<$BlogRSDURL$>

Friday, October 03, 2008

Homer vs. the voting machine

My friend Jessie sent me a link to this awesome clip of Homer trying to vote for Obama

Labels: , , , ,

electronic voting means trusting a stranger with your vote

I just completed a radio interview for CBC Radio Spark, about Internet voting specifically. I think it will air next week - and I think they will only use short excerpts from the interview, but I have asked for the entire thing to be posted online.

UPDATE: I should check my stats for this blog more often - I see that there is an item specifically about this in the Spark blog

Would you vote over the internet in a Canadian federal election?
- Posted by Dan Misener on October 01 [2008]

There are some good comments on the blog posting.

ENDUPDATE

I think I conveyed my three major points:
* a key element of the voting system is trust
* a voting machine (or Internet voting) is no different than telling your vote to a stranger
* a computer can lie

Or in other words, electronic voting means that in a system based on trust, you're giving your vote to a stranger who can lie.

There is one thing I regret saying, I said something like "not everyone is a computer scientist or a mathematician, the average Canadian can't comprehend web voting" - my actual intent was something more like "the average Canadian doesn't have the technical training to understand exactly how web voting works and all the associated risks".

I did then wrap up with what I think was a strong point: Internet/web/electronic voting introduces uncertainty and complexity into what should be the most certain and least complex process in our democracy.

If you look at the specific example of the Referendum, which was so incredibly close - imagine what would have happened if the next day people had started saying "I think my computer didn't record my vote correctly" - we'd never be able to resolve it - we'd still be arguing about it.

Speech! Speech!



If I was giving this as a prepared presentation (which is more my area of communication strength), rather than as an interview, it would go something like...

Voting is about policies, but also about trust. In yesterday's leaders debate, we saw five people around a table that most of us will never meet, five strangers. We have to determine, in part, whether we trust them. Similarly most of us only talk to our MPs for a few minutes when they show up at the door before the election; they are also strangers.

It's quite a remarkable transfer of trust, from millions of people to a few hundred, transferring the authority to declare war and to spend billions of taxpayer dollars.

The process to transfer this trust is voting, which also involves trusting strangers - you probably don't know the poll workers or the scrutineers.

But the good news is that in the physical world, we are really good at reasoning about how to manage the risks of trusting strangers. If a stranger asks for directions on the street, you will probably help them, but if they ask for a $100 loan and your name and address and promise to return the money to you later, you probably won't help them.

Our existing paper-based, human-counted system is based on our understanding of the balancing of motivations and self-interest, along with a clear physical evidence chain. You mark the ballot yourself in secret, you drop it in the box in front of everyone, and you trust that the competing interests of the scrutineers from the different parties will ensure that the open counting of the paper ballots is done properly.

If there's an issue, you can just count the ballots again.

And you know that if something does go wrong, all of those people live in your community and have to deal with the consequences.

You literally could have an elementary school class run a classic Canadian Federal election scenario and they could identify all of the possible risks, because reasoning about physical evidence and human behavior is one of our strengths.

Now imagine instead that when you walk into the polling station, they say to you "for improved efficiency, just tell this stranger how you want to vote, and he will go and handle the rest". So you tell him "I want to vote for the red party" and he goes and marks a ballot in secret and drops it in the ballot box. Now you have to trust that stranger totally. You can ask him, "did you vote for red?" and he can assure you over and over, but you can never actually know, for certain, how he voted on your behalf.

In effect, his report of your vote is now testimony, or even hearsay.
We understand this quite well in our criminal justice system. Physical evidence (e.g. a marked ballot that you can see) has the highest degree of credibility. Testimony much less so, because humans can lie. Hearsay least of all, because humans can really lie a lot about other people.

You go from e.g. seeing an X in a circle on a piece of paper, to having someone say "I definitely marked an X by the red candidate", to someone saying "I think I thought I saw someone mark an X by the red candidate".

So now we just need to replace one step and I think you'll see the problem: replace "tell your vote to a stranger" to "enter a your vote on a computer".

How is that like telling a stranger? Well when you think about it, computers don't program themselves. Every computer program, and even every computer chip, was designed by someone - by a stranger. Actually by many many strangers. The computer is not some cold objective logic machine, incapable of error, the computer is the embodiment of the human intentions that went into its code and hardware - the computer is a human, in silico.

That means all of the things a person can do, a computer might do - a computer might fail, because of an error, or a computer might behave maliciously, because of malicious intent.

