Live data from Hacker News

Protecting democratic elections through secure, verifiable voting

blogs.microsoft.com

141–150 of 177 posts

Re: Protecting democratic elections through secure, verifiable voting

#141

Earlier quoted context omitted.

The correctness of cryptographic voting systems is determined by their publicly observable behavior, not by their internal implementation. It's the protocol that's secure, not the specific hardware or software implementation. So the attack you're describing doesn't really apply.

But you cannot observe it. You see that someone with a hash X has voted. How do you know whether it was a real person, a real person voting under boss supervision, a real person who actually didn't take part in elections, or just sysadmin inserting records into the database?

- You see the number of records aggregated, it should not exceed the amount of voters

- You can somehow identify your own vote and thus verify it was properly counted

- Everyone else can do the same, thus fraudsters would have to find a protocol weakness to add additional votes

One attack vector might be whatever you use to identify your vote. Aka find a way to make two people think the same record is their own vote, then use the other yourself. This seems like a tricky problem, since everyone shouldn't just be able to see their own vote was included but also not not be able to show others how you voted. The article seems to indicate they solved this somehow, but I'm not familiar enough with the details / homomorphic encryption to understand that or even just trust that specific kind of encryption.

Re: Protecting democratic elections through secure, verifiable voting

#142

Earlier quoted context omitted.

> Just so the results of voting can be displayed on TV a bit earlier, we are supposed to accept substantial risks to democracy You already accept the influence of corporate PACs, which arguably are a much bigger threat to democracy. Not saying you should add another vector, (electronic voting), just that the argument that there's a solid democratic system now is not quite true.

A corporate PAC is simply a group of people joining together to create political speech, with the added legal protection of incorporation. The Citizens United case was in direct response to the FEC approving nearly all corporate speech from liberal sources, while stopping conservative versions. Explicitly in the Michael Moore v Citizens United FEC complaints. Nothing changed for liberals voices in Citizens United, on…

that is a version of the story I never heard before!

Can you share some links?

Re: Protecting democratic elections through secure, verifiable voting

#143
post #105

Can someone smarter than me explain if this system maintains anonymity? To a layperson, statements like the one below raise a flag. If I can track it electronically, is it also possible for someone else to see who voted for whom? "After the election is complete, the tracker codes can be used by voters to confirm that their votes were not altered or tampered with and that they were properly counted" Again, to a layper…

The system does not ensure anonymity as to who has voted , but it does maintain secrecy as to how you voted . The idea is that you can have a public, verifiable "ledger" of voters. You can verify that you are on the list with your encrypted vote. I.e. you verify that your vote counts. You can match it to the receipt you received when voting. You do not, however possess the key to decrypt your vote or the vote of anyo…

Thank you for taking the time to clarify. So if I understand this correctly, the system can allow an individual to verify that their vote was counted but not validate that the vote was counted correctly?

From that perspective, it seems analogous to the system in use but perhaps more efficient. In other words, does this actually introduce any new features or just translate the existing features of the current system to a new medium?

Re: Protecting democratic elections through secure, verifiable voting

#144

Earlier quoted context omitted.

Electronic voting may be a harder to implement solution in terms of trust but the problem is not non-existent. Voting today is a complex and costly process. Hence, it cannot be carried out frequently and hence the accountability/ feedback loop is slower. Imagine if we could conduct voting in a day (even in large democracies). We would be able to remove bad representatives faster.

> Imagine if we could conduct voting in a day (even in large democracies). That would be horrible. "direct democracy" does not work (Switzerland is also a representative democracy), practical policy making requires some domain knowledge, patience and the ability to make compromises that the Internet mob could not possibly deliver. People are generally very good at judging the trustworthiness of other people, however,…

Have you seen who represents the people?

just have a test we can take to illustrate competence in a domain. Passing the test grants us the right to vote on laws in that domain.

Then, those who represent us are those who have illustrated the intellectual capacity to make good decisions.

