In December 2002 I received an email out of the blue, from David Dill. It said:
"I'm a computer science professor at Stanford. I'm aghast that places are actually using DRE machines with no paper trail. I would like to see if I can help to ensure that new voting machines are auditable."
And help he has. In the three years since that time, David Dill has started Verified Voting, testified before Congress and all across the country, and helped to establish ACCURATE, a multi-university, multi-million dollar National Science Foundation-funded project to improve voting equipment. Dave and I served together on the California Secretary of State's 2003 Touch Screen Voting Task Force, and I was honored to share the Electronic Frontier Foundation's 2004 Pioneer Award with him.
One of the many things I admire about Dave is his ability to understand human nature and politics. I also admire his commitment to working on voting technology problems, which are complicated and at times frustrating. But the years of toil have given David Dill a clear vision of where we need to go, as he explains in this piece, recently published on TomPaine.com and featured below.
-------
Making Democracy Transparent
by David Dill
Public trust in our elections is eroding. While the general public still seems to accept election results, there is an undercurrent of bitterness that has grown tremendously over the last few years. There is a rapidly expanding body of literature on the Internet about the "stolen election of 2004," and several books on election fraud have recently been written. More are in the works.
Theories of widespread election fraud are highly debatable, to say the least. Some people enjoy that debate. I do not. It encourages a sense of hopelessness and consumes energy that could instead be focused on long-term changes that could give us elections we can trust.
The election fraud debate frames the problem incorrectly. The question should not be whether there is widespread election fraud. It should be: "Why should we trust the results of elections?" It's not good enough that election results be accurate. We have to know they are accurate - and we don't.
In a word, elections must be transparent. People must be able to assure themselves that the results are accurate through direct observation during the election and examination of evidence afterwards.
U.S. elections are far from transparent. Instead, winning candidates and election officials alike tend to put all their efforts into suppressing recounts. That attitude has led to increasing bitterness with each national election, at least since Florida 2000.
But we can conclusively win a debate about election transparency. And while making elections more transparent will be difficult, it is more feasible than solving many of our other national problems. All that is required for success is a long-term strategy and a commitment from many citizens at the grassroots level, since politicians and election officials are not going to solve the problems on their own.
Here are some initial thoughts on how we can do it. I propose a four part solution: We need to ensure that voting technology is transparent; election procedures need to be rethought to emphasize openness, security and checks and balances; election laws need to be revised to support these points and to make it easy for candidates to get reliable, manual recounts; finally, citizens need to participate in witnessing elections and making sure they are conducted properly.
Questions about voting technology have been in the spotlight in the last few years. The first concerns were about accuracy, inspired by the problems with punch cards in the 2000 election. The supposed solution to that problem lead to plans for the widespread adoption of paperless electronic voting. But paperless e-voting is totally opaque - no one can observe the handling of the (electronic) ballots. The hardware and software of modern computer systems are designed and built by thousands of specialists: Decades have passed since a single person could comprehend an entire computer system. As a result, there is no way to ensure that such voting systems are accurate or honest.
Right now, the only feasible solution to the insecurity of electronic voting is a universal requirement for voter-verified paper records of all ballots (VVPR). We also need to pass laws that enable candidates to obtain manual recounts easily and inexpensively. There is now a national movement to make sure this technology is used, and it's winning, slowly but surely. Since the 2004 election, state after state has passed laws requirement VVPRs, and others have required VVPRs by administrative decree. In most states, this is the result of grassroots activism by citizens groups with support from national groups. A recent example of an outstanding success is New Mexico's law requiring paper ballots, marked by the voters, which was signed March 2.
There remains much to do on the technology front, including converting hard-core e-voting states like Texas, Florida, and Georgia to VVPR (or, better, adopting a nationwide law, such as the one proposed by Rep. Rush Holt in the House or the one proposed by Sen. John Ensign). Also, the system for certifying voting technology at the state and national level is completely broken. But these problems can be solved with time and dedicated activism.
Election procedures need much greater attention, from the storage of equipment before an election to the storage of ballots after the last recount. Currently, inadequately tested voting machines break down on Election Day. Uncertified and sometimes buggy software is routinely used. Votes are counted behind closed doors. Machines and ballots are in the custody of a single individual, and are sometimes misplaced. Recounts are conducted with rules that are often made up on the spot.
Detailed election procedures need to be defined, taking into account the differences between jurisdictions (including differences in technology). These procedures need to be followed rigorously, even in remote locations with underfunded and understaffed election offices. Procedures need to be improved from election to election, and experiences with new procedures need to be shared among different election offices.
Many of the reforms in technology and procedures need to be codified in election law, including requiring VVPRs. There should be a law requiring the mandatory auditing of election results by manually counting paper ballots from a random sample of the precincts. Routine manual audits depoliticize recounts because they do not have to be requested by a candidate, and because they must occur regardless of whether an election is close or which candidate won. With routine audits, election problems can be discovered and addressed when the outcome of the election is not in dispute.
It is critical that candidates (or, even better, members of the public) be able to obtain manual recounts easily and inexpensively. In recent years, putative winners of close elections have often alluded the "chaos in Florida 2000" for the purpose of suppressing a recount. Recounts conducted under clear rules would not be so chaotic. It is simple common sense to take a close look at the ballots when there is a question about an election. A little cost or effort to satisfy a disgruntled candidate (and his or her supporters) pays huge dividends for democracy.
Finally, these improvements will have little effect unless citizens are more involved in elections. Citizens have to generate grassroots pressure for reforms. There need to be observers to take advantage of any increased openness in election procedures. Indeed, many procedural improvements depend on the presence of independent witnesses to be effective. Citizens need to be see what procedures are actually followed in an election, and compare that with the procedures that should be followed. We have seen time and time again that election laws are routinely ignored—unless someone is watching.
Many of our current problems stem from a "quick-fix" attitude - leading to fresh problems, such as the idea that new touch-screen machines would solve all our election woes. To have the kind of elections we need will take hard work and many years, and there will be setbacks along the way. But if we follow a long-term plan, we'll see that each election is better than the previous.
