> To keep the published record anonymous, ballot scanners shuffle the electronic records randomly before releasing them
So they were never secret in the first place.
I have never understood the desire to have voting machines when a paper ballot works just fine. We tried electronic voting in three municipal elections in 2008 and courts ended up invalidating the results due to horrible usability issues.
DrScientist 14 hours ago [-]
In person, pure paper voting, in local community halls etc, run by volunteers is the best voting system.
Incredibly resistant to influencing at scale, resistant to voter coercion, transparent, and invokes a sense of occasion and community spirit.
The problem with electronic systems is the public can't see the piles of votes, can't get involved in the count, and ultimately it's the perfect system for being able to tip the scales subtly.
Even vote counting machines for paper ballots are a mistake in my view.
thadt 10 hours ago [-]
> In person, pure paper voting, in local community halls etc, run by volunteers is the best voting system.
This is the right answer. Using tech as an auditor for batches after manually counting could be useful. Getting everyone together to count votes in a process that everyone can see, understand, and be personally invested in - that process is what is needed far more than efficiency, at this point in time.
rjmunro 10 hours ago [-]
> Even vote counting machines for paper ballots are a mistake in my view
I think machines are only acceptable if they sort ballots into multiple bins, not if you are using them for the actual count. The bins should be designed so you can casually see that the last ballot to be added is correct for that bin while the machine is working. Something to insert a marker every 100 ballots is probably a good idea, then you can count the number of hundreds, and randomly sample a few of them to check they are correct.
guhcampos 9 hours ago [-]
This is a BIG discussion in Brazil, where the election is basically 100% electronic, no paper involved. There's a large portion of the population that distrusts the electronic voting machines, partly due to rightwing propaganda, but partly due to a genuine distrust of a system they can't understand.
In person paper voting, however, only works on a relatively healthy democractic community. What used to happen around here was that whoever was the local hegemonic power, mostly oligarcs, sometimes gangs, would just plant a grunt in the voting halls and coerce people to reveal their votes. That or they would simply have a bag of pre-cast votes and drop them all in the ballot box. Lots of absentees and dead people used to happily cast votes at the time.
So ultimately the full electronic system has been working quite well over here for the past 30-something years. It has only really started to be aggressively questioned since 2016 with the rise of social-media as an election driving powerhouse.
drdexebtjl 6 hours ago [-]
I also think it's pretty clear that this "aggressive questioning" has ulterior motives, since it never points out specific flaws in the transparency of the system, and never advocates for actual improvements to electronic voting machines, while there are very obvious low-hanging fruit to criticize and improve.
For example, while the software and hardware is audited by a very diverse panel, it's too institutional: you can't inspect it as an independent researcher. It's also not clear which parts of the supply chain are subject to the audits. I trust it's all of them, and these institutions are doing their job of pointing out the parts that they have _not_ audited, but I, as a member of the public, can't verify.
smitty1e 13 hours ago [-]
I've got over a decade of experience supporting elections using a ballot scanner.
The need to balance voter security, with auditability, rapid Ness of results, with ease of setup/teardown of the voting place, is hard to beat with scanners.
CoastalCoder 11 hours ago [-]
Sincere question: why is "rapidness of reporting" so important that we'd trade away other important goals?
(Within reasonable limits, I mean.)
smitty1e 2 hours ago [-]
Because people instant gratification.
We close the polls at 1900 and have a Collector Officer run one copy of the data on a thumb drive to the County.
The Chief gets to deliver a backup a couple hours later.
Hand-counting the ballots instead of scanning would be expensive in terms of time and money, and error-prone.
I'd argue that Fairfax County, VA is about optimal, all factors considered.
As I'm fond of saying: "Virginia is for lovers...of elections."
roenxi 11 hours ago [-]
Extend the question why are rapidity of results and ease of setup/teardown of the voting place design goals at all?
There are elections in India and the US to control billions of people and some very aggressive military people armed with weapons capable of ending modern civilisation. This is one of the most fundamental social technologies we have to keep the whole system stable (up there with limited liability corporations and courts). The downside of one of those elections failing because of voting machine trickery is stupendous.
Frankly, I'm not sure even auditability is that important as a design goal compared to voter security. If the election is close enough that an audit matters the two candidates are pretty similar. In practice, if there is any meaningful gap in preferences then the outcome of the election should be clear enough that an audit isn't that meaningful. It's nice to have and it is cheap enough to include in a paper ballot.
drfloyd51 9 hours ago [-]
The last 3 US elections were very close and had very different candidates with very different ideas. The closeness of the election has nothing to do with the “similarity” of any candidates. And to imply a “coin flip” would be fine is ludicrous.
GJim 11 hours ago [-]
Rapid results?
In Blighty, we have paper voting. The polls close at 10pm, the manual count takes place overnight, and the result is typically known the next day.
How much more rapid do you need?
rjmunro 10 hours ago [-]
Even the next day is silly. If the election is Thursday, it seems reasonable to count on Friday and the weekend, and have the new MPs declared on Sunday, ready to travel to London on Monday and get sworn in.
In the US, the election is in November and the president doesn't get sworn in until January. It could take a couple of weeks to count the votes and it would be fine.
RandomLensman 12 hours ago [-]
How do other larger countries manage it without scanners?
cyberge99 5 hours ago [-]
Smaller chunks.
hanibrel 13 hours ago [-]
> In person, pure paper voting, in local community halls etc, run by volunteers is the best voting system.
Unless those volunteers are all die-hard fans of a particular party/candidate and thereby intimidating everybody that has a different opinion. (Not openly of course, but if everybody knows everybody, the mere presence suffices to sway people.)
GJim 11 hours ago [-]
In Blighty, the counters (paid volunteers from the local council working voluntery overtime) are supervised and audited. Not to mention representitives from the local political parties will be present as well as the local press to oversee the proceedings. Typically the returing officer will also allow anybody else to be present and observe the proceedings, space and practicalities permitting.
The process is quite fair and rigorous.
neffy 12 hours ago [-]
Certainly it´s possible to rig in person voting - but if you do, people will know that you did. And that also matters.
looperhacks 12 hours ago [-]
This would need at least a majority of die-hards present in a (near) majority of polling locations. At this point, the party can probably win the election without fraud.
jcmontx 11 hours ago [-]
For the counting process you have "auditors" from all the different parties. We have that system in Argentina and it works pretty well in terms of electoral transparency. People's choices are another thing.
nonethewiser 5 hours ago [-]
This seems both the least likely and easiest threat to remediate. Also the threat doesn’t scale.
RandomLensman 12 hours ago [-]
Could just draft people, for example. On a local level there is also more knowledge in voters that can be compared to counts etc.
roenxi 11 hours ago [-]
These volunteers will have a far easier time scaling their conspiracy if voting machines are involved. There are fewer points of failure to corrupt and it is easier to produce a plausible sketchy result where their guy wins by 100 votes.
jcrawfordor 16 hours ago [-]
They are using paper ballots. The problem identified here comes from the counting process, and hand counting with similar audit records could end up having the exact same problem if the count audit ledgers were shuffled by similar means. The ballots are shuffled in the audit logs because it is known that a time/order correlation problem exists (ballots tend to be counted in the order they are cast), but the reason that Dominion uses a poor method of randomization, and that some (but not all!) election administrators include count sequence numbers in their publicly released records at all, seem to come down to a lack of care.
