Tuesday, January 26, 2010
Internet voting dialogue: brief morning summary
I was most impressed with Tarvi Martens' presentation about the technical details of the Estonian Internet voting system. They have clearly thought very seriously about the various issues involved, and have very very heavy physical security for the data centre, and no remote admin access outside the datacentre. He also emphasized they had a principle of "no black box systems" in the data centre, so they use Debian, an open source operating system, rather than Windows. The fact they have a national ID card addresses the key distribution and network encryption issues (because the ID card includes an encryption key, a public/private digital signature key). They also put ISPs on high alert during the election period and monitor continuously for attacks.
I did ask him the security of the user's desktop and his answer was reasonable but to me, ultimately still unsatisfactory. They are using what I assume are honeypot systems to monitor for emerging trojans that pretend to be some component of the desktop voting system (or presumably the ecard reader driver etc.) They also have as the first step of their voting procedure that the user should ensure their system is scanned for viruses. However there are multiple issues including the innumerable vectors for home system attack, the fact that most users WON'T secure or scan their systems no matter how often you educate them about the issue, and the possibility for root kit or other subtle elusive trojans that might not be picked up by their honeypots.
He did say, which I think is an important contingency measure, that in the event they did detect a widespread trojan attack they have the possibility to simply shut down Internet voting and tell people to vote on paper on their regular voting day (Sunday).
The other thing I heard from multiple speakers is that Internet voting is not having substantial impact on turnout. What it is doing is making it more convenient... for people who would have already voted.
Labels: elections canada, internet voting, ivotecan
first timer
Labels: meta
Liveblogging
UPDATE: Have exceeded the status update limit for @papervote (!) - already just for the first session. Have moved to liveblogging on FriendFeed at http://friendfeed.com/electronic-voting-in-canada
Labels: elections canada, internet voting, ivotecan
Monday, January 25, 2010
knowing the players
This is simply an analysis of the players from a computer security standpoint. Three main points are examined:
1. What is their academic background in computer security
2. What are their stated positions about Internet voting or, in the absence of statements, what is their corporation's position on Internet voting
3. If they are providing Internet voting technology, what information is publically available about the security analysis for these systems? It is incumbent for all voting technology providers to address all realistic threats to their systems in an open manner. There is no security through obscurity. A failure to do so shows an unseriousness about security.
I also want to make a key point: elections do not hinge on voter perceptions of security and convenience. Elections hinge on ACTUAL security. Asking members of the public if they think Internet voting is secure enough or if they are comfortable voting online or if it is convenient to vote online does not mean, in any way whatsoever, that the actual vote is ACTUALLY SECURE.
If citizens perceive a bank as (financially) safe but government regulation actually creates a situation where the bank fails (as has happened repeatedly in the United States), then it is clear the citizen perception was meaningless, what was important was the government failure to actually deliver an appropriate level of ACTUAL security.
And again, even if the system was actually secure, which is somewhere between highly unlikely and impossible, it still doesn't mean the system meets necessary requirements for a functioning democracy.
The Players:
* Michael Alvarez, California Institute of Technology (Caltech)
- Dr. Alvarez is a Professor of Political Science at Caltech and Co-Director of the Caltech/MIT Voting Technology Project. His BA, MA and PhD are in Political Science.
- info from CalTech site
The mission of the Voting Technology Project is, not surprisingly, around technology: "All of this research and policymaking activity seeks to develop better voting technologies, to improve election administration, and to deepen scientific research in these areas."
It is important to remember that US elections are much more complicated than Canadian elections, with many more candidates running for many more positions, in addition to (in many states), multiple complicated ballot initiatives (direct democracy issues to be voted upon).
