Casting a vote online can be secure and convenient
spectrum.ieee.org
spectrum.ieee.org
This isn't why we don't have online ballots. The issue is specifically that you aren't in a voting booth, which means there is no control over voter influence.
Imagine a husband and wife plus a ballot initiative on outlawing flowers. The husband is strongly pro-flowers while the wife is strongly anti-flowers.
With online voting, the husband or wife can force the other to vote in front of them. There is no plausible deniability, so individuals are easily pressured into voting one way or another. Groups can say, "you need to vote in front of another group member" to pressure everyone to do what they want.
Voting booths prevent this, to a large extent.
Another issue is electioneering. By current law, one cannot campaign within 100ft of a polling station. This gives a "safe-space" where people can think about their options and make up their own mind. If I can vote on my phone, a random volunteer can get me all hyped up on the street and I can impulse-vote on the spot. Not a great way to run a nation.
(I'm not saying the current system is perfect, or anywhere close to it.)
So vote pro-flowers in front of husband, and then change your vote on your cellphone or in the library
As for the value of digital signature, I don't think it's legally equivalent to the physical signature, at least in my country. I've yet to see any administration accepting a digital signature.
I read through your parent comment and could not find any sentence for which the response "it does" makes sense. (Maybe the parent comment was edited?)
I can't imagine elections being any more screwed up, even including Jim Crow. Jim Crow has nothing on this.
But I'm still of the opinion that anything electronic is by nature untrustworthy. Just ask Microsoft, who for more than a decade or more has tried to lock down their O/S.
I know how the theory works. But that's just a theory regarding abstract concepts. Real voting doesn't work like that. At all. It's much more than the theory describes.
And if we get past all of that? Then we can start talking about how nobody who founded the U.S. wanted a democracy. Democracies are inherently extremely dangerous.
It's just a terrible idea masquerading as some cool new thing tech can do.
(It also reduces voting from an in-person civic ritual to just one more form you get in the mail and have to fill out and mail back, like paying a bill. But that's a whole separate problem.)
Whether or not that's enough of a problem to outweigh all the benefits of voting by mail, I don't know. It certainly lowers the actual barriers to voting: You don't need time off work to drop an envelope in a mailbox. But I do worry about the loss of ritual, and what it will do to voter engagement over a few decades.
Too bad. You can claw my mail-in ballot from my cold, dead hands.
This would rely on having is no method to determine how your vote has been cast, before or after the election. But this should be a feature of any online voting system.
For what it's worth my ex-wife slightly reprimanded me after a general election some time ago because I hadn't told her with whom I was voting for, because she would have cast the same vote as me.
On the electioneering thing I have no strong opinion. Just wanting to say that if a person's vote can be so easily influenced by a "volunteer hyping up" someone on the street then maybe, just maybe, that person's vote (and lot of other persons' votes) does (do) not accurately represent la "volonté générale", to quote Rousseau, meaning that universal voting might not result in what's actually best for the people. Related wiki link: https://en.wikipedia.org/wiki/General_will
But funny he should mention Estonia's e-voting scheme specifically. There was a very interesting look at Estonia's e-voting system at a previous CCC. Here is a video of the talk: https://youtu.be/JY_pHvhE4os
(Spoiler: Opsec fails begins at 42 min. But watch the whole thing, it's interesting.)
And the system in Estonia is not an especially bad example. E-voting in is hard even in theory, with issues like transparency and voting secrecy, but the systems in actual use have hasn't even nailed the engineering problems yet.
Voting requires authentication, verifiability and anonymity.
Online electronic voting only allows you to pick two.
They may be lo-fi, but paper ballots work very well here, and engineering a secure Internet voting system which maintains these attributes is a difficult problem.
The people who understand computer security and voting systems well will never design an Internet voting system, because they know it can't be safe. Unfortunately, that means we're left with systems deployed by those who don't understand these well.
But there is one more problem: most verifiable voting protocols are fiendishly complex for the average voter to validate, specially if they need to keep in mind how to verify things in a way that is robust to their devices being compromised. If you were holding an election where only people with a crypto or security systems Ph.D. voted and where they would rather punch you in the face than sell you a vote for 1 million USD, then you could have very secure online voting. The real world is a little bit more complex than that... one of the main advantages of paper ballots is that the technology involved is quite widely understood.
It's easy. You get a large screen "Thanks for voting, hope you trust us!"
When you use a SaaS, you have to trust the provider.
There's little problem in an election where only people with knowledge of cryptography can verify the official results.
1) Verify that my vote was correctly encoded and cast as intended. Every voter must verify this. It can be as "easy" as: printing a hash produced by a voting terminal/device you trust (which doesn't need to be government provided), submitting the resulting encoded vote into a (untrusted) government website where you authenticate with a smartcard, and then later comparing your original hash against a hash published in a newspaper... This exceeds the level of sophistication/care of most voters in any large country.
2) Some organization must check a large trail of signatures, zero-knowledge proofs of correctness, re-encryption mixnets, etc, etc. This can be done well enough as long as every political party and election watchdog has one or two crypto professionals in their employ.
I am not really worried about #2, even though it is harder, I am worried about #1. The important part is that all the checking of the world regarding #2 is useless without at least a representative subset of voters performing #1 (~1% would be enough, but only if distributed uniformly at random, otherwise you can flip votes from the population(s) least likely to check).