Wednesday, March 8, 2006
Tuesday, March 7, 2006
More on the prosecution of Diebold law firm whistleblower
This week's LA Weekly features this article by Christine Pelisek about Los Angeles DA Steve Cooley's prosecution of Stephen Heller, the Jones Day employee who leaked Diebold's legal memos to the media and state authorities. Excerpts are featured below.
------------
What would you call a well-meaning employee at a law firm handling Diebold's legal strategies who leaks key documents outlining problems with voting machines to the secretary of state and a newspaper reporter?
If you're Steve Cooley, L.A. County's district attorney, you'd call him a thief and charge him with three felonies. If you're an expert in a state law that protects employees who rat out potentially dangerous and illegal conduct, you'd call him a whistleblower.
"The issue is that he shouldn't have been charged at all," said Louis Clark, president of the Government Accountability Project, a nonprofit whistleblower protection organization in Washington, D.C. "It really is against public policy to bring felony charges against a whistleblower who is alleged to have brought forward information about election misconduct."
But Cooley did just that on February 21 when his office charged Stephen Heller, 44, with felony access to computer data, commercial burglary and receiving stolen property. The New York native could face up to three years in prison if convicted.
"This is basically a man who allegedly hacked into private files," said D.A. spokesperson Jane Robison. "We are alleging that he stole computer files. If you are an attorney you have every reason to believe that the information is guarded. Attorney-client privilege is sacrosanct."
Heller became the focus of the District Attorney's Office in 2004 after he allegedly gave the secretary of state and the Oakland Tribune memos the law firm Jones Day sent to its client, Diebold, outlining possible state elections law violations of its electronic voting machines.
Heller, an actor by trade, was working as a temporary word processor on a three-month contract with Jones Day when he came across the internal documents exposing irregularities in Diebold's electronic voting machines. He passed the documents along to an intermediary, who has not been identified, who placed them in the hands of Beverly Harris, the founder of a Seattle-based elections-watchdog group called Black Box Voting Inc. Harris then turned over the documents to Heller's intended recipients in Sacramento and Oakland.
The Diebold memos were published on the Tribune's Web site in April 2004, a month after voting irregularities surfaced in San Diego and Alameda counties by voters who were turned away at the polls while others had to use paper ballots.
---
Harris defends Heller's actions. "He was concerned that he was doing the right thing. If you are a good citizen, what are you supposed to do? Nothing?" said Harris. "If citizens don't stand up when there is something clearly wrong, then we are in deep trouble. We have to depend on our citizens to be responsible and that is what he did. They should be giving him a medal. This is an effort by big, powerful players who want to change the subject from what they did and they also want to discourage anyone else from telling what they know."
The state whistleblower law doesn't protect the employee from criminal prosecution. "There is nothing that can protect him from a prosecutor who decides to prosecute other than a jury and a judge," said Clark. "The district attorney can do something to Mr. Heller that perhaps Diebold couldn't do."
Robison said the District Attorney's Office is not alleging monetary gain.
"If there is no intention to profit from this then I think the charges are outrageous," said Clark. "I would be surprised if any member of the Legislature who put the law on the books had in mind someone who was taking information and making sure it went to government officials in order for them to look at whether a crime had been committed by a company."
------------
What would you call a well-meaning employee at a law firm handling Diebold's legal strategies who leaks key documents outlining problems with voting machines to the secretary of state and a newspaper reporter?
If you're Steve Cooley, L.A. County's district attorney, you'd call him a thief and charge him with three felonies. If you're an expert in a state law that protects employees who rat out potentially dangerous and illegal conduct, you'd call him a whistleblower.
"The issue is that he shouldn't have been charged at all," said Louis Clark, president of the Government Accountability Project, a nonprofit whistleblower protection organization in Washington, D.C. "It really is against public policy to bring felony charges against a whistleblower who is alleged to have brought forward information about election misconduct."
But Cooley did just that on February 21 when his office charged Stephen Heller, 44, with felony access to computer data, commercial burglary and receiving stolen property. The New York native could face up to three years in prison if convicted.
"This is basically a man who allegedly hacked into private files," said D.A. spokesperson Jane Robison. "We are alleging that he stole computer files. If you are an attorney you have every reason to believe that the information is guarded. Attorney-client privilege is sacrosanct."
Heller became the focus of the District Attorney's Office in 2004 after he allegedly gave the secretary of state and the Oakland Tribune memos the law firm Jones Day sent to its client, Diebold, outlining possible state elections law violations of its electronic voting machines.
Heller, an actor by trade, was working as a temporary word processor on a three-month contract with Jones Day when he came across the internal documents exposing irregularities in Diebold's electronic voting machines. He passed the documents along to an intermediary, who has not been identified, who placed them in the hands of Beverly Harris, the founder of a Seattle-based elections-watchdog group called Black Box Voting Inc. Harris then turned over the documents to Heller's intended recipients in Sacramento and Oakland.
The Diebold memos were published on the Tribune's Web site in April 2004, a month after voting irregularities surfaced in San Diego and Alameda counties by voters who were turned away at the polls while others had to use paper ballots.
---
Harris defends Heller's actions. "He was concerned that he was doing the right thing. If you are a good citizen, what are you supposed to do? Nothing?" said Harris. "If citizens don't stand up when there is something clearly wrong, then we are in deep trouble. We have to depend on our citizens to be responsible and that is what he did. They should be giving him a medal. This is an effort by big, powerful players who want to change the subject from what they did and they also want to discourage anyone else from telling what they know."
The state whistleblower law doesn't protect the employee from criminal prosecution. "There is nothing that can protect him from a prosecutor who decides to prosecute other than a jury and a judge," said Clark. "The district attorney can do something to Mr. Heller that perhaps Diebold couldn't do."
Robison said the District Attorney's Office is not alleging monetary gain.
"If there is no intention to profit from this then I think the charges are outrageous," said Clark. "I would be surprised if any member of the Legislature who put the law on the books had in mind someone who was taking information and making sure it went to government officials in order for them to look at whether a crime had been committed by a company."
