cypherpunks-legacy
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1998 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1997 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1996 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1995 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1994 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1993 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1992 -----
- December
- November
- October
- September
- 130025 discussions
<http://www.truthout.org/docs_04/printer_110804A.shtml>
Worse Than 2000: Tuesday's Electoral Disaster
By William Rivers Pitt
t r u t h o u t | Report
Monday 08 November 2004
Everyone remembers Florida's 2000 election debacle, and all of the new
terms it introduced to our political lexicon: Hanging chads, dimpled chads,
pregnant chads, overvotes, undervotes, Sore Losermans, Jews for Buchanan
and so forth. It took several weeks, battalions of lawyers and a
questionable decision from the U.S. Supreme Court to show the nation and
the world how messy democracy can be. By any standard, what happened in
Florida during the 2000 Presidential election was a disaster.
What happened during the Presidential election of 2004, in Florida, in
Ohio, and in a number of other states as well, was worse.
Some of the problems with this past Tuesday's election will sound all
too familiar. Despite having four years to look into and deal with the
problems that cropped up in Florida in 2000, the 'spoiled vote' chad issue
reared its ugly head again. Investigative journalist Greg Palast, the man
almost singularly responsible for exposing the more egregious examples of
illegitimate deletions of voters from the rolls, described the continued
problems in an article published just before the election, and again in an
article published just after the election.
Four years later, and none of the Florida problems were fixed. In
fact, by all appearances, they spread from Florida to Ohio, New Mexico,
Michigan and elsewhere. Worse, these problems only scratch the surface of
what appears to have happened in Tuesday's election. The fix that was put
in place to solve these problems - the Help America Vote Act passed in 2002
after the Florida debacle - appears to have gone a long way towards making
things worse by orders of magnitude, for it was the Help America Vote Act
which introduced paperless electronic touch-screen voting machines to
millions of voters across the country.
At first blush, it seems like a good idea. Forget the chads, the punch
cards, the archaic booths like pianos standing on end with the handles and
the curtains. This is the 21st century, so let's do it with computers. A
simple screen presents straightforward choices, and you touch the spot on
the screen to vote for your candidate. Your vote is recorded by the
machine, and then sent via modem to a central computer which tallies the
votes. Simple, right?
Not quite.
A Diebold voting machine.
Is there any evidence that these machines went haywire on Tuesday?
Nationally, there were more than 1,100 reports of electronic voting machine
malfunctions. A few examples:
* In Broward County, Florida, election workers were shocked to
discover that their shiny new machines were counting backwards. "Tallies
should go up as more votes are counted," according to this report. "That's
simple math. But in some races, the numbers had gone down. Officials found
the software used in Broward can handle only 32,000 votes per precinct.
After that, the system starts counting backward."
* In Franklin County, Ohio, electronic voting machines gave Bush
3,893 extra votes in one precinct alone. "Franklin County's unofficial
results gave Bush 4,258 votes to Democratic challenger John Kerry's 260
votes in Precinct 1B," according to this report. "Records show only 638
voters cast ballots in that precinct. Matthew Damschroder, director of the
Franklin County Board of Elections, said Bush received 365 votes there. The
other 13 voters who cast ballots either voted for other candidates or did
not vote for president."
* In Craven County, North Carolina, a software error on the
electronic voting machines awarded Bush 11,283 extra votes. "The Elections
Systems and Software equipment," according to this report, "had downloaded
voting information from nine of the county's 26 precincts and as the
absentee ballots were added, the precinct totals were added a second time.
An override, like those occurring when one attempts to save a computer file
that already exists, is supposed to prevent double counting, but did not
function correctly."
* In Carteret County, North Carolina, "More than 4,500 votes may
be lost in one North Carolina county because officials believed a computer
that stored ballots electronically could hold more data than it did. Local
officials said UniLect Corp., the maker of the county's electronic voting
system, told them that each storage unit could handle 10,500 votes, but the
limit was actually 3,005 votes. Officials said 3,005 early votes were
stored, but 4,530 were lost."
* In LaPorte County, Indiana, a Democratic stronghold, the
electronic voting machines decided that each precinct only had 300 voters.
"At about 7 p.m. Tuesday," according to this report, "it was noticed that
the first two or three printouts from individual precinct reports all
listed an identical number of voters. Each precinct was listed as having
300 registered voters. That means the total number of voters for the county
would be 22,200, although there are actually more than 79,000 registered
voters."
* In Sarpy County, Nebraska, the electronic touch screen machines
got generous. "As many as 10,000 extra votes," according to this report,
"have been tallied and candidates are still waiting for corrected totals.
Johnny Boykin lost his bid to be on the Papillion City Council. The
difference between victory and defeat in the race was 127 votes. Boykin
says, 'When I went in to work the next day and saw that 3,342 people had
shown up to vote in our ward, I thought something's not right.' He's right.
There are not even 3,000 people registered to vote in his ward. For some
reason, some votes were counted twice."
Stories like this have been popping up in many of the states that put
these touch-screen voting machines to use. Beyond these reports are the
folks who attempted to vote for one candidate and saw the machine give
their vote to the other candidate. Sometimes, the flawed machines were
taken off-line, and sometimes they were not. As for the reports above, the
mistakes described were caught and corrected. How many mistakes made by
these machines were not caught, were not corrected, and have now become
part of the record?
The flaws within these machines are well documented. Professors and
researchers from Johns Hopkins performed a detailed analysis of these
electronic voting machines in May of 2004. In their results, the Johns
Hopkins researchers stated, "This voting system is far below even the most
minimal security standards applicable in other contexts. We identify
several problems including unauthorized privilege escalation, incorrect use
of cryptography, vulnerabilities to network threats, and poor software
development processes. We show that voters, without any insider privileges,
can cast unlimited votes without being detected by any mechanisms within
the voting terminal software."
"Furthermore," they continued, "we show that even the most serious of
our outsider attacks could have been discovered and executed without access
to the source code. In the face of such attacks, the usual worries about
insider threats are not the only concerns; outsiders can do the damage.
That said, we demonstrate that the insider threat is also quite
considerable, showing that not only can an insider, such as a poll worker,
modify the votes, but that insiders can also violate voter privacy and
match votes with the voters who cast them. We conclude that this voting
system is unsuitable for use in a general election."
Many of these machines do not provide the voter with a paper ballot
that verifies their vote. So if an error - or purposefully inserted
malicious code - in the untested machine causes their vote to go for the
other guy, they have no way to verify that it happened. The lack of a paper
ballot also means the end of recounts as we have known them; now, on these
new machines, a recount amounts to pushing a button on the machine and
getting a number in return, but without those paper ballots to do a
comparison, there is no way to verify the validity of that count.
Worst of all is the fact that all the votes collected by these
machines are sent via modem to a central tabulating computer which counts
the votes on Windows software. This means, essentially, that any gomer with
access to the central tabulation machine who knows how to work an Excel
spreadsheet can go into this central computer and make wholesale changes to
election totals without anyone being the wiser.
Bev Harris, who has been working tirelessly since the passage of the
Help America Vote Act to inform people of the dangers present in this new
process, got a chance to demonstrate how easy it is to steal an election on
that central tabulation computer while a guest on the CNBC program 'Topic A
With Tina Brown.' Ms. Brown was off that night, and the guest host was none
other than Governor Howard Dean. Thanks to Governor Dean and Ms. Harris,
anyone watching CNBC that night got to see just how easy it is to steal an
election because of these new machines and the flawed processes they use.
"In a voting system," Harris said on the show, "you have all the
different voting machines at all the different polling places, sometimes,
as in a county like mine, there's a thousand polling places in a single
county. All those machines feed into the one machine so it can add up all
the votes. So, of course, if you were going to do something you shouldn't
to a voting machine, would it be more convenient to do it to each of the
4000 machines, or just come in here and deal with all of them at once? What
surprises people is that the central tabulator is just a PC, like what you
and I use. It's just a regular computer."
Harris then proceeded to open a laptop computer that had on it the
software used to tabulate the votes by one of the aforementioned central
processors. Journalist Thom Hartman describes what happened next: "So
Harris had Dean close the Diebold GEMS tabulation software, go back to the
normal Windows PC desktop, click on the 'My Computer' icon, choose 'Local
Disk C:,' open the folder titled GEMS, and open the sub-folder 'LocalDB'
which, Harris noted, 'stands for local database, that's where they keep the
votes.' Harris then had Dean double-click on a file in that folder titled
Central Tabulator Votes,' which caused the PC to open the vote count in a
database program like Excel. 'Let's just flip those,' Harris said, as Dean
cut and pasted the numbers from one cell into the other. Harris sat up a
bit straighter, smiled, and said, 'We just edited an election, and it took
us 90 seconds.'"
