Disclaimer: I served as an election judge in the 2012 general election in Arapahoe County, CO.
I'm so sick and tired of stories like this framing the issue of election security as a software issue or hardware issue. You can mitigate software flaws with chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency. Most election systems in the United States employ all of these controls, which is why you have few stories of legitimate votes being discarded due to software failure or tampering.
If your argument is that paper ballots are more auditable or harder to hack, they are not. The same access controls above can be applied to paper, and paper is always susceptible to being destroyed, lost, or conveniently found in a clutch race. In Russia, cameras were provided at many election booths in a recent race and caught multiple instances of suspected ballot stuffing [0]. Paper products can be created at will and the requirement for ballots to be anonymous often prevents measures to prevent double voting or outright forging of votes.
Hackable machines are a problem, but they are not the only problem. Ultimately, it's easier to influence an election by discarding legitimate voters from voter registration systems, selectively failing to notify voters of elections, and other indirect interference campaigns that have been known to happen. Not only are hackable machines not the biggest issue, but they turn the camera away from bigger issues like these, which decreases scrutiny on the most vulnerable parts of the system.
Ultimately, if you vote in an election system, you must have something you trust in the system. You need to be able to trust the body running the election, the individuals that makeup the body, or the system elements itself. If you trust the government then you can be certain that collection processes happen correctly. If you can't trust the government, why do you think trusting the terminals that collect votes is any better? It's like trusting your child to bring home important documents from the school about their discipline. Sure, the paper might be tamper proof or tamper evident, but if your child throws it away it's pointless [note 1].
[note 1] The analogy breaks down if you talk about electronic records, and assumes that the child is the "higher authority" bringing the documents to you. The point is to demonstrate that tampering with reporting is much easier than tampering with the record collection.
> I'm so sick and tired of stories like this framing the issue of election security as a software issue or hardware issue.
Election security is certainly more than software or hardware. But I'm sick and tired of jurisdictions that permit paperless votes, because by definition they are insecure.
> You can mitigate software flaws with chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency.
Not true; none of these mitigations work. If the software is malicious, it can receive one input and produce a different result. Reviews of source code and even machine code are not enough, because you don't get adequate confidence that what was reviewed is what was run. "Tamper proof" seals don't help, because the malicious code could have been what's installed in the first place, and hardware can easily report "what you expect to see" while running something else in practice on election day. In most cases the source code isn't even available for public review & scrutiny, so there's no possibility of enough transparency even if you could somehow be assured of what code was run.
When I was a kid I liked to do magic tricks. I bought cheap plastic devices that looked like they did one thing, but in actuality did something else. Modern DRE systems are just a magic trick device - they'll do something, but not necessarily what you think they do.
> Most election systems in the United States employ all of these controls, which is why you have few stories of legitimate votes being discarded due to software failure or tampering.
You hear few stories because there is no effective logging, and therefore no way to report failure or tampering.
> If your argument is that paper ballots are more auditable or harder to hack, they are not. The same access controls above can be applied to paper, and paper is always susceptible to being destroyed, lost, or conveniently found in a clutch race.
Paper ballots are subvertible, but because they are physical items someone has to physically be there to do the manipulation. There's also a long history with paper ballots, so the ways they can be subverted are known - as are their countermeasures.
> Hackable machines are a problem, but they are not the only problem. ...
It's true that these machines are not the only problem, but voting systems are systems. For voting systems to be legitimate we must address all parts. Direct Recording Equipment (DREs) subvert the entire voting system, and thus should never be allowed to be part of one.
I take "secure voting" to mean a process where every participant can later individually audit that their vote was counted without betraying the confidentiality of any other voter.
For that, what would you think about a system where the election board published all the votes after the fact without any names, but placing each vote alongside a secret, a key, shared with that voter?
So, as a voter, I could perform a few operations on this published list of results. (1) I could search for my row indicated by my shared secret key to confirm my vote was recorded correctly. (2) I could add all the votes to confirm election officials added all recorded votes. (3) I could confirm that the number of rows is equal to the turnout reported on the day, possibly by district, so no ballot boxes could suddenly be lost or added after the fact.
> If the software is malicious, it can receive one input and produce a different result.
Sure, but all of cryptography is about solving for bad middlemen. The trick to secure multiparty computation is forcing the system to show enough of its work to verify, like above. Just publish the votes with the individual voters strongly masked.