Thursday, March 2, 2006
CA certification hearing draws e-voting critics
Yesterday I attended the Secretary of State's public hearing on certification of new voting equipment for California. There were about 80-100 people in attendance, many coming from outside of Sacramento. The crowd included activists, county election officials, vendors and reporters.
Prior to the hearing, a group of activists, many affiliated with the California Election Protection Network, held a rally criticizing Secretary of State Bruce McPherson's decision to certify voting equipment manufactured by Diebold. Once inside the meeting, however, the citizens who spoke up focused their remarks on general distrust of computerized voting systems. Several spoke out in favor of hand-counting paper ballots, and many expressed a lack of confidence in voting systems produced by private companies and utilizing proprietary software.
My comments focused on the draft procedures produced by the vendors, and specifically their descriptions (or lack thereof) of how the one percent manual count be conducted. I also expressed concern that the volume testing on Sequoia's Edge I and II touchscreen voting machines showed numerous problems with the voter activation cards, or "smart cards" used to call up the electronic ballots. During the meeting Bruce McDannold of the Secretary of State's staff explained these problems were due to the fact that the smart cards were preprogrammed before the volume test began. During my testimony I said that additional volume tests should be conducted to ensure the voter activation cards are working properly. I also expressed concern about the number of printer problems found in the Hart eSlate electronic voting machine found during volume testing, and said that it should not be certified until those problems are worked out.
For more news on the meeting, see Marianne Russ' story on Capitol Public Radio. Kevin Yamamura's Sacramento Bee article described the protest rally held by activists prior to the meeting as well as views expressed by registrars and disability rights activists. Ian Hoffman's Oakland Tribune article describes the problems discovered during testing and the pressure counties are under to plan for the upcoming June Primary. Excerpts from that story and the Sacramento Bee article are featured below.
-----------
(excerpts from Sacramento Bee article)
Dan Ashby's button asked, "Who did your voting machine vote for?" Michelle Gabriel held a sign accusing Secretary of State Bruce McPherson of flip-flopping on voting security procedures.
Other activists promoted the slogan, "Live Free or Diebold."
Electronic voting critics rallied Wednesday at McPherson's downtown headquarters to denounce his decision last month to certify Diebold machines for 2006 and testify against three other computer-based systems under review.
They charged that electronic voting machines are prone to hackers and testified they would prefer paper ballots.
---
Ashby, a San Pablo volunteer organizer with the California Election Protection Network, said he has no confidence in security procedures because he believes the Diebold machines have "too many attack pathways that can be overcome."
He said activists may pursue a lawsuit to stop them from being used.
McPherson's approval of Diebold came as he faced pressure to meet a 2006 federal Help America Vote Act requirements for upgrades in voting technology and accessibility. Many of the state's registrars said McPherson had delayed certification for too long, while the secretary of state said he wanted to conduct a thorough review process.
---
Warren Cushman, a Sacramento member of California Council for the Blind, said he considers new technology a positive step if it makes voting more accessible.
He took issue with activists who suggest that voting machine companies have curried favor with accessibility rights groups though donations, as one claimed during Wednesday's hearing.
"Our issue is voter accessibility, and when we're accused of being dupes, we have to disagree with that," Cushman said. "There has to be a respect issue because some folks are so wrapped up in their security issues that they forget about the right to vote for people with disabilities."
----------
(excerpts from Oakland Tribune article)
As state officials race to evaluate voting machines for the June elections, critics complained Wednesday that the state was short-circuiting its own rules and putting substandard tools in the hands of voters.
The latest crop of machines are more accessible for disabled voters than ever before but still show significant errors in "volume testing" that simulates an election.
Testing 50 to 100 machines at a time has revealed problems — some minor, some major — with virtually every kind of voting system that vendors want to sell in the state, from common ballot jams and touchscreen errors to system crashes and the rare lost ballot.
In all but one case, in which 59 total errors arose on 100 Hart optical scanners, state elections staff is recommending Secretary of State Bruce McPherson approve the machines for voters, with detailed instructions for recalibrating and rebooting if problems occur on Election Day.
---
Congress made disabled access part of voting reforms passed under the Help America Vote Act following the 2000 presidential election. State legislatures in California and a dozen other states set the bar higher still by requiring printers on the ATM-like voting machines so voters could verify their choices and elections officials could have a paper record to recount.
---
Some county elections officials say the June primaries, now 96 days away, are too close to contemplate buying and training on a new voting system.
Alameda County, for example, is considering handing out paper ballots in the polling places while offering touchscreens possibly borrowed from San Diego County to voters with disabilities. San Mateo County is moving ahead with a 12-county proposal for a one-time, all-mail election in June. Failing necessary approval by the state Legislature, the county may accommodate voters with disabilities by setting up two dozen or so regional voting centers with Hart touchscreens, the remainder of voters to use optically scanned paper ballots.
"This is a tough time," said Contra Costa County Registrar of Voters Steve Weir. "We're way too close to this election."
Earlier in the day, federal civil-rights lawyers sued the state of New York for failing to acquire disabled-accessible voting machines and create a statewide voter-registration database, another requirement of the Help America Vote Act. Officials at the U.S. Department of Justice said in a statement that they "repeatedly urged" New York to work on the matter and that as of Jan. 1, the state was "not close to compliance with either provision."
California elections officials want to avoid the same fate. But the state is running into objections from voting-reform activists who say the rush risks sacrificing reliable, secure voting systems.
"There are many errors. It's just too many. You shouldn't certify it," Berkeley computer programmer Jerry Berkman told the state panel.
Critics said the machines' shortcomings will force elderly pollworkers to become computer experts and swap out printer rolls on the fly on Election Day.
"When you have machines that have to be recalibrated, rebooted with pollworkers who are 70, it's just clear these machines are not reliable," said Mary Beth Brangan of Bolinas. "I just think the answer to a lot of these problems is to get simpler, not more complex."
Disability advocates say accessibility has to be as important in new voting systems as reliability and security. "There is a solution," said Warren Cushman, a blind voter in Sacramento. "We just need to find a solution that works for everybody."
