Slashdot Mirror


California Panel Recommends Dumping Diebold

sdw3u writes "Wired reports that a voting panel urged California officials to stop using a voting machine made by Diebold Election Systems, and recommends that the state consider filing civil and criminal charges against the company." There's also an AP story. We covered the hearing yesterday, with Diebold admitting that their machines had numerous problems.

18 of 526 comments (clear)

  1. Online Banking Model by mfh · · Score: 5, Interesting

    This is the problem: you've got a system that is rotting away, where people have to drive/walk/take the bus to a designated voting station, register, and use a computer to vote. If you're going to have electronic voting, just throw a secure link online and let people vote through a web interface. Banks are pretty damn secure; why aren't these systems set up the same way as online banking? Sure you'll have criminals trying to break into systems to steal money, and you'll have the same criminals trying to break into voting systems to rig elections, but the bottom line is that if you are going to develop a system that's electronic, follow a system that is alread working: the online banking model.

    --
    The dangers of knowledge trigger emotional distress in human beings.
    1. Re:Online Banking Model by Shakrai · · Score: 5, Insightful
      but the bottom line is that if you are going to develop a system that's electronic, follow a system that is alread working: the online banking model.

      That's not the bottom line. The bottom line is that we don't need electronic voting systems. At best they are a political ploy to score cheap points for looking like we are "doing something" about the mess in Florida. At worst (if you are a tinfoil hat wearer) it's a giant conspiracy to rig our electoral system.

      I (and others) have said it before and I'll say it again. What the heck is wrong with paper ballots that are actually auditable? Or mechanical voting systems that don't rely on software that we can't see or understand? Why the heck do we need touchscreen voting? Why are the companies so afraid of putting an auditable paper trail in it?

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    2. Re:Online Banking Model by earlytime · · Score: 5, Interesting

      I've done security audits for online banking systems, and I can tell you fisrthand, they have weak security. Session hijacking and replay attacks are trivial.

      The main reason the public thinks that online banking is secure is because banks don't reveal the security incidents. What bank wants to tell it's customers that fees are going up because a couple million was stolen over the internet?

      --

    3. Re:Online Banking Model by delphi125 · · Score: 5, Interesting

      Of course you need electronic voting systems, but admittedly not for two horse elections every four or five years. No, you need them for regular referenda, and by regular I mean weekly. I don't have a problem with having elected representatives, but calling it democracy is not accurate. For sake of argument, if both major parties vote the same way on 70% of all issues, and I agree with the other decisions in a 16-14 ratio, that doesn't really give me much of a vote every four years now, does it? Never mind that what they will do in the future isn't really related to what they did in the past.

      Now of course government 'by the people' isn't trivial to set up. In modern countries with millions of inhabitants, automation will be necessary. That includes having 'voting' computers accessible to all, including those without computers, however remote, and a ton of other security measures. As another poster mentioned, online banks have such measures, so it should be doable with current technology. Of course, those in power don't have any reason to want to do this; they have a vested interest in the current system.

      The system I am suggesting would still rely strongly on representation: if you don't want to vote every week, you can give your proxy to someone else with similar views. This person will have made themselves available, will have had training, and be responsible to their 'constituency'.

      Such a system could be extended to allow people to vote for issues more important to them; for example people with children could have more say on education, or those living in a certain area have say on local issues.

      Not that it will happen in my lifetime, but I can imagine.

  2. Amazing by Luminari · · Score: 5, Funny

    Only took numerous voting irregularities and complete admission of guilt. Glad to see our swift democracy in action.

  3. Figures... by RedShoeRider · · Score: 5, Insightful
    "But members of the panel appeared to disagree with the company's claims, saying repeatedly that Diebold had been less than forthcoming during the state's nearly five-month investigation into its practices, often producing "frivolous" documents or responding slowly to state queries."

    Perhaps I'm just a cynic of the first order, but why on earth would they be less-than-forthcoming if they didn't have some sort of adjenda of their own? You would think that, as a large business, they'd be as forthcoming as possible to put the voters (and the investigatigators) minds at ease with the new technology. Of course, if you were hiding something.....

    Fudging elections is not a new concept. This is just a new twist on it. /tinfoil hat on

    --

    Chris Knight is my hero.