That is to say, the computer can lie. We often don't think about this, because for commercial reasons most people write code intended to behave well and to present information correctly. But there's no reason your code can't say

get input
if input = "vote blue" then
record +1 blue vote
display "voted for blue"
else if input = "vote red" then
record +1 blue vote
display "voted for red"
end

THE COMPUTER CAN LIE.

You can see very real examples of this in sophisticated virus social engineering - the virus presents a window that says "you need to update your antivirus software immediately [ok] [cancel]" and when you press [ok], it actually fills you computer with viruses.

Beyond that, even without malicious intent, the computer can fail in a million bazillion ways - bugs in the code, hardware error, network error, power failure, overloaded by too much network traffic (as happened with Do Not Call List), and on and on. Whereas a paper voting system can continue without power, and short of burning the paper or killing the people, it has limited ways that it can fail.

And this is an important point: people already attack physical voting systems, which is very high risk. (See e.g. Zimbabwe.) The reason they take this risk is the rewards are enormous - wealth beyond any other criminal scheme, power, privilege...

Consider that spammers have already constructed networks of hijacked machines ("botnets") - millions of machines in some cases - just to take advantage of the few thousand or at most few million dollars they can earn by ripping people off. Now just think - if there's Internet voting they can use the exact same technology to control who gets access to BILLIONS OF DOLLARS.

So think about it - you would never vote by telling a stranger your intent and letting them vote for you - why would you vote by telling a strange machine your intent and letting it vote for you?

Labels: , , , ,

Tuesday, September 30, 2008

Elections Canada and the Very Bad Online Idea

I've written here before about the false idea that if we make voting "convenient" by enabling online voting, it will increase turnout.

If you want to increase turnout, have a campaign to increase turnout.
Have ballot boxes at workplaces, or make the entire day a holiday.
There are lots and lots of ways to increase turnout.

Supporting Internet voting is asking for catastrophe in many different ways:
* it turns the solemn act of voting, one of the few acts of citizenship, into something no different than adding an item to your Amazon.ca shopping cart
* it means that you're using inherently unsafe, unsecured machines to provide the infrastructure for the most critical process of our democracy
* it means that someone can stand with a gun to my head and force me to vote the way they want while they watch (which, incidentally, also applies to voting by mail)

If you seriously think online voting will engage "the youth", then why not just go all the way and let them vote on their cellphones and called it "Greatest Canadian Idol"? (The sad part is that their cellphones are almost all much more secure than their computers.)

Here's what prompts this latest concern:

Elections Canada hopes it has the answers.

The federal agency has adopted a five-year strategy to boost turnout, with a focus on youth engagement.

Key planks in the plan are to communicate more frequently with voters between elections, via education programs, and to make voting more accessible to all Canadians.

Elections Canada is hoping to adopt online voter registration in two years, a tool already available in some provinces like Alberta.

Perhaps more importantly, the agency hopes to test web voting within five years, beginning with a byelection.

"The general philosophy is to take the ballot box to the voter," says Mayrand, Canada's chief electoral officer.

If the Internet gamble proves successful and security concerns can be addressed, Elections Canada would ask Parliament to amend legislation to include e-voting for general elections.

"Youth are quite familiar with technology. They expect to be able to use it for most of their life activities," Mayrand adds.

Black Mark - Calgary Herald - September 6, 2008

The problem being, voting is not like "most of their life activities".
Voting is not banking, voting is not surfing the net, voting is not listening to music, voting is not texting a friend.

Banking is an example that is often used, or online taxes, but these are completely false examples. The bank knows exactly how much money you have, as does the government, and every transaction has an audit trail and can be reversed.

Voting must not have an audit trail, and cannot be reversed (if you are going to retain a system of private, secret ballots).

Voting, since it provides the transfer of power from the very many to the very few, is a very attractive attack point for malicious actors, and I mean "attack point" quite literally - people die for their vote already today, can you imagine how much more tempting for all of the negative forces in our society to take advantage of the vast computer networks that already exist for spam and attacks ("botnets") and use them to throw the election or to write a targetted virus to compromise the election?

That's not even to touch the issues of just running the election assuming everything actually goes right. The Do Not Call List site just went down because of high demand after it was launched. The Tax servers routinely get overloaded when millions of Canadians use the online systems near filing day. That's not a problem, because those transactions are repeatable.

What happens when the election servers go down from heavy demand on election day?
People resubmit their vote? We have the vote again another day?