Prior to the hearing, a group of activists, many affiliated with the California Election Protection Network, held a rally criticizing Secretary of State Bruce McPherson's decision to certify voting equipment manufactured by Diebold. Once inside the meeting, however, the citizens who spoke up focused their remarks on general distrust of computerized voting systems. Several spoke out in favor of hand-counting paper ballots, and many expressed a lack of confidence in voting systems produced by private companies and utilizing proprietary software.
My comments focused on the draft procedures produced by the vendors, and specifically their descriptions (or lack thereof) of how the one percent manual count be conducted. I also expressed concern that the volume testing on Sequoia's Edge I and II touchscreen voting machines showed numerous problems with the voter activation cards, or "smart cards" used to call up the electronic ballots. During the meeting Bruce McDannold of the Secretary of State's staff explained these problems were due to the fact that the smart cards were preprogrammed before the volume test began. During my testimony I said that additional volume tests should be conducted to ensure the voter activation cards are working properly. I also expressed concern about the number of printer problems found in the Hart eSlate electronic voting machine found during volume testing, and said that it should not be certified until those problems are worked out.
For more news on the meeting, see Marianne Russ' story on Capitol Public Radio. Kevin Yamamura's Sacramento Bee article described the protest rally held by activists prior to the meeting as well as views expressed by registrars and disability rights activists. Ian Hoffman's Oakland Tribune article describes the problems discovered during testing and the pressure counties are under to plan for the upcoming June Primary. Excerpts from that story and the Sacramento Bee article are featured below.
-----------
(excerpts from Sacramento Bee article)
Dan Ashby's button asked, "Who did your voting machine vote for?" Michelle Gabriel held a sign accusing Secretary of State Bruce McPherson of flip-flopping on voting security procedures.
Other activists promoted the slogan, "Live Free or Diebold."
Electronic voting critics rallied Wednesday at McPherson's downtown headquarters to denounce his decision last month to certify Diebold machines for 2006 and testify against three other computer-based systems under review.
They charged that electronic voting machines are prone to hackers and testified they would prefer paper ballots.
---
Ashby, a San Pablo volunteer organizer with the California Election Protection Network, said he has no confidence in security procedures because he believes the Diebold machines have "too many attack pathways that can be overcome."
He said activists may pursue a lawsuit to stop them from being used.
McPherson's approval of Diebold came as he faced pressure to meet a 2006 federal Help America Vote Act requirements for upgrades in voting technology and accessibility. Many of the state's registrars said McPherson had delayed certification for too long, while the secretary of state said he wanted to conduct a thorough review process.
---
Warren Cushman, a Sacramento member of California Council for the Blind, said he considers new technology a positive step if it makes voting more accessible.
He took issue with activists who suggest that voting machine companies have curried favor with accessibility rights groups though donations, as one claimed during Wednesday's hearing.
"Our issue is voter accessibility, and when we're accused of being dupes, we have to disagree with that," Cushman said. "There has to be a respect issue because some folks are so wrapped up in their security issues that they forget about the right to vote for people with disabilities."
----------
(excerpts from Oakland Tribune article)
As state officials race to evaluate voting machines for the June elections, critics complained Wednesday that the state was short-circuiting its own rules and putting substandard tools in the hands of voters.
The latest crop of machines are more accessible for disabled voters than ever before but still show significant errors in "volume testing" that simulates an election.
Testing 50 to 100 machines at a time has revealed problems — some minor, some major — with virtually every kind of voting system that vendors want to sell in the state, from common ballot jams and touchscreen errors to system crashes and the rare lost ballot.
In all but one case, in which 59 total errors arose on 100 Hart optical scanners, state elections staff is recommending Secretary of State Bruce McPherson approve the machines for voters, with detailed instructions for recalibrating and rebooting if problems occur on Election Day.
---
Congress made disabled access part of voting reforms passed under the Help America Vote Act following the 2000 presidential election. State legislatures in California and a dozen other states set the bar higher still by requiring printers on the ATM-like voting machines so voters could verify their choices and elections officials could have a paper record to recount.
---
Some county elections officials say the June primaries, now 96 days away, are too close to contemplate buying and training on a new voting system.
Alameda County, for example, is considering handing out paper ballots in the polling places while offering touchscreens possibly borrowed from San Diego County to voters with disabilities. San Mateo County is moving ahead with a 12-county proposal for a one-time, all-mail election in June. Failing necessary approval by the state Legislature, the county may accommodate voters with disabilities by setting up two dozen or so regional voting centers with Hart touchscreens, the remainder of voters to use optically scanned paper ballots.
"This is a tough time," said Contra Costa County Registrar of Voters Steve Weir. "We're way too close to this election."
Earlier in the day, federal civil-rights lawyers sued the state of New York for failing to acquire disabled-accessible voting machines and create a statewide voter-registration database, another requirement of the Help America Vote Act. Officials at the U.S. Department of Justice said in a statement that they "repeatedly urged" New York to work on the matter and that as of Jan. 1, the state was "not close to compliance with either provision."
California elections officials want to avoid the same fate. But the state is running into objections from voting-reform activists who say the rush risks sacrificing reliable, secure voting systems.
"There are many errors. It's just too many. You shouldn't certify it," Berkeley computer programmer Jerry Berkman told the state panel.
Critics said the machines' shortcomings will force elderly pollworkers to become computer experts and swap out printer rolls on the fly on Election Day.
"When you have machines that have to be recalibrated, rebooted with pollworkers who are 70, it's just clear these machines are not reliable," said Mary Beth Brangan of Bolinas. "I just think the answer to a lot of these problems is to get simpler, not more complex."
Disability advocates say accessibility has to be as important in new voting systems as reliability and security. "There is a solution," said Warren Cushman, a blind voter in Sacramento. "We just need to find a solution that works for everybody."
NM Governor to sign paper ballot bill today in live webcast
Paper ballots were the big talk of the day at yesterday's California voting equipment certification hearing. I'll have more to report on that later, along with links to news coverage.