* Kimberley Kitteringham, Town Clerk, Town of Markham
- reported in media as advocating Internet voting
"We definitely think our early voting turnout was a direct result of the increase participation of people in the online voting process because online voting, from our staff and post-election survey, engages the voter that has been typically apathetic or difficult to reach. It offers a convenient solution for them because they can do it from anywhere in the world," Ms Kitteringham said.
yorkregion.com - Internet gateway to election reforms in Vaughan - September 30, 2009
* Andrew Brouwer, Deputy Town Clerk, Town of Markham
- Bachelor of Environmental Studies , Urban and Regional Planning; Master of Public Administration , Local Government Program (from LinkedIn profile)
* Cathy Mellett, Acting Clerk/Manager, Halifax Regional Municipality
- reported in media as advocating Internet voting
"We had people vote from Sri Lanka, from Korea, from over 50 Canadian cities and 25 American states," said Cathy Mellett, e-voting project manager for the Halifax Regional Municipality.
"That's really been the objective from the very beginning, it's about getting voters accessible and participating in the overall election here in the HRM."
Mellett said there were no serious glitches in the system during the voting period.
CBC News - 10% of HRM voters cast e-ballots - October 7, 2008
* John McKinstry, Sales Manager, Dominion Voting Systems
- a company that has literally trademarked the word democracy: "Dominion Democracy™ is our comprehensive yet flexible voting suite, designed to uphold the principles and ideals of the electoral process."
- message is shaped entirely around turnout
Voter turnouts continue to fall even in the face of aggressive communications campaigns at all levels of government. One way to improve turnouts is to give the voters more voting choice; choices that reflect changing technologies. Chief among these alternative choices is remote voting. In taking voting to the voter, you remove one of the barriers to turnout.
Taking the voting booth to the voter
- according to Google search (site:www.dominionvoting.com security) entire site has exactly two mentions of security
1.
Everything before and after the ballot is hosted on computer servers. There may not even paper ballots, as is the case with Internet voting.
Dominion can host your elections on our secure servers to ensure the integrity of your election. We pride ourselves on the security and permanency of our server system.
Hosting your election
In summary: your election, hosted on a private company's servers. How do you know they are secure? Because they pride themselves on security.
2. There is a single instance of the word "security" in their document Democracy Suite EMS Edition 2007 (PDF)
To address the sensitivity of the election process from a security standpoint, the system provides role-based authentication and authorization, while all data transactions are protected for greater confidentiality and data integrity.
While it is good that the system uses authorisation to limit access, and "protection" for data transactions (whatever that means), this assumes that a) the authentication credentials have not been compromised b) the network transmission is a particularly vulnerable and interesting place to attack.
Just on the second point: HTTPS encyrption of web transactions is essentially like using an armored car to transport money between two completely unsecure endpoints, between a house with no locks on its doors and a bank vault with no lock or security system. Attackers target system weaknesses. Since the Democracy Suite uses Windows computers, isn't an attacker more likely to attack the servers themselves using known Windows vulnerabilities, than to try to intercept the data in transit? The document does not address these issues. You have to secure Internet voting systems END-TO-END, from keystroke on the desktop to calculated results on the datacentre servers. This is impossible to do with anything approaching a high level of security (a high level of risk mitigation) for an election threat model.
* Alexander Trechsel, European University Institute, Florence
- Professor of Political Science and the first full-time holder of the Swiss Chair in Federalism and Democracy at the European University Institute (EUI) in Florence, Italy.
- info from EUI site
- PhD in Political Science (from LinkedIn profile)
* Tarvi Martens, Development Director, Certification Centre, Estonia
- MSc IT, Tallinna Tehnikaülikool (from LinkedIn profile)
- Program Manager for Internet Voting at Estonian National Electoral Committee (currently)
- Development Director at SK (currently)
- SK is a company that provides "provision of different certificates to physical persons and organisations. Currently, the largest project handled by SK involves issuing authentication and digital signature certificates to Estonian ID cards." - http://www.sk.ee/pages.php/0203
That is, SK is a private company in the business of providing certification technology.
* Urs Gasser, Harvard University
- Dr. Urs Gasser is the Berkman Center for Internet & Society's Executive Director.
- graduate of the University of St. Gallen (S.J.D. 2001, J.D. 1997) and Harvard Law School (LL.M. 2003) (Note: these are all law degrees)
- info from Berkman Center site
* Tom Hawthorn, The Electoral Commission
Remote electronic voting via the internet and telephone was once the future of British elections. But trials held in the 2003 local elections found it made little difference to turn-out and raised concerns about security, privacy and transparency.