RandomLensman 13 hours ago [-]
Hand counting paper ballots by a somewhat random assembly of people might make that less easy (as people might need to collude). Also, why would the ledgers be accessible to everyone counting? Other than using them to check off who voted/eligibility when a voter shows up, what are they needed for at the counting stage?
jcrawfordor 6 hours ago [-]
The decision to publish the ledger is one made by the election administrator in the interest of transparency - there is no requirement to do so, but it is believed to increase public trust in the process. Unfortunately these types of transparency measures haven't necessarily been rigorously evaluated and the tradeoffs with ballot secrecy may not be favorable. that is the real significance of this research to me, not really anything about the use of machines.
Some states do quite the opposite, e.g. seal ballots after the election and only allow inspection by court order. This has obvious benefits for secrecy, but then creates a lot of objections when people/organizations that doubt the election outcome are told that they cannot review the actual ballots (without meeting some threshold to justify such an order, which can be quite high since these rules were often put in place to try to counter pay-to-vote or voter intimidation schemes).
The existence of such a ledger isn't even required, but it makes it radically easier to audit the count process to detect errors. US election administrators demand a very high level of accuracy in vote counts (higher than what is typical in a lot of other countries), so in hand-count processes it's common to tabulate each ballot multiple times, and with machine tabulation there is usually some kind of automatic recount or risk limiting audit, either by retabulating with separate machines or hand-counting a sample. All of these are much easier processes when you can correlate a ballot to the previous time it was counted, so that errors discovered in auditing can be tracked to the specific ballot that was miscounted and corrected. Otherwise, if you count a batch of ballots twice and get different results (which is virtually guaranteed with hand counting), you will have to recount the entire batch over and over until you get satisfactory convergence. There are several different methods of doing this: some jurisdictions serialize ballots when they are printed so that tabulation can be tracked by that serial number. Other jurisdictions avoid this potential secrecy hazard by only serializing ballots after initial tabulation (e.g. ballots pulled for a sample audit have sequence numbers added on stickers or hand-written). Some tabulating machines can add sequence numbers as they run. All of these have different considerations as far as reliability and secrecy, but unfortunately there is next to zero funding or political interest in researching these issues and applying the resulting knowledge. The result is that everything is highly variable from state to state and some states continue to use processes that are known to have significant defects, most famously Louisiana with its ongoing use of non-auditable DRE machines (the only state that continues to do so).
yorwba 10 hours ago [-]
In this case, the ledgers were published on the internet, there was no collusion necessary to obtain them. The problem here is more the level of record-keeping and transparency about the counting process, not how the counting itself was done.
Maken 14 hours ago [-]
Pair that with voting machines that are always online and you have the easiest to tamper elections ever.
RA2lover 16 hours ago [-]
Diego Aranha had found an exploit with brazilian voting machines back in 2017. They scrambled votes whenever every vote was cast using a CSPRNG, but initialized its seed with the time the voting machine had been turned on (rounded to the second), which due to voting protocols at the time meant you only had to have one person vote a specific way and bruteforce 3600 orderings to find that person's vote and destroy ballot secrecy for everyone else who voted on the same machine.
Seems like this is the same mode of failure, which is strange considering diebold made the brazilian machines back then and should have fixed that.
arcanemachiner 16 hours ago [-]
Wow, a Diebold voting machine with security vulnerabilities? You think they would stop making so many silly mistakes after two decades[0] of making faulty voting machines.
What a bunch of silly clowns with their silly little whoopsies! Maybe they'll get it right someday.
The machines used in Brazil, while based originally on a Diebold design, are widely different from the ones used in US. There are genuine complaints: for instance some of us belive the software and hardware should be open source, but it has passed the test of time in the last 30 years.
cryptonector 18 hours ago [-]
The way this sort of problem has been fixed in Texas since 2024 is to require that all ballots be sequentially numbered -- that is, they arrive at polling locations in packs of 50 or 100 ballots, each pack having sequentially numbered ballots, but the presiding judge takes 10-20 at a time, signs them, then shuffles them, places them with the serial number facing down towards the table, and voters get to pick one at random when they check in.
"In October 2022, a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots. Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing. However, the algorithm by which the machines generate this random number is actually deterministic and can be exactly reversed to identify the sequence in which ballots were cast.
...
Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."
---------------------
1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.
2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)
I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.
jcrawfordor 16 hours ago [-]
They are using paper ballots. GA for example has since 2020. Several methods of auditing the counts of paper ballots require some tabular record of the contents of the ballots (so that it's practical to perform risk limiting audits on random samples), and the problem here originates from the process by which that tabular record is produced and the way it is made public. The same problem could exist in a hand counting process with risk limiting audits.
deathanatos 17 hours ago [-]
> Alternatively, just use plain paper ballots.
Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.
If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)
This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.
(If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)
> Either upgrade your pseudo-RNG
It seems grossly negligent that a voting machine is using a non-CSPRNG.
> Dominion has not shared any details about the new PRNG.
rmunn 16 hours ago [-]
Just remembered another report about a vote-counting machine with a security problem. Can't remember enough details to find the original report, but the guy found that the QR code the machine was scanning to read the vote did not have any kind of replay protection, and that although the ballots were printed on special paper, the machine did not have any verification of the paper being fed into it, and would accept plain photocopy paper. Meaning that all that would be needed to "hack" that particular machine, if the report was accurate, would have been to get hold of a ballot belonging to someone you know voted for your preferred candidates, and have it for 20-30 seconds of secrecy, long enough to make one photocopy before giving it back to the voter. Easy to do if the voter and the poll worker are in cahoots. And then you can run off 50, 100, 250 copies of that ballot and stuff the ballot box. Would be caught on a recount... probably. But it shouldn't be possible to do that sort of thing in the first place.
The simpler the machine, the better. As I said in my other comment, I'm about ready to go back to locked wooden boxes myself, opened and counted in full view with cameras rolling.
deathanatos 8 hours ago [-]
> And then you can run off 50, 100, 250 copies of that ballot and stuff the ballot box.
At least at my polling place (but I'd really hope this is universal), the machine (the ballot box, effectively) is in the middle of the room, and closely watched. You would not be permitted to stuff more than one ballot into it. (Not to mention this would be voter fraud.)
> Easy to do if the voter and the poll worker are in cahoots.
Again poll watchers are the answer.
> The simpler the machine, the better.
The simplicity of the machine does nothing for this attack? In fact a wooden box is perhaps most vulnerable. But, again, this is completely mitigated by poll watchers. (Not to mention such an attack would likely be mitigated by other voters simply going "yo, what are you doing?"…)
> Would be caught on a recount... probably.
… aside from perhaps a discrepancy between the count of voters who voted on the roll, and the number of ballots in the box (on the initial count), a recount isn't really catching this.