Meanwhile, over in New Mexico, Governor Bill Richardson is getting ready to sign a bill mandating paper ballots for his state in a live webcast. The event is being organized by his re-election campaign, and the webcast is supposed to be available from this page, starting at 10 a.m. Pacific/1 p.m. Eastern.
With the signing of the legislation, New Mexico becomes the 26th state to require paper ballots or voter-verified paper audit trails at the polls. This move also will reduce the number of paperless electronic voting machines used in the nation, since two-thirds of New Mexico's counties currently use this kind of voting equipment. Richardson is also calling on political leaders in other states to get on board. Below is an excerpt from his "Open Letter" to state officials. The full text is available from the link above.
---------------
On March 2, 2006, I will sign a bill that will transition New Mexico to an all paper-ballot system using optical scanners to count the vote. Paper ballots are the least expensive, most secure form of voting available. Having marked their votes with pen and paper, voters will walk out of the booth and know their voices have been heard. Optical scanners will quickly and accurately provide results, while in the event of a recount, the ballots themselves will be a permanent, verifiable record of the people’s directions to their government.
Some believe that computer touch screen machines are the future of electoral systems, but the technology simply fails to pass the test of reliability. As anyone who uses one can attest, computers break down, get viruses, lose information, and corrupt data. We know this to be the case, and so we back-up our files to ensure nothing important is lost. Paper ballots serve as the ultimate back-up for our elections, providing secure and permanent verification of the will of the people.
New Mexico has chosen paper ballots as the best system to secure our election process. With the new system in place, future elections will be secure, honest, and verifiable. Every vote will count and the citizens of our state will know that their government belongs to them.
One person, one vote is in jeopardy if we do not act boldly and immediately. American citizens once took for granted that every vote mattered, but no longer. It is time that we, the elected state officials, work to restore American’s confidence in our electoral systems and undertake reform that moves to eliminate skepticism and uncertainty.
When a vote is cast, a vote should be counted. With paper ballots we will have a record. With paper ballots the fundamental principle of one person, one vote is safe.
Meanwhile, over in New Mexico, Governor Bill Richardson is getting ready to sign a bill mandating paper ballots for his state in a live webcast. The event is being organized by his re-election campaign, and the webcast is supposed to be available from this page, starting at 10 a.m. Pacific/1 p.m. Eastern.
With the signing of the legislation, New Mexico becomes the 26th state to require paper ballots or voter-verified paper audit trails at the polls. This move also will reduce the number of paperless electronic voting machines used in the nation, since two-thirds of New Mexico's counties currently use this kind of voting equipment. Richardson is also calling on political leaders in other states to get on board. Below is an excerpt from his "Open Letter" to state officials. The full text is available from the link above.
---------------
On March 2, 2006, I will sign a bill that will transition New Mexico to an all paper-ballot system using optical scanners to count the vote. Paper ballots are the least expensive, most secure form of voting available. Having marked their votes with pen and paper, voters will walk out of the booth and know their voices have been heard. Optical scanners will quickly and accurately provide results, while in the event of a recount, the ballots themselves will be a permanent, verifiable record of the people’s directions to their government.
Some believe that computer touch screen machines are the future of electoral systems, but the technology simply fails to pass the test of reliability. As anyone who uses one can attest, computers break down, get viruses, lose information, and corrupt data. We know this to be the case, and so we back-up our files to ensure nothing important is lost. Paper ballots serve as the ultimate back-up for our elections, providing secure and permanent verification of the will of the people.
New Mexico has chosen paper ballots as the best system to secure our election process. With the new system in place, future elections will be secure, honest, and verifiable. Every vote will count and the citizens of our state will know that their government belongs to them.
One person, one vote is in jeopardy if we do not act boldly and immediately. American citizens once took for granted that every vote mattered, but no longer. It is time that we, the elected state officials, work to restore American’s confidence in our electoral systems and undertake reform that moves to eliminate skepticism and uncertainty.
When a vote is cast, a vote should be counted. With paper ballots we will have a record. With paper ballots the fundamental principle of one person, one vote is safe.
Tuesday, February 28, 2006
Voting system certification hearing tomorrow in Sacramento
Tomorrow the Secretary of State's office will conduct a public hearing on pending certifications of voting equipment made by three different manufacturers -- Sequoia, ES&S and Hart. The Secretary of State has posted a number of documents on the agency's Voting Systems web page relating to the hearing (scroll down to "Pending Certification" to find them). The collection includes the agenda and staff and consultant reports.
Although conditional certification of Diebold voting equipment has already been granted, it is likely that many activists will be showing up for this hearing to express their opposition to that certification decision, beginning with a 9:30 a.m. news conference outside the Secretary of State's office. Those who cannot attend the hearing but wish to comment can do so by email. The address is VotingSystemComment@ss.ca.gov.
The certification of Diebold's voting systems, along with those made by the other three manufacturers would increase the number and variety of voting equipment available for counties to purchase in order to comply with the state voter-verified paper audit trail law and the federal accessibility law. All of the touchscreen systems currently used in California must under law be replaced or retrofitted with a voter-verified paper audit trail printer as of Jan. 1 of this year.
At this stage, most counties are unlikely to be considering switching vendors, and are hoping that they will be able to augment their exisitng systems to comply with the federal and state laws. Counties using Sequoia touchscreens, for example, are counting on the state to lift the condition currently in place that prevents Sequoia's touchscreens from being used in a California Primary due to a component of the system that was not examined by federal testers. According to the Sequoia staff report, federal testing on Sequoia's touchscreens has been "successfully completed" and the state has received draft reports from the federal laboratories but is still awaiting final reports. According to the staff report, "A final report must be received from Wyle upon report acceptance from NASED (National Association of State Election Directors) and prior to State certification of this system."
Although conditional certification of Diebold voting equipment has already been granted, it is likely that many activists will be showing up for this hearing to express their opposition to that certification decision, beginning with a 9:30 a.m. news conference outside the Secretary of State's office. Those who cannot attend the hearing but wish to comment can do so by email. The address is VotingSystemComment@ss.ca.gov.
