> To keep the published record anonymous, ballot scanners shuffle the electronic records randomly before releasing them
So they were never secret in the first place.
I have never understood the desire to have voting machines when a paper ballot works just fine. We tried electronic voting in three municipal elections in 2008 and courts ended up invalidating the results due to horrible usability issues.
They are using paper ballots. The problem identified here comes from the counting process, and hand counting with similar audit records could end up having the exact same problem if the count audit ledgers were shuffled by similar means. The ballots are shuffled in the audit logs because it is known that a time/order correlation problem exists (ballots tend to be counted in the order they are cast), but the reason that Dominion uses a poor method of randomization, and that some (but not all!) election administrators include count sequence numbers in their publicly released records at all, seem to come down to a lack of care.
Diego Aranha had found an exploit with brazilian voting machines back in 2017. They scrambled votes whenever every vote was cast using a CSPRNG, but initialized its seed with the time the voting machine had been turned on (rounded to the second), which due to voting protocols at the time meant you only had to have one person vote a specific way and bruteforce 3600 orderings to find that person's vote and destroy ballot secrecy for everyone else who voted on the same machine.
Seems like this is the same mode of failure, which is strange considering diebold made the brazilian machines back then and should have fixed that.
Wow, a Diebold voting machine with security vulnerabilities? You think they would stop making so many silly mistakes after two decades[0] of making faulty voting machines.
What a bunch of silly clowns with their silly little whoopsies! Maybe they'll get it right someday.
The way this sort of problem has been fixed in Texas since 2024 is to require that all ballots be sequentially numbered -- that is, they arrive at polling locations in packs of 50 or 100 ballots, each pack having sequentially numbered ballots, but the presiding judge takes 10-20 at a time, signs them, then shuffles them, places them with the serial number facing down towards the table, and voters get to pick one at random when they check in.
"In October 2022, a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots. Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing. However, the algorithm by which the machines generate this random number is actually deterministic and can be exactly reversed to identify the sequence in which ballots were cast.
...
Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."
---------------------
1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.
2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)
I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.
They are using paper ballots. GA for example has since 2020. Several methods of auditing the counts of paper ballots require some tabular record of the contents of the ballots (so that it's practical to perform risk limiting audits on random samples), and the problem here originates from the process by which that tabular record is produced and the way it is made public. The same problem could exist in a hand counting process with risk limiting audits.
Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.
If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)
This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.
(If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)
> Either upgrade your pseudo-RNG
It seems grossly negligent that a voting machine is using a non-CSPRNG.
> Dominion has not shared any details about the new PRNG.
Just remembered another report about a vote-counting machine with a security problem. Can't remember enough details to find the original report, but the guy found that the QR code the machine was scanning to read the vote did not have any kind of replay protection, and that although the ballots were printed on special paper, the machine did not have any verification of the paper being fed into it, and would accept plain photocopy paper. Meaning that all that would be needed to "hack" that particular machine, if the report was accurate, would have been to get hold of a ballot belonging to someone you know voted for your preferred candidates, and have it for 20-30 seconds of secrecy, long enough to make one photocopy before giving it back to the voter. Easy to do if the voter and the poll worker are in cahoots. And then you can run off 50, 100, 250 copies of that ballot and stuff the ballot box. Would be caught on a recount... probably. But it shouldn't be possible to do that sort of thing in the first place.
The simpler the machine, the better. As I said in my other comment, I'm about ready to go back to locked wooden boxes myself, opened and counted in full view with cameras rolling.
As long as the official count is actually done, then that's fine... but there's a natural human tendency to want to skip unnecessary work. And any polling place where the workers get lazy and just rubber-stamp the machine's counts have now made it possible for someone who hacks the machine to get away with it.
The machines should be kept air-gapped, not connected to the Internet, and all that. But again, human nature kicks in. There have been some poll workers who swore under penalty of perjury that in their polling place, there had been election machines that got an over-the-wire software update on Election Day. That's just... all kinds of wrong, if those reports are accurate. It doesn't prove cheating, but it does prove that whoever was in charge of that polling place should be fired. Because part of the job is making sure everyone knows the results are valid and accurate, and having voting machines connected to the Internet goes directly against "hey, you can see that no hacking is possible here". Doesn't matter how much the machine's manufacturer promises their machines are unhackable, the machines should not be connected to the Internet at all once they are actively being used for voting.
