An Internet Voting System Fatally Flawed in Creative New Ways

Andrew W. Appel,Philip B. Stark
2024-11-19
Abstract:The recently published "MERGE" protocol is designed to be used in the prototype CAC-vote system. The voting kiosk and protocol transmit votes over the internet and then transmit voter-verifiable paper ballots through the mail. In the MERGE protocol, the votes transmitted over the internet are used to tabulate the results and determine the winners, but audits and recounts use the paper ballots that arrive in time. The enunciated motivation for the protocol is to allow (electronic) votes from overseas military voters to be included in preliminary results before a (paper) ballot is received from the voter. MERGE contains interesting ideas that are not inherently unsound; but to make the system trustworthy--to apply the MERGE protocol--would require major changes to the laws, practices, and technical and logistical abilities of U.S. election jurisdictions. The gap between theory and practice is large and unbridgeable for the foreseeable future. Promoters of this research project at DARPA, the agency that sponsored the research, should acknowledge that MERGE is internet voting (election results rely on votes transmitted over the internet except in the event of a full hand count) and refrain from claiming that it could be a component of trustworthy elections without sweeping changes to election law and election administration throughout the U.S.
Cryptography and Security,Computers and Society
What problem does this paper attempt to address?
The main problems that this paper attempts to solve are related to the security and feasibility of a new Internet voting system (CAC - Vote and its MERGE protocol). Specifically: 1. **Voting problems of overseas military voters**: How can overseas military voters submit their ballots before election day? In particular, in cases where they are unable to send paper ballots by mail in a timely manner, can they submit electronic ballots via the Internet to speed up the vote - counting process? 2. **Security issues of electronic voting**: Although the CAC - Vote system has designed a complex encryption protocol (MERGE) to ensure the security of electronic voting and verification is carried out through subsequently mailed paper ballots, the paper points out that there are serious problems with the security and reliability of this system, especially in cases where computers may be hacked. 3. **Mismatch between law and practice**: There is a huge gap between the MERGE protocol and the existing election laws and practices in various states in the United States, which makes it difficult to apply this protocol in practice. For example, many states have not implemented risk - limiting audits (RLA), which is one of the key steps to ensure the effectiveness of the MERGE protocol. 4. **Challenges in technical implementation**: The paper also discusses the difficulties in implementing the CAC - Vote system at the technical level, including how to ensure the security of communication between voting booths and local election offices, and how to handle various possible technical failures. In summary, this paper mainly explores the theoretical innovation of the CAC - Vote system and its MERGE protocol and the infeasibility in practical applications, emphasizing the major security and technical challenges faced by Internet voting.