Live data from Hacker News

Protecting democratic elections through secure, verifiable voting

blogs.microsoft.com

131–140 of 177 posts

Re: Protecting democratic elections through secure, verifiable voting

#131

For the most part, this seems like a pretty reasonable application of homomorphic cryptography to act as an extra voting record. Like others here I think it would need to be secondary to the paper voting record, and I worry that would be hard to enforce forever. But one line stands out as particularly troubling: Our sample reference will showcase how people can make their selections at home, where they can easily res…

Yes, but there is no proof that the user actually used that QR to make their vote. This diminishes the incentive to buy votes because there is no verifiable proof of how someone voted.

I'm not saying it's a perfect solution, but it's more secure than mail-in ballots, which are currently in use and popular in many locations.

Re: Protecting democratic elections through secure, verifiable voting

#132
post #54

Earlier quoted context omitted.

The correctness of cryptographic voting systems is determined by their publicly observable behavior, not by their internal implementation. It's the protocol that's secure, not the specific hardware or software implementation. So the attack you're describing doesn't really apply.

Having a cryptographically secure voting protocol doesn't protect you if the human-computer interface is compromised to alter the votes as they are being entered into the system. You get a code to verify that "your" vote was counted correctly, but because you're not supposed to be able to prove who you voted for to prevent vote-buying, you can't tell that the voting machine has slipped you the wrong code. It may not…

Homomorphic cryptography allows you to track your vote without revealing the vote content (who you votes for), but at the same time vote tallying is possible on the encrypted votes in a process that is verifiable.

Of course the trust only comes with understanding of the mathematics.

Re: Protecting democratic elections through secure, verifiable voting

#133

Earlier quoted context omitted.

Electronic voting is the classical solution to a nonexistent problem. Just so the results of voting can be displayed on TV a bit earlier, we are supposed to accept substantial risks to democracy posed by blatantly insecure endpoints, blatantly insecure company infrastructure, insecure network communications and devices (routers, etc.), private companies that often have a track record of insecure and sloppy programmin…

> Electronic voting is the classical solution to a nonexistent problem. That is incorrect. Voting is a feedback loop for the will of the voters. The slower the process is, the less representative it is. The fidelity of the loop is paramount, but the issue remains. EDIT: do the downvoters understand that there is setup involved in a paper process and getting results is not the end of the feedback loop (not race)? SMH

> Voting is a feedback loop for the will of the voters

Why should it go on both direction ? Even if it's true, is it a good thing ? You should change your opinion if you hear good arguments and not because you want to vote like the others.

Re: Protecting democratic elections through secure, verifiable voting

#134
I've been accumulating a mental list of properties that would support less-exploitable, more-auditable paper balloting. This has a surprising number of the properties.

The main items I don't see represented are all roughly related to auditability for ballot chain of custody. I think issues/irregularities with the ballot chain of custody are probably good proxies for triaging hand-audit efforts.

The goal is knowing when ballots go missing, or turn up in unexpected places (but I'm not sure where the sweet spot is for securing that chain without making individual votes unmaskable). I think it's a similar process, with lots of identifiers, and lots of scanning. It would live or die by rapid, simple, reliable scanning.

This means scanning identified ballots into shipping boxes, and generating an identifier for the box based on which ballots were scanned in. A pallet gets an identifier based on the boxes that went in. Shipments get identifiers based on whatever combination of boxes/pallets they contain. Scan in boxes at the polling station and accumulate identifiers for the polling place. Perhaps per poll worker. Scan ballots out of the boxes, back into the completed-ballot boxes and/or trash. Cumulative identifiers for completed-ballot boxes, trashed ballots, and unused ballots are scanned back out of the poling place and at each step back up the chain again.

Re: Protecting democratic elections through secure, verifiable voting

#135

Earlier quoted context omitted.

Depends if "electronic voting" means "in-person voting at polling stations with existing polling cards and polling booths, but replace paper ballots with touchscreen vote-counting machines" or if it means "Voting by smart phone" Although there are downsides to vote-by-smartphone, an advocate would argue you should compare it to vote-by-mail rather than vote-in-person, given that almost every election allows vote-by-m…

Smartphone voting sounds like a recipe for disaster. The fact that votes are cast in private in an otherwise public place is part of what makes the system work. If you let a large number of people vote remotely, you have zero certainty that a) the voters weren't pressured into voting a certain way, say by a domineering parent or b) that the device wasn't compromised.

Personally I agree and am not an advocate of smartphone voting.

However, I can tell you what someone who was an advocate of smartphone voting would say.

