows the tally at
Popular vote Coleman:1,211,562 Franken:1,211,356 Barkley:437,389
If you want that in percentages that's Coleman 41.988%, Franken 41.981%
That means if your voting machines have even a .01% error rate, they've already thrown the election. And the high-tech threat to Minnesota's optical mark-sense scanners? Dust.
Undecided Minnesota Senate Race Used Machines that Flunked Accuracy Tests - Wired - November 5, 2008
In an earlier posting, Wired writes
The problems occurred during logic and accuracy tests in the run-up to this year's general election, Oakland County Clerk Ruth Johnson disclosed in a letter submitted October 24 (.pdf) to the federal Election Assistance Commission (EAC). The machines at issue are ES&S M-100 optical-scan machines, which read and tally election results from paper ballots.
Johnson worried that such problems -- linked tentatively to paper dust build-up in the machines -- could affect the integrity of the general election this week.
ES&S Voting Machines in Michigan Flunk Tests, Don't Tally Votes Consistently - Wired - November 3, 2008
Say what you will about human failure modes, but dust usually isn't one of them.
Given that
1. Elections are often surprisingly close
2. Integrity of the count is paramount (your vote must be correctly counted)
3. Machines have many failure modes
4. A paper count by humans can be open and easily verified and rechecked
Then the best option to ensure confidence in election results is: hand-counted paper ballots.
(I don't know whether the Minnesota recount will require hand-counts.)
Labels: election, electronic voting, optical scan, usa
a note on navigation
http://papervotecanada.blogspot.com/search?q=cbc
http://papervotecanada.blogspot.com/search?q=toronto
Labels: meta
E-voting on TVO The Agenda November 10, 2008
The Debate: E-Voting: An Idea Whose Time Has Come?
Technology and the vote: Why has there been a stubbornly slow adoption of electronic voting?
The Agenda - November 10, 2008
Note: This episode has not yet aired, it will be on television tonight at 8 PM and again at (I think) 11 PM. The video is usually up online a few days after the show airs. I will update this posting with new information when available.
UPDATE: I have created a discussion thread on the "Your Agenda" discussion forum: e-voting. You'll have to create an account there if you want to add your thoughts before or after the show. ENDUPDATE
UPDATE 9 PM: The show has just ended. I thought the debate was good. I also thought it was positive that the debate focused on a much more realistic assessment of evoting in terms of voter engagement and turnout.
If voting was about convenience, you wouldn't have seen people standing in line for hours in the United States. Voting is about citizen engagement. If the citizens find something interesting to engage with, technology can be an enabler. But you don't need online voting for that, you need an online presence for every day other than the election, much as we're seeing already with Barack Obama, who reached out through BarackObama.com (and into many other Internet channels) and is now connecting with Americans through his transition site change.gov
To me this technology argument "young people use technology, so voting should use technology" is ridiculous. Young people aren't stupid. Putting up a Facebook page is not the answer, putting up content that they care about is the answer.
Both of the letters from the MPPs were very well informed.
As well Farhad Manjoo and Darin Barney were both well-informed about the technical issues, and it was great to see Don Lenihan being very clear that it is for the computer security experts to determine whether voting online is secure, not the politicians or corporations.
Marie Bountrogianni was obviously not well-informed about the technical issues, but unfortunately that didn't seem to stop her making incorrect assertions (if we can bank online, why not vote online? um, because they have COMPLETELY DIFFERENT SECURITY REQUIREMENTS).
John Hollins brings a corporate perspective to voting, talking about "serving customers", an approach which to be quite frank, I hate. Voters are not consumers being provided a service, they are citizens engaged in one of the few public activities of our democracy. Voting is not the same as paying a parking fine. (Longtime readers of this blog will know of Mr. Hollins and his boosterism for technology solutions.) In Canada we have very simple elections. You don't need a $3000 touchscreen voting machine with VVPAT paper trail, to record a single vote, so that when there's a problem, you can count the votes on the paper trail. JUST VOTE ON PAPER FIRST.
I will write a follow-up post on citizen engagement vs. e-voting.
Overall I thought it was a good discussion which in the end turned far more on the citizen engagement aspect.
After posting on the Agenda forum I was fortunate to get an email from Sandra Gionas and to have a chance to talk with her on the phone, and she has kindly included substantial quotes from me in her Inside Agenda blog posting Control, Alt, Delete and Vote.
ENDUPDATE
I love the loaded language people use for paper voting: "quaint", "old-fashioned"
or for the lack of technology in Canada's federal elections: "stubbornly slow adoption".
stubbornly?
This is what I had to say the last time someone argued that you couldn't stop the wheels of e-voting progress:
Ah yes. The real world. The modern world. The practical, down-to-earth, realistic, Common Sense Revolution world. Paper is obsolete, so old-fashioned, like the Geneva Convention and other inconveniences.
Bullshit.
corporate voting bullshit - Paper Vote Canada - November 24, 2006
If paper voting is so obsolete, why is it that, overwhelmingly, the most articulate and forceful campaigners against electronic voting are computer scientists? Are computer scientists generally considered stubbornly slow adopters? Could it be that the actual experts in computer technology know that from the standpoints of security, cost, simplicity and core principles of democracy, electronic voting is just a very bad idea?
You don't believe me?
* Computer Scientists question electronic voting - March 3, 2003
* Computer scientists slam e-voting machines - CNet News - September 27, 2004
* Following issuance of an analysis by four computer scientists who were members of the SERVE Security Peer Review Group, the Pentagon decided to scrap plans for the use of this technology to cast ballots in the 2004 Presidential election.
* Computer scientists weigh in on e-voting - July 20, 2006
* UC Computer Scientists Release Video on How to Hack a Sequoia Touch-Screen Voting Machine - September 9, 2008
* E-Voting Doesn’t Get Computer Scientist’s Vote - October 10, 2008
I could go on listing reports and articles for many pages, but I hope I've made my point.
