An algorithmic failure beneath the secret ballot

(citp.princeton.edu)

64 points | by leecoursey 2 days ago

10 comments

  • RA2lover 2 minutes ago
    Diego Aranha had found an exploit with brazilian voting machines back in 2017. They scrambled votes whenever every vote was cast using a CSPRNG, but initialized its seed with the time the voting machine had been turned on (rounded to the second), which due to voting protocols at the time meant you only had to have one person vote a specific way and bruteforce 3600 orderings to find that person's vote and ballot secrecy for everyone else who voted on the same machine.

    Seems like this is the same mode of failure, which is strange considering diebold made the brazilian machines back then and should have fixed that.

  • anilakar 35 minutes ago
    > To keep the published record anonymous, ballot scanners shuffle the electronic records randomly before releasing them

    So they were never secret in the first place.

    I have never understood the desire to have voting machines when a paper ballot works just fine. We tried electronic voting in three municipal elections in 2008 and courts ended up invalidating the results due to horrible usability issues.

  • cryptonector 1 hour ago
    The way this sort of problem has been fixed in Texas since 2024 is to require that all ballots be sequentially numbered -- that is, they arrive at polling locations in packs of 50 or 100 ballots, each pack having sequentially numbered ballots, but the presiding judge takes 10-20 at a time, signs them, then shuffles them, places them with the serial number facing down towards the table, and voters get to pick one at random when they check in.
  • beloch 1 hour ago
    "In October 2022, a team of researchers published a report showing that certain ballot scanning machines used throughout the US had a critical privacy failure in how they anonymized ballots. Specifically, the machines would assign a seemingly random number to each electronic ballot record at the time of scanning to label each ballot for later auditing. However, the algorithm by which the machines generate this random number is actually deterministic and can be exactly reversed to identify the sequence in which ballots were cast.

    ...

    Naturally, knowing the order ballots were cast is just one piece of the puzzle. But, when paired with publicly available records on the order in which voters cast their ballots (such as logbooks or poll watchers), a simple procedure exists to reconstruct the mapping from ballots back to voters."

    ---------------------

    1. Either upgrade your pseudo-RNG's to real RNG's ($$$) or omit the "random" number from records.

    2. Alternatively, just use plain paper ballots. (Yes, I know America is extra-superduper special and ordinary paper ballots that work everywhere else on the planet will never work in America. Special requirements, too many people, labour intensive, politicians hate them, the moon is in the wrong phase, etc..)

    I understand there is the desire to provide a paper trail that can be used to validate results, but being able to track individual ballots back to the people who cast them is not a feature of a functioning democracy. This is the sort of thing Russia would want to do. People need to feel their secret ballots are, indeed, secret.

    • deathanatos 1 hour ago
      > Alternatively, just use plain paper ballots.

      Eh … I can't tell from the article entirely, but the picture of the machine looks very familiar (and the one in the paper even moreso), and if it is the same machine as what my precinct uses, they are paper ballots. (My state is highlighted in the paper as having been vulnerable, too.) See figure 6a in the paper, which is a good view of the paper ballot.

      If I've the right machine, these are just paper ballots, marked with pen. The machine is just an automated vote-counter that can read the ink off the paper. I've always assumed these provide a rough, quick tally that can give information in elections that aren't close, while the real human tally follows up with the official count in due time. (I do not really see how an anonymized per-ballot record really proves election integrity, per TFA. Seems like the data could be faked, though it not matching the official count would also be suspect, too. … there is no substitute for poll watching?)

      This (assigning a hardly-random number) is essentially tagging the ballot with a sequence number when you drop it in the box — an utterly unnecessary step.

      (If your point is that the machine could simply be ditched for a locked wooden box … yes, quite possibly so.)

      > Either upgrade your pseudo-RNG

      It seems grossly negligent that a voting machine is using a non-CSPRNG.

      > Dominion has not shared any details about the new PRNG.

  • rapidaneurism 13 minutes ago
    I feel a bit silly, but I do not understand how the results were verified.
  • lenerdenator 4 hours ago
    > this allows you to know whether your neighbor voted, but never who they voted for.

    There's probably an angle I'm not thinking of here, but imho, it's absolutely not John Q. Public's damned business what a person does or does not do on election day.

    • mcherm 4 hours ago
      The practice of making public whether someone has voted dates back a very long time. There were practical reasons for it when it originated, and many of those remain valid today.

      Originally, everyone in town knew most everyone else and could see them physically walking into the polling place. So long before electronic records were kept, the question of who voted was public information.

      Even today, I run my local polling station and I know and recognize a significant portion of the voters in my precinct.

      The fact that the list of who votes is made public protects against several kinds of abuses. It goes a long way to protect against "dead people voting" and other kinds of ballot box stuffing if the list of voters is public so anyone can review it and potentially catch such abuses.

      • skew-aberration 4 hours ago
        The value of transparency goes above and beyond protecting against abuses (for which there are other methods) - it also provides assurance to the public that there is protection against those abuses, and that those abuses are not taking place.

        i.e. 'Justice must not only be done, but must also be seen to be done'

        • derektank 14 minutes ago
          Yet so few people go the next step and say, “Let’s do away with the secret ballot itself.” It really is a recent invention, American democracy survived nearly 100 years before the Australian ballot was adopted. There are obviously concerns (vote buying, organized crime, etc) but they can be dealt with. And public voting would almost completely eliminate concerns about the voting process itself being subverted by a malign actor.
        • rmunn 1 hour ago
          I once read an account by a poll watcher of her experience in 2012. She said that at her polling place, there had been a number of people showing up to vote on Election Day, being told they had already voted during the early-voting process, and swearing up and down that that wasn't true, that they always voted on Election Day and never voted early, and that whoever had voted in their name had done so fraudulently.