At this point, I'm ready to go back to paper ballots and a locked wooden box (kept in public view, and publicly verified to be empty before locking it up) myself. The simpler the solution, the better, is what I'm arriving at.
> this allows you to know whether your neighbor voted, but never who they voted for.
There's probably an angle I'm not thinking of here, but imho, it's absolutely not John Q. Public's damned business what a person does or does not do on election day.
The practice of making public whether someone has voted dates back a very long time. There were practical reasons for it when it originated, and many of those remain valid today.
Originally, everyone in town knew most everyone else and could see them physically walking into the polling place. So long before electronic records were kept, the question of who voted was public information.
Even today, I run my local polling station and I know and recognize a significant portion of the voters in my precinct.
The fact that the list of who votes is made public protects against several kinds of abuses. It goes a long way to protect against "dead people voting" and other kinds of ballot box stuffing if the list of voters is public so anyone can review it and potentially catch such abuses.
The value of transparency goes above and beyond protecting against abuses (for which there are other methods) - it also provides assurance to the public that there is protection against those abuses, and that those abuses are not taking place.
i.e. 'Justice must not only be done, but must also be seen to be done'
I once read an account by a poll watcher of her experience in 2012. She said that at her polling place, there had been a number of people showing up to vote on Election Day, being told they had already voted during the early-voting process, and swearing up and down that that wasn't true, that they always voted on Election Day and never voted early, and that whoever had voted in their name had done so fraudulently.
Now, in that particular case, the state (I believe it was Colorado though I'd have to find the article I read, and I don't remember where to find it any more) didn't require photo ID, so there was no way to prove that the people showing up on Election Day were the actual voters, as opposed to the cheaters. But this poll watcher's opinion was that they were the actual voters, and the cheating had been done by whoever had submitted ballots in their name days (or weeks) earlier. Given how many people she said this had happened to, I'm inclined to agree with her: it wasn't three or four people, it was (she said) something like one-third of the people who showed up on Election Day at that polling place.
That's a case where the fraud couldn't be repaired by knowing that it had occurred — the fraudulent ballots (if they were indeed fraudulent) had already been accepted, and it was impossible to go pull the ballot allegedly belonging to Joe Smith back out of the ballot box. But the publicly-available list of "who voted" did at least make it possible for the fraud to be detected in that particular case.
I personally do support voter ID, and for the same reason. Members of the public must be able to verify the process is happening fairly. It might be fair without it (fraud truly negligible), but it must also be seen to be fair. This would resolve so many controversies.
Likewise mandatory voting and private ballots (can cast a donkey vote) helps ensure the public people are not being paid to vote and that other biases are not coming into play.
I'm not entirely sure mandatory voting is wise in a country the size of the United States, but I'm with you on the voter ID and the rationale. I was shocked to learn that with everything else that requires photo ID, it's not required to vote in American elections. (At least, in some locations; laws vary from place to place). That just looks bad.
My personal opinion is that if people think they can benefit from cheating, a certain number will do so. It's just human nature. We're seeing more and more of this with LLM cheating on the rise in universities. So there's always going to be a certain number of people who want to vote fraudulently — after all, if the right person gets into office, it'll probably benefit you. Your taxes might be lowered, or your government handouts might be increased, or whatever other reason you have for preferring one politician over another. Preference alone does not mean that people will vote fraudulently: after all, most legitimate voters also prefer one politician over another. But the easier you make it to cheat, the more people will cheat successfully: among those who wanted to cheat but didn't, usually the only reason they didn't is because they couldn't see how to get away with it.
So photo ID to vote just seemed like common sense to me, along with other measures like ballot boxes kept in a publicly-visible place until they're opened, to help prove that nobody has tampered with them. (Read up on the 1946 elections in Athens, TN sometime — there, the fraud was being done by the sheriff and his cronies who would take the ballot boxes away, "count" them in private with no outside observers present, and announce that surprise surprise, the sheriff's crony had won the election again).
An added benefit of voter id is that by making it easy or cheap for one groups and difficult or expensive for an other (or choosing acceptable IDs that already have these characteristics) you can create some friction to make it more difficult for the wrong people to vote.
That is why I like voter ID if it relies on documents provided for free with minimal fuss.
The situation you describe, where the laws would be selected to make obtaining a photo ID (and thus voting) difficult for one group over another, would amount to a poll tax — which has already been found unconstitutional in the United States.