Not having electronic voting is not stubborn resistance to progress, it's rational opposition to expensive, unnecessary, insecure technology that will undermine the foundations of our democracy.
Labels: canada, electronic voting, television
Wednesday, November 05, 2008
The Onion Reports
All hail the DRE 700.
Labels: electronic voting, humour, video
Monday, November 03, 2008
Oprah's Presidential vote initially not recorded by electronic voting machine
What's interesting (and sad) is that Oprah blames herself for her voting problems.
First of all, if the machine doesn't record your vote, that's because the machine is badly designed. Second of all, it means you shouldn't be using machines.
It doesn't seem to occur to Oprah that the fault could lie with the machine.
Labels: election, electronic voting, usa
Friday, October 31, 2008
machines are insecure and vulnerable
shape-shifting electronic votes are more than fantasy, according to reports from states including West Virginia, Missouri, Nevada, Georgia and Colorado. Whether by accident or design, touch-screen voting machines have "flipped" votes from a caster's chosen candidate to one he opposes.
Unlike the old days when campaigners hung around street corners haranguing voters with handouts and pints of beer, the electronic era presents a sophisticated challenge to democracy.
Now, says Crispin Miller, author of Loser Take All: Election Fraud and Subversion of Democracy 2000-2008, changes can occur seamlessly, without a breath of suspicion. Electronic glitches are only one of a range of mishaps, mistakes and dirty tricks that may decide outcome on Nov. 4.
Complaints about the electronic machines have mounted, along with calls for a return to paper ballots, like Canada's.
"More traditional systems are better," says Jeremy Epstein, a technological security expert and member of two Virginia legislative commissions that studied voting machines. "Paper-based and hand-counted ballots are fast, accurate and cheap. Studies show that machines are insecure and vulnerable to attack."
Fraud fears grow as [US] voters throng polls - The Toronto Star - October 21, 2008
(The article title is not great, something like "voting machine errors and voting surpression plague election" might have been closer to the mark.)
Labels: election, electronic voting, usa
Thursday, October 30, 2008
optical scan to dominate 2008 US election
I should mention that they use some confusing terminology.
To me electronic voting covers optical scan, DRE and Internet voting.
They consider electronic voting to cover only DRE (usually touchscreen) machines.
An optical mark-sense reader is an electronic device just like a touchscreen machine. It uses optical sensors to read a dot on paper, rather than to record a fingerprint. It is subject to most of the kinds of attacks that a touchscreen suffers from: you can compromise the software/firmware, there may be errors in the software/firmware, the optical sensors may be mis-aligned or malfunctioning, the paper path may jam, the power can fail, etc.
As well, if you record the order in which voters submit their ballots for scanning, you can reverse this to determine exactly who voted for whom, by going down the stack of ballots - once again the secret ballot is compromised.
It is true that IF AN ERROR IS DETECTED or IF A RECOUNT IS MANDATED, you can then hand-count the ballots (albeit going slightly crosseyed staring at tiny circles for hours).
Of course if you were a clever hacker, you would just program the scanner to distort the election by a margin smaller than that which would trigger any investigation. A similarly small error would also not be detected.
NOTE: some kind of rendering bug puts this table far down on the page.
| Type | % Registered Voters |
|---|---|
| Punch Cards | 0.10 |
| Lever Machines | 6.72 |
| Hand-Counted Paper Ballots | 0.17 |
| Optically-Scanned Paper Ballots | 56.17 |
| Electronic (DRE / Touchscreen) Systems | 32.63 |
| Mixed | 4.22 |
from 2008 Voting Equipment Study (PDF)
According to votingmachines.procon.org the numbers previously were
2004: 1% paper, 35% optical scan, 29.5% DRE
2000: 1.5% paper, 29.5% optical scan, 12.5% DRE
Labels: election, electronic voting, usa
Wednesday, October 22, 2008
machines: oh the many ways they can fail
The elections staff had collected electronic copies of the votes on memory cards and taken them to the main office, where dozens of workers inside a secure, glass-encased room fed them into the “GEMS server,” a gleaming silver Dell desktop computer that tallies the votes.
Then at 10 p.m., the server suddenly froze up and stopped counting votes. Cuyahoga County technicians clustered around the computer, debating what to do. A young, business-suited employee from Diebold — the company that makes the voting machines used in Cuyahoga — peered into the screen and pecked at the keyboard. No one could figure out what was wrong. So, like anyone faced with a misbehaving computer, they simply turned it off and on again. Voilà: It started working — until an hour later, when it crashed a second time.
...
so many printers had jammed that 20 percent of the machines involved in the recounted races lacked paper copies of some of the votes. They weren’t lost, technically speaking; Platten could hit “print” and a machine would generate a replacement copy. But she had no way of proving that these replacements were, indeed, what the voters had voted. She could only hope the machines had worked correctly.
...
In the last three election cycles, touch-screen machines have become one of the most mysterious and divisive elements in modern electoral politics. Introduced after the 2000 hanging-chad debacle, the machines were originally intended to add clarity to election results. But in hundreds of instances, the result has been precisely the opposite: they fail unpredictably, and in extremely strange ways; voters report that their choices “flip” from one candidate to another before their eyes; machines crash or begin to count backward; votes simply vanish.
An extensive New York Times Magazine report from January 6, 2008: Can You Count on Voting Machines?
And these are just the obvious, visible ways in which machines can fail.
There are many other silent ways in which the machines could fail internally that you would never detect.
You can move to optical mark-sense, but these are still machines:
* the poll workers need to get trained on them
* the paper can jam
* the scanners can fail
* the entire machine can fail
and on and on and on.
In case you think those are unlikely scenarios, they are already happening in advance voting in the United States.
