Live data from Hacker News

To Protect Voting, Use Open-Source Software

mobile.nytimes.com

91–100 of 237 posts

Re: To Protect Voting, Use Open-Source Software

#91

This is plain bullshit. Opensource gives no guarantee that the vote won't be altered by whoever runs the machine. What we need is a zero-knowledge proof: we need the entire voting dataset to be publicly downloadable and some kind of checksumming so that, while maintaining anonimity, I can 1)check that my vote is the same 2)run whole the counting in a blink on my PC. This gives much better guarantees of no tampering

One other requirement too.

3) Users should not be able to prove to another person who they voted for

This is to prevent people from using threats of violence or promise of reward to coerce others into voting a certain way.

Unfortunately, this requirement is very hard to fulfil while also fulfilling requirement 1.

Re: To Protect Voting, Use Open-Source Software

#93

This is plain bullshit. Opensource gives no guarantee that the vote won't be altered by whoever runs the machine. What we need is a zero-knowledge proof: we need the entire voting dataset to be publicly downloadable and some kind of checksumming so that, while maintaining anonimity, I can 1)check that my vote is the same 2)run whole the counting in a blink on my PC. This gives much better guarantees of no tampering

I think this make a lot of sense. I'm not sure a checksumming method that can indicate tampering can be devised, but my hope would be that by making the data publicly available for every stage of the processing pipeline, auditors or interested parties might be able to detect fraud.

But the data is worthless if you cannot trust the way is has been acquired.

Re: To Protect Voting, Use Open-Source Software

#94

Well, IMHO a good way to digitize voting would be to give out a USB-drive-like (NFC) device with an option to set a value and lock it in the read-only mode using voter ID. How it will work: A person gets this device in the voting center enters/gets his voter ID, does the voting (anonymously), presses the read-only lock and throws it into the bin. After all the voting these device are scanned and voting data is retrie…

The only winner in that scenario is the company manufacturing the NFC devices. That system is too complex.

Re: To Protect Voting, Use Open-Source Software

#95

Earlier quoted context omitted.

The vote processing chain is lengthy, it is inevitable that a computer system will be inserted somewhere in that chain. Right now the push is to have these systems right at the front, facing the voter, but that isn't the only time the votes are processed electronically. In my district we vote by coloring in little circles with a #2 pencil, we then feed that directly into an electronic machine that tallies the results…

> With so many links in the chain, it's my opinion that it's unreasonable to expect them all to be processed by people. It won't scale and I'm not convinced that it's that much safer anyway. I think the main argument for physical voting is that it's much safer precisely because it doesn't scale well - and so attacks against it don't scale well either. The manpower requirements buy you security. > As painful as it is,…

>>> I also agree with the people who point out that inserting electronic systems destroys that transparency (too easy to hack, too complex for general population to inspect).

Spot on. Democratic process means "owned by people". So the voting system must be able to be run in the hands of the people. Hence the necessity to have it in the form of a simple technology such as pen/paper.

Moreover, having the votes counted in some hours instead of a night doesn't make a big difference, considering the time that is needed for example, to form a government once the vote is closed.

I love computers, but it's not the right tool for this job. It's not much different than free software : the problem here is political rather than technical.

Re: To Protect Voting, Use Open-Source Software

#97
post #3

Electronic voting is a bad idea and I'd be suspicious on anyone trying to promote it. How can you know that even if the source code for the voting machine is open, the voting machine is running the exact same source code? How can you know nobody has tampered the code the instance is running? I'm glad my country is still running on paper ballots and glad we require voter ID.

The vote processing chain is lengthy, it is inevitable that a computer system will be inserted somewhere in that chain. Right now the push is to have these systems right at the front, facing the voter, but that isn't the only time the votes are processed electronically. In my district we vote by coloring in little circles with a #2 pencil, we then feed that directly into an electronic machine that tallies the results…

Your entire premise is based on there being a long complicated chain, which I think is a bit of a red herring. Voting happens in districts. The totals for those districts are already posted publicly. There's no need to validate the entire chain when the lowest level is already open and free to be audited by anyone. Additionally, for the districts I'm familiar with, polls are staffed by volunteers and anyone is free to stand around and watch the whole process.

A paper ballot system where local volunteers from the district count the votes at the polls in a manner that can be observed would absolutely work for the US. It would be pretty easy to just write down what the volunteers counted and then check later whether that matched up with the nationally posted numbers. No long chain to decipher, no obscure software to worry about. And, as a bonus, there are places where this is already done this way, so really nothing needs to change policy wise (other than eliminating the other methods).

Re: To Protect Voting, Use Open-Source Software

#98

Earlier quoted context omitted.

The trick is that you don't just have to convince somebody (a security expert) that the system is trustworthy, you have to convince everyone (voters) that the system is trustworthy. Anything more complicated than paper ballots counted in public will leave room for doubt.

Paper ballots leave a lot of room for doubt in my mind. How you can you recount the ballots and come up with a different number? This shouldn't be possible, but it happens all the time: https://en.m.wikipedia.org/wiki/Election_recount Thinking out loud here, how about a blockchain based solution? Each user gets a new address, and that address is printed on a receipt after you vote. This way you can verify your vote a…

A ballot design that is prone to getting different results when recounted (hanging chads, etc) is a bad ballot design. Fix your ballot design first.

>Each user gets a new address, and that address is printed on a receipt after you vote. This way you can verify your vote at anytime, and the votes can be counted in public.

Voting receipts like this are bad. They enable people in power (bosses, spouses, etc) to intimidate you into voting the way they want to see and threatening to punish you if you don't because they can force you to prove the way you voted. It also allows vote buying.

Re: To Protect Voting, Use Open-Source Software

#99

Earlier quoted context omitted.

The trick is that you don't just have to convince somebody (a security expert) that the system is trustworthy, you have to convince everyone (voters) that the system is trustworthy. Anything more complicated than paper ballots counted in public will leave room for doubt.

Paper ballots leave a lot of room for doubt in my mind. How you can you recount the ballots and come up with a different number? This shouldn't be possible, but it happens all the time: https://en.m.wikipedia.org/wiki/Election_recount Thinking out loud here, how about a blockchain based solution? Each user gets a new address, and that address is printed on a receipt after you vote. This way you can verify your vote a…

Good question. Volunteer to help with your local elections. Learn how it's done.

As for blockchains: Voters sign in before they cast their ballot. If the order in the pollbook matches the order the ballots are recorded, no more secret ballot.

Any crypto- blocko- based system that both protects the secret ballot and ensures the public vote count (aka Australian Ballot) has to create a digital equivalent to the physical secure one-way hash (shuffle) of dropping a ballot into a box.

Re: To Protect Voting, Use Open-Source Software

#100
post #83

Earlier quoted context omitted.

That should be solved by issuing a free government ID, not by compromising and creating a giant loophole when potentially citizens of other countries can vote in your election and there is no way to verify that.

Like I said, studies shown that having an ID didn't change much. Plus, they already can! Commonwealth citizens can vote in UK elections pretty much as soon as they arrive.

I question the results of these studies. I think it's very difficult to measure empirically how many people are cheating if it is not required to have voter ID / some sort of proof of your identity when voting.
Post reply on HN