CHVote: Open-source e-voting system from Switzerland
republique-et-canton-de-geneve.github.io
republique-et-canton-de-geneve.github.io
For electing state officials, no. A voting scheme needs to be designed for the worst possible circumstances which practically means a bordering civil war, and where trust between voters is zero at best. Voting allows revolution to take place peacefully.
Therefore the method of voting needs to be understood, carried over, and be verifiable by the common (wo)man. No electronic scheme can do that: anything that runs in software means that the correctness of the system depends on the experts' word only, and that word is likely to mean nothing when half the population is already collecting arms.
Two or more block chains. Each run by different parties. And a need for the same vote to show up on multiple blockchains to count. The voters would visit multiple websites to cast their votes which would then be verified between the various block chains, potentially by software that anyone can run on their own computer or vps. Every single person does not have to vote on multiple platform. Just enough that you can validate the voting.
https://en.wikipedia.org/wiki/New_Black_Panther_Party_voter_...
https://www.theguardian.com/us-news/2016/nov/05/election-day...
That includes "shouting racial slurs" in your first link.
First of all, there are fifty elections in the US (not counting territories like Puerto Rico and Guam). Each state runs its own elections separately and can decide on their procedures.
Secondly, some jurisidctions already experimented with making election days a holiday. Aside from the fact that this only affects government employees (private businesses set their work schedules at their discretion, just as they do for other holidays), this ended up decreasing turnout, because people ended up taking the previous day off, treating it as an extra-long weekend for travel or vacation.
Third, this is a moot point when most states (34/50) offer early voting, and three more vote by mail, making "election day" rather arbitrary. It's really the last date on which someone can cast their vote. Those states also include three of the four largest states, meaning that the vast majority of people in the US have the option to vote well ahead of election day.
(For the record, the states which have neither early voting nor no-excuse absentee voting are Alabama, Connecticut, Mississippi, Kentucky, Virginia, Missouri, Michigan, Pennsylvania, South Carolina, Rhode Island, New Hampshire, and New York)
Too late to edit my own post but please s/voting booth/polling station/ in the parent. Of course every voter should have absolute privacy in the voting booth in order to rule out coercion, but the ballot storage in the polling station should be publicly verifiable.
* Unboxing the ballot is done in public, anyone can come and watch those.
* Counting the votes is public and anyone can come and watch.
Voting on paper is dead simple, has withstood centuries of attacks, counting scales insanely well while attacks don't scale and it just takes one person to notice it and your whole plan goes south. Whereas electronic voting requires trusting black boxes, more black boxes, and understanding asymmetric cryptography.
Show up and keep showing up. Take notes. Fact check.
Over time, you'll know when the story doesn't add up.
Been there, done that. For years. It works.
If that's "too hard to fix" then there must be at least a fraction of people who don't think this is broken.
The time to fix it is right after elections.
https://en.wikipedia.org/wiki/Secret_ballot
So I guess ballots should be anonymous. So how to do that with a blockchain. Well simply by assigning some random number or hash to the voters that no one else knows.
Perhaps it would be better to turn the vote-selling market into a publicly verifiable open market?
If I say that it would cost a buyer $10k more for me to vote yes than the highest open bid for me to vote no, that is a strong quantifiable indication of the magnitude of my opposition. I'm sure the vote-pricing data would be a gold mine for statisticians.
Of course, this would make the plutocratic oligarchy operate out in the open, officially, rather than behind the scenes with lobbying, campaign contributions, and speaking fees. Some people might find that objectionable: both those who do not want a plutocracy and those who do not want their money influence on politics to be openly known.
If you can not possibly reveal your vote (like with the ballot box) you can not sell your vote.
And that's even before we conclude the preferred candidate of the plutocratic oligraphy would actually be massively aided by being able efficiently purchase the votes of the indifferent rather than having to inefficiently purchase airtime to convince people their candidate actually has merit. (And of course they'll still be able to continue to organise their vote-buying operations through shadowy umbrella organizations to the extent they can be bothered to disguise who they want to win)
This paper shows you know to achieve exactly that. You can vote anonymously and receive a proof that your vote was counted correctly, without ever telling anyone what that vote was. To prove that your vote was miscounted, I believe you do need to reveal who you voted for, but you can prove to the world that there was fraud.
This paper solves one of the major problems with blockchain based voting, but there are many more. I don't endorse blockchain voting.
Even with paper ballot we still have to trust the people/devices counting the votes.
As an American citizen theres no website I can go to and check my vote. How do I know it was even counted, or properly registered.
If such a site existed, vote buying and/or coercion would be a lot more prevalent.
No paper ballot in box scheme can do that: anything that is run by officials means that the correctness of the system depends on the officials' word only.
Please sign up and observe your local elections. The Australian Ballot system (private voting, public counting) is time proven, battle hardened.
Paper ballots cast at precincts counted when the polls close is the gold standard. It works because opposing belligerents agree on the outcome. Trust forged from mutual distrust.
Paper ballots permit guaranteeing the physical chain of custody. You should show up and help keep that guarantee.
The security of a digital systems is "good enough" IMO, especially if there's a public cryptographically verifiable ledger. We bank online where the banks essentially only hold cash in the form of a database entry. The benefits of digital voting means we can have more granular input in our government's operations. I don't see paper ever scaling to meet that demand.
Remember that your IMO is not what the consensus among security experts is. There are many things that you and me missed.
The worst problem with electronic internet voting is that depending on country, something like 5-40 percent of voters loses the secret ballot and the opportunity to vote independently without coercion. Husband, brother or other family member will be behind their back to watch how they vote.
Here in Finland I have a friend who has been election official and he says that it's not uncommon common for family member trying to squeeze into ballot box or try get behind. Especially if the ballot has been cast in post office with small space.
Your jurisdiction's voter registration database is (hopefully) up to date. YMMV. Note that verified reports of registration fraud are very, very few. Whereas caging, purging are fairly common.
Briefly, On election day: voter shows up to correct poll site, shows some kind of ID (YMMV), name found in that location's poll book, voter signs in, ballot is issued, voter marks ballot, voter casts ballot. If there's any error (question) during this process, voter is issued a provisional ballot, to be adjudicated out of band.
Ballots are counted before the polls open and again when the polls close. The bookkeeping is simple and easily verified.
Everything is bundled in tamper evident seals, observed and signed by members of opposing parties, physically escorted by opposing members, etc.
I don't see why this level of security couldn't be used to randomly and deterministically assign crypto keys that are used for some kind of blockchain voting scheme. Put a thousand pre-known keys in a hat, one thousand people draw keys from a hat, the key is activated on the blockchain and points to a user-defined voting wallet. Now you have anonymous cryptographically verifiable voting with double spend protection. Am I missing something?
Might as well just vote then and there
Voting wallets? Assign crypto keys? You mean just like issuing a ballot? How would someone do a recount? An end-to-end audit? Keep track of who was assigned which key (thereby destroying the secret ballot)? Who voted and who didn't? How do you handle provisional ballots? Etc.
PM me once your proposal satisfies the requirements (works as a replacement) for current election administration systems.
Okay, maybe I'm being too dismissive, which I normally hate. But blockchains, crypto, signatures are not magical. Design the whole system, make it auditable while accounting for information leakage, simulate a few real world elections. Do the leg work, unlike Chaum, Rivet, others. THEN we can talk.
"Scantegrity II Municipal Election at Takoma Park: The First E2E Binding Governmental Election with Ballot Privacy"
http://static.usenix.org/event/sec10/tech/full_papers/Carbac...
With the prior Punchscan system, voter privacy is accomplished thru hash collisions. Hiding your ballot in a herd of ballots cast. A trick that works only if your herd (precinct) is large enough and your ballots are simple enough. Definitely would not work (protect voter privacy) in my jurisdiction.
Side note about IRV, as used in Maryland Park: It's now a non-starter. After the handful of well-studied experiments, election administrators are dead set against it. Ballots are complicated, voter education is tough, and IRV necessitates electronic tabulation, which rules out legally required manual recounts. (My jurisdiction often gets over 500k ballots. IRV is not feasible here.)
People lose wads of cash that are valuable to them; they're going to care even less about their electronic verification file.
This is a thing you actively don't want. You don't want to be able to prove to anyone else how you voted. Otherwise it would be absolutely trivial for your boss to say, "So, you voted for that anti-union candidate, right?" (Or your boss to not say that, but just happen to give promotions to people who show proof of voting the way the boss wants.)
The right to a secret ballot is demanded by the Universal Declaration of Human Rights.
Yes, this renders the electronic voting problem - and honestly the voting problem in general - very close to impossible. That's why it's hard.
I just invented a scheme to anonymize votes in 5 minutes. I'm sure if smarter people tried we could definitively solve this. I'm not convinced this is hard as much as people are saying it's hard.
(The other thing is that photos of ballots have only become a serious threat in the last few years, and at the moment there's not really voter coercion through those photos, as far as we know. If it becomes a problem, I expect a bigger crackdown on it.)
Tada!
You need to have deniability; I need to be able to revoke my ability to prove how I voted, and moreover I need to be required to revoke it (otherwise I can be compelled not to revoke it). Right now, I am unable to leave the voting booth with any receipt of how I voted, even if I wanted to (i.e, even if someone else wanted me to). I can see my vote, and election monitors prevent anyone else from seeing it until it leaves my hands. In most places in the US, I can't even take a cell phone photo of my votes, and that's a good thing because nobody can ask me to take a cell phone photo of my votes.
2. If they're pre-known, anonymous, single-use keys, nothing prevents a corrupt election official from keeping a copy of the key and voting before the voter gets home. The voter has no way to prove that they didn't vote and that someone stole their key.
We use this in Mexico, in addition to (non-digital) fingerprint-carrying voter ids. Historically, it has not prevented fraud in general (most of which happened due to insufficient audit procedures and rural polls not having observers from all parties, allowing for stuffed ballots and the like). It did however close that particular attack vector. My trust on the results of an individual polling station in an urban area with observers from all major and most minor parties is actually quite high, even as I know any or all of the observers involved are likely to be corrupt and have low regard for the law. The reason for this is that they are all incentivized to prevent each other from cheating and have the means to detect tampering in such setting (without needing uncommon expertise beyond observation and basic arithmetic).
Here in Romania there were cases when two or more parties agree to cancel the votes for the opposition or even count them as theirs.
We call those "allies".
To change the outcome of an paper ballot election you need to have thousands of thousands of people on your side and have everybody keep quite.
In most countries parties or volunteer groups nominate their own observers. UN can send their own observers.
Electronic voting is by far most vulnerable. It's not the algorithms, it's all other tings around them and verifying them.
Do most people trust the officials? Sure. But any campaign with enough volunteers is able to verify everything.
Then again, it appears in some countries you can just claim millions of fraudulent votes without any proof without being called out for it.
> No paper ballot in box scheme can do that: anything that is run by officials means that the correctness of the system depends on the officials' word only.
This comparison is flawed, the entire correctness of a electronic scheme could only be verified by a few experts, whereas in every polling place with a paper ballot, there is a committee, and witnesses of the vote count. Proving the correctness of a paper ballot system such as the one described in [1] is trivial.
Ultimately, the correctness doesn't even depends solely on officials: In the course of the day, the polling station officials ask voters whether they want to participate in ballot counting as tellers. Voters can also volunteer to do so ; candidates can nominate tellers as well.
[1] http://www.elections-legislatives.fr/en/system.asp (search for "How are the ballots counted"). The presidential elections protocol is the same as the one described here.
It's to an extent possible to mount a local attack with paper ballots but its cost is an effort too great that it doesn't scale. You would basically have to get your own people, or paid people, to swap the ballots while nobody else is watching to get the results you want in one election district.
Because ballots need to be saved for recounting the marks on the ballots also need to be sufficiently distinct so that they don't look like they all come from a photocopier. Again, if there seems to be anything fishy, people can and will organise to redo the election locally, this time with different representatives from the parties.
With digital voting, vulnerabilities and malware and automated attacks scale to all systems involved and theoretically a single entity can rewrite the election results of the whole nation. Worse yet, it may not be evident whether the results are skewed or not as it's just digits in a computer and those can be changed without a trace.
[1]: https://github.com/bitcoin/bitcoin/blob/master/doc/gitian-bu...
For the future let's see how they will manage external contributions. Opening the code for transparency is a good point (even if this still doesn't ensure you that the same version of the code is running in production on trusted hardware), but doing this on GitHub will certainly bring some contributions. Will they refuse everything? Or accept external contributions? Will they use GitHub as the central development process? If not how are they going to handle the development in intern in regards with external contributions? Also are they going to do all commits with this dedicated state-account? Who will be part and what would be the process for reviewing and accepting external contributions, to be sure they are not adding backdors purposely desguised as mistakes? Having a state starting to work on open-sourcing such a sensitive software in Switzerland opens a wide range of interesting questions. Maybe, and probably, this has already been discussed in other countries or even other part of Switzerland, but in the state of Valais (Switzerland) this is at least not the case.
It's not the first project under state control in Switzerland that is on GitHub. I'm also aware of geo-admin [2] who have their sources there. As far as I saw, they are handling GitHub much more professionally.
[0] https://github.com/republique-et-canton-de-geneve/chvote-1-0
[1] https://github.com/republique-et-canton-de-geneve/chvote-1-0...
For me, they haven't fixed the problem GUN.FREE highlighted when they decided to shut down (https://www.gnu.org/software/free/), but they have highlighted the risks and made them harder to exploit.
I need to sit down and think about attack vectors properly, as the process is quite convoluted, but it seems to me there are multiple opportunities for key personnel to change votes and to identify whom voted for each outcome - the scope is limited, and within a very small step due to ballot shuffling, but it definitely is there on a first read-through.
if __name__ == '__main__':
passhttps://github.com/vvk-ehk/evalimine/blob/master/ivote-serve...
> Election().count_questions()
> Election().is_hes()
> for el in Election().get_questions()
> Election().is_voters_list_disabled()
Election is a singleton so they keep reinstantiating it every time they want to use it instead of just doing
> election = Election()
at the module level and having a more idiomatic singleton (module variable are singletons). But a singleton design probably isn't the best approach.
The singleton example isn't that bad of code since it assumes that one server will run one election which is a valid assumption, but reading through this code makes me weary about e-voting. I think this proves that OpenSource doesn't always mean good code. There is little incentive for people outside of Estonia to contribute to the project.
They have some voting system - a black box - and they believe it works and no one has hacked it.
I have compiled a list of reading materials here for those who are interested.
But how do you verify that the Computer actually does what is in the Bytecode?
"But how do you verify that the Computer actually does what is in the Bytecode?" It is much closer to the original question. hardware backdoors is a difficult topic
There is always going to be a weak point where you have to trust somebody - this is why party members should not be involved in every step from setting constituency borders, all the way to being in charge of any balloting and reporting results. It needs to be independent (e.g. in the UK it is fiercely independent of party members' involvement at any level).
The interesting attack vector here is your ISP could trick you. That can be mitigated with certificates and some of the measures banks use to identify themselves to customers (strings that you added at registration being displayed at login that only you know, etc.)
But yes, a hard problem to solve.
You can watch it.
With a "ballot box" system, you could get there, put your vote in the box, then sit there and watch it all day until it's counted. Hell if you want you could get there and inspect the box before they start voting.
And it's not just you that can do that, everyone can do that regardless of profession, age, race, background, education, etc...
Actually, the government is required to have some people watching the counting (specific rules vary on a per-canton basis). Some states select random citizens for that (similar to jury duty in the US - you get fined if you don't show up, but get paid for your time). Other states have a pool of people they choose from randomly (you volunteer for the pool).
