I asked the AEC about the new software they used for counting votes. Concerns have been raised about previous AEC software by cryptologists and the National Audit Office.

The AEC claims to have written new software that fixes all of these problems, but they won’t tell us who audited it and what the results were. An open and transparent audit is absolutely necessary to ensure there is 100% confidence in our elections.

Transcript

Thank you, Miss Jay.

Thanks Senator Sullivan, Senator Roberts.

[Malcolm Roberts] Thank you. And thank you for appearing today. My questions apart from the first and third, fairly brief. So the first one, in reference to testimony at the last estimates, and I’ve I’ve got copies of your questions on that, responses to your questions and that is. The AEC bought but did not use the Scytl software. Rather you write your own. To write your own election software is a really impressive feat. We’ve been talking to people, they’re very impressed. May I ask how many staff are on the development team please?

I’d have to take that on notice.

[Malcolm Roberts] Okay. What was the total cost of doing that?

I’d have to take that on notice.

[Malcolm Roberts] Okay. What testing did you use before deployment now I’d imagine some kind of parallel running or some form of a dry run.

Well, in fact, we did multiple forms of testing and assurance Senator, as I’m sure you would as I’m sure you’d be aware. And look Senator, to be abundantly helpful here, we’re happy to provide you a more detailed personal briefing on this. I’m happy to talk to you about it. It is a complex process. As you’re aware, we’ve been using our audit, our checked software, easy CAAT for a number of years and we’ve redeveloped that that’s effectively what we deployed as part of the 2016 solution. As I think we said last time, the Siedel solution, we got Seidel on board as really as a business assurance process to make sure that we had software that was going to work at 12 week period to deliver it. The software we’re using has been checked, double-checked and assured. And not only that, the important point to note it’s totally in line with the existing legislation and all of the data that we then generate from that software is put online and the results are then replicated by a number of psephologists and political science departments who use that data to replicate the count. And it exactly matches the outcome of their own. So there’s a range of different ways of assuring that this software is fit for purpose.

[Malcolm Roberts] Okay, thank you. Still part of the first question. Were any of the staff involved doctorate or masters degree qualified in a suitable discipline such as mathematics or cryptology?

Senator I’d have to take that on notice.

[Malcolm Roberts] Could we get their names please? When you provide it a notice?

No.

[Malcolm Roberts] Okay. And how long did it take?

We had for the 2016 process we had that 12 week periods in Israel, as I’ve said previously.

[Malcolm Roberts] Yeah. And can you provide their qualifications?

Senator again, if you can help me here on letting me know where you’re trying to head, maybe I can provide some more fulsome answers.

[Malcolm Roberts] Perhaps we can, we can go into that in the briefing. I’d love to take you up on that. So did your bespoke solution use any code from Scytl and if so, what percentage?

It did not.

[Malcolm Roberts] None at all. Great. Your software, you intimated has been audited in accordance with standards published by the National Association of Testing Authorities, NADA. That certification does not specify a standard for the auditing of election software. It’s more of a general process for an audit to follow, as I understand it. Having the audit is not a guarantee that your software works within acceptable accuracy levels. Although these issues may come out in an audit who conducted the audit and how much did it cost and what was the result?

Senator as I’ve just said, if you can help me here by telling me where you’re trying to head with this process I would get some of these questions. If somehow the results of this were somehow secret or behind closed doors. We use a piece of software that’s been tested and assured on multiple occasions. The same time, all of the data that this software produces is then publicly published on our virtual teller even on our website, which on election day, as one of the most used pages in Australia, that data is then used by a variety of psephologists and computer and political science experts to replicate those results. It’s intensely public. If you’re trying to indicate that there’s some sort of issue, I just don’t understand why you’d be doing that when there’s been no evidence of that at all.

[Malcolm Roberts] Well, we were just concerned about the auditing. That’s all. Because we got some answers from the, I think it was a Nao that didn’t give us the assurance. So let’s go onto some of the physical things then of the 511 polling places in the last election. How many of those had computers or other devices that communicated with the AEC computer system or were capable of doing so?

Senator I’m Jeff Pope, deputy electoral commissioner. I’m not sure what you’re referring to with 511 polling places we had nearly 8,000.

[Malcolm Roberts] Could that be state?

Perhaps you might be referring to–

[Malcolm Roberts] While it is not a mandatory requirement for pre-poll voting centres at the 2019 federal election. 115 of the 511 people voting centres. So pre-poll, sorry, pre-poll. My mistake.

[Man] Right.

[Malcolm Roberts] Had me worried there.

You had me worried.

[Malcolm Roberts] Well, just how many have got a physical connection? How many had a physical connection?

For what purpose, Senator?

[Malcolm Roberts] Well, I’m going to go into that in the next few questions.

Many in terms of the role. And–

There are, we have electronic certified lists in every I think in every one of those pre-poll centres last event where citizens names and marked off the roll.