          Now, in that particular case, the state (I believe it was Colorado though I'd have to find the article I read, and I don't remember where to find it any more) didn't require photo ID, so there was no way to prove that the people showing up on Election Day were the actual voters, as opposed to the cheaters. But this poll watcher's opinion was that they were the actual voters, and the cheating had been done by whoever had submitted ballots in their name days (or weeks) earlier. Given how many people she said this had happened to, I'm inclined to agree with her: it wasn't three or four people, it was (she said) something like one-third of the people who showed up on Election Day at that polling place.

          That's a case where the fraud couldn't be repaired by knowing that it had occurred — the fraudulent ballots (if they were indeed fraudulent) had already been accepted, and it was impossible to go pull the ballot allegedly belonging to Joe Smith back out of the ballot box. But the publicly-available list of "who voted" did at least make it possible for the fraud to be detected in that particular case.

          • skew-aberration 37 minutes ago
            I think all you can do is sue at that point.

            I personally do support voter ID, and for the same reason. Members of the public must be able to verify the process is happening fairly. It might be fair without it (fraud truly negligible), but it must also be seen to be fair. This would resolve so many controversies.

            Likewise mandatory voting and private ballots (can cast a donkey vote) helps ensure the public people are not being paid to vote and that other biases are not coming into play.

            • rmunn 19 minutes ago
              I'm not entirely sure mandatory voting is wise in a country the size of the United States, but I'm with you on the voter ID and the rationale. I was shocked to learn that with everything else that requires photo ID, it's not required to vote in American elections. (At least, in some locations; laws vary from place to place). That just looks bad.

              My personal opinion is that if people think they can benefit from cheating, a certain number will do so. It's just human nature. We're seeing more and more of this with LLM cheating on the rise in universities. So there's always going to be a certain number of people who want to vote fraudulently — after all, if the right person gets into office, it'll probably benefit you. Your taxes might be lowered, or your government handouts might be increased, or whatever other reason you have for preferring one politician over another. Preference alone does not mean that people will vote fraudulently: after all, most legitimate voters also prefer one politician over another. But the easier you make it to cheat, the more people will cheat successfully: among those who wanted to cheat but didn't, usually the only reason they didn't is because they couldn't see how to get away with it.

              So photo ID to vote just seemed like common sense to me, along with other measures like ballot boxes kept in a publicly-visible place until they're opened, to help prove that nobody has tampered with them. (Read up on the 1946 elections in Athens, TN sometime — there, the fraud was being done by the sheriff and his cronies who would take the ballot boxes away, "count" them in private with no outside observers present, and announce that surprise surprise, the sheriff's crony had won the election again).

            • rapidaneurism 14 minutes ago
              An added benefit of voter id is that by making it easy or cheap for one groups and difficult or expensive for an other (or choosing acceptable IDs that already have these characteristics) you can create some friction to make it more difficult for the wrong people to vote.

              That is why I like voter ID if it relies on documents provided for free with minimal fuss.

    • __MatrixMan__ 3 hours ago
      I suspect the missing angle is that people are more likely to trust claims made to the public if, in principle, those claims could be verified by the public.

      Of course it's pretty impractical that a bunch of concerned citizens might gather together and check the published data against how they each remember voting. But preserving the possibility in principle makes it easier to trust the published results. It gives a would-be deceiver yet another thing to worry about.

      Its a trade-off I'd have opted into had I been asked. Though I'd feel a lot better about it if I had been asked.

    • allforJesse 4 hours ago
      I was thinking the same. It's not as if visibility into whether someone voted or not has driven voter turnout significantly. Hell, I'd assumed this was private until I learned otherwise recently.

      But it's such a specific structure, clearly there was an objective in mind when it was imlpemented.

      • mcherm 4 hours ago
        > It's not as if visibility into whether someone voted or not has driven voter turnout

        Actually, it does. If the party you are registered with thinks are a voter who might not make it to the polls, and this is a close/important election, then there is a good chance you will receive numerous calls and/or visits reminding you to go out and vote. However, if you show up on the list of people who have voted by mail OR if you appear on the registry of people who have already voted in person, then they will stop reaching out to offer rides and reminders.

        • BobbyTables2 2 hours ago
          What if the opposing party knows you haven’t voted yet?
      • autoexec 3 hours ago
        > It's not as if visibility into whether someone voted or not has driven voter turnout significantly.

        It's hard to say how much impact it has, but presumably there's a degree of social pressure when people are seen wearing/posting all those "I voted today" stickers.

      • thaumasiotes 4 hours ago
        The registry of people who voted has to exist because you're not allowed to vote more than once. That reason doesn't require the registry to be published, but it does require it to be compiled.
  • allforJesse 4 hours ago
    When I hit the term "load-bearing" in the first sentence my mind immediately turned off. Had to forcibly reengage in reading. Claude trauma is real.
    • rosstex 3 hours ago
      As an ex-CITP member, that's most definitely a human written joke.
    • thaumasiotes 4 hours ago
      The report does feel like LLM output.

      The biggest problem I see related to that is the marked haziness over what exactly has been accomplished. As best I can tell, this paper claims to have deanonymized primary election ballots that were cast during the early voting period. But it's written as if it was deanonymizing general election ballots cast on election day.

  • leecoursey 2 days ago
    [dead]
  • digitalPhonix 3 hours ago
    [flagged]
  • baggy_trough 2 hours ago
    [flagged]