Votebook – A proposal for a blockchain-based electronic voting system [pdf]
economist.com
economist.com
- Hack the voting machines to just turn on the "duress" mode for everyone, or do it just in the precincts that tend to vote for my opponent
- Use my great new paper receipt to prove I have voted for candidate A and collect my bribe as if the paper receipt doesn't encode the candidate it's useless. I don't care to verify if my vote was counted if I can't verify that it was counted for my candidate
- Hack the voting machines to record candidates at random ignoring the key presses, turning the election into disarray
- Selectively deny network access at polling places to create longer queues at the sites where my opponent is stronger
I'm sure you can cause a riot or two pretty easily. The fact that paper is dumb and paper elections use extremely simple technology, math and process is a feature not a bug.
As a citizen, I want to be more involved. Even in a representative democracy, I want to hold my representatives responsible for their actions. I want to be able to recall them. I want to support some bills and oppose others. I want to have votes in my local community about building a playground or whatever. I may even want to propose policies and have other citizens vote or maybe even crowdfund it.
While I do not support this specific proposal, I think we should move on from paper elections.
I would think that as the response time becomes shorter and shorter, the system starts being more and more volatile. One of the benefits of the current system is its stability. It's unfortunate (depending on your point of view) that certain causes don't move faster, but at the same time it also prevents bad ideas from moving fast.
Not only that, but as the involvement is more and more frequent, it might have the effect of numbing people more. Right now national elections are a big deal because they are so rare, so it adds a bit of "moral weight" to the whole process. If they are as easy as pulling out your phone and tapping a button from your couch, is that actually going to result in more "correct" (in terms of long-term viability) decisions being made?
These things might not actually matter though, because they might have equal and opposite benefits that balance things out.
I'm sure many people smarter than me have debated this topic from both sides. If anyone knows of any articles/papers on these ideas I'd love to read them!
I think a lot of people are indifferent because it doesn't seem to matter whether they vote for the red or blue team every few years, <insert favorite cause> doesn't seem to be improving. If they had a slider to set their preferred allocation of public spending and they could vote on specific proposals about <their favorite cause>, they would probably be more inclined to participate and do so in a more responsible manner.
You can't force people to participate though. Maybe you could optionally delegate your vote, and then it would be effectively the same level of involvement as with the current hands-off representative system. But at least you could still withdraw or reassign the voting power at any time.
Recently they tried out e-voting, with what I consider predictable results:
http://www.swissinfo.ch/eng/voting-with-a-click_hacking-fear...
Also, I agree with ianstormtaylor in that I don't think that what you're proposing would necessarily be good. You need a political system that you trust will promote wise decision makers, and then you need to not micromanage them. If the people who get elected can't be trusted to make good decisions on a scale of several years, then the political system needs to be corrected, not expanded.
Sure it might get harder with increase scale, but I don't see it as a huge problem.
Can we start with the city? Bill de Blasio (bless his heart) won 282,344 votes in the 2013 Democratic Primary. What's worse is Lhota won his primary with just 32,236 votes. https://en.wikipedia.org/wiki/New_York_City_mayoral_election...
I hate to agree with President Obama on this topic but I have to agree with him. The first problem we need to tackle is not to fix the electoral process. The first problem we need to tackle is getting people to actually care enough to show up and show up in large enough numbers so we can effect change.
He has a point there. Transportation, heavy machinery, power grids, cruical infrastructure, healthcare, economy and so on all increasingly run computer systems with questionable security. Lives and world order depend on them. Are we really going to draw the line at voting? (edit: expanded on this point a bit)
Trust on the scale of several years is a difficult thing. People go from lovers to archenemies in that time. But yes, some long term projects do need stability and long term support to become fruitful. You could introduce constraints to support this, or trust the voters to take it into account.
But even more important than time is the granularity of trust. Just as in everyday life I trust different people to different degrees in different domains, I would love to have a voting system that reflects this with regards to political representatives or activists.
If you can change that byte across even a small percentage of voting machines, you can leverage that into control of the country's government.