EDIT: Furthermore, Swiss people vote in their community. It's not like you need to go out of your way to watch the counting - it happens in your town hall or (sometimes) the school. It always happens on Sundays (which is a required day off in Switzerland except in some rare cases).
If you don't mind me asking, how does Switzerland handle those which are required to work on election days?
That's one of the ugliest parts of the US election system to me, is the fact that many people need to fit the election around their work schedule, and I know of at least 3 people that couldn't get time to vote this year, and my state makes it so you basically need to be actively deployed in the military, or be hospitalized to get an absentee ballot.
I'm not certain what would happen if say a nurse working a shift in an ICU was selected. I'm pretty sure it's either announced early enough that the hospital would have to switch shiftees or they would be given a pass for free. I suspect a person working in a train station shop on a Sunday would tell their boss, and would simply be shifted to another time (it's not like the boss or the employee can do anything about it - it's law).
EDIT: to clarify once again - I'm pretty sure it does happen, but the case is probably rare enough for it not to matter too much. The rule works for a good 90% of cases, exceptions can certainly be done on a case-by-case basis at community level.
A non-critical worker cannot refuse but:
a) Chosen citizens are paid, even if not much (60€ I think).
b) Chosen citizens have the following Monday morning free, should they need to travel back to their job site, etc.
c) Chosen citizens have strong legal protections should their boss try anything.
In practice, when an employee is chosen for election duty the boss just deals with it as best as they can, since it's a case where judges and police are super strict: messing with election duty will get you heavy fines and/or jail time. So no-one is going to fire you or retaliate if you are assigned election duty.
- I never had to show up (there seem to be enough people volunteering...). - If you have good reasons, you can contest the election.
(IIRC, formally, I've been elected to that task... but I have no idea who did elect me...).
EDIT: also, the mail goes to one of these places where people are standing around watching the people counting (your community's townhall, usually)
Voting days should be public holidays, polling stations should be festivals, and moving ballet boxes should be a parade.
We hold festivals like these for far less important purposes, so why not celebrate the foundation of our society.
So is pulling down a lever and watching spinning wheels. Permit placing bets on the outcome. Turn it into entertainment. That always works. And if money is involved, people will triple check. [oh the Humanity. I forget now if this comment started as an /s.]
It's completely impractical to try to watch millions of physical ballots. Or to even simply count to a million without making a mistake.
But if the voting was done (correctly, securely) in software, each person could independently audit the complete results. And to be clear, it's the overall election being audited that's important, not my vote in particular.
Perhaps it would be more difficult to understand the algorithm and code than following a physical ballot, but not a million times more difficult.
There is no one person counting millions of votes. There are people counting hundreds or even thousands of votes in every precinct. Then from there they are publicly announced, and then anyone and everyone can tally up the totals.
The more people that vote, the more precincts there are, so the amount that any one person or place is responsable for (even only partially) is kept small so that mistakes or "bad actors" can only do a very small amount of damage on their own.
And if you read down in this submission a bit, people are pointing out that some countries (namely Switzerland) not only encourage people to watch ballot boxes and count along, but actually "draft" people to do it similar to a jury-duty kind of thing in the US.
Also I think you are severely underestimating the difficulty of auditing code. For starters, it completely removes the ability for the vast majority of the population to audit even if they wanted to. non-programmers can't read programming. Not to mention the illiterate, the elderly, and anyone else that doesn't have the knowledge to be able to read and follow a programming language.
Then there's the amount of time it takes. Watching a ballot box takes the duration of the election day. A day at most. Auditing every inch of a codebase? Months, years, even longer. You can point out that not everyone has to review every single line, but then you are back to letting a fraction of a percent of the population validate the code (and in a ballot box system, you can have everyone validate the process, adding magnitudes more redundancy that something shady will be caught). And what percentage of programmers do you think have a good enough grasp on cryptographic protocols and voting systems to be able to correctly and securely vet a system like this? I'd be willing to bet good money there are less than a thousand of them in the united states, and by sheer (un)luck at least one of them will be a "bad actor".