I suppose if I wanted to mitigate this, you could put a signed "This is the ballot for the 2026 election" (+nonce, so that if someone duplicates it, we can pick out the duplicates/replays) on the ballot paper, and attempt to control physical distribution of actual ballots. But now we need to generate a nonce, and we're right back to "I'm sure an LCG is sufficient, right?"
rmunn 16 hours ago [-]
As long as the official count is actually done, then that's fine... but there's a natural human tendency to want to skip unnecessary work. And any polling place where the workers get lazy and just rubber-stamp the machine's counts have now made it possible for someone who hacks the machine to get away with it.
The machines should be kept air-gapped, not connected to the Internet, and all that. But again, human nature kicks in. There have been some poll workers who swore under penalty of perjury that in their polling place, there had been election machines that got an over-the-wire software update on Election Day. That's just... all kinds of wrong, if those reports are accurate. It doesn't prove cheating, but it does prove that whoever was in charge of that polling place should be fired. Because part of the job is making sure everyone knows the results are valid and accurate, and having voting machines connected to the Internet goes directly against "hey, you can see that no hacking is possible here". Doesn't matter how much the machine's manufacturer promises their machines are unhackable, the machines should not be connected to the Internet at all once they are actively being used for voting.
At this point, I'm ready to go back to paper ballots and a locked wooden box (kept in public view, and publicly verified to be empty before locking it up) myself. The simpler the solution, the better, is what I'm arriving at.
m3047 2 hours ago [-]
Specifically pertains to voting systems in GA.
"a security vulnerability disclosed back in 2022 shows the shuffle can be reversed, and some states have not applied the software update that resolves it."
"a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots"
"Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing."
I can tell you that before WA went to all-mail voting it wouldn't have happened, because I served as a pollworker and election site inspector. There was a optical scan ballot reader / counter, my confidence is high it only kept running totals. The ballots fell into a bin, at the end of the day the bin was unlocked and the ballots were tossed into bags (no particular order) which were then sealed. As inspector I printed a copy of the tape which went downtown with the bag(s); they would have been able to print a new tape until the machine's memory was wiped (at which point they still had "hardcopy backup"). The ballots were not marked upon by the scanner in any manner. There was an incident where one of the ballot printing / counting companies (because they both typically had to come from the same manufacturer) started printing sequence numbers on ballots (not just ballot styles) and that went to court.
I've not witnessed what happens with all-mail voting, but there is no sequence number on the ballots. ;-) The count is not supposed to start until the polls close. Before that the ballots are ostensibly separated from their identity (the envelope) in an identity confirmation ceremony. My impression is that they're scanned at this point and the scans are utilized for counting / optical scan, but I'm not certain about this or that it's the same everywhere. I don't know what happens to the physical ballots; back in the day what I know is that if a ballot needed to be corrected (defacement or damage renders it unreadable) then a new ballot was prepared under the supervision and adjudication of election observers and the old ballot was destroyed; but that's the exception which proves the rule that physical, anonymized ballots were retained.
The voting process is in the hands of the individual (United) States; in WA it's largely in the hands of the County administrators and varies to a degree Statewide.
amelius 14 hours ago [-]
Democracy's main problem isn't the voting process, at the moment.
whatever1 14 hours ago [-]
We are the first generation that we, or our parents did not have to fight for their freedom.
We forgot what it took to be where we are.
brainwad 13 hours ago [-]
Nobody has fought for freedom in Switzerland in 175 years, and yet democracy thrives.
falserum 13 hours ago [-]
Maybe not freedom, but Switzerland did some shooting (at allies and axis) and took casualties. To preserve its neutrality.
NooneAtAll3 13 hours ago [-]
doesn't help that it's the "moderate" parties that want to fight, while "extremists" proclaim the need for peace
rapidaneurism 16 hours ago [-]
I feel a bit silly, but I do not understand how the results were verified.
chrisjj 12 hours ago [-]
> Through the history of computer security, there has usually been a moat of expertise separating a vulnerability from its exploitation. ... Large Language Models (LLMs), the systems behind chatbots like ChatGPT, are building bridges across that moat.
Draining it, more like.
lenerdenator 21 hours ago [-]
> this allows you to know whether your neighbor voted, but never who they voted for.
There's probably an angle I'm not thinking of here, but imho, it's absolutely not John Q. Public's damned business what a person does or does not do on election day.
mcherm 21 hours ago [-]
The practice of making public whether someone has voted dates back a very long time. There were practical reasons for it when it originated, and many of those remain valid today.
Originally, everyone in town knew most everyone else and could see them physically walking into the polling place. So long before electronic records were kept, the question of who voted was public information.
Even today, I run my local polling station and I know and recognize a significant portion of the voters in my precinct.
The fact that the list of who votes is made public protects against several kinds of abuses. It goes a long way to protect against "dead people voting" and other kinds of ballot box stuffing if the list of voters is public so anyone can review it and potentially catch such abuses.
skew-aberration 21 hours ago [-]
The value of transparency goes above and beyond protecting against abuses (for which there are other methods) - it also provides assurance to the public that there is protection against those abuses, and that those abuses are not taking place.
i.e. 'Justice must not only be done, but must also be seen to be done'
rmunn 17 hours ago [-]
I once read an account by a poll watcher of her experience in 2012. She said that at her polling place, there had been a number of people showing up to vote on Election Day, being told they had already voted during the early-voting process, and swearing up and down that that wasn't true, that they always voted on Election Day and never voted early, and that whoever had voted in their name had done so fraudulently.
Now, in that particular case, the state (I believe it was Colorado though I'd have to find the article I read, and I don't remember where to find it any more) didn't require photo ID, so there was no way to prove that the people showing up on Election Day were the actual voters, as opposed to the cheaters. But this poll watcher's opinion was that they were the actual voters, and the cheating had been done by whoever had submitted ballots in their name days (or weeks) earlier. Given how many people she said this had happened to, I'm inclined to agree with her: it wasn't three or four people, it was (she said) something like one-third of the people who showed up on Election Day at that polling place.
That's a case where the fraud couldn't be repaired by knowing that it had occurred — the fraudulent ballots (if they were indeed fraudulent) had already been accepted, and it was impossible to go pull the ballot allegedly belonging to Joe Smith back out of the ballot box. But the publicly-available list of "who voted" did at least make it possible for the fraud to be detected in that particular case.
skew-aberration 17 hours ago [-]
I think all you can do is sue at that point.
I personally do support voter ID, and for the same reason. Members of the public must be able to verify the process is happening fairly. It might be fair without it (fraud truly negligible), but it must also be seen to be fair. This would resolve so many controversies.
Likewise mandatory voting and private ballots (can cast a donkey vote) helps ensure the public people are not being paid to vote and that other biases are not coming into play.
rmunn 17 hours ago [-]
I'm not entirely sure mandatory voting is wise in a country the size of the United States, but I'm with you on the voter ID and the rationale. I was shocked to learn that with everything else that requires photo ID, it's not required to vote in American elections. (At least, in some locations; laws vary from place to place). That just looks bad.