Tom Hawthorn, electoral modernisation manager for the Electoral Commission, says that remote e-voting is unlikely this decade, although he believes the idea may return. "In the short- to medium-term, there's things about the existing voting system - voting stations and postal ballots - which can be improved," he says.
guardian.co.uk - Voting searches for the x-factor - Nov 23, 2005
- 2006 presentation "What voters expect from a voting system" indicates high degree of concern about "my vote being private" and "my vote being safe from fraud and abuse" (in terms of percentages these are the top two concerns expressed)
* Adam Froman, President, Delvinia Interactive
- corporation that promotes Internet voting
- "Internet voting made a positive impact on the election results." from blurb on page for their report "Understanding the Digital Voter Experience"
* Dean Smith, President, Intelivote Systems Inc.
- corporation that provides Internet voting
- eight results for site search on "security" (site:www.intelivote.com security)
* Jason Gallagher, Open Source Software Developer
- I don't actually know who this is. The most likely match appears to be: "Lead Open Source Software Developer for McMaster University, Dept. of Family Medicine" (from PCHRI 2006 participants)
* Peter Wolf, International Institute for Democracy and Electoral Assistance (IDEA), Stockholm
- MSc., GraZ University of Technology (from IDEA site)
I welcome corrections and clarifications and I will update this posting if more information becomes available.
Labels: canada, elections canada, internet voting, ivotecan
Thursday, January 21, 2010
http://twitter.com/papervote
No hashtag has been declared that I can find. I'm proposing #ivotecan
For electronic voting in Canada in general I have been using hashtag #evotecan
and there's an aggregator / discussion group on FriendFeed: Electronic Voting Canada.
Labels: elections canada, internet voting, twitter
Ottawa Jan 26, 2010 Elections Canada event on Internet voting
The Canada-Europe Transatlantic Dialogue (Strategic Knowledge Cluster)
Internet Voting: What Can Canada Learn?
This workshop brings together practitioners and scholars to explore issues involved in the development of Internet voting. Speakers include experts from various jurisdictions where Internet voting has been used, and prominent researchers who have studied models of Internet voting. Speakers will detail the development of Internet voting in Canada at the municipal level by examining the cases of Markham, Peterborough and Halifax, and in Europe nationally and sub-nationally by exploring the experiences of Estonia, Switzerland and the United Kingdom. The workshop will consider rationales for the implementation of Internet voting, various features and models of its application, advantages and disadvantages, public acceptance, effects on accessibility and voter turnout, and security issues. Experts will share advice regarding technical considerations such as cost, legal requirements, software and security.
UPDATE 2010-01-25: I just realised I forgot to include a link to the event itself. Here is the Elections Canada link - Elections Canada: Media: Special Events and Conferences: Internet Voting and the Carleton link - Canada-Europe Transatlantic Dialogue (CETD) Events: Internet Voting. ENDUPDATE
Look at the issues they're examining:
* cost
* legal requirements
* software
* security
Let's revisit what I have called the "Democracy Requirements" for voting:
* preserving the secret ballot
* retaining the right to an uncoerced vote
* the integrity and accuracy of the vote count (all votes gathered and correctly counted)
* the simplicity of the system (can voters understand how the entire voting system works?)
Do you see the problem? They're talking about voting, but as usual, they're talking about it as if it were any other government "service" that is "delivered", rather than the single foundational element of our democratic society. This is what they always do, focus on the technology rather than the actual requirements for the integrity of the vote.
I can guarantee what the Internet voting presenters will discuss is three main things: convenience, turnout, and security. They will make a bunch of abstract claims about encryption and secure networks that will sound good but that, if you are an actual computer security expert, are actually nonsense.
You CANNOT, as in impossible:
* use technological security to ensure perfect end-to-end chain of custody for Internet voting
* construct a system in which the ballot is actually secret and anonymous
While it is true that there are theoretical computer constructs that can accomplish this, they run on theoretical computers over theoretical networks to theoretical servers. They do not run on Windows 7 computers on an ISP Internet connection to a bunch of servers in an actual datacentre.
