Saturday, October 11, 2008
The Star on paper and electronic voting
"It's a very human system. It works," says Akerman, 40, an Ottawa technology planner and security expert. "You mark your ballot in private, but it's in a public setting. And it balances interests. You have scrutineers from different parties watching each other. It's hands on, easy to understand."
The ballot question: Paper or not? - The Toronto Star - October 11, 2008 - by Leslie Scrivener
Previously:
The Star had a very good article about the electronic voting issue in 2004, but unfortunately it doesn't seem to be online anymore, I wrote about it at
July 13, 2004 Is the future in line or online? - Toronto Star - published July 12, 2004
Labels: canada, electronic voting, newspaper
Friday, October 10, 2008
Spark plug

That reminds me I should put up some info about voting places and election results on the 13th, since I usually get a pile of hits on election day.
UPDATE: In case you're wondering, most of the hits are people searching for general voting/election information (where to vote, how to vote), not about the specific issue of electronic voting in Canada.
Labels: meta
Wednesday, October 08, 2008
the security stuff problem
Here's the problem: lots of people have tried to create secure systems for a long time, and have failed miserably.
I don't have to get technical at all, I can just talk in the consumer space.
1. For years, games companies put elaborate efforts and skilled people into trying to protect their games from piracy. They had special codes, special floppy disks with holes punched into the magnetic media or deliberate errors, physical dongles, you name it.
And yet their games were always pirated. Eventually most of them just gave up on protecting their games.
2. For years, continuing today, media companies like the record and movie industry have attempted to protect their content from piracy with Digital Rights Management (DRM). They have sophisticated hardware, elaborate codes, highly skilled people and a large monetary incentive. And they have failed.
iTunes music DRM? There's a hack.
DVD DRM? There's a hack.
3. Apple has an incentive to protect its iPhone from being used on any network, as it has an exclusive deal with AT&T. Their phone is "locked".
iPhone locking? There's a hack
THERE IS ALWAYS A HACK.
Because any piece of software or hardware you can create, I can put a layer in front of. Your software talks to a hardware dongle? I write a layer of software that pretends to be the hardware.
And we're not talking big power or political incentives here, we're talking smart kids (mostly) who wanted to play some games, listen to some music, or watch some movies.
So if they couldn't even protect SONGS, do you seriously think they're going to be able to protect AN ENTIRE ELECTION?
There is no unbreakable "security stuff" to do that, it simply doesn't exist.
And even if it did, the incredible complexity of it would mean that the entire election would boil down to "trust the machine and the computer guys".
Wouldn't you rather trust a piece of paper you can see, a counting system so simple elementary school students could perform it, and volunteers and scrutineers from your own neighbourhood that you can watch?
Labels: security
HRM e-voting success...fully eliminates the secret ballot
There were e-voters in more than 30 countries, with the oldest born in 1913, they said.
"We had people vote from Sri Lanka, from Korea, from over 50 Canadian cities and 25 American states," said Cathy Mellett, e-voting project manager for the Halifax Regional Municipality.
10% of HRM voters cast e-ballots (via Carol) and 28,709 cast municipal e-votes (via sparkcbc Twitter)
Hmm, so let's see. You assign a PIN number to each citizen, and mail the PIN to their address, and the verification info is their birth year, AND you're tracking their voting location, which can only be done by tracking their IP address, which semi-uniquely identifies their computer.
So you know who they are multiple times over, through the combination of PIN, birth year, mailing address, and IP address.
So number one, goodbye secret ballot.
Are you seriously going to take it on trust that they won't be tempted to check to find out who voted for whom? That no one will ever be tempted to check this?
Number two, in a world full of good people and lots and lots of bad people, from Nigerian scammers to Russian mafia, letting people vote in a Halifax election from any computer anywhere in the world is a feature? Are you kidding me?
