Weekly Edition Return to the Front page |
Where free software should be required by law
RISKS 22.24 includes a detailed article
by Rebecca Mercuri on the latest fun with the new voting systems in
Florida. That state, of course, was the source of (ongoing) uncertainty in
the 2000 U.S. presidential election, due, in part, to its ancient voting
equipment. Since then, the voting machines have been upgraded to new,
computer-based systems with touchscreen interfaces.
These systems are based on closed source code. There is no external audit trail, no way of verifying that they are recording votes as they were actually cast. Trade secret law forbids the inspection of the code in the systems. One just has to trust the vendor that the results are correct. A primary election held there recently turned up a whole set of problems, ranging from basic usability issues to outright failure. There has been a lot of interest recently in laws requiring governments to use free software in many or all situations. It remains unclear, to some people anyway, that such laws are really in the best interest of government, the governed, or the free software community. But, in the case of voting systems, the case seems clear: no part of the system that elects people into positions of power should be opaque. The creation of a free, transparent, verifyable electronic voting system should not be that hard a task for governments or the free software community. There is no excuse for using anything else. (Log in to post comments)
Where free software should be required by law Posted Sep 12, 2002 9:11 UTC (Thu) by beejaybee (guest, #1581) [Link] "There is no external audit trail, no way of verifying that they are recording votes as they were actually cast. Trade secret law forbids the inspection of the code in the systems. One just has to trust the vendor that the results are correct."And I bet that no-one in the Florida electoral office was priveleged to hear any explanations as to why this should be. Scary stuff, when the corporations who develop this sort of software are already gross abusers of the lobby system. Rig a few votes (or a lot, if neccessary) then claim that "the people" have decided? What price democracy now? There are numerous other issues with electronic voting - personation is one of the more obvious ones - but the system really does need to be sound. The old technology ("X" on a ballot paper) isn't perfect but it seems to be more so than the "modern" alternatives.
Where free software should be required by law Posted Sep 12, 2002 9:31 UTC (Thu) by tres (guest, #352) [Link] Considering the two types of security, "black box" and "crystal ball", otherwise knowm as proprietary and Free Software, I believe that there are instances for both. As I pointed out in a letter to the editor this week, if I'm a cancer patient that is going in to be exposed to radiation, I want the software to be the best. Since not that many programmers are writing programs for radiation machines the quality of the software is something less than desired. The same for the voting machines. With a team of talented and dedicated programmers, I have no doubt that a quality free software solution could be developed. On the other hand, if the project cannot not attrack a cryptographer and security expert to help in auditing the code then problems will surely develop. If all of the states wanted to adopt a new system then they could band together and produce, or hire the job out, some quality software that is capable of doing the job. Short of that, the idiom becomes: security through obscurity. Even though we all know that it is not a very good security system, we must admit that it is better than nothing.Regards,
Where free software should be required by law Posted Sep 12, 2002 13:24 UTC (Thu) by AAP (guest, #721) [Link] My own question would be, why NOT open the source? True, it might be hard to attract geeks to specialty projects, but somebody writes those programs now. Why not pay them to write those programs, as they now do, and release the source for public scrutiny? Presumably, they don't make money off the software, just off the radiation treatments/voting machines. The only minus is that if they screw up, the proof will be out there.
Just PRINT the ballot Posted Sep 12, 2002 14:38 UTC (Thu) by pflugstad (subscriber, #224) [Link] The thing many people miss (even Open Source proponents) whenlooking at this problem (and the one thing suggested by Ms. Mercuri in her Risks posting) is that the solution to these problems is very simple: just print out the damn ballot after the user has finished using the computer to select his candidates. The printed piece of paper can be a simple sheet, with bar codes With this *simple* *basic* idea, I don't care if the voting As Ms Mercuri notes: Brazil uses electronic voting, but they Pete Flugstad
Just PRINT the ballot Posted Sep 12, 2002 17:37 UTC (Thu) by ksmathers (subscriber, #2353) [Link] Printing a machine readable copy of the completed ballot is necessary but not sufficient I think. The printed ballot also has to be human readable; otherwise any electronic recording system would be sufficient. What you want is a way to visually verify that the vote has been recorded correctly. My first guess would be to use an OCR font to print the information in plain english. The records that the machine uses to maintain its count must be in the same format so that any printed voting record can be accurately compared to the corresponding database record, by independently developed software if need be. Also the OCR'able output should be printed twice, once for the voter, and once for the voting machine, preferably one being a carbon copy of the other, like the output from cash registers.
Just PRINT the ballot Posted Sep 13, 2002 16:26 UTC (Fri) by gswoods (subscriber, #37) [Link] You most definitely do NOT want the voter to leave the booth with a recordshowing how they voted. One reason that you have to vote by going to a polling place and voting in a booth where nobody can see is that nobody ever knows how you voted. This is important for preventing coercion. An abusive husband, for instance, would be able to force his wife to vote how he wanted her to if he were able to verify how she voted. Other types of coercion (boss to employee, etc.) are also possible, but are voided if there is no after-the-fact record of how a person voted. Yes, this is a problem with absentee ballots too, which is why I am always
Just PRINT the ballot Posted Sep 13, 2002 17:59 UTC (Fri) by pflugstad (subscriber, #224) [Link] What I meant, which I apparently didn't communicate properly,is that you print the ballot in both HUMAN and MANCHINE readable forms, on the same PAGE, one corresponding to the other. The human form would be OCR capable, but that's not a requirement. The Human looks at the human part of it and if it looks right, If there is any question about the validity of election, these This is NOT a hard problem. There are *simple* solutions to It's not like the hardware requirements are terribly difficult But these are all just details. The reason this is failing is Pete Flugstad
Just PRINT the ballot Posted Sep 15, 2002 1:44 UTC (Sun) by Baylink (subscriber, #755) [Link] Indeed, Pete. Apparently, gswoods hasn't ever voted -- you've *always* walked away from the booth with a readable ballot (although perhaps you had to hold it up to a voting machine to read it, but...*My* personal approach was, indeed, to separate the ballot *validation* from the accelerated electronic *counting* by... Numbering the races, lettering the candidates (1A - Janet Reno, 1B - Bill McBride), etc, on the voting screen, and then, once the ballot is accepted, *print it out on Polaroid SX-70 film, in OCR font, without the candidate names*, show the voter a screen *with both codes and candidate names*, and then let them compare and approve. Once they do, they drop the film in a scanner at the table, and it adds the vote to the totals, making a noise and updating a ballot totalizer counter. It then drops into a locked box, with a slot too small to reach into. Say, an ammo box with a replacement cover. At the end of the night, you plug each counter into a phone line box, and like ET, it phones home. Simple, reasonably hard to screw with -- it even gives you *something to recount* (say it with me now: "a vote is a physical object") -- and the only *problem* with it is Sequoia Votings Systems will only make about 1/3 as much money. But who knows, maybe it's just me.
Florida LUGs, your state needs you. Posted Sep 12, 2002 19:51 UTC (Thu) by Odinson (guest, #1402) [Link] http://www.linux.org/groups/usa/florida.htmlAny lawyers want to get involved in a national debate of presidential proportions? Contact one of the above lugs and tell them you want want to check the software for incorrect or hidden instructions too.
Florida LUGs, your state needs you. Posted Sep 13, 2002 5:02 UTC (Fri) by costa (guest, #3670) [Link] U (USA citizens) have lost all of your freedom afterhorrible 11 september events. So why do U need such election machines? Just use tirany instead.
|
Copyright © 2002, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.