Live data from Hacker News

Swiss e-voting pilot can't count 2,048 ballots after decryption failure

theregister.com

361–370 of 501 posts

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#361
post #4

Meanwhile Brazil does full e-vote for almost 30 years collecting more than 100 million votes (that's 11 times the whole of Switzerland's population). You'll get there Switzerland, it can be done. It is safer and faster.

And they probably started with small-scale pilots, too.

Not really. It started with hundreds of thousands of votes.

That said, Brazilian elections are completely unverifiable. They don't seem to be false, but it's hard to say anything that would be different if they were.

When it started, at the 90s, the machines were at least simpler and possible to verify up to the firmwares. Nowadays, they are not.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#362

The biggest advantage physical voting has it is follows human-scaling laws. Which often is a problem (inefficient) but for voting this is a massive benefit for one particular reason - due to lack of automation any fraud doesn't also benefit from the same automation so has to be large scale and widely distributed for it to be impactful (the fraud has to be distributed to the humans involved). Which isn't to say that i…

Isn't the advantageous fraud easy to do? Sheriff monitors the ballot box (ex. Jimmy Carter's opponent). Only allow loyalists to count the result (and then report w/e you want; ex. Russia).

It's not fraud is difficult to do, it's difficult to do so without people noticing. The problem of r-country is not that fraud is not discovered, they problem is they are not capable to course-correct (in general, but in regards to having elections specifically)

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#363

Earlier quoted context omitted.

The USA threads the needle by simply not having verifiable voting. And it turns out it works pretty well. Despite countless hours and lawsuits dedicated to finding people who voted more than once, only a handful of cases have actually turned up. It's not that there are no checks. You have to give your name, and they know if you've voted more than once at that station that day. To vote more than once you'd have to pre…

> The USA threads the needle by simply not having verifiable voting. And it turns out it works pretty well. No, no, no. January 6 is a systemic failure. The purpose of a voting system is to select the most popular candidate in a way that is so far beyond doubt that a populist loser can't claim the results are wrong without alienating his base . Even leaving aside the whole "Trump doesn't care if his lies are credible…

>The purpose of a voting system is to select the most popular candidate in a way that is so far beyond doubt that a populist loser can't claim the results are wrong without alienating his base.

The systemic failure is not in a voting system in this case, unfortunately.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#364
post #258

Earlier quoted context omitted.

No other country is quite as heterogeneous as the US. And there is a significant history in the US of using restrictions around voting to disenfranchise certain ethnicities. That makes any restriction around voting a sensitive topic in the US. Proponents of voter ID claim it is needed to prevent fraud, while opponents point out that there's not enough fraud for it to be worth the cost. Note that countries such as Aus…

> No other country is quite as heterogeneous as the US. there's no scientific link between race and the ability to go to a DMV once every 10 years

If you have to go to a specific DMV at a specific time, it's a link to a ZIP code and economical situation (i.e. having enough time during work hours just for that). That's a good enough proxy for race. Bonus points if you can also make a specific DMV for a specific ZIP code shittier experience on purpose. Nobody would ever try to do that in a-country, right.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#365
post #286

Earlier quoted context omitted.

Why?

One of the main goals of an electoral system is to ensure that the population trusts that their views are fairly represented. The reason that paper voting is so good in this regard is that everybody can fully understand the entire process. It is so very, very simple. And if you need proof, you can go see the counting for yourself. The issue with electronic voting is that there is far greater complexity. There are man…

>One of the main goals of an electoral system is to ensure that the population trusts that their views are fairly represented.

Do you trust the system now enough to say your views are fairly represented (looking at the war and ... all the other things) ?

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#366

Earlier quoted context omitted.

Isn't the advantageous fraud easy to do? Sheriff monitors the ballot box (ex. Jimmy Carter's opponent). Only allow loyalists to count the result (and then report w/e you want; ex. Russia).

It's not fraud is difficult to do, it's difficult to do so without people noticing. The problem of r-country is not that fraud is not discovered, they problem is they are not capable to course-correct (in general, but in regards to having elections specifically)

It's also very difficult to scale. For one voting site you might need a few people to force it, plus a few more counting the votes. For thousands of sites you need many thousands of people.

Versus e-voting where may conceivably manage to swing the vote with a handful of people.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#367
post #12

I don't care how much maths and encryption you use, you can't get out of the fact that things can be anonymous (no one can know how you voted) or verifiable (people can prove that you only voted once) but not both. - Switzerland usually gets around this by knowing where everyone lives and mailing them a piece of paper 'something you have' - South Africa gets around this by putting ink on your fingernail I've read qui…

Sorry, isn't this dead simple? Maintain a list of identity hashes. When someone goes to vote, deny them if they're already in the list . Otherwise, add their hash to the list then allow a vote to be cast.

This makes the secrecy aspect problematic. You can't have zero trust in authority, verifiability and resistance to sabotage all at once.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#368
post #12

I don't care how much maths and encryption you use, you can't get out of the fact that things can be anonymous (no one can know how you voted) or verifiable (people can prove that you only voted once) but not both. - Switzerland usually gets around this by knowing where everyone lives and mailing them a piece of paper 'something you have' - South Africa gets around this by putting ink on your fingernail I've read qui…

What about this? Consider a toy system: everyone gets issued a UUID, everyone can see how every UUID voted, but only you know which one is your vote. This is of course flawed because a person can be coerced to share their ID. In which case you could have a system in which the vote itself is encrypted and the encryption key is private. Any random encryption key works and will yield a valid vote (actual vote = public v…

You have to trust that both 1) the UUID issuing party is not keeping the actual id to uuid mapping in the logs 2) the same party isn't allocating an excessive number of uuids to mass-vote for the "good" choice.

In-person voting does provide these guarantees, to extent that violating them will be discoverable and both parties have an incentive to discover such things.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#369
post #321

Earlier quoted context omitted.

How do you determine voter eligibility without ID?

The name is on the list, so the person can vote. Why would you need them to show an id for that? You would need to establish the identity first (which everybody would have anyways, should the US not be a bunch of third world countries in a trench coat), but not eligibility.

So all you need to do is know somebody's name for that voting station. And since we're not checking IDs, when the "right" person shows up, how do we know they're the right person?

I have to show ID to get into my local zoo, but not to vote someone onto the board in charge of the zoo. That doesn't make sense.

Re: Swiss e-voting pilot can't count 2,048 ballots after decryption failure

#370

Earlier quoted context omitted.

> As noted, the number of fraudulent votes are astonishingly small, given the amount of money spent on proving otherwise How would you even know? The fact that prosecutions for fraudulent voting are rare tells you nothing. Prosecutions for tax evasion are also rare. Does that mean nobody evades taxes? If you have a system that’s insecure, how would you even know when it’s been compromised?

There have been numerous efforts to scrutinize the voting. In 2020 there were 62 lawsuits; none of them succeeded. Tax evasion is rarely prosecuted because nobody is looking very hard. People looked very, very, very hard for fraud in 2020 and found zilch.

Most of those 62 lawsuits were thrown out on procedural grounds, such as lack of standing (which I think was a bad reason: if the losing candidate doesn't have standing to challenge an allegedly fraudulent voting system, then who does?). But that means they never reached the fact-finding stage, so citing those cases as meaning "there was no fraud" is not supported by the evidence. The cases thrown out on procedural grounds only mean "no conclusion was reached on whether the facts alleged in the complaint were true".
Post reply on HN