The certification of Diebold's voting systems, along with those made by the other three manufacturers would increase the number and variety of voting equipment available for counties to purchase in order to comply with the state voter-verified paper audit trail law and the federal accessibility law. All of the touchscreen systems currently used in California must under law be replaced or retrofitted with a voter-verified paper audit trail printer as of Jan. 1 of this year.
At this stage, most counties are unlikely to be considering switching vendors, and are hoping that they will be able to augment their exisitng systems to comply with the federal and state laws. Counties using Sequoia touchscreens, for example, are counting on the state to lift the condition currently in place that prevents Sequoia's touchscreens from being used in a California Primary due to a component of the system that was not examined by federal testers. According to the Sequoia staff report, federal testing on Sequoia's touchscreens has been "successfully completed" and the state has received draft reports from the federal laboratories but is still awaiting final reports. According to the staff report, "A final report must be received from Wyle upon report acceptance from NASED (National Association of State Election Directors) and prior to State certification of this system."
Thursday, February 23, 2006
New CVF web page about California's manual count law
Since I am frequently asked about California's manual count law, I figured it was time to create a new web page dedicated to this important requirement. The page features background information, the text of the law, seven steps to a meaningful manual count, and links to places where more information about manual counts and public verification of software vote counts can be found.
LA Times articles on Diebold and Voting Security
The Los Angeles Times featured two excellent articles recently about Diebold and voting security. This story by Hemmy So ran in yesterday's paper and describes the legal fallout for Stephen Heller following his release of confidential legal documents relating to Diebold's use of uncertified voting equipment. The legal memos were published by the Oakland Tribune, and ultimately Diebold settled a lawsuit resulting from their use of uncertified software. The episode raises the thorny question of whether it's a crime to commit a crime in an attempt to stop a crime -- in this case, the whistleblower, Mr. Heller, believed thousands of voters were potentially going to be disenfranchised in the next election, which ultimately was the case in San Diego.
Today's LA Times features an excellent column by business writer Michael Hiltzik questioning the recent certification of Diebold's voting equipment, especially in light of the critical security report issued by the Secretary of State's technical advisors. Excerpts from Hiltzik's column are featured below.
------------
Let's face it: When it comes to computer security, we're all slobs.
At work, we scribble our secret passwords on our desk blotters. At home, we leave our Internet connections open to be peeked through by anyone - whether the neighbor next door or a geek in pajamas halfway around the world. We forget our laptops in taxicabs, and transmit our credit card numbers to strangers over the Web.
Generally, the consequences are trivial. Most of the information let loose into cyberspace is, frankly, of no interest to anybody.
But there's no excuse for exposing the integrity of our election system to computer hackers. Yet that's what California Secretary of State Bruce McPherson may have done last week by approving electronic voting machines from Diebold Election Systems for use in California elections through the end of this year.
McPherson's approval was conditioned in part on local election officials keeping the Diebold machines under tight security before polls open. Diebold will have to make significant changes to its software and undergo further scrutiny from state and federal authorities for 2007. Given the rising panic among county registrars about having machines ready for the June primary, it's hard to avoid the impression that McPherson's decision reflected expediency more than confidence in Diebold's work.
Indeed, his ruling produced a statewide sigh of relief from county registrars, who were squeezed between a federal law requiring them to install efficient new high-tech poll machines and a state law requiring the machines to be formally certified. "This means I won't have to go to either Leavenworth or Folsom," San Diego registrar Mikel Haas told me. His county, which will stage a primary on April 11 to replace the bribe-taking Rep. Randy "Duke" Cunningham, bought 10,200 Diebold machines for $31 million in 2003, but hadn't been allowed to use them since 2004.
As the last two presidential elections demonstrate, ballot results are of profound interest to everybody - including determined hackers with partisan agendas. Therefore, it's proper to demand of the high-tech machines replacing the paper ballots and punch cards of yore that they be technologically bulletproof. The Diebold systems certified by McPherson - an optical scanner that reads hand-marked ballots and a touch screen that totes up votes directly - fall well short of that standard.
How do we know this? It's the conclusion of a panel of computer security experts McPherson commissioned specifically to study Diebold's software. Three days after they issued their report Feb. 14, McPherson gave Diebold thumbs up, noting that the panel regarded the software problems it found as "manageable" and had said the risks could be "mitigated" if election officials took care.
But the experts were plainly troubled by flaws in Diebold's systems. The panel, which included David Jefferson of Lawrence Livermore National Laboratory and David Wagner of Berkeley, observed that the removable memory cards used by Diebold were vulnerable to undetectable acts of tampering.
The panel found 16 software bugs that could cede "complete control" of the system to hackers who might then "change vote totals, modify reports, change the names of candidates, change the races being voted on," and even crash the machines, bringing an election to a halt. Hackers wouldn't need to know passwords or cryptographic keys, or have access to any other part of the system, to do their dirty work. Voters, candidates and election monitors wouldn't necessarily know they'd been rooked.
The bugs lead some computer professionals to believe that Diebold's software designers never treated security as a high priority. "It's like they were making a mechanical device, and never heard of computer security," says David Dill, an expert in electronic voting at Stanford University who wasn't on the panel.
The bugs pale next to another discovery by the panel. This is the presence of a cryptographic key written into the source code, or basic software, of every Diebold touch-screen machine in the country. The researchers called this blunder tantamount to "a bank using the same PIN code for every ATM card they issued; if this PIN code ever became known, the exposure could be tremendous."
Here's the punch line: The Diebold key became known in 2003, when it was published by researchers at Johns Hopkins and Rice universities. It can be found today via a Google search. What's worse, the key was first identified in 1997 by a University of Iowa researcher, who promptly warned the manufacturer of the flaw, apparently to no avail.
Diebold contended in 2003 that the Hopkins-Rice researchers had examined "an older version" of its code, suggesting that the flaw had been removed. But that doesn't explain why the same defect was found this year by the Berkeley panel, which wrote that it was hard-pressed "to imagine any justification" for continuing to use a cryptographic key that had been publicly compromised.
