Live data from Hacker News

Estonian E-Voting Source Code Made Public

news.err.ee

41–50 of 144 posts

Re: Estonian E-Voting Source Code Made Public

#43

How does a voter or independent voter know that the code that has been verified is actually running on the machine that they connect to? You have to trust the sys admins. And as we all know: something is trusted if it can break your security policy.

https://en.wikipedia.org/wiki/Quis_custodiet_ipsos_custodes%...

Re: Estonian E-Voting Source Code Made Public

#44

Could it be, that secret ballots are insecure? https://en.wikipedia.org/wiki/Secret_ballot In the US, we officially supported secret ballots in 1892. Still, I wonder if we all found the strength to open up the ballot, if that wouldn't eliminate some of the viability of voting fraud? I'll start, I voted for Obama in 2008 & 2012.

A lot of people are in circumstances where those they can't escape from (parents, abusive boyfriends, etc) will physically assult you for voting for the guy they didn't like. In the more general case, you can lose friends not going with the collective choice, and open ballots expose that, which makes more people vote for the guy their friends want rather than what they want to maintain social acceptance.

Re: Estonian E-Voting Source Code Made Public

#45
post #44

Could it be, that secret ballots are insecure? https://en.wikipedia.org/wiki/Secret_ballot In the US, we officially supported secret ballots in 1892. Still, I wonder if we all found the strength to open up the ballot, if that wouldn't eliminate some of the viability of voting fraud? I'll start, I voted for Obama in 2008 & 2012.

A lot of people are in circumstances where those they can't escape from (parents, abusive boyfriends, etc) will physically assult you for voting for the guy they didn't like. In the more general case, you can lose friends not going with the collective choice, and open ballots expose that, which makes more people vote for the guy their friends want rather than what they want to maintain social acceptance.

Those are extreme cases! I hope your family isn't beating you often, for your voting habits.

Re: Estonian E-Voting Source Code Made Public

#46

Could it be, that secret ballots are insecure? https://en.wikipedia.org/wiki/Secret_ballot In the US, we officially supported secret ballots in 1892. Still, I wonder if we all found the strength to open up the ballot, if that wouldn't eliminate some of the viability of voting fraud? I'll start, I voted for Obama in 2008 & 2012.

Yes everything about voting gets simpler if you throw away the anonymity aspect. The election can be better audited[1] and you can be too if you voted for the wrong party. You would also probably get to discover the market price of votes in marginal constituencies.

[1] Audited, fired from a government job, beaten, not to mention social, religious or family pressures to vote in a particular way. The reality or fear of these things could influence elections if not so much in the West but if these standards were adopted where elections are a little more life threatening (I'm thinking of Kenya but there are probably many other examples too).

Re: Estonian E-Voting Source Code Made Public

#47
post #5

Earlier quoted context omitted.

All voting systems that I know of require trust, with or without machines. Do you trust the person counting your ballot to count correctly? There's a district in the UK that prides itself on always being the first to return results. I would be fairly worried about the ballot counters there. Eventually someone has to trust someone to execute correctly. Unless there's some voting system I'm not aware of that doesn't re…

Thats why any person can act as an observer if they so wish and oversee the person counting your ballot. I can not possibly do the same with a turing machine.

So why can't you be an observer of the sys admin when they install the software. Witness some chain of command that the software has come from an authorized source, meets a digital check-sum and is installed properly. It can then be secured by another party with a two password "lock box" type approach kind of like we use with our crypto system at work that guards our CC processing. There are systems invented and implemented in the world already that can rid your concern over some rogue sys admin. Takes all of 1 minute of critical thinking.

Re: Estonian E-Voting Source Code Made Public

#48
post #15

Sadly many of the identifiers are named in estonian. Limiting this project to estonian developers only. I'm aware that this is _estonians_ voting system, but i'm sure there are developers all around the world who would be interested in contributing (especially security audits would be interesting) to this project without the necessity to reverse engineering/translating the code.

We all know naming things is one of the most difficult things in programming. Give the guys a chance, let them do it in the language they are fluent in, rather than the language you grew up with

Re: Estonian E-Voting Source Code Made Public

#49

Could it be, that secret ballots are insecure? https://en.wikipedia.org/wiki/Secret_ballot In the US, we officially supported secret ballots in 1892. Still, I wonder if we all found the strength to open up the ballot, if that wouldn't eliminate some of the viability of voting fraud? I'll start, I voted for Obama in 2008 & 2012.

Yes everything about voting gets simpler if you throw away the anonymity aspect. The election can be better audited[1] and you can be too if you voted for the wrong party. You would also probably get to discover the market price of votes in marginal constituencies. [1] Audited, fired from a government job, beaten, not to mention social, religious or family pressures to vote in a particular way. The reality or fear of…

In Italy, there's a strict ban on phones or cameras in the voting booths because, like you say, it's a way to verify that you voted for who you did, and consequently, get paid for it.

Re: Estonian E-Voting Source Code Made Public

#50
post #38

Common, not a single positive comment ? Things in the administration always take time. At least it's a move in the right direction. Next add a build CI to produce signed images. Then propose USB keys for people to boot their own system on the voting booth. At least it's better than the Diebold debacle in the states.

IMHO internet voting falls under "because you can does not mean you should".
Post reply on HN