Earlier quoted context omitted.
Now you can demonstrate to anyone what you voted. That's how you get people selling votes. In any reasonable election system you need to be able to be sure your vote is being counted without at the same time being able to prove who you voted for. The demands of voting are incredibly unsuited to digital systems and definitely to any online voting. For every layer of extra complexity you add there's either a way to sub…
Can't you hash a signature of some manner to your vote in a manner only the individual can know how they voted? After all this is exactly how login/passwords work.
In Estonian parliamentary election, 44% of the votes were cast online
81–90 of 208 posts
Re: In Estonian parliamentary election, 44% of the votes were cast online
#82Earlier quoted context omitted.
It should be impossible even with a court order, and I think most voting systems are set up like that. How else do you guard against the party in power, that can get all the court orders it wants?
It's entirely possible in the UK, while "court order" is probably the wrong terminology, the core meaning is still there. Ballots are numbered and the number recorded against your name. You would need access to both to work out who voted for whom. I don't know of any reason why it could be accessed, though since parliament is sovereign "if a judge agrees" is always a safe disclaimer to add since the underlying law ca…
It's hard for me to express what a terrible idea this is. Pray you never get a government that would exploit this.
Re: In Estonian parliamentary election, 44% of the votes were cast online
#83I like this trend towards e-voting since it seems to be influenced by trends in cutting edge blockchain technology like decentralised autonomous organisations. It means that novel types of national governance may follow from blockchain governance models, such as liquid democracy. This would be a vast improvement over our current representative democracy model since we'd be able to hold politicians accountable more ea…
It's amazing how short-sighted people are.
Re: In Estonian parliamentary election, 44% of the votes were cast online
#84Earlier quoted context omitted.
>few-to-none signs of subversion You could make it so you can view your vote and check it was registered the way intended. If you voted A and it came out B that would be a sign.
Now you can demonstrate to anyone what you voted. That's how you get people selling votes. In any reasonable election system you need to be able to be sure your vote is being counted without at the same time being able to prove who you voted for. The demands of voting are incredibly unsuited to digital systems and definitely to any online voting. For every layer of extra complexity you add there's either a way to sub…
I can do this multiple times. Each time I void my previous ballot, betraying my previous customer.
Then comes election day, then I show up in person and cast a physical ballot for the party that I favor. As a buyer, my customers have no way of knowing I didn’t void the preliminary ballot by showing up on election day.
Note that frauding vote buyers this way is also possible in most election systems that have non-digital preliminaries.
Re: In Estonian parliamentary election, 44% of the votes were cast online
#85Earlier quoted context omitted.
You can avoid that, by having your vote correspond to multiple potential entries. But that is still pointless cause the person you sold your vote can be physically next to you, or you can film yourself voting. Online voting is unsafe, and should only be used if any other option is unfeasible.
You can film yourself voting now. Vote buying is not a serious problem, and can be readily solved by stiff jail time for attempting it, and large monetary rewards for reporting on people doing it. If you get 10 years in prison for trying to buy votes, and the government offers a standing reward of say, $100,000 for evidence that leads to a conviction, all of the sudden you have to pay substantially more than $100k/vo…
Re: In Estonian parliamentary election, 44% of the votes were cast online
#86Earlier quoted context omitted.
>few-to-none signs of subversion You could make it so you can view your vote and check it was registered the way intended. If you voted A and it came out B that would be a sign.
This makes voter intimidation much easier though. Nobody without a court order can check how I've voted, and can't ask me to show how I've voted.
Re: In Estonian parliamentary election, 44% of the votes were cast online
#87"The system has been designed to ensure that voters' computers are not infected by any kind of malware that could change or block their vote." I'm sure this cannot be subverted by an attacker with the resources of USA/China/India/.., or with access to the supply chain from the chip fab onward (don't forget about malware hidden in USB cables!), or or,... And you'd have to be dead sure , because, unlike with physical v…
My main criticism is that as it is it could still feed the card with the wrong vote to sign. The (state-provided) USB reader should have a small lcd screen to sum up the thing being signed "Vote for Ms.Ryjavik on election #123" "Vote for Yes on vote #432" and a confirmation button.
With these modifications, and the ability to check a cast vote has been received, you can have secure elections on insecure devices.
However it requires trust in the officials to do their jobs correctly and to not tamper the tally.
I, personally, love a lot of e-Estonia initiatives, but consider electronic voting to be a bad idea, unless you are ready to get rid of the anonymity of the vote (you can have secure non-anonymous remote voting)
Re: In Estonian parliamentary election, 44% of the votes were cast online
#88Earlier quoted context omitted.
> You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that. This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit. > There are many systems in the literature. What are your credenti…
> This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit. Feel free to point out where you previously discussed receipt freeness. And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt fr…
I'm not going to go around spelunking on my old comments to prove to you that your attacks on me are unfounded. Do your own homework if you care about this for some reason but this is getting extremely aggressive for no reason.
> And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt free?
The point of my comment was to explain that what appears to be a common solution to a problem that we'd use in any kind of electronic system breaks down other stuff in electronic voting. I wasn't about to go 10 rounds of "but you could do X and then be broken by Y". My point isn't that there aren't clever ways to engineer digital systems for electronic voting, is that however you do that you end up with something that can be attacked in horrible ways. See below for an example.
> You're going to have to be more specific about what you mean.