A human-run, human-counted paper voting system has a very small number of failure modes, all of which anyone who understands the physical world can easily work out (people can steal the ballot boxes, etc.)

Computer-run, computer-counted voting systems have almost unlimited failure modes, which almost no one except computer and network security experts can fathom.

A paper voting system must work during the voting, and during the counting, and then it just disappears.

An electronic voting system requires servers that must be secured both physically and electronically 365 days of the year, every year, in case a vote is called.

The whole idea that you would get any benefits from online voting is patently ridiculous. The only way you can make it appear to work is to ignore all of the security issues, ignore all of the ongoing cost issues, treat it as if it were a banking or other repeatable and auditable transaction, as if voting is something that should somehow be made "efficient", and make a bunch of claims about turnout.

It is a Very Bad Idea.

Previously:
November 28, 2006 let's have a discussion
November 15, 2006 Geist on e-voting

Labels: , ,

Thursday, August 21, 2008

Lou Dobbs - private companies running voting


DOBBS: For more than two years here, we've been reporting on the serious threat that electronic voting poses to this democracy. As a result, some states have begun to scrap their e-voting machines altogether. But a third of the nation will still be using e-voting machines in November. And more disturbing a new report says election officials often are outsourcing their responsibilities to the very companies that make the e-voting machines, even trusting those companies to count the votes. Kitty Pilgrim has our report.

(BEGIN VIDEOTAPE)

KITTY PILGRIM, CNN CORRESPONDENT (voice-over): Ellen Theisen has been a software writer for more than two decades. Living in Washington State, she was disturbed by electronic voting problems across the country, so she formed a nonpartisan citizen's activist group to investigate voting irregularities. A new report by that organization, VotersUnite.org, says that private companies now run many elections.

ELLEN THEISEN, VOTERSUNITE.ORG: Elections should be accountable to the people and run by public officials who are selected by the people to run them. So when that's handed over to private vendors, these public elections are no longer public.

PILGRIM: According to the report, many jurisdictions in the country are entirely dependent on the voting machine companies. The companies also tabulate results. State officials have to take their word for the results. The company owns the software and equipment and doesn't have to share it. It's proprietary. Election officials often can't do a recount without help. One state that rejected that arrangement is Oklahoma. In 1992, Oklahoma put in its own optical scan system, which is still owned and operated by the state.

MICHAEL CLINGMAN, OKLAHOMA STATE ELECTION BOARD: Election night, it's really all public officials dealing with the election and nobody else.

PILGRIM: Oklahoma wasn't tempted by new federal funds in 2002 when many other state and local governments used the Help America Vote Act money to buy touch screen machines.

UNIDENTIFIED MALE: There was really nothing on the market we would buy then and there's still nothing we would want to buy today.

Lou Dobbs Tonight - August 20, 2008

Labels: ,

Saturday, January 12, 2008

Olbermann - Man vs. Machine

Rep. Rush Holt

Anything of value should be auditable. ...

To give voters the confidence that they deserve that their votes will be counted as they intended... in every election there should be an audit.

See the full interview



Countdown with Keith Olbermann - #4 Man vs. Machine

via Black Box Voting forum

Labels: ,

e-voting was a bad idea and is reaping the whirlwind

The basic premise of e-voting went something like this:

1) Electronics makes things "efficient" and will save money.
2) Elections are a government service just like any other.

Underlying this was an extraordinarily naive concept of elections as uncontroversial events that would never be challenged, and that no one would ever make a serious attempt to commit election fraud. There would never be close races. In essence, a disdain for the whole voting process, because it implies that a single vote will never make a difference.

This is simply demonstrably untrue, as elections with contested results have been a worldwide problem, with accusations flying, often with violent repercussions. Time and time again we have seen incredibly close elections.

The reality is: the more complicated and indirect you make the voting process and the vote counting process, the more you open the system to suspicions of fraud, and associated loss of confidence in the results of the election.

As I've said before, voting is an incredible act of civic alchemy, in which the will of the many is transmuted into tremendous power for a very few (e.g. in the US, a few hundred people leading a nation of 300 million). WITHOUT COMPLETE CONFIDENCE, this cannot work; a million people are not going to hand over power to a single politician unless they are confident s/he was actually selected by a fair vote.

In a partisan environment with close-fought elections, this means that now

EVERY SINGLE ELECTION WILL BE CHALLENGED


Oh, brilliant cost savings there, you idiot technocrats. Instead of pen and paper and election results in hours with full confidence of the electorate, elections will now turn into endless recounts, court challenges, and code examinations. Since it is almost impossible to prove that machines weren't hacked, any case where there is not a full paper trail will end up basically unresolvable.