The Jacksonville Times-Union reported long lines in northeast Florida, with at least two counties reporting problems with voting machines. In Duval County, 7 of 15 optical scanning machines used to count ballots had to be replaced, the newspaper reported.
Early voting suggests 2008 may see record turnout, expert says - CNN - October 21, 2008
Labels: election, electronic voting, usa
Monday, October 20, 2008
US moving to optical mark-sense rather than DRE
The main issue, according to a 2005 overview of electronic voting by the Institute of Governmental Studies at the University of California-Berkeley, is that if the record of votes cast exists only in digital form in a touch-screen system, there is no independent way to confirm the votes were recorded accurately and thus no way to conduct a reliable recount.
Overall, in the nation’s 170,000 polling places, there has been a shift from predominantly using manual systems (lever machines, punch cards, paper ballots) to computer-based systems (optical scan and DREs) in federal elections.
But according to news reports, as a result of the controversy over DRE machines, in the 2008 election many states might use optical scan paper ballots that require voters to fill in ovals with a pen.
Debate Continues over Security, Reliability of Voting Technology - America.gov - 27 August 2008
As I've said before, optical scan is the least-worst electronic technology, because you can at least do a manual recount of the paper ballots,
but you're still better off just counting the paper ballots by hand in the first place.
Labels: electronic voting
The Coast on electronic voting
It's no wonder that Americans are increasingly distrustful of the voting process. Voting experts challenge every aspect of elections, including the registration process, the procedures at the polling place itself, the use of electronic machines and the counting and recounting of votes.
Contrast the sour American experience to Canadian elections: In this country, voters show up at the poll and are handed a paper ballot and a pencil. They check the box next to their preferred candidate and put the ballot in a box. After the polls close, an election official opens the box, and the official and poll observers from the political parties examine each ballot and agree on how the vote was cast. A final tally takes about half an hour.
The Canadian system is clean, unambiguous and fair.
But the Halifax Regional Municipality doesn't like the Canadian system, and is determined to change it.
iVote: Can electronic voting save democracy? - The Coast - September 18, 2008
Labels: canada, halifax, internet voting
Sunday, October 19, 2008
machines don't fail, people fail
This will be shown to be totally false when, on election day, a percentage of the millions of voting machines fail in the following ways:
* mechanical failure
* touch screen misaligned
* touch screen doesn't work at all
* display screen fails (black screen)
* power fails
* printer fails
* card reader fails
* software error
If they were using Internet voting, the ways in which things could fail would be even more spectacular:
* computer monitor fails
* computer hard drive fails
* mouse not working
* keyboard error
* power fails
* network card fails
* router fails
* connection to ISP fails
* network attack or denial of service
* ISP hardware or software fails
* network transmission error
* voting software error
* central voting servers fail
* air conditioning in central voting server room fails
* power fails in central voting server room
* network fails in central voting server room
* server room catches fire (this happens more often than you might think)
Note that all of the above is just a sample of what WILL happen (the odds of a hard drive failing eventually are 100%) and none of the above require any malicious activity, just normal failures of systems. When you add in malicious activity, the scenarios get much, much worse.
Labels: electronic voting
and so it begins
"People make mistakes more than machines," said Jackson County Clerk Jeff Waybright.
Dear Jeff Waybright,
You are way wrong. You are confusing consistency with correctness. If a machine is programmed to do something (programmed, by a person) it will do that thing, consistently. If what it was programmed to do is WRONG, it will do it CONSISTENTLY WRONG.
Yours Truly,
Someone who actually knows about machines
Above quote from More W.Va. voters say machines are switching votes in the Charleston Gazette, October 18, 2008. The story reports that machines are not correctly displaying votes (presumably because of touch screen misalignment, or other malfunction).
Labels: election, electronic voting
Friday, October 17, 2008
Is America Ready to Vote?
On November 4, 2008 voting systems will fail somewhere in the United States in one or more jurisdictions in the country. Unfortunately, we don't know where. For this reason, it is imperative that every state prepare for system failures. We urge each state to take steps necessary to insure that inevitable voting machine problems do not undermine either the individual right to vote, or our ability to accurately count each vote cast.
Is America Ready to Vote? State Preparations for Voting System Problems in 2008
Labels: electronic voting, usa
Tuesday, October 14, 2008
Election Day in Canada - Please Vote - October 14, 2008
Please vote.
Remember there are new identification rules, roughly you need either a driver's license (or health card with photo and address in Ontario) or two pieces of ID, one with name & photo and one with address.
See Voter Identification at the Polls for more information.
In general, see
http://www.elections.ca/
for any information you need about voting today.
If you're new to the process, this very simple guide will walk you through (with the exception of the new identification rules).
Saturday, October 11, 2008
The Star on paper and electronic voting
"It's a very human system. It works," says Akerman, 40, an Ottawa technology planner and security expert. "You mark your ballot in private, but it's in a public setting. And it balances interests. You have scrutineers from different parties watching each other. It's hands on, easy to understand."
The ballot question: Paper or not? - The Toronto Star - October 11, 2008 - by Leslie Scrivener
Previously:
The Star had a very good article about the electronic voting issue in 2004, but unfortunately it doesn't seem to be online anymore, I wrote about it at
July 13, 2004 Is the future in line or online? - Toronto Star - published July 12, 2004
Labels: canada, electronic voting, newspaper
Friday, October 10, 2008
Spark plug

That reminds me I should put up some info about voting places and election results on the 13th, since I usually get a pile of hits on election day.
UPDATE: In case you're wondering, most of the hits are people searching for general voting/election information (where to vote, how to vote), not about the specific issue of electronic voting in Canada.
Labels: meta
Wednesday, October 08, 2008
the security stuff problem
Here's the problem: lots of people have tried to create secure systems for a long time, and have failed miserably.
