Live data from Hacker News

Debian decides to allow secret votes

lwn.net

261–270 of 280 posts

Re: Debian decides to allow secret votes

#261

Earlier quoted context omitted.

I stand behind Debian to do votes in secrecy. During the RMS issue, I've seen many people who did not have their ferocity under control. This went as far as people wanting to have the "others" removed from the Debian project. People not being able to cast their vote without having to fear repercussions is justification enough for secret votes.

If you can't justify your vote, then maybe you shouldn't be voting. Anonymous voting should be enjoyed by the masses, never the ones representing them.

> If you can't justify your vote, then maybe you shouldn't be voting.

Sorry, wrong in every possible sense of the word. The only true way for an individual to be free from the consequence of placing their vote is for voting to be anonymous.

Any argument that a voter must face direct repercussions for their vote makes voting pointless.

> Anonymous voting should be enjoyed by the masses, never the ones representing them.

Well, since the debian voters are not, as far as a I know, elected by voters themselves, they are not representing anyone.

Re: Debian decides to allow secret votes

#262

Apparently by a single vote and the legitimacy of the vote is in question due to some technicality I didn't care to reread until I understood. What I don't understand is why the project is NOT already secret voting? Do not most free democratic countries practice 'secret ballot' voting specifically because not doing so caused all kinds of problems like voter intimidation? I googled the first three that came to mind (f…

> What I don't understand is why the project is NOT already secret voting?

There was a debian poll that people were afraid to vote in because they expected harassment for their position[1]. That poll raised the question of secret voting.

In my mind, the best option for Debian going forward would be to have public voting records, but have each future poll include a single option at the bottom for "Redo this poll as anonymous".

If more than (for example) 10% of the votes are for redoing the poll as anonymous, then redo it as anonymous.

They way they are doing it now makes it an all or nothing way for every issue that will be voted on in the future. My simplistic proposal above allows polls to be anonymous based on whether a minority feel that they will be harassed by a majority.

[1] Whether or not their expectation was realistic or not is irrelevant.

Re: Debian decides to allow secret votes

#263

Earlier quoted context omitted.

It's not about splitting the vote in that way; Debian's system is robust to that. It's about the 3:1 supermajority requirement that was needed for Option 1 and Option 2. It turns out that their rules for dealing with this work by comparing those options against NOTA only; the problem is that it's plausible that many of the voters didn't realise this.

> It turns out that their rules for dealing with this work by comparing those options against NOTA only; the problem is that it's plausible that many of the voters didn't realise this. Yet Another case for approval voting over like, all other voting systems.

it's the simplified case of score voting, which is even even more accurate with a scale like 0-5. albeit at the cost of simplicity.

Re: Debian decides to allow secret votes

#264
post #254
post #223

Earlier quoted context omitted.

> isn't the way you keep them united is by promising the smaller ones that they won't be trampled on by the big ones? Yes, but in the US, at least, it's gotten to the absurd opposite where the minority is more or less assured a majority of votes. In order to avoid tyranny of the majority, we've more or less codified tyranny of the minority.

What's your evidence behind the statement that "the minority" is assured a majority of votes? Both Democrats and Republicans have won the electoral college and each of them throw a big rhetorical fit any time the other wins with it. At some point you have to accept that being equal doesn't always look fair in a micro vs macro sense of time. In the moment it doesn't look fair, when you look at the longer timeline they…

This comment is confusing to read. It doesn't matter which party wins the election because the voting system itself is flawed. It's also not a particularly new thesis but an often acknowledged problem. It might be that this was the intent of the system, that doesn't change the fact that nowadays significant portions of the population have gravitated towards a few very large metropolis, effectively giving disproportionate power to the people living in rural areas

Re: Debian decides to allow secret votes

#265

Earlier quoted context omitted.

> I don't understand the argument of reducing cost of elections and scaling. How about if we could scale ballots to such an extent that a citizen can vote from wherever/whenever on all issues they're interested in[1], not just a head of state election every X years? Wouldn't that be a more democratic process ? I believe it would, and that paper ballots won't get us there. [1] A current instance of this is the Swiss v…

Well, I live in a representative democracy, and it mostly works. I don't think the vote is only way to express political power, just the most 'sacred' and extreme of all. The one of removing your ruler (or ruling party) from power. And making people vote on issues they're interested in just makes me think only extremes will be heard and counted, and I would have to give my opinion on a bunch of things I don't really…

> It's a place to vent, not to decide

When the ballot process can be done in the morning with your coffee and toast, maybe more people would be inclined to apply judgement and vote in good faith.

And I think I speak a truism when I say that more deciding power for each citizen is a better kind of democracy than representative democracy. What I'm hearing from you are just hypotheticals that nobody can be sure of without actually trying a system like this. Basically that's all I'm saying, the current democratic process leaves a lot of citizens without proper representation and probably we need to move in a direction where that's not true any more. We need to look at alternative ballot systems which would allow that. If the current political strata are wrecked in the process, all the better.

Re: Debian decides to allow secret votes

#266

Earlier quoted context omitted.

I would normally agree with you, but no voting system today can provide you an answer to this question. The problem of unscrupulous operators can be circumvented if the votes are in a public ledger where the voter can backtrack their vote to the ledger "yes, its' my vote, nobody tempered with it", but the vote in the ledger can not be linked to the voter.

