Remix.run Logo
▲ beloch 3 hours ago

"In October 2022, a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots. Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing. However, the algorithm by which the machines generate this random number is actually deterministic and can be exactly reversed to identify the sequence in which ballots were cast.

...

Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."

---------------------

1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.

2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)

I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.

▲jcrawfordor an hour ago | parent | next [-]

They are using paper ballots. GA for example has since 2020. Several methods of auditing the counts of paper ballots require some tabular record of the contents of the ballots (so that it's practical to perform risk limiting audits on random samples), and the problem here originates from the process by which that tabular record is produced and the way it is made public. The same problem could exist in a hand counting process with risk limiting audits.

▲deathanatos 2 hours ago | parent | prev [-]

> Alternatively, just use plain paper ballots.

Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.

If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)

This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.

(If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)

> Either upgrade your pseudo-RNG

It seems grossly negligent that a voting machine is using a non-CSPRNG.

> Dominion has not shared any details about the new PRNG.

▲rmunn 25 minutes ago | parent | next [-]

Just remembered another report about a vote-counting machine with a security problem. Can't remember enough details to find the original report, but the guy found that the QR code the machine was scanning to read the vote did not have any kind of replay protection, and that although the ballots were printed on special paper, the machine did not have any verification of the paper being fed into it, and would accept plain photocopy paper. Meaning that all that would be needed to "hack" that particular machine, if the report was accurate, would have been to get hold of a ballot belonging to someone you know voted for your preferred candidates, and have it for 20-30 seconds of secrecy, long enough to make one photocopy before giving it back to the voter. Easy to do if the voter and the poll worker are in cahoots. And then you can run off 50, 100, 250 copies of that ballot and stuff the ballot box. Would be caught on a recount... probably. But it shouldn't be possible to do that sort of thing in the first place.

The simpler the machine, the better. As I said in my other comment, I'm about ready to go back to locked wooden boxes myself, opened and counted in full view with cameras rolling.

▲rmunn 39 minutes ago | parent | prev [-]

As long as the official count is actually done, then that's fine... but there's a natural human tendency to want to skip unnecessary work. And any polling place where the workers get lazy and just rubber-stamp the machine's counts have now made it possible for someone who hacks the machine to get away with it.

The machines should be kept air-gapped, not connected to the Internet, and all that. But again, human nature kicks in. There have been some poll workers who swore under penalty of perjury that in their polling place, there had been election machines that got an over-the-wire software update on Election Day. That's just... all kinds of wrong, if those reports are accurate. It doesn't prove cheating, but it does prove that whoever was in charge of that polling place should be fired. Because part of the job is making sure everyone knows the results are valid and accurate, and having voting machines connected to the Internet goes directly against "hey, you can see that no hacking is possible here". Doesn't matter how much the machine's manufacturer promises their machines are unhackable, the machines should not be connected to the Internet at all once they are actively being used for voting.

At this point, I'm ready to go back to paper ballots and a locked wooden box (kept in public view, and publicly verified to be empty before locking it up) myself. The simpler the solution, the better, is what I'm arriving at.