Just black box stand alone machines that are networked together with no outside scrutiny while popping out a magical final number is completely unreasonable.
Just black box stand alone machines that are networked together with no outside scrutiny while popping out a magical final number is completely unreasonable.
I studied cryptography, and it's hard for me to imagine a cryptographic proof I'd trust more than that system; it's almost impossible for me to imagine an implementation that I'd trust as much.
Most people have never studied cryptography, and will never trust a cryptographic proof at all.
At the end of the day, you randomly select say 1% of all the machines and hand count all the ballots inside, making sure the counts and votes match. If they do, then you can be reasonably sure it wasn't tampered with, and if they don't match, then you can hand count all the paper ballots using the old system to verify the computer.
If you're working on the assumption that there's a possibility that the machines may have been tampered with, does it not stand to follow that the procedures for redress may also have been?
It's a lot harder to tamper with a paper and pen system where many people are involved. To many people to rat you out, too many people to have to all do the right thing at the right time, etc.
Why? Because marking a ballot is the challenge?
How about we simplify ballots?
The Election Verification Network has studied the auditing of elections exhaustively.
Their conclusion: Expensive, approaching the costs of a full recount, and doesn't increase the certainty of the results.
https://electionverification.org
The correct answer (gold standard) remains precinct-based paper ballots tabulated on site when the polls close.
I studied a few of the crypto voting systems a while back. TLDR: For real world elections, they leak information. Meaning they don't protect the secret ballot.
Each system I studied relies on a hash collision to hide your ballot in the herd of ballots. Alas, our precincts are too small and our ballots to complex (too many choices, meaning too many combinations, meaning too much information) so the trick doesn't work.
Heck, it often doesn't now with mail ballot processing.
For comparison, when using paper ballots, dropping the ballot into the ballot box is the secure one-way hash that separates you from your ballot. Because it's physical, poll site based can also ensure the chain of custody, which is also not possible with electronic voting or tabulating.
Further, who would provide that implementation? A vendor.
Our election administration is increasingly outsourced (privatized). Using crypto would be the final nail in the coffin of public, citizen administered elections.
Aren't vote (re)counting efforts publicly scrutable?
Given active malevolent actors and the stakes at hand, the "perfect system" sounds very difficult indeed. Just take a look at how much Google's search algorithm is gamed/tweaked to see the arms race involved.
Give me pen&paper, and a transparent, well understood process over some unicorn-rainbow perfect system.
The reason this builds trust is that it is adversarial. Each party has huge incentive to find fraud or mistakes by the other. If they both agree that a result is valid, we can trust it's valid, because neither side gains anything by lying about that.
This is the same reason our system of criminal justice is adversarial.
A computer cannot replicate that, no matter how good the code. And it seems impossible to build a computer system that is completely trusted; for one thing the halting problem seems to imply that we can never fully predict all outputs of a given piece of code; for another:
Name two, err, one.