But probably the biggest thing is that to sway a "paper and pencil" election, you need materials, you need a LOT of people, and all it takes is one person to see what's going on and it all collapses. If you're really clever, you might be able to get away with changing the outcome of a single precinct, but what about the rest of the county? the state? the nation? In 2012 there were 2712 voting precincts in virginia alone. Orchestrating a system where you can put a person at a majority of them that will do something nefarious to sway the election means you are looking at 1000 people spread across a not-insignificant amount of land. And that's just for one state.
With an electronic voting system, one bug is all it takes. One vulnerability, one crypto flaw, one guy somewhere that can put the backdoor in the manufacturing of the CPUs for the vote counters. A single person can (if the are very smart and lucky) completely change the outcome of the election. And they might get caught, but the chances are much smaller than if it required thousands of people at the least to do so.
The subtotal tape cries out to have a block chain added to make it impossible to rewrite history. Once the five neighboring precincts hash and sign my precincts results it would be very difficult to later fake historical results.
There is of course the false assumption that everyone involved in elections wants a fair election, in which case systems will be constrained to make a fair election impossible, with technologies such as e-voting or obscure registration procedures or strange voting laws in general. But its very easy to run a fair election if the people running it want it that way. If. The sheer amount of problems indicate a very large number of people actively discourage democracy in practice.
UK: Knocking up - visiting, in this case going door to door to canvass voters
North America: Knocking up - making pregnant
This doesn't make funny business impossible but does make it both unlikely and difficult to tamper with on a large scale.
I just don't get the draw of an electronic voting system.
Paper works, and it works well. Anyone that can count can validate a single precinct. You can have one person, or 100 people all standing there watching a ballot box all day for tampering. You can have a whole group of people count the results, or just a few.
In a traditional paper system, swaying a single precinct with "blackhat" methods takes a lot of physical resources, a lot of time, and in most cases a lot of people. Then multiply that by every precinct in the country, and it quickly becomes pretty much impossible to do (and get away with).
I've said it before, and i'll say it again. Electronic voting is dangerous and is a very bad idea. And it doesn't matter if it's FOSS, it doesn't matter if it's vetted, it doesn't matter what safeguards are put in place, all it takes is one mistake. One fuckup, and someone can now choose the leader of a nation.
And replacing a system where literally everyone can validate a system on voting day if they want to with a system where only a fraction of a fraction of people can even read and understand the code, let alone validate the code (and can't actually validate the hardware, or make sure what is running on the hardware is actually that code), and it takes a magnitude more time to do so, just isn't a good idea.
Make elections cheap. For those that wish to experiment with majority rules a reliable system would allow the people to technically be able to vote in their government on a daily, weekly, monthly basis.
So further to this if elections are easy to run and are cheap what does it matter if someone breaks one election? You can just run the next one fine. It changes the variables somewhat and requires a sustained and persistent threat to be engaged to subvert the democracy. Combined with a team that investigate irregularities you can create a vaguely stable system, especially if you consider ideas such as binding authentication to geography instead of identity making it more difficult to stuff ballot boxes as teams can easily verify how many votes should be possible from a specific gps co-ordinate.
I'm not saying its a great idea, its probably awful but it opens up an option to society that previously hasn't been available and that's interesting.
> what does it matter if someone breaks one election? You can just run the next one fine
This assumes it's easy to detect manipulation which I think is very unlikely.
Edit: according to Wikipedia, Switzerland has 13 national referendums (not "referenda" apparently) in 2016 so not as many as I thought. https://en.m.wikipedia.org/wiki/Swiss_referendums,_2016
Citizens can also decide to submit things to referendum, and that has absolute decision power. To do so you need to gather a set number of signatures depending on the level of the decision (communal, state-wide or federal). This is very often used by political parties as a "weapon" to counter their opponent's decisions - they organise signature gatherings, and if they reach their goal the people gets to have the final word on the topic at hand.
