So, you might remember my spirited defense of EVMs. I still stand by it, except that my first election with VVPAT has taken away my trust. VVPAT has created a hole in the EVM armor & made the process amenable to hacking @DrSYQuraishi@AshokLavasa@ECISVEEP
@DrSYQuraishi@AshokLavasa@ECISVEEP Just to state the source, all my references and pics are from the ECI manual on EVMs and VVPAT available for download from the ECI site. eci.gov.in/files/file/923… In case of any doubt one may download it and go through in detail. 2/n
It has a memory because serial numbers, names & symbols of the candidates need to be loaded on to it before the elections, so that it gets printed in the paper slip.
Note: This pic from internet.
@DrSYQuraishi@AshokLavasa@ECISVEEP So VVPAT has a processor, and has a programmable memory, and it is what registers vote in the control unit.
And if it has a processor and a programmable memory, it can be hacked. Any malware downloaded on to it can cause the entire system to misbehave
For symbols are loaded on to the VVPAT by the engineers from their Laptops/Jigs after the candidates are finalized.
VVPATs are connected to external devices after candidate sequence is known!!
@DrSYQuraishi@AshokLavasa@ECISVEEP When one can access the VVPAT after the candidate sequence is known, and can connect a laptop/computer/Symbol Loading Jig, is precisely when one can load a malware also into the VVPAT.
This access should not have been provided.
That answers the when question. Now to the how.
@DrSYQuraishi@AshokLavasa@ECISVEEP I forgot to add the other defense we had. That no-one had physical access to the EVMs once candidates are set.
By allowing external devices to be brought to the commissioning room, and allowing it to be connected to VVPAT, we have foregone this defense too.
@DrSYQuraishi@AshokLavasa@ECISVEEP On to the how part: Since VVPAT controls both the trust factor & the vote factor, a possible method could be,
VVPAT prints what is pressed in the BU. So voter sees that paper trail tallies with his pressing of the button. #TheTrust
@DrSYQuraishi@AshokLavasa@ECISVEEP While we have a provision for if a voter complaints that the VVPAT paper trail does not match with the button he pressed, there is no way he can know if the VVPAT has send the same input to the CU.
So the wrong printing can be caught, but not right printing and wrong registering
Now on to the question of do we have a fool-proof process check against this.
Ideally, since such a new device has been inserted in between two devices, the verification and tallying should be done at both the ends for every vote.
@DrSYQuraishi@AshokLavasa@ECISVEEP While citizen has verified the BU & VVPAT end, that what he saw is what he pressed, the CU & VVPAT verification needs to be done through tallying paper trails with vote count in the CU.
But as it takes time, we only do such verification for a selected few per constituency.
@DrSYQuraishi@AshokLavasa@ECISVEEP Even if we find an inconsistency, current procedure simply says go as per the VVPAT count for that particular EVM.
So if one is to manipulate only a few EVMs & not all through VVPATs, 1. Chances of getting caught are less. 2. Even if caught, it will be seen as a one-off error.
Randomization is completely ineffective here as the access of VVPAT to external devices is given after it is allotted to the constituency.
So it doesn't matter which EVM is going to which PS after randomization.
@DrSYQuraishi@AshokLavasa@ECISVEEP The other check is of mock-polls. There are two mock-polls after the commissioning of EVMs (When candidates sequence is loaded).
1. Mock-poll of 1000 votes on random 5% of EVM at the time of commissioning. 2. Mock-poll of 50 votes at the polling station (PS) on the day of poll
If one is attempting to manipulate only a few EVMs, the chances of it getting caught are less. And even if caught, it is seen as a malfunction and the EVM is set aside.
If it is known that in every EVM first 50 votes will be tallied on the spot, you write your code such that it starts manipulating only after say a 100 votes.
No chance of getting caught there.
@DrSYQuraishi@AshokLavasa@ECISVEEP So, by introducing VVPATs, we have created so much vulnerability to an otherwise fool-proof process, while not adding adequate checks, either in the process or during the counting.
I feel there is an urgent need to address this so that the process become more robust.
@DrSYQuraishi@AshokLavasa@ECISVEEP The fact that so many VVPAT slip counting has tallied with EVMs does instill a lot of confidence that such a manipulation wouldn't have happened in the past.
But we cannot & should not leave elections of the largest democracy in the world to even the slightest of the chances.
Dear PM @narendramodi, after the surprise incursion from China last summer & the Galwan valley incident, I have been trying to understand China, by studying their history, culture, language etc.
I am no China expert. But here is two cents on why they did what they did. 1/n
As with India, China also should be studied based on its current position in its civilisational and historic journey.
And in that journey, there is not a more important theme than this theme of "Unification of China" 2/n
Unification phase and disintegration phase is a repeated pattern in Chinese history.
Hence it becomes important to understand which phase they view themselves to be in, in the present.
And in their collective imagination, this is very clearly a unification phase. 3/n
1. The VVPAT that sits in the middle is an active device and one which was connected to an external device like SLU or laptop for symbol loading unlike the BU which was an electromechanical device.
1. There is no active verification at the time of voting as irrespective of whether voter has seen the vote or not, the printed slip falls down & gets stored.
2. VVPAT auditing (not verification) during counting is less than 2%.
Some of you might be aware of my curiosity driven project : whatchinareads.com.
Today, I added Science related news section to the website and I came to know that a Chinese academician has applied for emergency use of nebulized inhaled covid vaccine. 1/n
Also added another section for academic papers abstracts.
A mine-field of information for those who are interested in the field. Only abstracts though. Those really interested will still have to go to the original site and get the full paper PDFs 2/n
An astonishing thing is the number of papers that are on industrial and manufacturing technology.
I am sure you must be feeling bad that Govt did not do enough in the past one year to prepare.
But please realize that it is still not late for many districts since they are not yet severely affected.
Do focus there as well. 1/n
Apart from the team that is dealing with the ongoing full-blown crisis in many places, please create another team to focus on the districts that are yet to be as severely affected.
Start preparation in those districts also on war footing. 2/n
I don’t want to burden you with any new suggestions or sermons dear PM @narendramodi.
But would like to share some screenshots of the suggestions/requests that were posted last year during the lockdown. 3/n
A 20 minute video on my concerns regarding the vulnerabilities of current EVM-VVPAT design.
On how it surrendered the strengths of pre-VVPAT EVM design & also did not bring in the checks of a true VVPAT design. What we have is a jugaad EVM-VVPAT now.
To all who are watching/reading these concerns, my humble request is to please don't link it to election results one way or the other. These are process concerns. And it will be there irrespective of which party wins.