Part of me worries that any voting system without public key cryptography is insecure, but our standards are so low we're just settling for paper, assuming that's the best we can do.
But I'm not sure what attacks paper advocates are trying to prevent, so I'm probably missing something. If I think my local election officials threw out my vote, how do I use my receipt to detect that from home?
But I agree with you if your main points are:
1) Current electronic implementations are terrible.
2) Paper never hurts.
N.b. - Vote selling could be an issue with either paper receipts or my protocol above. The best solution for either is probably outside the system (criminal penalties and significant whistle-blower rewards). You might be able to add deniability to the toy protocol above, but things would get complicated.
My point is not that paper never hurts. My point is that paper is the absolute minimum. The security requirements of a voting system are radically different than most systems.
A good summary of the problems and how to solve them is here:
My absolutely minimum is that every citizen should be able to confirm how their vote was recorded after the fact.
If we can't do that, then no system can guarantee us anything. If we can do that, then the system doesn't matter.
I'm familiar with VV. I completely agree with their position that post-election audits are critical to ensuring trust in the system. (That's a weaker version of my own requirement above.)
However, their latest policy recommendation was that we must keep hand-marked ballots, which is just bizarre to me. That's the sort of policy you endorse if you want elections to be decided by teams of lawyers debating stray marks and creative misspellings to deduce voter intent. It's a good way to let money break ties in elections, and makes me question VV's impartiality or judgment on these issues.
They have repeatedly linked to outside teams of researchers covering end-to-end verifiable systems though. A thorough read of the research notes that while there are a number of challenges to overcome, end-to-end verifiable could provide a path to secure elections.
> Vote selling could be an issue with either paper receipts or my protocol above. The best solution for either is probably outside the system (criminal penalties and significant whistle-blower rewards). You might be able to add deniability to the toy protocol above, but things would get complicated.
Extortion and bribery work against individuals some of the time, but using it against large groups of people hoping not even one of them will alert reporters or police?
Not to mention, this is a flaw in the current voting system, because people can easily sneak phones into booths to take video of their votes.
Being able to confirm that your specific vote was counted should be considered a basic human right. If you look at it that way, it feels strange to deny people a basic right to protect against some harm we don't currently address now, but could easily address in other ways.
> Being able to confirm that your specific vote was counted should be considered a basic human right.
No, not if that means that many people cannot safely vote. At one time it was considered a right in many jurisdictions that everyone could know what everyone else's vote was, and votes were public. This enabled the local landlords to ensure that bad things happened to people who didn't vote the "right" way. Many vote-confirmation systems allow others to verify the vote as well, and the historical record makes it clear that this can be very dangerous.
Currently we can't even verify that votes are counted correctly at all. We currently allow people to press buttons and then have an unverifiable machine report what its owners want the vote to be, without any reasonable way to verify it.
It's great to want much more, but let's start with the basics. Having a way to verify that the counted vote is the actual vote is that basic.
Paper ballots have a much more visible chain of custody than paperless ballots. In my county, from the time voting starts to the time votes are counted, ballots must either be in a locked closet with tamper-evident seals (for example, at night during early voting) or simultaneously in view of both Democratic and Republican election judges.
It might still be possible to interfere with those, but it's much more difficult than electronic voting machines, which can in some cases be manipulated over the internet, or very quickly by a voter who exchanges memory storage units.
I think this is the OPs point though. You are trusting someone to make sure the ballots are in a locked closet. You aren't personally there to see it, and I personally have never been on scene to witness vote counting by a bipartisan coalition of judges. For all I know, the ballots are taken in a back room, burned, and then the election officials throw darts at a board to determine who wins. There are no publicly available recordings of the count. I'm trusting quite a few people who say they were witness that the count was legitimate. But in my experience buying off the word of even dozens of people is fairly cheap for what you get manipulating an election.
And more generally, if you are already trusting said election commission to do the counting by being in a partisan staredown the same principle would apply to said commissions scrutiny over voting machines. If the parties are balanced enough in power to insure no one is stuffing the ballot behind anyone elses back they can probably mutually conclude if an electronic voting machine is safe to use for the both of them.
Its worth mentioning and considering that, even in those coalition election commissions, both parties are incentivized to discredit third parties any way they can. They share a duopoly of power that they are both in their own self interest to protect, and I do not hear often about third party oversight of election commissions. Why do you trust them on that front, then, when their incentives are entirely aligned against being truthful?