For an analogy: I grew up in Mexico during the 70 years PRI rule, and I can tell you in my city, in my polling station, with watchers from all major parties and a few ONGs, it is actually very unlikely that anyone stuffed the ballot. But in a rural area, where Spanish is not the primary language and the poll watchers were all from one party or few enough to be for sale... well... My point being that a similar scheme is quite possible when the barrier is "computer literacy" instead of "rights literacy" or plain old literacy (in the country's majority language, I mean). Either way, the smaller the group of people who understand how the election works, the easier it is to disenfranchise people.
It's not a hard problem, it's an _impossible_ problem.
If there's any security hole between the BIOS, CPU, firmware, OS, app, a state-sponsored attacker will get it.
The US got into air-gapped systems. You think China (or Russia, Iran, ISIS, Europe, Anonymous, you name it) won't break in?
And what do you do if you discover that there was external vote manipulation? Hold re-elections?
And how easy is it for someone to delete, say, a couple thousand votes in a strategic state? It's hard to physically do it without evidence and a conspiracy, but if a hacker (or a simple bug) gets in, all bets are off.
That's why the paper-trail is so important
- You enter into the voting booth with your ballot and cross off your preferred candidate or party. No trust needed.
- You fold it together and put it into a ballot box. No trust needed.
- The ballot box is sealed and driven to a counting station. This is done under supervision of all stakeholders, meaning that cheating is extremely hard because your political adversary is present.
- The ballot boxes are unsealed and the votes are counted. Note that the votes are counted by all stake holders (typically one or more people from each party) making it hard to cheat.
- The final vote is passed on.
None of the above steps require trust in any one person or entity, and the probability of cheating (if the procedure is done correctly) is quite low. If there is some anomaly the votes are saved so they can be counted again.
And again if "probability is low" is the bar, then we can surely keep _exploring_ Internet voting systems without engendering rejection as academicly 'impossible' for the whole concept.
Traditional ballots don't really provide any authentication. If you check your mail and find a blank ballot addressed to someone who used to live at your address, you can vote twice. Nobody will know unless that person comes looking for their ballot.
Traditional ballots don't really provide any verification. Sure, two weeks after election day I can look up the code printed on my ballot to see if it's been counted. But there isn't any way to verify that it's been counted correctly, nor is there any way to prove that the system isn't lying to me.
Traditional ballots don't really provide any anonymity. In addition to the aforementioned number printed on the ballot, my return address and signature of displayed on the outside of the envelope. I'm told that whoever or whatever opens the envelope won't look at the ballot inside, but I have no way of proving that.
Authentication, verifiability and anonymity are all properties that can only be implemented with together with the aid of cryptography.
And what cryptographic system provides a proof that your vote is counted for the total?
https://en.m.wikipedia.org/wiki/End-to-end_auditable_voting_...
Not to mention, the ability to 'undo' a vote is only marginally helpful in preventing voter coercion or vote buying - it only changes the way it's done a bit.
How would Estonia's online voting hold up to the kind of global assault that a US system would inevitably draw for example? If Russia, China and the US all went to work on trying to influence (or damage) the outcome by attacking Estonia's voting system, what would happen? All online voting systems will not all receive the same level of assault or garner the same kind of attention toward that end. The best technology companies in the world find it difficult to create an atmosphere of extremely high level security around information, transactions, etc. Outside of very large monetary theft, could there be a juicer target than being the group or hacker that collapses the US online voting system? It would make the front page of every newspaper on earth and would cause as much or more immediate financial damage than 9/11 did. The US stock market would at least temporarily shed hundreds of billions of dollars the next open day.
There is a very strong argument to be made that one size will never and could never fit all when it comes to online voting.
"The Estonia National Electoral Committee responded to their criticisms shortly after by saying that the theoretical attacks they described were not feasible."
But why wouldn't those attacks be feasible?
I don't recall convenience being a fundamental attribute of maintaining democracy.
Having said that, some countries' current voting systems are a mish-mash of different methods, approaches, technologies and even rules (I'm looking at you USA), that make paper-ballot voting less "convenient" than it could be. There's no reason why paper-ballot voting needs to be inconsistent across electoral boundaries, difficult to execute, or difficult to validate (cf: Australia's system).
Convenience is important to ensure a representative sample of the population is heard, and not just those who have enough free time to wait in line to vote. Mail-in ballots are a good example of convenience allowing greater participation.
I can see then, why for some, the argument that "e-voting can enable use of standover tactics" falls on deaf ears - because the risk is no different than what is currently the case.
However, it still requires that people "undo" their vote. I can imagine that a large percentage of people won't, so it will still be a net gain to coercion.
It seems like a good idea indeed but it could be countered. Force or pay a person to vote the last day and then to give you their ID until the vote is closed.
Of course, it's still a step in the right direction as it makes a large vote buying scheme harder.
1. _Right now_, I don't know how many nation states are trying to hack the election in Estonia. I know of quite a few who would be more than happy to do so in the US. And while it's true you can send spies... it's much easier and safer to hack from a safe base than to go into foreign countries (and no plausible-deniability).
2. You're _assuming_ no one's logging anything. There's no way to ensure that.