I don't have to get technical at all, I can just talk in the consumer space.
1. For years, games companies put elaborate efforts and skilled people into trying to protect their games from piracy. They had special codes, special floppy disks with holes punched into the magnetic media or deliberate errors, physical dongles, you name it.
And yet their games were always pirated. Eventually most of them just gave up on protecting their games.
2. For years, continuing today, media companies like the record and movie industry have attempted to protect their content from piracy with Digital Rights Management (DRM). They have sophisticated hardware, elaborate codes, highly skilled people and a large monetary incentive. And they have failed.
iTunes music DRM? There's a hack.
DVD DRM? There's a hack.
3. Apple has an incentive to protect its iPhone from being used on any network, as it has an exclusive deal with AT&T. Their phone is "locked".
iPhone locking? There's a hack
THERE IS ALWAYS A HACK.
Because any piece of software or hardware you can create, I can put a layer in front of. Your software talks to a hardware dongle? I write a layer of software that pretends to be the hardware.
And we're not talking big power or political incentives here, we're talking smart kids (mostly) who wanted to play some games, listen to some music, or watch some movies.
So if they couldn't even protect SONGS, do you seriously think they're going to be able to protect AN ENTIRE ELECTION?
There is no unbreakable "security stuff" to do that, it simply doesn't exist.
And even if it did, the incredible complexity of it would mean that the entire election would boil down to "trust the machine and the computer guys".
Wouldn't you rather trust a piece of paper you can see, a counting system so simple elementary school students could perform it, and volunteers and scrutineers from your own neighbourhood that you can watch?
Labels: security
HRM e-voting success...fully eliminates the secret ballot
There were e-voters in more than 30 countries, with the oldest born in 1913, they said.
"We had people vote from Sri Lanka, from Korea, from over 50 Canadian cities and 25 American states," said Cathy Mellett, e-voting project manager for the Halifax Regional Municipality.
10% of HRM voters cast e-ballots (via Carol) and 28,709 cast municipal e-votes (via sparkcbc Twitter)
Hmm, so let's see. You assign a PIN number to each citizen, and mail the PIN to their address, and the verification info is their birth year, AND you're tracking their voting location, which can only be done by tracking their IP address, which semi-uniquely identifies their computer.
So you know who they are multiple times over, through the combination of PIN, birth year, mailing address, and IP address.
So number one, goodbye secret ballot.
Are you seriously going to take it on trust that they won't be tempted to check to find out who voted for whom? That no one will ever be tempted to check this?
Number two, in a world full of good people and lots and lots of bad people, from Nigerian scammers to Russian mafia, letting people vote in a Halifax election from any computer anywhere in the world is a feature? Are you kidding me?
Labels: halifax, hrm, internet voting
Tuesday, October 07, 2008
short piece on electronic voting on CBC Radio Spark
Dan talks to Ilona Dougherty, Richard Akerman, and Grace Lake about voting online
Episode 48 - October 8 & 11, 2008 - CBC Radio - Spark - posted October 07, 2008
The audio is available as an MP3 download, or you can subscribe to the podcast, or get it through iTunes.
Just a couple quotes from me were used, but I think I got my points across.
Labels: audio, canada, cbc radio, cbc radio spark, electronic voting
terminology
Internet voting = web voting = Using the Internet to record your vote on some central election servers.
Electronic voting machine (or I sometimes just say "voting machine") = any of a number of different technologies for voting, primarily about touch-screen voting machines, but I would extend it to mark-sense optical scanners as well, in its broadest sense.
Electronic voting encompasses both using electronic voting machines, and Internet voting (which you can think of as using an electronic voting machine, at a distance, over the net).
This is fairly consistent with the use at
http://en.wikipedia.org/wiki/Electronic_voting
Labels: electronic voting
more thoughts on electronic voting
This is what I just said in an email to a newspaper interviewer:
Ultimately it comes down to a choice between a very simple system in the physical world where we use a combination of privacy, being in public, and the competing interests of strangers (the scrutineers and election workers) to provide results based on physical evidence that everyone can agree upon,
or an incredibly complex system involving your computer, many computer networks, and computer servers, all running software created by strangers, with all the possibilities this raises for either malicious attacks on the election, or normal computer errors, a situation where there simply is no evidence to rely upon other than what the computer says, and the computer can lie.
In other words, electronic voting is no different than telling a stranger how you want to vote ("I want to vote for the blue party"), and then having to trust that they actually voted the way you asked, despite the fact you know that they can lie.
Can you imagine if we had used Internet voting for the last Quebec referendum? We would still be arguing about the results.
In short, although I love technology, I know the difference between appropriate technology and unnecessary technology.
Paper and pen is the appropriate technology for voting.
Labels: canada, electronic voting
Friday, October 03, 2008
paper voting isn't broken
If it ain't broke don't fix it - May 13, 2008
When officials come away from observing an electronic vote-counting system used in Monday's New Brunswick municipal election, I hope the lesson they take with them is this: Citizens do not need a machine to vote, nor to count those votes. And I hope for the health of our democracy that they will see that the application of technology to replace humans in this area is wholly inappropriate.
Labels: canada, electronic voting, new brunswick
Homer vs. the voting machine
Labels: electronic voting, simpsons, usa, video, voting machines
electronic voting means trusting a stranger with your vote
UPDATE: I should check my stats for this blog more often - I see that there is an item specifically about this in the Spark blog
Would you vote over the internet in a Canadian federal election? - Posted by Dan Misener on October 01 [2008]
There are some good comments on the blog posting.
ENDUPDATE
I think I conveyed my three major points:
* a key element of the voting system is trust
* a voting machine (or Internet voting) is no different than telling your vote to a stranger
* a computer can lie
Or in other words, electronic voting means that in a system based on trust, you're giving your vote to a stranger who can lie.
