https://www.youtube.com/watch?v=abQCqIbBBeM
edit:
Also, Ron Rivest was recently on Numberphile, where he talked about using homomorphic encryption to enable end-to-end verifiable voting.
https://www.youtube.com/watch?v=abQCqIbBBeM
edit:
Also, Ron Rivest was recently on Numberphile, where he talked about using homomorphic encryption to enable end-to-end verifiable voting.
We instead take extensive precautions with paper votes to physically protect the integrity of ballot boxes and the counting process explicitly to avoid having to have a system where votes can be verified, because there's been plenty of experience with what can happen if they can be.
The problem with most electronic voting is that it throws away this verification of integrity of the voting record.
I completely agree that electronic voting is currently a terrible idea. The other talk I linked to by Andrew Appel strongly encourages using only paper votes and statistically verifying them by manually recounting a random sample of voting locations.
However, I'm willing to listen to Ron (the "R" in "RSA") Rivest's ideas about using encryption in voting. I think the idea needs more work, but it's interesting approach that does attempt to address both anonymity and verifiability.
It's no doubt possible to make digital voting systems with some awesome properties, but in the end, are the improvements they give worth this loss of understanding (which might come with a decreased trust in the system)?
Such as? Was there ever a time in the history of modern democracies where "vote receipts" were actually used and caused problems? I was under the impression that they've never been used out of preemptive fear.
Suppose there's a method for calculating a fake choice token from a true choice token. This means that applying it to a fake choice must also produce corresponding fake choice tokens, otherwise a fake choice could be identified in this way. And by induction, any number of applications of the function must also reach a matching choice.
(This isn't a complete proof, but chasing up the remaining loose ends makes me think such a system is impossible, or at very least extremely complicated, and almost certainly impractical for non-mathematicians.)
I vote for candidate 0. The voting machine tells me the random number 1 (out of 0, 1). When the voting results are published, I can check that next to my name it has 0^1 = 1. When someone asks me what my random number is, I can either answer 0, to pretend I voted for 0(random number)^1(public list) = 1, or 1, to say that I voted for 1(random number)^1(public list) = 0.
Or any variation of it.