The voter checks this print-out is correct and submits it to an audit box as they leave the voting booth.
If it is incorrect, they file an immediate complaint, and the data is later corrected based on their unique vote identifier (this could be recorded in the audit box with a vote correction audit form for that identifier).
The physical audit counts can then be retained, and spot-verified against the electronic counts if/as needed.
This assumes (as I think we must) integrity of the voting officers and of chain of custody of the physical audit voting boxes.
>Some DREs can be equipped with Voter Verified Paper Audit Trail (VVPAT) printers that allow the voter to confirm their selections on an independent paper record before recording their votes into computer memory. This paper record is preserved and, depending on State election codes, made available in the event of an audit or recount. -https://www.verifiedvoting.org/resources/voting-equipment/
> unique vote identifier
This is also a serious problem if it is possible for the voter's copy of the identifier to recover their vote after they have left the voting booth. That would enable vote buying or coercing votes.
edit:
Unfortunately I'm not familiar with the detail of how mail-in ballots are handled. I should research that.
How is this issue currently dealt with in places that allow mail in ballots?
Bob may choose to deliberately change his signature so the ballot is at least invalidated, but that still takes a vote away from his preferred candidate, and would rely on Alice not knowing what Bob's true signature looks like.
Good question. The best answer I have been able to come up with is that those places are simply hoping that mail in ballots are too rare to make them a target. Increasing popularity relative to in person voting could challenge that, but with today's abundance of handheld cameras, in person voting stops being much safer.
You do gain a lot by going digital with the voting system as you can quickly count the votes.
But at the same time you can count on the integrity of the votes by keeping a physical backup with the paper votes, which can be checked if needed.
But what exactly is gained by that? The UK takes about a day, what are they losing?
I was in and out of our last election in Australia in 5 minutes, and it occurred on a Saturday.
It'd be easier to simply count all the votes cast on a convenient day for most people than apply statistical modelling to look for anomalies in predictive data.
> I was in and out of our last election in Australia in 5 minutes
Yes, but then countless people who pass voter ID laws and close polling stations in certain areas would be out of things to do.
That and then American politicians would actually have to work a lot harder, as right now they just count on mobilising their base to vote more than the other person's.
I'd love for voting to be mandatory, but let's face it, American politicians love the system in its current form.
https://www.youtube.com/watch?v=abQCqIbBBeM
edit:
Also, Ron Rivest was recently on Numberphile, where he talked about using homomorphic encryption to enable end-to-end verifiable voting.
We instead take extensive precautions with paper votes to physically protect the integrity of ballot boxes and the counting process explicitly to avoid having to have a system where votes can be verified, because there's been plenty of experience with what can happen if they can be.
The problem with most electronic voting is that it throws away this verification of integrity of the voting record.
I completely agree that electronic voting is currently a terrible idea. The other talk I linked to by Andrew Appel strongly encourages using only paper votes and statistically verifying them by manually recounting a random sample of voting locations.
However, I'm willing to listen to Ron (the "R" in "RSA") Rivest's ideas about using encryption in voting. I think the idea needs more work, but it's interesting approach that does attempt to address both anonymity and verifiability.
It's no doubt possible to make digital voting systems with some awesome properties, but in the end, are the improvements they give worth this loss of understanding (which might come with a decreased trust in the system)?
Suppose there's a method for calculating a fake choice token from a true choice token. This means that applying it to a fake choice must also produce corresponding fake choice tokens, otherwise a fake choice could be identified in this way. And by induction, any number of applications of the function must also reach a matching choice.
(This isn't a complete proof, but chasing up the remaining loose ends makes me think such a system is impossible, or at very least extremely complicated, and almost certainly impractical for non-mathematicians.)
I vote for candidate 0. The voting machine tells me the random number 1 (out of 0, 1). When the voting results are published, I can check that next to my name it has 0^1 = 1. When someone asks me what my random number is, I can either answer 0, to pretend I voted for 0(random number)^1(public list) = 1, or 1, to say that I voted for 1(random number)^1(public list) = 0.
Or any variation of it.
Such as? Was there ever a time in the history of modern democracies where "vote receipts" were actually used and caused problems? I was under the impression that they've never been used out of preemptive fear.
Stallman is, as per usual, completely wrong about the power of free software.