My personal opinion is that if people think they can benefit from cheating, a certain number will do so. It's just human nature. We're seeing more and more of this with LLM cheating on the rise in universities. So there's always going to be a certain number of people who want to vote fraudulently — after all, if the right person gets into office, it'll probably benefit you. Your taxes might be lowered, or your government handouts might be increased, or whatever other reason you have for preferring one politician over another. Preference alone does not mean that people will vote fraudulently: after all, most legitimate voters also prefer one politician over another. But the easier you make it to cheat, the more people will cheat successfully: among those who wanted to cheat but didn't, usually the only reason they didn't is because they couldn't see how to get away with it.
So photo ID to vote just seemed like common sense to me, along with other measures like ballot boxes kept in a publicly-visible place until they're opened, to help prove that nobody has tampered with them. (Read up on the 1946 elections in Athens, TN sometime — there, the fraud was being done by the sheriff and his cronies who would take the ballot boxes away, "count" them in private with no outside observers present, and announce that surprise surprise, the sheriff's crony had won the election again).
venzaspa 14 hours ago [-]
We only recently started requiring ID here in the UK, it was a move that was seen by many as a form of Gerrymandering because the actual recorded rate of voter fraud in a general election is very low, around 200-300 cases per election usually.
In the last general election 16,000 people were prevented from voting because they didn't have the correct ID - despite there being mechanisms for them to get suitable ID for free ahead of an election.
Sometimes the fix is worse than the actual problem you're trying to solve.
skew-aberration 12 hours ago [-]
Interestingly UK has another system to prevent fraud - you can only vote at a single polling station. So it is historically more restrictive than most of US (and here in AU). Explains the low fraud rates. And likely inhibits a lot more voters than a simple ID check.
Also, without a photo ID the fraud rate is near impossible to measure - people can just sell their votes to imposters, fabricate voters, etc. It would be undetectable in your stats. A similar concern applies to postal votes, and there have been high profile cases of this in the UK.
As a concrete example The Tower Hamlets Scandal saw Luftur Raham's election declared null 'on the grounds of corrupt and illegal practices by him and his agents, and general corruption so extensively prevailing so to reasonably supposed to have affected the election' despite a similar number of low hundreds of allegations of fraud. That's a proven-in-court example showing you are wrong to dismiss the concern based on the data. The methods used are clearly not detectable by the system you endorse, and that system has demonstrably lead to the unjust disenfranchisement of your fellow countrymen.
rapidaneurism 16 hours ago [-]
An added benefit of voter id is that by making it easy or cheap for one groups and difficult or expensive for an other (or choosing acceptable IDs that already have these characteristics) you can create some friction to make it more difficult for the wrong people to vote.
That is why I like voter ID if it relies on documents provided for free with minimal fuss.
rmunn 16 hours ago [-]
The situation you describe, where the laws would be selected to make obtaining a photo ID (and thus voting) difficult for one group over another, would amount to a poll tax — which has already been found unconstitutional in the United States.
However, every US state I'm aware of (if you know of exceptions, please let me know) has some form of photo ID you can obtain for free. Usually it's in the same format as a driver's license, and obtained from the same place (the Department of Motor Vehicles, Department of Land Transportation, the name varies). There's a fee to obtain a driver's license, but a photo ID card (in the same format as a driver's license but marked "NOT LEGAL FOR DRIVING" or similar wording) can be obtained for free, by going through the same process as getting a driver's license (bring something to prove your identity, get your photo taken, wait for the card to be printed) but without taking a driving-skills test.
And before someone asks "what about the people who can't prove their identity"? Well, I can actually give an anecdote. I know someone who ended up in that situation: away from home for college, couldn't get her birth certificate or anything else, and needing to replace her passport that was lost. (She is American but had grown up overseas because of her parents' job, hence why she had a passport but no driver's license when she went off to college). She had quite a time of it at first, since every "prove your identity" requirement circled back around to another form of ID. But she was eventually able to get a fishing license just by swearing under penalty of perjury that she was indeed (name). With that in hand, she got another form of ID (I think a library card, though there my memory is iffy), then with two forms of ID she could get something else, and then eventually she was able to get that non-driver's ID card... and then was able to prove who she was to get her lost passport reissued.
That all happened nearly 30 years ago so I can't swear to the details. But the point is, photo ID cards are widely available, and it's normal to be asked for one. So as long as the law specifies that acceptable forms of photo ID include X, Y, and Z (where X, Y and Z are forms that most people would already have, and that are normal and in common use), and as long as at least one of those forms can be obtained without a fee (which as I said, is true in all U.S. states that I'm aware of, please mention any exceptions you know about because I'd like to know) then it will pass Constitutional muster.
rsingel 16 hours ago [-]
This sounds like some third-hand anecdata. Trump et al (Chris Kobach, for one) have spent millions of dollars trying to find voter fraud and they have all come up with zilch.
And you have some memory of some account from someone 12 years ago in a state you can't remember saying that a third of voters had someone pretend to be them?
If this were close to true, it wouldn't be some blog post that you can't remember; it would have been a national scandal and it would have been something that we would never forget because the election stealer conspiracy theorists would never let it go.
Really, you should just delete this post as it's irresponsible and lacks any data.
rmunn 16 hours ago [-]
The point I'm trying to make is that I agree with the parent comment to mine, which pointed out that transparency is essential to protect people's confidence in the voting process, especially when people are loudly claiming that someone committed fraud. The more open the process, the easier it is to prove that it's legitimate.
retsibsi 11 hours ago [-]
> The point I'm trying to make is that I agree with the parent comment to mine
But you did that by making a big, surprising claim for which you haven't provided any evidence. You might not intend for that to be the main thing people focus on, but they are right to be both interested and skeptical! If true, it's a big deal.
The closest thing I could find is this (https://www.thenation.com/article/archive/voters-predominant...), which was attributed to 'human error' rather than fraud, and was resolved by allowing the affected voters to cast provisional ballots. 'Human error' is a vague explanation, and for all I know it was a coverup -- but the onus is on you to provide some positive reason to believe that. Surely there were plenty of people motivated to investigate this, so it would be surprising if a bullshit explanation was just quietly accepted and no further public attention paid.
rsingel 9 hours ago [-]
And my point is you, like Trump and Kobach, can't prove there is a voting fraud problem so instead share, at best, anecdotes.
Not sure why your OG post is still up.
Voter ID solves a non-existent fraud problem and does so by making voting harder.
estearum 13 hours ago [-]
No system is immune to bad faith actors undermining trust by just making shit up.
The idea that if we had paper ballots with walk-in only, ID-verified votes, that Trump and Fox News et al wouldn't have launched a coup attempt, or wouldn't have gotten nearly as far, is pretty laughable. In fact we have Trump on the record saying as much: "It doesn't matter whether you win or lose, you have to fight like hell."
Let's take your scenario. In fact there is a way to verify which vote was correct (and it's used already) which is to match the signatures between the voter registration and the ballot.