Labels: halifax, hrm, internet voting
Tuesday, October 07, 2008
short piece on electronic voting on CBC Radio Spark
Dan talks to Ilona Dougherty, Richard Akerman, and Grace Lake about voting online
Episode 48 - October 8 & 11, 2008 - CBC Radio - Spark - posted October 07, 2008
The audio is available as an MP3 download, or you can subscribe to the podcast, or get it through iTunes.
Just a couple quotes from me were used, but I think I got my points across.
Labels: audio, canada, cbc radio, cbc radio spark, electronic voting
terminology
Internet voting = web voting = Using the Internet to record your vote on some central election servers.
Electronic voting machine (or I sometimes just say "voting machine") = any of a number of different technologies for voting, primarily about touch-screen voting machines, but I would extend it to mark-sense optical scanners as well, in its broadest sense.
Electronic voting encompasses both using electronic voting machines, and Internet voting (which you can think of as using an electronic voting machine, at a distance, over the net).
This is fairly consistent with the use at
http://en.wikipedia.org/wiki/Electronic_voting
Labels: electronic voting
more thoughts on electronic voting
This is what I just said in an email to a newspaper interviewer:
Ultimately it comes down to a choice between a very simple system in the physical world where we use a combination of privacy, being in public, and the competing interests of strangers (the scrutineers and election workers) to provide results based on physical evidence that everyone can agree upon,
or an incredibly complex system involving your computer, many computer networks, and computer servers, all running software created by strangers, with all the possibilities this raises for either malicious attacks on the election, or normal computer errors, a situation where there simply is no evidence to rely upon other than what the computer says, and the computer can lie.
In other words, electronic voting is no different than telling a stranger how you want to vote ("I want to vote for the blue party"), and then having to trust that they actually voted the way you asked, despite the fact you know that they can lie.
Can you imagine if we had used Internet voting for the last Quebec referendum? We would still be arguing about the results.
In short, although I love technology, I know the difference between appropriate technology and unnecessary technology.
Paper and pen is the appropriate technology for voting.
Labels: canada, electronic voting
Friday, October 03, 2008
paper voting isn't broken
If it ain't broke don't fix it - May 13, 2008
When officials come away from observing an electronic vote-counting system used in Monday's New Brunswick municipal election, I hope the lesson they take with them is this: Citizens do not need a machine to vote, nor to count those votes. And I hope for the health of our democracy that they will see that the application of technology to replace humans in this area is wholly inappropriate.
Labels: canada, electronic voting, new brunswick
Homer vs. the voting machine
Labels: electronic voting, simpsons, usa, video, voting machines
electronic voting means trusting a stranger with your vote
UPDATE: I should check my stats for this blog more often - I see that there is an item specifically about this in the Spark blog
Would you vote over the internet in a Canadian federal election? - Posted by Dan Misener on October 01 [2008]
There are some good comments on the blog posting.
ENDUPDATE
I think I conveyed my three major points:
* a key element of the voting system is trust
* a voting machine (or Internet voting) is no different than telling your vote to a stranger
* a computer can lie
Or in other words, electronic voting means that in a system based on trust, you're giving your vote to a stranger who can lie.
There is one thing I regret saying, I said something like "not everyone is a computer scientist or a mathematician, the average Canadian can't comprehend web voting" - my actual intent was something more like "the average Canadian doesn't have the technical training to understand exactly how web voting works and all the associated risks".
I did then wrap up with what I think was a strong point: Internet/web/electronic voting introduces uncertainty and complexity into what should be the most certain and least complex process in our democracy.
If you look at the specific example of the Referendum, which was so incredibly close - imagine what would have happened if the next day people had started saying "I think my computer didn't record my vote correctly" - we'd never be able to resolve it - we'd still be arguing about it.
Speech! Speech!
If I was giving this as a prepared presentation (which is more my area of communication strength), rather than as an interview, it would go something like...