There is one thing I regret saying, I said something like "not everyone is a computer scientist or a mathematician, the average Canadian can't comprehend web voting" - my actual intent was something more like "the average Canadian doesn't have the technical training to understand exactly how web voting works and all the associated risks".
I did then wrap up with what I think was a strong point: Internet/web/electronic voting introduces uncertainty and complexity into what should be the most certain and least complex process in our democracy.
If you look at the specific example of the Referendum, which was so incredibly close - imagine what would have happened if the next day people had started saying "I think my computer didn't record my vote correctly" - we'd never be able to resolve it - we'd still be arguing about it.
Speech! Speech!
If I was giving this as a prepared presentation (which is more my area of communication strength), rather than as an interview, it would go something like...
Voting is about policies, but also about trust. In yesterday's leaders debate, we saw five people around a table that most of us will never meet, five strangers. We have to determine, in part, whether we trust them. Similarly most of us only talk to our MPs for a few minutes when they show up at the door before the election; they are also strangers.
It's quite a remarkable transfer of trust, from millions of people to a few hundred, transferring the authority to declare war and to spend billions of taxpayer dollars.
The process to transfer this trust is voting, which also involves trusting strangers - you probably don't know the poll workers or the scrutineers.
But the good news is that in the physical world, we are really good at reasoning about how to manage the risks of trusting strangers. If a stranger asks for directions on the street, you will probably help them, but if they ask for a $100 loan and your name and address and promise to return the money to you later, you probably won't help them.
Our existing paper-based, human-counted system is based on our understanding of the balancing of motivations and self-interest, along with a clear physical evidence chain. You mark the ballot yourself in secret, you drop it in the box in front of everyone, and you trust that the competing interests of the scrutineers from the different parties will ensure that the open counting of the paper ballots is done properly.
If there's an issue, you can just count the ballots again.
And you know that if something does go wrong, all of those people live in your community and have to deal with the consequences.
You literally could have an elementary school class run a classic Canadian Federal election scenario and they could identify all of the possible risks, because reasoning about physical evidence and human behavior is one of our strengths.
Now imagine instead that when you walk into the polling station, they say to you "for improved efficiency, just tell this stranger how you want to vote, and he will go and handle the rest". So you tell him "I want to vote for the red party" and he goes and marks a ballot in secret and drops it in the ballot box. Now you have to trust that stranger totally. You can ask him, "did you vote for red?" and he can assure you over and over, but you can never actually know, for certain, how he voted on your behalf.
In effect, his report of your vote is now testimony, or even hearsay.
We understand this quite well in our criminal justice system. Physical evidence (e.g. a marked ballot that you can see) has the highest degree of credibility. Testimony much less so, because humans can lie. Hearsay least of all, because humans can really lie a lot about other people.
You go from e.g. seeing an X in a circle on a piece of paper, to having someone say "I definitely marked an X by the red candidate", to someone saying "I think I thought I saw someone mark an X by the red candidate".
So now we just need to replace one step and I think you'll see the problem: replace "tell your vote to a stranger" to "enter a your vote on a computer".
How is that like telling a stranger? Well when you think about it, computers don't program themselves. Every computer program, and even every computer chip, was designed by someone - by a stranger. Actually by many many strangers. The computer is not some cold objective logic machine, incapable of error, the computer is the embodiment of the human intentions that went into its code and hardware - the computer is a human, in silico.
That means all of the things a person can do, a computer might do - a computer might fail, because of an error, or a computer might behave maliciously, because of malicious intent.
That is to say, the computer can lie. We often don't think about this, because for commercial reasons most people write code intended to behave well and to present information correctly. But there's no reason your code can't say
get input
if input = "vote blue" then
record +1 blue vote
display "voted for blue"
else if input = "vote red" then
record +1 blue vote
display "voted for red"
end
THE COMPUTER CAN LIE.
You can see very real examples of this in sophisticated virus social engineering - the virus presents a window that says "you need to update your antivirus software immediately [ok] [cancel]" and when you press [ok], it actually fills you computer with viruses.
Beyond that, even without malicious intent, the computer can fail in a million bazillion ways - bugs in the code, hardware error, network error, power failure, overloaded by too much network traffic (as happened with Do Not Call List), and on and on. Whereas a paper voting system can continue without power, and short of burning the paper or killing the people, it has limited ways that it can fail.
And this is an important point: people already attack physical voting systems, which is very high risk. (See e.g. Zimbabwe.) The reason they take this risk is the rewards are enormous - wealth beyond any other criminal scheme, power, privilege...
Consider that spammers have already constructed networks of hijacked machines ("botnets") - millions of machines in some cases - just to take advantage of the few thousand or at most few million dollars they can earn by ripping people off. Now just think - if there's Internet voting they can use the exact same technology to control who gets access to BILLIONS OF DOLLARS.
So think about it - you would never vote by telling a stranger your intent and letting them vote for you - why would you vote by telling a strange machine your intent and letting it vote for you?
Labels: canada, cbc radio, cbc radio spark, internet voting, radio
Tuesday, September 30, 2008
Elections Canada and the Very Bad Online Idea
If you want to increase turnout, have a campaign to increase turnout.
Have ballot boxes at workplaces, or make the entire day a holiday.
There are lots and lots of ways to increase turnout.
Supporting Internet voting is asking for catastrophe in many different ways:
* it turns the solemn act of voting, one of the few acts of citizenship, into something no different than adding an item to your Amazon.ca shopping cart
* it means that you're using inherently unsafe, unsecured machines to provide the infrastructure for the most critical process of our democracy
* it means that someone can stand with a gun to my head and force me to vote the way they want while they watch (which, incidentally, also applies to voting by mail)
If you seriously think online voting will engage "the youth", then why not just go all the way and let them vote on their cellphones and called it "Greatest Canadian Idol"? (The sad part is that their cellphones are almost all much more secure than their computers.)