This is sufficient except in cases where the registration itself was fraudulent, which would have required 1) having someone's ID at time of registration and 2) intercepting the mail sent to their ID- or utility-bill-confirmed mailing address.
An attacker who could achieve that could also have achieved just walking into the polling place to achieve the same false vote.
Any attack is extremely expensive to do at any meaningful scale, and all scaled attacks are detectable by simple statistical sampling.
If meaningful amounts of tampering were detected by statistical sampling then you can obviously re-run elections with tighter controls, more burden, lower turnout, and a generally-less-representative result, which is why we start with a more inclusive system. This can and does actually happen. Whether it's necessary is literally 100% statistically knowable through basic sampling.
derektank 16 hours ago [-]
Yet so few people go the next step and say, “Let’s do away with the secret ballot itself.” It really is a recent invention, American democracy survived nearly 100 years before the Australian ballot was adopted. There are obviously concerns (vote buying, organized crime, etc) but they can be dealt with. And public voting would almost completely eliminate concerns about the voting process itself being subverted by a malign actor.
rmunn 16 hours ago [-]
> There are obviously concerns (vote buying, organized crime, etc) but they can be dealt with.
I don't think they can be dealt with. But I'm willing to listen to your ideas. How would you deal with vote buying? How would you stop the scenario where a guy says "I'll give you $1,000 if you vote for candidate X" (or "I know where you live, I'll break your kneecaps if you vote for candidate Y")?
derektank 9 hours ago [-]
I mean, the same way we deal with corruption, bribery, and threats generally; have a strong, independent law enforcement and prosecutors office. The FBI regularly and successfully investigates (and the DoJ indicts and secures convictions for) legislators, whose voting record is already public, who sell their votes on city councils or in state legislatures. It takes a lot of votes to swing most elections, so a concerted bribery campaign would be much easier to investigate than these examples.
retsibsi 9 hours ago [-]
Are you confident that Trump's FBI and DOJ (and Trump-aligned state police/prosecutors; if you are a Trump supporter, please substitute in the names of your most distrusted democrats) would vigorously pursue all credible allegations of vote-buying and coercion in his favour? And even if you are, and they did, do you think more than ~half the country would believe it?
derektank 9 hours ago [-]
As elections are run by the states, you can have state and local governments legislate anti-corruption law and enforce it too. So, no, no real concerns with who specifically is in charge at the federal level at any given time
skew-aberration 16 hours ago [-]
Vote buying/intimidation is just too big a vector, IMO. I would never accept that risk. It's transitive too - you can pay/intimidate the people who enforce the no paying/intimidating rule.
derektank 9 hours ago [-]
You can structure the law such that, if you report a bribe that results in a conviction, the criminal is still forced to pay the person they attempted to bribe, similar to how Qui Tam works. This would do a lot to discourage attempts at bribing law enforcement and prosecutors, who would be best positioned to secure such a conviction.
y1n0 16 hours ago [-]
I would never vote again if it wasn’t anonymous. Retaliation is real.
derektank 9 hours ago [-]
I would suggest that if you don’t have the courage of your convictions to stand by your vote in public, maybe you shouldn’t be voting in the first place
sfink 7 hours ago [-]
It's easy to minimize someone else's situation down to "courage".
Quite a few husbands believe they should have control over their wives' votes. I guess you'd say they should have the courage to leave them and wreck their children's lives and be ostracized by their family and community?
And it's not hard to imagine certain employers having a strong opinion on how you vote on specific measures. Of course they couldn't compel anyone to reveal their votes, but it could be made customary enough that refusing to would be enough of a signal. I guess you'd need the courage to quit and take a lower paying job?
derektank 6 hours ago [-]
An employer creating a hostile workplace should obviously create a tort and liability under any kind of reasonable anti-corruption law in the same way it does under anti-discrimination law.
As for what happens in marriages or other social settings, yes, wives can coerce their husbands, fathers can coerce their adult daughters, friends can coerce one another. If your counterpart is the kind of person who would threaten to blow up your relationship over how you vote, yes, I would suggest maybe that tells you something about who they are and whether or not you want them in your life. But if the relationship means that much to you, you can always go along to get along and let them tell you how to vote. I think that says something about how much you value your vote though. And at the societal level, I don’t think this would have a meaningful impact on governance
__MatrixMan__ 20 hours ago [-]
I suspect the missing angle is that people are more likely to trust claims made to the public if, in principle, those claims could be verified by the public.
Of course it's pretty impractical that a bunch of concerned citizens might gather together and check the published data against how they each remember voting. But preserving the possibility in principle makes it easier to trust the published results. It gives a would-be deceiver yet another thing to worry about.
Its a trade-off I'd have opted into had I been asked. Though I'd feel a lot better about it if I had been asked.
allforJesse 21 hours ago [-]
I was thinking the same. It's not as if visibility into whether someone voted or not has driven voter turnout significantly. Hell, I'd assumed this was private until I learned otherwise recently.
But it's such a specific structure, clearly there was an objective in mind when it was imlpemented.
mcherm 21 hours ago [-]
> It's not as if visibility into whether someone voted or not has driven voter turnout
Actually, it does. If the party you are registered with thinks are a voter who might not make it to the polls, and this is a close/important election, then there is a good chance you will receive numerous calls and/or visits reminding you to go out and vote. However, if you show up on the list of people who have voted by mail OR if you appear on the registry of people who have already voted in person, then they will stop reaching out to offer rides and reminders.
BobbyTables2 19 hours ago [-]
What if the opposing party knows you haven’t voted yet?
autoexec 20 hours ago [-]
> It's not as if visibility into whether someone voted or not has driven voter turnout significantly.
It's hard to say how much impact it has, but presumably there's a degree of social pressure when people are seen wearing/posting all those "I voted today" stickers.
thaumasiotes 21 hours ago [-]
The registry of people who voted has to exist because you're not allowed to vote more than once. That reason doesn't require the registry to be published, but it does require it to be compiled.
brainwad 13 hours ago [-]
Knowing whether you voted exactly once is the easiest way to know you _didn't_ vote multiple times.
allforJesse 21 hours ago [-]
When I hit the term "load-bearing" in the first sentence my mind immediately turned off. Had to forcibly reengage in reading. Claude trauma is real.
rosstex 19 hours ago [-]
As an ex-CITP member, that's most definitely a human written joke.
vessenes 10 hours ago [-]
Maybe. But this article was at the least drafted by claude. It does all the things, including that weird word density + concept vapidity that makes parsing so difficult and annoying.
mbeavitt 13 hours ago [-]
It's surprising that Pangram gives 0% AI text. There are notable examples of LLM writing here:
> Tied to a specific ballot is the stronger claim and requires one additional public record.
clearly a claude-ism
I guess the author went back and forth running pangram and slightly tweaking the text until it read "0% LLM text"
thaumasiotes 21 hours ago [-]
The report does feel like LLM output.
