Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The paper trail is not so wonderful.

What we saw in 2016 was that even if a candidate were to contest a result, none of the election committees were willing to commit to a full hand recount; instead, the only options were to retabulate through the very same tabulation processes and machines that had produced the questionable results in the first place.

Without low barrier to recount by hand, the electronic systems production of paper trails is worthless. Arguably worse than worthless, because it leaves everyone thinking there is a usable backup, when there isn't.



This is absolute hogwash, there are other methods than a full hand recount if you have a paper trail, some of which only require counting a small number of the ballots by hand.

The best example of this is a Risk Limiting Audit (RLA). You only have to re-count a smaller number of ballots until the overwhelming probability is that the vote is confirmed, or that the vote is rejected. Depending on the disparity between the ballot options, this count can actually be very small.

See: https://www.stat.berkeley.edu/~stark/Preprints/gentle12.pdf

This system is perfect for this kind of an audit -- essentially a ballot marking device written by an organization known for formal verification.


During the mid aughts, the consensus of the Election Verification Network (EVN) crowd (academics, election administrators, feds) was that audits were no better than manual recounts and just as expensive.

I'll read the paper you linked, but know that it's contrary to the received wisdom, and I'm very skeptical of any claims that auditing elections are feasible or worthwhile. By audit, I mean anything short of a full manual recount.

--

Okay. I lightly read that paper.

First, it specifically says to only audit the VVPR, meaning the actual ballots, not the VVPAT, which is just what the computer says it recorded. So there might be some miscommunication. I assumed #bdamm was referring to the VVPAT.

Second, the meat of the paper is refinements for calculating the confidence that the official result is correct based on recounting a sample. All of the caveats with audits, not within the scope of this paper, remain the same.


More reading: https://www.npr.org/2017/11/22/566039611/colorado-launches-f...

Colorado successfully performed an RLA, and didn't have to recount every ballot. If you really want to read more, Free and Fair (IIRC, the same group bidding on the DARPA grant) has open source software and instructions on how to perform RLAs: https://github.com/FreeAndFair/ColoradoRLA


> none of the election committees were willing to commit to a full hand recount

I don't see how any system can work if nobody is willing to double-check it.


You don't have to recount "by hand". You start with auditing by hand - looking at a sample and seeing if it's accurate. Then you run the original paper ballots through another scanner.


With too low a barrier to recount-by-hand, every election becomes contested because the cost to demand a recount is minimal and the losing candidate might win.


Where's the problem? I've been leaning towards the idea that maybe every election should have a hand count. You can get your electronic count first for the early announcements, but it should be verified by the hand count. What's the downside, just the cost? Seems likely worthwhile to me.


The problem is that the vast majority of elections aren't counted incorrectly, and you're vastly increasing the cost on an under-funded system for no benefit in five-nines of the cases (and the remaining cases can have a recount triggered by one of the candidates, but not at no cost to them).


I fail to see what the downside is of counting every election twice.

Frankly the cost of elections doesn't seem to be a serious problem for any government. They're choosing to fix some roads instead of boosting the quality of elections. Frankly I'll take the election over potholes or whatever else the government is spending money on, because if I can't trust the election, I can't trust the government.


Not sure why hand counting is so difficult. In the UK we hand count elections. It is just a matter of sorting ballot papers into a pile for each candidate. This pile can then be easily checked to make sure that no vote has been mis-recorded.


Sort and stack is pretty good. When done at poll sites, it's fairly manageable (many hands make light work).

In the USA, federal, state, and local contests are all on the same ballot. Where I live, general election ballots have 30+ items.

For manual counting to be feasible, we'd have to split into separate ballots.

Of all the people I've spoken with over the years, there's been no objections to this. But it is a big change and there's been no advocacy.


Having too many races on the same ballot already compromises ballot secrecy, to an extent.

"We want you to vote for Jim Totes-Legitimate for President. But so that we can recognize your ballot paper and we can verify that you voted for him and we don't have to break your kneecaps, please also mark your other ballot races as follows: Fred Also-Ran for First Assistant Flangedoodle, Sheila Plausible for Second Assistant Flangedoodle, Hazel Placeholder for Junior Hog Counsellor."


Browser fingerprinting for ballots -- how many bits of entropy on a long ticket?

Not hard if you've got 10 or so multi-way contests or 20 or so ballot measures.


Exactly.

Which is also why the cryptographic voting systems cannot protect voter privacy. Those systems require hash collisions to hide your ballot in the herd of ballots. But the combination of precinct size and complicated ballots means any particular ballot is utterly unique (no hash collision).

I'd be far more charitable towards crypto advocates if they also specified the conditions required for their system to work correctly.


Yup.

Similarly, with postal balloting (vote by mail), your ballot is batched (upon receipt), so will be mixed with ballots from other precincts, therefore more easily tied back to its voter.


During one of VVPAT audits I observed, they just switched out the unreadable memory stick.

Best as I can tell, the only thing determined from the audit was that the machines still powered on and the printers worked.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: