Showing posts with label 2024 General Elections. Show all posts
Showing posts with label 2024 General Elections. Show all posts

Wednesday, June 19, 2024

Results of General Election 2024 - the gaming of EVMs – saving future elections



General Elections 2024 (GE 2024) results were expected to produce highly divergent results depending upon who you chose to back or believe - these targeted tallies were 400+ by the ruling side versus ~300 by the opposition side. Therefore, if at all any side were to achieve their predicted tally, the other side was expected to cry foul and immediately try to seek redress through the available legal recourse – either file for Electronic Voting Machine (EVM) audit, within seven days, or else file petitions in the Supreme Court of India (SCI) or a lower Court within 45 days. According to a press report, only 10 losing contestants have demanded EVM audit, including one from Bhartiya Janta Party (BJP).

There is enough circumstantial evidence that points to a con game the BJP team led by PM Modi and HM Amit Shah pulled off and, made suckers out of Opposition. The Opposition parties could have changed their fate had they joined the petitions civil rights groups and NGOs had filed against EVM - read what M.G. Devasahayam says about the stolen mandate. It is likely, the Opposition parties will suffer the same fate of losing elections in future if they fail to force Election Commission of India (ECI), through a review petition in the Supreme Court of India (SCI), to change the process of using EVMs. 

Narrative ("400 par") - was part of a con game - cover fire for EVM hacking

The ruling BJP, led by Modi, had run an “intimidating” narrative that it would by itself win 370 out of 543 seats and together with its partners, in the National Democratic Alliance (NDA), their tally would be 400+ seats (“abki bar 400 par” : 3 min clip). Indian National Congress (INC) with mass contact yatras, led by Rahul Gandhi,  across the country - south to north and east to west, had picked up a far more accurate pulse of the voters, their leaders declared INC would win 100+ seats and together with its alliance partners in the Indian National Developmental Inclusive Alliance (INDIA) bloc, they would easily cross the majority tally of 272 seats and end Modi’s rule. Rahul Gandhi proclaimed that he would write down that Narendra Modi will not return as the PM: clip of 30 secs

The results announced on 4th June were a stunning blow to BJP (it lost 63 seats compared to its 2019 tally) and they were just a little shy of a home run for INC (it doubled its seats compared to 2019 tally despite contesting far fewer seats). BJP/NDA tally was 240/292 seats. INC/INDIA tally was 99/234. The independents and unaffiliated parties won 17 seats to make up the total of 543 seats of Lok Sabha. Both sides claimed victory, though BJP fell far short of its target. So, no losing contestant charged the winner of fraud. INDIA bloc members, particularly INC, ought to have risen in protests and charged BJP for engineering results quite contrary to its own estimates; BJP's tally was  significantly higher than sub-200 tally many independent observers and opposition party members had predicted. INDIA being 38 short of the majority tally, had missed its most important goal of dislodging BJP from power. INDIA bloc parties did not immediately accuse BJP of hacking because being 130 seats short of its target of 370, BJP seemingly had a sufficient alibi - had BJP hacked the EVM System, why would they be so short of their target? 
The expectations of INDIA bloc were cleverly tamped down through atmospherics that Modi and team created otherwise they would have likely charged the ruling side of the fraud of carrying out a fiddle with the EVM or of a conspiracy with ECI in ballot stuffing (one example: stonewalling sharing of Form 17C with public).  

Ploys of distraction and misdirection

Many believe PM, Modi & Home Minister, Amit Shah (also known as Modi-Shah duo) are masters of electoral strategies and aces in the art of distraction and misdirection. Most ground reports filed by independent journalists and observers predicted big losses for BJP. Modi-Shah duo must be getting all State agencies’ intelligence reports besides their own Party’s surveys about the mood of voters and the likely grim election outcomes. Is it possible that Modi-Shah strategized to ensure their victory through EVM hacking and provide a cover through engineered atmospherics? Let us unpack this ingenious plot. 

