Damning Report On Sequoia E-Voting Machine Security 200
TechDirt notes the publication of the New Jersey voting machine study, the attempted suppression of which we have been discussing for a while now. The paper that the Princeton and Lehigh University researchers are releasing, as permitted by the Court, is "the same as the Court's redacted version, but with a few introductory paragraphs about the court case, Gusciora v. Corzine." What's new is the release of a 90-minute evidentiary video — the researchers have asked the court for permission to release a shorter version that hits the high points, as the high-res video is about 1 GB in size. See TechDirt's article for the report's executive summary listing eight ways the AVC Advantage 9.00 voting machine can be subverted.
Don't look (Score:5, Funny)
Re:Don't look (Score:5, Funny)
http://www.theonion.com/content/video/diebold_accidentally_leaks [theonion.com]
Re:Don't look (Score:5, Informative)
"why bother with rigging the voting machines...it seems this year a simpler method has been found, with Acorn registering everyone they can, dead, undead, fictional or alive"
This is, as the poster must be surely be aware by now, not what happened. What actually happened is that a few ACORN employees got lazy and filled out fake voter registrations using the. names of athletes, characters from fiction, etc.). ACORN found out, fired the people responsible, and identified the bad registrations to the authorities when they turned them in. They were required to turn them in by law, as it is illegal to not hand in any voter registration forms due to the obvious potential for abuse if the registration organization is allowed to be selective about which registrations to submit.
Because ACORN identified the suspicious registrations, and because the government agencies that process the registrations validates them, there were likely few or no fake voters actually registered to vote.
And, of course, Micky Mouse, etc., is not going to show up to vote.
So the fraud was not the creation of fake votes, but of ACORN (and to a degree the voter registration agencies) getting their time and money wasted by a few former ACORN employees. Given that ACORN hired 13,000 people and generated 1.3m legitimate registrations, the number of bad registrations reported so far is surprisingly small (a few thousand is claimed).
For actual voter fraud, you'll have to look elsewhere. Like, say, electronic voting machines, caging, etc.
Re:Don't look (Score:5, Insightful)
False registration is the first step in voter fraud, is it not?
And flamebait on the original post? What...Is rigging the machines not just as bad as encouraging and aiding voter fraud by fraudulently registering voters multiple times, fake voters, etc?
I mean...c'mon...if it is bad for one side, it is bad for the other side too.
Re:Don't look (Score:4, Informative)
"is rigging the machines not just as bad as encouraging and aiding voter fraud by fraudulently registering voters multiple times, fake voters, etc?"
Rigging machines is much worse. Rigging machines can affect every vote cast in the machines.
Registering fake voters results in no fake votes, because fake voters don't show up to vote. It is legal for people to register multiple times, so long as they only vote once.
So you're right that "if it is bad for one side, it is bad for the other side too". But in simply saying that doesn't magically make the behavior of the two parties identical.
Historically the Republicans have been the minority party that applies superior tactics and funding to win national elections. When you're the majority party you don't need to cheat - you need to have the rules enforced. When you're the minority party, you do all you can to get every vote.
For example, changing people's voter registrations between parties without their knowledge (http://conspireality.tv/2008/10/20/finally-an-actual-arrest-in-vote-fraud-case-and-its-a-republican/), however, turns out to be illegal.
Re: (Score:3, Insightful)
Why in the world did you think ACORN et. al. would go to all the trouble of setting up multiple registrations if such did not result in additional votes?
ACORN agents send in fake registrations so they get paid more by ACORN. What could be simpler than that?
Re:Don't look (Score:5, Insightful)
encouraging and aiding voter fraud by fraudulently registering voters multiple times, fake voters, etc?
And if you actually look into it beyond fox news and the "sources" that they quote, you may find out that it is legally required by a voter registration group such as ACORN to submit every single registration form that they receive, regardless of if they think it is valid. They are allowed to mark ones that they believe to be invalid, so that they will be further inspected by actual officials, but to my knowledge, no one has questioned the accuracy of their markings. The issues with false registrations are mostly being found as cases of the person collecting registrations attempting to hit quotas to prove that he/she is actually working. Molehill, not a mountain.
False registration is the first step in voter fraud, is it not?
It could be the first step, but it isn't necessary for voter fraud (as some other replies around this thread suggest, there are plenty of ways to mess with democracy).
As for this particular method, are you suggesting that people going to show up with fake ID's to match the false registrations that they submitted? Seems a bit more involved than designing the machines to falsely provide results.
Outside of that, I have recently realized an issue of concern regarding our electoral process... some people have realized that many minorities who are legal citizens of the country and should be allowed to vote aren't being allowed to vote because they lack ID that is accepted at the time of voting. The problem is that while the Democrats are fighting to get these ID laws removed, they aren't really acknowledging that false registrations in conjunction with no ID required would completely undermine our voting system. We still need to find a way for all citizens to vote though (preferably not a solution involving ID's with RFID chips, GPS tracking or whatever else is remotely possible).
I rolled a 2 (Score:2, Funny)
My reading comprehension must have failed a saving throw. I can't understand the summery.
