Live data from Hacker News

USPS Files Patent for a Blockchain-Based Voting System

heraldsheets.com

61–70 of 390 posts

Re: USPS Files Patent for a Blockchain-Based Voting System

#61
post #48

Am I the only one still against network-based, and to a lesser extent electronic-based, voting? It's near impossible to rig or suppress a physical election without a lot of effort, but one person can DDoS an entire network and no one can vote and the whole election needs to be scrapped. Not even the strongest cryptographic or software systems are free from exploits (especially over time) and there's no way to be sure…

You can read a some of my comments in this thread addressing various concerns. That said, I would still agree. At least for the next 5-10 years (until we have Starlink-level internet and advances in cryptography/UX), electronic voting systems are not feasible. The nice thing about blockchains is you can avoid DDoS by only allowing people who are "authorized" to "talk to" the blockchain. This can be done by ensuring t…

It's worth working on to be sure. Another thing I think is worth working on is educating people on what blockchain actually is (which it seems you are doing). I think paper voting works primarily because people know and trust how the votes are counted and how they get to the counters, for the most part. But personally I barely understand transistors and flip flops let alone blockchain and that makes me slightly worried about how it might be possible to exploit them.

Re: USPS Files Patent for a Blockchain-Based Voting System

#63

Earlier quoted context omitted.

I strongly disagree. This is a comment from someone who (I presume) is unaware of the advances in Proof-of-Stake blockchains, and other consensus protocols like the Stellar Consensus Protocol. Databases do not have a distributed way to manage consensus - one of the main things that sets a blockchain apart from a distributed database. This consensus mechanism is what's important when something important (like an elect…

Stellar operates on the basis of trust in a third party [1]. The jury is still out on proof of stake blockchains like Casper [2] [1] https://stellar.stackexchange.com/questions/160/how-does-the... [2] https://medium.com/@muneeb/peer-review-cbc-casper-30840a98c8...

If you define "third party" as your first link does, everything relies on trust in a third party. The counting of ballots also relies on a third party, albeit a less homogenous and "centralized" third party (though that term is also hard to define).

The difference is that a public blockchain provides an open and auditable overview of the actions of the third party, and what the state of the entire "database" is. This is something that a Merkle tree whose root is published in a newspaper once a week can't achieve (an anecdote from a story Roberto Di Cosmo of the Software Heritage Foundation told me).

To your second link — I'm not arguing for such a system today. Of course there are many roadblocks and hurdles in getting to full proof-of-stake or full "decentralization". But in 5-10 years I'm sure we'll be there. There are hundreds of teams, from Algorand to Casper to Ethereum, working on this issue.

Re: USPS Files Patent for a Blockchain-Based Voting System

#64
post #54

What is wrong with in-person paper-ballots? They have worked for centuries. And continue to be the absolute best system from multiple criteria.

It's way too easy for the ruling party to put the thumb on the scale and That's what's actually been happening for centuries.

These days it's ID laws where certain IDs are accepted and others aren't based on who is likely to have what.

It's closing the places to acquire the ID in the areas that will vote against you

It's closing the polling stations, putting them in inconvenient locations, reducing the number of machines, putting only new people at the polling place, reducing the hours of operation, making the directions intentionally confusing ... there's many ways these are being manipulated.

Historically it was much worse. Ballots were the parties responsibilities and lots of shenanigans happened there, making the slots too small to fit some ballots, giving the counters a way to "prefer" which ones to count first and thus give a candidate momentum.

There's also lots of instances of "losing" ballots or finding stashes after the results were announced.

I mean really, it's not a panacea, it's susceptible to dishonesty and manipulation like any other human institution.

There's a number of great precautions other countries have done but the blinders of American exceptionalism strikes again and we're still stuck in the relative dark ages.

Re: USPS Files Patent for a Blockchain-Based Voting System

#65
post #61

Earlier quoted context omitted.

You can read a some of my comments in this thread addressing various concerns. That said, I would still agree. At least for the next 5-10 years (until we have Starlink-level internet and advances in cryptography/UX), electronic voting systems are not feasible. The nice thing about blockchains is you can avoid DDoS by only allowing people who are "authorized" to "talk to" the blockchain. This can be done by ensuring t…

It's worth working on to be sure. Another thing I think is worth working on is educating people on what blockchain actually is (which it seems you are doing). I think paper voting works primarily because people know and trust how the votes are counted and how they get to the counters, for the most part. But personally I barely understand transistors and flip flops let alone blockchain and that makes me slightly worri…

I fully share your concerns. There is a massive amount of blockchain infrastructure which 0.0001% of the world population comprehends. Beyond further technical development and the creation of UX and UI libraries around blockchain internals (like https://blockstack.org is trying to do), we need more education.

I'd love to have more debates like this, but I'm trying to help researchers with simple to use blockchain-based tools (like https://assembl.app/chronos, our timestamping service for research outputs).

Paper voting is, in my opinion, still the most "secure" way to vote. This is mainly because any sort of voter fraud requires a lot of people and a lot of time, whereas flawed technology can be hacked by very few in a very short amount of time.

I'm interested to see how this discussion develops.

Re: USPS Files Patent for a Blockchain-Based Voting System

#66

Earlier quoted context omitted.