    1. Re:Figures... by Ralph+Wiggam · · Score: 5, Insightful

      Only the conspiracy folks are suggesting that Diebold is actively working to rig elections. The president of Diebold's fund raising efforts and promises of delivering electoral votes aren't helping to calm those fears.

      The problem is that Diebold's incompetence and inability to follow even the most basic commercial security practices leaves the door open for other people to rig elections. And since the systems are un-auditable, we would all just be stuck with the winners of a rigged election as our leaders.

      Federal HIPAA regulations use a 2" thick binder to describe in great detail what computer security procedures must be followed for handling private health information. Aren't elections slightly more important?

      -B

  4. Re:Good! by Kierthos · · Score: 5, Insightful

    Given that Ahhhnold became the Governator because of (in part) the shitty budget of California, it's always possible that Diebold has a bigger legal fund. :P

    Actually, if they can prove (and it could be very easy to do so) that Diebold knew about the problems with their machines, then it's practically an open and shut case. Sooo... anyone want to help California out on this? No, no, a nice orderly line please. You'll all have a chance to help.

    Kierthos

    --
    Mr. Hu is not a ninja.
  5. About time... by Bored+Huge+Krill · · Score: 5, Interesting

    It's just unfortunate that so much (of our) money had to be spent before it became obvious to the point that something had to be done about it. What I found truly shocking was the way that Diebold admitted yesterday that thousands of voters had been disenfranchised as a result of their practices, and didn't seem to treat it as a big deal. Now we have an employee complaining that the state is being "too confrontational" and they should be "working together to fix the problems" Fundamental disconnect here, methinks. If you pay a commercial organization good money to deliver a system, which they get to keep proprietary, it's up to them to fix it. If the system design and software is to be open to inspection, then we can talk about "working together"

  6. Result of the Panel by Downside · · Score: 5, Funny

    The five person voting panel voted 57 to 3.14 in favour of getting rid of the Diebold machines...

  7. Re:Diebold voting machines by Shakrai · · Score: 5, Insightful
    No, the Florida results COULD have been disasterous if Gore had been allowed to block the military votes that had yet to be counted.

    Like Bush trying to block the absentee ballots from Democratic leaning counties? Or the fake mobs of Republican congressional staffers bussed down from DC?

    It's a double-edged sword and I suggest you stay away from it. Both of them acted in the most ruthless manner possible. What else would you expect?

    Posted as AC due to the liberals on /.

    So you don't have the guts to risk a little karma to stand up for what you think is right? It's only karma for goodness sake. Do you think I'm going to go home and cry if this post gets modded down by a Republican?

    --
    I want peace on earth and goodwill toward man.
    We are the United States Government! We don't do that sort of thing.
  8. Many many problems by visionsofmcskill · · Score: 5, Insightful
    There are tons of issues with this.

    One.. voter verification: the overwhelming majority of voters must present picture ID and face to face with a pollster at their DESISGNATED district for voting.

    Two, DDOS and many other types/styles of web attacks, which dont need to break security can easily be driected at say the midwestern states, or the liberal states... rendering their sum vote count down, thus allowing the other states a greater showing.

    Three, hard break security, with a physical seperation from any public network, it becomes much more difficult for hackers and RICH politcal powers to corrupt the system. With even polling sites seperated by hard breaks it becomes a decentralized and distributed system that is much more difficult to compromise even if a few nodes are compromised.

    Four, anonymity, passwords, and human ID. While we currently have mail-in voting, it is a small portion of our voting poulace, and still reuires a signature far more of a proof that it was cast by said person. With online voting, we would have difficulties verifying voters across disparete hardware, as well as their passwords can be much more easily compromised than a signature for a mail-in. anonymity should only extend as far as the VOTE, not the proof of the existance of the voter.

    finaly... id like to say this idea isnt without merit... there are existing security solutions that are very powerfull... i would suggest using them in a CLOSED network entirely physicaly seperete from any public network, with the nodes also seperated.

    just my thirty three cents worth

    --
    --Idiots, Every single one of YOU, A flaming mass of conglomerated morons, hey wait a second, isnt that how RAID works?
    1. Re:Many many problems by neowolf · · Score: 5, Insightful

      What I find interesting is that Diebold makes probably MOST of the ATMs that people use on a regular basis, so they actually do know how to make secure and reliable machines on secure networks (at least secure and reliable enough for banks). Not sure why they have such a hard time with voting machines.

