Live data from Hacker News

Debian decides to allow secret votes

lwn.net

111–120 of 280 posts

Re: Debian decides to allow secret votes

#111
post #71

Earlier quoted context omitted.

> How can I trust that my voice was actually heard by the system? Most vote countings are public. I can go to my polling place, cast my vote, check that nobody tampers with the box, watch how they count every vote correctly, ensure that the written tallies are correct, and then verify that the central system tallies match with those I counted.

Great, ZKProofs present the possibility for everyone to do better than that with much less work.

Less work isn't the optimisation goal, though. Reliability, trust, verifiability, secret ballot, etc. is what it is about. If things can be made more efficient without sacrificing the primary goals ok, but if I as a citizen can't verify the results anymore (by watching the count etc.) the purpose isn't met.

Re: Debian decides to allow secret votes

#112

Earlier quoted context omitted.

By definition "none of the above" can't be the same as any of the above options.

But then the question becomes, "if you don't want private votes and you don't want public votes, what do you want?"

Maybe you want for some votes to be public and some votes to be private. Putting "all votes should be {public,private}" in the constitution prevents that.

Re: Debian decides to allow secret votes

#113
post #92
post #9

A brief summary because I had to re-read this a few times to figure out what was going on. Debian had a vote with 4 options: Option 1 "Hide identities of Developers casting a particular vote" Option 2 "Hide identities of Developers casting a particular vote and allow verification" Option 3 "Reaffirm public voting" Option 4 "None of the above" (NOTA) The objection raised here is that Option 3 and Option 4 can be consi…

> If those two were represented as a single "NOTA" option, that option would have won the ballot in terms of votes. If the ballot were different, the results would be too. You can't take the results of one ballot and mush them around to support a hypothetical result; see also counting of the 'popular vote' for US president, a ballot which has never been tried, and whose results are unknowable. A vote for 4 says (to m…

It's a binary decision.

The only way to properly poll that is either rank choice voting or a second vote after voting to change or not.

Re: Debian decides to allow secret votes

#114
post #71

Earlier quoted context omitted.

> How can I trust that my voice was actually heard by the system? Most vote countings are public. I can go to my polling place, cast my vote, check that nobody tampers with the box, watch how they count every vote correctly, ensure that the written tallies are correct, and then verify that the central system tallies match with those I counted.

Great, ZKProofs present the possibility for everyone to do better than that with much less work.

Tell that to the people who now, instead of just going to a polling place and placing a paper on an envelope, have to download and store digital certificates, possibly download and install new programs and deal with the troubles of all that, just so "verifying votes" is slightly easier for the minority of people with the knowledge of the system and ZK proofs.

Also, you're assuming the system is perfectly implemented. In reality, such a system will be complex, will have many more pieces than the ZK system itself (and those pieces will have vulnerabilities), and will require users to do more which will also be prone to errors and vulnerabilities.

I don't understand the insistence on electronic voting for elections. It's less transparent to laypeople, offers small benefits and adds significant complexity both in the implementation and use.

Re: Debian decides to allow secret votes

#115
post #18

Earlier quoted context omitted.

I am not familiar with Debian's practices, but electronic voting can't work for a nation because: - centralization (there must be a central, corruptible place where the voters are authenticated or the votes are counted) - software is untrustable: https://www.win.tue.nl/%7Eaeb/linux/hh/thompson/trust.html The USA has had a Diebold voting scandal. Other countries are using a paper-based voting process which can be supe…

Electronic voting systems using zero knowledge proofs are superior to paper votes because it's possible to check for yourself that your vote was actually counted and not ignored. Paper voting is extremely expensive to scale compared to a website that lets you vote. Everyone could get a notification on their phone when they are asked to vote on something as opposed to having to fill out paper and send it somewhere to…

> Paper voting is extremely expensive to scale

And thus is impossible to hack at scale.

It costs $x to run an election and count the votes for Y thousand peple voting for a position, that scales pretty much linearly - have 1 ballot and 1,000 votes costing say $100, have 1 ballot and 1 million votes and it costs no more than $100,000

Re: Debian decides to allow secret votes

#116
post #83

Earlier quoted context omitted.

>That's a bug, not a feature It's a trade off. I want to be able to prove that my vote was counted. How can I trust that my voice was actually heard by the system? >as nobody else can verify what you voted for. You can mitigate this problem by giving people a way to fake any vote outcome. The voter knows how to verify their actual vote, but someone else would not be sure if what they verified was real or fake. Also I…

> Also I doubt this type of buying votes with verification is that big of an actual thing. You can trivially do it with paper voting to by just asking them to stream themself voting or by taking a picture of their ballot. It's not so much selling votes, as to discourage voter intimidation: The husband forces his wife, the boss forces his subordinates, the local mafia forces their victims to vote a particular way. I d…

> I don't know the rules in the USA, but in the UK it is generally forbidden to stream yourself voting or take a photo in the polling station. Maintaining the secrecy of ballots is high priority.