This is a ridiculous argument, because it could just as well apply to mail-in voting as blockchain-based voting. I also think this fear is far overstated (do we have any stories of this happening in the US?) and the more pernicious forms of voter suppression and misinformation are downplayed. If blockchain systems allow 90% of the populace to vote unencumbered, with a 5% inaccuracy rate (which is far higher than to b…

It's certainly not a ridiculous argument. Anonymity is a cornerstone of fair voting systems, and any system that allows votes to be deanonymised increases the risk of coercion. The same type of risk applies to postal voting, although with less severity, as with postal voting there is only one opportunity to check the coerced vote. Blockchain based votes can be checked after the fact. Still, for this reason, postal vo…

The results of blockchain-based elections can be checked after the fact, that's true. But if the votes of the individuals in the electorate can be checked after the fact, the system was badly architected. The USPS solution linked by OP does not link the identity of a voter to their blockchain identity, so coercion remains as much of a threat as in postal voting.

Blockchain-based voting systems can be either the least or the most anonymous voting systems. Electronic voting allows the abstraction of many voter-suppression tactics which are still in play in the US.

I may have misjudged the audience, because the postal voting argument is very US centric, at a time when the prevailing media narrative is that postal voting is an essentially infallible system which should not be questioned. I would find it hypocritical if people strongly supported mail-in voting while not considering that blockchain-based voting carries similar advantages and risks (which is why the USPS proposed this, I'm sure).

If you read my other comments in this thread, you'll see I'm not in favor of implementing a blockchain-based voting system yet. I just think the above argument was made from a fundamental misunderstanding of blockchain technology.

Re: USPS Files Patent for a Blockchain-Based Voting System

#67

My whole startup is built on blockchain, and I'm an Estonian e-Resident (Estonia allows their citizens to vote digitally), so I find blockchain voting fascinating. That said, there are some problems with it. This Tom Scott video explains why: https://www.youtube.com/watch?v=LkH2r-sNjQs . But this is a very cool idea: combining the USPS vote-by-mail infrastructure with a blockchain layer that sits on top, used mainly…

Very nice video, though in the personally delivered sponsored message at the end he seems to be contradicting himself. Why would you still trust a password manager after seeing the video? And wouldn't it be incredibly stupid if an entire nation put their passwords in a vault controlled by some company in possibly another nation?

Re: USPS Files Patent for a Blockchain-Based Voting System

#68

Earlier quoted context omitted.

How do you prove the database hasn't been tampered with?

Make it public and put it in version control, every time a vote is counted you publicise a new revision, everybody with an interest can download regularly and check for tampering?

Or, you know, use a hash of the previous row as a column value of the current row. That way, you can’t tamper with any data already stored in the database.

Re: USPS Files Patent for a Blockchain-Based Voting System

#69
post #55

Earlier quoted context omitted.

This is a tricky UX issue at the moment, but I'm sure this will be doable in time. The nice thing about blockchains is that once transactions are finalized, the state is known, independently of whether or not the user was hacked. With zero-knowledge proofs, voters could theoretically verify that their "right to vote token" (as I've explained in another answer above) was used to cast a certain vote, without revealing…

It's not a UX issue, it's a logic issue. Voting has to count each vote exactly once, must be easily (!) verifiable at every step, and must be anonymous. Every blockchain systems violates at least one of those constrains, mostly the verifiable part. Estonia is more or less unimportant on the global scale. There is very little incentive to manipulate an election from the outside.

Estonia is probably the most vulnerable country to election tampering in Europe aside from Belarus. Their entire internet and e-voting infrastructure was built up after the largest cyber-attack on a foreign nation, which came from Russia after Estonia removed a Soviet-era war memorial.

This attack also led to the NATO Cybersecurity Center of Excellence being based in Tallinn, and Estonian firms becoming leaders in cybersecurity consulting worldwide. The Estonian example is a splendid example of decentralization and self-sovereign identity done right. All medical records, civil data, banking information, is stored in a decentralized mesh called X-Road.

Finland and other Nordic countries are now adopting X-Road after Estonia's success with it.

If you wish to speak more about this, I'd be glad to, but you're wrong on all fronts. I don't want to regurgitate my blockchain arguments, but if you Ctrl-F this thread for "Right to Vote", you will find my contention about how verifiable, anonymous, and single-vote elections can be held on-chain.

But don't get me wrong, I'm not a proponent of it. I still thing in-person paper-ballot voting is the most reasonable way to vote.

- https://en.wikipedia.org/wiki/2007_cyberattacks_on_Estonia - https://www.nbcnews.com/news/world/data-security-meets-diplo...

Re: USPS Files Patent for a Blockchain-Based Voting System

#70
post #67

My whole startup is built on blockchain, and I'm an Estonian e-Resident (Estonia allows their citizens to vote digitally), so I find blockchain voting fascinating. That said, there are some problems with it. This Tom Scott video explains why: https://www.youtube.com/watch?v=LkH2r-sNjQs . But this is a very cool idea: combining the USPS vote-by-mail infrastructure with a blockchain layer that sits on top, used mainly…

Very nice video, though in the personally delivered sponsored message at the end he seems to be contradicting himself. Why would you still trust a password manager after seeing the video? And wouldn't it be incredibly stupid if an entire nation put their passwords in a vault controlled by some company in possibly another nation?

That's a good point.

I suppose it's poignant in a way — though we might wish to stop the tide, everything is digitizing. Voting will inevitably be swept up in this process, and it's not a matter of if we should do it or not, but how we do it best.

And for what it's worth, password managers are a very good idea (though probably not worth staking an election on). I would however recommend Bitwarden: https://bitwarden.com, which is open-source and well-audited.

In cryptography we trust (and we probably will for voting someday soon as well)!

Post reply on HN