Door for EVM hacking is left open; Civil Rights groups and Opposition must act to close it

There should have been much more disquiet among the Opposition parties than was seen, when on 26th April, the SCI dismissed ADR’s and two other tagged petitions (none was a political party) against the manner of usage of EVMs.  The petitioners wanted two voting process changes that could satisfy the voters at a very basic level. Petitioners had explained how the EVM system was hackable; and how these hacks could be foiled by the two simple process changes they prayed for. The extant rules of secrecy ECI has defined are such that it is almost impossible to provide evidence of hacking or a demo of a possible hack with real EVMs. ECI rejected the Petitioners’ suggestions and sadly SCI, siding with the ECI, dismissed the petitions and instead issued directions for post-result audits to ECI. The audits envisaged by SCI were technically absurd and untrustworthy. The time window for losing contestants to request for EVM audits expired on 11th June. The stands ECI and SCI took, left the door open for the elections to be subverted through the gaming of EVMs – ECI and SCI imperiled India’s democracy.       

Discrepancies in votes cast, as published on ECI’s website, were not acknowledged by ECI - neither in the past nor in the GE 2024 (also watch herehere and here). In view of the foregoing, it is imperative that opposition parties as well as civil society unite and mount a concerted challenge in the SCI to upturn the 26th April Judgement of the two-judge bench. SCI had delayed hearing the petitions so much that there was no time left to file a review petition, however, now this must be done, and opposition parties must boycott the usage of EVM unless the two process changes demanded earlier are accepted and implemented by ECI.

“400 par” was a distraction and Stock Market and Exit Poll “scam” a misdirection?

There was a low voter turn-out right from the first phase, in the 7-phase election, which was another indicator. Therefore, it is safe to assume that the narrative of 400 seats Modi flogged till the end was false and set with an ulterior motive.

This false narrative of “400 par” required to be reinforced. This was done through two methods - scripted multiple Exit Polls and hyping the imminent boom in Stock Market.

On 1st June when polling concluded, all Exit Polls made unanimous predictions of a land-slide victory for BJP. All pollsters projected BJP tally of 350 to 400. It is highly improbable that multiple pollsters make the same mistake at the same time. It became strikingly obvious the Exit Polls were scripted by a central source.

In the weeks preceding the election results, the PM, HM, Finance Minister and External Affairs Minister, gave unsolicited (and illegal) advice to investors. All four top leaders of BJP gave public advice, which was none of their business (only Securities Exchange Board of India  [SEBI] licensed advisers can do so), to buy stocks before 4th June. They misled the retail investors by telling them the stock prices will sharply go up. The tip shared with the entities of interest to Modi or BJP donors was opposite in nature (based on truth about the expected results). The retail investors followed Modi and his team’s advice and lost money whereas the favoured entities followed the honest advice and booked profits. When sub-par results are declared, the market crash was predictable and that is exactly what happened; in one day Rs.30 lac crores (Rs. 30 trillion) market cap meltdown occurred on 4th-5th June. This is a classic example of insider trading which is a criminal offense. Rahul Gandhi has asked for the appointment of Joint Parliamentary Committee (JPC) to investigate this “Exit Poll scam. A petition has been filed in SCI asking that Government and SEBI be ordered to investigate the charge of insider trading and fix the responsibility. Praveen Chakravarty of INC in an interview with Karan Thapar on The Wire explained the curious stocks transactions and Exit Poll timings. It is possible that Modi-Shah used the Stock Market hype to make money for BJP in conspiracy with some known entities, but the primary purpose must have been to create atmospherics in which BJP’s victory would appear to be sub-par to the Opposition and, therefore, acceptable.