Voting is about policies, but also about trust. In yesterday's leaders debate, we saw five people around a table that most of us will never meet, five strangers. We have to determine, in part, whether we trust them. Similarly most of us only talk to our MPs for a few minutes when they show up at the door before the election; they are also strangers.
It's quite a remarkable transfer of trust, from millions of people to a few hundred, transferring the authority to declare war and to spend billions of taxpayer dollars.
The process to transfer this trust is voting, which also involves trusting strangers - you probably don't know the poll workers or the scrutineers.
But the good news is that in the physical world, we are really good at reasoning about how to manage the risks of trusting strangers. If a stranger asks for directions on the street, you will probably help them, but if they ask for a $100 loan and your name and address and promise to return the money to you later, you probably won't help them.
Our existing paper-based, human-counted system is based on our understanding of the balancing of motivations and self-interest, along with a clear physical evidence chain. You mark the ballot yourself in secret, you drop it in the box in front of everyone, and you trust that the competing interests of the scrutineers from the different parties will ensure that the open counting of the paper ballots is done properly.
If there's an issue, you can just count the ballots again.
And you know that if something does go wrong, all of those people live in your community and have to deal with the consequences.
You literally could have an elementary school class run a classic Canadian Federal election scenario and they could identify all of the possible risks, because reasoning about physical evidence and human behavior is one of our strengths.
Now imagine instead that when you walk into the polling station, they say to you "for improved efficiency, just tell this stranger how you want to vote, and he will go and handle the rest". So you tell him "I want to vote for the red party" and he goes and marks a ballot in secret and drops it in the ballot box. Now you have to trust that stranger totally. You can ask him, "did you vote for red?" and he can assure you over and over, but you can never actually know, for certain, how he voted on your behalf.
In effect, his report of your vote is now testimony, or even hearsay.
We understand this quite well in our criminal justice system. Physical evidence (e.g. a marked ballot that you can see) has the highest degree of credibility. Testimony much less so, because humans can lie. Hearsay least of all, because humans can really lie a lot about other people.
You go from e.g. seeing an X in a circle on a piece of paper, to having someone say "I definitely marked an X by the red candidate", to someone saying "I think I thought I saw someone mark an X by the red candidate".
So now we just need to replace one step and I think you'll see the problem: replace "tell your vote to a stranger" to "enter a your vote on a computer".
How is that like telling a stranger? Well when you think about it, computers don't program themselves. Every computer program, and even every computer chip, was designed by someone - by a stranger. Actually by many many strangers. The computer is not some cold objective logic machine, incapable of error, the computer is the embodiment of the human intentions that went into its code and hardware - the computer is a human, in silico.
That means all of the things a person can do, a computer might do - a computer might fail, because of an error, or a computer might behave maliciously, because of malicious intent.
That is to say, the computer can lie. We often don't think about this, because for commercial reasons most people write code intended to behave well and to present information correctly. But there's no reason your code can't say
get input
if input = "vote blue" then
record +1 blue vote
display "voted for blue"
else if input = "vote red" then
record +1 blue vote
display "voted for red"
end
THE COMPUTER CAN LIE.
You can see very real examples of this in sophisticated virus social engineering - the virus presents a window that says "you need to update your antivirus software immediately [ok] [cancel]" and when you press [ok], it actually fills you computer with viruses.
Beyond that, even without malicious intent, the computer can fail in a million bazillion ways - bugs in the code, hardware error, network error, power failure, overloaded by too much network traffic (as happened with Do Not Call List), and on and on. Whereas a paper voting system can continue without power, and short of burning the paper or killing the people, it has limited ways that it can fail.
And this is an important point: people already attack physical voting systems, which is very high risk. (See e.g. Zimbabwe.) The reason they take this risk is the rewards are enormous - wealth beyond any other criminal scheme, power, privilege...
Consider that spammers have already constructed networks of hijacked machines ("botnets") - millions of machines in some cases - just to take advantage of the few thousand or at most few million dollars they can earn by ripping people off. Now just think - if there's Internet voting they can use the exact same technology to control who gets access to BILLIONS OF DOLLARS.