To (a) they would say we already allow postal votes, so the pressure/vote-selling is already with us; and furthermore although the pressure/vote-selling is bad for democracy, low turnout and voter suppression like making polling stations hard to access are worse.

To (b) they would say if Apple Pay can be secure, so can online voting. Maybe even more secure! I mean, in my country the ruling party doesn't have enough members to put an activist in each polling station watching the ballot box, even if they worked a 15-hour shift without toilet breaks. So it's not like the current system offers total protection against fraud.

Re: Protecting democratic elections through secure, verifiable voting

#136
post #82

Earlier quoted context omitted.

These are mostly solved problems in all western nations (except for the US). E.g. I am Austrian living in Germany and I vote by mail since a decade. Mail voting has the downside that it invites the kind of problems where some guy tricks elderly people into giving them their vote etc. But all in all it works quite well.

>>> These are mostly solved problems in all western nations (except for the US). E.g. I am Austrian living in Germany and I vote by mail since a decade. The US has had vote-by-mail for as long as I can remember [0]... So what is an example of a "mostly solved problems in all western nations (except for the US)" other than an example that you posted that is inaccurate? I'm not arguing that we have solved all election…

The US doesn't have vote-by-mail, we have mail-in absentee ballots and they're intended to be a last resort. You can only request an absentee ballot if you're unable to vote in person. You can't request an absentee ballot simply because it's more convenient.

Re: Protecting democratic elections through secure, verifiable voting

#137
post #108
post #12

The mechanism for voter verification is based on homomorphic encryption. Numberphile made a video on this topic recently, with a few basic explainers: https://www.youtube.com/watch?v=BYRTvoZ3Rho

Very related: Why Electronic Voting is a BAD Idea - Computerphile : https://www.youtube.com/watch?v=w3_0x6oaDmI

no its not.

Re: Protecting democratic elections through secure, verifiable voting

#138

Earlier quoted context omitted.

>>> These are mostly solved problems in all western nations (except for the US). E.g. I am Austrian living in Germany and I vote by mail since a decade. The US has had vote-by-mail for as long as I can remember [0]... So what is an example of a "mostly solved problems in all western nations (except for the US)" other than an example that you posted that is inaccurate? I'm not arguing that we have solved all election…

The US doesn't have vote-by-mail, we have mail-in absentee ballots and they're intended to be a last resort. You can only request an absentee ballot if you're unable to vote in person. You can't request an absentee ballot simply because it's more convenient.

That is an incorrect statement in many states. [0] I voted by mail in Colorado in elections that were held at least 20 years ago. [1]

[0] http://www.ncsl.org/research/elections-and-campaigns/all-mai...

[1] https://www.sos.state.co.us/pubs/elections/FAQs/mailBallotsF...

Re: Protecting democratic elections through secure, verifiable voting

#139
post #105

Can someone smarter than me explain if this system maintains anonymity? To a layperson, statements like the one below raise a flag. If I can track it electronically, is it also possible for someone else to see who voted for whom? "After the election is complete, the tracker codes can be used by voters to confirm that their votes were not altered or tampered with and that they were properly counted" Again, to a layper…

The system does not ensure anonymity as to who has voted, but it does maintain secrecy as to how you voted.

The idea is that you can have a public, verifiable "ledger" of voters. You can verify that you are on the list with your encrypted vote. I.e. you verify that your vote counts. You can match it to the receipt you received when voting. You do not, however possess the key to decrypt your vote or the vote of anyone else.

The public list can also be used (more work) to verify that only real people voted: They could presumably be contacted.

Homomorphic encryption allows the votes to be tallied while still encrypted. The result is an encrypted tally.

At this point someone with the decryption key can decrypt the final tally and reveal the result. Presumably this can happen per polling place.

Re: Protecting democratic elections through secure, verifiable voting

#140
post #35

I shall repeat it like a mantra: voting beeing slow inefficient is a side effect of it’s transparency. You want a voting system were a average voting helper can look at it and say: “There was nothing fishy there, I saw it”. This is because it is about trust and not only about secrecy and security. Your electronic voting system can be mathematically perfect, but if nobody average can say from the outside that everythi…

Electronic voting is the classical solution to a nonexistent problem. Just so the results of voting can be displayed on TV a bit earlier, we are supposed to accept substantial risks to democracy posed by blatantly insecure endpoints, blatantly insecure company infrastructure, insecure network communications and devices (routers, etc.), private companies that often have a track record of insecure and sloppy programmin…

The problem is cost, which electronic voting solves to some degree.
Post reply on HN