Live data from Hacker News

In Estonian parliamentary election, 44% of the votes were cast online

zdnet.com

71–80 of 208 posts

Re: In Estonian parliamentary election, 44% of the votes were cast online

#71
post #69

Earlier quoted context omitted.

> Now you can demonstrate to anyone what you voted. Not necessarily. It is possible to have verifiability and receipt freeness: https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy... > The demands of voting are incredibly unsuited to digital systems and definitely to any online voting. Clearly you need to do more research before making such sweeping claims.

> Not necessarily. It is possible to have verifiability and receipt freeness I know these methods, but they were not used in OPs suggestion. They fix this issue and introduce others. > Clearly you need to do more research before making such sweeping claims. On the contrary, I'm willing to double down on my claim. I'm willing to provide either a breach or a denial of service for any digital or online voting system you…

> I know these methods, but they were not used in OPs suggestion.

You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that.

> I'm willing to provide either a breach or a denial of service for any digital or online voting system you care to describe.

There are many systems in the literature. What are your credentials in this field? Are you a cryptanalyst?

> Voting is however one of the few situations where the lack of sophistication of pen and paper works in your favor significantly.

This is as myopic as saying “E-commerce and e-banking are some of the few situations where the lack of sophistication of pen and paper works in your favor significantly. The demands of e-commerce and e-banking are incredibly unsuited to digital systems and definitely to any online systems.”

Re: In Estonian parliamentary election, 44% of the votes were cast online

#72

Newver understood the fascination with e-votes. E-votes are great when you vote for reality shows but for a normal election I think walking to the local booth and vote is a much better idea because it is hackers proof and also only citizens with enough motivation will vote.

> and also only citizens with enough motivation will vote.

Why are physical barriers restricting public engagement a desirable trait in a democracy?

Re: In Estonian parliamentary election, 44% of the votes were cast online

#73

Newver understood the fascination with e-votes. E-votes are great when you vote for reality shows but for a normal election I think walking to the local booth and vote is a much better idea because it is hackers proof and also only citizens with enough motivation will vote.

> Newver understood the fascination with e-votes.

People want convenience. Citizens would like to vote online, and are largely ignorant of the technical challenges that make it impossible to secure, at least on your average everyday Internet connected consumer device.

Its the job of us techies to keep shouting from the rooftops how all these implementations of online voting are deeply flawed and exploitable the same way climatologists have to keep screaming from the rooftops about the damage rising co2 is causing to our biosphere.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#74
post #43

Earlier quoted context omitted.

Now you can demonstrate to anyone what you voted. That's how you get people selling votes. In any reasonable election system you need to be able to be sure your vote is being counted without at the same time being able to prove who you voted for. The demands of voting are incredibly unsuited to digital systems and definitely to any online voting. For every layer of extra complexity you add there's either a way to sub…

You can avoid that, by having your vote correspond to multiple potential entries. But that is still pointless cause the person you sold your vote can be physically next to you, or you can film yourself voting. Online voting is unsafe, and should only be used if any other option is unfeasible.

You can film yourself voting now. Vote buying is not a serious problem, and can be readily solved by stiff jail time for attempting it, and large monetary rewards for reporting on people doing it.

If you get 10 years in prison for trying to buy votes, and the government offers a standing reward of say, $100,000 for evidence that leads to a conviction, all of the sudden you have to pay substantially more than $100k/vote, which means that it's completely impractical to engage in.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#75
post #69

Earlier quoted context omitted.

> Not necessarily. It is possible to have verifiability and receipt freeness I know these methods, but they were not used in OPs suggestion. They fix this issue and introduce others. > Clearly you need to do more research before making such sweeping claims. On the contrary, I'm willing to double down on my claim. I'm willing to provide either a breach or a denial of service for any digital or online voting system you…

> I know these methods, but they were not used in OPs suggestion. You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that. > I'm willing to provide either a breach or a denial of service for any digital or online voting system you care to describe. There are many systems in the literature. What are your credentials in…

> You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that.

This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit.

> There are many systems in the literature. What are your credentials in this field? Are you a cryptanalyst?

There are plenty of systems in the literature, even ones I am happy to stipulate right now are 100% cryptographically sound for the purpose of the discussion. The kinds of attacks you'd use against them are not to break the crypto. They're to break the usage of the system by common citizens and eliminate all trust from the election. Once you do that you no longer have a functioning democracy.