Just think of the thousands, probably millions of phishing attempts every day, and the large number of these attempts that are successful. Just think of the recent security attacks on Google. Just think of the endless litany of lost passwords, lost user accounts, compromised commercial organisations. The home computer and the public Internet is one of the LEAST SECURE possible places I can imagine to hold an election.
Just off the top of my head I can list numerous possible compromises:
* if the password is sent in the physical mail, requiring at most some publically-discoverable extra piece of information (e.g. the user's birthdate), then I can attack the password distribution, in the same way that people steal credit cards and identities
* if it's not sent by mail, how do you solve the huge problem of secure key distribution to 30 million people? (secure key distribution is one of the single hardest problems in computer security)
* If your machine is already on a botnet, and millions of compromised machines already are, I have basically unlimited freedom to alter and compromise the election. I can watch your keystrokes and record who you voted for. I can watch your keystrokes and then, behind the scenes, CHANGE who you voted for. I can decide I don't like the parties running and use my botnet to attack the election servers (if you say "well, the datacentre can just block the attack" - yes, but the attackers are CITIZEN COMPUTERS)
* I can skip the end user and compromise the physical security of the data centre. And/or I can insert code into the servers that counts whatever votes for whatever candidates I want.
Even if the security is done well, there are insurmountable issues.
But even worse, the security is almost never done well. Because it is about cost, it goes often to the lowest bidder. Do you seriously want your entire election run by some private company that was the lowest bidder? Or consultants for Elections Canada that gave the best price? What "best price" means is, as was shown repeatedly for Diebold, the elections technology provider takes off-the-shelf technology (how could they not, and still provide the lowest cost), hacks together some amateurish backend with a somewhat pretty frontend, and then serves that up as a secure elections solution, leaving NOT ONLY all the security issues with e.g. running on Windows, but introducing ADDITIONAL security issues with code that is almost always woefully insecure, badly designed, and not available for review by outside computer security experts.
And even if, by some miracle, none of these things happens, ok we run an election.
It ends like the 1995 Quebec Referendum, 50.58% "No" to 49.42% "Yes" (note: elections are razor close ALL THE TIME).
So you say, all settled then, 50.58% "No".
And I say: PROVE the computers, the Internet, and the data centre were not compromised. PROVE the votes were not coerced. PROVE that it was actually Canadians voting, once, and not stolen accounts anywhere in the world voting multiple times.
You cannot prove this. Goodbye decisive elections. Hello endless battles.
Do you think this is abstract? There was ALREADY a fiasco with electronic voting machines in Quebec, which as terrible as they are, are at least in observable physical space. It was so bad, they had to investigate it, and:
On October 24, 2006 the Chief Electoral Officer of Quebec released a report (in French only) "Report on the Evaluation of New Methods of Voting" (Rapport d'évaluation des nouveaux mécanismes de votation). In a press release, three root causes of problems with electronic voting machines in the 2005 municipal elections were identified:
* an imprecise legislative and administrative framework
* absence of technical specifications, norms and standards
* poor management of voting systems (especially lack of security measures)
He recommended that the current moratorium on the use of these systems be maintained, and leaves it up to the provincial legislature to decide whether or not to use electronic voting in future.
Labels: canada, elections canada, internet voting
Friday, December 18, 2009
Canadians support online voting?
In the poll, released exclusively to CBC: Power & Politics, Canadians were asked if Elections Canada offered a safe way of voting on the internet, how likely is it that they would use it.
Around 49 per cent of respondents said they were very likely and 15 per cent said they were somewhat likely.