All of the examples you listed are continuously running, auditable, highly heterogeneous systems that can have multiple parties cross-checking because there isn't the absolute need for the actions of the participants to be untraceable back to them, the way it needs to be with voting.
I work with government often. I am often outside begging to be given access to help my community with one civic project or another. Interactions that take hours in open source communities, take months to coordinate with City staff.
I'm the last one to advocate taking the brakes off the car, but there are many many many parts of government where decisions require several years only because everything takes years to do. I think there is a perspective, if you step back to imagine this world, where we as citizens can participate and make the turn-around quicker. Not everywhere. Many government functions require care and caution and sober second/third/fourth thoughts.
But many of these actions need not take years, if we could re-imagine something better. And right now, the lifeblood of government runs like molasses, not because each slow process has been intentionally made slow, but because the processes and practices and hierarchies are structurally slow at their core. That's not clever slowness. That's a calcifying fossil.
I personally think giving citizens more decision-making access will keep civil servants on their toes, keep them learning, and speed up the cycle time in many needlessly slow areas of government.
In principle, frequent voting might sound nice. But I don't know if it really would be in practice. (I'm not arguing a position here, just thinking out loud.) I'm not really interested in most politics, I don't really feel qualified, or compelled to become qualified, to deal with a lot of the questions that come up. I'm pretty happy to instead vote for a person (or even just a party) to represent me in most cases. I don't want to propose policies.
Lots of people in my town are retired and/or seem to have endless time and energy to devote to meddling in town business. It would be exhausting if I had to keep constant vigilance every few weeks or months to make sure these people can't enact policies, rather than just voting every few years to make sure they don't get into office.
At the same time, I do want to vote directly on issues I have a strong opinion about, I'm willing to put in the effort to find different people to delegate my votes to in domains I'm not competent in. Occasionally I may have an idea I would like people to discuss and vote on. If people like the idea, they may even delegate their votes in that specific domain to me and I would be further motivated and empowered to come up with and champion similar ideas.
I think technology would allow everyone to find their sweet spot of involvement in this spectrum.
Essentially votes can be cast on every subject (for the very interested voters), or delegated to another representative (for the less interested voters).
This could have some interesting side-effects, not all positive; I'd expect volatility and cult of personality to increase. But then that's the trajectory of politics in general recently, so perhaps there's not much more to lose. Benefits would include the ability for voters to actually enact the legislation that they want, but which no legislators will choose to implement (e.g. anti-corruption/insider trading laws).
[edit: link is here: http://www.tdcommons.org/cgi/viewcontent.cgi?article=1092&co...]
If you're willing to do away with the requirement that you can't prove to someone else who you voted for then you can implement mail-in voting. Still paper and you can have an election every day if you want. Some US states use that. Once you go that route a simple HTTPS website run by the government that you authenticate to is all you need for electronic voting with the same guarantees.
Voter suppression and other ways to make less people vote are the same in both kinds of voting.
They are distributed, based on different standards and access to them rely on physical access plus 75% of them have a paper trail.
They are as secure as anything out there IMO even if the boxes can be easily hacked.
They're much less secure than just dumb paper and pen. That's the point.
Of course, the particilar implementation of an electronic voting protocol can be hacked. Also, some cryptographic algorithms are not proven to be completely secure, so there is a chance that someone will learn to break them. We should take those facts into consideration and be aware.
What about paper elections? Aren't they fundamentally broken because of their protocol? I go to the election, sign a ballot paper and drop it into a box. Then some people from the government report me the voting result. Why should I trust it? Because I trust all the people who were involved in collecting the ballots, counting them and so on?
Why should I trust people at all if the cryptography allows me to verify their actions?
You are afraid of voting machines being hacked? No problem, let's use paper. I'm OK with paper certifying my vote as long as my digital signature is printed on it (in hex, QR-code or whatever). Alternatively, the government can publish an open protocol of internet voting so that everyone can use an implementation that he accepts to be secure.
Should be noted that I am not very proficient at cryptography. All I know is based on a couple of books and a university course.
People that want to propose complex electronic voting systems need to first understand the requirements of an election and how the paper voting achieves them. There's quite a lot of well thought-out systems thinking in paper voting that people just don't know about.