Motivations for the plot of EVM hack  

Having come thus far, it is time to explain the motivations underlying the above plot Modi-Shah likely enacted. For them losing was not an option because the adversaries they had created over the ten-year rule at the Centre would be a source of serious discomfort for them if at all they got to form the Government. Either BJP would need to hack certain numbers of EVMs to ensure victory or risk losing too many constituencies then resort to EVM audits and generate false positives through subterfuge to establish hacking has happened when none has happened. Modi-Shah could easily get ECI to countermand the elections – in the constituencies or even the entire 2024 General Election.
Now it is known that Modi-Shah did not choose the audit route to stay in power, instead the EVM hacking route was chosen. The constraints in EVM hacking were the capacity to safely subvert either the ECI or District Election Officers/Returning Officers in charge of target constituencies and the method used for hacking. According to certain political observers, without EVM manipulations, BJP would have likely won 180-200 seats only. Assuming this to be also the input received by Modi-Shah,  BJP’s hacking would be required in about 100 constituencies, however, due to capacity constraints, it was likely planned / done only in 30 – 60 constituencies. Since Modi-Shah were still not sure of hitting the target of 272, they pulled out all stoppers and Modi conducted a campaign that was unprecedented in vitriol and intensity - Modi gave 80 scripted interviews to media houses, conducted 206 public rallies and road shows, his campaign ran over 76 days, he traveled across the country and gave hate speeches and told lies about INC's manifesto unfettered by the Model Code of Conduct as ECI played along.
The only explanation for Modi's over the top and shrill speeches, of the type a man gone berserk would make (Modi claimed he is non-biological, he told voters in rallies that INC intends to steal your wealth, buffaloes and "mangal sutra" to give away to Muslims), is that Modi was thrown off balance with the inputs he must have received of the worst case scenario of winning only 180 seats and also the inputs from his hacking partners of the maximum number of EVMs that could be gamed safely and, still not reaching the required tally of 272. For making up the deficit, BJP needed to swing additional voters but Modi's vicious campaign, though fueled with unlimited funds, backfired. Hindus saw through the charade and Muslims were undoubtedly spooked. The real issues came to the fore, and Modi Government's track record and Modi guarantees could not sway the voters, especially in States that mattered most. 

Securing the future of Indian democracy - it is essential to change few processes and rules - it is not necessary to discard EVMs

PM Modi mocked the Opposition parties’ silence over EVM, post 4th June results – his jibe was whether opposition thought EVM was dead or alive, he expressed hope that at least for the next five years no one will oppose EVMs. This was his finesse (aka Masterstroke) in concluding the saga of EVMs which Modi-Shah will continue to exploit unless, as already mentioned, Opposition parties join the efforts of civil rights groups and NGOs to save subversion of electoral democracy.

Opposition parties and citizens must make SCI upturn the April 26th Judgment and also the May 24th Judgment (interim order) refusing the petition ADR had filed praying for ECI to publish Form 17C-Part I which the Presiding Officer and Polling Agents file from each booth, on its website soon after polling closed in each constituency.

It is unfortunate that despite India having an excellent Digital Public Infrastructure, no one is talking about introducing a hybrid-online system; in the meanwhile we are stuck with a totally obsolete and hackable EVM system which has been hyped up as invincible and the "Gold Standard".

Saturday, April 20, 2024

EVM VVPAT Petitions and the SCI - Voter verification even more important than 100% manual vote count (updated 27th April'24)

 The spectacular bluff of two "silos" of data of Electoral Bonds (EB) that State Bank of India (SBI), represented by top lawyers, tried to pull off was live streamed to the whole country from the Supreme Court no.1 in the month of March 2024. The two "silos" were actually two tables of data. Such data of EB buyer and EB recipient in two tables of a Database (or even Excel worksheets) would require not even three minutes to match but the lawyers of SBI, FICCI and GOI asked the five-judge bench to grant them three months. Had SBI used the word tables instead of "silos", any computer literate person could have pointed out that the matching is a trivial exercise of writing one join query in a database or "vlookup" command in an Excel worksheet.


Another more spectacular drama of EVM System hackability has been unfolding in the two-judge bench of the Supreme Court but this time it is not live streamed; as only constitutional bench proceedings are live-streamed at present. This time ECI is the culprit for obfusctions or outright lies which have left everyone confused. What could have been argued and concluded in two hours went on for three days without any order by the bench. As a result the General Elections of 2024 which have commenced from 19th April with status quo on the EVM System which people of India rightly suspect can be gamed.

The petitioners have laboured to convince the court that EVM System has deficiencies and the possible hacks can be easily foiled by making two changes in processes: i) allow voter to verify the correctness of the printed vote slip and ii) manually count all the printed vote slips and compare with the EVM count (in case of discrepancy, as per existing ECI rules, the manual count prevails). ECI's lawyers and experts argued that there is no deficiency; ECI representatives actually lied and made self-contradictory statements (such contradictory statements also exist on ECI's website).