Here's the comment I left:
Information on the Internet is just a click away. This issue has been well-studied by computer security experts. One part of it comes down to this magic phrase "a safe way of voting on the internet". That is probably impossible in the real world, outside of the confines of computer science theory. I know some will respond "online banking is already secure" but 1) it isn't & 2) banking has a completely, totally different set of threats and necessary security measure from voting
One good starting point is the Computer Technologists' statement on internet voting http://www.verifiedvoting.org/article.php?id=5867
"Election results must be verifiably accurate -- that is, auditable with a permanent, voter-verified record that is independent of hardware or software. Several serious, potentially insurmountable, technical challenges must be met if elections conducted by transmitting votes over the internet are to be verifiable. There are also many less technical questions about internet voting, including whether voters have equal access to internet technology and whether ballot secrecy can be adequately preserved."
I want to draw attention to that phrase: "potentially insurmountable". Given that paper voting works well now, is easy to understand, and is quick to count, would you rather stay with that, or try a system that computer experts say may be impossible to create? One which even if it solved the technical problems, would still have no solution for the secrecy of your ballot, a sacred right of democracy. Voting integrity is not theoretical. We know that votes were compromised in Iran and Afghanistan. Now imagine instead of paper votes and people in the streets, it had all taken place electronically? You would never know if the results reflected the votes cast.
Labels: canada, electronic voting, internet voting
Monday, July 06, 2009
Norway Internet voting
The Ministry of Local Government and Regional Development is now working on a plan to test the possibility for allowing Norwegians to cast their vote from the home PC at the municipal elections in 2011.
The Minister of Local Government, Magnhild Meltveit Kleppa, is eager to introduce reforms which will increase the interest for elections and for voter participation.
The Norway Post - Electronic home voting next - July 7, 2009
Labels: electronic voting, internet voting, norway
Saturday, June 27, 2009
say no to Elections Canada online voting idea
Allowing Canadians to vote electronically may be the remedy for the ever-dwindling percentage of voters who bother to exercise their democratic rights, Elections Canada suggests.
In a report released late Friday, the independent electoral watchdog says it will push this fall for legislative changes that would allow it to implement online registration of voters.
And it wants parliamentary approval to conduct an electronic voting test-run in a byelection by 2013.
Elections Canada backs online voting - June 26, 2009
(It's not actually clear to me if they're talking about electronic voting machines, or voting online. Both approaches have huge flaws.)
As readers of this blog will already know, I favour the traditional in-person enumeration, and voting on paper in public. These are simple processes that are critical to the integrity of our democracy.
I've already written a critique of the idea that electronic voting will help with voter turnout - citizen engagement and e-voting. I have also outlined many, many times the security risks associated with electronic voting.
Electronic voting is a very bad idea based on incorrect assumptions.
And if you don't think having total confidence in the results of an election is important, check out the current situation in Iran. Elections matter.
This blog started in 2004 before the days of hashtags and such, but I'm suggesting hashtag #evotecan and tag evotecan for this issue.
There are also a few searches that should pull up references to this particular article:
Twitter - Elections Canada backs online voting
Twitter - bit.ly link to Toronto Star article
Google News - articles related to "elections canada" electronic
Labels: canada, elections canada, electronic voting, evotecan
FriendFeed discussion room
http://friendfeed.com/electronic-voting-in-canada
Labels: meta
the linkroll bookmarks
In the meantime if you want to see the actual, non-spammy e-voting links, they're at
http://www.linkroll.com/index.php?action=links&user=papervotecanada
UPDATE: Linkroll is displaying spam links when you pull their RSS feed or use their JavaScript widget. Goodbye Linkroll.
Labels: meta
Sunday, February 01, 2009
Behind the Freedom Curtain - 1957 film about mechanical voting machines
I tried to embed it, but the embed code was too complex, you can see it at
http://www.archive.org/details/Behindth1957
For those of us not experienced with US elections, it's also a reminder of their incredible complexity.
My favorite part is when they talk about how the machine cannot make an error, and is protected by the incredible security of... a key.
Another gem from the Prelinger Archives, the video was on the front page of Archive.org today.
Labels: video, voting machines
Monday, January 05, 2009
why voting systems matter
Office of the Minnesota Secretary of State: Voting Systems map (PDF)
When a recount is necessary:
* You can see the ballots.
* You can determine for yourself whether they are being unfairly accepted or rejected, and how they should be counted.