Any system that makes it this easy to steal or corrupt an election has
no business being anywhere near the voters on election day.
The counter-argument to this states that people with nefarious intent,
people with a partisan stake in the outcome of an election, would have to
have access to the central tabulation computers in order to do harm to the
process. Keep the partisans away from the process, and everything will work
out fine. Surely no partisan political types were near these machines on
Tuesday night when the votes were counted, right?
One of the main manufacturers of these electronic touch-screen voting
machines is Diebold, Inc. More than 35 counties in Ohio alone used the
Diebold machines on Tuesday, and millions of voters across the country did
the same. According to the Center for Responsive Politics, Diebold gave
$100,000 to the Republican National Committee in 2000, along with
additional contributions between 2001 and 2002 which totaled $95,000. Of
the four companies competing for the contracts to manufacture these voting
machines, only Diebold contributed large sums to any political party. The
CEO of Diebold is a man named Walden O'Dell. O'Dell was very much on board
with the Bush campaign, having said publicly in 2003 that he is "committed
to helping Ohio deliver its electoral votes to the president next year."
So much for keeping the partisans at arm's length.
Is there any evidence that vote totals were deliberately tampered with
by people who had a stake in the outcome? Nothing specific has been
documented to date. Jeff Fisher, the Democratic candidate for the U.S.
House of Representatives from Florida's 16th District, claims to have
evidence that the Florida election was hacked, and says further that he
knows who hacked it and how it was done. Such evidence is not yet
forthcoming.
There are, however, some disturbing and compelling trends that
indicate things are not as they should be. This chart displays a breakdown
of counties in Florida. It lists the voters in each county by party
affiliation, and compares expected vote totals to the reported results. It
also separates the results into two sections, one for 'touch-screen'
counties and the other for optical scan counties.
Over and over in these counties, the results, based upon party
registration, did not come close to matching expectations. It can be
argued, and has been argued, that such results indicate nothing more or
less than a President getting cross-over voters, as well as late-breaking
undecided voters, to come over to his side. These are Southern Democrats,
and the numbers from previous elections show that many have often voted
Republican. Yet the news wires have been inundated for well over a year
with stories about how stridently united Democratic voters were behind the
idea of removing Bush from office. It is worth wondering why that unity did
not permeate these Democratic voting districts. If that unity was there, it
is worth asking why the election results in these counties do not reflect
this.
Most disturbing of all is the reality that these questionable Diebold
voting machines are not isolated to Florida. This list documents, as of
March 2003, all of the counties in all of the 37 states where Diebold
machines were used to count votes. The document is 28 pages long. That is a
lot of counties, and a lot of votes, left in the hands of machines that
have a questionable track record, that send their vote totals to central
computers which make it far too easy to change election results, that were
manufactured by a company with a personal, financial, and publicly stated
stake in George W. Bush holding on to the White House.
This map indicates where different voting devices were used nationally. The
areas where electronic voting machines were used is marked in blue.
A poster named 'TruthIsAll' on the DemocraticUnderground.com forums
laid out the questionable results of Tuesday's election in succinct
fashion: "To believe that Bush won the election, you must also believe:
That the exit polls were wrong; that Zogby's 5pm election day calls for
Kerry winning Ohio and Florida were wrong (he was exactly right in his 2000
final poll); that Harris' last-minute polling for Kerry was wrong (he was
exactly right in his 2000 final poll); that incumbent rule #1 - undecideds
break for the challenger - was wrong; That the 50% rule - an incumbent
doesn't do better than his final polling - was wrong; That the approval
rating rule - an incumbent with less than 50% approval will most likely
lose the election - was wrong; that it was just a coincidence that the exit
polls were correct where there was a paper trail and incorrect (+5% for
Bush) where there was no paper trail; that the surge in new young voters
had no positive effect for Kerry; that Kerry did worse than Gore against an
opponent who lost the support of scores of Republican newspapers who were
for Bush in 2000; that voting machines made by Republicans with no paper
trail and with no software publication, which have been proven by thousands
of computer scientists to be vulnerable in scores of ways, were not
tampered with in this election."
In short, we have old-style vote spoilage in minority communities. We
have electronic voting machines losing votes and adding votes all across
the country. We have electronic voting machines whose efficiency and safety
have not been tested. We have electronic voting machines that offer no
paper trail to ensure a fair outcome. We have central tabulators for these
machines running on Windows software, compiling results that can be
demonstrably tampered with. We have the makers of these machines publicly
professing their preference for George W. Bush. We have voter trends that
stray from the expected results. We have these machines counting millions
of votes all across the country.
Perhaps this can all be dismissed. Perhaps rants like the one posted
by 'TruthIsAll' are nothing more than sour grapes from the side that lost.
Perhaps all of the glitches, wrecked votes, unprecedented voting trends and
partisan voting-machine connections can be explained away. If so, this
reporter would very much like to see those explanations. At a bare minimum,
the fact that these questions exist at all represents a grievous
undermining of the basic confidence in the process required to make this
democracy work. Democracy should not ever require leaps of faith, and we
have put the fate of our nation into the hands of machines that require
such a leap. It is unacceptable across the board, and calls into serious
question not only the election we just had, but any future election
involving these machines.
Representatives John Conyers, Jerrold Nadler and Robert Wexler, all
members of the House Judiciary Committee, posted a letter on November 5th
to David Walker, Comptroller General of the United States. In the letter,
they asked for an investigation into the efficacy of these electronic
voting machines. The letter reads as follows:
November 5, 2004
The Honorable David M. Walker
Comptroller General of the United States
U.S. General Accountability Office
441 G Street, NW
Washington, DC 20548
Dear Mr. Walker:
We write with an urgent request that the Government Accountability Office
immediately undertake an investigation of the efficacy of voting machines
and new technologies used in the 2004 election, how election officials
responded to difficulties they encountered and what we can do in the future
to improve our election systems and administration.
In particular, we are extremely troubled by the following reports, which
we would also request that you review and evaluate for us:
In Columbus, Ohio, an electronic voting system gave President Bush nearly
4,000 extra votes. ("Machine Error Gives Bush Extra Ohio Votes," Associated
Press, November 5)
An electronic tally of a South Florida gambling ballot initiative failed
to record thousands of votes. "South Florida OKs Slot Machines Proposal,"
(Id.)
In one North Carolina county, more than 4,500 votes were lost because
officials mistakenly believed a computer that stored ballots could hold
more data that it did. "Machine Error Gives Bush Extra Ohio Votes," (Id.)
In San Francisco, a glitch occurred with voting machines software that
resulted in some votes being left uncounted. (Id.)
In Florida, there was a substantial drop off in Democratic votes in
proportion to voter registration in counties utilizing optical scan
machines that was apparently not present in counties using other mechanisms.
The House Judiciary Committee Democratic staff has received numerous
reports from Youngstown, Ohio that voters who attempted to cast a vote for
John Kerry on electronic voting machines saw that their votes were instead
recorded as votes for George W. Bush. In South Florida, Congressman
Wexler's staff received numerous reports from voters in Palm Beach, Broward
and Dade Counties that they attempted to select John Kerry but George Bush
appeared on the screen. CNN has reported that a dozen voters in six states,
particularly Democrats in Florida, reported similar problems. This was
among over one thousand such problems reported. ("Touchscreen Voting
Problems Reported," Associated Press, November 5)
Excessively long lines were a frequent problem throughout the nation in
Democratic precincts, particularly in Florida and Ohio. In one Ohio voting
precinct serving students from Kenyon College, some voters were required to
wait more than eight hours to vote. ("All Eyes on Ohio," Dan Lothian, CNN,
November 3)
We are literally receiving additional reports every minute and will
transmit additional information as it comes available. The essence of
democracy is the confidence of the electorate in the accuracy of voting
methods and the fairness of voting procedures. In 2000, that confidence
suffered terribly, and we fear that such a blow to our democracy may have
occurred in 2004.
Thank you for your prompt attention to this inquiry.
Sincerely,
John Conyers, Jr., Jerrold Nadler, Robert Wexler
Ranking Member, Ranking Member, Member of Congress
House Judiciary Committee, Subcommittee on the Constitution
cc: Hon. F. James Sensenbrenner, Chairman
"The essence of democracy," wrote the Congressmen, "is the confidence
of the electorate in the accuracy of voting methods and the fairness of
voting procedures. In 2000, that confidence suffered terribly, and we fear
that such a blow to our democracy may have occurred in 2004." Those fears
appear to be valid.