To be clear, the property we want is, broadly speaking, "hard to tamper with (at scale) without getting caught". Ideally we would also catch tampering at small scale, but that's darn close to incompatible with denying vote buying. (A possible resolution is, of course, "well, what's wrong with vote buying between informed consenting adults?" But the unfortunate history shows that our electoral systems must compensate…

I don't know if you realize, but you moved the goal posts a little. Yes I agree that an electronic system would be more difficult to wrap your mind around as a layperson, but if you go now on the street and you ask someone how paper ballots work in their district, I bet that even though they know the big picture, they will fail at the details.

So the common person will probably not understand the cryptographic underlayers of this theoretical new system, they need to have confidence "in the science". I know that doesn't sound as good, but we're heading towards a world where computing literacy is increasing, so in some years that could be possible.

Re: Debian decides to allow secret votes

#267

Earlier quoted context omitted.

> Let's say you voted for candidate A and didn't find your vote. How can you prove that you really voted for A? With ZKP it would look something as follows: 1. Encrypt a vote with a commonly known public key and publish it to the bulletin board. 2. Shuffle the votes and producing a ZKP proof of correctness assuring that only votes from bulletin board where shuffled, no vote were added, removed or modified. 3. Tally t…

I didn't understand the algorithm completely (for example, whether you post your vote anonymously or under your name, and where is the private key for the public key you mentioned). Let's say bulletin board software replaces the vote with 20% probability. You post your vote for candidate A and see that it didn't appear on the board (because the board replaced it with vote for candidate B, but you don't know about it)…

> I didn't understand the algorithm completely (for example, whether you post your vote anonymously or under your name, and where is the private key for the public key you mentioned).

It's best to illustrate it with the ElGamal cryptosystem. Let's say that system officials have set up keypair `sk`, `pk = g^sk` and let everyone know `g, pk`. To submit a vote, the voter selects an option corresponding to a message `m` and encrypts it with a freely chosen randomization factor `r` and obtains a tuple `(g^r, m*pk^r)`. He signs this encryption under their name and sends it to the bulletin board.

The last bit is whether to allow everyone to see that you have or have not voted so whether the fact that you have participated in the elections. There seems to be the consensus in the literature that the signature should be concealed from the public and be allowed to verify only for independent auditors.

> Let's say bulletin board software replaces the vote with 20% probability. You post your vote for candidate A and see that it didn't appear on the board (because the board replaced it with vote for candidate B, but you don't know about it). How can you prove that you tried to vote for A and not for B? The records show that you have voted, and as voting is anonymous it is impossible to know how you voted.

One way to preserve the integrity of the bulletin board is that upon receiving a `vote > Of course, there are other ways to meddle with such election. For example, you see that the turnout is 99%. How can you verify this number? The government refuses to publish a list of voters because GDPR doesn't allow that. And even if the country publishes this list how you can verify that the list doesn't contain fictious voters?

The fictitious voters are indeed a thing if we can't trust the independent auditors of the bulletin board. Personally, I would never support an internet voting system where the result of the elections would lay on the integrity of a few trusted auditors who have special access to do so. Thus I would greatly prefer for the voter lists (the signatures) to be public in spite of losing participation anonymity.

Re: Debian decides to allow secret votes

#268

Earlier quoted context omitted.

> would secret voting here make sense? I don't think so. When people are not afraid to speak their mind - then a real consensus can be faster found. You are swapping cause and effect and are implying that making voting secret creates fear. This is plain wrong.

Maybe you misread something there? I merely stated, that there is no need for complex secret voting mechanisms - when the group is small and trusting. Or do you practice secret voting in decision making among your friends?

> Maybe you misread something there?

I didn't.

> Or do you practice secret voting in decision making among your friends?

Now you are making a strawman. But I'll answer anyways. If I had a simple way to do anonymous polls with friends (e.g. an app) I would certainly use it because it would be a fun experiment.

But this is besides the point. Social pressure exists amongst coworkers, volunteers, friends, families and even couples. A lot of it.

That's why secret voting is useful in many environments even where people trust each other.

Re: Debian decides to allow secret votes

#269
post #163

Earlier quoted context omitted.

or that people would making a different vote if it was counted differently? Two changes would happen. A lot of people who don't vote today because their state either heavily favours the 'wrong' candidate or the 'right' candidate will already win by a massive margin, would start voting, since all of sudden their vote matters a lot more. Secondly, and more importantly, candidates would campaign very differently. In tod…

This also makes many states cease to matter. Already a big issue that big cities vote one way while rural voters go another way.

By that you mean the swing states? If so, good. Those states don't deserve a disproportionate weight into who we elect as President.

Re: Debian decides to allow secret votes

#270

Earlier quoted context omitted.

You are spreading FUD written by a notorious troll that has been expelled from FOSDEM, FSFE, Debian and other organizations as well.

>You are spreading FUD written by a notorious troll that has been expelled from FOSDEM, FSFE, Debian and other organizations as well. I was asked for citation. I more than delivered with quite a few links there. All of which were unique folks with unique situations. It seems to me you are referring to one of these but I genuinely don't know which you are talking about. Something abundantly clear to me is that there's…

> I more than delivered with quite a few links there.

Random URLs from the Internet do not make reputable sources.

> All of which were unique folks with unique situations.

Wrong. Various websites belong to the same person.

> It seems to me you are referring to one of these but I genuinely don't know which you are talking about.

Then do some research before posting random stuff.

> Something abundantly clear to me is that there's some serious harassment going on at Debian.

Yes, and this is why an anti-harassment team has been created.

> People are requesting secret votes to avoid harassment. So this "expelled" troll isn't the problem.

The first sentence does not imply the second.

Post reply on HN