Live data from Hacker News

Swiss e-voting pilot can't count 2,048 ballots after decryption failure

theregister.com

111–120 of 501 posts

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#111
post #12

I don't care how much maths and encryption you use, you can't get out of the fact that things can be anonymous (no one can know how you voted) or verifiable (people can prove that you only voted once) but not both. - Switzerland usually gets around this by knowing where everyone lives and mailing them a piece of paper 'something you have' - South Africa gets around this by putting ink on your fingernail I've read qui…

The USA threads the needle by simply not having verifiable voting. And it turns out it works pretty well. Despite countless hours and lawsuits dedicated to finding people who voted more than once, only a handful of cases have actually turned up.

It's not that there are no checks. You have to give your name, and they know if you've voted more than once at that station that day. To vote more than once you'd have to pretend to be somebody else, in person, which means that if you're caught you will go to jail.

We could certainly do better, but thus far all efforts to defeat this non-problem are clearly targeted at making it harder for people to vote rather than any kind of election integrity.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#112
post #18

Earlier quoted context omitted.

It is not even about understanding. It is about how easy it is to distrust it. Contrary to what nerds think, the goal of elections isn't to get bulletproof results by mathematical standards. The goal is to create agreeable consent among those who voted. A good election system is one where even sworn enemies can begrudgingly agree on the result. A paper ballot system has the advantage that it can be monitored by any g…

> the goal of elections isn't to get bulletproof results by mathematical standards. The goal is to create agreeable consent among those who voted. A good election system is one where even sworn enemies can begrudgingly agree on the result. First you must explain to them why the former is not an example of the latter.

GP already said.

> eVoting cannot be understood and audited by normal citizens, not even by nerdy ones.

I suggest you explain the verifiability of evoting systems to your grandma or your friend with an art degree. Then ask them to explain the same to their peer while you just listen. Then repeat the exercise with paper voting. You will see the difference.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#114

Earlier quoted context omitted.

Some states only require a piece of mail and checking a box saying you are legally allowed to vote to register. Then when you checkin to vote the workers are not permitted to ask for ID to prove you are the person you claim to be. At no point during that process is there presentation of proof of citizenship.

Any ballots that are cast under same-day registration are cast as provisional and will go through the full verification process if the election is close enough where those ballots are necessary. Source: actually ran a fucking election precinct. Non-citizens aren’t casting ballots illegally.

I'm not talking about same day registration. If you are on the rolls and proof of citizenship is not required to register, then how do you as a poll worker know the person on the rolls is a citizen?

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#115
post #109
post #99

Earlier quoted context omitted.

Sure you can, you just need an anonymous voting mechanism that's sufficiently naive. You use the verifiable process to restrict access to that anonymous mechanism. In Canada, at both federal and provincial levels, you walk up to a desk and identify yourself, are crossed off a list, and handed a paper ballot. You go behind a screen, mark an X on the ballot, fold it up, take it back out to another desk, and put it in t…

There will never be a technical or operational process that excludes cheating. The only deterrence that seems to work on humans and even then only most of the time is severe capitol punishment and that will only be as effective as people believe it happens thus requiring live streaming of the removal of cheaters heads without censorship. The current legal process of each country would have to be by-passed or people w…

Also cheating with paper ballots is much harder to scale and remain undetected than cheating by altering records in a database.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#116
post #12

I don't care how much maths and encryption you use, you can't get out of the fact that things can be anonymous (no one can know how you voted) or verifiable (people can prove that you only voted once) but not both. - Switzerland usually gets around this by knowing where everyone lives and mailing them a piece of paper 'something you have' - South Africa gets around this by putting ink on your fingernail I've read qui…

What about this? Consider a toy system: everyone gets issued a UUID, everyone can see how every UUID voted, but only you know which one is your vote. This is of course flawed because a person can be coerced to share their ID. In which case you could have a system in which the vote itself is encrypted and the encryption key is private. Any random encryption key works and will yield a valid vote (actual vote = public v…

Besides the fact that 99% of the general population won't be able to understand this, a $5€ wrench says that you show me proof of the correct private key (either by you showing me the letter you received, me being present when you set it up, or however it is set up)

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#118
post #12

I don't care how much maths and encryption you use, you can't get out of the fact that things can be anonymous (no one can know how you voted) or verifiable (people can prove that you only voted once) but not both. - Switzerland usually gets around this by knowing where everyone lives and mailing them a piece of paper 'something you have' - South Africa gets around this by putting ink on your fingernail I've read qui…

The USA threads the needle by simply not having verifiable voting. And it turns out it works pretty well. Despite countless hours and lawsuits dedicated to finding people who voted more than once, only a handful of cases have actually turned up. It's not that there are no checks. You have to give your name, and they know if you've voted more than once at that station that day. To vote more than once you'd have to pre…

> You have to give your name, and they know if you've voted more than once at that station that day.

So you go to other stations, duh. It's called "carousel voting" [0], if done on a large, organized scale.

[0] https://en.wikipedia.org/wiki/Carousel_voting

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#119
post #12

I don't care how much maths and encryption you use, you can't get out of the fact that things can be anonymous (no one can know how you voted) or verifiable (people can prove that you only voted once) but not both. - Switzerland usually gets around this by knowing where everyone lives and mailing them a piece of paper 'something you have' - South Africa gets around this by putting ink on your fingernail I've read qui…

The USA threads the needle by simply not having verifiable voting. And it turns out it works pretty well. Despite countless hours and lawsuits dedicated to finding people who voted more than once, only a handful of cases have actually turned up. It's not that there are no checks. You have to give your name, and they know if you've voted more than once at that station that day. To vote more than once you'd have to pre…

[flagged]

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#120
post #18

Earlier quoted context omitted.

It is not even about understanding. It is about how easy it is to distrust it. Contrary to what nerds think, the goal of elections isn't to get bulletproof results by mathematical standards. The goal is to create agreeable consent among those who voted. A good election system is one where even sworn enemies can begrudgingly agree on the result. A paper ballot system has the advantage that it can be monitored by any g…

> the goal of elections isn't to get bulletproof results by mathematical standards. The goal is to create agreeable consent among those who voted. A good election system is one where even sworn enemies can begrudgingly agree on the result. First you must explain to them why the former is not an example of the latter.

Just imagine you have to explain a child in kindergarden how the collective choice is made. Raising hands works. Putting different pieces of paper into a jars works. Magical machine says the result was X does not work unless they trust it, regardless of how correct the magical machine was under the hood, because the majority lacks the skill of intuitively understanding this themselves. Sure, they could trust an expert or an figure of authority, but that is a fleeting thing. A fleeting thing that may be enough for inconsequencial decisions, but not enough to steer countries.

Even I as someone who would have the skillset to understand why it has to be correct would have an easier time verifying a paper ballot process than ensuring that network connected complexity behemoth was running the program I checked for weeks correctly in any moment during an election. And even if you had a way to guarantee that, who tells me this was the case in the whole country or thst evidence wasn't faked a millisecond before I checked?

Meanwhile with paper and poll watchers from each party it is very easy to find actual irregularities and potential tampering — trust is a gradual thing with paper while it is much more binary with digital. If there is a sign for the digital machine being untrustworthy you can throw the whole result into the bin.

Post reply on HN