I was arguing against treating a blot on a paper as a certification of one's opinion rather than proposing a real electronic voting protocol. Of course, simple digital signature doesn't solve all the problems, it only certifies with known assumptions that I and only I have signed the document.
Far more voters is worth complexity. Security should just something we must engineer and deliver. Maximizing people voting is the real goal, outside of engineering excuses and worries.
This means that you have to trust the:
* VPN
* OS
* Network stack
* Display and input drivers (HW and SW)
* SSD controller
* CPU
* CPU's "Management Engine" or equivalent
* Mainboard chipset
To all be free of exploits and backdoors. You're trusting many, many thousands of people, from hundreds of different companies in several different nations, to not have put backdoors in, despite the fact that backdoors and exploits have been discovered after the fact in essentially all of the listed components.I don't say this lightly: the authors are dangerous fools. They're fools to think that this is secure enough for an election. And they're dangerous because someone in power might believe them.
That's pretty hard. How, for example, are you going to get a CPU bug to do this for you?
I'm not saying it's impossible, but it's sort of like saying that we're fools for using gas-powered engines for the military. Thousands of people design them, so how do we know the designs haven't been sabotaged? You might be right, but you're probably wrong.
Except that many of the backdoors are universal backdoors, meaning that they can be remotely updated with new instructions.
Additionally, if you really made something that specific, that was only ever discovered and used to hack an election, and the only people that could have done it were the chip vendor... how do you think that will play out when it's discovered? Or do you, as the attacker, bank on no one ever discovering this, ever?
If you're an engineer working for one of these places, how much do you have to get paid, or what do you have to be threatened with, to make this work out?
This seems much more like a novel written by Ian Fleming, not le Carre...
Second, at the silicon level there's billions of transistors in a CPU, silicon in general is prohibitively expensive to audit, and you can do malicious things by just putting in nigh-undetectable changes in dopant levels:
https://www.schneier.com/blog/archives/2013/09/surreptitious...
Third: you don't need to hide the hack forever. You just need to gain enough power in the election that you can suppress any further investigation.
Given the parade of hacks that make the HN front page every week, at all levels of government and industry, given that the well-funded and incredibly paranoid US military inadvertently deployed backdoored chips, given that existing voting machines have had demonstrable amateur-hour exploits in them:
http://fortune.com/2016/11/04/voting-machine-hack-watch-vide... http://www.pcworld.com/article/135461/article.html
is it really that difficult to believe that voting machines can be hacked?
And you don't have to put in the backdoor just for the election. You can put one in and use it opportunistically. Someone backdoored a huge amount of Juniper VPN hardware, in hopes that it might be useful some day:
http://arstechnica.com/security/2016/01/juniper-drops-nsa-de...
And to answer your question, this is how you get silicon like a CPU to do what you want:
https://www.schneier.com/blog/archives/2012/05/backdoor_foun...
These are just two examples that made the news. It's a practical certainty that there's backdoors in all sorts of COTS components that we don't know about yet. At this point there's nothing above suspicion.
For the scheme in TFA to work, they need a unhackable computer. If there is a single exploit or backdoor that happens to be in it, whoever controls it can pick the US congress, the senate, and the POTUS. Not metaphorically, literally. How is taking that degree of risk, when you know that backdoors and exploits are commonplace, not incredibly foolish?
Modifications at the hardware/OS level can deliberately misrepresent the voter input from the touch panel, and can then alter what is displayed on the screen to match what the voter expects.
No matter how bulletproof the encryption protocol is, it still needs to be fed a choice via an analog, unencrypted channel because human beings are analog and unencrypted. If you control that channel, it's game over.
And you can't get around that by having a system that enables people to verify their vote at a later time on a second (presumably unhacked) machine, because then you'll also enable the forcing of voters to prove that they've voted the way that they've been coerced to.
For example, chipTAN is commonly used in Germany to verify online banking. You have to trust the chip on the banking card and the card reader, but not your computer, network connection, or your smartphone.
A similar device may also work for online voting. The hardware would be simple enough to audit it. Your computer would never learn the vote.