Where I come from, we use paper ballots and votes are counted multiple times by different people both on election day and after. And yes, the public is invited to monitor vote counting.
> You are trusting someone to make sure the ballots are in a locked closet
Where I'm from, the paper ballots are in a transparent box, you can stay there forever / be the one who does the counting of the ballots, and you need two locks that are given to the two frontrunners parties.
The number of people who can actually comprehend the operation of a computerized voting system, let alone inspect it (not possible without an electron microscope basically) is incredibly small.
Yet the possible impact of subverting it once is incredibly large. Paper ballots are not unhackable, but they do require a conspiracy. People have to turn up and take physical actions which can be comprehended by most of the general public.
But there are countless stories of paper ballots being miraculously found that sway the vote in a close race or ones that are found in a dumpster after a vote count has just taken place.
If the chain of custody is correct, it should be readily traceable which precincts were the sources of "ballots found in a dumpster".
And besides, "countless stories" are just stories. Show me one that's been investigated by responsible, neutral journalists. Just because everyone knows it's true doesn't mean it's actually true.
Tampering with voting machines software is easier, less noticeable and doesn't even require a cooperation from staff at the polling station (which ballot stuffing requires). You just need cooperation from the manufacturer.
> Hackable machines are a problem, but they are not the only problem.
They might not be the biggest problem, but they're definitely an _extra_ problem. I don't see what problems they take away, in exchange for bringing this extra problem.
With a paper ballot, I can go to the polling booth, see my vote being counted, and see whether any other funky stuff happens, right there. It's all in the open. This in turn gives you extra trust in the system.
With an electronic system, how do I know what happens behind those layers of abstraction between the user interface and the hardware? How can I in any way verify that my vote has been counted?
In VA (or, at least in Fairfax County), we fill in a paper ballot which is scanned by a machine. The vote counting is done by the scanners/electronically, but there is a paper trail for audits. Seems like the best of both worlds (when implemented properly).
Like you, I would have zero faith in an electronic voting booth that simply said "Yup, you pushed a button." I have no idea what actually gets "written to disk".
The reverse also seems fine to me; fill it out in a machine, that shows you the paper ballot it's printing. (Presumably the latter is what gets recounted)
That is basically useless though. Have it print upfront with a certain amount per district, then hand-fill them out.
There is no difference between making a cross and pushing a button, except that the cross is unique. (There's a case where a guy made a huge anarchy sign on the ballot paper and it was a valid vote because two lines met for a candidate. This is also a thing btw. people should be free to vote as they like. They should be allowed to write in someone else, write "fuck", or draw a huge dick, whatever. Invalid votes are an important part of the electoral process as they signal decidedly uncontent voters.)
I mean especially considering the US, it is beyond ridiculous that this is even a discussion. You guys spend upwards of 2 billion dollars on presidential elections anyway, and then get up in big discussions over a few million dollars on election security.
Whether or not he lives in the US, he is right to express some level of interest in our government (and how it is elected). We're the worlds largest economy (or close to it), the world's largest democracy, and generally what happens here has a massive impact on the rest of the world.
And in this case, he's right. We spend an absurd amount of money on political campaigning, but then get lost in the weeds, and/or hand-wavey, when somebody wants to discuss election security. There are legitimate criticisms of how we process elections.
Is cable TV programming political campaigning? How about youtube videos funded by the Kochs or Soros?
"Election security," as in mandate, at the federal level, what the states do? Centralizing power (maximizing the possibility of a single point of failures) makes elections more vulnerable. Voting machines are air-gaped. Our elections were influenced by propaganda on social media, just like the Arab Spring.
Evaluating actual 'cause and effect' is helpful when trying to understand situations.
Is cable TV programming political campaigning? How about youtube videos funded by the Kochs or Soros?
No, that's not campaigning, at least not officially. But, adding those into the mix makes the money spent even more ludicrous.
As for federal mandates, I'm not sure I agree. Right now, states have nearly complete control of the election system, with vastly varying levels of competence. I'm not sure I'd want the federal government mandating which specific machine to use, but I'd love some consistency across states. And also some mandates around vote-by-mail and similar systems.
Air-gapping voting machines only does so much good when nobody outside Diebold knows what the machine does on the inside.
With scanning machines there still is a problem that they can be tampered with and even if you see that the outcome doesn't match exit polls, you don't have any solid proofs to require the manual re-counting of paper ballots.