Hand counted paper ballots were never broken,
the only way to fix this problem is to go back to them.

New Hampshire is lucky they have optical scan (the least-worst of the electronic options) so that confidence can be restored by a manual recount.

For a taste of what's to come, see ArsTechnica - Analysis: Why the "Hillary hacked NH?" story is important (Updated)

Labels: , , ,

Thursday, October 25, 2007

minor site note: added feedflare

Added FeedFlare, which provides some additional capabilities for emailing and bookmarking within each post.

UPDATE: Minor template change to adjust FeedFlare.

Labels:

Saturday, April 07, 2007

electronic voting machines explained



From The Daily Show, November 2, 2006

Thursday, January 25, 2007

new blogger

This blog has just moved to the new blogger, so some things may break.

Labels:

Tuesday, December 19, 2006

why postal ballots also suck

1. Procedures are more complicated than in-person voting
2. No immediate feedback / oversight if there are problems with the ballots
3. People screw up and put their signed declarations in the same envelope as their vote, thus a) spoiling their ballot and/or b) revealing who they voted for

Globe and Mail - Postal-ballot errors spark review - December 19, 2006
Municipal Affairs and Housing Minister John Gerretsen says he's considering revisions to Ontario's municipal elections law as towns and townships continue to struggle through counts of problem-plagued mail-in balloting in the Nov. 13 vote.

...

This week, judges in Bracebridge and Lindsay ordered that efforts be made to count ballots that had been determined spoiled by clerks in four Ontario municipalities because no signed declaration was enclosed.

Although some other municipalities faced with high postal-ballot rejection rates -- generally about 20 per cent -- instituted procedures before election day to try to salvage the votes, that option was refused by Lake of Bays Township in Muskoka, the City of Kawartha Lakes and the townships of Highlands East and Minden Hills.

Minden Hills is the only municipality so far where the added votes have made a difference. Out of 849 rejected ballots, 256 votes were found with a signed declaration improperly inserted inside the secrecy envelope and the vote was allowed.

As a result, challenger Lisa Schell saw her 11-vote loss to Clayton Cameron reversed to give her a one-vote majority.

Saturday, December 02, 2006

US NIST recommends scanned paper ballots

Slashdot reports

"Paperless electronic voting machines 'cannot be made secure' [pdf] according to the [US] National Institute of Standards and Technology (NIST). In the most sweeping condemnation of voting machines issued by any federal agency, NIST echoes what critics have been saying all along, that due to the lack of verifiability, 'a single programmer could rig a major election.' Rather than adding printers, though, NIST endorses the hand-marked optical-scan system as the most reliable."

(in case you're wondering, Internet voting counts as a "paperless e-voting machine")

I wonder how many experts have to say that electronic voting sucks before people will listen.

Of course, crazed luddite that I am, I would eliminate the machine-based counting as well, and just have humans count the paper.

Slashdot - NIST Condemns Paperless Electronic Voting - December 1, 2006 /.

Tuesday, November 28, 2006

let's have a discussion

Adam asserts that I have
a very disturbing and one sided perspective

But Adam, you haven't responded to a single issue that I raised.

I welcome all perspectives, provided they are fact-based.

In particular, I invite realistic threat-risk assessments, cost assessments, and cultural assessments.

Let us take Internet voting.

1. Is the code open-source?
2. Has the code been audited by neutral computer security experts?
3. Where are the servers?
4. How are the servers protected?
5. Has the server security been audited by neutral computer security experts?
6. Who pays to protect the servers and the code for the thousands of days during which they are not being used for municipal elections?
7. Who wrote the code?
8. Have they all passed an independent security certification?
9. Do they have ties to any particular political party or other organization that might have an interest in the outcome of the election?
10. How do you mitigate the risk of paying or forcing someone to vote in the way you want, as you watch them on the Internet?
11. How do you mitigate the risk of the massively insecure home computers that are used for Internet voting?
12. When the full costs of security audits and thousands of days of security protection are taken into account, in order to provide a single day of municipal voting, how do you justify the expense?

There's a dozen questions. I have way more where those came from.
I challenge anyone to answer.

Friday, November 24, 2006

corporate voting bullshit

From a comment on my previous posting

You need to recognize that municipalities such as Markham are no less concerned about the integrity of the voting process, they simply live in the real world and recognize that offering Internet voting is clearly a solution for voter apathy.