John Kerry and John Edwards promised on Tuesday night that every vote
would count, and that every vote would be counted. By Wednesday morning,
Kerry had conceded the race to Bush, eliciting outraged howls from
activists who were watching the reports of voting irregularities come
piling in. Kerry had said that 10,000 lawyers were ready to fight any
wrongdoing in this election. One hopes that he still has those lawyers on
retainer.
According to black-letter election law, Bush does not officially get a
second term until the electors from the Electoral College go to Washington
D.C on December 12th. Perhaps Kerry's 10,000 lawyers, along with a real
investigation per the request of Conyers, Nadler and Wexler, could give
those electors something to think about in the interim.
In the meantime, soon-to-be-unemployed DNC chairman Terry McAuliffe
sent out an email on Saturday night titled 'Help determine the Democratic
Party's next steps.' In the email, McAuliffe states, "If you were involved
in these grassroots activities, we want to hear from you about your
experience. What did you do? Did you feel the action you took was
effective? Was it a good experience for you? How would you make it better?
Tell us your thoughts." He provided a feedback form where such thoughts can
be sent.
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
1
0
Holy Crap! Am I on crack? I think I agree with everything here!
However...
(James Donald wrote...)
>I cannot understand why you Bush haters are so excited about this
>election when on Mondays, Wednesdays, and Fridays, Kerry promised to
>continue all Bush's policies only more effectually.
That's basically why Kerry lost. He didn't seem to challenge anything Bush
did, only the way he carried things out. That means the republicans
successfully caused any debate to happen on their terms. Kerry's willingness
to kowtow to the idea of a benevolent invasion of Iraq just made him seem
like a scumbag to me, no matter what he actually believed.
However, there are some things that Bush did that, symbolically at least, he
should have been drummed out for. The fact that he won and with large voter
turnout is more or less a vindication of his crimes. It means that Bush
won't be afraid of doing even more, and then the countless mountains of
hillbillies out there will watch his back and take the inevitable bullet or
two for him.
Well, every people deserve the government they get, and these hillbillies
are no exception. Bush will dominate them, take away their rights, make them
poor and scared, and they'll deserve every bit of it. (Where's a Tim May
rant when you need one?)
-TD
_________________________________________________________________
Dont just search. Find. Check out the new MSN Search!
http://search.msn.click-url.com/go/onm00200636ave/direct/01/
2
1
"He won because 53 percent of voters approved of his performance as
president. Fifty-eight percent of them trust Bush to fight terrorism. They
had roughly equal confidence in Bush and Kerry to handle the economy. Most
approved of the decision to go to war in Iraq. Most see it as part of the
war on terror."
In other words, he won because some hillbilly was afraid that the guy at the
local 7-11 was going to blow up his chicked farm. Those of us living close
enough to "Ground Zero" to smell it back in those days are apprarently less
than convinced.
So: A 'moral values' question for Cypherpunks. Does this election indict the
American people as being complicit in the crime known as "Operation
Freedom"? (I notice everyone forgot about that name.)
-TD
_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today - it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/
8
11
My mother's family's name is Sanders. It's Scots-Irish.
Apparently, I like to have my "rock fights" on the net...
:-).
Cheers,
RAH
-------
<http://www.timesonline.co.uk/printFriendly/0,,1-524-1347653-524,00.html>
The Times of London
November 07, 2004
Focus: US Election Special
'Talk to someone in Cincinnati? Are you crazy?'. . . and so the Democrats
blew it
Tom Wolfe on the elite that got lost in middle America
Over the past few days I've talked to lots of journalists and literary
types in New York. I've grown used to the sound of crushed, hushed voices
on the end of the phone. The weight of George Bush's victory seems almost
too much. But what did they expect, I ask myself.
They don't like the war and the way the war is going, they don't like Bush
and they don't like what this election says about America. But where's
their sense of reality?
The liberal elite showed it was way out of touch even before the election.
I was at a dinner party in New York and when everyone was wondering what to
do about Bush I suggested they might do like me and vote for him. There was
silence around the table, as if I'd said "by the way, I haven't mentioned
this before but I'm a child molester".
Now, like Chicken Licken after an acorn fell on his head, they think the
sky is falling. I have to laugh. It reminds me of Pauline Kael, the film
critic, who said, "I don't know how Reagan won - I don't know a soul who
voted for him." That was a classic and reflects the reaction of New York
intellectuals now. Note my definition of "intellectual" here is what you
often find in this city: not people of intellectual attainment but more
like car salesmen, who take in shipments of ideas and sell them on.
I think the results in Ohio, the key state this time, tell us everything
we need to know. Overall, the picture of Republican red and Democratic blue
across the country remained almost unchanged since last time. The millions
of dollars spent and miles travelled on the Bush and Kerry campaigns made
no difference at all.
But look at Ohio and the different voting patterns in Cleveland and
Cincinnati. Cleveland, in the north of the state, is cosmopolitan, what we
would think of as an "eastern" city, and Kerry won by two votes to one.
Cincinnati, in the southeast corner of Ohio, is a long way away both
geographically and culturally. It's Midwestern and that automatically means
"hicksville" to New York intellectuals. There Bush won by a margin of
150,000 votes and it was southern Ohio as a whole that sent him back to the
White House.
The truth is that my pals, my fellow journos and literary types, would
feel more comfortable going to Baghdad than to Cincinnati. Most couldn't
tell you what state Cincinnati is in and going there would be like being
assigned to a tumbleweed county in Mexico.
They can talk to sheikhs in Lebanon and esoteric radical groups in
Uzbekistan, but talk to someone in Cincinnati . . . are you crazy? They
have no concept of what America is made of and even now they won't see that.
So who are the people who voted for Bush? I think the most cogent person
on this is James Webb, the most decorated marine to come out of Vietnam.
Like John Kerry he won the Silver Star, but also the Navy Cross, the
equivalent of our highest honour, the Congressional Medal.
He served briefly under Reagan as secretary for the navy, but he has since
become a writer. His latest book, Born Fighting, is the most important
piece of ethnography in this country for a long time. It's about that huge
but invisible group, the Scots-Irish. They're all over the Appalachian
mountains and places like southern Ohio and Tennessee.
Their theme song is country music and when people talk about rednecks,
this is the group they're talking about: this is the group that voted for
Bush.
Though they've had successes, the Scots-Irish generally haven't done well
economically. They're individualistic, they're stubborn and they value
their way of life more then their financial situation. If a politician
comes out for gun control they take it personally. It's not about guns,
really: if you're against the National Rifle Association you're against
them as a people.
They take Protestantism seriously. It tickles me when people talk about
"the Christian right". These people aren't right wing, they're just
religious. If you're religious, of course, you're against gay marriage and
abortion. You're against a lot of things that have become part of the
intellectual liberal liturgy.
Everyone who joins the military here thinks, "Where did all these
Southerners come from?" These people love to fight. During the French and
Indian wars, before there was a United States, recruiters would turn up in
the Carolinas and in the Appalachians and say, "Anyone want to go and fight
Indians?" There was a bunch of boys who were always up for it and they
haven't lost that love of battle.
My family wasn't Scots-Irish but my father was from the Shenendoah Valley,
in the Blue Ridge mountains in western Virginia, so I know the kind of
folks Webb is talking about.
They do like fighting: many's the time I was visiting there and I'd get
taken down to town to watch the rock fights on a Saturday night. All the
men would hit the bar, drink beer - the only drink you could buy out there
- come out of the saloon, pick up rocks, throw them at each other and then
go home.
Bush, despite his wealthy and refined lineage, in terms of family and
where he went to school, manages to come across to people like that as one
of them. He walks like them, he talks like them, he likes cattle and he
says he likes stock car racing, the most popular sport in the United
States, not that you'd know it from reading the New York papers - they
don't cover it.
There's an annual race in a little place, Bristol Tennessee, a place full
of Scots-Irish, that draws 165,000 people every year, 55,000 more than go
to the biggest football game. Bush reflects this America - the real America
- and that is maybe what the liberal elite and his critics abroad can't
stomach.
He honestly seems to believe in God, whereas Kerry says, "I'm a Roman
Catholic so I must believe in God." It's as if he turns to James Carville
(the Democratic strategist) and says, "Don't I?" It obviously doesn't play
a part in his life.
