I had no opinion before now, but clearly these machines are unusable anywhere.
Colorado resident here. The CO Secretary of State has been proactive about everything election related. There's complete, transparent procedures for voting, there's educational materials about the risk limiting audits that get done for every election.
All registered voters get a ballot in the mail. You can return them by mail, use a secured drop box which reside in locations under security camera. You can check your ballot's status on-line, and get email updates. You can also vote in person, should you want, on election day.
Some yahoo state rep introduced a patently-unfair bill that would have made CO do things like stop counting on midnight of election day, which would almost certainly leave large fractions of ballots uncounted no matter how you vote, mail or in-person. No way around that. Thankfully, the CO legislature is not particularly crazy this year, so it failed.
The conspiracy theorists caused the breech - the Mesa County Clerk is the one that c illegally copied the voting machine hard drives and gave the images to other conspiracy theorists.
You are putting the blame exactly in the wrong place.
E.g. here's sci am on 2016: https://blogs.scientificamerican.com/guest-blog/election-sec...
Contesting only elections that don't go your way and providing dubious or nonsense evidence (see various thrown out lawsuits) is simply subverting the process and the electorate.
If they're unusable, then they're unusable everywhere : and the election needs to be run without them.
> When the entire election in a district is run by officials from a single political party, with unlimited access to the voting machines
This probably shouldn't happen. Unfortunately, hyper-polarisation has.
According to the article they disabled the security cameras monitoring the machines for a week.
Once someone deliberately breaks the chain of custody on voting equipment, whether it’s electronic or a paper ballot box, it becomes suspect. Not only that, but the machines are now evidence in the investigation, so they have to be set aside anyway.
Replacing the equipment was the only option. There is no perfectly secure voting system that isn’t affected by chain of custody breaks.
You hit the nail on the head. Election systems must be obviously honest to low information voters in the other party who don’t trust the election officials.
All politics aside, it's fairly obvious that electronic voting machines can be very dangerous unless they're handled very, very, very carefully. The contracts for these machines aren't going to the best of the best, they're going to the lowest bidders. As a software engineer, the idea of going from manual, verifiable tabulation to opaque software is completely horrifying.
It is significantly harder to forge thousands of paper ballots. Not impossible, but not nearly as easy as manipulating opaque software or simply gaining access to these machines.
People can actually observe and confirm the tabulation process currently. All machines should be open-source and easily audited if we want to inspire any sort of confidence in them to the average voter.
If the only way a bank (or its depositors) knew the bank had been robbed was if the robbers told everyone they'd robbed that bank, would we consider the bank secure, no matter what consequences employees faced?
There seems to be a fundamental failure of process with no plans to actually improve security in the future.
The more interesting question is, what are the knock on effects of a popular loss of confidence in western elections held with these machines?
> Griswold also said that one week before the breach, Peters ordered her staff to turn off the video surveillance system that monitors the voting machines and that it was only recently turned back on.
Somehow they ended up with an unauthorized person attending a procedure to update the machines, which then resulted in video and other information being posted to a QAnon-affiliated blog.
Replacing the potentially compromised machines is a good move, but it seems like the real story is that something has gone very wrong inside this government office.
This is probably about the point where you should ask your boss's boss "is this okay?" rather than just following orders, tbh. The whole thing is bizarre.
Any election official that shows allegiance to such theories should be summarily banned from ever holding public office.
How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review?
If they are compromised, I'd love to see a post mortem and understand how they were compromised and how that can be mitigated going forward.
I doubt the officials suspect the machines have been compromised, but they have no way of knowing. There are chain of custody rules to help ensure integrity of the systems. Those have been violated so the machines can't be used until they've been carefully examined and recertified.
Putting this in a money context might help some--lets say you owned slot machines that could have big payouts. Would you let rando unauthorized person to be alone with one of your machines in a private office, doing upgrades, and still trust the machine? Probably not. You'd want to take a look at it top to bottom before trusting it to do any payouts. The person might not have done anything wrong but you've got to be sure first, and since there are other ways these things could be compromised than just adding unauthorized software to the hard drive, a clean install isn't enough.
I mean, _probably_. There's malware that's extremely difficult to get rid of, but probably it wasn't used here.
But it looks like they have elections coming up in a few weeks, so "do it on paper" is probably a not-unreasonable precaution, particularly given the general pattern of dodginess, in particular the thing about the video surveillance.
If nothing else, if you phone up the manufacturer and tell them that a weird pillow website devotee allowed some unknown third party to potentially mess with the machines, the manufacturer is probably _not_ going to say "yeah, that'll definitely be fine, use them"; they won't want to take the risk. This is probably a return-to-manufacturer job.
As soon as an unidentified attacker has unsupervised access to a piece of hardware it's game over. An exploit that uses persistence features like embedding itself into the BIOS/UEFI firmware (see e.g. https://www.coresecurity.com/core-labs/articles/the-bios-emb...) can be very hard to get rid of - so hard that it's likely easier to dispose of the machines entirely.
They’re now evidence in an ongoing investigation. They don’t know exactly what happened to them because the perpetrators deliberately disabled the security cameras monitoring the machines before doing whatever they did.