Adam Froman
President
Delvinia Interactive

Ah yes. The real world. The modern world. The practical, down-to-earth, realistic, Common Sense Revolution world. Paper is obsolete, so old-fashioned, like the Geneva Convention and other inconveniences.

Bullshit.

You want the real world?
The real world is run, to a very large extent, by corporations.
Corporations exist, their sole purpose is, BY LAW, to make money.
To make money, as constrained by the legal framework.
Corporations also must, under our system, continue to grow.
To grow endlessly.

There are only two ways for corporations to grow
1) By finding more ways to charge people more money for things
2) By changing the legal framework itself, to remove constraints on them making more money

A corporation is providing Internet voting in Markham not out of the goodness of its heart, not out of a passion for citizen involvement, but to make more money.

Delvinia is promoting the wonders of that Internet voting system because it was paid to.

Tobacco companies and their paid apologists promoted smoking, even when the evidence against them was damning and incontrovertable, because more smoking made them more money.

Carbon dioxide emitters and their paid apologists promote unrestricted carbon emissions, even when the climate change evidence against them is damning and incontrovertable, because emitting more carbon makes them more money.

Corporations hate, by their very nature, by their DNA, any activity that does not transfer money from the public to corporations. If they could charge us for thinking and breathing, they would.

Internet voting is not about getting more VOTERS it's about getting more MONEY from the government to voting technology CORPORATIONS.

Corporations that, as I have already noted, may have an interest in the outcome of the voting. Let's imagine that one party said they would eliminate the legal fiction of corporations as a person if elected, and the other would increase the rights of corporations and lower corporate taxes.

Now tell me, are you going to trust the corporate designed and run voting system to decide the outcome of that election?

But you don't even need to go to that extent.
Paying people to SAY stuff is much cheaper than paying people to DO stuff well.

How do I maximize profits at my corporation?
Make the cheapest, most quickly and half-assedly programmed system possible.
Don't pay to test it.
Don't pay security experts to evaluate it.
Don't bother with secure design at all.

Computer security COSTS MONEY.
Good computer security costs A LOT of money.
Corporations HATE SPENDING MONEY.

Instead, just pay some people to go out and say "hey, look at this wonderful system, it's improving your quality of life. It's yet another modern convenience, like the washing machine and refrigerator. It's all about serving you, the customer."

Who are you going to trust on electronic voting?
Paid corporate advocates?

Or neutral observers, with no financial incentive, who are trained security experts.

I am a trained computer security expert.
I make zero dollars from anyone for opposing electronic voting.
In fact, it costs me greatly in my own time to oppose it.

The reason I oppose it is that history teaches us that the integrity of our voting systems is always at risk. We have a good, cheap, transparent voting system.
To destroy that would be folly.

Everything in life is not a financial transaction, with a service provider and a client. Voting is not electronic banking, it's not paying your taxes, it's not selecting the latest reality show contestants online, it's not online gambling.

Voting translates voter INTENT into voter CONSENSUS through TRUST.
It's a civic duty. It's a free interaction between citizens and the society as a whole.

Internet voting undermines that trust.
There is no way to do secure, anonymous, independent Internet voting.
It. Is. Impossible.

To compromise a paper election, I must either compromise the ballots, the local counting, or the total tally. People understand security in the physical world extremely well. Any citizen (for that matter, any child) can understand the current paper-based voting system, and could explain to you clearly the small number of ways in which it could be compromised, and how to mitigate against those risks.

To compromise an Internet election, the easiest thing is for me to compromise the voter. This may be in charming ways, like a bottle of hard liquor in exchange for your voting code. Or in less charming ways, like holding a gun to your head and watching you vote the way I want.

I can also attack:
- the home computer
- the home computer software
- the computer network
- the corporate voting software
- the corporate vote counting software

Most citizens have not the faintest idea of the security risks involved, nor do they have the skills to rationally assess the risks. Many citizens, in fact, do not even own a computer, and instead of being empowered by Internet voting, are instead further marginalized.

Wow, that's a boon for democracy, that is.

I have written thousands of words in this blog about the folly that is Internet voting. I may, on my own free time, go back and find some of those links, for those of you too afflicted with apathy to bother to do a search.

If someone who is an actual neutral computer security expert would like to debate this issue, I would be more than happy to do so.

PS When carrying your paid advocacy over to Wikipedia, at least respect the Wikipedia rules and syntax. Thanks.