The biggest problem I see related to that is the marked haziness over what exactly has been accomplished. As best I can tell, this paper claims to have deanonymized primary election ballots that were cast during the early voting period. But it's written as if it was deanonymizing general election ballots cast on election day.
chrisjj 12 hours ago [-]
Human authors really need to screen their output with a (relatively) good AI detector.
alescalaios 13 hours ago [-]
[dead]
digitalPhonix 19 hours ago [-]
[flagged]
dang 19 hours ago [-]
Can you please make your substantive points without snarky internet tropes like "... sigh"? We're trying for something else here.
Noted. Are you going to enforce the entirety of the site guidelines?
> HN is for sharing between humans
My (and others’) comments are knee jerks when that guideline gets violated.
baggy_trough 19 hours ago [-]
[flagged]
leecoursey 3 days ago [-]
A Princeton researcher showed that a known flaw in Georgia's ballot scanners, still unpatched in places, lets someone with public records and cheap AI tools work out the order ballots were cast and potentially link them to voters. He recovered the order for nearly 99% of in-person ballots in 114 counties and says secrecy can be broken entirely in small ones.
andrewclunn 12 hours ago [-]
We've moved beyond secret ballots making sense. The security of the vote is far more important. As far as concerns over voter intimidation... let someone just try that and see what happens. Besides, if they have to "shuffle" the ballots to anonymize them, then they weren't actually secret to the people initially collecting them anyways, so the secrecy was just theater anyways.
Rendered at 22:31:52 GMT+0000 (Coordinated Universal Time) with Vercel.
So they were never secret in the first place.
I have never understood the desire to have voting machines when a paper ballot works just fine. We tried electronic voting in three municipal elections in 2008 and courts ended up invalidating the results due to horrible usability issues.
Incredibly resistant to influencing at scale, resistant to voter coercion, transparent, and invokes a sense of occasion and community spirit.
The problem with electronic systems is the public can't see the piles of votes, can't get involved in the count, and ultimately it's the perfect system for being able to tip the scales subtly.
Even vote counting machines for paper ballots are a mistake in my view.
This is the right answer. Using tech as an auditor for batches after manually counting could be useful. Getting everyone together to count votes in a process that everyone can see, understand, and be personally invested in - that process is what is needed far more than efficiency, at this point in time.
I think machines are only acceptable if they sort ballots into multiple bins, not if you are using them for the actual count. The bins should be designed so you can casually see that the last ballot to be added is correct for that bin while the machine is working. Something to insert a marker every 100 ballots is probably a good idea, then you can count the number of hundreds, and randomly sample a few of them to check they are correct.
In person paper voting, however, only works on a relatively healthy democractic community. What used to happen around here was that whoever was the local hegemonic power, mostly oligarcs, sometimes gangs, would just plant a grunt in the voting halls and coerce people to reveal their votes. That or they would simply have a bag of pre-cast votes and drop them all in the ballot box. Lots of absentees and dead people used to happily cast votes at the time.
So ultimately the full electronic system has been working quite well over here for the past 30-something years. It has only really started to be aggressively questioned since 2016 with the rise of social-media as an election driving powerhouse.
For example, while the software and hardware is audited by a very diverse panel, it's too institutional: you can't inspect it as an independent researcher. It's also not clear which parts of the supply chain are subject to the audits. I trust it's all of them, and these institutions are doing their job of pointing out the parts that they have _not_ audited, but I, as a member of the public, can't verify.
The need to balance voter security, with auditability, rapid Ness of results, with ease of setup/teardown of the voting place, is hard to beat with scanners.
(Within reasonable limits, I mean.)
We close the polls at 1900 and have a Collector Officer run one copy of the data on a thumb drive to the County.
The Chief gets to deliver a backup a couple hours later.
Hand-counting the ballots instead of scanning would be expensive in terms of time and money, and error-prone.
I'd argue that Fairfax County, VA is about optimal, all factors considered.
As I'm fond of saying: "Virginia is for lovers...of elections."
There are elections in India and the US to control billions of people and some very aggressive military people armed with weapons capable of ending modern civilisation. This is one of the most fundamental social technologies we have to keep the whole system stable (up there with limited liability corporations and courts). The downside of one of those elections failing because of voting machine trickery is stupendous.
Frankly, I'm not sure even auditability is that important as a design goal compared to voter security. If the election is close enough that an audit matters the two candidates are pretty similar. In practice, if there is any meaningful gap in preferences then the outcome of the election should be clear enough that an audit isn't that meaningful. It's nice to have and it is cheap enough to include in a paper ballot.
In Blighty, we have paper voting. The polls close at 10pm, the manual count takes place overnight, and the result is typically known the next day.
How much more rapid do you need?
In the US, the election is in November and the president doesn't get sworn in until January. It could take a couple of weeks to count the votes and it would be fine.
Unless those volunteers are all die-hard fans of a particular party/candidate and thereby intimidating everybody that has a different opinion. (Not openly of course, but if everybody knows everybody, the mere presence suffices to sway people.)
The process is quite fair and rigorous.
Some states do quite the opposite, e.g. seal ballots after the election and only allow inspection by court order. This has obvious benefits for secrecy, but then creates a lot of objections when people/organizations that doubt the election outcome are told that they cannot review the actual ballots (without meeting some threshold to justify such an order, which can be quite high since these rules were often put in place to try to counter pay-to-vote or voter intimidation schemes).
The existence of such a ledger isn't even required, but it makes it radically easier to audit the count process to detect errors. US election administrators demand a very high level of accuracy in vote counts (higher than what is typical in a lot of other countries), so in hand-count processes it's common to tabulate each ballot multiple times, and with machine tabulation there is usually some kind of automatic recount or risk limiting audit, either by retabulating with separate machines or hand-counting a sample. All of these are much easier processes when you can correlate a ballot to the previous time it was counted, so that errors discovered in auditing can be tracked to the specific ballot that was miscounted and corrected. Otherwise, if you count a batch of ballots twice and get different results (which is virtually guaranteed with hand counting), you will have to recount the entire batch over and over until you get satisfactory convergence. There are several different methods of doing this: some jurisdictions serialize ballots when they are printed so that tabulation can be tracked by that serial number. Other jurisdictions avoid this potential secrecy hazard by only serializing ballots after initial tabulation (e.g. ballots pulled for a sample audit have sequence numbers added on stickers or hand-written). Some tabulating machines can add sequence numbers as they run. All of these have different considerations as far as reliability and secrecy, but unfortunately there is next to zero funding or political interest in researching these issues and applying the resulting knowledge. The result is that everything is highly variable from state to state and some states continue to use processes that are known to have significant defects, most famously Louisiana with its ongoing use of non-auditable DRE machines (the only state that continues to do so).
Seems like this is the same mode of failure, which is strange considering diebold made the brazilian machines back then and should have fixed that.
What a bunch of silly clowns with their silly little whoopsies! Maybe they'll get it right someday.
[0] https://www.wired.com/2006/09/e-voting-machine-an-easy-hack/
[1]: https://en.wikipedia.org/wiki/K-anonymity
...
Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."
---------------------
1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.
2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)
I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.
Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.
If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)
This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.