Firstly ECI has claimed that EVM machines are a standalone system - standalone in IT industry means, "not ever connected to Internet or any network (WAN or LAN)". Secondly, ECI claimed that EVM has only "firmware" as opposed to "software". ECI claimed that the VVPAT (Voter Verifiable Paper Audit Trail) into which Symbol Loading Unit (SLU is a "red herring" name for a pen drive, like silo was the fancy name for a data table) has only OTP (One-time-programmable) memory and that no software (or malware) can be transferred into it through the SLU or by any other means. Both these claims are contradicted by ECI's own admission - as visible on its website pages. 

Search for "standalone" and "OTP" in the linked note here and here - you will find multiple occurrences of "standalone", "laptop" and "OTP" - you can read in five minutes in context what ECI has mentioned. EVM machines (BU, CU and VVPAT) are not the whole picture - EVM System is the whole picture - it comprises of a Central Server to be accessed via Internet, Laptop (in the custody of DEO/RO) and SLU. EVM System by no means is a standalone system and VVPAT has programmable memory too. This being the case, malware (software written by a hacker) can enter the system: via the central server or via the Internet into the Laptop, via the Laptop into the SLU, and finally via the SLU into the VVPAT's programmable memory. This infiltration of malware can occur with or without the knowledge of District Election Officer/Returning Officer or field engineers deployed in the over 1.2 million booths to commission the EVM during the 15 days prior to poll commencement. The malware can make the VVPAT misbehave as per multiple parameters set by the hacker, for e.g. date, time slots, constituency, the party to favour, the party to steal votes from, preceding rate of voting (i.e. misbehave only when there is rush) etc. Prashant Bhushan, ADR's Sr advocate, did try to explain some of these characteristics but the Justices cut him off frequently. 

The petitioners have made very sensible and feasible demands. Will the bench grant these reliefs? Without these reliefs, the 2024 Election's system will be highly fraught and its results untrustworthy. The public, at least a large section, will lose complete faith in the ECI's and GOI's democratic credentials.

Reliefs sought:

RELIEF # 1 to defeat 1st method of "steal the same successive votes - hack": The voter should be able to pick up the VVPAT printed slip for verification and physically insert it into the ballot box; else the voter should be able to see the vote slip printed is correct and it is actually cut and dispensed into the ballot box - it is not sufficient for the voter to just see the vote slip (because it could be the previous voter's slip which has not been cut and dispensed due to a hack) - this means the light should remain on and not merely for seven seconds, as is presently the case. This is a clever hack because it cannot be caught - the stolen consecutive 2nd or 3rd or successive votes (as parameterised) - cast in favour of the hacker's party - will not be seen because their printing, cutting, dispensing into ballot box and writing into the CU will all occur only when the light is in the switched off state and in few seconds after the button for a different party's candidate is pressed by a subsequent voter or when the stealing parameter count is reached. In this hack, the vote count in CU and the manual count of VVPAT printed votes will match. Therefore, even a 100% manual vote count cannot foil this hack. This delayed printing of consecutive vote will likely be the preferred method of hack.
 
RELIEF # 2 to defeat the 2nd method of "print correct vote slip but write vote in CU for hacker's party candidate - hack": The election results should be based on a manual count of 100% slips. In case of discrepancy between the manual count and the CU count, recounts may be ordered. Ultimately, the manual count would prevail and not the CU Count. This change in process is required to foil the second method of possible hack of VVPAT printing a vote slip for one party and writing into the CU a vote of another party. Compared to the above method of hack, this one is laible to be caught and, therefore, less likely to be preferred by the hacker.
 
RELIEF # 3 for safe transport: After the Polling finishes, the CU and the Ballot Box pairs are transported to the counting station. During the journey, oversight of contestants' representatives should be allowed.
 
RELIEF #4 for enabling genuine complaints: Presently a voter who complains to the Presiding Officer (PO) in the Polling Booth that his/her vote is not properly generated, i.e. the VVPAT has printed the wrong vote - is required to prove the allegation is correct through a retest. If the error is repeated well and good but if it is not repeatable, the voter can face a fine of up to Rs.1,000 and imprisonment of up to 3 months or both. It is a matter of common knowledge that programs can be written to work with random parameters or based on parameters such that without the knowledge of source code, no one can predict if the error will repeat nor when it will repeat. The punishment under rule 49MA - Section 177, should be totally removed as it is illogical, and it works as a deterrent for genuine voter complaints - unless source code is made public, and its auditability allowed before and during elections.  
   