So think about it - you would never vote by telling a stranger your intent and letting them vote for you - why would you vote by telling a strange machine your intent and letting it vote for you?
Labels: canada, cbc radio, cbc radio spark, internet voting, radio
Tuesday, September 30, 2008
Elections Canada and the Very Bad Online Idea
If you want to increase turnout, have a campaign to increase turnout.
Have ballot boxes at workplaces, or make the entire day a holiday.
There are lots and lots of ways to increase turnout.
Supporting Internet voting is asking for catastrophe in many different ways:
* it turns the solemn act of voting, one of the few acts of citizenship, into something no different than adding an item to your Amazon.ca shopping cart
* it means that you're using inherently unsafe, unsecured machines to provide the infrastructure for the most critical process of our democracy
* it means that someone can stand with a gun to my head and force me to vote the way they want while they watch (which, incidentally, also applies to voting by mail)
If you seriously think online voting will engage "the youth", then why not just go all the way and let them vote on their cellphones and called it "Greatest Canadian Idol"? (The sad part is that their cellphones are almost all much more secure than their computers.)
Here's what prompts this latest concern:
Elections Canada hopes it has the answers.
The federal agency has adopted a five-year strategy to boost turnout, with a focus on youth engagement.
Key planks in the plan are to communicate more frequently with voters between elections, via education programs, and to make voting more accessible to all Canadians.
Elections Canada is hoping to adopt online voter registration in two years, a tool already available in some provinces like Alberta.
Perhaps more importantly, the agency hopes to test web voting within five years, beginning with a byelection.
"The general philosophy is to take the ballot box to the voter," says Mayrand, Canada's chief electoral officer.
If the Internet gamble proves successful and security concerns can be addressed, Elections Canada would ask Parliament to amend legislation to include e-voting for general elections.
"Youth are quite familiar with technology. They expect to be able to use it for most of their life activities," Mayrand adds.
Black Mark - Calgary Herald - September 6, 2008
The problem being, voting is not like "most of their life activities".
Voting is not banking, voting is not surfing the net, voting is not listening to music, voting is not texting a friend.
Banking is an example that is often used, or online taxes, but these are completely false examples. The bank knows exactly how much money you have, as does the government, and every transaction has an audit trail and can be reversed.
Voting must not have an audit trail, and cannot be reversed (if you are going to retain a system of private, secret ballots).
Voting, since it provides the transfer of power from the very many to the very few, is a very attractive attack point for malicious actors, and I mean "attack point" quite literally - people die for their vote already today, can you imagine how much more tempting for all of the negative forces in our society to take advantage of the vast computer networks that already exist for spam and attacks ("botnets") and use them to throw the election or to write a targetted virus to compromise the election?
That's not even to touch the issues of just running the election assuming everything actually goes right. The Do Not Call List site just went down because of high demand after it was launched. The Tax servers routinely get overloaded when millions of Canadians use the online systems near filing day. That's not a problem, because those transactions are repeatable.
What happens when the election servers go down from heavy demand on election day?
People resubmit their vote? We have the vote again another day?
A human-run, human-counted paper voting system has a very small number of failure modes, all of which anyone who understands the physical world can easily work out (people can steal the ballot boxes, etc.)
Computer-run, computer-counted voting systems have almost unlimited failure modes, which almost no one except computer and network security experts can fathom.
A paper voting system must work during the voting, and during the counting, and then it just disappears.
An electronic voting system requires servers that must be secured both physically and electronically 365 days of the year, every year, in case a vote is called.
The whole idea that you would get any benefits from online voting is patently ridiculous. The only way you can make it appear to work is to ignore all of the security issues, ignore all of the ongoing cost issues, treat it as if it were a banking or other repeatable and auditable transaction, as if voting is something that should somehow be made "efficient", and make a bunch of claims about turnout.