  9. Vote-From-Home is NOT a good idea! by LithiumX · · Score: 5, Interesting

    Every time the subject of electronic voting comes up, you hear people saying that polling stations themselves are part of the problem, or that we should be able to vote from the convenience of home or office.

    I disagree. Vehemently.

    Voting is somewhat of a ritual in many countries, especially the US. People will gladly talk about their politics, but ask them who they voted for and you usually get the cold shoulder. It's a private matter. You'd have better luck asking them how their bowels are doing. The polls themselves are nice and curtained or secluded, so no one can see. People bring their kids and let them watch, even let them do the final act of pressing the lever or button. There aren't many companies that aren't willing to let their people take a long lunch in order to go vote, and those that don't are not looked upon highly.

    When it is your civic duty to periodically go to your official polling station, when you have to go to a specific place that you probably never go for any other reason, where you're around a large spectrum of people of all types that you might not otherwise be exposed to, and go specifically to cast your vote... it means a little more than simply hitting a website and picking the guy who you'd like to have lead.

    The percentage of people who vote is truly sad, but it's not a good idea to fix it by making it TOO easy to vote. There must be at least a minimum of effort involved - a place to go, as long as it's reasonably easy to get to. The same place as all your neighbors. When you have to make an event of it, it tends to focus you more on what you're doing, and I've found that people become far less extreme in their politics when faced with this fact.

    If you could vote from home, you'd put less thought into it. It would be one step closer to a news site poll, except THIS poll would make our final official selections. People wouldn't take it seriously enough. More people would vote, but the quality of those votes would not carry the same weight.

    If the Primaries had been run over the web, I'm willing to bet Dean would have outdone his competition. But people were at an event, a political ritual, and that sobered them into making a more mature choice (though I think there were better people they could have chosen).

    Voting should be readily available to the masses. It should be quick, efficient, and as infallible as we can safely make it. But it should also be an official civic act not taken lightly, and deffinitely never done from home.

    All technical questions of security and validation aside, the concept of a quick and easy home solution for choosing our national leaders is not a good idea.

    --
    Do not confuse "Freedom of Choice" with "Free Will".
  10. They did this with Good Reason by KarmaOverDogma · · Score: 5, Interesting

    /. has covered numerous examples of how Diebold has a less than stellar record when it comes to their honesty, impartiality, and a willingness to pursue auditability and quality control in their machines. Here in Ohio, a protsest march was held regarding Diebold's practices at a shareholder meeting.

    I heard an interview on NPR today where the chief of marketing participated in the on air talk-show (InfOhio after 9) review of this protest and Diebold's activities with regard to electronic voting. He basically said California's Voting Laws were so complex and constantly changing that they were not upset at having to leave the CA e-voting machine market.

    Sounds like the pot calling the Kettle Black to me.

    Diebold's CEO and President Walden O'Dell promised to deliver Ohio (which makes me angry to have them here in my state) to Bush in November, donated to the Bush campaign and worked to organize re-election effrts to do the same. Since this time he has publicy apoligized for his public support of the Bush campaign (one would guess because of the obvious suspicions of impartiality and conflict-of-interest, wether founded or not) and vowed to keep out in the future. IMO, the damadge of his public display of support has already been done. He hasn't asked for the money back. I don't think its unreasonable to hope that the CEO and President of a company hawking a product that manages/administers/records voting would treat voting what it is, THE SINGLE MOST IMPORTANT FOUNDATION OF DEMOCRACY. He and his company are not trustworthy to me.

    .

    --
    uR iGn0ranc3, Their Power
  11. Re:Why by Shakrai · · Score: 5, Insightful
    Micro-auditing is possible if you check your account after voting to make sure the vote you placed was the vote you wanted. Each user can remember who they voted for, and they could easily call out if their account was violated in any way. Any database can tally up votes if they are micro-audited internally, and cross-referenced. Very standard secure database design will always be able to print a receipt. They could mail you a receipt too.