The RELIEF#1 and 2 are essential but the 1st one is more important. Without these changes, the results of 2024 General Elections will always be suspect.

Both ECI and SCI have treated the challenges to the EVM usage in elections with contempt and derision. Requests for a meeting of political parties, citizens councils and lawyers to ECI have been ignored, not even acknowledged.

The petitions principally focused on EVM vulnerabilities have been pending with the SCI for many months or even years. In March'24, when Kapil Sibal and Prashant Bhushan, on behalf of ADR (Association of Democratic Reforms) requested SCI for an urgent hearing since the General Elections 2024 were set to start from 19-Apr-24, they were told that there are many pending matters and their pleas will be heard and decided before the polling starts.

The bench of Justices Sanjiv Khanna and Dipankar Datta finally heard the petitioners on 16th April, 18th April and 24th April for about 2.5 days and finally reserved the order. On 24th April the bench had asked ECI to provide answers to six questions. One question was about the repgrammability of microcontroller program in the EVM - in the VVPAT or the CU? This is a wrong question to ask. Even if the program is unalterable because it sits in the OTP memory, the device can be hacked - by malware being loaded into the programmable memory (VVPAT has both OTP and programmable memory) and intercepting the commands going into or out of the program. So the elections have started with status quo being maintained, no one knows when and what the bench will rule on the two main demands of the petitioners.

RELATED



Search for "laptop" in the proceedings - live updates from Bar & Bench here
There is a crucial fact of use of a laptop in every election cycle in every constituency, possibly every booth, where "EVM" must be commissioned within two weeks prior to polling date - this has always been obfuscated by ECI. Judge asks an incoherent but a leading and somewhat meaningless question, "software by ECI has a lock mechanism". Firstly, the software according to ECI does not exist in VVPAT - only firmware exists in VVPAT, secondly ECI itself does not have software which is kept secret by BEL and ECIL; no one knows what is meant by "lock in mechanism", ECI does not provide an answer either.
  
Excerpts (copied from Bar & Bench updates):

12:03 pm, 18 Apr 2024
  •   
  •  
Supreme Court: The SLUs are not stored to ensure that there is no tampering. etc.? Of course, very difficult.. SLU is done from the computers.. laptop etc used by returning officer.. The software by ECI has a lock in mechanism.

ECI: Yes, it is a secured software.

------------------------------------------------------------

21-Apr-24 The Leaflet this article reproduces portions of the proceedings and highlights the relevant issues here


Terminology primer for non-IT readers:

Any computer system or an intelligent device (e.g. VVPAT, Smartphone) works with the following components:

Hardware
Firmware - this sits in OTP (one-time-programmable) memory
Operating System - OS (or Control Program) - this sits in programmable memory
Application Program
Data (input from keypad or sensors or attached devices like pen drive)

Hacker corrupts the Operating System or the Control Program - if someone has the source code (or even the object code - from the set of stolen EVM machines - object code could be retrieved and reverse compiled - this is surely within the reach of a sophisticated hacker) then malware can be written into the programmable memory - in context of VVPAT, this can be done at the time SLU is inserted for copying the candidate data file; the SLU would likely be infected via the DEO/RO's laptop. 

Any laptop requires an OS and the OS can be infiltrated by malware knowingly or unknowingly by the user. Everyone knows when a computer is connected to Internet, virus can enter the computer - even if anti-virus program is installed on the device - this happens unknowingly - user can also download a malware knowingly, if he wants to. Everyone knows Windows OS is easy to hack, that's why antivirus programs are necessary to instal. Most of the computers today run under Windows OS. We donot know which OS runs on the laptops the DEO/RO use in commissioning the EVM. ECI representative at some point mentioned in the court that PO's (Polling Officer) laptop is used in commissioning of EVM, whereas on ECI website, it says, DEO/RO's laptop is used. The SLU (pen drive) inserted into an infected laptop will carry the malware and transfer it into any other computer or intelligent device (like the VVPAT) into which it is inserted. This is not rocket science.