[Malcolm Roberts] No, it’s beyond that. I note from your answer on questions on notice F-O six five on polling place security, that those electronic devices were protected by monitored back to base alarm in only 115 of the 511 polling places. Were any other measures in place to protect the cyber integrity of those devices during the election period? For example were they air gaped, were they turned off at night, was there IP traffic monitoring for the period when they should have been none because they were turned off? That’s what we’re after.

I think all of your thoughts–

[Malcolm Roberts] You think?–

So we’ll take it on notice. But again, we’ve had no issue with any breach of our software or our hardware, with respect to delivery of the election–

At all, and no indicator of any breach and our handling of all of that data. And the physical equipment was in line with relevant Commonwealth guidelines and regulations and the risk assessment that we undertook.

[Malcolm Roberts] Okay. I’m just doing my job on behalf of my constituents.

I get it Senator. And I’m doing my job.

[Malcolm Roberts] Yes.

On also defending one of the world’s best and most transparent electoral systems.

[Malcolm Roberts] Well I’m not attacking it. I’m just making sure that–

Fantastic. And so we’re both doing our jobs in terms of making sure that citizens have the information they need to form their judgements.

[Malcolm Roberts] Correct. I’ve only got three questions to go. In your response to questions on notice F-0 six eight, you make the comment, ” All preferences and all Senate ballot papers are reviewed by at least one person at the scanning side.” Does that mean that they compare the scanned ballot with the paper ballot to ensure accuracy? Because that’s the impression your answer gives. Do they compare the actual scanned ballot with the paper ballot?

Senator the process is that a data is both manually entered and scanned and then that’s matched with the automated process–

[Malcolm Roberts] All the ballot papers are manually entered?

Manually entered but all paper is scanned when it first arrives. Then from that image which is an image that data is then entered. And then the scan, the data from the scan is then compared with that to make sure that they match. Where they don’t match, we undertake further processes.

[Malcolm Roberts] Could you explain that in terms of, we have a physical paper ballot that is scanned in–

[Man] Correct.

[Malcolm Roberts] And then–

And then it captures an image.

[Malcolm Roberts] Right. And then what is compared with that image?

That image is then presented to the Data Entry Operator who enters the data from that image–

[Malcolm Roberts] From the image–

Right.

[Malcolm Roberts] So he or she enters it physically.

Correct.

[Malcolm Roberts] So that’s the manual part.

That’s the manual part, then at the same time the data capture process as part of capturing the image is then compared with that manual process. Where that matches, that’s taken to be an accurate match. And that’s included in the count. Where it doesn’t match, we undertake further processes.

[Malcolm Roberts] So that last estimates in October, I asked what percentage of computer records that checked back against the paper record. And you took that on notice, your lengthy answer failed to provide a figure. Is that because it’s a hundred percent?

Which was the question Senator?

[Malcolm Roberts] I asked what percentage of computer records are checked back against the paper record? And you took that a notice, your lengthy answer, which is I think F-068. Hang on, it might be zero eight four. Sorry, zero eight, four. So, as I was saying your lengthy answer failed to provide a figure. Counting ballots is a quantitative exercise. So everything comes down to figures. What percentage of electronic voting cards are compared back to the ballot paper and what is the variance?

I wonder whether we’re talking about different things here, Senator. The process that I’ve just been through demonstrates that every single paper.

[Malcolm Roberts] Thank you.

Yep.

[Malcolm Roberts] Last question . On this topic, anyway. Has the AEC ever run a test batch of a few thousand ballot papers through your system then run those same ballots through a second time and compared the result? Surely any variance between these two runs would give you a figure for system accuracy.

Again, Senator I’d rely on what I’ve just said before that the process that we’re running involves a full manual entry of every single ballot paper compared then to the scanning, capture of the scanned data. So we’re doing that in any case.

[Malcolm Roberts] That that’s what I thought. Okay. Just a final question. Just to lose question. I was thinking as, the senators were asking questions. Voters tell us quite often that they’re then not in favour of being assaulted by a number of how to vote cards distributors being volunteers, distributing how to vote cards when they’re entering a polling booth and some of the premises managers getting to have a bit of strife with it too. I don’t know. I haven’t read the act that covers this, but would there be any possibility or any consideration given to putting the, how to vote cards in the booth or is that fundamentally flawed?

Absolutely not Senator yet. I know what you’re saying that occasionally people do so that. What I’d say in defensive 99.9% of all of the party workers is most people strive to do the right thing.

[Man] Yeah.

We have a few over-excited individuals that really like to get those how to vote cards in the hands of voters. And that can cause some offence but most people do the right thing. We would never put a how to votes in the polling place, because then get confused and think we’re endorsing a particular process and it creates grief.

[Malcolm Roberts] What about if everyone was in there? Every party.

Same thing people then get confused and I’d be absolutely–

[Malcolm Roberts] That’s a fair comment. So if someone’s handing it they can stop them and ask questions about it. Okay. Thank you. Thank you, Chair.

Thank you, Senator Roberts.