And voting through a web app is wrong on so many levels:
- "Electronic voting": Electronic voting machines already have a bad enough track record. If nothing else, it makes large-scale attacks easier. Voters have to trust the ballot operators (different from home banking, where (a) you can choose your bank and (b) manual banking wouldn't be better either).
- "Electronic voting, at home": Assuming [1], it wouldn't be coercion resistant, wouldn't be independently verifiable, couldn't guarantee vote secrecy to voters and be susceptible to ballot stuffing, open against technical attacks (eg. as simple as DDOS, or malware).
- "Electronic voting, at home, in a web app": No local (non-attacker-controlled) code means you must trust server completely. And its basically impossible to really isolate the voting from everything else.
All these problems for what? Paper ballots really aren't so bad. Especially if you eliminate two of the obvious problems US elections have: get rid of voter registration, and move votes to sundays.
[1] Assuming you don't use a cryptographic voting scheme; these have their own problems. It's an entire field of research that just can't be summarized in an HN post, but key problems are: a) impossible to understand by voters, b) some desirable properties are mutually exclusive, c) computationally prohibitively expensive (even with state level resources), d) some problems aren't technical in nature and can't be solved technically (think coercion).
Most banking -- "home" or multi-millions -- is done electronically. It's safer.
Banking is a completely different problem. The secrecy requirements are different - in fact, audit trails of all individual transactions are expected. Big transactions are typically individually reviewed by humans. People/organizations can choose their bank. There are multiple banks -> no single target. Transactions can be traced and rolled back, so coercion is less of a problem. Risk is mostly financial.
Do any of those exist? Is this possible in practice, in this decade?
I'm neutral on web voting, because I basically agree with all the observations you make. But I think it's important to look at things from the individual perspective as well. Voting by mail seems like the best option to me at present.
As an aside, all these discussions miss something significant: even if you can vote with ease, it's too damn complicated. Most people just don't have the time or knowledge to properly evaluate all the various ballot initiatives at the local and state level in many jurisdictions, nor are most people able to properly evaluate candidates for all the various offices in local elections. Frankly I don't think people should even be allowed to vote for offices like judgeships and public prosecutors, since almost nobody has the education required to assess any of the candidates properly and almost invariably end up choosing whoever happens to be the most photogenic candidate instead.
1. Internet voting is not compatible with democracy
2. No amount of technology can change this
3. Whom you voted for ought to be secret
4. Who voted should not be secret -- it should be known as widely as possible
5. And who counts the votes, and how, certainly ought not be secret
Here's one way that a crypto-voting protocol might give you this right. It provides for a separate ballot for each race, and each ballot has a perforation down the middle so you can separate it into two halves. The candidates are randomly ordered, with their names on the left-hand side of the perforation and your vote on the right-hand side. When you vote, the machine tears off the left-hand side and returns it to you, while it scans in the right-hand side, and then locks it in a secure box for auditing. Then your vote is recorded in a public database with your name and which-number you voted for, but the correspondence between that number and that name is only privately recorded on the half of the ballot that you retain. So you can verify that the database says 3 and that was the Green Party candidate who you voted for; but nobody else who sees the 3 on the web site knows directly what it means.
The protocol might then do two more things with this two-sided randomized ballot:
(1) Create plausible deniability. This is done by putting other left-hand-sides of other torn ballots into the voting booth, for you to choose from. Even if your boss demands that you vote Libertarian and goes so far as to hire goons who mug you for your piece of paper on your way out, that boss cannot prove that you didn't just take a left-hand-side from the voting booth which "proves" that you voted Libertarian, even though you voted Green. Suddenly the only people who can buy votes are state-level conspiracies who can put cameras in the polling stations etc. It may sound weird that you're making it hard for someone to sell their own votes, but it makes it hard also for anyone else to thereby buy them.
(2) Create confidence in the two-sided ballot. The biggest point of lost confidence in the two-sided ballot is that when you see 3, you think that you know who you voted for, but who's to say that these numbers match up with the votes that are stored in encrypted form on the ballot? You will want to therefore let someone decrypt a ballot or two at their leisure, to build up this confidence. However if you do, the thing is decrypted and no longer suitable for voting, so it must be immediately destroyed. So that's the end result; you have this thing called the Checker which issues a network request to the election authority asking for a ballot to be decrypted; when it is, its right-hand side is simultaneously shredded. It tells you the order that's on the left-hand side; you verify that against the actual left-hand side. Boom, there is no longer any tampering with the mapping between names and encrypted data, at least not on a large scale, by anyone who is not the central election authority themselves. If there is, people will hopefully notice and complain loudly.
