Live data from Hacker News

Protecting democratic elections through secure, verifiable voting

blogs.microsoft.com

11–20 of 177 posts

Re: Protecting democratic elections through secure, verifiable voting

#11
post #10
post #3

>After the election is complete, the tracker codes can be used by voters to confirm that their votes were not altered or tampered with and that they were properly counted. So what's preventing vote-buying schemes?

That's a great point. If I understand correctly schemer could agree to pay for votes, but had no way to verify the ballot was indeed cast for that candidate. With this system they could first verify the vote before paying. It's made possible by the information which is used to verify the vote. It's supposed to be kept secret by the vote, but could be shared with the schemer in order to get paid. This would make vote-…

Whether or not a person voted in a given election is already public knowledge. How does this scheme give an attacker any more information than that?

If you're willing to assume the attacker is into the voting booth, you're no worse off with this.

Re: Protecting democratic elections through secure, verifiable voting

#13
post #11
post #10

Earlier quoted context omitted.

That's a great point. If I understand correctly schemer could agree to pay for votes, but had no way to verify the ballot was indeed cast for that candidate. With this system they could first verify the vote before paying. It's made possible by the information which is used to verify the vote. It's supposed to be kept secret by the vote, but could be shared with the schemer in order to get paid. This would make vote-…

Whether or not a person voted in a given election is already public knowledge. How does this scheme give an attacker any more information than that? If you're willing to assume the attacker is into the voting booth, you're no worse off with this.

Because they can ask to verify.

Re: Protecting democratic elections through secure, verifiable voting

#14

I don't understand how counting verification is achieved. Let's say that election officials release a list of hashed votes, so that you can verify that your vote has been counted and included into results. But how can you check that all other votes in the list are the votes from real people and not arbitrarily added by sysadmin to get the expected result? Does anyone know how such things are implemented? I have read…

Who voted is public record (depending on your state [1]), so the numbers should add up.

[1] https://www.nytimes.com/2018/11/04/us/politics/apps-public-v...

Re: Protecting democratic elections through secure, verifiable voting

#17
post #11

Earlier quoted context omitted.

Whether or not a person voted in a given election is already public knowledge. How does this scheme give an attacker any more information than that? If you're willing to assume the attacker is into the voting booth, you're no worse off with this.

Because they can ask to verify.

Imagine I ask the voting machine to give me 100 sealed envelopes with "Alice" written in them and 100 sealed envelopes with "Bob" written in them. I open and destroy 199 of them, verify that Alice votes are Alice votes and Bob votes are Bob votes. I then walk out of the voting booth with a sealed Alice envelope, then deposit it into the ballot box.

That's the "verifiable" step in here.

The only way for you to know who I voted for is if you were in that booth with me.

Re: Protecting democratic elections through secure, verifiable voting

#18
It certainly has nothing to do with democracy, and intended to solve exactly one problem: Microsoft's need to increase revenue through sweet gov't funded contracts. Let's not be fooled by opensourced code, once the idea is sold to politicians, and media, someone should be contracted to implement this useless staff. And who's this going to be? Not hard to guess.

Re: Protecting democratic elections through secure, verifiable voting

#20

I don't understand how counting verification is achieved. Let's say that election officials release a list of hashed votes, so that you can verify that your vote has been counted and included into results. But how can you check that all other votes in the list are the votes from real people and not arbitrarily added by sysadmin to get the expected result? Does anyone know how such things are implemented? I have read…

Who voted is public record (depending on your state [1]), so the numbers should add up. [1] https://www.nytimes.com/2018/11/04/us/politics/apps-public-v...

What if it is not a public record? Also, even if it is a public record, how can you be sure that people in the voters list are real, they are eligible to vote in this region and not made up by authorities?

Also, even if the list of people who voted is public, and if results were falsified, with electronic voting you cannot estimate the scale of falsification. Did they alter just a hundred of votes or hundred thousands.

Post reply on HN