* You can determine, therefore, whether you think the results fairly reflect the will of the people.
This is important because the current Senator-Elect, Al Franken, is certified as having won by 225 votes. Out of over 2.8 million votes cast in the 2008 US Senate election in Minnesota.
Voting systems matter because elections can be very close,
which means they will be challenged,
which means you must have VISIBLE EVIDENCE of the votes that can be counted by anyone,
so that the public can determine if the results are fair.
CNN: Minnesota canvassing board certifies Franken win - January 5, 2008
Monday, November 10, 2008
citizen engagement and e-voting
For many people concerned about democracy and about electronic voting, the problems we consider are:
* preserving the secret ballot
* retaining the right to an uncoerced vote
* the integrity and accuracy of the vote count (all votes gathered and correctly counted)
* the simplicity of the system (can voters understand how the entire voting system works?)
I call the above "The Democracy Requirements".
You will very rarely hear advocates of electronic and particularly Internet voting talking about any of the above concerns. What they talk about is:
* efficiency
* modernity
* convenience and customer service
* voter turnout (# of votes cast, % of eligible voters who cast votes)
You will notice this is a completely different set of problems.
I call the above "The Voter Engagement Requirements".
So in a sense, we're talking at cross-purposes.
The computer security experts say "electronic voting can never be secure, and you can never know that your vote was counted properly" and they say "we think security is a non-issue because (other technology with unrelated requirements) is 'secure', and e-voting is modern and convenient and young people will use it".
The Democracy Argument Against Electronic Voting (and some paper voting too)
It should be mentioned, the first set of issues applies to many, many other voting options. As soon as you compromise chain-of-custody and the private-in-public vote, you risk all except simplicity.
For example: mail-in voting.
1. If I can identify the sender (by watching the mail they send, by identifying their handwriting, by some unique identifier on their ballot), then no more secret ballot.
2. There is a huge chain-of-custody issue - anyone in the mail stream can intercept and destroy, replace or alter your ballot
3. Your enemies can stand beside you and force you to vote the way they want
These are not abstract issues and rights. People are injured and even die every year in countries where voting is taking your life into your own hands.
Even just advance voting introduces chain-of-custody issues.
(Battlestar Galactica showed a simple fictional scenario for compromising a paper-based election, by having collusion in the chain-of-custody so that an original ballot box was changed with one stuffed with votes for a particular candidate.)
So let me make it very clear: voting on one day privately, in public, on paper, with a hand-count of ballot boxes that never leave the polling station, with scrutineers from all parties watching the count - this is the most elegant solution I can think of to the key issues of secrecy, non-coercion, integrity, accuracy and simplicity.
A machine-mediated vote, or a machine-mediated count CANNOT do this, because you CANNOT (as in, technologically impossible) know what program the computer is actually running. You cannot meet these requirements with an electronic system. I know this is a world where there are few absolutes, but trust me, any computer security expert can tell you this.
The Voter Engagement Argument for Some (non-voting) Use of Electronic Systems
Ok, assuming you want to engage your citizens in some meaningful way, and not in some Canadian Idol illusion-of-convenience superficial way, then I thought it came out quite clearly in the TVO discussion that you need:
* leadership
* engaging issues
* a real connection with voters, particularly young voters
Do you see any mention of technology in the above three items?
There is no website that is going to make you a leader, there is no social network that is going to make your issues engaging, there is no blog posting that can substitute for actually listening to your constituents. IF you already have addressed those issues, then you can reach your voters using...
* radio
* television
* and maybe you've heard of this Internet thing?
Technology is not a solution. Technology is one channel to communicate your message. You have to have an interesting message, first.
If you want more people to vote, give them something they care about to vote for, convince them that their vote matters, and connect with them before and AFTER the election, to demonstrate that you value them for their opinions, not for their increment to your vote count.
If you do that, they will wait in lines for hours. Voting technology doesn't matter. It doesn't solve a problem that Canada has.
Labels: citizen engagement, electronic voting, internet voting, politics
elections are often surprisingly close
There is another great example going on right now in the Minnesota senate race.
