Voting under a cloud of suspicion

A recent decision by California’s top election official to decertify electronic voting machines in 39 counties because of widespread security problems is the latest flash point in the campaign to implement e-voting nationwide. Continuing disclosures of vulnerabilities in e-voting technology are an embarrassment to voting machine vendors and have made many voters mistrustful of e-voting, political experts say.California Secretary of State Debra Bowen ordered Aug. 3 that hundreds of voting machines be decertified after security tests found pervasive vulnerabilities at nearly every level of thee-voting system. Machines manufactured by Diebold, Sequoia Voting Systems, and Elections Systems and Software (ES&S) were decertified after researchers found what research team leader Matt Blaze said were “significant, deeply rooted security weaknesses in all three vendors’ software.”Blaze, associate professor of computer science at the University of Pennsylvania and an expert in cryptography, said rather than finding holes designed to exploit voting records, researchers found “garden-variety design and implementation blunders that plague any system not built with security as a central requirement.”Bowen has been criticized for rushing the testing to comply with a finish date of July 20 and a final certification approval date of Aug. 3.Michelle Shafer, vice-president of communications and external affairs at Sequoia Voting Systems, said the testing process did not involve a realistic scenario of how electronic voting machines could be hacked or misused. None of the tests were conducted in a realistic voting environment, Shafer said. “The research team was just given unfettered access to the materials and source code, without any process or procedure as to what might actually happen.”However, in the tests, researchers discovered troubling problems and security holes. “The fact that major security vulnerabilities were found in all machines is a testament to how poorly they were designed, not to the thoroughness of the analysis,” wrote security researcher Bruce Schneier.Bowen conditionally recertified the machines as safe to use provided the manufacturers adhere to a lengthy list of security requirements, including sharing the source code with state election officials and providing manual-audit counts of all votes cast using the machines.Another research team in Florida published results of a series of certification tests of Diebold voting machines requested by the Florida Department of State. The Florida team found that, although Diebold had attempted to fix previously reported flaws in its optical-scan and touch-screen software applications, many flaws remained unaddressed.For example, the team found that an outsider could convert designated-voter cards into smart cards that could register multiple votes in a single session, enabling an attacker to stuff the electronic ballot box. The team also found that optical-scan machines could have their memory cards swapped out for new ones that would change votes cast on that particular machine, according to a report published by the investigative team of university computer science professors.Bowen’s office conducted a deeper investigation of ES&S’ business practices in California and found the company may have sold as many as 1,000 uncertified and untested voting machines to five California counties. The state is investigating the possibility that ES&S might have added certification stickers to machines that had not yet been tested. The company could face fines of as much as $10,000 per uncertified unit and be barred from doing business in California for as long as three years if found guilty.Why do e-voting technology vendors continue to provide machines that are deeply flawed? Vendors are not required to build secure products, and therefore they don’t approach building new voting technologies with security in mind, said Rebecca Mercuri.Mercuri, founder of the Notable Software computer security firm, proponent of the voter-verified paper audit trail (VVPAT) concept and an expert on voting technology, said it is pointless to continually recertify or resubmit machines and technology that have repeatedly proven untrustworthy.Mercuri said the Election Assistance Commission should completely decertify all existing electronic voting technology and work on improving paper-based voting technology and standards until a new electronic voting system can be designed and implemented. “Adding VVPATs to existing insecure products won’t solve the problem,” she said. “We need to get rid of all the existing products and start from scratch with new designs.”Rep. Rush Holt (D-N.J.) has proposed new legislation that would mandate the use of electronic voting machines that produce a voter-verified paper ballot, beginning with the 2008 presidential election. The Voter Confidence and Increased Accessibility Act would make paper ballots the primary record for vote recounts and audits.It would ban Internet and wireless connections in voting machines and prohibit the use of uncertified and untested voting software.Holt praised the California official’s decision to conditionally decertify the audited voting machines, saying that findings of systemic problems bolstered the need for his bill. “We can’t go into another federal election with machines that do no allow voters to verify their votes and have people in 20 states saying they do not believe the results,” Holt told Steven Rosenfeld, a senior fellow at AlterNet.org, an alternative online news magazine.A coalition of organizations representing disabled Americans opposes Holt’s bill. They say it will undermine disability standards set by the Help America Vote Act of 2002. Jim Dickson, director of the Disability Vote Project at the American Association of People with Disabilities, said “Luddites who want all-paper balloting don’t know the realities of election administration.”Dickson advocates electronic voting as a way to increase voter turnout and ensure that votes from disabled, military and overseas voters are counted. “Low voter turnout is a much bigger problem for elections than problems with voting machines,” he said. “Internet and electronic voting have already been used in the corporate world and successfully in other countries. It’s more convenient and will increase voter turnout.”Dickson, who is blind, said that if Holt’s bill were enacted, “reel-to-reel paper would become the ballot of record.” Votes cast with direct-recording electronic voting machines would not be counted, leading to greater disenfranchisement of voters, he said.Despite sharing Dickson’s concerns, Mercuri said many of the machines designed to aid disabled users don’t fulfill that function. Some touch-screen machines instruct voters to ‘press the yellow button.’ “How is a blind person supposed to use that?” she asked. Mercuri said some voters in New Jersey waited as long as 40 minutes to vote while election officials helped disabled voters figure out how to use the machines made for them. “Many of these machines are too cumbersome for the disabled to use, and not every machine can be built to handle every disability.”Mercuri, who supported earlier versions of Holt’s bill, said she opposes the present bill because of what she sees as interference from industry. “When you have private interests like Microsoft inserting clauses into the bill saying that you can’t reveal tradesecrets in your examination [of the software code], how is that openness?”When it comes to the central issue of security versus usability, each side in the e-voting battle believes the other should be willing to give ground. Proponents of e-voting technology believe that some security weaknesses are a necessary trade-off to ensure voting machines can be accessible and convenient for voters to use.“I could have built a system tough enough to withstand a nuclear weapon, but voters and auditors wouldn’t be able to use it,” Shafer said.Mercuri said opponents of paper balloting and auditing are convinced that the technology has not advanced since the 1880s. “We can do amazing things with paper today,” such as using watermarks or fluorescent fibers embedded in ballot paper to prevent tampering or counterfeiting, she said. “Paper has more security controls and more capability now than ever before.”In addition to the controversy about touch-screen machines, security audits and competing interest groups, a more fundamental question needs attention, some voting-rights advocates say. Will any advance in technology effectively succeed in raising the dismal voter turnout levels in the United States, or will voters continue to feel disenfranchised and unmotivated to participate in the democratic process?


Matt Blaze, University of Pennsylvania


















































That question troubles David Moon, program director of FairVote, a voter rights advocacy group. “Alterations to voting equipment fundamentally alter the structure of democracy,” he said. “There’s a disincentive to participate if you don’t believe the process is being conducted fairly.”

Moon said the problem is deeper than flawed equipment and rests in the decision to outsource the administration of elections and election systems to private companies. “There’s a profit motive involved in everything they do,” Moon said. “There’s no accountability or reliability when you have companies charging states to perform security reviews and handling every aspect of the election process.”

There also is no magic bullet that will solve the complex issue of accessible, secure voting and address the needs of every user group, Moon said. “We need multiple types of equipment and multiple solutions for each voting system. We really need, most of all, transparency and a return to public ownership of the voting process.”

Bosworth is a technology writer who lives in Washington.

NEXT STORY: Strength in numbers

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.