The values of middle America don't play well in New York. Among American
writers, with few exceptions, you don't say anything patriotic and you
don't say anything generally good about the country.
I must finish now because I need to get to Kennedy airport to wave goodbye
to all those writers and journalists who've told me they can't take another
four years of Bush. Triumphalism is not my style but I can't help an "I
told you so" smile. Oh, by the way, most of them are leaving for London.
Heaven help you when they get there.
Tom Wolfe was talking to Margarette Driscoll
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
2
1
<http://www.timesonline.co.uk/printFriendly/0,,1-523-1348172-523,00.html>
The Times of London CLICK HERE TO PRINTCLOSE WINDOW?
November 07, 2004
Plane passengers shocked by their x-ray scans
Dipesh Gadher,Transport Correspondent
AN X-RAY machine that sees through air passengers' clothes has been
deployed by security staff at London's Heathrow airport for the first time.
The device at Terminal 4 produces a "naked" image of passengers by
bouncing X-rays off their skin, enabling staff instantly to spot any hidden
weapons or explosives.
But the graphic nature of the black and white images it generates -
including revealing outlines of men and women - has raised concerns about
privacy both among travellers and aviation authorities.
In America, transport officials are refusing to deploy the device until it
can be further refined to "mask" passengers' modesty.
The Terminal 4 trial - being conducted jointly by the British Airports
Authority and the Department for Transport - became fully operational last
month and is intended to run until the end of the year. Its deployment has
not been reported until now since new security measures at airports are not
normally publicised.
If the new body scanner is able to cope with large volumes of passengers,
improves detection rates and, crucially, receives public acceptance, it is
likely to be rolled out across all Britain's airports.
At Heathrow, passengers are picked to go through the body scanner on a
random and voluntary basis. Those who refuse are subjected to an automatic
hand search.
The scanner, which resembles a tall, grey filing cabinet, operates in a
curtained area and passengers are asked to stand in front of it, adopting
several poses, for their "naked" image to be registered. Once checked, the
images are immediately erased.
Security officials claim it is a far more effective way of countering
potential terrorists because it detects the outline of any solid object -
such as plastic explosives or ceramic knives - which conventional metal
detectors would miss.
Managers at Heathrow also say the new technology does away with the need
to subject passengers to potentially intrusive hand searches. However,
travellers who have been screened - and have asked to see the images - have
been surprised by their clarity.
"I was quite shocked by what I saw," said Gary Cook, 40, a graphic
designer from Shaftesbury, Dorset. "I felt a bit embarrassed looking at the
image.
A female passenger, who did not want to be named, said: "It was really
horrible. It doesn't leave much to the imagination because you're virtually
naked, but I guess it's less intrusive than being hand searched."
In a similar trial at Orlando international airport in Florida in 2002,
passengers were shown a dummy image before going through, and at least a
quarter of them refused to volunteer.
In America last year, Susan Hallowell, director of the US Transportation
Security Administration's (TSA) security laboratory, showed off her own
x-ray image to demonstrate the technology to reporters.
"It basically makes you look fat and naked, but you see all this stuff,"
said Hallowell, who had deliberately hidden a gun and a bomb under her
clothes.
The TSA has decided not to deploy the device at American airports until
manufacturers can develop an electronic means of masking sensitive body
parts.
Copyright 2004 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and
Conditions . Please read our Privacy Policy . To inquire about a licence to
reproduce material from The Times, visit the Syndication website .
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
1
0
Enzo Michelangeli writes:
> In the world of international trade, where mutual distrust between buyer
> and seller is often the rule and there is no central authority to enforce
> the law, this is traditionally achieved by interposing not less than three
> trusted third parties: the shipping line, the opening bank and the
> negotiating bank.
Interesting. In the e-gold case, both parties have the same bank,
e-gold ltd. The corresponding protocol would be for the buyer to instruct
e-gold to set aside some money which would go to the seller once the
seller supplied a certain receipt. That receipt would be an email return
receipt showing that the seller had sent the buyer the content with hash
so-and-so, using a cryptographic email return-receipt protocol.
> > You could imagine a trusted third party who would inspect the code and
> > certify it, saying "the source code with hash XXX appears to be
> > legitimate Cisco source code". Then they could send you the code bit
> > by bit and incrementally show that it matches the specified hash,
> > using a crypto protocol for gradual release of secrets. You could
> > simultaneously do a gradual release of some payment information in the
> > other direction.
>
> But it's hard to assess the value of partially-released code. If the
> gradual transfer bits-against-cents is aborted, what is left to the buyer
> is likely to be unusable, whereas the partial payment still represents
> good value.
Actually you can arrange it so that neither the partially-released code
nor the partially-transferred ecash is of any value until the whole
transfer finishes. For example, send the whole thing first in encrypted
form, then release the encryption keys bit-by-bit. If someone aborts
the protocol early, the best each side can do is a brute force search
over the untransferred bits to try to find the key to unlock the data
they received.
> A more general issue is that source code is not a commodity, and
> intellectual property is not "real" property: so the traditional "cash on
> delivery" paradigm just doesn't work, and looking for protocols
> implementing it kind of moot. If the code is treated as trade secret,
> rather than licensed, an anonymous buyer may make copies and resell them
> on the black market more than recovering his initial cost, at the same
> time undercutting your legitimate sales (see e.g. the cases of RC4 and
> RC2). This can cause losses order of magnitude larger than refusing to pay
> for his copy.
That's a good point. Maybe you could use some kind of DRM or trusted
computing concept to try to force the buyer to lock up his received data.
For source code that would be pretty difficult though, it needs to be
handled in flexible ways.
Hal
3
3
<http://www.nytimes.com/2004/11/06/opinion/06brooks.html?hp=&pagewanted=prin…>
The New York Times
November 6, 2004
OP-ED COLUMNIST
The Values-Vote Myth
By DAVID BROOKS
Every election year, we in the commentariat come up with a story line to
explain the result, and the story line has to have two features. First, it
has to be completely wrong. Second, it has to reassure liberals that they
are morally superior to the people who just defeated them.
In past years, the story line has involved Angry White Males, or Willie
Horton-bashing racists. This year, the official story is that throngs of
homophobic, Red America values-voters surged to the polls to put George
Bush over the top.
This theory certainly flatters liberals, and it is certainly wrong.
Here are the facts. As Andrew Kohut of the Pew Research Center points out,
there was no disproportionate surge in the evangelical vote this year.
Evangelicals made up the same share of the electorate this year as they did
in 2000. There was no increase in the percentage of voters who are
pro-life. Sixteen percent of voters said abortions should be illegal in all
circumstances. There was no increase in the percentage of voters who say
they pray daily.
It's true that Bush did get a few more evangelicals to vote Republican,
but Kohut, whose final poll nailed the election result dead-on, reminds us
that public opinion on gay issues over all has been moving leftward over
the years. Majorities oppose gay marriage, but in the exit polls Tuesday,
25 percent of the voters supported gay marriage and 35 percent of voters
supported civil unions. There is a big middle on gay rights issues, as
there is on most social issues.
Much of the misinterpretation of this election derives from a poorly
worded question in the exit polls. When asked about the issue that most
influenced their vote, voters were given the option of saying "moral
values." But that phrase can mean anything - or nothing. Who doesn't vote
on moral values? If you ask an inept question, you get a misleading result.
The reality is that this was a broad victory for the president. Bush did
better this year than he did in 2000 in 45 out of the 50 states. He did
better in New York, Connecticut and, amazingly, Massachusetts. That's
hardly the Bible Belt. Bush, on the other hand, did not gain significantly
in the 11 states with gay marriage referendums.
He won because 53 percent of voters approved of his performance as
president. Fifty-eight percent of them trust Bush to fight terrorism. They
had roughly equal confidence in Bush and Kerry to handle the economy. Most
approved of the decision to go to war in Iraq. Most see it as part of the
war on terror.
The fact is that if you think we are safer now, you probably voted for
Bush. If you think we are less safe, you probably voted for Kerry. That's
policy, not fundamentalism. The upsurge in voters was an upsurge of people
with conservative policy views, whether they are religious or not.
The red and blue maps that have been popping up in the papers again this
week are certainly striking, but they conceal as much as they reveal. I've
spent the past four years traveling to 36 states and writing millions of
words trying to understand this values divide, and I can tell you there is
no one explanation. It's ridiculous to say, as some liberals have this
week, that we are perpetually refighting the Scopes trial, with the metro
forces of enlightenment and reason arrayed against the retro forces of
dogma and reaction.
