Live data from Hacker News

Protecting democratic elections through secure, verifiable voting

blogs.microsoft.com

101–110 of 177 posts

Re: Protecting democratic elections through secure, verifiable voting

#101
post #35

I shall repeat it like a mantra: voting beeing slow inefficient is a side effect of it’s transparency. You want a voting system were a average voting helper can look at it and say: “There was nothing fishy there, I saw it”. This is because it is about trust and not only about secrecy and security. Your electronic voting system can be mathematically perfect, but if nobody average can say from the outside that everythi…

Went to a conference in 1993 or thereabouts, put on by a now defunct organization called "CPSR" (Computer Professionals for Social Responsibility). I rememeber Phil Zimmerman was a speaker. Anyway, one of the topics was the problem of electronic voting.

About 10 years later...

Underhanded V Contest http://graphics.stanford.edu/~danielrh/vote/vote.html

(If I remember correctly, the "Underhanded C Contest" came later.)

http://lcamtuf.coredump.cx/soft/vote.c

Now, a Microsoft SDK with a catchy name, "Defending Democracy".

What next?

Re: Protecting democratic elections through secure, verifiable voting

#102
post #28

It certainly has nothing to do with democracy, and intended to solve exactly one problem: Microsoft's need to increase revenue through sweet gov't funded contracts. Let's not be fooled by opensourced code, once the idea is sold to politicians, and media, someone should be contracted to implement this useless staff. And who's this going to be? Not hard to guess.

While I appreciate the cynicism, I'm not seeing how an open schema for tamper-evident verifiable voting machines could be anything other than positive. It's worth noting that Microsoft has discouraged the use of embedded Windows on voting machines in the past: https://www.infoworld.com/article/2680658/gates-undaunted-by... > “We ourselves are not going after the e-voting market or the nuclear reactor control market,”…

For starters, the whole voting machines concept is a essentially a ploy to exploit wide-spread respect for computer technologies in society to sell hardware, and software. It reduces observability compared to pieces of paper, and doesn't solve any real problems.

I don't think Gates words from 2004 can be seen as policy statement for today's Msft. Apparently, a lot has changed.

Re: Protecting democratic elections through secure, verifiable voting

#103

It certainly has nothing to do with democracy, and intended to solve exactly one problem: Microsoft's need to increase revenue through sweet gov't funded contracts. Let's not be fooled by opensourced code, once the idea is sold to politicians, and media, someone should be contracted to implement this useless staff. And who's this going to be? Not hard to guess.

So therefore it's better if they didn't do this, is your conclusion?

The simple truth is that society doesn't need computerized voting technologies to have fair elections.

Re: Protecting democratic elections through secure, verifiable voting

#104
post #79
post #35

I shall repeat it like a mantra: voting beeing slow inefficient is a side effect of it’s transparency. You want a voting system were a average voting helper can look at it and say: “There was nothing fishy there, I saw it”. This is because it is about trust and not only about secrecy and security. Your electronic voting system can be mathematically perfect, but if nobody average can say from the outside that everythi…

Also prevent uninterested, lazy, people from voting out of spite. I know it's unpopular to say, but I don't think it's a bad thing that voting requires personal (strictly personal; no corporation should get in your way) effort.

I agree. I never understood the notion of same-day registration, nor the constant blasting of voting reminders for months before the midterms. Do we really want people who have to be extremely convinced to vote, to vote? Do we really want people who didn't care at all, got convinced by one team the day of, and decided to vote on a whim, to vote? Thus, are the votes from people who had to be reminded on twitter and google to vote, "real" votes? Or were they gamed?

Re: Protecting democratic elections through secure, verifiable voting

#105
Can someone smarter than me explain if this system maintains anonymity?

To a layperson, statements like the one below raise a flag. If I can track it electronically, is it also possible for someone else to see who voted for whom?

"After the election is complete, the tracker codes can be used by voters to confirm that their votes were not altered or tampered with and that they were properly counted"

Again, to a layperson the above statement seems potentially at odds with the one below at first blush (because I don't understand the technology):

"With homomorphic encryption, individually encrypted votes can be combined to form an encrypted tabulation of all votes which can then be decrypted to produce an election tally that protects voter privacy."

So we have privacy but electronic traceability to the individual voter? To the uninitiated like myself, it seems like we'd have to choose between electronic traceability and anonymity.

Re: Protecting democratic elections through secure, verifiable voting

#106
post #82

Earlier quoted context omitted.

Paper ballots are vulnerable to systemic voter suppression of the kind that’s hard to eliminate. Voter ID laws. Complicated ballots. Overloaded polling stations. Worst, all these weaknesses are difficult to eliminate because they are both difficult to sincerely debate and difficult to generate the public interest necessary to generate enough activism. Electronic voting can reduce the friction enough to where we can a…

These are mostly solved problems in all western nations (except for the US). E.g. I am Austrian living in Germany and I vote by mail since a decade. Mail voting has the downside that it invites the kind of problems where some guy tricks elderly people into giving them their vote etc. But all in all it works quite well.

>>> These are mostly solved problems in all western nations (except for the US). E.g. I am Austrian living in Germany and I vote by mail since a decade.

The US has had vote-by-mail for as long as I can remember [0]... So what is an example of a "mostly solved problems in all western nations (except for the US)" other than an example that you posted that is inaccurate?

I'm not arguing that we have solved all election problems, but it's unfair to say we haven't solved something and share a solution that your country has that our country has too. Maybe Austria does something different with their vote-by-mail system than what the US does, if so please share what that is.

[0]https://dos.myflorida.com/elections/for-voters/voting/vote-b...

Re: Protecting democratic elections through secure, verifiable voting

#108
post #12

The mechanism for voter verification is based on homomorphic encryption. Numberphile made a video on this topic recently, with a few basic explainers: https://www.youtube.com/watch?v=BYRTvoZ3Rho

Very related: Why Electronic Voting is a BAD Idea - Computerphile:

https://www.youtube.com/watch?v=w3_0x6oaDmI

Re: Protecting democratic elections through secure, verifiable voting

#109

Earlier quoted context omitted.

The correctness of cryptographic voting systems is determined by their publicly observable behavior, not by their internal implementation. It's the protocol that's secure, not the specific hardware or software implementation. So the attack you're describing doesn't really apply.

But you cannot observe it. You see that someone with a hash X has voted. How do you know whether it was a real person, a real person voting under boss supervision, a real person who actually didn't take part in elections, or just sysadmin inserting records into the database?

That question applies equally to a paper ballot.

Re: Protecting democratic elections through secure, verifiable voting

#110
For the most part, this seems like a pretty reasonable application of homomorphic cryptography to act as an extra voting record. Like others here I think it would need to be secondary to the paper voting record, and I worry that would be hard to enforce forever.

But one line stands out as particularly troubling:

Our sample reference will showcase how people can make their selections at home, where they can easily research their choices, then bring a QR code to the polling place to scan and pre-populate their ballot.

On the one hand, I support the goal of making it easier for people to research and select their choices. But the risk of enabling a "scan-to-vote" operation is pretty clear: voters will be given their QR codes pre-populated by some interested third party.

Post reply on HN