Here's what prompts this latest concern:
Elections Canada hopes it has the answers.
The federal agency has adopted a five-year strategy to boost turnout, with a focus on youth engagement.
Key planks in the plan are to communicate more frequently with voters between elections, via education programs, and to make voting more accessible to all Canadians.
Elections Canada is hoping to adopt online voter registration in two years, a tool already available in some provinces like Alberta.
Perhaps more importantly, the agency hopes to test web voting within five years, beginning with a byelection.
"The general philosophy is to take the ballot box to the voter," says Mayrand, Canada's chief electoral officer.
If the Internet gamble proves successful and security concerns can be addressed, Elections Canada would ask Parliament to amend legislation to include e-voting for general elections.
"Youth are quite familiar with technology. They expect to be able to use it for most of their life activities," Mayrand adds.
Black Mark - Calgary Herald - September 6, 2008
The problem being, voting is not like "most of their life activities".
Voting is not banking, voting is not surfing the net, voting is not listening to music, voting is not texting a friend.
Banking is an example that is often used, or online taxes, but these are completely false examples. The bank knows exactly how much money you have, as does the government, and every transaction has an audit trail and can be reversed.
Voting must not have an audit trail, and cannot be reversed (if you are going to retain a system of private, secret ballots).
Voting, since it provides the transfer of power from the very many to the very few, is a very attractive attack point for malicious actors, and I mean "attack point" quite literally - people die for their vote already today, can you imagine how much more tempting for all of the negative forces in our society to take advantage of the vast computer networks that already exist for spam and attacks ("botnets") and use them to throw the election or to write a targetted virus to compromise the election?
That's not even to touch the issues of just running the election assuming everything actually goes right. The Do Not Call List site just went down because of high demand after it was launched. The Tax servers routinely get overloaded when millions of Canadians use the online systems near filing day. That's not a problem, because those transactions are repeatable.
What happens when the election servers go down from heavy demand on election day?
People resubmit their vote? We have the vote again another day?
A human-run, human-counted paper voting system has a very small number of failure modes, all of which anyone who understands the physical world can easily work out (people can steal the ballot boxes, etc.)
Computer-run, computer-counted voting systems have almost unlimited failure modes, which almost no one except computer and network security experts can fathom.
A paper voting system must work during the voting, and during the counting, and then it just disappears.
An electronic voting system requires servers that must be secured both physically and electronically 365 days of the year, every year, in case a vote is called.
The whole idea that you would get any benefits from online voting is patently ridiculous. The only way you can make it appear to work is to ignore all of the security issues, ignore all of the ongoing cost issues, treat it as if it were a banking or other repeatable and auditable transaction, as if voting is something that should somehow be made "efficient", and make a bunch of claims about turnout.
It is a Very Bad Idea.
Previously:
November 28, 2006 let's have a discussion
November 15, 2006 Geist on e-voting
Labels: canada, internet, internet voting
Thursday, August 21, 2008
Lou Dobbs - private companies running voting
DOBBS: For more than two years here, we've been reporting on the serious threat that electronic voting poses to this democracy. As a result, some states have begun to scrap their e-voting machines altogether. But a third of the nation will still be using e-voting machines in November. And more disturbing a new report says election officials often are outsourcing their responsibilities to the very companies that make the e-voting machines, even trusting those companies to count the votes. Kitty Pilgrim has our report.
(BEGIN VIDEOTAPE)
KITTY PILGRIM, CNN CORRESPONDENT (voice-over): Ellen Theisen has been a software writer for more than two decades. Living in Washington State, she was disturbed by electronic voting problems across the country, so she formed a nonpartisan citizen's activist group to investigate voting irregularities. A new report by that organization, VotersUnite.org, says that private companies now run many elections.
ELLEN THEISEN, VOTERSUNITE.ORG: Elections should be accountable to the people and run by public officials who are selected by the people to run them. So when that's handed over to private vendors, these public elections are no longer public.
PILGRIM: According to the report, many jurisdictions in the country are entirely dependent on the voting machine companies. The companies also tabulate results. State officials have to take their word for the results. The company owns the software and equipment and doesn't have to share it. It's proprietary. Election officials often can't do a recount without help. One state that rejected that arrangement is Oklahoma. In 1992, Oklahoma put in its own optical scan system, which is still owned and operated by the state.
MICHAEL CLINGMAN, OKLAHOMA STATE ELECTION BOARD: Election night, it's really all public officials dealing with the election and nobody else.
PILGRIM: Oklahoma wasn't tempted by new federal funds in 2002 when many other state and local governments used the Help America Vote Act money to buy touch screen machines.
UNIDENTIFIED MALE: There was really nothing on the market we would buy then and there's still nothing we would want to buy today.
Lou Dobbs Tonight - August 20, 2008
Labels: electronic voting, usa
Saturday, January 12, 2008
Olbermann - Man vs. Machine
Anything of value should be auditable. ...
To give voters the confidence that they deserve that their votes will be counted as they intended... in every election there should be an audit.
See the full interview
Countdown with Keith Olbermann - #4 Man vs. Machine
via Black Box Voting forum
e-voting was a bad idea and is reaping the whirlwind
1) Electronics makes things "efficient" and will save money.
2) Elections are a government service just like any other.
Underlying this was an extraordinarily naive concept of elections as uncontroversial events that would never be challenged, and that no one would ever make a serious attempt to commit election fraud. There would never be close races. In essence, a disdain for the whole voting process, because it implies that a single vote will never make a difference.
This is simply demonstrably untrue, as elections with contested results have been a worldwide problem, with accusations flying, often with violent repercussions. Time and time again we have seen incredibly close elections.
