Live data from Hacker News

To Protect Voting, Use Open-Source Software

mobile.nytimes.com

191–200 of 237 posts

Re: To Protect Voting, Use Open-Source Software

#191
post #190

Earlier quoted context omitted.

That's right. And now do both things _publicly_! For money (or others things you own) you will need a Torrens-like title system with a replicated database among your fellow-citizens. For voting - it will be a database replicated on DVDs (or something that can be read, say, by a microscope:) You may be astonished how secure that will be.

How do you verify the entities that are registered on the chain are who they are supposed to be? It may show a commit log of Citizen X voted in a certain way, but how do you verify it was Citizen X that actually voted or that they even exist?

The same way as you supposed (not:) to check it under a paper-ballots voting system. By the Citizens Database - when every citizen's biometric data (photos, eye or ear scans, body measurements, etc.) and contact data is published on holographic discs, magnetic tapes (IBM has one with 330 TB storage). It will allow anyone to verify there are no fake identities there. One may store just a hash table for all entries, if he can't afford those storage mediums.

Have they told you about it?

Re: To Protect Voting, Use Open-Source Software

#192
post #167

Earlier quoted context omitted.

Public - i.e. everyone knows how others have voted - voting can be both precise and secure. Public voting can be done electronically, say, via encrypted SMS. So why to bother with secrecy in the first place?

So you can't pay people to vote for a particular candidate.

Didn't SCOTUS recently uphold peoples right to take selfies in the ballot box? Seems that ship has already sailed in the US.

Also, California allows for absentee voting with no particular reason. I've voted in every election I've ever been eligible to vote in and I have never once set foot in a physical polling place.

Re: To Protect Voting, Use Open-Source Software

#193
post #190

Earlier quoted context omitted.

How do you verify the entities that are registered on the chain are who they are supposed to be? It may show a commit log of Citizen X voted in a certain way, but how do you verify it was Citizen X that actually voted or that they even exist?

The same way as you supposed (not:) to check it under a paper-ballots voting system. By the Citizens Database - when every citizen's biometric data (photos, eye or ear scans, body measurements, etc.) and contact data is published on holographic discs, magnetic tapes (IBM has one with 330 TB storage). It will allow anyone to verify there are no fake identities there. One may store just a hash table for all entries, if…

I'm sorry but I'm having difficulty understanding what you're trying to say. You still need a body to oversee adding entries, otherwise anyone could add anything? How do you verify exactly, you've just got a bunch of data, which may or may not be legitimate. It still boils down to the best way to protect voting, isn't by the more exotic systems whereby fudging can be done at scale. It's by making the exploits not scale and keeping anonymity by having another process for voter registration.

I'm not sure what the choice of media has to do with anything.

Who has told me what about what now?

Re: To Protect Voting, Use Open-Source Software

#194

Earlier quoted context omitted.

The fact that it doesn't scale is exactly why we should stick with it. We want voting to be hard, distributed, and diverse. That prevents a single county or state from destabilizing the rest of the country. It should prioritize accuracy over speed and all else. It's like an ecosystem. The more homogeneous the system then the more vulnerable we are to a single virus (or hacker) we become.

Wait, why do we want voting to be hard? If voting is hard, that means it takes more time to vote, and not everyone is equally able to take extra time to vote. A disproportionate percentage of the voters will end up being people with more time and/or more flexible schedules.

They mean vote counting should be hard.

Re: To Protect Voting, Use Open-Source Software

#195
post #159

Earlier quoted context omitted.

That's silly. Do you need to use paper and pencil to do banking? If we as a society and individually can trust our money to technology then why not voting? Having a merkle tree and voting from your device instead of a polling station is not just more convenient - it's more secure too. Everyone can verify their vote was counted!! And right now? Right now we have a government database of who voted for what. That's craz…

With electronic banking I can verify that my money are where they should be. With electronic voting, I can't be sure my vote got counted, and even less sure others weren't tampered with.

Sure you can. If you signed your vote and all votes got included in a markle tree then you can for sure verify that your vote is counted.

Imagine bitcoin but with votes instead of transactions. Boom.

Re: To Protect Voting, Use Open-Source Software

#196
post #75

Earlier quoted context omitted.

Why use a voting machine at all? Isn't the main point of having a polling location simply so you can verify your identity? If we could come up with a system that allowed one's identity to be verified online, or by postal service, then do we really need thousands of machines collecting the votes. Couldn't it be centralized to a handful of more easily audited systems?

No, the point of a polling station is so that there's provably no coercion. You fill out your ballot in secret, you're not permitted to take a photograph of it, and you place it in the ballot box without telling anybody what you've voted for. The more you allow people to vote from their homes, the more likely it is that people can be coerced into voting the way their partner, employer, or otherwise, want them to.

>You fill out your ballot in secret, you're not permitted to take a photograph of it, and you place it in the ballot box without telling anybody what you've voted for.

In the US, only one of those is guaranteed [0]. In California, where I can get an absentee ballot just by asking for it, none of those is guaranteed.

[0] https://www.bloomberg.com/news/articles/2017-04-03/ballot-se...

Re: To Protect Voting, Use Open-Source Software

#197
post #190

Earlier quoted context omitted.

That's right. And now do both things _publicly_! For money (or others things you own) you will need a Torrens-like title system with a replicated database among your fellow-citizens. For voting - it will be a database replicated on DVDs (or something that can be read, say, by a microscope:) You may be astonished how secure that will be.

How do you verify the entities that are registered on the chain are who they are supposed to be? It may show a commit log of Citizen X voted in a certain way, but how do you verify it was Citizen X that actually voted or that they even exist?

The same way you verify that the person using the banking app is the one they are supposed to be. Or any other service.

Obviously you use your device, and you can lock it with a password. You can use two factor authentication.

It's straightforward, really. You sound like identity has never been solved electronically.

If anything, holding a physical paper id document is far less secure than a personal device with your private keys in the Secure Enclave.

Re: To Protect Voting, Use Open-Source Software

#198
post #190

Earlier quoted context omitted.

How do you verify the entities that are registered on the chain are who they are supposed to be? It may show a commit log of Citizen X voted in a certain way, but how do you verify it was Citizen X that actually voted or that they even exist?

The same way as you supposed (not:) to check it under a paper-ballots voting system. By the Citizens Database - when every citizen's biometric data (photos, eye or ear scans, body measurements, etc.) and contact data is published on holographic discs, magnetic tapes (IBM has one with 330 TB storage). It will allow anyone to verify there are no fake identities there. One may store just a hash table for all entries, if…

No one requires these biometrics to make bank transactions. The bank can give you a simple security device, but with smartphones even that is optional now.

Biometrics, seriously?

Biometrics are only a one-time proof when eg you are issued a token. They can be replayed later and can't be used anywhere except where there's a physical security guard preventing tampering. And even then you trust the security guard.

Re: To Protect Voting, Use Open-Source Software

#199

No. To protect voting, don't use software. Everyone needs to be able to _understand_ as well as be able to verify that they successfully voted. Besides the issues with what software the machine is actually running, most people cannot comprehend or understand that software - even if it is open source. That is not acceptable for an open democratic society, or to sustaining it. In this particular situation it should not…

I like the model where you vote electronically and you can see (through a clear material) that the machine prints out a copy of your votes and drops them into a bin.

You can throw cryptographic verification on top of that if you like.

Post reply on HN