    I'm sorry, but I'm not ready to give up my anonymous ballot just so I can vote online from home. The anonymous ballot is one of the most important features of our voting system. And if you are too lazy to go down to the polling place once a year (or request an absentee ballot) then you probably don't need to be voting anyway.

    Mechanical voting systems are a thing of the past. I really believe that society is ready for online voting.

    Why? They work just fine and any poll worker with an hour of training can understand how they work. They are virtually impossible to sabotage without being detected. And they leave a paper trail.

    Imagine a nice record of your voting history? That would seriously rock.

    Umm??? WTF??? No it would not rock. Do I want my voting record retained forever? That's a great idea. That way there's always the possibility of being harassed/jailed/murdered if my current political party ever goes out of style. Oh, and a nice way of my employer/union leader to blackmail me too.

    --
    I want peace on earth and goodwill toward man.
    We are the United States Government! We don't do that sort of thing.
  12. Re:Which problems do you want? by __aanebg9627 · · Score: 5, Insightful

    Human error we're going to get no matter what, so we want a system that will minimize it. Not one that makes it difficult to spot.

    Damaged punch cards are easy to see, bad optical scanners will get noticed. Problems with voting software in black-box voting systems are much harder to spot, if there's no paper trail to audit.

    But the problems with Diebold systems are much worse than this. The vote counts are stored in a MS Access database, which can easily be edited by anyone who knows how. They are not necessarily protected with a password. Even worse, the audit log is also editable, so that it's possible to go into the system, alter the votes, and then edit the log to hide all traces.

    Bev Harris' expose/Diebold memos And more of Harris' expose

    Perhaps Diebold was keeping this backdoor in so that they could edit vote counts when their systems malfunctioned. However, others can also use the backdoor, and perhaps they have. There were some very squirrely results out of Georgia last election, where the pre-election polls were at wide variance with the results.

  13. I'm in Orange County, CA and I vote by rjamestaylor · · Score: 5, Informative
    During the last election, the one after we elected the doing-better-than-anticipated Arnold Schwartzanegger (I can't spell) Governor, I voted in Rancho Santa Margarita and our polling location used electronic voting machines. Exiting the booth one of the 4 or 5 volunteers asked if I liked the new machines, clearly expecting a hearty "Hell yeah". Since no one else was in the polling area at the time I stopped and told them the truth: I did not and I was worried about my vote, other's votes and the potential for loss or after the vote manipulation, present company excepted. They were shocked and the leader asked me to please explain. I gladly told them that
    • the user interface was different than the punch cards we'd used for so long; that meant confusion, especially since there was no way to "train" on the new equipment before casting the actual vote(!),
    • there was no physical record of the vote
    • being that there was no physical record changing the vote count would be simple.
    • there was no "receipt" showing me my vote so I knew I voted correctly.
    I did not get into the hacking issues, since these were not the brightest people; which was another problem in itself. They responded that they did indeed have a record of each vote -- on a central machine controlled by a lady who had a running tally of votes and could print a vote audit trail for each machine. But each machine depended on that central one to hold its votes and there was no corroborrating (I can't spell) record from each machine. I asked what would happen if the central computer failed. I don't rememeber the precise details but it was clear that there was one backup and if it was also lost, all was lost. What is a recount? Re-print the vote total you just printed. There is no way to recount the counted votes. They thought this was a feature ("no need to recount") instead of a flaw ("no way to recount").

    Then I told them I was responsible for databases. At different times I have been responsible for hundreds of thousands of credit card settlements daily and explained how our failsafe measures failed to the extent a days worth of customers (say, half a million US dollars, without including AMEX) were doubled and, due to an API error, the fix resulted in a triple billing. Wheee. Our systems had much more checks and balances, backups and audit trails than there silly voting system and yet one days transactions went wildly wrong (we somehow avoided the news, though our problem involved the same processor as Walmart's in their recent fiasco). How would they retract double/triple counted votes? Replace lost votes?

    The good people at my polling place had received the warm fuzzies from the people promoting inaccountable electronic voting; they didn't like hearing my input. But why would we treat our money as more precious than the foundation of our republican democracy?

    --
    -- @rjamestaylor on Ello