In the first place, there is an immense diversity of opinion within
regions, towns and families. Second, the values divide is a complex
layering of conflicting views about faith, leadership, individualism,
American exceptionalism, suburbia, Wal-Mart, decorum, economic opportunity,
natural law, manliness, bourgeois virtues and a zillion other issues.
But the same insularity that caused many liberals to lose touch with the
rest of the country now causes them to simplify, misunderstand and
condescend to the people who voted for Bush. If you want to understand why
Democrats keep losing elections, just listen to some coastal and university
town liberals talk about how conformist and intolerant people in Red
America are. It makes you wonder: why is it that people who are completely
closed-minded talk endlessly about how open-minded they are?
What we are seeing is a diverse but stable Republican coalition gradually
eclipsing a diverse and stable Democratic coalition. Social issues are
important, but they don't come close to telling the whole story. Some of
the liberal reaction reminds me of a phrase I came across recently: The
rage of the drowning man.
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
2
1
--
John Young wrote:
> Commie is the term used here like is nazi used elsewhere as the most
> fearsome if thoughtless epithet. Nazi here is a term of endearment,
> and also admirable role model by some.
>
> Calling someone both is not allowed, check the FAQ under impurity.
I routinely call people like you nazi-commies.
As George Orwell observed, anyone who thinks there is a significant
difference between nazis and commies is in favor of one or the other.
--digsig
James A. Donald
6YeGpsZR+nOTh/cGwvITnSR3TdzclVpR0+pr3YYQdkG
tcPPLhn9aMTaLb/hq3C0TK4TWGyDiUmRgFC+48C2
4sa/dBFoKxqt/B8oRTgvooxp3PmvXeSL3LjqpFI+W
___________________________________________________________
$0 Web Hosting with up to 120MB web space, 1000 MB Transfer
10 Personalized POP and Web E-mail Accounts, and much more.
Signup at www.doteasy.com
4
4
http://www.rense.com/general59/rig.htm
More Evidence The Vote Was Rigged
>From Wayne Nash
11-5-4
I don't want rain on the parade but I am getting quite a few emails from
various sources citing possible irregularities with the voting process.
So, I did a little research myself on the net to see what I could find. As
a political scientist I could not resist.
Regardless of the veracity of any claim to possible irregularities I
suggest that this question of legitimacy of the process needs to be
addressed if everyone casting their vote is to feel that their vote is
being properly counted. No one can feel disenfranchised in a real
democracy. Otherwise, you end up with a dictatorship and not a democracy
at all.
Unless BOTH sides feel the system is verifiable then you may end up with a
banana republic 'democracy'. This is not question of who won the election.
It is a matter of much greater importance; the legitimacy of the
democratic process itself.
Here are a couple of sites which address the issue:
1. http://www.openvotingconsortium.org/
2. http://www.electoral-vote.com/
On this last web site I found this interesting bit of information:
"Various people sent me mail saying that it is awfully fishy that the exit
polls and final results were substantially different in some places. I
hope someone will follow this up and actually do a careful analysis. Does
anyone know of a Website containing all the exit poll data? If we go to
computerized voting without a paper trail and the machines can be set up
to cheat, that is the end of our democracy. Switching 5 votes per machine
is probably all it would take to throw an election and nobody would ever
see it unless someone compares the computer totals and exit polls. I am
still very concerned about the remark of Walden O'Dell a Republican fund
raiser and CEO of Diebold, which makes voting machines saying he would
deliver Ohio for President Bush. Someone (not me) should look into this
carefully. The major newspapers actually recounted all the votes in
Florida last time. Maybe this year's project should be looking at the exit
polls. If there are descrepancies between the exit polls and the final
results in touch-screen counties but not in paper-ballot counties, that
would be a signal. At the very least it could be a good masters thesis for
a political science student. The Open voting consortium is a group
addressing the subject of verifiable voting."
Could there be a possible problem here? Let's see...
* In states where there were paper ballots the results exactly matched the
exit polls.
* In states where there were only electronic 'touch-screen' paperless
voting machines Bush showed an inexplicable 5-8 point or more difference
from the polls, contradicting otherwise accurate exit polls.
* The software used in these voting machines is so sophisticated that you
can't even check out the programming because it disappears leaving nothing
to verify, no source code, no nothing.
Below are 3 articles explaining how these E-voting programs work. The man
who published these articles is apparently an expert on this E-voting
subject and a computer scientist.
Article 1 http://www.southbaymobilization.org/newsroom/
articles/04.0303.ADeafeningSilence_article.htm Article 2
http://www.southbaymobilization.org/newsroom/
articles/04.0618.SecretAgentPrograms_article.htm Article 3
http://www.southbaymobilization.org/newsroom/
articles/04.0701.EVoting_TheNewCloseUpMagic_article.htm
Another site takes the subject seriously...
http://www.rense.com/general59/steI.HTM
Highlight:
* SoCalDem has done a statistical analysis... ...on several swing states, and
EVERY STATE that has EVoting but no paper trails has an unexplained advantage
for Bush of around +5% when comparing exit polls to actual results.
* In EVERY STATE that has paper audit trails on their EVoting, the exit poll
results match the actual results reported within the margin of error.
* Analysis of the polling data vs actual data and voting systems supports the
hypothesis that evoting may be to blame in the discrepancies.
* The media was a bit taken aback that the results didn't match the exit polls
AT ALL. Most of the commentators were scratching their head in disbelief at the
results. The media has gracefully claimed they "just got it wrong."
Some examples?
WISCONSIN:
Kerry leads Female voters by 7%, Bush leads male voters by 7%. Male vs. Female
voter turnout is 47% M, 53% F. That means Kerry statistically has a 7% edge in
exit polling in Wisconsin.
Actual results however show Bush ahead by 1%, an unexplained difference of 8%.
NEVADA:
Kerry leads in the exit polls by a clear margin, but is still behind in the
reported results. This state is even closer.
Actual is just 1% favor of Bush. Exit polls show Kerry with a wider margin.
Women favored Kerry by 8% here out of 52% of total voters. Men favored Bush by
just 6% out of 48% of total voters. Actual reported results don't match exit
polling AT ALL in Nevada.
Easy Programming?
According to the programmer cited above here is how easy it is to "make magic"
...
We need COUNTERS - (B) = Bush; (K) = Kerry; (V) = Vote; (T) =Tally
1. If V = B, add 1 to B
2. If T = 8, add 1 to B; Clear T; Skip 3
3. If V = K, add 1 to K; Add 1 to T
This extremely simple bit of programming would shift 12% of the vote from Kerry
to Bush, it would defy exit polls, and it would make it look like Bush had a
huge popular win.
_____
Feel free to pass this on to your Republican and Democratic friends. If you are
American, this should concern you regardless of who won this election or wins
future elections. If your process is flawed your democracy is flawed and
everything you believe in is on the line. I am sure that people on the ground
are acting in good faith and voting according to their values and beliefs. It
is the people at the top that concern me.
1
0
http://www.infosecwriters.com/hhworld/hh9/voting.txt
Hitchhiker's World (Issue #9)
http://www.infosecwriters.com/hhworld/
Observable Elections
--------------------
Vipul Ved Prakash <mail(a)vipul.net>
November 2004
This is an interesting time for electronic voting. India,
the largest democracy in the world, went completely paper-
free for its general elections earlier this year. For the
first time, some 387 million people expressed their
electoral right electronically. Despite initial concerns
about security and correctness of the system, the election
process was a smashing success. Over a million electronic
voting machines (EVMs) were deployed, 8000 metric tonnes of
paper saved[1] and the results made public within few hours
of the final vote. Given the quarrelsome and heavily
litigated nature of Indian democracy, a lot of us were
expecting post-election drama, but only a few, if any,
fingers were found pointing.
Things didn't fare so well in the United States. The
Dieobold electronic machines, slated for use in many states
for the November 2004 Federal elections, turned out to have
rather large security holes. Cryptography experts, Avi Rubin
et al, did a formal analysis of the machines and found that
they could be subverted to introduce votes that were never
casted[2]. An independent government-backed analysis
confirmed this[3] and concluded that the Diebold voting
system "as implemented in policy, procedure, and technology,
is at a high risk of compromise."
It is clear, even to a cursory observer, that Diebold
systems are sloppily designed, never mind the sloppiness is
a function of incompetence or intent. The recent controversy
from the "Black Box Voting" security advisory titled "the
Diebold GEMS central tabulator contains a stunning security
hole"[4] has added to the confusion. It claims that a code
entered at a remote location can replace the real vote count
with a fabricated one. This security hole, discovered last
year, is still not fixed says the advisory. In response,
Diebold claims that this is possible, but only in debug
mode, which does little to make people confortable.