A Diebold spokesman told me that the key isn't a security issue today because election officials are instructed to override it with their own key before running the machines. McPherson's office requires county officials to perform the override as a condition to allowing them to use the machines. But many computer security experts say that's a poor solution. The human factor is an inherent flaw in any security system, and it's a mistake to rely on overstressed and overworked election officials to run through a complicated checklist, especially when the procedure would be unnecessary if the system were designed properly in the first place.
Today's LA Times features an excellent column by business writer Michael Hiltzik questioning the recent certification of Diebold's voting equipment, especially in light of the critical security report issued by the Secretary of State's technical advisors. Excerpts from Hiltzik's column are featured below.
------------
Let's face it: When it comes to computer security, we're all slobs.
At work, we scribble our secret passwords on our desk blotters. At home, we leave our Internet connections open to be peeked through by anyone - whether the neighbor next door or a geek in pajamas halfway around the world. We forget our laptops in taxicabs, and transmit our credit card numbers to strangers over the Web.
Generally, the consequences are trivial. Most of the information let loose into cyberspace is, frankly, of no interest to anybody.
But there's no excuse for exposing the integrity of our election system to computer hackers. Yet that's what California Secretary of State Bruce McPherson may have done last week by approving electronic voting machines from Diebold Election Systems for use in California elections through the end of this year.
McPherson's approval was conditioned in part on local election officials keeping the Diebold machines under tight security before polls open. Diebold will have to make significant changes to its software and undergo further scrutiny from state and federal authorities for 2007. Given the rising panic among county registrars about having machines ready for the June primary, it's hard to avoid the impression that McPherson's decision reflected expediency more than confidence in Diebold's work.
Indeed, his ruling produced a statewide sigh of relief from county registrars, who were squeezed between a federal law requiring them to install efficient new high-tech poll machines and a state law requiring the machines to be formally certified. "This means I won't have to go to either Leavenworth or Folsom," San Diego registrar Mikel Haas told me. His county, which will stage a primary on April 11 to replace the bribe-taking Rep. Randy "Duke" Cunningham, bought 10,200 Diebold machines for $31 million in 2003, but hadn't been allowed to use them since 2004.
As the last two presidential elections demonstrate, ballot results are of profound interest to everybody - including determined hackers with partisan agendas. Therefore, it's proper to demand of the high-tech machines replacing the paper ballots and punch cards of yore that they be technologically bulletproof. The Diebold systems certified by McPherson - an optical scanner that reads hand-marked ballots and a touch screen that totes up votes directly - fall well short of that standard.
How do we know this? It's the conclusion of a panel of computer security experts McPherson commissioned specifically to study Diebold's software. Three days after they issued their report Feb. 14, McPherson gave Diebold thumbs up, noting that the panel regarded the software problems it found as "manageable" and had said the risks could be "mitigated" if election officials took care.
But the experts were plainly troubled by flaws in Diebold's systems. The panel, which included David Jefferson of Lawrence Livermore National Laboratory and David Wagner of Berkeley, observed that the removable memory cards used by Diebold were vulnerable to undetectable acts of tampering.
The panel found 16 software bugs that could cede "complete control" of the system to hackers who might then "change vote totals, modify reports, change the names of candidates, change the races being voted on," and even crash the machines, bringing an election to a halt. Hackers wouldn't need to know passwords or cryptographic keys, or have access to any other part of the system, to do their dirty work. Voters, candidates and election monitors wouldn't necessarily know they'd been rooked.
The bugs lead some computer professionals to believe that Diebold's software designers never treated security as a high priority. "It's like they were making a mechanical device, and never heard of computer security," says David Dill, an expert in electronic voting at Stanford University who wasn't on the panel.
The bugs pale next to another discovery by the panel. This is the presence of a cryptographic key written into the source code, or basic software, of every Diebold touch-screen machine in the country. The researchers called this blunder tantamount to "a bank using the same PIN code for every ATM card they issued; if this PIN code ever became known, the exposure could be tremendous."
Here's the punch line: The Diebold key became known in 2003, when it was published by researchers at Johns Hopkins and Rice universities. It can be found today via a Google search. What's worse, the key was first identified in 1997 by a University of Iowa researcher, who promptly warned the manufacturer of the flaw, apparently to no avail.
Diebold contended in 2003 that the Hopkins-Rice researchers had examined "an older version" of its code, suggesting that the flaw had been removed. But that doesn't explain why the same defect was found this year by the Berkeley panel, which wrote that it was hard-pressed "to imagine any justification" for continuing to use a cryptographic key that had been publicly compromised.
A Diebold spokesman told me that the key isn't a security issue today because election officials are instructed to override it with their own key before running the machines. McPherson's office requires county officials to perform the override as a condition to allowing them to use the machines. But many computer security experts say that's a poor solution. The human factor is an inherent flaw in any security system, and it's a mistake to rely on overstressed and overworked election officials to run through a complicated checklist, especially when the procedure would be unnecessary if the system were designed properly in the first place.
Tuesday, February 21, 2006
More details on the Secretary of State's Diebold certification
Last Friday, Secretary of State Bruce McPherson announced he has certified several pieces of Diebold equipment, includng the TSX touchscreen voting machine with a voter-verified paper audit trail printer attachment. The certification came with a number of conditions, which are more fully discussed in this report issued by members of the Secretary of State's Voting Systems Technology Assessment Advisory Board (VSTAAB). The Secretary of State has also made public this letter to Diebold, and the certification document, which outlines the conditions under which the equipment may be used in California.
The certification is controversial because it has come after a security flaw was identified by Harri Hursti, who demonstrated how Diebold's code could be exploited to alter vote totals without leaving any trace of the attack. The VSTAAB members discussed this in their report, which concluded that these known security risks could be addressed through tighter procedures, which are reflected in the certification conditions.
Coverage of the certification was featured in this article by Kevin Yamamura in Saturday's Sacramento Bee and this Oakland Tribune article by Ian Hoffman, excerpts from which are featured below.