Re:I rolled a 2 (Score:5, Funny)
No problem, just put a disclaimer on the machines (Score:5, Funny)
"We provide this voting booth for entertainment purposes only. Use of this machine does not constitute the actual act of voting for a bill or candidate. The State of [INSERT_STATE_NAME_HERE] and the United States Federal Government are not liable for any damages that may arise through the use of this entertainment apparatus."
That ought to do it.
Re: (Score:2)
Re: (Score:2, Interesting)
Re: (Score:2, Insightful)
The reason is that from the viewpoint of lottery, an individual player gets an individual result (win/lose). A voter is placing a vote which is aggregated with the corresponding inputs from other voters to determine the election winner (we'll ignore the electoral college as being ove
"E-Voting Machine Security" like "Microsoft Works" (Score:5, Insightful)
An oxymoron.
The only thing a e-voting machine should be used for is printing a paper ballot.
Count the paper ballots.
Anything else means you have to trust the voting machine, or the people who verified the voting machine.
(You have to make sure that there are no hidden things in any of the chips, the software, any memory card that comes into contact with the machine, the network that the machine is connected to, etc. Seriously, who can possibly think that a E-voting machine with a Sprint data card in it is secure?)
Re: (Score:3, Insightful)
You have a very good point here - why are these things even doing all the "tallying" on there own? Wasn't the overall MAIN issue was the validity of "hanging chads" and the like - why in the hell can't we have a simple machine with all the same bells and whistles that simply punches the damn things for us?!?!
On a side note - how hard can this stuff be? It's not like they aren't making a fortune from these things - it's seeming like they are barely able to break even so they have to hire "below the barrel" t
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:5, Interesting)
Making a machine that counts or tallies votes shouldn't be very hard, and should be a first year programming assignment.
Making that whole system *secure*, otoh, is almost impossible, especially when it is something as large and distributed as a national voting system. If a company could actually make a completely secure voting system, they could also have a good DRM system. (Yeah, I did say "good DRM system", which shows how possible I think that is)
From Ken Thompson's essay Reflections on Trusting Trust [bell-labs.com], he says it isn't enough to check the source code, you also have to check the compiler, the output from that compiler, and I would add, in the context of a voting system, everything that is or could be in the system/network.
Re: (Score:2)
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:5, Insightful)
Because those are different cases.
The user isn't going to hack his own computer to get his credit card number. Hope that persons computer doesn't have a virus or key logger.
That insurance company or hospital hopefully will have physical security protecting their machines. That doesn't always work, surely you have seen the articles about x million peoples data lost from (company of the week).
Securing E-voting is really like DRM: you want to distribute a device to potential hackers, and keep it secure from those hackers.
Anonymity and reliability are directly at odds (Score:5, Informative)
Most of the common credit card fraud-prevention schemes (such as date/time stamping every transaction) violate this. Not really a surprise, since the credit card system is designed to enforce accountability, the antithesis of anonymity (the whole purpose of anonymity is to avoid accountability).
Fundamentally, anonymity is about removing traceability information, and fraud prevention is about maintaining it. These are both core requirements, and they directly work against one another.
Re:Anonymity and reliability are directly at odds (Score:4, Informative)
Re: (Score:2)
Don't be so sure about that [google.com]
Re: (Score:3, Informative)
Making a human and machine readable, voter verified, printout is far from impossible in fact it's simple. Safely getting Paper ballots from the voting locations to a central polling place is simple. Counting the human and machine verifiable ballots with a high degree of accuracy is simple.
Now making a e-voting system that is obtuse and vague enough that elections can be skewed with a good sot at deniablity and a complete lack of papaer trail?
Re: (Score:3, Insightful)
you do realize that most e-voting machines run windows right?
The base OS in these machines is fscked from the beginning, there is no way to secure them completely.
If they used Open BSD, stripped of all unnecessary components compiled from scratch from at least two different compilers to double check all the out puts and inputs then you have a reasonable base to start with. DRM on all software pieces is also needed. at the very least a hash system to approve updates unless they occur 10 days before and 10
Re: (Score:3, Informative)
Re: (Score:3, Insightful)
Making that whole system *secure*, otoh, is almost impossible, especially when it is something as large and distributed as a national voting system. If a company could actually make a completely secure voting system, they could also have a good DRM system. (Yeah, I did say "good DRM system", which shows how possible I think that is)
From Ken Thompson's essay Reflections on Trusting Trust [bell-labs.com], he says it isn't enough to check the source code, you also have to check the compiler, the output from that compiler, and I would add, in the context of a voting system, everything that is or could be in the system/network.
I would like to respectfully disagree here. Your comment can be too easily be summarized to "well, if you can't solve every possible flaw, you don't have a secure system, and so there's no point in trying, if they're all insecure anyway, any system is as bad as any other."
This belief is flawed. Even if you can't prove that there isn't any possible attack, it is nevertheless true that there are better systems and worse systems, and you don't want a worse system. Being able to check the source code-- and
Re: (Score:3, Insightful)
"if they're all insecure anyway, any system is as bad as any other."