Since you haven't provided a voting system for me to attack I'll try with what I consider to be a very good one:
- You vote by pressing a button or touchscreen at your polling place
- A paper ballot is printed with your vote that you verify and drop into a traditional ballot box to be counted as usual
- A receipt is printed with some code that you can later use to check that your vote was counted in a cryptographically secure way
- Paper ballots are tallied locally as usual, electronic results are sent encrypted to a central server that can be later used for vote count verifications
- The electronic count and the paper count are done in parallel and both published. You expect small differences in the count (mostly from human error in the paper count) but as long as the results match up to a low difference you trust your election.
- There are no flaws in any of the crypto and all the polling officials are honest (this last part is something the paper system does not depend on)
So this seems strictly better than a paper election right? You get the electronic count just as the polls close, the safety that you can later check that your vote was counted electronically, and the double-check of the paper count to fall back on. So here's how I attack it if I'm just a skilled hacker working alone:
- Work as a tech at one of the polling places and intentionally miscalibrate touchscreens. People will register wrong results and get some stories out that strange things happened in some polling places.
- Pick polling places where a minority is heavily represented and break those machines in particular. At worst some extra coverage, at "best" the election gets skewed because those polling places start having long lines and people walk away.
- Spread some malicious code to the general population through any of the normal means (Android apps, unpatched vulnerabilities, etc). I just need to get a small number of common citizens. Have that code intercept the place where you check if your vote was counted and tell you it was not. Hopefully you'll recheck in a clean machine and be satisfied. If possible target politicians and the actual losing candidates in the election so that they are particularly worried that the election was stolen from them.
- Finally hack into the central server where you do the checks to see if your vote was counted and make checks fail randomly.
At the end of this you have seeded pretty deep distrust over the election. Depending on how skilled the hacking is it may be enough to break down the trust in your democracy. I'm not willing to take that risk. But now if you're a very well funded hacker group or a state actor you can do more:
- Hack the network providers and selectively DoS the verification server for minorities or parts of the country that voted against the winner.
- Infiltrate the supply chain of a few of the thousands of suppliers of the voting machines and plant hardware level bugs that are time coded or just cause random errors (e.g., the touchscreen bugs)
- Hack the networks used to communicate votes from polling places and DoS those so that the count is delayed
- If you can hack the power grid have power cuts in polling places. If you were voting on paper it wouldn't matter but now you can't vote
- Do all those again in targeted polling places looking for minorities and/or populations that are very skewed from the national average to entice maximum distrust
- After enough doubt is created manipulate social networks based on those cases to nudge the population into thinking the election is rigged. It only takes a small percentage of the population believing that before you have a crisis on your hands (think yellow vests in Paris).
At the end there's a very high chance your election is now fully distrusted and the country is in chaos. Even if it doesn't work 100% of the time it only takes one or two successful events globally for people to distrust these systems, whichever they are.
The scary thing about what I just described is that plenty of it is indistinguishable from what is already happening in some cases in US elections today. I'm willing to hope that the US case is just pure incompetence, but the attack surface is very large and we've seen that foreign state actors are extremely motivated to meddle with elections. I expect more examples of this in the future, particularly since the actual systems deployed are incredibly poor compared to this one.
> This is called receipt freeness, which we just discussed. > This is called universal verifiability, which is also perfectly attainable by e-voting systems.
Yep both of these are possible as long as the crypto is sound. No current electronic voting system actually clears that bar, most have no crypto at all. But there's no reason you couldn't do it at enormous extra cost if you had enough extremely competent people dedicated to the problem. I still haven't seen a good argument why you'd want to though. Which is the second part of this problem. If there are no advantages why do it? Proper paper counts are cheap, well tested and get results 2 or 3 hours after the polls close. The US is notorious for not being able to do that but it's routinely done across the world with no issues.
> You've provided no reason whatsoever to believe that citizens will never trust e-voting systems, and there is strong evidence against this from the fact that they are perfectly willing to engage in e-commerce and e-banking.
See the above attack scenarios for why I definitely think citizens should never trust any electronic voting system. The difference for eCommerce and eBanking is that under any of those attack scenarios you just go to the bank branch and sort things out, including reverting transactions. You can't do that with your vote. Once the verification system fails the whole election fails and the faith in your democracy plummets. None of those attacks are specific to this system either. They're just relying on the flexibility of computers versus the extreme lack of features of pen and paper.
> This is just flat-out wrong and reflects your ignorance of the subject. It is perfectly possible to have all of the above properties simultaneously.
At this point it's on you. Feel free to improve on the above system to try to get the three properties. It's extremely unlikely you'll be able to just from the nature of computers and computer networks. We put up with all their extra complexity for all the extra value they bring. I couldn't be having this discussion with a person I don't know that is most likely half way across the world without the internet. But all that complexity plays against you when you're trying to secure a vote. You don't need to change the vote to destroy an election. You just have to seed enough distrust that the process is no longer accepted.
The most important characteristic of the voting process is that you are able to convince those who lost that they've really lost and what computers/networks have in abundance is failure modes and corner cases. Couple that with the lack of knowledge of the general population (and certainly of most politicians) about technology and it's very easy to attack an election by just engineering doubt over the whole system even if all the failures that you induce were designed for.
Re: In Estonian parliamentary election, 44% of the votes were cast online
#89Earlier quoted context omitted.
It's not about being safe, it's about being provably shareable. When the option of privately sharing your vote is there, it doesn't take long before a malicious candidate forces you to do it or face consequences. See Halter Vote: https://books.google.com.br/books?id=7gPvCgAAQBAJ&pg=PT144&l... https://translate.google.com/translate?source=osdd&sl=auto&t...
But couldn't you just take a photo of the ballot? Considering that not submitting the ballot after taking it is not allowed here.