Re: Protecting democratic elections through secure, verifiable voting

#146

For the most part, this seems like a pretty reasonable application of homomorphic cryptography to act as an extra voting record. Like others here I think it would need to be secondary to the paper voting record, and I worry that would be hard to enforce forever. But one line stands out as particularly troubling: Our sample reference will showcase how people can make their selections at home, where they can easily res…

Yes, but there is no proof that the user actually used that QR to make their vote. This diminishes the incentive to buy votes because there is no verifiable proof of how someone voted. I'm not saying it's a perfect solution, but it's more secure than mail-in ballots, which are currently in use and popular in many locations.

The issue isn't that someone can force you to vote a certain way or check that you voted in some way. The issue is that someone can make it outrageously convenient for you to make a whole set of uninformed votes.

Imagine you're very busy and haven't spent the time yet to figure out what to vote for. Someone tells you that if you vote a certain way, it will be great for a certain pet issue that you care about, and they give you (and many others) a QR code. The QR code contains a vote for one candidate who cares about the pet issue, but the rest of the votes in the QR code are all oriented around a different issue that you don't know about, don't care about, or actively care the other way about, but you don't notice and scan it and vote it as-is.

Mail-in ballots don't have that issue.

Re: Protecting democratic elections through secure, verifiable voting

#147
post #35

I shall repeat it like a mantra: voting beeing slow inefficient is a side effect of it’s transparency. You want a voting system were a average voting helper can look at it and say: “There was nothing fishy there, I saw it”. This is because it is about trust and not only about secrecy and security. Your electronic voting system can be mathematically perfect, but if nobody average can say from the outside that everythi…

Electronic voting is the classical solution to a nonexistent problem. Just so the results of voting can be displayed on TV a bit earlier, we are supposed to accept substantial risks to democracy posed by blatantly insecure endpoints, blatantly insecure company infrastructure, insecure network communications and devices (routers, etc.), private companies that often have a track record of insecure and sloppy programmin…

A bit earlier?

Election recounts were triggered and entire countries and regions were affected because a recount couldn’t be completed in time.

Take for example Al Gore vs George W Bush: https://m.youtube.com/watch?v=qcz6NSyxrfQ

Because the recount was stopped earlier than it could be completed, Bush became President, stopped watching Bin Laden and we got 9/11, then invaded Iraq and Afghanistan and the entire region was heavily destabilized and overrun with Islamic terrorists. The largest geopolitical disaster of the last 50 years with effects as far reaching as Syrian civil war, Libyan anarchy, and millions of refugees and families broken.

If only a recount could have been done faster...

Re: Protecting democratic elections through secure, verifiable voting

#148
post #35

I shall repeat it like a mantra: voting beeing slow inefficient is a side effect of it’s transparency. You want a voting system were a average voting helper can look at it and say: “There was nothing fishy there, I saw it”. This is because it is about trust and not only about secrecy and security. Your electronic voting system can be mathematically perfect, but if nobody average can say from the outside that everythi…

Has anybody even read the article? Jesus. Your comment is a complete non-sequiter. There are two ENTIRELY UNRELATED questions. One question is "cryptographic verification." One is "Paper/electronic" You can have any combination. You can have a crypographical, verifiable, PAPER voting system, for example (and that's what this article is about).

Did you read the comment you're replying to? Its whole point is that lay people don't understand sophisticated cryptography like homomorphic encryption, which makes it difficult to trust, whereas they do understand and trust paper. A cryptographic paper voting system that required advanced math to understand would have the same legitimacy problem as a cryptographic electronic voting system.

Re: Protecting democratic elections through secure, verifiable voting

#150

I've been accumulating a mental list of properties that would support less-exploitable, more-auditable paper balloting. This has a surprising number of the properties. The main items I don't see represented are all roughly related to auditability for ballot chain of custody. I think issues/irregularities with the ballot chain of custody are probably good proxies for triaging hand-audit efforts. The goal is knowing wh…

I think the whole point of this fancy homomorphic encryption-based system is that only the endpoints need to be verifiable, you no longer have to worry about chain of custody anymore. Kinda like how end-to-end encryption means you no longer have to trust every link in the network that connects you to the other party.

As long as you can verify that the final tally is correctly calculated from all the public encrypted votes, that those encrypted votes include yours, and none are by fake voters, who cares how the encrypted votes are transmitted to the body that officially calculates the final tally?

Post reply on HN