It is a Very Bad Idea.
Previously:
November 28, 2006 let's have a discussion
November 15, 2006 Geist on e-voting
Labels: canada, internet, internet voting
Thursday, August 21, 2008
Lou Dobbs - private companies running voting
DOBBS: For more than two years here, we've been reporting on the serious threat that electronic voting poses to this democracy. As a result, some states have begun to scrap their e-voting machines altogether. But a third of the nation will still be using e-voting machines in November. And more disturbing a new report says election officials often are outsourcing their responsibilities to the very companies that make the e-voting machines, even trusting those companies to count the votes. Kitty Pilgrim has our report.
(BEGIN VIDEOTAPE)
KITTY PILGRIM, CNN CORRESPONDENT (voice-over): Ellen Theisen has been a software writer for more than two decades. Living in Washington State, she was disturbed by electronic voting problems across the country, so she formed a nonpartisan citizen's activist group to investigate voting irregularities. A new report by that organization, VotersUnite.org, says that private companies now run many elections.
ELLEN THEISEN, VOTERSUNITE.ORG: Elections should be accountable to the people and run by public officials who are selected by the people to run them. So when that's handed over to private vendors, these public elections are no longer public.
PILGRIM: According to the report, many jurisdictions in the country are entirely dependent on the voting machine companies. The companies also tabulate results. State officials have to take their word for the results. The company owns the software and equipment and doesn't have to share it. It's proprietary. Election officials often can't do a recount without help. One state that rejected that arrangement is Oklahoma. In 1992, Oklahoma put in its own optical scan system, which is still owned and operated by the state.
MICHAEL CLINGMAN, OKLAHOMA STATE ELECTION BOARD: Election night, it's really all public officials dealing with the election and nobody else.
PILGRIM: Oklahoma wasn't tempted by new federal funds in 2002 when many other state and local governments used the Help America Vote Act money to buy touch screen machines.
UNIDENTIFIED MALE: There was really nothing on the market we would buy then and there's still nothing we would want to buy today.
Lou Dobbs Tonight - August 20, 2008
Labels: electronic voting, usa
Saturday, January 12, 2008
Olbermann - Man vs. Machine
Anything of value should be auditable. ...
To give voters the confidence that they deserve that their votes will be counted as they intended... in every election there should be an audit.
See the full interview
Countdown with Keith Olbermann - #4 Man vs. Machine
via Black Box Voting forum
e-voting was a bad idea and is reaping the whirlwind
1) Electronics makes things "efficient" and will save money.
2) Elections are a government service just like any other.
Underlying this was an extraordinarily naive concept of elections as uncontroversial events that would never be challenged, and that no one would ever make a serious attempt to commit election fraud. There would never be close races. In essence, a disdain for the whole voting process, because it implies that a single vote will never make a difference.
This is simply demonstrably untrue, as elections with contested results have been a worldwide problem, with accusations flying, often with violent repercussions. Time and time again we have seen incredibly close elections.
The reality is: the more complicated and indirect you make the voting process and the vote counting process, the more you open the system to suspicions of fraud, and associated loss of confidence in the results of the election.
As I've said before, voting is an incredible act of civic alchemy, in which the will of the many is transmuted into tremendous power for a very few (e.g. in the US, a few hundred people leading a nation of 300 million). WITHOUT COMPLETE CONFIDENCE, this cannot work; a million people are not going to hand over power to a single politician unless they are confident s/he was actually selected by a fair vote.
In a partisan environment with close-fought elections, this means that now
EVERY SINGLE ELECTION WILL BE CHALLENGED
Oh, brilliant cost savings there, you idiot technocrats. Instead of pen and paper and election results in hours with full confidence of the electorate, elections will now turn into endless recounts, court challenges, and code examinations. Since it is almost impossible to prove that machines weren't hacked, any case where there is not a full paper trail will end up basically unresolvable.