(If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)
> Either upgrade your pseudo-RNG
It seems grossly negligent that a voting machine is using a non-CSPRNG.
> Dominion has not shared any details about the new PRNG.
The simpler the machine, the better. As I said in my other comment, I'm about ready to go back to locked wooden boxes myself, opened and counted in full view with cameras rolling.
At least at my polling place (but I'd really hope this is universal), the machine (the ballot box, effectively) is in the middle of the room, and closely watched. You would not be permitted to stuff more than one ballot into it. (Not to mention this would be voter fraud.)
> Easy to do if the voter and the poll worker are in cahoots.
Again poll watchers are the answer.
> The simpler the machine, the better.
The simplicity of the machine does nothing for this attack? In fact a wooden box is perhaps most vulnerable. But, again, this is completely mitigated by poll watchers. (Not to mention such an attack would likely be mitigated by other voters simply going "yo, what are you doing?"…)
> Would be caught on a recount... probably.
… aside from perhaps a discrepancy between the count of voters who voted on the roll, and the number of ballots in the box (on the initial count), a recount isn't really catching this.
I suppose if I wanted to mitigate this, you could put a signed "This is the ballot for the 2026 election" (+nonce, so that if someone duplicates it, we can pick out the duplicates/replays) on the ballot paper, and attempt to control physical distribution of actual ballots. But now we need to generate a nonce, and we're right back to "I'm sure an LCG is sufficient, right?"
The machines should be kept air-gapped, not connected to the Internet, and all that. But again, human nature kicks in. There have been some poll workers who swore under penalty of perjury that in their polling place, there had been election machines that got an over-the-wire software update on Election Day. That's just... all kinds of wrong, if those reports are accurate. It doesn't prove cheating, but it does prove that whoever was in charge of that polling place should be fired. Because part of the job is making sure everyone knows the results are valid and accurate, and having voting machines connected to the Internet goes directly against "hey, you can see that no hacking is possible here". Doesn't matter how much the machine's manufacturer promises their machines are unhackable, the machines should not be connected to the Internet at all once they are actively being used for voting.
At this point, I'm ready to go back to paper ballots and a locked wooden box (kept in public view, and publicly verified to be empty before locking it up) myself. The simpler the solution, the better, is what I'm arriving at.
"a security vulnerability disclosed back in 2022 shows the shuffle can be reversed, and some states have not applied the software update that resolves it."
"a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots"
"Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing."
I can tell you that before WA went to all-mail voting it wouldn't have happened, because I served as a pollworker and election site inspector. There was a optical scan ballot reader / counter, my confidence is high it only kept running totals. The ballots fell into a bin, at the end of the day the bin was unlocked and the ballots were tossed into bags (no particular order) which were then sealed. As inspector I printed a copy of the tape which went downtown with the bag(s); they would have been able to print a new tape until the machine's memory was wiped (at which point they still had "hardcopy backup"). The ballots were not marked upon by the scanner in any manner. There was an incident where one of the ballot printing / counting companies (because they both typically had to come from the same manufacturer) started printing sequence numbers on ballots (not just ballot styles) and that went to court.
I've not witnessed what happens with all-mail voting, but there is no sequence number on the ballots. ;-) The count is not supposed to start until the polls close. Before that the ballots are ostensibly separated from their identity (the envelope) in an identity confirmation ceremony. My impression is that they're scanned at this point and the scans are utilized for counting / optical scan, but I'm not certain about this or that it's the same everywhere. I don't know what happens to the physical ballots; back in the day what I know is that if a ballot needed to be corrected (defacement or damage renders it unreadable) then a new ballot was prepared under the supervision and adjudication of election observers and the old ballot was destroyed; but that's the exception which proves the rule that physical, anonymized ballots were retained.
The voting process is in the hands of the individual (United) States; in WA it's largely in the hands of the County administrators and varies to a degree Statewide.
We forgot what it took to be where we are.
Draining it, more like.
There's probably an angle I'm not thinking of here, but imho, it's absolutely not John Q. Public's damned business what a person does or does not do on election day.
Originally, everyone in town knew most everyone else and could see them physically walking into the polling place. So long before electronic records were kept, the question of who voted was public information.
Even today, I run my local polling station and I know and recognize a significant portion of the voters in my precinct.
The fact that the list of who votes is made public protects against several kinds of abuses. It goes a long way to protect against "dead people voting" and other kinds of ballot box stuffing if the list of voters is public so anyone can review it and potentially catch such abuses.
i.e. 'Justice must not only be done, but must also be seen to be done'
Now, in that particular case, the state (I believe it was Colorado though I'd have to find the article I read, and I don't remember where to find it any more) didn't require photo ID, so there was no way to prove that the people showing up on Election Day were the actual voters, as opposed to the cheaters. But this poll watcher's opinion was that they were the actual voters, and the cheating had been done by whoever had submitted ballots in their name days (or weeks) earlier. Given how many people she said this had happened to, I'm inclined to agree with her: it wasn't three or four people, it was (she said) something like one-third of the people who showed up on Election Day at that polling place.
That's a case where the fraud couldn't be repaired by knowing that it had occurred — the fraudulent ballots (if they were indeed fraudulent) had already been accepted, and it was impossible to go pull the ballot allegedly belonging to Joe Smith back out of the ballot box. But the publicly-available list of "who voted" did at least make it possible for the fraud to be detected in that particular case.
I personally do support voter ID, and for the same reason. Members of the public must be able to verify the process is happening fairly. It might be fair without it (fraud truly negligible), but it must also be seen to be fair. This would resolve so many controversies.
Likewise mandatory voting and private ballots (can cast a donkey vote) helps ensure the public people are not being paid to vote and that other biases are not coming into play.
My personal opinion is that if people think they can benefit from cheating, a certain number will do so. It's just human nature. We're seeing more and more of this with LLM cheating on the rise in universities. So there's always going to be a certain number of people who want to vote fraudulently — after all, if the right person gets into office, it'll probably benefit you. Your taxes might be lowered, or your government handouts might be increased, or whatever other reason you have for preferring one politician over another. Preference alone does not mean that people will vote fraudulently: after all, most legitimate voters also prefer one politician over another. But the easier you make it to cheat, the more people will cheat successfully: among those who wanted to cheat but didn't, usually the only reason they didn't is because they couldn't see how to get away with it.
So photo ID to vote just seemed like common sense to me, along with other measures like ballot boxes kept in a publicly-visible place until they're opened, to help prove that nobody has tampered with them. (Read up on the 1946 elections in Athens, TN sometime — there, the fraud was being done by the sheriff and his cronies who would take the ballot boxes away, "count" them in private with no outside observers present, and announce that surprise surprise, the sheriff's crony had won the election again).
In the last general election 16,000 people were prevented from voting because they didn't have the correct ID - despite there being mechanisms for them to get suitable ID for free ahead of an election.
Sometimes the fix is worse than the actual problem you're trying to solve.
Also, without a photo ID the fraud rate is near impossible to measure - people can just sell their votes to imposters, fabricate voters, etc. It would be undetectable in your stats. A similar concern applies to postal votes, and there have been high profile cases of this in the UK.