Wednesday, November 15, 2006

Geist on e-voting

The ubiquitous Michael Geist had a good article last month, Time To Cast A Vote Against E-Voting

Democracy depends upon a fair, accurate, and transparent electoral process with outcomes that can be independently verified. Conventional voting accomplishes many of these goals - private polling stations enable citizens to cast their votes anonymously, election day scrutineers offer independent oversight, and paper-based ballots provide a verifiable outcome that can be re-counted if necessary.

While technology may someday allow us to replicate these essential features online, many of them are currently absent from Internet voting, which is subject to any number of possible disruptions, including denial of service attacks that shut down the election process, hacks into the election system, or the insertion of computer viruses that tamper with election results.

Electronic voting machines are similarly prone to error. Last year the City of Montreal implemented an electronic voting system that was later characterized as a "debacle" with delays, equipment malfunctions, and erroneous results. The City acknowledged that some of the electronic voting machines were "lemons" - voting too quickly caused the machines to breakdown, while 45,000 ballots were counted twice (an error corrected before the results were announced).

Both Internet and electronic voting are also unable to guarantee independent verification. Unlike paper, electronic votes are subject to manipulation, placing enormous power in the hands of the electronic voting machine companies who must ensure tamper-free results.

Monday, November 13, 2006

Ontario municipal elections - Nov 13, 2006

For general information about this event see Wikipedia - Ontario municipal elections, 2006.

I voted today in Ottawa, I believe the counting system is a Diebold Accuvote OS.

As I saw my ballot slide silently into the machine with its prominent "Accu Vote" logo, I thought about how these machines silently kill the humanity of the voting process.

Plus which, you get this flimsy paper "voting shield", which they still have to open up in case your ballot is upside down (in which case, they see who you voted for), or backwards (apparently the genius counting machine can't handle backwards ballots).
The whole thing makes you feel like voting is a slipshod yet automated process, neither of which should be the impression left with citizens.

I encourage you to vote today, if applicable.
If you don't like voting on these machines, the first step is to contact your city councilor and mayor, and make them aware of your displeasure, and also of the costs associated with voting machines.

I am also happy to re-print any experiences (positive or negative) you have had with voting machines today. Just send me an email and include a line to the effect of "you have my permission to reprint this report in your blog".

On a side note, I saw with dismay that TD Bank's exciting new ATM's are made by... Diebold. Oh great, now they're handling my money too.

Thursday, November 09, 2006

City of Ottawa voting machines unhackable?

The recent voting machine controversies/disasters in the US (and Quebec) have, finally, woken Canadians up to the potential problems from the use of electronic vote counting machines.

The response from government and thought leaders is, as far as I can tell "don't worry, can't happen here, completely different, hey, look, is that a pony?"

a computer is a computer is a computer
Go take a computer science course and learn about Mr. Turing, if you don't understand that. Any computer can be hacked. You can change the software, you can alter the firmware, you can compromise the hardware. Plus which, you can't tell through external inspection whether a machine has been altered. Which means you need a perfect chain of custody for the machine, 24x7x365.

Now of course, auditing every single machine down to the assembly code level, and securing them in an e-voting machine Fort Knox for the thousands of days when they're NOT being used, just to ensure that they work for about 12 hours on one day, would be enormously, prohibitively expensive. This would also be the actual cost of voting machines.

But that would interfere with the bulls--t about voting machines being modern and efficient and cost-saving. So no one actually does it. At best, some machines are sort of checked by someone, and we sort of trust the people who are handling them on election day, and then they go to some warehouse somewhere and we forget about them.

With that in mind, read the incorrectly cheerful Ottawa Citizen editorial comment City of Ottawa Technology gets my vote, November 6, 2006, page A14 (not available online)

David Reevely, The Ottawa Citizen

Sometimes the old ways are the best, and that's never been truer about anything than it is about voting.

Tick a paper ballot, drop it in a box, wait for it to be counted. Simple. It's worked for as long as we've had democracies. Efforts to update it have largely been failures.

Correct.

Under its old name [Global Election Systems, now part of Diebold], the company made the machines that Ottawa uses to count ballots in municipal elections. Ottawa's elections manager Shane Kennedy, who has overseen civic elections since 1994, is on his third using a tabulator called the Accu-Vote OS.

"We've used the same equipment all that time and it's been entirely successful," Kennedy says.