In most states, if the election is within a certain degree of closeness (like half a percent), it triggers an automatic recount. And that will catch mismatches between the machine counts and the contents of their ballot boxes, unless you also carefully rig the manual recount - at scale.
And altering the count more than a percent or so is a LOT of alteration.
Sibling comment is correct - most states will auto-recount within a certain margin. If somebody hacks a difference larger than that, we have a larger problem (ie, not just a machine or two hacked, but the entire system has fallen apart).
And that also brings us back to an earlier comment about driving turnout (or lack thereof) is possibly a larger problem than tampering at the polls. If a party (or somebody acting on behalf of a party) can convince a significant block of voters to stay home, that's more likely to have an impact.
> With a paper ballot, I can go to the polling booth, see my vote being counted, and see whether any other funky stuff happens, right there. It's all in the open. This in turn gives you extra trust in the system.
> With an electronic system, how do I know what happens behind those layers of abstraction between the user interface and the hardware? How can I in any way verify that my vote has been counted?
The best I've seen is a verifiable electronic system with a paper trail. After a voter records their vote electronically, they're shown a "receipt" of their vote to verify it, and the "receipt" is stored securely and anonymously after the user verifies the vote. If the receipt doesn't match their inputs, a red flag can be raised immediately. After the election, the paper records can be used to run a stop-loss audit to verify the electronic vote count. The redundancy has an added benefit -- you're increasing the surface area of the attack itself, and by adding a physical element, you can capture bad actors on camera.
> the paper records can be used to run a stop-loss audit to verify the electronic vote count
You can't do this. Probably the most fundamental problem with electronic vote verification is that you cannot give someone physical evidence of how their vote was cast, because it makes voter coercion feasible.
Its why almost all absentee / write in ballots are set up so that if you send multiple ballots only the last one is counted (or an in person vote if you give one). If someone tries to coerce your vote and use the absentee ballot as proof unless they keep you imprisoned until the election is over they can't prove you didn't resubmit / go in person to change your vote.
With receipts for in person ballots the only way to defeat coercion is to make it so you can, at the point of receipt, get issued an intentionally flawed receipt. But if you are verifying votes this way, it would have to be for another legitimate voter voting the exact way your coercer wanted. That sounds like a hugely limiting technical flaw.
> You can't do this. Probably the most fundamental problem with electronic vote verification is that you cannot give someone physical evidence of how their vote was cast, because it makes voter coercion feasible.
There are machines that print paper receipts to voters (presented under glass so voters can verify), and then drop the receipts into a traditional lockable ballot box. The voter cannot access the paper ballot without evidently tampering with the machine; the only issue is that you'd need a way to get poll workers the ballot at issue without identifying the voter.
> you cannot give someone physical evidence of how their vote was cast, because it makes voter coercion feasible
Some countries try to solve this with an extended voting period and by making votes repudiable / changeable up until the end of the election.
Another solution is generous whistleblower rewards and significant criminal penalties.
There are tools outside the ballot box to prevent crime, and extortion is a crime regardless of whether there's an election going on or not.
(If you bake deniability into your system, you lose the ability to let voters prove to others that their vote was miscounted, so receipts lose a key feature at that point.)
>With a paper ballot, I can go to the polling booth, see my vote being counted, and see whether any other funky stuff happens, right there. It's all in the open. This in turn gives you extra trust in the system.
What do you mean you see it counted? I don't think I've ever voted with a paper ballot.
They are the biggest problem in terms of foreign interference. I don't think a Russian national can hang out in rural Organ and mess with paper ballots without being noticed.
The point is that you don't want to have to trust individuals or small groups of people. There are ways of manipulating a paper election, but that's why you have judges and election observers. If the count is done in a decentralized way, and the precinct results posted, you have to physically compromise the vote in many precincts. Doing this on a large scale runs a high probability of someone noticing.
With these zero paper systems, there is no observability. Even if everything is sealed, you don't know what the software inside is doing. You probably don't even know what software the device is running, because the machines are stored in some warehouse for months at a time, with who knows who having access to them.
If someone replaced the firmware, so selecting one candidate had a 10% chance of being counted as a vote for another, how could this be detected with "chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency"?
> Ultimately, it's easier to influence an election by discarding legitimate voters from voter registration systems, selectively failing to notify voters of elections, and other indirect interference campaigns that have been known to happen.