As a concrete example The Tower Hamlets Scandal saw Luftur Raham's election declared null 'on the grounds of corrupt and illegal practices by him and his agents, and general corruption so extensively prevailing so to reasonably supposed to have affected the election' despite a similar number of low hundreds of allegations of fraud. That's a proven-in-court example showing you are wrong to dismiss the concern based on the data. The methods used are clearly not detectable by the system you endorse, and that system has demonstrably lead to the unjust disenfranchisement of your fellow countrymen.
That is why I like voter ID if it relies on documents provided for free with minimal fuss.
However, every US state I'm aware of (if you know of exceptions, please let me know) has some form of photo ID you can obtain for free. Usually it's in the same format as a driver's license, and obtained from the same place (the Department of Motor Vehicles, Department of Land Transportation, the name varies). There's a fee to obtain a driver's license, but a photo ID card (in the same format as a driver's license but marked "NOT LEGAL FOR DRIVING" or similar wording) can be obtained for free, by going through the same process as getting a driver's license (bring something to prove your identity, get your photo taken, wait for the card to be printed) but without taking a driving-skills test.
And before someone asks "what about the people who can't prove their identity"? Well, I can actually give an anecdote. I know someone who ended up in that situation: away from home for college, couldn't get her birth certificate or anything else, and needing to replace her passport that was lost. (She is American but had grown up overseas because of her parents' job, hence why she had a passport but no driver's license when she went off to college). She had quite a time of it at first, since every "prove your identity" requirement circled back around to another form of ID. But she was eventually able to get a fishing license just by swearing under penalty of perjury that she was indeed (name). With that in hand, she got another form of ID (I think a library card, though there my memory is iffy), then with two forms of ID she could get something else, and then eventually she was able to get that non-driver's ID card... and then was able to prove who she was to get her lost passport reissued.
That all happened nearly 30 years ago so I can't swear to the details. But the point is, photo ID cards are widely available, and it's normal to be asked for one. So as long as the law specifies that acceptable forms of photo ID include X, Y, and Z (where X, Y and Z are forms that most people would already have, and that are normal and in common use), and as long as at least one of those forms can be obtained without a fee (which as I said, is true in all U.S. states that I'm aware of, please mention any exceptions you know about because I'd like to know) then it will pass Constitutional muster.
And you have some memory of some account from someone 12 years ago in a state you can't remember saying that a third of voters had someone pretend to be them?
If this were close to true, it wouldn't be some blog post that you can't remember; it would have been a national scandal and it would have been something that we would never forget because the election stealer conspiracy theorists would never let it go.
Really, you should just delete this post as it's irresponsible and lacks any data.
But you did that by making a big, surprising claim for which you haven't provided any evidence. You might not intend for that to be the main thing people focus on, but they are right to be both interested and skeptical! If true, it's a big deal.
The closest thing I could find is this (https://www.thenation.com/article/archive/voters-predominant...), which was attributed to 'human error' rather than fraud, and was resolved by allowing the affected voters to cast provisional ballots. 'Human error' is a vague explanation, and for all I know it was a coverup -- but the onus is on you to provide some positive reason to believe that. Surely there were plenty of people motivated to investigate this, so it would be surprising if a bullshit explanation was just quietly accepted and no further public attention paid.
Not sure why your OG post is still up.
Voter ID solves a non-existent fraud problem and does so by making voting harder.
The idea that if we had paper ballots with walk-in only, ID-verified votes, that Trump and Fox News et al wouldn't have launched a coup attempt, or wouldn't have gotten nearly as far, is pretty laughable. In fact we have Trump on the record saying as much: "It doesn't matter whether you win or lose, you have to fight like hell."
Let's take your scenario. In fact there is a way to verify which vote was correct (and it's used already) which is to match the signatures between the voter registration and the ballot.
This is sufficient except in cases where the registration itself was fraudulent, which would have required 1) having someone's ID at time of registration and 2) intercepting the mail sent to their ID- or utility-bill-confirmed mailing address.
An attacker who could achieve that could also have achieved just walking into the polling place to achieve the same false vote.
Any attack is extremely expensive to do at any meaningful scale, and all scaled attacks are detectable by simple statistical sampling.
If meaningful amounts of tampering were detected by statistical sampling then you can obviously re-run elections with tighter controls, more burden, lower turnout, and a generally-less-representative result, which is why we start with a more inclusive system. This can and does actually happen. Whether it's necessary is literally 100% statistically knowable through basic sampling.
I don't think they can be dealt with. But I'm willing to listen to your ideas. How would you deal with vote buying? How would you stop the scenario where a guy says "I'll give you $1,000 if you vote for candidate X" (or "I know where you live, I'll break your kneecaps if you vote for candidate Y")?
Quite a few husbands believe they should have control over their wives' votes. I guess you'd say they should have the courage to leave them and wreck their children's lives and be ostracized by their family and community?
And it's not hard to imagine certain employers having a strong opinion on how you vote on specific measures. Of course they couldn't compel anyone to reveal their votes, but it could be made customary enough that refusing to would be enough of a signal. I guess you'd need the courage to quit and take a lower paying job?
As for what happens in marriages or other social settings, yes, wives can coerce their husbands, fathers can coerce their adult daughters, friends can coerce one another. If your counterpart is the kind of person who would threaten to blow up your relationship over how you vote, yes, I would suggest maybe that tells you something about who they are and whether or not you want them in your life. But if the relationship means that much to you, you can always go along to get along and let them tell you how to vote. I think that says something about how much you value your vote though. And at the societal level, I don’t think this would have a meaningful impact on governance
Of course it's pretty impractical that a bunch of concerned citizens might gather together and check the published data against how they each remember voting. But preserving the possibility in principle makes it easier to trust the published results. It gives a would-be deceiver yet another thing to worry about.
Its a trade-off I'd have opted into had I been asked. Though I'd feel a lot better about it if I had been asked.
But it's such a specific structure, clearly there was an objective in mind when it was imlpemented.
Actually, it does. If the party you are registered with thinks are a voter who might not make it to the polls, and this is a close/important election, then there is a good chance you will receive numerous calls and/or visits reminding you to go out and vote. However, if you show up on the list of people who have voted by mail OR if you appear on the registry of people who have already voted in person, then they will stop reaching out to offer rides and reminders.
It's hard to say how much impact it has, but presumably there's a degree of social pressure when people are seen wearing/posting all those "I voted today" stickers.
> Tied to a specific ballot is the stronger claim and requires one additional public record.
clearly a claude-ism
I guess the author went back and forth running pangram and slightly tweaking the text until it read "0% LLM text"
The biggest problem I see related to that is the marked haziness over what exactly has been accomplished. As best I can tell, this paper claims to have deanonymized primary election ballots that were cast during the early voting period. But it's written as if it was deanonymizing general election ballots cast on election day.
This is in the site guidelines: https://news.ycombinator.com/newsguidelines.html.
> HN is for sharing between humans
My (and others’) comments are knee jerks when that guideline gets violated.