---------
After almost three years, Diebold Election Systems won approval Friday to sell its latest voting machines in California, despite findings by computer scientists that the software inside is probably illegal and has security holes found in earlier Diebold products.
The scientists advised Secretary of State Bruce McPherson last week that those risks were "manageable" and could be "mitigated" by tightening security around Diebold's voting machines.
McPherson gave conditional approval to Diebold's latest touch-screen voting machines and optical scanners Friday, while his staff ordered the McKinney, Texas-based company to get rid of the security holes as quickly as possible.
In a statement, McPherson said, "after rigorous scrutiny, I have determined that these Diebold systems can be used for the 2006 elections."
The decision is likely to set off a buying spree for as many as 21 counties, more than a third of the state, as local elections officials rush to acquire one ofonly two voting systems approved for use in the 2006 elections. Registrars and clerks prefer having voting systems for at least six months before conducting a statewide primary like the one in June, partly because it is California's most complicated and error-prone type of election.
---
McPherson's approval comes just in time for San Diego County, which bought the new machines in 2003, used them once in 2004, then saw the state's approval withdrawn. The county has been warehousing 10,000 Diebold AccuVote TSx touch-screens for more than two years and withholding its $35 million payment to Diebold until approval. Now, with an election set for early April to replace Rep. Duke Cunningham, San Diego can use those machines. In June, so could San Joaquin County, which also bought and has been storing the new touchscreens trusting on approval.
---
Sen. Debra Bowen, who chairs the Senate elections committee and is running for the Democratic nomination to challenge McPherson as secretary of state, criticized the approval as contrary to state and federal law.
Part of the software running in Diebold's touch-screens and optical scanners is what computer scientists call "interpreted code" that is loaded by memory cards or PC cards just before an election. That changes the software that private testing labs and states had tested and approved, and for that reason interpreted code is prohibited by federal 2002 voting system standards.
McPherson found that private laboratories charged with testing Diebold's machines for compliance with the federal standards never examined the interpreted code and ordered Diebold back into lab testing. At the same time, he asked a team of scientific advisers from Lawrence Livermore National Laboratory, the University of California, Berkeley and UC Davis, to study the interpreted code and report back. The panel included computer scientists who have been skeptical, even critical of electronic voting systems, such as David Jefferson, Matt Bishop and David Wagner.
The scientists recommended counties change the encryption keys on all Diebold touch-screens and maintain tighter controls over the memory cards and PC cards, for example by requiring two people be present whenever the cards are moved or their contents changed. Serial numbers for the cards and the tamper-proof seals to lock them into the voting machines will have to be logged by elections officials at each polling place.
McPherson adopted those recommendations in certifying the Diebold machines for the June and November statewide elections. His staff wrote Diebold Friday urging the company to fix the bugs in its software and eventually to get rid of the interpreted code entirely.
The certification is controversial because it has come after a security flaw was identified by Harri Hursti, who demonstrated how Diebold's code could be exploited to alter vote totals without leaving any trace of the attack. The VSTAAB members discussed this in their report, which concluded that these known security risks could be addressed through tighter procedures, which are reflected in the certification conditions.
Coverage of the certification was featured in this article by Kevin Yamamura in Saturday's Sacramento Bee and this Oakland Tribune article by Ian Hoffman, excerpts from which are featured below.
---------
After almost three years, Diebold Election Systems won approval Friday to sell its latest voting machines in California, despite findings by computer scientists that the software inside is probably illegal and has security holes found in earlier Diebold products.
The scientists advised Secretary of State Bruce McPherson last week that those risks were "manageable" and could be "mitigated" by tightening security around Diebold's voting machines.
McPherson gave conditional approval to Diebold's latest touch-screen voting machines and optical scanners Friday, while his staff ordered the McKinney, Texas-based company to get rid of the security holes as quickly as possible.
In a statement, McPherson said, "after rigorous scrutiny, I have determined that these Diebold systems can be used for the 2006 elections."
The decision is likely to set off a buying spree for as many as 21 counties, more than a third of the state, as local elections officials rush to acquire one ofonly two voting systems approved for use in the 2006 elections. Registrars and clerks prefer having voting systems for at least six months before conducting a statewide primary like the one in June, partly because it is California's most complicated and error-prone type of election.
---
McPherson's approval comes just in time for San Diego County, which bought the new machines in 2003, used them once in 2004, then saw the state's approval withdrawn. The county has been warehousing 10,000 Diebold AccuVote TSx touch-screens for more than two years and withholding its $35 million payment to Diebold until approval. Now, with an election set for early April to replace Rep. Duke Cunningham, San Diego can use those machines. In June, so could San Joaquin County, which also bought and has been storing the new touchscreens trusting on approval.
---
Sen. Debra Bowen, who chairs the Senate elections committee and is running for the Democratic nomination to challenge McPherson as secretary of state, criticized the approval as contrary to state and federal law.
Part of the software running in Diebold's touch-screens and optical scanners is what computer scientists call "interpreted code" that is loaded by memory cards or PC cards just before an election. That changes the software that private testing labs and states had tested and approved, and for that reason interpreted code is prohibited by federal 2002 voting system standards.
McPherson found that private laboratories charged with testing Diebold's machines for compliance with the federal standards never examined the interpreted code and ordered Diebold back into lab testing. At the same time, he asked a team of scientific advisers from Lawrence Livermore National Laboratory, the University of California, Berkeley and UC Davis, to study the interpreted code and report back. The panel included computer scientists who have been skeptical, even critical of electronic voting systems, such as David Jefferson, Matt Bishop and David Wagner.
The scientists recommended counties change the encryption keys on all Diebold touch-screens and maintain tighter controls over the memory cards and PC cards, for example by requiring two people be present whenever the cards are moved or their contents changed. Serial numbers for the cards and the tamper-proof seals to lock them into the voting machines will have to be logged by elections officials at each polling place.
McPherson adopted those recommendations in certifying the Diebold machines for the June and November statewide elections. His staff wrote Diebold Friday urging the company to fix the bugs in its software and eventually to get rid of the interpreted code entirely.
Subscribe to:
Posts (Atom)