There's the whole business of securely distributing the chips (so they're not swapped out with counterfeits in transit), dealing with theft (and coersion to not report the theft), etc. But yes, if you can get a never-network-connected, brutally simply, completely automated voting device into 230 million hands, then I can't think off the top of my head how to exploit that. I would move on to trying to exploit the tallying system.
At that point, though, is it really cheaper than paper ballots? Perhaps it's worth it to engage more voters, but it still seems like a terrible risk to take - I'm only very grudgingly aware of computer security matters, just because I can't think of a way to exploit it, doesn't mean that one of the 7 billion people out there won't. And it only takes one.
Also I should point out that my original point stands - what you bring up is a million miles from what they proposed in TFA.
- Did my vote get counted? (can you prove it)
- Did it get counted correctly? (can you prove it)
- Can a vote be both traceable to the voter and anonymous publicly?
The parallel to blockchain is simple. I get a "vote coin" that I can spend at the election. You can then see who has the most votes. The challenge to overcome in any block-chain approach is how to prevent votes from being bought and sold.
If done correctly you don't have to trust the hardware to trust the election. If done correctly we could vote by phone.
if you can get votea into the hands of legitimate voters, the rest falls into place.
As a proponent of blockchain-based voting. we're not hitting the 10x better rule with this solution.
https://roamingaroundatrandom.wordpress.com/2014/06/16/an-mp...
Votebook proposes using a blockchain as a tamper evident (immutable) audit log. Because voters sign-in chronologically, recording votes in order removes the secret ballot. Votebook's proposal is to group up multiple into "blocks" and randomize the order within a block.
Randomizing the order of the votes in an audit log would simulate the secure one-way hash of dropping your paper ballot into a ballot box.
Poll sites are "bursty". During rush hour, lots of voters, so blocks will span small time windows. During midday, blocks will be large.
1 - How large must these blocks be to guard the secret ballot? Using some differential privacy mojo might determine they have to be 100 votes. I'm skeptical. It's problem even today with poll sites and postal ballots. Situations like small precincts or low turnout. In which case, Votebook is adding complexity without any real world benefit.
2 - What happens with the vote data as blocks are being built? So now this system has plaintext data in memory awaiting processing. Oops, power outage. Oops, software bug.
3 - Votebook does not solve the problem of properly, accurately recording the ballot as the voter cast it.
4 - Votebook will be cryto-based, necessitating further outsourcing our elections to vendors.
5 - I would never be able to explain how Votebook works to my mother (Jane average).
Blockchains are useful in situations where centralized trust can't be established or would be less valuable. If you can't trust the government that's running the election process, how would a blockchain solve that?
Too many blockchain proposals just boil down to building a slow, expensive to maintain database.
There are cheaper ways to get transparency than a blockchain I think.
The first clause of Design Considerations, "Although elegant and (thus far) invincible," shows a lack of understanding of currently possible and prior blockchain attacks.
This protocol allows voting any Voter ID multiple times. There is a significant window of time until one of the blocks containing the Voter ID/ballot ID Hash is added to the block chain. During this time, all Voter IDs in the prospective block may be voted multiple times. This can occur by making a copy of a physical voter ID and simply using it twice at relatively the same time - just not on the same terminal. The exploitability chance increases as the number of votes per block increases. The blockchain plus the union of all unsent blocks for all terminals, not a local database, should be checked for who has voted. This is compounded by not checking when the blocks are added to the blockchain.
Another issue with the local database, is that even if it is made to be a site database, many jurisdictions with early voting allow voters to vote anywhere, not just at their assigned voting location.
The selected candidates are not signed properly with a voter's key. There is no assurance that a particular voter actually cast a vote for a specific candidate and not, say, "Mickey Mouse." This is actually one of the purposes of smart cards and similar. Beyond any protocol issues, this is the central purpose of any voting system, to ensure that when votes are cast the voter id is redacted but that that voter id's candidate selection can be validated!
The Central Admin should release the list of the machine's public keys _prior_ to the election not _after_.
There really are a lot of security issues with this security design.