According to Daily Kos, "Today's latest results show [Democratic challenger Al Franken] is now trailing Republican incumbent Norm Coleman by 204 votes."
Wikipedia currently shows the tally at
Popular vote Coleman:1,211,562 Franken:1,211,356 Barkley:437,389
If you want that in percentages that's Coleman 41.988%, Franken 41.981%
That means if your voting machines have even a .01% error rate, they've already thrown the election. And the high-tech threat to Minnesota's optical mark-sense scanners? Dust.
Undecided Minnesota Senate Race Used Machines that Flunked Accuracy Tests - Wired - November 5, 2008
In an earlier posting, Wired writes
The problems occurred during logic and accuracy tests in the run-up to this year's general election, Oakland County Clerk Ruth Johnson disclosed in a letter submitted October 24 (.pdf) to the federal Election Assistance Commission (EAC). The machines at issue are ES&S M-100 optical-scan machines, which read and tally election results from paper ballots.
Johnson worried that such problems -- linked tentatively to paper dust build-up in the machines -- could affect the integrity of the general election this week.
ES&S Voting Machines in Michigan Flunk Tests, Don't Tally Votes Consistently - Wired - November 3, 2008
Say what you will about human failure modes, but dust usually isn't one of them.
Given that
1. Elections are often surprisingly close
2. Integrity of the count is paramount (your vote must be correctly counted)
3. Machines have many failure modes
4. A paper count by humans can be open and easily verified and rechecked
Then the best option to ensure confidence in election results is: hand-counted paper ballots.
(I don't know whether the Minnesota recount will require hand-counts.)
Labels: election, electronic voting, optical scan, usa
a note on navigation
http://papervotecanada.blogspot.com/search?q=cbc
http://papervotecanada.blogspot.com/search?q=toronto
Labels: meta
E-voting on TVO The Agenda November 10, 2008
The Debate: E-Voting: An Idea Whose Time Has Come?
Technology and the vote: Why has there been a stubbornly slow adoption of electronic voting?
The Agenda - November 10, 2008
Note: This episode has not yet aired, it will be on television tonight at 8 PM and again at (I think) 11 PM. The video is usually up online a few days after the show airs. I will update this posting with new information when available.
UPDATE: I have created a discussion thread on the "Your Agenda" discussion forum: e-voting. You'll have to create an account there if you want to add your thoughts before or after the show. ENDUPDATE
UPDATE 9 PM: The show has just ended. I thought the debate was good. I also thought it was positive that the debate focused on a much more realistic assessment of evoting in terms of voter engagement and turnout.
If voting was about convenience, you wouldn't have seen people standing in line for hours in the United States. Voting is about citizen engagement. If the citizens find something interesting to engage with, technology can be an enabler. But you don't need online voting for that, you need an online presence for every day other than the election, much as we're seeing already with Barack Obama, who reached out through BarackObama.com (and into many other Internet channels) and is now connecting with Americans through his transition site change.gov
To me this technology argument "young people use technology, so voting should use technology" is ridiculous. Young people aren't stupid. Putting up a Facebook page is not the answer, putting up content that they care about is the answer.
Both of the letters from the MPPs were very well informed.
As well Farhad Manjoo and Darin Barney were both well-informed about the technical issues, and it was great to see Don Lenihan being very clear that it is for the computer security experts to determine whether voting online is secure, not the politicians or corporations.
Marie Bountrogianni was obviously not well-informed about the technical issues, but unfortunately that didn't seem to stop her making incorrect assertions (if we can bank online, why not vote online? um, because they have COMPLETELY DIFFERENT SECURITY REQUIREMENTS).
John Hollins brings a corporate perspective to voting, talking about "serving customers", an approach which to be quite frank, I hate. Voters are not consumers being provided a service, they are citizens engaged in one of the few public activities of our democracy. Voting is not the same as paying a parking fine. (Longtime readers of this blog will know of Mr. Hollins and his boosterism for technology solutions.) In Canada we have very simple elections. You don't need a $3000 touchscreen voting machine with VVPAT paper trail, to record a single vote, so that when there's a problem, you can count the votes on the paper trail. JUST VOTE ON PAPER FIRST.