What is disturbing to me as a technologist is the
burgeoning public opinion that electronics is an unviable
medium for conducting the serious business of elections.
Over the last year I've seen numerous formal reports and
articles in popular press[5] equating the failures of
Diebold systems with the untenability of electronic voting.
This is rather silly. Diebold systems are not only poorly
engineered, they are also seriously flawed in design. Even
if they were immaculately bug-free, they are so far from
what electronic voting systems should be, that I have
trouble categorizing them as "voting systems". "Electronic
counters" is more accurate.
Various augmentations have been proposed to Diebold systems;
most revolve around parallel paper trails. Verified
Voting[6] for example proposes that a vote be printed based
on the voter's touch-screen selection, so the voter can
touch, feel and verify their vote before casting it into a
traditional ballet box. These votes would then be processed
with an OCR type machine to compute a cumulative result and
the physical votes would be saved so an independent party
can verify the electronic result at a latter date. This is a
reasonable tradeoff -- after all integrity of elections is
way more important than saving trees and time.
While this is the best recommendation for the upcoming
elections, it subtly promotes the primacy of paper and
distrust in electrons. We know that paper elections are no
more secure. The history of vote tampering in paper based
elections is quite illustrious (I'll simply refer the gentle
reader to [7]) and the reason electronics was considered in
the first place was to eliminate such tampering. Verified
Voting recommends that count of the physical votes is to be
considered superior than that of the electronic counterparts
in case of a difference. What happens if the process of this
count is tampered using traditional methods? We are back to
square one.
The central point that I want to get across in this paper is
that the promise of electronic voting is not merely a
quicker, slightly more secure and ecologically enlightened
replacement for paper elections. Electronic voting, if
implemented correctly, could be a major qualitative leap,
not only changing the way in which we approach democratic
elections, but also the the way in which we expect a
democratic government to function.
Cryptographic Integrity
I want to draw attention to the work done by cryptographic
community in the last 20 years to study, formalize and solve
many of the problems of Internet Voting. This area of work
is focused on building election systems that leave behind a
trail of mathematical proofs of the integrity of the voting
process. With mathematical solutions to the common issues of
vote tampering, it becomes unnecessary to trust election
officials and it becomes possible to build voting systems
that are open and universally verifiable.
A voting system for appointing a democratic government has
certain "ideal properties". These are rather obvious, but I
recount them for the purpose of this discussion. First, all
votes must be counted exactly like they were casted.
Altering a vote, or leaving one out from the final tally
must be impossible. Ballot stuffing, ie. artificial
injection of invalid votes must be impossible as well. The
system should reject non-eligible voters, and ensure
eligible users can cast only a single vote. And, finally,
votes must be absolutely anonymous -- even the voter should
be unable to prove the way in which they voted. Systems like
Diebold's depend on large-scale observation to uphold the
ideal properties. Large-scale observation is hard, and once
an act of tampering is done, there is little that can be
done to detect or correct it. The attacks such as the one
described by the Black Box Voting advisory are particularly
heinous, since they compromise the entire election process.
The ideal properties are true in paper elections when they
are implemented perfectly, but the nature of paper precludes
proofs of correctness without compromising anonymity. The
problems are much the same as in the "Electronic Counter"
systems; without correctness proofs, it is largely
infeasible to detect and correct tampering.
Cryptographers have been trying to emulate the property of
anonymity that is inherent to paper when it us used as cash
or votes. The research in the field has led to invention of
several mathematical primitives and computing systems that
not only model paper but go beyond to provide proofs of the
properties they emulate. Techniques like blind signatures,
homomorphic encryption, digital mixes and onion routing have
been used to build systems that provide strong anonymity.
The pioneering cryptographer David Chaum introduced the
blind signature in order to build permit truly anonymous
interaction on the Internet[8]. Since then, they have been
applied to all manner of problems from untraceable
electronic cash to electronic voting schemes. Blind
signatures are a class of digital signatures that allow a
document to be signed without revealing its contents. The
effect is similar to placing a document and a sheet of
carbon paper inside an envelope. When the envelope is
signed, the signature transfers to the document and remains
on it even when the envelope is removed.
In his paper, Chaum hinted that blind signatures could be
used for secret ballot elections. Fujioka, Okamoto, and
Ohta[9] created the first significant blind signature based
voting protocol, which made it practical to use blind
signatures in democratic elections. However, some problems
were discovered in their work, most notably the system's
vulnerablity to a corrupt election authority. I present a
system, dubbed ``Athens'', that builds on their work, but
solves several problems in their model. I also focus on a
real-world election system, rather than an Internet one, and
adopt a pragmatic approach, in that I make use of physical
resources like volunteers and physical infrastructure
usually available for large-scale democratic elections.
Athens also borrows elements and thinking from the
Sensus[10] system and David Chaum's recent work on Visual
Cryptography[11].
Design of Athens
The basic procedure for conducting a democratic election is
fairly standard. The procedure has four tasks: Registration,
Validation, Collection and Tallying. In Athens, these four
tasks are carried out with a few specialized machines and
software, most of which are connected through the Internet.
While Athens employs an Election Authority to oversee the
process of elections, it does away with the dependence on
trustworthiness of one. Athens philosophy is that there are
no truly non-partisan parties; even the Election Authority
can't be completely trusted. The Athens model is closer to a
"game" between contesting parties, such that the only way to
cheat in the game is for all competitors to collude - an
axiomatic impossibility. The Election Authority performs
tactical tasks to optimize the election process, but all
tasks performed by the Authority are open to review by
competing parties.
Registration
Registration is the process of determining eligible voters,
and is conducted by the "Registrar" -- a distributed
authority put in place by the Election Authority. The Athens
registration process involves validating voters (through
traditional means) and registering their "Voter Public Key"
in the "Register." The corresponding "Voter Secret Key"
remains with the voter, magnetically encoded (or bar coded
for cheaper implementation) on a "Voting Card".
The keys are generated through the "Voting Card Creator
Machine". The Card Creator Machine is also implemented as
software that can be used by a voter on their home computer.
It is not hard to imagine Card Creators installed in local
registration offices or even at Kinko's and shopping malls,
where they charge a few dollars for generating a card.
Fairness in design is important, because Card Creators could
compromise the security of the system by storing the key
pairs they generate.
A card creator is mostly an RSA key generator - it needs
computing power of a 300 Mhz PC, and is constructed fairly
cheaply. Once the voter enters their personal information
into the machine, it spits out two cards: one with the
public key, that is handed over to the Registrar and the
other with the secret key and identification information
required by the Election Authority (like the social security
number of the voter.) The second card is known as the
"Voting Card" and is used to validate the voter at the time
of elections. Both cards also contain a large random number,
known as the Voter Id. This is used throughout the voting
process to facilitate lookups in the Register without
compromising the privacy of the voter.
Once all voters have handed their Voter Public Key Card over
to the Registrar, the registration process is considered to
be complete. As with traditional elections, there is a cut-
off date for this process.
On completion of registration, the Election Authority hands
the Register over to all the competitors. The competitors
then check every 1 in 1000 entries (or more according to
their capacity) to ensure that they belong to a legitimate
voter, i.e. it isn't a fake entry inserted by a corrupt
competitor to stuff the ballot. This process is woefully
lacking in elections of today, and a hence a major vector
for election fraud. Mathematics can do little to alleviate
the dangers of registering fake voters, but competitors who
depend on the correctness of the Register and raise funds
for the purpose can easily perform this task. Register
verification would be a lucrative business for independent
professional services organizations, so it is not hard to
imagine such organizations sprouting up to assume delegation
of this responsibility.
The competitors also put the Register on the Internet before
the election so that voters can ensure their voter key is
present in all copies of the Register. When requested, each
competing party provides a digitally signed proof that the
voter is registered to vote, i.e. their key is present in
the Register. The voter, if denied the right to vote, can
take this proof to a court of law. A pre-voting verification
of eligibility limits the kind of fiasco that occurred in
Florida during the Presidential elections of 2000, where a
large number of people were denied vote.
Validation
In most electronic voting protocols, there exists the notion
of the "Validator" - a party that holds the Register and
validates voters during the election. In Athens, the
competing parties, that were handed a copy of the Register
in the previous step, all serve as Validators. Athens,
therefore, is a multi-validator system. It is reasonable to
assume that independents or fiscally constrained parties
would team up and have a single Validator represent them.