Thursday, February 8, 2024

EVM System usage in 2024 General Elections - minimum demands necessary to place before SCI and ECI

IN A DEMOCRACY PEOPLE GET THE GOVERNMENT THEY DESERVE - BUT WHAT IF THE ELECTION PROCESS IS COMPROMISED?

Anything can be made more complex than it really is. However, the looming threat due to the existing EVM System usage process, coupled with the attitude of ECI and SCI, is so serious and complex that political party leaders, technical experts, lawyers and activists must collaborate. Without collaboration and a unified approach, it will be tough to mount a credible campaign to counter the threat to "purity of the election process".


This note has references to old notes and one new note on an online solution - all links (in orange colour) provided below. Just so that we are clear of the terminology, copied below is the existing EVM usage (graphics copied from ECI website - however, red colour annotations are added):


IT IS IMPORTANT TO NOTE THAT WITHIN 15 DAYS BEFORE POLLING COMMENCES, SLU IS CONNECTED TO LAP TOP FOR DOWN LOADING THE CANDIDATES + SYMBOLS DATA FROM THE CENTRAL SERVER  AND THEN IT IS INSERTED INTO VVPAT FOR UPLOADING THE SAME - IT IS AT THIS MOMENT, A ROGUE PROGRAM CAN INFILTRATE THE VVPAT AND EVM SYSTEM COMPROMISED. HACKER NEEDS TO SUBVERT ONLY FEW FIELD STAFF IN THOSE BOOTHS WHICH MATTER MOST TO HACKER'S MASTER. AS THERE ARE OVER A MILLION EVMS TO BE COMMISSIONED, WITHIN 15 DAYS, THERE HAS GOT TO BE AN ARMY OF FIELD STAFF HIRED BY ECIL AND BEL. TO SAY THE LEAST, THIS SHOULD BE A SECURITY NIGHTMARE FOR ANY SYSTEM DESIGNER. WHY HAS ECI NOT DISCUSSED THE RISKS IN THIS SORT OF OPERATION IS A QUESTION BEGGING TO BE ASKED. It is also ironical that none of the well-known IT tycoons of India has spoken out about the obsolete design of the "EVM System" and its hackability, instead ECI is flogging the assessments of IIT Professors (on Government's payroll) about the "non-hackability" of the "EVM" (do they even know the difference between the "EVM" and "EVM System", one ought to ask). Just as the rewards or stakes of hacking India's elections bear no comparison with ordinary hacking of an organisation's or an individual's account, expectedly the calibre and organisational wherewithal of the two sets of hacker groups are non-comparable. [Read in the RELALTED links below, the story of Stuxnet virus and ECI presentations and FAQ anomalies and lies] 





In the existing process, this is what happens (or can happen):

  1. An elector (voter) walks into the Polling Station (PS) with an ID proof. S/he walks up to the row of Polling Agents of Political parties and they tick off the name after verifying his/her name on the voters list. If name is not found, the voter is not allowed to vote; s/he is asked to exit the booth.
  2. Indelible ink is smeared on one finger of the eligible voter.
  3. The voter walks up to the Voting Compartment and waits to press a button on the BU to register his/her vote. The BU has the names of contestants and election symbols adjacent to buttons. Max 16 names per BU - they can be daisy-chained.
  4. The Polling Officer with the CU presses a key to enable the BU to register a vote.
  5. The voter pushes a button to register his/her vote after hearing the audio beep that tells everyone that BU is enabled to accept one vote.
  6. VVPAT lights up for 7 seconds during which the voter can see the voting slip with the name of the candidate and symbol. Voter must assume that this slip is not of the previous voter - though there is no telling it could well be of the previous voter - a hacked VVPAT could behave in this manner. If the visible slip is NOT as per the vote cast then the Voter can complain and fill out a a form to nullify the "wrong vote". There is an intimidating process to rectify the error - which includes actions to "prove" that the machines are misbehaving! VVPAT is supposed to write a record of the vote in the CU; a hacked VVPAT could well write a vote in favour of a candidate of hacker's choice.
  7. The voter having cast his/her vote walks out trusting the the vote is recorded correctly in the CU and that the slip s/he saw in the VVPAT has been indeed dispensed in ballot box. It could well be that the the slip has NOT been dispensed in the ballot box nor recorded in the CU. A hacked VVPAT could behave like this - hold all consecutive votes of an adversary party (adversary of the hacker's party) until a vote is cast of a different party - upon that happening, the hacked VVPAT could print and dispense all the votes it had held back, in favour of the hacker's party candidate and also record the votes in the CU consistent with the printed slips!      
 