Of course, anyone can submit a referendum on anything, as long as you gather the required number of signatures. You don't need to be elected or in a party or anything like that.
The system does lead to some ridiculous things being put up for nation-wide discussion, but that is usually seen as the cost of living in a direct democracy. I can think it's stupid, but it's your right to bring it to my attention if you consider it important (a bit like freedom of speech and the old "I'll fight your your right to say it even though I disagree").
EDIT: doh' I did repeat the "referenda" mistake here :/ Edited out.
An interesting simpler direct majority rule scheme is to halt elections completely and use jury selection techniques to select decision makers. What we'd lose in expertise we'd more than gain in the lack of sociopaths and psychopaths. A government completely of jury duty/draft would be far more effective than the one we have, which is probably why no one in power wants it.
I think far more likely these people would mostly just end up taking advice from whichever experts are left further down the hierarchies, who would then effectively run the country.
Surely you can't be implying we have subject matter experts running the country now. Or that the subject matter experts we do have from law and show business who are in charge now are only in charge of their areas of expertise specifically law or show business? I'm just saying there's nothing wrong with having congress leading the American Bar Association, its just that having lawyers in charge of, say, nuclear power plants, is about as dumb as having plumbers in charge of source code.
Having too many votes simply doesnt work, because the voters can't put in the required effort per vote to decide on a prudent course of action.
The only reason to switch off paper ballots is of you're running so many elections you're just influence laundering by pretending to be democratic when you're not.
Not self-entitled part, but the idiot (on a particular topic) part. I think lobbyists could sell the public on things they could never sell senators on.
Now lobbying is a problem, but the solution should be in our picking and regulatory mechanisms, not in letting them lobby the public directly.
You're not one of those people who think "America isn't a democracy, it's a constitutional republic" are you? I see that meme expressed online a lot, and it's really unnerving that people believe that.
Also, might I infer that your support of "republicanism" over "democracy" is because you support the Republican party in the US and have been taught to fear and loath anything which starts with the string "Democra"?
> "people are self-entitled idiots"
Actually, that answers my question, thanks.
I would argue that kind of by definition, a republic is a representative democracy, though it's possible there are representative democratic governments that aren't republics.
The US is a republic, which is a form of representative democracy -- much like Im a mammal and a eukaryote.
The end of your comment of course is just a non-sense ad hominem. I don't support the Republican party, but your need to other and slander people you don't agree with is troubling.
And yes, people are self-entitled idiots. You, me, everyone else. That's why, even with it as our full time job, a support staff, and the genuine motivation to make a difference, we couldn't keep up with the actual complexity of every vote. Expecting the average person to do what a professional with staff can't is ludicrous!
Now, there are lots of ways we could use technology to better harness the public for decision making, but having them vote on everything would just be a disaster.
We feel that we'd do good at it because most of us honestly have no idea what's actually required to work in that environment. I don't imagine that I, as an amateur with a job and social life, would really be more informed than the people in Congress. I don't think most of us would be.
So the solutions to the problem need to address how to combine our effort and expertise, rather than asking us all to be experts. (If that makes sense....)
I think there's a lot of promise in, say, using ML and public repos (eg, github) to let us collectively scan, annotate, and suggest edits for legislation.
Why isn't Congress just the maintainers of the authoratative repo that anyone can make a PR to? That seems much more useful than having a vote about everything -- let's argue about it, lay out our best cases as the PRs merge up the hierarchy, and let the Congress people argue out the final merge of a dozen proposal PRs? I mean, that's basically what they do, but it's weirdly pay-to-play, and it seems much more democratic to, ya know, let the public in on it.
Paper works, and it works well. Anyone that can count can validate a single precinct
Add to that there's not really a need to speed up deployment of the results for elections and referendums in Switzerland.Except for the "house of representatives" (Nationalrat) where it can take a tad longer due to the complexities of the vote, results are usually in at voting day before 6pm (Voting closes at noon).