The machine looks a little like a fax: you slide your ballot in and it gets scanned and counted and spat out again. When the polls close, results are available in minutes, not the hours it used to take to count several hundred thousand pieces of paper. For the candidates, one way or the other, the drinking can begin immediately.

Although they're from the same manufacturer, Ottawa's machines bear none of the weaknesses the American critics point out.

"The hacking relates to touch-screen technology, primarily," Kennedy says in defence of Ottawa's machines. "It's a totally different animal."

None of the weaknesses? NONE OF THE WEAKNESSES? Wrong.
Did I mention that any system running computer code can be hacked?
Maybe not as easily as the crappy Windows touch-screens, but it's still possible.

Quebec's director-general of elections, Marcel Blanchet, examined Diebold's ES 2000, an updated version of the machines Ottawa uses, when he reviewed the province's municipal elections last year. Those elections saw an unprecedented deployment of e-voting machines across Quebec, and an unprecedented number of problems with them.

Things weren't bad enough to nullify any elections, Blanchet concluded, but he still advised that Quebec's cities stop using e-voting machines at least until the province sets standards of accuracy and security.

This is almost certainly overkill, especially for the simple tabulating machines. They need electricity and memory chips and they can jam, which ballot boxes don't, but other than that they're just fancy counting machines -- they don't replace the ballot itself, as touch-screen machines do.

Oh I see, they're just "simple tabulating machines". Sure, they have memory chips, but they're just "fancy counting machines".

FANCY COUNTING MACHINES?
What the f--k do you think a computer is?

If they're so simple, why not have humans count the votes? Why do we need simple technology to replace humans? But wait, they're fancy? If they're so complicated, aren't they vulnerable?

Machines have gears and levers and you have to be a mechanical engineer to compromise them, if you can alter their behavior at all. COMPUTERS have code. Any code can be changed.

In Ottawa's elections, the machines sit on tables out in the open, guarded by clerks and scrutineers. Before the machines could be hacked all the overseers would have to go bad together, and if that happened, the technology would be the least of our problems.

Another criticism of Diebold's touch-screen machines is that they don't make a paper trail. The only record that a voter has been in the booth is in the ephemeral form of electrons on a microchip: if somebody did crack open a machine and go to work on it, there'd be no other record to check the machine's results against. In Ottawa, Kennedy's returning officers at each poll keep the ballots in traditional boxes. If every tabulator failed, each ballot could still be counted by hand.

So, they machines are out in the open... during election day. And the other THOUSANDS OF DAYS they are unused? Where are they exactly? Are there clerks and scrutineers and overseers watching them, 24x7x365?

If every tabulator failed?
And how, exactly, are we going to know if the tabulator failed?
Will there be a flashing red light indicating "tabulator now failing to count ballots correctly"?

No. In fact, these "simple machines" betray no evidence of their internal workings.

Their only, ONLY saving merit is that IF YOU CHALLENGED THE COUNT, you could count the paper.

But if counting the paper is the last word in confidence, then

JUST USE PAPER AND HAND COUNT

But wait, there's more
CFRA - City Defends Voting System - November 8, 2006

The City of Ottawa insists the electronic voting system for Monday's Municipal Election is safe.

Ottawa's Elections Office has issued a memo to all councillors and candidates after a recent documentary into the electronic tabulation system used in the United States.

The HBO documentary raises the possibility that an election system could be accessed with intent to alter the outcome of the vote tabulation.

The City Clerk says Ottawa's preparations for the municipal election by electronic vote have met the standards imposed by an independent third party auditor in the past and those standards are in place for this year's election.

The clerk adds security standards put in place by the municipal election administration make it impossible to hack into the system to access memory cards.

1. What standards? What auditor? Who decided the auditor was qualified and trustworthy? For this election? What about previous ones?
2. "impossible to hack"? hahah ahahahahahahaaha

I challenge the City of Ottawa to invite teams of actual computer security experts, using actual computer security standards, to openly do a threat-risk assessment on the voting system. I can guarantee it is not "impossible to hack".

Plus which, an auditor is a lot of extra expense, then re-assuring citizens reduces confidence in the elections, gee, this is a lot of hassle and money.

You know what would be cheaper and easier?

JUST USE HAND-COUNTED PAPER

I will be writing to both the Ottawa Citizen, CFRA and to my city councilor (before and after the election).

Wednesday, November 08, 2006

close races and recounts

The electronic voting perspective on recounts seems to be
1) they will be easy
2) (perhaps) they happen rarely

But what's important recounts is not how quickly they happen (in fact, "speed" is an odd thing to make paramount in vote counting). What is important is how confident the people are in the result.