Validators are connected to the Internet and run Validation
software, that accepts validation requests over a TCP port.
The Validators are firewall'ed off to accept data only from
certain IP addresses. The Electronic Voting Machines talk to
the Validators via a Proxy. EVMs could theoretically talk
directly to Validators, but the reasons for using a proxy
will become apparent later. The Proxy is operated by the
Election Authority and observed by representatives from all
competing parties.
Validators have their own RSA key pair, the public portion
of which is published widely over the Internet. They also
maintain two lists (other than the Register). This is the
list of voters who have casted a vote and a list of
corresponding validation requests.
Before the commencement of the election, the Election
Authority chooses a a random number which is known as the
"Election Number". The only property of this number is its
uniqueness to the election - it should not have been used in
a previous election. The Election Number is distributed to
all Validators.
Electronic Voting Machines (EVMs) used in Athens are quite
unlike Diebold's or the ones used in the Indian elections.
Athens' EVMs are simply "agents" that vote on behalf of the
voter. Each EVM has an Id and a RSA key pair. The public
part of the EVM key is published widely over the Internet.
Communications initiated by the EVM are signed with EVMs
secret key. The elections are considered formally commenced,
when the Validators broadcast the Election Number and their
public keys to EVMs via the Proxy.
The Athens Voting Protocol
The voter enters a private booth and swipes their Voting
Card on the EVM. The EVM reads the secret key and the Voter
Id off the Card. The EVM has a little printer attached to
it, much like a cash register receipt printer, on which it
prints out the Voter Id. It the sends the voter Id off to
the Validators via the proxy to initiate a "voting session"
on behalf of the voter. If the voter has already casted a
vote, Validators return a "proof" of previously casted vote.
The proof and its implications are discussed a little later.
If there's no previous vote, the Validators send a positive
acknowledgment and the EVM asks the voter to cast a ballot.
The voter enters their vote using the on-screen display. The
EVM concatenates the Voter's choice with the Election Number
(EN) and the result is encrypted with a secret key (randomly
generated) using a symmetric cipher like AES. The encrypted
ballot is then blinded. At this point, the EVM has:
Voter Id +
Blind(Encrypted(Ballot . EN))
The blinded ballot is then signed with the voter's secret
key. The EVM also signs the EN with the Voter's key. The
EVM now has:
Voter Id +
VoterSignature(EN) +
VoterSignature(Blind(Encrypted(Ballot . EN))) +
Blind(Encrypted(Ballot . EN))
The EVM sends the signed, blinded ballot over to the the
Proxy, that sends it to all Validators. Upon receipt, a
Validator looks up the public key corresponding to the Voter
Id and uses it to check the voter signature. If the voter
signature is valid the Validator signs the blind with its
own key. It adds the Voter Id to the list of voters who have
casted a vote and keeps, in another list, the original
blinded request, the signed EN, and the timestamp of request
as a proof of the casted vote. It sends the signed blinded
ballot back to the Proxy, that forwards it to the
originating EVM. The data packet contains:
EVM Id +
Voter Id +
ValidatorSignature(Blind(Encrypted(Ballot . EN)))
If the Validator can't validate the signature, it sends a
VERIFY_FAILURE error to the EVM:
EVM Id +
Voter Id +
VERIFY_FAILURE +
ValidatorSignature(
VERIFY_FAILURE +
Blind(Encrypted(Ballot . EN))
)
If the Validator can't find the Voter Id, it sends an
INVALID_VOTERID_FAILURE error to the EVM:
EVM Id +
Voter Id +
INVALID_VOTERID_FAILURE +
ValidatorSignature(
INVALID_VOTERID_FAILURE +
Blind(Encrypted(Ballot . EN))
)
As described earlier, if the Voter has already casted a
vote, the Validator sends a proof of the vote, which
contains:
REPEAT_VOTE_FAILURE +
Proof
Where Proof is:
EVM Id +
Voter Id +
Request_Timestamp +
PreviousBlind(Encrypted(Ballot . EN)) +
VoterSignature(PreviousBlind(Encrypted(Ballot . EN))) +
VoterSignature(EN)
Once the EVM has received responses from all Validators, it
informs the voter that their vote was casted. If all
Validators sent a positive response the EVM prints out the
message "Vote successfully casted" (immediately following
the previously printed Voter Id), and instructs the voter to
take the printed receipt. If any of the Validators return a
failure, the EVM prints out all Validator responses,
including the steps for unblinding and decrypting the
original vote. A little later I will demonstrate how this
receipt can be used to detect various types of tampering and
attacks on the system. For now, we will assume validation
was successful. For a successful validation, the EVM removes
the blind and is left with ``n' validated encrypted ballots:
Validator_1_Signature(Encrypted(Ballot . EN))) ..
Validator_n_Signature(Encrypted(Ballot . EN))) +
Encrypted(Ballot . EN)
This data encapsulates a secret vote by a voter whose
eligibility has been attested to by all competing
Validators, none of whom know the way in which the vote was
cast. Additionally, any independent party can now confirm
the integrity of the vote by checking the Validator
signatures.
The EVM places the signatures, the ballot and the secret key
used to encrypted the Ballot on a "Tally Queue". For votes
that failed, the failure messages are placed on the Tally
Queue instead.
Tallying
When the Election is over, several pieces of data are
published over the Internet in a public forum that has
properties of a Usenet group (ie. published information
can't be retracted). First, the Validators publish their
list of Voter Ids that casted a vote along with "proofs" of
validation request, where the proof is exactly the same as
one described above. This includes all the data on the two
lists maintained by the Validators.
Once Validators have published their lists, the proxy opens
up the constraints on EVM communication, such that they can
all talk to each other and read and write in the public
forum. The proxy informs EVMs of this event and sends them a
list of IP addresses all EVMs. The EVMs then participate in
an Onion Routing protocol[12] to publish the encrypted
ballots and Validator signatures on these ballots from their
Tallying Queue. Once encrypted votes and Validator
signatures are faithfully transmitted over to the public
forum, EVMs enter a second round of Onion routing to publish
the AES passwords to decrypt the votes. The Onion Routing
protocol strips the origination information, so it becomes
impossibly hard to corelate votes to EVMs, thereby making
the publication anonymous.
At this point, all data required to do a tally is available
publically. It should be noted that almost everything that
transpires during the election process, with the exception
of the data that links the voters to their votes, is made
public at the end of the election. This level of
transparency is one of the greatest benefits of a well
designed electronic voting system.
In Athens, the tallying is done by the Election Authority,
but anyone equiped with Tallying software can check the
tally independently. Athens tally is straightforward. Ballots
that have valid signatures from _all_ Validators are
selected as countable votes. These are decrypted with the
published AES secret keys, votes are separated from the
Election Number, and counted to produce a final tally.
Security of Athens
To analyse the security of Athens, I will show how various
common attacks are made trivially detectable by the Athens
architecture.
Denial of Vote Attacks
The pre-election registration verification keeps the
Registrar honest. If the registrar drops people from the
Register, there's a high probability that the drop will be
detected and the Registrar will be answerable in a court of
law. Since competing parties are independently undertaking the
verification, it is in everyones interest to keep the
process honest.
During the election, two different types of denial attacks
are possible. The first attack is where one of the
competitors know (based on the Voter Id, or region), the way
in which the voter will cast a vote. Outspoken supporters,
representatives and volunteers of a party are vulnerable to
this attack. A competing Validator could try to deny them
the vote by raising one of the three possible errors:
INVALID_VOTERID_FAILURE, VERIFY_FAILURE or
REPEAT_VOTE_FAILURE.
To protect from the INVALID_VOTERID_FAILURE denial attack, a
copy of the register is published widely prior to the
commencement of the elections. A receipt generated by the
EVM with a valid Voter Id and an INVALID_VOTERID_FAILURE
notice is an easily established proof of Validators'
corruption. VERIFY_FAILURE is also trivially established
with help of the positive validation requests from competing
Validators (also on the receipt), the public Register and
the voter's Voting Card.
The attack based on the third error, REPEAT_FAILURE is more
interesting. What if a Validator refuses to Validate a vote
by claiming that the Voter has already voted? In that case,
the Validator must provide a proof of the previous
Validation request. Since the proof contains a signature
made on both the EM and the Blinded ballot by Voter's secret
key, the Validator cannot provide such a proof with the
knowledge of the key - which is unavailable to the
Validator. This is why Athens requires Validators to keep a
copy of all validation requests, and conducts the validation
process in 2-steps, so the first validation request can't be
used as a proof. Also, since the Election Number is encoded
in the ballot, and a signed EN is part of the proof,
validation requests from previous elections can't be cited
as proofs. An incorrect proof is easily verifiable by the
EVM as well as the voter and a court of law with help of the
printed receipt.
