# Electronic voting machine fraud..is it possible?

**URL:** <https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103>\
**Category:** Factual Questions\
**Created:** [July 8, 2003, 10:12pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103 "2003-07-08T22:12:57Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Reeder](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Reeder](https://boards.straightdope.com/u/Reeder)\
**Post date:** [July 8, 2003, 10:12pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/1 "2003-07-08T22:12:57Z")

</div>

I give for your perusal…

[http://whatreallyhappened.com/insideUSvote.html](http://whatreallyhappened.com/insideUSvote.html)

[http://whatreallyhappened.com/biggerthanwatergate.html](http://whatreallyhappened.com/biggerthanwatergate.html)

[http://whatreallyhappened.com/flawfound.html](http://whatreallyhappened.com/flawfound.html)

For those more in the know than myself. Are these guys blowing smoke or is it really possible?

If it is…oh my god.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [July 8, 2003, 10:15pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/2 "2003-07-08T22:15:40Z")

</div>

I have no idea about the credibility of that site, but as far as I know, no voting machine company has released their encryption or authentication technology for public scrutiny. Based on my experience with security technology, any system which is not peer-reviewed by cryptographic experts is _de facto_ vulnerable.

But that’s just my opinion.

---

<div class="post-metadata">

**Author:** ![Reeder](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Reeder](https://boards.straightdope.com/u/Reeder)\
**Post date:** [July 8, 2003, 10:30pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/3 "2003-07-08T22:30:50Z")

</div>

The site are just mirror sites. The main site was overloaded.

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [July 8, 2003, 11:08pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/4 "2003-07-08T23:08:02Z")

</div>

There are so many spots to compromise electronic voting systems.

The voting terminals themselves can be jiggered.  
Assuming the terminals at a polling place are aggregated for transmission, the server they’re connected to can be tampered with.  
The data sent to the central server at the elections department can be intercepted and changed  
The central server(s) can be messed with.

How will you know that the voting terminals were’t programmed to report every third vote for Candidate B as one for Candidate A? Sure, the thing may print a receipt showing you voted for B, but do you really know it transmitted B?

I could go on, but won’t - just not enough time right now.

Security will come in the form of a mix of old-fashioned physical security and high-tech encryption and validation techniques. And a whole lot of trust.

Being in the information security business, I’m not convinced we’re ready for electronic voting.

---

<div class="post-metadata">

**Author:** ![Reeder](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Reeder](https://boards.straightdope.com/u/Reeder)\
**Post date:** [July 8, 2003, 11:13pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/5 "2003-07-08T23:13:57Z")

</div>

What gets me is there is no paper trail.

That’s scary.

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [July 8, 2003, 11:22pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/6 "2003-07-08T23:22:19Z")

</div>

Back when I lived in New Mexico we used mechanical voting machines. They did not provide a paper trail either.

---

<div class="post-metadata">

**Author:** ![Belrix](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Belrix](https://boards.straightdope.com/u/Belrix)\
**Post date:** [July 8, 2003, 11:24pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/7 "2003-07-08T23:24:12Z")

</div>

Slashdot posted today a reference to a New Zealand article concerning potential voting machine fraud.

[http://www.scoop.co.nz/mason/stories/HL0307/S00065.htm](http://www.scoop.co.nz/mason/stories/HL0307/S00065.htm)

Pretty scary.

---

<div class="post-metadata">

**Author:** ![Belrix](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Belrix](https://boards.straightdope.com/u/Belrix)\
**Post date:** [July 8, 2003, 11:31pm UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/8 "2003-07-08T23:31:22Z")

</div>

Further linkage - a meta article for the link above:

[http://www.scoop.co.nz/mason/stories/HL0307/S00064.htm](http://www.scoop.co.nz/mason/stories/HL0307/S00064.htm)

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [July 9, 2003, 12:05am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/9 "2003-07-09T00:05:47Z")

</div>

In principle it _is_ possible to design a system which is secure but it can get pretty technical

The concept of [blind digital signatures](http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22blind+digital+signatures%22) would come in handy as well as other concepts like observers and agents.

[http://ntrg.cs.tcd.ie/mepeirce/Project/Chaum/sciam.html](http://ntrg.cs.tcd.ie/mepeirce/Project/Chaum/sciam.html)

Yes, it is possible for voter A to cast a vote and encrypt it. then have the observers for different parties sign it digitally to validate it and then have a program be able to count the votes for each candidate and not be able to connect each vote with each voter.

It works in a similar way for untraceable digital ash.

---

<div class="post-metadata">

**Author:** ![Reeder](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Reeder](https://boards.straightdope.com/u/Reeder)\
**Post date:** [July 9, 2003, 12:17am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/10 "2003-07-09T00:17:25Z")

</div>

So what y’all are saying is that in any district using electronic voting the elections can be suspect?

They are used in 30 states and more are going to them.

It’s worth a look to see who owns the various companies that make these machines.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [July 9, 2003, 12:40am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/11 "2003-07-09T00:40:25Z")

</div>

> [@](#):
>
> \*Originally posted by Reeder \*  
> So what y’all are saying is that in any district using electronic voting the elections can be suspect?

Did you read my post? I said exactly the opposite.