Well, duh, this isn't happening in real democracies. Americans really need to get rid of their delusions regarding the form of governance they live in.
The problem with voting machines is that it makes it so much easier for a single entity to control the election. And that the people organizing the election are completely technologically illiterate as well as the huge majority of the electoral. If you can hide behind techno mumbo jumbo and plausible deniability it gets ever easier to manipulate the electorate in failing to see a problem.
They used admin as a password in voting machiens in the US, and the same company still holds contracts. The whole notion is beyond laughable.
You seem to be discounting the seriousness of this issue. If it weren't for Snowden, we would all blindly be thinking there _may_ be mass surveillance, but instead we _know_ there is and it's way worse than we imagined.
With ballot stuffing and voter manipulation you maybe able to _possibly_ affect votes, but with hacking, you can practically just pick the outcome you want and be done.
We shouldn't be so easily duped anymore, we've seen to much come to light to pretend this isn't completely real, and most likely much, much worse than we know.
You have mentioned electoral fraud in Russia. With paper voting and cameras, we can at least know that the fraud has happened and estimate its scale. With electronic voting, we wouldn't be able even to check anything.
In major cities like Moscow or Saint-Petersburg, there are many activists that work as observers and just their presense helps to prevent fraud. With electronic voting, they wouldn't be able to do anything, except for verifying that reported turnout matches the number of people who visited the polling station.
I think that main threat for elections is the government and election staff. They have uncontrolled access to voting machines and can tamper with them. Maybe in Western countries it is impossible, who knows, but in my country paper voting is more transparent and auditable than electronic voting.
So why not paper AND everything else you talk about above? I just don't understand why people are arguing against any paper trail at all. Is there some NEGATIVE reason why having paper backup is more harmful to have in addition to everything else you listed above than not having any at all?
Assuming you're using proper paper chain of custody, seals, etc on your paper ballots, then how do you propose that ballots would be "destroyed, lost, or conveniently found"? These things are all extremely easy to audit.
Humans have been doing paper document chains of custody since the ancient Chinese and the Romans. It's not rocket surgery.
Ok, so here are my assumptions for a good chain of custody...
Ballots, whether sealed or unsealed, blank or marked, must have at least two people present (from different parties) for all handling. At the end of the process, it should be possible to account for every ballot, marked or blank, and know who handled it (except for the individual voter), from the moment it was received from the printer to the moment it is eventually destroyed. Counts should match at every level, from the printer to the distribution to the voters to the number of ballots in each locked box. Every box can also be traced to an individual machine.
Assuming this is done, where do you fit fraud in? I see three paths for fraud - adding ballots, removing ballots, and substituting/altering ballots. How do you add or remove ballots without upsetting the counts? How do you substitute/alter ballots without breaking seals? And mind you, the techniques have to be able to a: survive a recount, and b: work at a sufficient scale to meaningfully alter the election results.
The way to break this isn't the weakness of paper security. It's to undermine the chain of custody itself, do have the kinds of sloppy processes endemic to Florida, Ohio, etc.
It's also true that errors (aka fraud) happens with the machines.
Just one example: Voter Action proved in court that New Mexico's touchscreens didn't count Spanish language ballots in 2004. Kerry would have won the state.
Paper ballots cast at poll sites tabulated when the polls close is the best available system. Our gold standard (per the Election Verification Network, which is everyone).
By comparison, any digital tabulation system is irredeemable.
" you must have something you trust in the system."
No. You don't.
Our very form of government's balance of power is built on mutual distrust.
The only system I "trust" is when all the belligerents mutually certify the results.
...we have paper ballots in CO. Yes there are potential problems with paper ballots, particularly when you don't allow the public to view the entire process, but non paper systems are much worse.
Software-only machines are qualitatively different than machines with paper trails, since they can be tampered with en masse by a small number of adversaries without needing physical access at voting time; and because such tampering may not leave any trace whatsoever.
There is something to be said for forcing an actual person to be physically present, using procedures visibly different from the normal voting procedure, in order to commit vote fraud. But you're right.
I emphatically do not trust the voting system used locally, but what is my alternative, really? It's not like the people for whom I am voting actually have a snowball's chance in Gehenna in this blood-red state with gerrymandered districts and independent-annihilating ballot-access laws.