A different kind of denial of vote attack can be mounted by
the EVMs. In this attack the EVMs withhold publication of
validated votes. However, such withholding is easily
discovered in Athens because the list of proofs published
by the Validators indicate the number of casted and
verified votes.
Ballot Stuffing Attacks
There are several ways in which an attacker can try to stuff
ballots. The first method, that was discussed earlier, is by
registering fake voters during the registration process.
Since the Register is open to independent scrutiny by all
competitors, the risks of adding fake voters is high and
hence discouraged.
Another ballot stuffing attack is to cast votes for
absentees. This attack is very hard in Athens, since it
requires the knowledge of absentees' secret keys.
The third way to stuff the ballot is for an eligible voter
to cast multiple votes. This is made impossible in Athens
with help of Validation proofs. Even when the Validators
of n-1 colluding parties (where n is the number of
competing parties), validate multiple requests from
Mallory (a colluding voter), the non-colluding party is
able to present a proof of Mallory's first vote and deny
all subsequent requests with impunity. The Tallying
process requires an affirmation from _all_ Validators, so
such votes are not counted.
Vote Alteration Attacks
The Athens protocol requires that EVMs act honestly on the
behalf of the Voter. A corrupt EVM could easily display to
the voter that it has casted a vote their choice, but
actually cast the vote for another party. This attack would
be impossible if the EVM was required to print out a
receipt of every vote that included the blinded ballot,
signed by Voter's secret key, the steps to unblind it and
the secret AES key with which the actual vote was
encrypted. The voter could then look up the encrypted
ballot after it was published and ensure the vote was cast
and counted correctly. Doing this, however, would leave the
voter with a proof of vote that could lead to vote coercion
or vote buying.
It is not sufficient to blindly trust the EVM either. Code
reviews, or open source development of the EVM software
(while should be encouraged) do not guarantee that the code
running on the deployed EVM is the one that was reviewed. To
keep the EVMs honest, Athens implements a sub-protocol for
EVM verification.
All competing parties add a few thousand fake voters to
their own copy of the Register, and generate corresponding
voting cards. These voting cards are then used by designated
verifiers (volunteers) to cast arbitrary votes (usually for
the party that runs the Validator) to test the EVMs. The
volunteers are normal, eligible voters with multiple voting
cards - they first vote with their real card, and then pull
out the fake ones to run a series of tests. When the
designated verifier casts a vote with one of the faked card,
the vote is verified correctly by the Verifying Validator
(the one who has the fake keys on it copy of the Register),
while other n-1 Validators decline validation with an
INVALID_VOTERID_FAILURE. This causes the EVM to print out
the entire transaction, down to the selection of the actual
vote that the EVM tried to validate.
If the EVM is systematically altering votes, the designated
verifier ends up with a receipt showing a selection that was
different from his actual selection. If the EVM attempts to
cover up its deception by printing a receipt that says "Vote
successfully casted", the designated verified immediately
knows the EVM is lying, since the n-1 Validators would have
failed the verification. If the EVM tries to back paddle and
cast a correct vote after it receives the
INVALID_VOTERID_FAILUREs, the duplicate vote attempt is
detected by (at least) the Verifying Validator, who responds
with a proof of the previous validation request. Unable to
differentiate a normal voter from a designated verifier
before sending a verification request, the EVM is forced to
act honestly.
Athens requires the physical constraint of using a proxy for
all communications originating from the EVMs, to ensure EVMs
have no out-of-bound, out-of-protocol communications with
Validators and other parties. This provides a single,
focused point of observation for the competing parties, and
can be performed fairly easily with a protocol decoder.
In sum, Athens uses cryptographic primitives to build an
electronic voting system that ties in the processes of
registration, voting, and tallying into a protocol that is
secure, anonymous and truly transparent. Since all aspects
of the protocol are verifiable the potential for fraud is
greatly reduced. Even more importantly, open systems like
Athens inspire confidence and promote participation in the
election process - the very foundation of democracy.
Partial Observability
"Participation" brings us to the one of the topics that
originally led to my interest in electronic voting. I know
many intelligent and politically sensitive Indians who have
never casted a vote in Indian democratic elections. I am
one of them. My reason for electoral inaction is not
apathy, but simple statistics. In a country of a billion
people, my vote doesn't really count. To be more precise,
if one party wins by 80% then my vote, in either direction,
is not useful. However, if a party that I don't support
happens to win by a small margin, my vote (and those of
others like me) could have made all the difference. Of
course, I have no way of knowing this till it is too late.
I could pay attention to gallop and exit polls, but those
can be quite wrong as demonstrated in the Indian general
elections earlier this year.
It is no surprise that the voter turnout in what is
perceived to be a hotly contested election is higher than
expected. A comprehensive IDEA survey[13] on voter turnout
failed to find corelations between turnout and various
factors they studied, but they found that "there does seem
to be a clear link between voter turnout and the
competitiveness of electoral politics in a political
system. In the 542 elections where the largest party won
less than half of the votes turnout was a full 10% higher
than the 263 elections where a single party won over 50% of
the popular vote."
Publishing partial results is a tactical nightmare in paper
based or electronic counter based elections. However, a
system like Athens could enter the Tally phase several times
during the election at no additional cost to provide an
"intermediate tally". The frequency and timing of the
intermidiate tallies could be function of the size of the
electorate and number of uncounted votes - large enough to
protect the anonymity of the voters and small enough to
provide an updating sense of the final result. The
intermediate tallies could be broadcastd on TV, Radio and
the Internet (much like Stock tickers), and would functions
as "get out the vote" campaigns, to encourage the
statistically informed to go out and vote.
This property of elections that I like to call "partial
observability", could greatly boost participation and
otherwise alter the dynamics of the election process. It is
just one of the ways in which electronic voting could
qualitative change the elections and democracy.
Bibliography
[1] Indian Election 2004, Facts and Figures
http://www.indian-elections.com/facts-figures.html
How Stuff Works, How many sheets of paper can be
produced from a single tree?
http://science.howstuffworks.com/question16.htm
[2] T. Kohno, A. Stubblefield, A. Rubin, D. Wallach, Analysis
of an Electronic Voting System, May 2004.
http://avirubin.com/vote/analysis/index.html
[3] Science Applications International Corporation (SAIC),
Risk Assessment Report: Diebold AccuVote-TS Voting
System and Processes, SAIC-6099-2003-261, 2 September 2003.
http://www.dbm.maryland.gov/DBM%20Taxonomy/Tech-
nology/Policies%20&%20Publications/State%20Voting%20-
System%20Report/stateVotingSystemReport.html
[4] Black Box Voting, Consumer Report Part 1: The Diebold
GEMS central tabulator contains a stunning security
hole, 26 August 2004
http://www.blackboxvoting.org/?q=node/view/78
[5] Paul O'Donnell, Why you are still voting on
paper, WIRED, August 2004.
http://www.wired.com/wired/archive/12.08/start.html?pg=7
[6] VerifiedVoter.org
[7] CRS Report for Congress, Election Reform and Electronic
Voting Systems: Analysis of Security Issues.
http://www.epic.org/privacy/voting/crsreport.pdf
[8] D. Chaum, Achieving Electronic Privacy
http://ntrg.cs.tcd.ie/mepeirce/Project/Chaum/sciam.html
[9] A. Fujioka, T. Okamoto, and K. Ohta, A Practical Secret
Voting Scheme for Large Scale Elections. 1992.
http://theory.csail.mit.edu/~rivest/voting/papers/-
FujiokaOkamotoOhta-APracticalSecretVotingSchemeFor-
LargeScaleElections.pdf
[10] L. Cranor, R. Cytron, Sensus: A security conscious
electronic polling system for the Internet.
http://lorrie.cranor.org/pubs/hicss/
[11] D. Chaum, Secret Ballot Receipts and Transparent
Integrity.
http://www.vreceipt.com/article.pdf
[12] R. Dingledine, N. Mathewson, P. Syverson, Tor: The Second-
Generation Onion Router.
http://www.freehaven.net/tor/cvs/doc/design-paper/tor-design.html
[13] IDEA, Voter Turnout: A Global Survey
http://www.idea.int/voter_turnout/voter_turnout.html
1
0