It is true that all voting systems are open to fraud, however rigging a paper election is orders of magnitude more difficult than rigging an electronic election simply because of the number of people needed to implement the "hack".
With
Re: (Score:3, Insightful)
Suppose we had such a situation as you suggest and thousands of reviewers pawed over the code making it "as good as it gets". How do you verify the code that was reviewed is the code that is running?
If the code that's reviewed is not the same as the code that's running, this is in itself evidence of fraud. You don't need to look for a back door in this case; you don't need to even know what the code that's running does, you have already shown fraud.
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:5, Interesting)
Re: (Score:2, Insightful)
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:4, Insightful)
Because the people with *physical* access aren't (usually) the people trying to hack the systems.
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:4, Interesting)
Things like financial recordkeeping and stock trading are relatively steady, constant, loads that can be handled in a fairly small number of highly centralized locations, for which people are willing to pay a great deal of money.
Voting is a highly bursty and uneven load, spread across tens of thousands of sites and systems, for which people don't seem willing to spend all that much.
It is definitely true that voting machines can be made secure in theory(and we know that they could be made far more secure than the are: not only are the current models not good enough, they aren't even as good as current generation consoles); but the analogy between voting systems and financial systems is weak and misleading. More accurate might be an analogy between voting machines and point of sale systems. Unfortunately, those are plagued by card skimmers and similar, despite the fact that they have the advantage of it being possible to calculate the "correct" outcome. It is fairly easy to detect and rectify fraudulent transactions just by looking at financial records. You can't do the same with votes.
Re: (Score:2)
The only thing a e-voting machine should be used for is printing a paper ballot.
Count the paper ballots.
You also have to make sure it prints completed ballots when and only when a voter is present and voting, once per voter.
And only when the voter has made all his choices and warns the voter if he leaves without completing the ballot submission process.
Paper ballots are ABSOLUTELY safe! (Score:4, Insightful)
Yeah, right! NO ONE can cheat in an election with paper ballots! The concept of a corrupt government did not exist before the invention of electronic voting.
*BULLSHIT*
Reading TFA: This is done by prying just one ROM chip from its socket and pushing a new one in, or by replacement of the Z80 processor chip. We have demonstrated that this ``hack'' takes just 7 minutes to perform.
Do you want to make a bet? Let's see how many paper ballots I can stuff in 7 minutes, given the same level of physical access one needs to change a chip in a computer. This means I can open a box, right? It doesn't matter if the box is electronic or not, it should have a padlock. If I can open the box, with no one noticing, it doesn't matter if the content is electronic or paper.
The intrinsic safety of electronic voting comes from the agility in counting. Counting a paper ballot box takes much longer than it takes to fill that box with a totally different set of votes. By the time you have counted, recounted, and counted again those paper votes, they could have been substituted a dozen times.
Re:Paper ballots are ABSOLUTELY safe! (Score:5, Insightful)
Lets change your bet a little bit. The 7 minutes are 2 days before the election. You get private time with the ballot box, I get private time with the voting machine.
What can you do to the ballot box that wouldn't be noticeable 2 days later and still affect the vote?
I was an election judge for Boulder County in 2004. Part of my duties as the head election judge for the precinct was to make sure that there was noting in the ballot box and seal it. From that time until I handed the box to the county officials, it was not left in the presence of any single person, so nobody would have 7 minutes during the election day.
You can't stuff the ballot box 2 days before the election with nobody being able to notice.
**THAT** is what they are complaining about. The machines were left in publicly accessible areas for days before the election. Replace one of the chips with that 7 minutes, and it would take a very detailed examination to notice the problem.
Re:Paper ballots are ABSOLUTELY safe! (Score:5, Insightful)
And I was an election judge for Itatiaia, in Brazil, in 1998. I had more or less the same duties as you had. It was an electronic box.
I inserted a flash card with the software, including the operating system, which was given to me by an officer of the electoral court minutes before the election started.
If you can corrupt a representative of the judge who is responsible for declaring if the vote is correct, does it matter if the box is electronic or paper?
You are ready to swear for the honesty of those county officials, yet you don't trust the people who handled the electronic box before the election?
That's *WRONG*, no matter if the ballots were paper or electronic. No part of an electoral process should be left unattended at any time at all.
To sum up, you have absolute trust in the paper voting system, because you have absolute trust in the way the paper ballot was handled *AFTER* the election, but you mistrust the electronic vote because you mistrust the way the electronic box is handled *BEFORE* the election.
For me, both systems can be corrupted, but the electronic system is better because, given the same level of precaution before and after the election, the electronic system gives faster results. To cheat, you need physical access to the system, so the quickest system is safer.
Re: (Score:3, Insightful)
Not really, no.
What about when the stuff is in storage? What if someone replaces the processor with a near duplicate that changes the voting output when certain conditions are true (time, the ID of the election, n
Re: (Score:2)
Except that it is really hard to corrupt a paper ballot before the election. Faster vote tallying also means faster vote tampering. I don't know why you think fast processing means safe. Paper voting isn't perfectly secure. It is just that almost all tampering will leave evidence. That isn't true at all for pure electronic voting
Bravo, my sentiments exactly!
Paper is hard to corrupt before the election, yet, it has been done. I think the real problem is that we the people care to little about the security
Re:Paper ballots are ABSOLUTELY safe! (Score:4, Interesting)
You obviously have no idea how a regulated manual system works wnen the government is corrupt and already using force to sustain it's rule. In a manual system, there are volunteers from all parties attending the ballot process, including, sealing of empty ballot boxes, handing out of the ballots, monitoring the filling of the ballot boxes, unsealing and emptying of the ballot boxes, and counting of the ballots. Normally the voting and ballot counting occur at the same location avoiding transport of ballot box problems.
In addition to the volunteers from all parties doing all the work, their are paid officials who supervise and monitor the activities of the volunteers. In a lot of countries the election takes place on a Saturday, to ensure easy access for volunteers and well as of course for voters and enabling the use of the numerous school halls available around most countries for the voting and vote counting process.
So cheating is enormously difficult and only really happens in regional areas, where the volunteers are all from one party and the election official is also corrupt, catch is only one or a handful of polling booths out of thousands is corrupted and, in reality only has negligible impact upon the election as a whole (and the risk is huge and the penalties severe).
With electronic voting machines and electronic vote counting machines of paper ballots, all with secret unverifiable code, as well as unverifiable electronic chips (how many are removed from their plastic housing and microscopically scanned and analysed), the whole election can be rigged and the electorate has absolutely no means by which to verify the validity of the electronic election process and even with receipts of electronic votes, the winning party will simply deny the chain of legal possession of those receipts to verify their authenticity. Only a fool would think that stuffing one election box at one polling booth, would compare with hacking the voting machines, the transfer of the output of the vote counting machines to the data analysis location and of course the data output of the analysis device.
Elections are all about people governing other people, so people should be fully involved in the control of and verification of every part of the process. The election is the single most fundamental part of any democracy and every step should be taken to ensure it's safety and validity, from voter registration to the final vote tally.
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:5, Funny)
Nonsense. The vast majority of computer security experts agree that electronic voting machines are the safest, most secure way to conduct an election, and that they are virtually immune to tampering or forging of votes.*
*results of a poll of 1000 experts conducted using Diebold voting machines. 93 of 1000 said electronic voting was not secure, 1237 out of 1000 said that it was.
Re: (Score:2)
Or the people, who count the paper ballots... I'd rather trust a machine, however imperfect...
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:2)
Anything else means you have to trust the voting machine, or the people who verified the voting machine.
Because the people counting the paper ballot are implicitly trustworthy? For that matter, can you trust people to vote intelligently? The technology is just a piece of equipment. Trust is something we place in people, or not. The machine has nothing to do with it.
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:5, Insightful)
Re: (Score:2)
Absolutely. Would you trust your credit card number to SSL if you knew there were hundreds, maybe thousands of professional hackers trying to sniff it?
Re:"E-Voting Machine Security" like "Microsoft Wor (Score:5, Insightful)
Absolutely. Would you trust your credit card number to SSL if you knew there were hundreds, maybe thousands of professional hackers trying to sniff it?
You mean there aren't?
Re: (Score:2)
if electronic voting (Score:5, Insightful)
could be made 100% secure, foolproof, etc., it should still not be used
simply because of the PERCEPTION of what happens to your vote in electronic voting
it is a black box. your votes go in, sausage comes out. meanwhile, a piece of paper has no secrets. it stays in a box, it can retallied. it can be messed with and falsified and burned, sure. but not with such ease and not in so many quick secret and immensely powerful ways electrons or magnetic marks on a disk can be messed with
all nations should use paper ballots, doesn't matter how rich they are. joe schmoe needs to touch and feel and smell his vote. voting machines and electronic voting represents a black box system, and therefore represents too much fundamental distrust. distrust undermines the legitimacy of democratically elected governments in the eyes of the people
it is not good enough that joe schmoe vote in absolute security and privacy and integrity. joe schmoe must also BELIEVE that. but in an irreducibly black box system, distrust is inescapable
electronic voting is the greates threat to democracy, ever. no ideological system or intolerant set of beliefs can undermine faith in democracy more than a method of tallying votes that the technofetishist loves, but the general populace views with suspicion
you don't need to say "gee whiz" when you vote
we need to end electronic voting, in the name of strengthening democracy
Re: (Score:3, Funny)
joe schmoe needs to touch and feel and smell his vote.
This certainly explains a lot. Apparently this is how we keep winding up with Republicans in office. If I had to sit and count poo streaks on a paper ballot all day I would demand E-voting too. There is clearly some confusion about what the booth is there for and what to do with the paper provided.
LOL (Score:5, Funny)
actually, i was referring to a scratch and sniff voting system
"hmmm... obama"
scrathscrathscratch
"yay! smells like jesus and cupcakes! ok, now... mccain"
scrathscrathscratch
"uggh. smells like depends and denture cream"
Re:LOL (Score:5, Insightful)
Every time I get upset about the tremendous disaster that our modern voting is with the rampant election fraud I remind myself... I am getting upset over the fairness of a system that will only let me choose between two criminals for who should be the leader. It seems to me that getting up in arms about the whole voting trainwreck is pretty stupid considering what we are demanding our votes get counted for. When I am faced with a choice more complex than liar/asshole vs asshole/liar I will be more concerned about how my vote gets counted. As it stands now I can rest assured that no matter what I do my vote would go towards putting a liar and an asshole in office.