The government mails a form to the address you registered when signing up as a voter. You complete a legal statement with a fairly high penalty for being caught lying. Then you return this legal statement.
There are security issues with this process, but for the most part it's no worse than how humans vote otherwise, and careful message encapsulation designs can make the /cost/ of manipulating individual votes in transit high while making the actual voting form 'anonymous'.
Online voting would only be more secure than this if the message were signed, and audit-able by both the signer and the recipient. This is possible, but it also complicates external review since they would also need to validate the identity of the signer.
At a very minimum a record of /who/ voted (and presumably when) would need to be known as a result of validating voter registration.
Vote tabulation could be separated if the registration validation stage fed a stripped (and trusted by the org) packet of cast votes.
However this presumes that you believe in the security of the /entire/ computing stack from base firmware up through the OS and counting applications. Auditing that is a LOT harder than humans tracking paper; we've had centuries to figure out how to do that in fair ways.
Mail-ins are already problematic in that regards.
So, despite all the flaws that you point out, why are these legal but a mobile app is not?
Here in Czech Republic we receive voting tickets by mail about a week before election and have to physically put them into a box behing a curtain in a voting room. I also see weakness here, and don't understand why we receive voting tickets by mail, because it allows you family relatives filter your tickets. Better system would be if the voting tickets were available only in the voting room.
Still it is better than web app. There are more security concerns with online voting, you can read more about it here: https://security.stackexchange.com/questions/15417/online-go...
Electronic voting and their associated processes are complex and verifiable by only a small portion of the population (those who are both smart enough and technically skilled enough to dive into the code). Even then very few people have the skills to determine if hacking or other forms of tampering take place.
As a technologist there's too much incentive for a bad actor to tamper with electronic voting and it is too difficult to check if tampering has occurred.
That is the core difference.
Without personally identifiable votes, we have no way to assure the voter their vote record cast matches their intent as they have no trusted way to evaluate that record.
When we press a butyon, or touch a screen, we have to trust the feedback we get. When we make a physical mark, the chain of trust is complete.
The problem is the machine can literally do anything and then just tell us what we want to know is true without it actually being true.
Electronic records are a forced vote by untrusted proxy.
Financials are personally identifiable and multiple parties are involved, which catches this problem nicely. That is why they work as well as they do.
The problem with home electronic voting, other than hacks, is that a voter can be coerced into voting for someone that they don't want. So the Estonian system has it that you can vote multiple times and only the last vote counts, you can also vote in person using paper and that trumps electronic voting.
https://media.ccc.de/v/31c3_-_6344_-_en_-_saal_1_-_201412281...
You can't have a bank account without ID, you can't even cash a check without ID. You can't get Medicaid or food stamps without ID. You can't even enter the White House without ID. Yet allowing people to vote without any means of verifying who they say they are? That's ludicrous. Every single state with voter ID laws has provisions for those that can't afford it.
So why oppose voter ID?
Requiring an id to vote might make some sense, but what doesn't make sense is making the id difficult or impossible to get (see Texas and North Carolina for examples). So much effort is being poured into voter id laws, but none is being put into getting citizens the "correct" id to vote with. Why is that? (I may be wrong here and maybe you have more info, if you do please provide links that show where the people proposing voter ids have also made it easy to get an id)
What other purpose aside from government sanctioned suppression would getting rid of the provision of the Voting Rights Act of 1965 requiring states to get federal approval before changing their voting laws serve? From what I understand, the justices that voted to get rid of the provisions did so because there was lack of data suggesting that there were issues at the ballot for people of color. But where is the information and data that supports the massive amounts of voter fraud that was heavily talked up before the vote?
If it was me making these decisions: I'd verify each person against a national fingerprint and facial database before even letting them fill in the ballot form and only accepting their vote if the verification was positive.
I vote with a mail in ballot. My signature is checked by a human being (I know as a family member was audited when their signature differed from historical).
Couldn't web-based replace paper-based mail-in ballots?
With an on-file signature that generates a "voting token" that could be mailed to me for goodness sake, I don't see why mailing in a piece of paper with ink on it is a necessary step.
I can recognize two problems with these.
a) vote buying, b) vote stealing.
Risk for vote buying is similar for both methods but electronic voting has in my opinion higher vote stealing risk as it is easier to implement on large scale.
I think both methods are suspicious and I am not in favour of them, but as usage of mail-in voting is not widespread, it does not involve too big risk.
Contrary electronic voting may become very popular and problems will be magnified.