> This is as myopic as saying “E-commerce and e-banking are some of the few situations where the lack of sophistication of pen and paper works in your favor significantly. The demands of e-commerce and e-banking are incredibly unsuited to digital systems and definitely to any online systems.”

eCommerce and eBanking have very different needs, so the query/replace doesn't work. In banking you both accept that some people in the banks have access to your data and that transactions can be reverted. None of that applies to voting where the process has to at the same time avoid leaking who you're voting for, provide accurate counts, and be trusted by the average citizen. Those properties are simply not possible without a traditional paper count done by adversaries.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#76
post #39
post #32

"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…

>few-to-none signs of subversion You could make it so you can view your vote and check it was registered the way intended. If you voted A and it came out B that would be a sign.

"You could make it so you can view your vote and check it was registered the way intended."

Then you have to trust the system to tell you the truth.

These systems can be hacked or just designed to give you false results in the first place.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#77
post #74

Earlier quoted context omitted.

You can avoid that, by having your vote correspond to multiple potential entries. But that is still pointless cause the person you sold your vote can be physically next to you, or you can film yourself voting. Online voting is unsafe, and should only be used if any other option is unfeasible.

You can film yourself voting now. Vote buying is not a serious problem, and can be readily solved by stiff jail time for attempting it, and large monetary rewards for reporting on people doing it. If you get 10 years in prison for trying to buy votes, and the government offers a standing reward of say, $100,000 for evidence that leads to a conviction, all of the sudden you have to pay substantially more than $100k/vo…

Those kinds of penalties and worse don't stop organized crime, for instance.

Politicians also tend to do all sorts of crazy, risky and/or illegal things to get elected or for personal profit. Nixon and Trump spring readily to mind.

If the reward is large enough, someone will risk it. Sometimes the reward doesn't even have to be large at all -- witness rich celebrities shoplifting, for instance.

People can also be compromised and blackmailed in to committing crimes, or otherwise feel desperate and at the end of their ropes, so they'll try anything.

That's to say that such laws shouldn't be made, but I am skeptical that they'll be enough.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#78
post #75

Earlier quoted context omitted.

> I know these methods, but they were not used in OPs suggestion. You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that. > I'm willing to provide either a breach or a denial of service for any digital or online voting system you care to describe. There are many systems in the literature. What are your credentials in…

> You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that. This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit. > There are many systems in the literature. What are your credenti…

> This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit.

Feel free to point out where you previously discussed receipt freeness. And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt free?

> The kinds of attacks you'd use against them are not to break the crypto. They're to break the usage of the system by common citizens and eliminate all trust from the election.

You're going to have to be more specific about what you mean.

> the process has to at the same time avoid leaking who you're voting for

This is called receipt freeness, which we just discussed.

> provide accurate counts

This is called universal verifiability, which is also perfectly attainable by e-voting systems.

> be trusted by the average citizen

You've provided no reason to think that citizens will never trust e-voting systems. The very article of this thread provides a counterexample, and it's not even the most secure.

> Those properties are simply not possible

This is just flat-out wrong. It is perfectly possible to have all of the above properties simultaneously.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#79
post #61
post #44

Earlier quoted context omitted.

This makes voter intimidation much easier though. Nobody without a court order can check how I've voted, and can't ask me to show how I've voted.

It should be impossible even with a court order, and I think most voting systems are set up like that. How else do you guard against the party in power, that can get all the court orders it wants?

It's entirely possible in the UK, while "court order" is probably the wrong terminology, the core meaning is still there. Ballots are numbered and the number recorded against your name. You would need access to both to work out who voted for whom.

I don't know of any reason why it could be accessed, though since parliament is sovereign "if a judge agrees" is always a safe disclaimer to add since the underlying law can be set.

Re: In Estonian parliamentary election, 44% of the votes were cast online

#80
post #52

Here's a video on an interesting talk about Estonia's e-voting system: https://youtu.be/PT0e9yTD2M8 (Spoiler: Opsec fails begins at 42 min. But watch the whole thing, it's interesting.) It might be prudent to point out that Estonia is one of the better e-voting systems. Voters can override their e-vote with a regular one on election day. However that just means that other systems are mostly even worse.

Seems like e-voting is used as a way to transition between a democracy to an hidden totalitarianism.

Citizens are lead to believe the voting system still works as usual but in the fact the results are manipulated to keep the same person or group of people in power. Which can probably last for a while. Meanwhile the person/group in power can take control of all parts of the state until it slowly fades into an obvious dictature.

This works because most people don't understand technology well enough to understand that electronic voting is very far from secure.

Post reply on HN