I mean really now...its like being lost in the woods and choosing if you want to wipe the shit off your ass with your left hand or your right hand. Which hand you choose is pretty tangent to the fact that you are lost in the damned woods. Seems to me we should be a little more concerned about getting out of the woods than to be upset about which hand got shit on it.
Re:LOL (Score:5, Interesting)
Aren't there more than two candidates? Can't you vote for the others instead?
Apparently in the past election 60+ million voted for X and 59+ million voted for Y.
But 80+ million didn't bother to even show up.
Think X and Y might notice if the 80+ million voted for Z?
I bet X and Y might also notice even if the 80+ million walked up to the voting booths and voted "none of the above" and thus "spoilt" their vote.
At least the foreign media would be reminding them of it e.g. "Mr President, how can you say you have support of the people?".
Re:LOL (Score:5, Funny)
I am torn between sort of a dusty smell or a 2000 year old zombie smell. I guess it depends on your take on the story. Even best case scenario of coming back non rotted they didn't exactly bathe much back then and washing feet was a big damned deal. No matter what, I can't imagine Jesus is a good smell. (love or hate the fan club, regardless of the divine/not divine, the J man was a cool guy...and thankfully he was a Jew so probably has a good sense of humor so I don't have to sweat it much if he was divine)
you don't know what jesus smells like? (Score:2)
you must be a communist muslim supported by jewish money
like mccain
(i'm being funny, but yes, there are people who actually think like this [nytimes.com])
Re:if electronic voting (Score:5, Insightful)
I think you have the perception most people have of computers wrong.
Most people think computers are incapable of being incorrect. Microsoft is trying hard to change that, but they are getting less effective.
If the computer is wrong, it must have been something that the user did incorrect. "I shouldn't have clicked on that link to that page", instead of "The browser is broken, it shouldn't have been vulnerable to the stuff on that page"
I agree that paper ballots should be used, but most people think that if a computer is involved it will not be incorrect.
Re: (Score:2)
Most people think computers are incapable of being incorrect.
I strongly disagree, and I'll explain why.
Microsoft is trying hard to change that, but they are getting less effective.
Heh :) A large portion of people remember the days of windows 95 and apps crashing all over the place, and the infamous blue screen of death. Even in XP you run into the neat dialog box "[App crashed! Send us your private information yes-no?]".
If the computer is wrong, it must have been something that the user did incorrect.
True some of the time. If the user can connect in their mind something they did with an undesired outcome, the outcome will act as a punishment [don't you love B.F. Skinner?] and they will learn to not do those things. Yo
Re: (Score:3, Insightful)
People have put their trust in black boxes for a long time. I'm neither for nor against electronic voting, but I do think there ought to be a paper tr
no (Score:3, Insightful)
people can use computers, television, and the car, but they don't have to trust them. in fact, they don't. the tv has the biased media on it. the computer spies on them with cookies. the car is always breaking down. sure, they still use thes tools, but that's not a question of trust going on with these things in the same way it is going on with their voting system. you do not have the same relationship you have with your tools that oyu have with your social environment
a government is a purely human construc
I disagree. (Score:2, Interesting)
a government is a purely human construct. its all about social structure and where you fit into it. its all about trusting or not trusting the other people around you.
Yes, the
Re: (Score:3, Funny)
"people can use computers, television, and the car,'
But not apparently, capital letters.
Re: (Score:2)
Electronic voting gives freedom to those with disabilities. Electronic voting gives instant results. Electronic voting allows for things like Internet voting. Electronic voting could eliminate all the wa
electronic voting in brazil is wrong (Score:2)
electronic voting in any democracy is wrong. it is nothing about americans or brazilians, it is baout putting your trust in a system which is more easily exploitable
do you think electornic voting is more or less exploitable than paper voting?
if you think it is less exloitable, you fail at logic
assume system a is more complex than system b. out of a simple logical conseuqence of it being more complex, it has many more avenues for exploitation in it
you need the cooperation of dozens of campaign workers to mak
Re: (Score:3, Insightful)
It's what I said. You aren't arguing about it. You have made up your mind and are on a religious rant against the antichrist, I mean, e-vote. You aren't making coherent thoughts. You are arguing one point one time, and one the other. "No one can trust it" "OK, Brasil trusts it, but the entire country is wrong to do so." You'll change your statements to mold to whatever counter-arguments someone comes up with. Pick a fact, and I'll prove it wrong, but I c
2 things: (Score:2)
1. it helps when criticising someone to not commit the same crime you criticize them of. i leave it to your vast superior intellect to understand what i am talking about (snicker)
2.