---

<div class="post-metadata">

**Author:** ![micco](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@micco](https://boards.straightdope.com/u/micco)\
**Post date:** [July 9, 2003, 1:00am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/12 "2003-07-09T01:00:33Z")

</div>

> [@](#):
>
> \*Originally posted by sailor \*  
> \*\*Did you read my post? I said exactly the opposite. \*\*

Do any of the systems actually implemented use the algorithms you cite? Almost all of the systems I’ve seen have not been open for review which, as **friedo** points out, means that they should be assumed insecure. I’ve seen a few which published specs but not source code so there’s no way to know if they meet their own specs. I haven’t seen any which even claim to use blind signatures. Mathematics is all fine and good, and I certainly trust Chaum’s work, but there’s a huge difference between a well-designed algorithm and a secure implementation ready for the real world.

I haven’t done anything like a complete survey of the industry, but given what I have seen, I think Reeder’s assumption that all the systems currently installed are suspect is a safe bet. Certainly safer than assuming the opposite. At the very least, any citizen in a precinct using these systems needs to push for full disclosure and qualified review.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [July 9, 2003, 1:09am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/13 "2003-07-09T01:09:07Z")

</div>

I do not have any capacity to judge the implementations but I think that, even if we had all the information, we would not be capable of serious analysis here so my trust would come more from the political parties and independent observers agreeing they are safe.

The fact that they are not open for review is indeed troubling but then I do not see why all parties would accept them.

---

<div class="post-metadata">

**Author:** ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)\
**Post date:** [July 9, 2003, 1:12am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/14 "2003-07-09T01:12:42Z")

</div>

Why not just use pencil and paper, like Canada did in its last federal election?

---

<div class="post-metadata">

**Author:** ![LordVor](https://avatars.discourse-cdn.com/v4/letter/l/90ced4/32.png) [@LordVor](https://boards.straightdope.com/u/LordVor)\
**Post date:** [July 9, 2003, 1:28am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/15 "2003-07-09T01:28:11Z")

</div>

> [@](#):
>
> \*Originally posted by Reeder \*  
> \*\*It’s worth a look to see who owns the various companies that make these machines. \*\*

Isn’t the CEO of one currently serving a term in the House of Representatives for some sparsely-populated state?

-lv

---

<div class="post-metadata">

**Author:** ![Reeder](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Reeder](https://boards.straightdope.com/u/Reeder)\
**Post date:** [July 9, 2003, 1:52am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/16 "2003-07-09T01:52:30Z")

</div>

Interesting site…

[http://www.blackboxvoting.com/modules.php?name=News&file=article&sid=15](http://www.blackboxvoting.com/modules.php?name=News&file=article&sid=15)

---

<div class="post-metadata">

**Author:** ![SmackFu](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@SmackFu](https://boards.straightdope.com/u/SmackFu)\
**Post date:** [July 9, 2003, 1:52am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/17 "2003-07-09T01:52:42Z")

</div>

I’ll only critique the tech-ish parts, since this is somehow in GQ (though being steered out of it).

The detailed reports in her scenario won’t balance to the summary reports, unless she modifies both copies of the ledger. So this is not “untraceable”.

Plus the whole thing is predicated on a complete lack of security to the database tables. For instance, what’s the point of an audit table if you can delete rows directly from it by editing the tables? That doesn’t ring true to me.

Also, not sure about this bit:

> [@](#):
>
> From an accounting standpoint, using multiple sets of books is NOT OKAY.

What’s so bad about multiple sets of books, as long as they are both public? You can compare them for discrepancies.

---

<div class="post-metadata">

**Author:** ![Shoeless](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/shoeless/32/7099_2.png) [@Shoeless](https://boards.straightdope.com/u/Shoeless)\
**Post date:** [July 9, 2003, 1:56am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/18 "2003-07-09T01:56:18Z")

</div>

**LordVor** , I believe you are talking about Sen. Chuck Hagel from Nebraska, who won his last election with something like 83% of the vote. Tell me _those_ aren’t fishy numbers…

---

<div class="post-metadata">

**Author:** ![LordVor](https://avatars.discourse-cdn.com/v4/letter/l/90ced4/32.png) [@LordVor](https://boards.straightdope.com/u/LordVor)\
**Post date:** [July 9, 2003, 4:06am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/19 "2003-07-09T04:06:24Z")

</div>

Right \*\* Shoeless\*\*, didn’t he beat a popular incombant as well? And the voting machines that his company made were in use in much of the state, and his software never went through public review? Granted, I think I’m talking from what I remember of an old Newsweek piece…

---

<div class="post-metadata">

**Author:** ![don\_t\_ask](https://avatars.discourse-cdn.com/v4/letter/d/e68b1a/32.png) [@don\_t\_ask](https://boards.straightdope.com/u/don_t_ask)\
**Post date:** [July 9, 2003, 4:16am UTC](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103/20 "2003-07-09T04:16:46Z")

</div>

It looks like it may have already happened. I found [this](http://www.commondreams.org/views03/0306-04.htm) some time ago.

[Next page](https://boards.straightdope.com/t/electronic-voting-machine-fraud-is-it-possible/187103.md?page=2)