However, every US state I'm aware of (if you know of exceptions, please let me know) has some form of photo ID you can obtain for free. Usually it's in the same format as a driver's license, and obtained from the same place (the Department of Motor Vehicles, Department of Land Transportation, the name varies). There's a fee to obtain a driver's license, but a photo ID card (in the same format as a driver's license but marked "NOT LEGAL FOR DRIVING" or similar wording) can be obtained for free, by going through the same process as getting a driver's license (bring something to prove your identity, get your photo taken, wait for the card to be printed) but without taking a driving-skills test.
And before someone asks "what about the people who can't prove their identity"? Well, I can actually give an anecdote. I know someone who ended up in that situation: away from home for college, couldn't get her birth certificate or anything else, and needing to replace her passport that was lost. (She is American but had grown up overseas because of her parents' job, hence why she had a passport but no driver's license when she went off to college). She had quite a time of it at first, since every "prove your identity" requirement circled back around to another form of ID. But she was eventually able to get a fishing license just by swearing under penalty of perjury that she was indeed (name). With that in hand, she got another form of ID (I think a library card, though there my memory is iffy), then with two forms of ID she could get something else, and then eventually she was able to get that non-driver's ID card... and then was able to prove who she was to get her lost passport reissued.
That all happened nearly 30 years ago so I can't swear to the details. But the point is, photo ID cards are widely available, and it's normal to be asked for one. So as long as the law specifies that acceptable forms of photo ID include X, Y, and Z (where X, Y and Z are forms that most people would already have, and that are normal and in common use), and as long as at least one of those forms can be obtained without a fee (which as I said, is true in all U.S. states that I'm aware of, please mention any exceptions you know about because I'd like to know) then it will pass Constitutional muster.
This sounds like some third-hand anecdata. Trump et al (Chris Kobach, for one) have spent millions of dollars trying to find voter fraud and they have all come up with zilch.
And you have some memory of some account from someone 12 years ago in a state you can't remember saying that a third of voters had someone pretend to be them?
If this were close to true, it wouldn't be some blog post that you can't remember; it would have been a national scandal and it would have been something that we would never forget because the election stealer conspiracy theorists would never let it go.
Really, you should just delete this post as it's irresponsible and lacks any data.
The point I'm trying to make is that I agree with the parent comment to mine, which pointed out that transparency is essential to protect people's confidence in the voting process, especially when people are loudly claiming that someone committed fraud. The more open the process, the easier it is to prove that it's legitimate.
Yet so few people go the next step and say, “Let’s do away with the secret ballot itself.” It really is a recent invention, American democracy survived nearly 100 years before the Australian ballot was adopted. There are obviously concerns (vote buying, organized crime, etc) but they can be dealt with. And public voting would almost completely eliminate concerns about the voting process itself being subverted by a malign actor.
> There are obviously concerns (vote buying, organized crime, etc) but they can be dealt with.
I don't think they can be dealt with. But I'm willing to listen to your ideas. How would you deal with vote buying? How would you stop the scenario where a guy says "I'll give you $1,000 if you vote for candidate X" (or "I know where you live, I'll break your kneecaps if you vote for candidate Y")?
Vote buying/intimidation is just too big a vector, IMO. I would never accept that risk. It's transitive too - you can pay/intimidate the people who enforce the no paying/intimidating rule.
I suspect the missing angle is that people are more likely to trust claims made to the public if, in principle, those claims could be verified by the public.
Of course it's pretty impractical that a bunch of concerned citizens might gather together and check the published data against how they each remember voting. But preserving the possibility in principle makes it easier to trust the published results. It gives a would-be deceiver yet another thing to worry about.
Its a trade-off I'd have opted into had I been asked. Though I'd feel a lot better about it if I had been asked.
I was thinking the same. It's not as if visibility into whether someone voted or not has driven voter turnout significantly. Hell, I'd assumed this was private until I learned otherwise recently.
But it's such a specific structure, clearly there was an objective in mind when it was imlpemented.
> It's not as if visibility into whether someone voted or not has driven voter turnout
Actually, it does. If the party you are registered with thinks are a voter who might not make it to the polls, and this is a close/important election, then there is a good chance you will receive numerous calls and/or visits reminding you to go out and vote. However, if you show up on the list of people who have voted by mail OR if you appear on the registry of people who have already voted in person, then they will stop reaching out to offer rides and reminders.
> It's not as if visibility into whether someone voted or not has driven voter turnout significantly.
It's hard to say how much impact it has, but presumably there's a degree of social pressure when people are seen wearing/posting all those "I voted today" stickers.