Re: (Score:2)
Assertion without support. Paper ballot A is more complex than paper ballot B? The system to generate the ballot may be, but the ballots themselves are both paper ballots, but one is mechanically generated for uniformity, and you are claiming that is less reliable than one that a person tries to mark, which is proven to be unreliable.
b. observation: electronic voting is more complicated than paper voting
A false statement. Walking up to a com
(mouth hangs open) (Score:2)
congratulations
you've utterly defeated and humbled me beyond the pale
i stand here in abject pain at how thoroughly you have spanked my rotten ways
i am now reeducated:
(drum roll)
a paper and a pencil are more complicated than a computer kiosk
(!?)
BWAHAHAHAHAHAHAHAHAHAHAHAHAHA
you sir, are a fucking retard, beneath even a consideration of intellectual charity
adios, stubborn moron
Re: (Score:2, Interesting)
I've heard people cite the ATM network when they talk about big, distributed hardware/software systems that anybody can access, and it works pretty well. It's a false-equivalence though. You get a paper statement at the end of every month (or online, immediately) which provides the paper trail. If my account g
exactly. thank you (Score:2)
you are not a luddite if you oppose electornic voting. you are simply someone with a better grasp of what is exactly being risked and what is exactly being gained. as in: trust and integrity in your government being risked, and slight pointless convenience being gained
electronic voting is the greatest threat to democracy in the world today
Re: (Score:3, Informative)
Surpisingly I agree with you on this one.
Heres how we do it in OZ.
All paper ballots. Voters must be on the electoral roll 2 weeks before the election, at a minimum.
At all times opening and closing of ballot boxes is done in the presence of representatives of the political parties and the electoral commision.
When you go to the polling station, you are asked your name and ID, which is then marked as voted on the electoral roll.
Votes are then counted under the eyes of party scrutinneers from all parties that
Actual report: (Score:5, Informative)
http://coblitz.codeen.org/citp.princeton.edu/voting/advantage/advantage-insecurities-redacted.pdf
Elections of 2010 (Score:3, Interesting)
My first thought was "what's the point of publishing this now?"
Everyone (yes, even the clueless people in charge) knows that electronic voting machines are SNAFU, they just didn't have the time/money to do anything about it this election cycle.
2010 should be much different.
Hopefully they'll take the next 2 years to do some criminal investigations into all the substituting and patching of firmwares while they're at it.
Re:Elections of 2010 (Score:5, Insightful)
Hardware Work Around (Score:5, Insightful)
Re: (Score:2)
I miss those too. Though I never got to use one, I went into the booth with my parents while they voted. How were the votes stored on those things?
Individuals' options? (Score:2, Interesting)
Re: (Score:2)
I've seen "vote absentee" floated as the answer, though I'm not sure that works everywhere. I'm also not sure I consider that more reliable (what if it never gets there? how can I prove it?).
ES&S has the same crap, as shown by UCSB (Score:5, Informative)
California ordered a review of all the machines used in the state last year. They would give access to university security labs to one manufacturer's machines at a secure location. I mean the machines were held in cages over night and there was controlled access for only the researchers, etc.
They were asked to evaluate the machines.
UC Santa Barbara did ES&S, and their analysis is here. [ucsb.edu]
They also have a short video on the subject, here it is on youtube [youtube.com]
In short, all the machines were utter crap. The "seals" can by bypassed by bending some plastic. The locks can be bypassed with a screwdriver. Plus the software is susceptible to viruses, and they managed to make the machine vote for whoever they wanted. Even though all the machines have the VVPT (voter-verified paper trail).
Re:ES&S has the same crap, as shown by UCSB (Score:4, Interesting)
I've done work for ES&S at a couple of different points, and can point out several things. First, the reports are mostly accurate (there are a few points which I'd disagree with, but there are a number of legitimate concerns in there). Second, no system is secure without physical security, and a number of the attacks ultimately come down to the state needing to ensure that these machines are treated as such. States are very lax about this, and that is a serious problem (personally I think precinct counters should be there to validate the ballot for the voter and give feedback/warnings or errors, and all tabulation should be done via high speed central scanners. The tabulation of the precinct counters might be kept as checks against voter fraud during ballot transport). Physical security is the single most important aspect of any voting system, with enough physical access any security system can be beaten (see every DRM or anti-cheat system for gaming). Unless it's fairly far into the videos, the video stuff is actually about the Sequoia not about ES&S systems. The PDF report linked to does include several chapters about the ES&S systems (all of part II).
Most of those that are dealing with the M100 and the M650 should be dealt with with the next generation of hardware/software for the newer paper scanner products (don't want to comment on the others as I didn't work on or with any of those). Not sure what ES&S's view is, but my personal view is that all DRE machines should be shipped to the nearest blackhole for permanent storage.
There is also some help in addressing some of the concerns about the review of proprietary software. Other then the Java compiler and the cryptography pieces (which are required to have FIPS complaince that most OSS products lack due to expense), all of the software is Open Source and is compiled during the system builds. I believe only one or two libraries aren't compiled from scratch on the machine (the commercial crypto tools, and the Sun JDK). I wouldn't be shocked to find out that OpenJDK is compiled on some future release. Every tool and/or line of source used to build the system has an MD5SUM, and a SHA1SUM along with the external site the software was retrieved from. Other then the crypto and the Java tools, all of the tools are built from source (a LiveCD distro with a minimal dev environment to build GCC, glibc, make, perl and a couple of other tools are bootstrapped into a chroot). It is fairly straight forward to use walk into a secure room and a blank PC with no software on it and end up with 99% of the software that ends up on the M100 replacement product. Two embedded compilers require windows that are built separately.