The reality is: the more complicated and indirect you make the voting process and the vote counting process, the more you open the system to suspicions of fraud, and associated loss of confidence in the results of the election.
As I've said before, voting is an incredible act of civic alchemy, in which the will of the many is transmuted into tremendous power for a very few (e.g. in the US, a few hundred people leading a nation of 300 million). WITHOUT COMPLETE CONFIDENCE, this cannot work; a million people are not going to hand over power to a single politician unless they are confident s/he was actually selected by a fair vote.
In a partisan environment with close-fought elections, this means that now
EVERY SINGLE ELECTION WILL BE CHALLENGED
Oh, brilliant cost savings there, you idiot technocrats. Instead of pen and paper and election results in hours with full confidence of the electorate, elections will now turn into endless recounts, court challenges, and code examinations. Since it is almost impossible to prove that machines weren't hacked, any case where there is not a full paper trail will end up basically unresolvable.
Hand counted paper ballots were never broken,
the only way to fix this problem is to go back to them.
New Hampshire is lucky they have optical scan (the least-worst of the electronic options) so that confidence can be restored by a manual recount.
For a taste of what's to come, see ArsTechnica - Analysis: Why the "Hillary hacked NH?" story is important (Updated)
Labels: electronic voting, optical scan, rant, usa
Thursday, October 25, 2007
minor site note: added feedflare
UPDATE: Minor template change to adjust FeedFlare.
Labels: meta
Saturday, April 07, 2007
electronic voting machines explained
Thursday, January 25, 2007
new blogger
Labels: meta
Tuesday, December 19, 2006
why postal ballots also suck
2. No immediate feedback / oversight if there are problems with the ballots
3. People screw up and put their signed declarations in the same envelope as their vote, thus a) spoiling their ballot and/or b) revealing who they voted for
Globe and Mail - Postal-ballot errors spark review - December 19, 2006
Municipal Affairs and Housing Minister John Gerretsen says he's considering revisions to Ontario's municipal elections law as towns and townships continue to struggle through counts of problem-plagued mail-in balloting in the Nov. 13 vote.
...
This week, judges in Bracebridge and Lindsay ordered that efforts be made to count ballots that had been determined spoiled by clerks in four Ontario municipalities because no signed declaration was enclosed.
Although some other municipalities faced with high postal-ballot rejection rates -- generally about 20 per cent -- instituted procedures before election day to try to salvage the votes, that option was refused by Lake of Bays Township in Muskoka, the City of Kawartha Lakes and the townships of Highlands East and Minden Hills.
Minden Hills is the only municipality so far where the added votes have made a difference. Out of 849 rejected ballots, 256 votes were found with a signed declaration improperly inserted inside the secrecy envelope and the vote was allowed.
As a result, challenger Lisa Schell saw her 11-vote loss to Clayton Cameron reversed to give her a one-vote majority.
Saturday, December 02, 2006
US NIST recommends scanned paper ballots
"Paperless electronic voting machines 'cannot be made secure' [pdf] according to the [US] National Institute of Standards and Technology (NIST). In the most sweeping condemnation of voting machines issued by any federal agency, NIST echoes what critics have been saying all along, that due to the lack of verifiability, 'a single programmer could rig a major election.' Rather than adding printers, though, NIST endorses the hand-marked optical-scan system as the most reliable."
(in case you're wondering, Internet voting counts as a "paperless e-voting machine")
I wonder how many experts have to say that electronic voting sucks before people will listen.
Of course, crazed luddite that I am, I would eliminate the machine-based counting as well, and just have humans count the paper.
Slashdot - NIST Condemns Paperless Electronic Voting - December 1, 2006 /.
Tuesday, November 28, 2006
let's have a discussion
a very disturbing and one sided perspective
But Adam, you haven't responded to a single issue that I raised.
I welcome all perspectives, provided they are fact-based.
In particular, I invite realistic threat-risk assessments, cost assessments, and cultural assessments.
Let us take Internet voting.
1. Is the code open-source?
2. Has the code been audited by neutral computer security experts?
3. Where are the servers?
4. How are the servers protected?
5. Has the server security been audited by neutral computer security experts?
6. Who pays to protect the servers and the code for the thousands of days during which they are not being used for municipal elections?
7. Who wrote the code?
8. Have they all passed an independent security certification?
9. Do they have ties to any particular political party or other organization that might have an interest in the outcome of the election?
10. How do you mitigate the risk of paying or forcing someone to vote in the way you want, as you watch them on the Internet?
11. How do you mitigate the risk of the massively insecure home computers that are used for Internet voting?
12. When the full costs of security audits and thousands of days of security protection are taken into account, in order to provide a single day of municipal voting, how do you justify the expense?
There's a dozen questions. I have way more where those came from.
I challenge anyone to answer.
Friday, November 24, 2006
corporate voting bullshit
You need to recognize that municipalities such as Markham are no less concerned about the integrity of the voting process, they simply live in the real world and recognize that offering Internet voting is clearly a solution for voter apathy.
Adam Froman
President
Delvinia Interactive
Ah yes. The real world. The modern world. The practical, down-to-earth, realistic, Common Sense Revolution world. Paper is obsolete, so old-fashioned, like the Geneva Convention and other inconveniences.
Bullshit.
You want the real world?
The real world is run, to a very large extent, by corporations.
Corporations exist, their sole purpose is, BY LAW, to make money.
To make money, as constrained by the legal framework.
Corporations also must, under our system, continue to grow.
To grow endlessly.
There are only two ways for corporations to grow
1) By finding more ways to charge people more money for things
2) By changing the legal framework itself, to remove constraints on them making more money
A corporation is providing Internet voting in Markham not out of the goodness of its heart, not out of a passion for citizen involvement, but to make more money.
Delvinia is promoting the wonders of that Internet voting system because it was paid to.