Anyone can understand a paper ballot recount, and the routes for challenge are quite limited. This is important, because elections ultimately transfer power from many people, to one. There are over 400 House seats in the US, and about 300 million citizens. That's a huge transfer of power, from hundreds of millions, to hundreds.

The routes of challenge for electronic vote counts are almost limitless.
You could challenge:
1) the manufacturer
2) the programmers
3) the software
4) individual machines
5) the people managing the machines on voting day
6) voters - potential hacking by individual voters
7) chain of custody on the machines or the memory cards

And probably more I haven't though of.
And even worse, many of those challenges are almost impossible to resolve.

This is bad, because close elections requiring recounts actually happen ALL THE TIME.

Tuesday, November 07, 2006

e-voting debacle

Gosh, if only this could have been predicted.
Oh wait, everyone who understands e-voting did predict this.

After warnings that electronic voting could cause trouble in Tuesday's U.S. elections, there are signs of "what now appears to be a growing debacle," the CBC's Henry Champ reports from Washington.

By mid-afternoon, officials in at least three jurisdictions — Denver, Colo., Muncie, Ind., and Davidson County, Tenn. — were asking federal judges for extended voting hours because, they said, voting machines in their areas have not functioned and they cannot handle the numbers of voters at the polls without more time.

Seventy-five precincts in Indiana — considered a bellwether state — failed to open on schedule because machines malfunctioned. In Cleveland, where there were problems with new machines in September's party primaries, things seemed no better.

"Again the same problem," Champ said. "Machines and machine supervisors unable to get the operations underway. Voters piling up in the doorways."

CBC News - Electronic voting shapes up as election debacle - November 7, 2006

comparing voting methods

DailyKos has a story Vote by mail is the answer.

Umm.
Here's my opinion.

* Internet voting - so many things wrong with this I can't even begin.
* Electronic touchscreen - the absolute worst in-person voting. You have no idea what was recorded for your vote, and neither does anyone else.
* Scanned paper ballot - this is the least-worst electronic option, only because in the event of complaint, the paper could be counted. It still suffers from the other electronic flaws - malicious or accidental error could alter the vote counts. Also if the ballots are stacked one-by-one as they're scanned, you could in theory figure out who voted for whom.

* Vote by mail and Internet voting actually share common flaws:
1) No more secret ballot. Anyone can watch you vote. If they like, they can threaten you until you vote how they want.
2) Weak authentication. Someone got a voting code or ballot and voted. Maybe it was you. Maybe it wasn't.
3) Less connection with the vote gathering, chain-of-custody and counting process. Your votes go somewhere, and are counted by someone. Are they organized? Supervised? You don't get to see, unless you specifically make the effort, and probably you don't get to watch the chain-of-custody, only the final count. Any time chain-of-custody is interrupted, there is potential for fraud - in fact, that's how they tried to steal the paper-ballot, hand-counted Presidential election on Battlestar Galactica.

* Vote using paper secret ballot in public, with hand-count afterwards.
The public secret ballot is actually a remarkably well-tuned voting system.
I can't think of any that is better. No one knows how you vote. Chain of custody is usually right in front of your eyes. Anyone can see the votes counted. A child can understand how the system works.

I have written lots more on this topic previously in this blog.

remember, paper is obsolete

Yet it seems to work when our mighty technology fails.

Programming errors and inexperience dealing with electronic voting machines frustrated poll workers in hundreds of precincts early Tuesday, delaying voters in Indiana, Ohio and Florida and leaving some with little choice but to use paper ballots instead.

In Cleveland, voters rolled their eyes as election workers fumbled with new touchscreen machines that they couldn't get to start properly until about 10 minutes after polls opened.

"We got five machines -- one of them's got to work," said Willette Scullank, a troubleshooter from the Cuyahoga County, Ohio, elections board.

In Indiana's Marion County, about 175 of 914 precincts turned to paper ballots because poll workers didn't know how to run the machines, said Marion County Clerk Doris Ann Sadler. She said it could take most of the day to fix all of the machine-related issues.

CNN - AP - Polling places turn to paper ballots after glitches - November 7, 2006

These places spent thousands of dollars on electronic voting machines, only to end up voting on paper anyway. You know what would be dramatically easier and cheaper?

JUST USE PAPER
<- Older Posts - Newer Posts ->

This page is powered by Blogger. Isn't yours?