The registry of people who voted has to exist because you're not allowed to vote more than once. That reason doesn't require the registry to be published, but it does require it to be compiled.
The biggest problem I see related to that is the marked haziness over what exactly has been accomplished. As best I can tell, this paper claims to have deanonymized primary election ballots that were cast during the early voting period. But it's written as if it was deanonymizing general election ballots cast on election day.
A Princeton researcher showed that a known flaw in Georgia's ballot scanners, still unpatched in places, lets someone with public records and cheap AI tools work out the order ballots were cast and potentially link them to voters. He recovered the order for nearly 99% of in-person ballots in 114 counties and says secrecy can be broken entirely in small ones.
So they were never secret in the first place.
I have never understood the desire to have voting machines when a paper ballot works just fine. We tried electronic voting in three municipal elections in 2008 and courts ended up invalidating the results due to horrible usability issues.
Seems like this is the same mode of failure, which is strange considering diebold made the brazilian machines back then and should have fixed that.
What a bunch of silly clowns with their silly little whoopsies! Maybe they'll get it right someday.
[0] https://www.wired.com/2006/09/e-voting-machine-an-easy-hack/
...
Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."
---------------------
1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.
2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)
I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.
Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.
If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)
This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.
(If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)
> Either upgrade your pseudo-RNG
It seems grossly negligent that a voting machine is using a non-CSPRNG.
> Dominion has not shared any details about the new PRNG.
The simpler the machine, the better. As I said in my other comment, I'm about ready to go back to locked wooden boxes myself, opened and counted in full view with cameras rolling.
The machines should be kept air-gapped, not connected to the Internet, and all that. But again, human nature kicks in. There have been some poll workers who swore under penalty of perjury that in their polling place, there had been election machines that got an over-the-wire software update on Election Day. That's just... all kinds of wrong, if those reports are accurate. It doesn't prove cheating, but it does prove that whoever was in charge of that polling place should be fired. Because part of the job is making sure everyone knows the results are valid and accurate, and having voting machines connected to the Internet goes directly against "hey, you can see that no hacking is possible here". Doesn't matter how much the machine's manufacturer promises their machines are unhackable, the machines should not be connected to the Internet at all once they are actively being used for voting.
At this point, I'm ready to go back to paper ballots and a locked wooden box (kept in public view, and publicly verified to be empty before locking it up) myself. The simpler the solution, the better, is what I'm arriving at.
There's probably an angle I'm not thinking of here, but imho, it's absolutely not John Q. Public's damned business what a person does or does not do on election day.
Originally, everyone in town knew most everyone else and could see them physically walking into the polling place. So long before electronic records were kept, the question of who voted was public information.
Even today, I run my local polling station and I know and recognize a significant portion of the voters in my precinct.
The fact that the list of who votes is made public protects against several kinds of abuses. It goes a long way to protect against "dead people voting" and other kinds of ballot box stuffing if the list of voters is public so anyone can review it and potentially catch such abuses.
i.e. 'Justice must not only be done, but must also be seen to be done'
Now, in that particular case, the state (I believe it was Colorado though I'd have to find the article I read, and I don't remember where to find it any more) didn't require photo ID, so there was no way to prove that the people showing up on Election Day were the actual voters, as opposed to the cheaters. But this poll watcher's opinion was that they were the actual voters, and the cheating had been done by whoever had submitted ballots in their name days (or weeks) earlier. Given how many people she said this had happened to, I'm inclined to agree with her: it wasn't three or four people, it was (she said) something like one-third of the people who showed up on Election Day at that polling place.
That's a case where the fraud couldn't be repaired by knowing that it had occurred — the fraudulent ballots (if they were indeed fraudulent) had already been accepted, and it was impossible to go pull the ballot allegedly belonging to Joe Smith back out of the ballot box. But the publicly-available list of "who voted" did at least make it possible for the fraud to be detected in that particular case.
I personally do support voter ID, and for the same reason. Members of the public must be able to verify the process is happening fairly. It might be fair without it (fraud truly negligible), but it must also be seen to be fair. This would resolve so many controversies.
Likewise mandatory voting and private ballots (can cast a donkey vote) helps ensure the public people are not being paid to vote and that other biases are not coming into play.