Tobacco companies and their paid apologists promoted smoking, even when the evidence against them was damning and incontrovertable, because more smoking made them more money.
Carbon dioxide emitters and their paid apologists promote unrestricted carbon emissions, even when the climate change evidence against them is damning and incontrovertable, because emitting more carbon makes them more money.
Corporations hate, by their very nature, by their DNA, any activity that does not transfer money from the public to corporations. If they could charge us for thinking and breathing, they would.
Internet voting is not about getting more VOTERS it's about getting more MONEY from the government to voting technology CORPORATIONS.
Corporations that, as I have already noted, may have an interest in the outcome of the voting. Let's imagine that one party said they would eliminate the legal fiction of corporations as a person if elected, and the other would increase the rights of corporations and lower corporate taxes.
Now tell me, are you going to trust the corporate designed and run voting system to decide the outcome of that election?
But you don't even need to go to that extent.
Paying people to SAY stuff is much cheaper than paying people to DO stuff well.
How do I maximize profits at my corporation?
Make the cheapest, most quickly and half-assedly programmed system possible.
Don't pay to test it.
Don't pay security experts to evaluate it.
Don't bother with secure design at all.
Computer security COSTS MONEY.
Good computer security costs A LOT of money.
Corporations HATE SPENDING MONEY.
Instead, just pay some people to go out and say "hey, look at this wonderful system, it's improving your quality of life. It's yet another modern convenience, like the washing machine and refrigerator. It's all about serving you, the customer."
Who are you going to trust on electronic voting?
Paid corporate advocates?
Or neutral observers, with no financial incentive, who are trained security experts.
I am a trained computer security expert.
I make zero dollars from anyone for opposing electronic voting.
In fact, it costs me greatly in my own time to oppose it.
The reason I oppose it is that history teaches us that the integrity of our voting systems is always at risk. We have a good, cheap, transparent voting system.
To destroy that would be folly.
Everything in life is not a financial transaction, with a service provider and a client. Voting is not electronic banking, it's not paying your taxes, it's not selecting the latest reality show contestants online, it's not online gambling.
Voting translates voter INTENT into voter CONSENSUS through TRUST.
It's a civic duty. It's a free interaction between citizens and the society as a whole.
Internet voting undermines that trust.
There is no way to do secure, anonymous, independent Internet voting.
It. Is. Impossible.
To compromise a paper election, I must either compromise the ballots, the local counting, or the total tally. People understand security in the physical world extremely well. Any citizen (for that matter, any child) can understand the current paper-based voting system, and could explain to you clearly the small number of ways in which it could be compromised, and how to mitigate against those risks.
To compromise an Internet election, the easiest thing is for me to compromise the voter. This may be in charming ways, like a bottle of hard liquor in exchange for your voting code. Or in less charming ways, like holding a gun to your head and watching you vote the way I want.
I can also attack:
- the home computer
- the home computer software
- the computer network
- the corporate voting software
- the corporate vote counting software
Most citizens have not the faintest idea of the security risks involved, nor do they have the skills to rationally assess the risks. Many citizens, in fact, do not even own a computer, and instead of being empowered by Internet voting, are instead further marginalized.
Wow, that's a boon for democracy, that is.
I have written thousands of words in this blog about the folly that is Internet voting. I may, on my own free time, go back and find some of those links, for those of you too afflicted with apathy to bother to do a search.
If someone who is an actual neutral computer security expert would like to debate this issue, I would be more than happy to do so.
PS When carrying your paid advocacy over to Wikipedia, at least respect the Wikipedia rules and syntax. Thanks.
Wednesday, November 15, 2006
Geist on e-voting
Democracy depends upon a fair, accurate, and transparent electoral process with outcomes that can be independently verified. Conventional voting accomplishes many of these goals - private polling stations enable citizens to cast their votes anonymously, election day scrutineers offer independent oversight, and paper-based ballots provide a verifiable outcome that can be re-counted if necessary.
While technology may someday allow us to replicate these essential features online, many of them are currently absent from Internet voting, which is subject to any number of possible disruptions, including denial of service attacks that shut down the election process, hacks into the election system, or the insertion of computer viruses that tamper with election results.
Electronic voting machines are similarly prone to error. Last year the City of Montreal implemented an electronic voting system that was later characterized as a "debacle" with delays, equipment malfunctions, and erroneous results. The City acknowledged that some of the electronic voting machines were "lemons" - voting too quickly caused the machines to breakdown, while 45,000 ballots were counted twice (an error corrected before the results were announced).
Both Internet and electronic voting are also unable to guarantee independent verification. Unlike paper, electronic votes are subject to manipulation, placing enormous power in the hands of the electronic voting machine companies who must ensure tamper-free results.
Monday, November 13, 2006
Ontario municipal elections - Nov 13, 2006
I voted today in Ottawa, I believe the counting system is a Diebold Accuvote OS.
As I saw my ballot slide silently into the machine with its prominent "Accu Vote" logo, I thought about how these machines silently kill the humanity of the voting process.
Plus which, you get this flimsy paper "voting shield", which they still have to open up in case your ballot is upside down (in which case, they see who you voted for), or backwards (apparently the genius counting machine can't handle backwards ballots).
The whole thing makes you feel like voting is a slipshod yet automated process, neither of which should be the impression left with citizens.
I encourage you to vote today, if applicable.
If you don't like voting on these machines, the first step is to contact your city councilor and mayor, and make them aware of your displeasure, and also of the costs associated with voting machines.
I am also happy to re-print any experiences (positive or negative) you have had with voting machines today. Just send me an email and include a line to the effect of "you have my permission to reprint this report in your blog".
On a side note, I saw with dismay that TD Bank's exciting new ATM's are made by... Diebold. Oh great, now they're handling my money too.