Wiping them could destroy evidence or it could miss a different issue (hardware modification, for example).
The only reasonable response is to quarantine the machines as evidence and replace them with new machines with a known chain of custody.
> How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review?
There’s more to the story, including someone intentionally disabling the security cameras that monitored the machines for at least a week. With a gap in the surveillance of the machines combined with a QAnon-associated leak and an intruder who misled the office, it’s time to start fresh and set the old machines aside as evidence.
The phrase "voting system" is an absurdity. It highlights the overly complex, bug-riddled lunacy we have now.
A lockbox, under guard with multiple observers, collecting ballots over the voting period, followed by a public counting of the paper ballots is simple and fast. What we have now isn't.
They go to one of the booths and mark their selection, and drop it off into a zip-tied big ballot box (that is visible to the general public, and of course election staff at all times).
After the polls close, the polling official cuts the zip-ties on the ballot boxes, everyone working sorts ballots into piles and count them, along with scrutineers from political parties who can watch. An officer-in-charge records and publishes the results continuously, and everything is saved and shipped for OCR-based recounting to verify the numbers. The process is federally operated and the same processes are followed everywhere.
Results are almost always revealed on election night.
The electoral roll books are processed centrally after every election, so someone who votes twice would be quickly caught. Someone who votes under fake names and addresses would most likely cross-over with someone else, hence an investigation would still happen. (We also have compulsory voting, which is another subject for debate, but it does mean "vote under multiple names" is mitigated without the need for ID laws).
The job pays reasonably well (A$457 for the day), more or less everyone who applies gets hired (I believe there is a bias towards maximizing first-time applicants), and it's hard to think about election fraud when every citizen can be part of the election process itself, and it's hard to conceive of how fraud can happen.
How many of those countries have as many races on a typical presidential-year ballot as the US does?
The US is also generally pretty fast to count its ballots; note that the election result is usually known within hours of polls closing, despite the insane number of races on the ballots. What happened in 2020 is there was an unusually high number of mail-in ballots, and this was combined with several states intentionally slowing down the counting process.
It’s also not available because making people show up to a few set of fixed locations at specific polling hours will exclude people who don’t have access to transportation which is why during the Obama election the big thing was the Obama campaign providing busses to voters.
If you’re willing to give up some anonymity (only that you voted not what/you voted for) then mail in ballots, public drop-boxes, and walk-in deposits are much faster and more available. If you can mail in then great! Done. If you want to go to the polls then you fill out your ballot ahead of time, verify yourself with the poll worker and then drop it in the box. Done. 30 seconds a person rather than 10 minutes a person.
I think the culture in the US surrounding voting is the real issue. The discussion is always around security and integrity and making sure only the right people vote which are the kind of problems people who read too many Tom Clancy books care about. Meanwhile we only get at most ~50% turnout every year and people have to fight to actually cast their ballots. And we pretend that our election results actually mean something when half the country doesn’t vote and the sample that does is so skewed because the factors that keep people from voting aren’t random.
Really, we should just be switching to using scantron style ballots everywhere. They're paper ballots which can be efficiently counted by a machine, and are super easy to manually recount later
I really like the system we have in DFW now. We have a global voter roll so you can vote in any location in your county. You submit your vote on a machine, which keeps a local machine-level tally and prints out a paper ballot. You verify the contents of the paper ballot, then drop it into a vote counting box, which scans, tallies, and displays your vote for you to confirm. If at any time anything looks wrong, you notify a poll worker to resolve it. At the end of each day, they verify the counts on the machines and ballot box match, then the ballot counter/box is locked along with the memory cards of each individual machine, so you have day-by-day results.
When the election ends, the ballot boxes are delivered to a central county counting system where they are put into another large-scale counting machine to verify that the counts there match the local counter/box. If at any point there's too many discrepancies, they'll do hand counts of the paper ballots. They can also unlock the voting machine memory cards if necessary. All of this process is done under the supervision of poll watchers.
In theory, you get near instantaneous results as each voting location can simply total the ballot box results and report them. You also have 4 separate systems (voting machine, local counter/ballot box, central counter, paper backups) that would need to be compromised to successfully tamper with the results.
I'm sure it wouldn't make a conspiracy theorist satisfied, but to me, it's a system that balances speed and convenience with the simplicity and security(?) of a paper ballot, without unnecessarily obfuscating the process behind electronic-only voting.
Notice i use the word "systems" to include the human element as well as all the other components that go into making what we have today far from an acceptable system of voting in the most powerful individual on the planet.
Problems are to be expected, as long as the system can detect and deal with the breach, democracy is protected, albeit at greater cost in this instance.
Is not something that anybody trying to ensure trust in elections should ever say.
Heh. What’s that saying, “even paranoid people have enemies.”
And what benefit do they offer over a hand count, to justify so much risk?
Just because the Republican's allegations about fraud were without merit, does not mean electronic voting is a good idea.
I might be tempted to say that the voters of Mesa County deserve having their freedoms stolen away. A vital part of democracy is holding transgressors accountable, and the voters of Mesa County have failed their responsibility.