This note is prepared with the intention to sensitise few more influencers and politicians who can mobilise public opinion against the continuance of the EVM usage in the present form. Regarding the pitch to be made before the ECI/SCI - what exactly should be the demand that is feasible to implement within weeks - to mitigate the risks of hijacking of the 2024 General Elections? We all believe that the outcome of upcoming General Election will be pivotal for the future (secular and democratic) character of the country.

  1. CJI recently said, "The great stabilizing force in the country is the purity of the election process". Ironically, the existing EVM usage process is DEMONSTRABLY HACKABLE - what makes it doubly fraught is that existing rules PREVENT AUDITABILITY and ECI is not prepared to engage with the citizens who have sought a meeting. To repeat - the present processes and rules allow a certain type of hacking to be done and the hack is not provable - this is a mockery of democracy and we should jettison such a set of processes and rules. As ECI is clearly aligned with the Government, it is only the SCI that can provide a solution. If SCI does not grant the following demands, the opposition ought to boycott all elections.

1.1 DEMAND#1 THE VOTER SHOULD BE ABLE TO PICK UP THE SLIP TO VERFIY ITS CORRECTNESS AND THEN PHYSICALLY INSERT IT INTO THE BALLOT BOX.   Or else the voter should be assured that the vote slip coming out of VVPAT, after the vote is cast (by pressing the button on the BU), has the right candidate name and symbol AND it is dispensed into the ballot box. At present the slip is illuminated for 7 seconds behind a one way mirror in the VVPAT and the voter CANNOT EASILY recognise the candidate name or the symbol AND FURTHERMORE, THE VOTER CANNOT FIND OUT IF THE SLIP IS ACTUALLY DISPENSED INTO THE BALLOT BOX. THEREFORE, THE VVPAT SHOULD BE RECONFIGURED (OPENED UP) FOR ENABLING EASY RECOGNITION OF CANDIDATE'S NAME & SYMBOL ON THE SLIP AND ITS DISPENSATION INTO THE BALLOT BOX.

1.2 DEMAND#2 The results should not be based on the count read off from the memory of the Control Unit (CU) rather it should be based on a MANUAL COUNT of 100% SLIPS or RECOUNT IN CASE OF DISCREPANCY BETWEEN THE MANUAL COUNT AND THE CU COUNT. To further reduce the chances of errors of the manual count, TWO RECOUNTS MAY BE ORDERED, IF NECESSARY. 

1.3 DEMAND#3 After the Polling finishes, the CU and the Ballot Box pairs are supposed to be transported to the counting station and en route they have to be stored for many hours or even days. ECI has prescribed an elaborate and secure process for transportation and storage but it precludes presence or oversight of contestants' representatives. Fraud can be committed by replacing the sets of the pair of CU and Ballot Box. To mitigate risks - i) CU and Ballot Box pairs should NOT be transported and stored together and ii) Oversight of contestants' representatives should be allowed.

1.4 DEMAND#4 Presently a voter who complains to the Presiding Officer in the Polling Booth that his/her vote is not properly generated, i.e. the VVPAT has printed the wrong vote - is required to prove the allegation is correct through a retest - if the error is repeated well and good but if it is not repeatable, the voter can face a fine of up to Rs.1,000 and imprisonment of up to 6 months or both. It is a matter of common knowledge that hacked programs can be made to misbehave erratically or based on parameters such that without the knowledge of source code, no one can predict if the error will repeat or when it will repeat. The punishment under rule 49MA - Section 177, should be totally removed as it is illogical, and it works as a deterrent for genuine voter complaints - unelsss source code is made public and its auditability allowed before and during elections.  