Another issue is that resolving issues quickly on election day is internally an important quality to the company. There are some security aspects that would be a disaster if the slightest thing goes wrong. With a deployment that large, by a mostly volunteer group, there are always significant mistakes and "proper" security would get in the way. The inability to do field firmware upgrades, because somebody in the state failed to upgrade the hardware before it shipped would be a disaster. It happens in every election despite all the procedures and guidelines. So part of the "only one key" thing falls into this category.
Finally, the most serious problem with all of the software is that no programmer in their right mind can deal with the various rules and obligations for VVSG compliance. I'd spend a day writing, unit testing, and writing "normal" documentation. Followed by at least a day or two of writing all of the required documentation, none of this included the stuff we had tools to auto-generate. I had to write the code first and document afterwards because it was hard to be concise and see all of the related code at a time when it was fully documented.
They require the generation of inane and superfluous documentation, and are bureaucratic and dogmatic about enforcing the rule co
Re: (Score:3, Interesting)
You're right, the ES&S system was for a different study. The one presented is Sequoia. That's what I get for posting tired ;)
Thank you for the post, it's great to hear about how the companies are run. Don't take the rest personally, it's a reply to you but addressed to your (former) bosses:
Though most of the difficulties you talk about are things faced by any large project. File management and documentation? Please. All projects have to handle this. Apparently the Sequoia system is also a hodgepodge of
Simple paper ballots, overseen by observers (Score:4, Insightful)
Simple paper ballot. Allow observers from all interested (political) parties to monitor the voting station and the count.
Presto, solves verification of the internals of the not so obvious "voting machines". Voting machines aren't truly verificable.
Re: (Score:3, Insightful)
Why not? What if the "machine" was a huge wheel with a counter for each candidate. There is a back room that has every candidate represented, and they verify that for every person that enters (they can't see the person) that the wheel only moves one slot. The person voting picks who they want and watch the wheel increment by one, then leave. That's a "machine" that is truly verifiable, isn't it?
And what about a machine that casts the votes, but doesn't tally t
If I didn't know any better (Score:3, Insightful)
You know, if I didn't know any better, I'd say that this was the same company as Diebold.
Oh, wait, it is ...
Re: (Score:2)
You know, if I didn't know any better, I'd say that this was the same company as Diebold.
Oh, wait, it is ...
No, it's not; it's the other one. (Diebold is the same as "Premier Election Solutions".)
cf info at eff.org [eff.org]
(blackboxvoting.com [blackboxvoting.com] isn't a bad source of info, either).
Optically-read Paper Ballots (Score:4, Informative)
Hell at this point.. (Score:2)
Ya know, I don't think I've ever voted for anyone that has won in my life. I'm so agaisnt everything that is going on.. Bush, Obama, McCain.. whatever.. none of these idiots believe in my liberty.
Why not just let politicians vote for us.. its cheaper and as far as I can tell it produces the same results. Why bother keeping up the charade that the people control this country?
Re: (Score:2)
Uh, politicians _do_ vote for us. This isn't a democracy, it's a republic. Sure, most states require them to vote the same way we do, not always, and there have been cases where they haven't.
An obvious question... (Score:5, Insightful)
Re: (Score:2)
Re: (Score:2)
OK now... 1, 2, Uh what comes after 2? *asks bystanders* One thousand and fifty two? OK.
Re: (Score:2)
My guess would be that we are either very comfortable with the way things are, or we are to stressed out with the day-2-day stresses of our chosen lifestyle to bother with any possible fiasco that could occur - while the powers that steer us are corrupt and only concerned with their money and taking more of ours.
Re: (Score:3, Funny)
One argument I heard, and you won't believe this:
"Because then the recounts would take forever, and we might not have a valid result by January with all the court cases as a result."
I don't remember which corner that came from, but it sounds as if it would take weeks to count a couple 1,000 votes in any contested districts.
20 minutes in (Score:5, Informative)
torrent for the gigabyte video file (Score:4, Informative)
Here you go, a torrent for the 1 gigabyte hi-res video:
advantage-insecurities-exhibit-hires.mp4.torrent [homeunix.net]
Cook County uses Sequoia Machines (Score:2)
And they don't use this Machine but they use other ones and the voter card activator does have a HD, USB ports for the touch screens usb keys that the votes are on as well a cartage port for the Optical scan reader. It also does have a Cell phone modem in it and the ZERO tape does print its IP address.
Hmm (Score:4, Interesting)
An electronic voting machine should be simple. Why the f- are they even using an operating system at all? Wouldn't a stripped down the bone OS do the job? How about using DOS?
(before you laugh or say to use free software, the reason I say DOS is there is ZERO chance someone 20 years ago inserted code that would corrupt a voting machine)
Also, with DOS you could easily verify the md5 of the OS image.