I will write a follow-up post on citizen engagement vs. e-voting.
Overall I thought it was a good discussion which in the end turned far more on the citizen engagement aspect.
After posting on the Agenda forum I was fortunate to get an email from Sandra Gionas and to have a chance to talk with her on the phone, and she has kindly included substantial quotes from me in her Inside Agenda blog posting Control, Alt, Delete and Vote.
ENDUPDATE
I love the loaded language people use for paper voting: "quaint", "old-fashioned"
or for the lack of technology in Canada's federal elections: "stubbornly slow adoption".
stubbornly?
This is what I had to say the last time someone argued that you couldn't stop the wheels of e-voting progress:
Ah yes. The real world. The modern world. The practical, down-to-earth, realistic, Common Sense Revolution world. Paper is obsolete, so old-fashioned, like the Geneva Convention and other inconveniences.
Bullshit.
corporate voting bullshit - Paper Vote Canada - November 24, 2006
If paper voting is so obsolete, why is it that, overwhelmingly, the most articulate and forceful campaigners against electronic voting are computer scientists? Are computer scientists generally considered stubbornly slow adopters? Could it be that the actual experts in computer technology know that from the standpoints of security, cost, simplicity and core principles of democracy, electronic voting is just a very bad idea?
You don't believe me?
* Computer Scientists question electronic voting - March 3, 2003
* Computer scientists slam e-voting machines - CNet News - September 27, 2004
* Following issuance of an analysis by four computer scientists who were members of the SERVE Security Peer Review Group, the Pentagon decided to scrap plans for the use of this technology to cast ballots in the 2004 Presidential election.
* Computer scientists weigh in on e-voting - July 20, 2006
* UC Computer Scientists Release Video on How to Hack a Sequoia Touch-Screen Voting Machine - September 9, 2008
* E-Voting Doesn’t Get Computer Scientist’s Vote - October 10, 2008
I could go on listing reports and articles for many pages, but I hope I've made my point.
Not having electronic voting is not stubborn resistance to progress, it's rational opposition to expensive, unnecessary, insecure technology that will undermine the foundations of our democracy.
Labels: canada, electronic voting, television
Wednesday, November 05, 2008
The Onion Reports
All hail the DRE 700.
Labels: electronic voting, humour, video
Monday, November 03, 2008
Oprah's Presidential vote initially not recorded by electronic voting machine
What's interesting (and sad) is that Oprah blames herself for her voting problems.
First of all, if the machine doesn't record your vote, that's because the machine is badly designed. Second of all, it means you shouldn't be using machines.
It doesn't seem to occur to Oprah that the fault could lie with the machine.
Labels: election, electronic voting, usa
Friday, October 31, 2008
machines are insecure and vulnerable
shape-shifting electronic votes are more than fantasy, according to reports from states including West Virginia, Missouri, Nevada, Georgia and Colorado. Whether by accident or design, touch-screen voting machines have "flipped" votes from a caster's chosen candidate to one he opposes.
Unlike the old days when campaigners hung around street corners haranguing voters with handouts and pints of beer, the electronic era presents a sophisticated challenge to democracy.
Now, says Crispin Miller, author of Loser Take All: Election Fraud and Subversion of Democracy 2000-2008, changes can occur seamlessly, without a breath of suspicion. Electronic glitches are only one of a range of mishaps, mistakes and dirty tricks that may decide outcome on Nov. 4.
Complaints about the electronic machines have mounted, along with calls for a return to paper ballots, like Canada's.
"More traditional systems are better," says Jeremy Epstein, a technological security expert and member of two Virginia legislative commissions that studied voting machines. "Paper-based and hand-counted ballots are fast, accurate and cheap. Studies show that machines are insecure and vulnerable to attack."
Fraud fears grow as [US] voters throng polls - The Toronto Star - October 21, 2008
(The article title is not great, something like "voting machine errors and voting surpression plague election" might have been closer to the mark.)
Labels: election, electronic voting, usa