That being said, this paper is the winner of a cyber challenge here: http://www.economist.com/whichmba/mba-case-studies/cyber-sec...
https://roamingaroundatrandom.wordpress.com/2014/06/16/an-mp...
Programmer in video says it all: https://www.youtube.com/watch?v=1thcO_olHas&sns=fb
Paper ballots are really the best for these reasons:
1) Fits human time frame. a large number of voters make up their mind incrementally. They take the mail ballot and mark the offices/measures that they know for certain on. Come election day they show up at the precinct with almost everything filled out. They then sit down and decide for everything else.
2) Does not require good eyesight. Older voters, younger voters, what ever - a simple magnifier can easily be used. We have them at the polling place.
3) Voter can vote on issues nonsequentially. Voting machines present the issues in the order they are on the ballot - not the order that the voter wants.
4) Speed of voting: if a voter knows how they are going to vote they can fly through a ballot in a couple of minutes. Voting on a voting machine takes a minimum of 6. Add in all the back and forth on the screens and it is frustrating for voters.
5) Ability to handle crushload of voters: If I have a lot of voters ready to vote: I put them anywhere in the room I have a seat, flat surface and a pen. With electronic voting machines I am limited to number of machines.
6) requires no training: everyone knows how to use a pen. Computer program... not so much. And I am not talking about tech sophistication. Anytime anyone uses a new program they have to slow down and make sure they understand what is being asked and what are the choices.
7) clarity of errors and error recovery: if a voter knows if they marked a ballot ( with a pen - not the chad Florida ballots) incorrectly. Error correction is easy.
8) No electricity is needed. Paper ballots always boot up correctly.
-----------
Only reason for electronic voting is for sight impaired voters. And of the sight impaired voters, 100% seem to have solved the problem with mail in ballots OR bringing someone with them to the polling place. (In the 6 years i have run a precinct with upwards of ~2000 voters personally processed by me : about 6 have actually voted electronically)
--------------
If you want to solve the real problem, based on my experience:
1) same day registration/automatic registration
2) easy voting at locations near transit.
3) easy access to mail-in ballots.
4) no electronic voting - much faster to process voters with paper.
5) allow people to vote out of precinct. (don't require people to get home - make it easier for them to vote near where they work)
As far as I can tell there are a ton more exploits to be had, from less powerful (money, connections, etc.) people in an electronic system than in our current paper system.
Right now the only individuals who have massive influence on an election are the candidates themselves (and maybe some specific people on their team).
The next closest individuals are probably the extremely, extremely wealthy, and there aren't that many of them, and they don't even have as much power as you'd think.
Part of the reason is that to compromise a paper ballot you need thousands of corrupt volunteers (and if you can find them, you have much bigger problems anyway).
The other part of the argument is that the security isn't enough for a voting system. You need /obvious/ security, and a mathematical proof just isn't obvious enough.
Also: ethereum. And your system probably suffers from allowing people to prove who they voted for.
> Sure it can be incorrectly implemented
...ignore reality.
>> Ethereum
> Dude if you want to prove blockchain can be incorrectly implemented
You're not making much sense. Sorry if life has been hard on you.
But if it's is tied to the process of voting such that it doesn't reveal the contents but confirm it was recorded right, then it can work.
See 3-ballot, and also my suggested scheme;
https://roamingaroundatrandom.wordpress.com/2014/06/16/an-mp...
Parents: Show us you voted for X or you are disowned.
Employer: Show me you voted for X or you are fired.
Criminal: Show us you voted for X or we'll break your knee caps.
Politician: Show me you voted for me or I won't give you that contract
BTW: even if the blockchain data were totally held all within local governments only, it STILL addresses at least the problem of tampering at any level other than where the information is first collected. Even if the blockchain DB doesn't go as fine-grained as per individual it still "hardens the system" considerably from hackers, in a way that paper could never do, because recounts of paper is susceptible to human miscounts (both intentional and unintentional), and blockchain is absolutely not.
Anyhow if you can't understand why secret ballots exist after all that explanation I'm never going to be able to explain it in a way you understand so I think we're done here.
Bottom line is: paper ballots CAN be tampered with (whether secret or public) but blockchain cannot. Got it now?