Except we allow postal voting pretty much willy nilly, especailly in areas where intimidation can happen

Re: Debian decides to allow secret votes

#117

Earlier quoted context omitted.

I agree. I don't understand the argument of reducing cost of elections and scaling. The current paper system in place in most works (at least in European countries where I've witnessed the process) and doesn't need to scale more. If actors in a democracy can't afford such a system, and the occasional (once, twice a year) walk to the voting place, 15 minutes wait and fellow-citizen interaction, can't we accept they do…

American here and I have had to wait >2 hours to vote multiple times. In the worst instance someone tried to illegally close the polling place even though people were still lined up outside. This is in clear violation of state law. So long as you are lined up to vote before the polling place closes they have to take your vote. To the sheriff's department credit (they are generally terrible) the deputy who responded r…

> American here and I have had to wait >2 hours to vote multiple times.

That doesn't have to be the case though, that's a political decision to staff voting booths like that. It's also trivial to fix.

Re: Debian decides to allow secret votes

#118
post #9

A brief summary because I had to re-read this a few times to figure out what was going on. Debian had a vote with 4 options: Option 1 "Hide identities of Developers casting a particular vote" Option 2 "Hide identities of Developers casting a particular vote and allow verification" Option 3 "Reaffirm public voting" Option 4 "None of the above" (NOTA) The objection raised here is that Option 3 and Option 4 can be consi…

Stopped using Debian a long time ago, and this is just making me glad I did exactly that.

What kind of hairbrained nimrod came up with that idea!?

You can't have mixed voting methods and still call it fair in any respect. Any chance there could be tampering should be considered not just to be happening, but to be assured to happen. "Secret ballots" of any sort when everyone else is not partaking in said "Secret ballots" just creates a skew towards unfairness and improper results. Assuming those ballots truly are secret and not just pseudo-secret. If true secret, then there is no way to track properly for sure if there is tampering...

I doubt anyone with Debian is going to be listening to me on this; but perhaps they should.

Debian crew: No. Normal voting methods only dammit.

Like they are going to listen though. In the meantime, I'll be using a different version of Linux. Debian has been dead to me for a long time now.

Re: Debian decides to allow secret votes

#119
post #92
post #9

A brief summary because I had to re-read this a few times to figure out what was going on. Debian had a vote with 4 options: Option 1 "Hide identities of Developers casting a particular vote" Option 2 "Hide identities of Developers casting a particular vote and allow verification" Option 3 "Reaffirm public voting" Option 4 "None of the above" (NOTA) The objection raised here is that Option 3 and Option 4 can be consi…

> If those two were represented as a single "NOTA" option, that option would have won the ballot in terms of votes. If the ballot were different, the results would be too. You can't take the results of one ballot and mush them around to support a hypothetical result; see also counting of the 'popular vote' for US president, a ballot which has never been tried, and whose results are unknowable. A vote for 4 says (to m…

> see also counting of the 'popular vote' for US president, a ballot which has never been tried, and whose results are unknowable.

I don't follow this point. I'm not an American, but my understanding is counting via simple popular vote vs "electoral college" doesn't change the ballot itself, you still vote for the president directly; it just changes the way the ballots are counted.

Are you suggesting either something on the ballot is different, or that people would making a different vote if it was counted differently?

Re: Debian decides to allow secret votes

#120

Earlier quoted context omitted.

Electronic voting systems using zero knowledge proofs are superior to paper votes because it's possible to check for yourself that your vote was actually counted and not ignored. Paper voting is extremely expensive to scale compared to a website that lets you vote. Everyone could get a notification on their phone when they are asked to vote on something as opposed to having to fill out paper and send it somewhere to…

Electronic voting is very difficult to monitor and verify independently, especially when voter lists are not publicly available. It is difficult to verify whether turnout number is correct, and on the countrary it is easy to add millions of fictious voters and vote for them. > it's possible to check for yourself that your vote was actually counted and not ignored. Let's say you voted for candidate A and didn't find y…

> Let's say you voted for candidate A and didn't find your vote. How can you prove that you really voted for A?

With ZKP it would look something as follows:

1. Encrypt a vote with a commonly known public key and publish it to the bulletin board.

2. Shuffle the votes and producing a ZKP proof of correctness assuring that only votes from bulletin board where shuffled, no vote were added, removed or modified.

3. Tally the votes and produce a proof of correct decryption.

The argument is that since authorities does not know the choice of the voter they would accept the vote to the authenticated and public bulletin board which would prevent vote omission.

Post reply on HN