My personal opinion is that if people think they can benefit from cheating, a certain number will do so. It's just human nature. We're seeing more and more of this with LLM cheating on the rise in universities. So there's always going to be a certain number of people who want to vote fraudulently — after all, if the right person gets into office, it'll probably benefit you. Your taxes might be lowered, or your government handouts might be increased, or whatever other reason you have for preferring one politician over another. Preference alone does not mean that people will vote fraudulently: after all, most legitimate voters also prefer one politician over another. But the easier you make it to cheat, the more people will cheat successfully: among those who wanted to cheat but didn't, usually the only reason they didn't is because they couldn't see how to get away with it.
So photo ID to vote just seemed like common sense to me, along with other measures like ballot boxes kept in a publicly-visible place until they're opened, to help prove that nobody has tampered with them. (Read up on the 1946 elections in Athens, TN sometime — there, the fraud was being done by the sheriff and his cronies who would take the ballot boxes away, "count" them in private with no outside observers present, and announce that surprise surprise, the sheriff's crony had won the election again).
That is why I like voter ID if it relies on documents provided for free with minimal fuss.
However, every US state I'm aware of (if you know of exceptions, please let me know) has some form of photo ID you can obtain for free. Usually it's in the same format as a driver's license, and obtained from the same place (the Department of Motor Vehicles, Department of Land Transportation, the name varies). There's a fee to obtain a driver's license, but a photo ID card (in the same format as a driver's license but marked "NOT LEGAL FOR DRIVING" or similar wording) can be obtained for free, by going through the same process as getting a driver's license (bring something to prove your identity, get your photo taken, wait for the card to be printed) but without taking a driving-skills test.
And before someone asks "what about the people who can't prove their identity"? Well, I can actually give an anecdote. I know someone who ended up in that situation: away from home for college, couldn't get her birth certificate or anything else, and needing to replace her passport that was lost. (She is American but had grown up overseas because of her parents' job, hence why she had a passport but no driver's license when she went off to college). She had quite a time of it at first, since every "prove your identity" requirement circled back around to another form of ID. But she was eventually able to get a fishing license just by swearing under penalty of perjury that she was indeed (name). With that in hand, she got another form of ID (I think a library card, though there my memory is iffy), then with two forms of ID she could get something else, and then eventually she was able to get that non-driver's ID card... and then was able to prove who she was to get her lost passport reissued.
That all happened nearly 30 years ago so I can't swear to the details. But the point is, photo ID cards are widely available, and it's normal to be asked for one. So as long as the law specifies that acceptable forms of photo ID include X, Y, and Z (where X, Y and Z are forms that most people would already have, and that are normal and in common use), and as long as at least one of those forms can be obtained without a fee (which as I said, is true in all U.S. states that I'm aware of, please mention any exceptions you know about because I'd like to know) then it will pass Constitutional muster.
And you have some memory of some account from someone 12 years ago in a state you can't remember saying that a third of voters had someone pretend to be them?
If this were close to true, it wouldn't be some blog post that you can't remember; it would have been a national scandal and it would have been something that we would never forget because the election stealer conspiracy theorists would never let it go.
Really, you should just delete this post as it's irresponsible and lacks any data.
I don't think they can be dealt with. But I'm willing to listen to your ideas. How would you deal with vote buying? How would you stop the scenario where a guy says "I'll give you $1,000 if you vote for candidate X" (or "I know where you live, I'll break your kneecaps if you vote for candidate Y")?
Of course it's pretty impractical that a bunch of concerned citizens might gather together and check the published data against how they each remember voting. But preserving the possibility in principle makes it easier to trust the published results. It gives a would-be deceiver yet another thing to worry about.
Its a trade-off I'd have opted into had I been asked. Though I'd feel a lot better about it if I had been asked.
But it's such a specific structure, clearly there was an objective in mind when it was imlpemented.
Actually, it does. If the party you are registered with thinks are a voter who might not make it to the polls, and this is a close/important election, then there is a good chance you will receive numerous calls and/or visits reminding you to go out and vote. However, if you show up on the list of people who have voted by mail OR if you appear on the registry of people who have already voted in person, then they will stop reaching out to offer rides and reminders.
It's hard to say how much impact it has, but presumably there's a degree of social pressure when people are seen wearing/posting all those "I voted today" stickers.
The biggest problem I see related to that is the marked haziness over what exactly has been accomplished. As best I can tell, this paper claims to have deanonymized primary election ballots that were cast during the early voting period. But it's written as if it was deanonymizing general election ballots cast on election day.
This is in the site guidelines: https://news.ycombinator.com/newsguidelines.html.