Hackable, unauditable machines are just another load of fuel on the fire, when I feel as though I have never been faithfully represented by any elected official. The game is so thoroughly rigged before the voting happens that it hardly even matters how we cast the ballots.
With your Russian example there is a paper trail. There is a timestamp when that occured and if the machines that receive the ballots timestamp the receipt of the ballot and the location with scanner #, it's pretty easy to pinpoint the infringements.
As for throwing away ballots, again, in the USA there should be video evidence of such possibilities.
I was helping out in Denver for one of the elections, might've actually been 2012 or 2016. They had cameras everywhere and they should.
Paper > paperless. Seriously, there are reports/studies about this. It's common sense. You don't contrast how paper is better than paperless. Are both flawed? Yes but one is a dumpster fire of issues where the other can be fully audited and accounted for.
Thank you for sharing this perspective! I think it's valuable. Few questions:
1) "... and other indirect interference campaigns that have been known to happen" Curious if you have links for these? The more I've learned about our election systems, the more I've suspected these to be highly vulnerable, but I hadn't been aware of known interference.
2) I believe Colorado has, generally, strong election practices. Given that "chain of custody" occurs at the county level across the US, and that a single county can sway an entire national election, could we not suspect that a single bad actor (or small group of bad actors) could intentionally modify the polling record? And that this is much harder to prevent & detect with purely electronic ballots?
3) Does chain of custody prevent attackers from altering the records of a voting machine in a voting booth? eg; accessing USB, other ports, or wireless connection?
> chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency
Does closed source software allow for any of that?
- The chain of hardware custody is difficult: did any components come from China? The chain of software custody is similarly difficult: are the dependencies disclosed at all? Who wrote all the components it uses? At least paper won't surprise you
- Poll watching and judging still involves a handoff to a black box. The poll watcher and judge cannot confirm or deny that the software or hardware performed as expected.
- There is no transparency with closed source software, period. It could be doing <X> and we wouldn't even know it - until it was disclosed, sort of, in an impossible to understand TOS document that was just updated. This is the entire story of the scandals facing tech for the last 10 years or more.
Even open source doesn't guarantee this unless you can verify that every machine is running the code you think it is and was doing so during the whole election.
There's no feasible way for a voter to verify that a machine they're voting isn't compromised without giving people ludicrous levels of access to the machines. (Way more than just a USB port) Never mind the fact that almost no-one has the ability to do this verification anyways.
I see it constantly here on HN when there's a story about privacy and there's countless comments suggesting how you as an individual can do some jury rigged thing to protect your privacy.
Politics, policy, and law never enter their brains.
I'm so sick and tired of stories like this framing the issue of election security as a software issue or hardware issue. You can mitigate software flaws with chains of custody, tamper proof seals, bipartisan poll watchers, bipartisan election judges, and enough transparency. Most election systems in the United States employ all of these controls, which is why you have few stories of legitimate votes being discarded due to software failure or tampering.
If your argument is that paper ballots are more auditable or harder to hack, they are not. The same access controls above can be applied to paper, and paper is always susceptible to being destroyed, lost, or conveniently found in a clutch race. In Russia, cameras were provided at many election booths in a recent race and caught multiple instances of suspected ballot stuffing [0]. Paper products can be created at will and the requirement for ballots to be anonymous often prevents measures to prevent double voting or outright forging of votes.
Hackable machines are a problem, but they are not the only problem. Ultimately, it's easier to influence an election by discarding legitimate voters from voter registration systems, selectively failing to notify voters of elections, and other indirect interference campaigns that have been known to happen. Not only are hackable machines not the biggest issue, but they turn the camera away from bigger issues like these, which decreases scrutiny on the most vulnerable parts of the system.
Ultimately, if you vote in an election system, you must have something you trust in the system. You need to be able to trust the body running the election, the individuals that makeup the body, or the system elements itself. If you trust the government then you can be certain that collection processes happen correctly. If you can't trust the government, why do you think trusting the terminals that collect votes is any better? It's like trusting your child to bring home important documents from the school about their discipline. Sure, the paper might be tamper proof or tamper evident, but if your child throws it away it's pointless [note 1].
[0]: https://www.youtube.com/watch?v=pH7uXZQsyHI
[note 1] The analogy breaks down if you talk about electronic records, and assumes that the child is the "higher authority" bringing the documents to you. The point is to demonstrate that tampering with reporting is much easier than tampering with the record collection.