Hand counted paper ballots were never broken,
the only way to fix this problem is to go back to them.
New Hampshire is lucky they have optical scan (the least-worst of the electronic options) so that confidence can be restored by a manual recount.
For a taste of what's to come, see ArsTechnica - Analysis: Why the "Hillary hacked NH?" story is important (Updated)
Labels: electronic voting, optical scan, rant, usa
Thursday, October 25, 2007
minor site note: added feedflare
UPDATE: Minor template change to adjust FeedFlare.
Labels: meta
Saturday, April 07, 2007
electronic voting machines explained
Thursday, January 25, 2007
new blogger
Labels: meta
Tuesday, December 19, 2006
why postal ballots also suck
2. No immediate feedback / oversight if there are problems with the ballots
3. People screw up and put their signed declarations in the same envelope as their vote, thus a) spoiling their ballot and/or b) revealing who they voted for
Globe and Mail - Postal-ballot errors spark review - December 19, 2006
Municipal Affairs and Housing Minister John Gerretsen says he's considering revisions to Ontario's municipal elections law as towns and townships continue to struggle through counts of problem-plagued mail-in balloting in the Nov. 13 vote.
...
This week, judges in Bracebridge and Lindsay ordered that efforts be made to count ballots that had been determined spoiled by clerks in four Ontario municipalities because no signed declaration was enclosed.
Although some other municipalities faced with high postal-ballot rejection rates -- generally about 20 per cent -- instituted procedures before election day to try to salvage the votes, that option was refused by Lake of Bays Township in Muskoka, the City of Kawartha Lakes and the townships of Highlands East and Minden Hills.
Minden Hills is the only municipality so far where the added votes have made a difference. Out of 849 rejected ballots, 256 votes were found with a signed declaration improperly inserted inside the secrecy envelope and the vote was allowed.
As a result, challenger Lisa Schell saw her 11-vote loss to Clayton Cameron reversed to give her a one-vote majority.
Saturday, December 02, 2006
US NIST recommends scanned paper ballots
"Paperless electronic voting machines 'cannot be made secure' [pdf] according to the [US] National Institute of Standards and Technology (NIST). In the most sweeping condemnation of voting machines issued by any federal agency, NIST echoes what critics have been saying all along, that due to the lack of verifiability, 'a single programmer could rig a major election.' Rather than adding printers, though, NIST endorses the hand-marked optical-scan system as the most reliable."
(in case you're wondering, Internet voting counts as a "paperless e-voting machine")
I wonder how many experts have to say that electronic voting sucks before people will listen.
Of course, crazed luddite that I am, I would eliminate the machine-based counting as well, and just have humans count the paper.
Slashdot - NIST Condemns Paperless Electronic Voting - December 1, 2006 /.
Tuesday, November 28, 2006
let's have a discussion
a very disturbing and one sided perspective
But Adam, you haven't responded to a single issue that I raised.
I welcome all perspectives, provided they are fact-based.
In particular, I invite realistic threat-risk assessments, cost assessments, and cultural assessments.
Let us take Internet voting.
1. Is the code open-source?
2. Has the code been audited by neutral computer security experts?
3. Where are the servers?
4. How are the servers protected?
5. Has the server security been audited by neutral computer security experts?
6. Who pays to protect the servers and the code for the thousands of days during which they are not being used for municipal elections?
7. Who wrote the code?
8. Have they all passed an independent security certification?
9. Do they have ties to any particular political party or other organization that might have an interest in the outcome of the election?
10. How do you mitigate the risk of paying or forcing someone to vote in the way you want, as you watch them on the Internet?
11. How do you mitigate the risk of the massively insecure home computers that are used for Internet voting?
12. When the full costs of security audits and thousands of days of security protection are taken into account, in order to provide a single day of municipal voting, how do you justify the expense?
There's a dozen questions. I have way more where those came from.
I challenge anyone to answer.