I say use DOS, and write the vote counting program in terminal graphics mode, with those colored ASCII characters for a GUI. A SIMPLE GUI. The feature count on this program should be limited to the crucial things only.
And NO network access. The only way to count votes should be to physically gather all the flash memory cartridges in one place. Each cartridge would have a ONE TIME PAD encryption lock. There would be a central "vote counting" terminal that would be the only machine in the county with the other copy of the one time pad used.
Why so backwards? (Score:5, Interesting)
Funny I think that people are so cautious to trust computers here, but they're fine for everything else. Just make it open. We can gain some advantages.
-Immediately before voting, you are handed a number. How we generate these numbers is up for debate. Perhaps they are centrally generated and serial. Perhaps a hash of name + DOB + other stuff. Each choice here opens different doors.
-Barcode equivalent to said number must be scanned at the machine. Number must also be entered on an onscreen key pad.
- Number + voting choices + timestamp + voting machine id are stored in a central database. Immediately. Nothing local.
-You get a receipt with your Number + voting choices + timestamp + machine ID. It also has these other handy value on there. A digital signature, created by said central authority with its private key. The public key is well known long in advance.
-After the election, the entire result set is made available for download. Yeah, a recount is a big fucking deal. We have these neat machines that are good at math. The bigger deal here is that if you check the database after you voted and the entry for your number doesn't match, you scream bloody murder. If you don't trust the machine, any party can verify the central authority's signature.
-But in addition to 'any' party, it is critical to have a non-networked verification appliance, which does nothing but verify the central signature for you before you physically leave. If you scream bloody murder at this point, we can consider the plain-text part of the receipt trusted. You obviously couldn't have faked the entire receipt while being watched by everyone. More on this soon.
Nice huh? Let's recap some advantages here:
-You can verify that your vote was counted and correctly
-You can't determine who voted for whom, except yourself.
-The receipt actually means something
Let's elaborate on that third point.
There are several means of lying to you, which can't easily be solved without adding machines into the mix
-What if the receipt says you voted for X but the machine recorded you as voting for Y? This is as good as pressing the wrong button. The signatures will both be valid. But if the plain-text portion shows the wrong candidate, you'll notice and scream. If the plain-text portion doesn't match the the central signature (the one most directly relevant to proper recording) you will catch this at the non-networked verifier. The receipt can still be trusted having not left the polling place, so you will be allowed to vote on another machine, as meanwhile the machine you previously used is marked for a serious investigation...
-What if the central authority records whatever it wants but produces a normal signature? The receipt will be considered entirely valid and endorsed. People will notice quickly as they check the database from home. You have a paper trail that can be trusted. What if the signature is bogus? People notice before they leave the polling place.
Up to this point? Criminal negligence bordering on treason. Open source needs to step up.
What happened to testing *before* deployment? (Score:3, Interesting)
To me the messed up thing in all this e-Voting stuff is that the counties are using e-Voting machines that are shown to be hackable... implying that they are using the machines without fully testing them. That is, they have decided on the machines (presumably after a convincing marketing presentation), and only *after* using them, have people come along and said, hey, these aren't safe.
In usual situations, a system would be tested for hacking *before* being deployed. Until such time as it can be independently declared safe, the old, trusted system would remain in place. This rule applies to every major server in the world, why does it not apply to something as fundamental as VOTING?
We shouldn't just be mad about hackable eVoting machines, we shouldn't just be mad at the companies that make them, we should be mad about bad decisions being made by those in power to use these machines without properly testing them.
(By "we" of course I mean people who actually have to use e-Voting machines.. myself, I'm from a place that banned them [slashdot.org], thankfully.)
Re: (Score:2, Interesting)
True, the significance of one vote is not much when there are many voters but it's pretty obvious how the ammount of power one vote wields goes up when the amount of voters goes down.
Re:So what? (Score:5, Informative)
"That's quite a lot of fud with not much to back it up with."
damn lameness filter, the 9 megabyte pdf is not FUD, it was a court ordered analysis of the voter system used in new jersey. http://coblitz.codeen.org/citp.princeton.edu/voting/advantage/advantage-insecurities-redacted.pdf [codeen.org]
NOTE REGARDING REDACTIONS. As paragraph 1.1 and Appendix L explain, this research was conducted pursuant to a Court Order by the Hon. Linda Feinberg of the New Jersey Superior Court. Sequoia Voting Systems filed a motion alleging that certain parts of this report contain protected trade secrets. Plaintiffs dispute Sequoia's contentions. Judge Feinberg has expressed her intention to preserve Plaintiffs' objections until the time of the hearing when she will rule on the merits of Sequoia's claims of trade secret. We are confident that the Court will then permit release of the full, unredacted report. In the interim, the Court encouraged us to release the report with redactions. Paragraphs 19.8, 19.9, 21.3, and 21.5, as well as Appendices B-G, are redacted in this release.
Re:Where are these machines used? (Score:5, Informative)
Check the map.
Re: (Score:2)
Link [dvice.com]
Check the map.
Whose scripts do I need to enable to see the map?
Re: (Score:2)