  1. Anything more than above demands may not be feasible to implement in the short time available before the elections. Anything less will not eliminate the threat of the election results getting hijacked. By getting bar coded slips, the counting process can be hastened by few hours. However, again the hacked VVPAT  could print a bar code different from the correct candidate id / symbol printed on the slip. So further sample audit will be needed and this is avoidable complexity. It is also doubtful if 1 million+ bar code printers can be procured and fitted up in VVPAT in the available time. The demand of junking EVMs and switching over to paper ballot is neither feasible in the short time available nor necessary. There are many advantages of continuting to use the existing infrastructure and processes in which millions of people are trained. The demands listed here are entirely feasible to make and will ensure a FAIR and SAFE process.

  1. Manual count in 100% of polling stations may add one or two days which is trivial considering the elections are conducted for a period longer than a month. The 2019 General Elections were scheduled from 11-Apr-2019 to 19-May-2019. ECI website shows that over one million polling stations were setup. Each BU can accommodate only 16 names, with greater number of contestants more BUs would be required. Each CU has a capacity to record max of 2K votes.

  1. In summary, the demand for software auditability will encompass disclosure of software and its revisions, setting up auditors panel, process of audit challenge by contestants and its resolution - for all of these both SCI ruling and ECI cooperation will be required which may be difficult to obtain. ECI will likely not cooperate with this demand as it is perfectly aligned with GOI. Therefore, absent the software auditability, there is no alternative to the demands formulated above. At least the first two must be acquiesced to - if any one is granted it is not sufficient. Remember the VVPAT hack can be of two types -

    4.1 the vote slip dispensed and and the vote recorded in CU are consistent but NOT according to the actual vote cast (hence demand#1 is made)

    4.2 the vote slip dispensed is consistent with the actual vote cast but the vote recorded in CU is NOT (hence demand#2 is made)

    4.3 The possibility of a fraud of replacing the CU and Ballot Box pairs is non-trivial because a RTI based PIL had revealed that whereabouts of 1.9 Million EVM Systems are not known to ECI.
4.4 The punishment should be totally removed as it is based on an illogical prmise of predictability of hacked programs and it deters gneuine complaints of voters. If source code is made public, independent auditors can confirm if VVPAT  BU and CU are working as per original program; this will allow citizens to prove hacking else it is NOT provable. Therefore, no fines or punishment should be inflicted on a complainant without the option of auditability of the source code.

  

To dig deeper, refer to other notes for which links are copied below.  


RELATED REFERENCES:

Read the "Stuxnet" virus story - how Iran Nuclear fuel processing centrifuges were knocked out by CIA even though Iran's engineers had claimed the plant had "stand alone" systems - just like ECI is claiming their devices are in a "stand alone" state - they allow connecting a SLU before commissioning the system - this is sufficient to infiltrate a rogue program into VVPAT. The hacking can be done selectively - in certain systems only - as all the machines have unique IDs. The rogue program can behave according to a date - time - number of votes cast - schedule - thus defeating the FLC which ECI pompously claims is sufficient proof of proper functioning of the EVM system. They are fooling the public or they are ignorant.

EVM System - updated website - new revelations and questions (ECI has updated its website pages; new FAQ on 7-Feb-24, Presentation too is changed; probably in response to recent protests and demos of hacking; it has now changed the definition of EVM - earlier it used to mean BU and CU but now it includes VVPAT; so, EVM now cannot be claimed to be OTP device as VVPAT has programmable memory; furthermore EVM System, is more than EVM but ECI is silent on it). 





Read about the two hack demos. Recently hacks of EVM System were demonstrated and videos shown on 4pm News Network. In these hacks the VVPAT votes differently from the actual votes cast - the slips printed and vote recorded in the CU were consistent. Therefore, the manual count of slips and the count from the CU would match. This type of fraud can only be prevented if Demand#1 is met, else it would require software audit but that is not possible as ECI and SCI have said that software is secret. SCI on the one hand ecourages Open Source - but on the other hand, in this particular instance, it protects the IPR of a ridiculously simple program - GOI can easily get the same software developed in Open Source or buy the IPR for cost which is not likely to exceed few million rupees! Another intriguing thing to read about is that 1.9 Million EVM Systems have gone missing - The Wire article of 22-May-19 linked.