I'm also deeply reluctant to accept the necessities of electronic voting. Given all parameters it's a really hard (if not impossible) problem to crack.
As a late sleeper, I find this voting system biased and unfair.
You don't have to show up on voting day in person. You can mail your vote in up to one month in advance. (Postage paid by your taxes)
You can chose not to vote for (usually dumb) reasons. But wanting to sleep in is not one of those.
The solution seems simple at first glance; scrap the entire voting system, scrap the entire fundraising system, and whichever candidate receives more individual $1 donations via check or money order wins. You can vote a dollar to as many candidates as you want but your federal tax return for that year is only getting a single $1 election credit. You could require the candidates to declare to the IRS each $1 contributor which makes election fraud also a form of income tax fraud.
Certainly, our financial marketplaces and clearinghouses at their absolute worst are more trustworthy and reliable than our evoting systems at their absolute best. And the additional infrastructure to transfer a hundred million bucks every four years is utterly trivial (well, more often due to primaries and midterm elections, but its still a drop in the bucket ...)
The anonymity emperor has no clothes, anyway. Thanks to the miracle of modern technology everyone who matters already knows exactly who you voted for and your complete financial life, you're just plausibly deniable on an individual basis against some non-state opfor some of the time. May as well face reality and make all votes part of the public financial record. Sure, it sucks. But better to face a reality you don't like, than to live in a fantasy world of completely broken anonymity. Living a lie means you'll slip up and the consequences of the slip up are likely worse than the lack of anonymity itself.
No, if you don't trust that your paper vote is actually counted you could stay in the election hall all day, watch the counting, check the when the results are transmitted. You don't have any comparable option with e-voting.
"CHVote, entirely developed, hosted and exploited by the Geneva Canton"
:) It's paragraph in english, or section.
I'm guilty of it as well. Despite English being my primary language for the last 10 years, whenever I read my previous comments I catch glaring mistakes.
English is my primary language as well but turns out living in a French-speaking country will do this to you.
Please, study how election administration (in the USA) works to better assess these new technologies, techniques, systems.
TLDR: Electronic (mediated) voting schemes cannot guarantee both the secret ballot and public count. Tech which may do one, or perhaps even both, hasn't even been conceived, must less invented.
Ring signatures are good for it for example:
https://en.wikipedia.org/wiki/Ring_signature#cite_note-FS07-...
1. Authenticity - One vote per citizen.
2. Secrecy - no one, not even the government, should know who voted for who.
3. Verifiability - I know my vote counts.
So if you have a login/password, #2 (logs are too easy) and #3 are out.
With a Blockchain, #1 is out (how do you verify that a private key is owned by a citizen)?
Theoretically, we have figured out the entire thing pretty damn well, we just need someone to try it ;)
Also, explaining blockchain to the general population and "assuring" them will be the hardest part. People will revolt and think it's rigged and have no understanding of how it works. Even politicians are clueless...so, yeah, not sure how far off we are on this hah.
So how is the citizen ID blockchain linked with the voting blockchain?
At the moment, the open sourced part is the "offline administration application" in the green box at the top right.
https://github.com/republique-et-canton-de-geneve/chvote-1-0...
North America isn't "the north part of America" -- the continent is named "North America."
So the nationality is American but citizens of the continent are North American or South American respectively.
The people's of North and South Americans aren't collectively known as "Americans." In French americain refers to "one who is from the United States." It's the same in multiple languages. Even Spanish refers to people from the US as americanos.
This is a subtle thing and in the grand scheme really makes no difference unless someone feels so strongly about it that they want to change multiple languages.
The American Embassy is not referred to anywhere (in English) as The United States Embassy --
edit: actually "US Embassy" is common, sorry for the misstatement. However American Embassy is very commonly used by diplomatic personnel and in general conversation. --
I don't understand why a certain subset of people, generally from South and Central America have such an obsession with this. Canadians never refer to themselves as Americans. In fact, many would resent such a thing.
Never, not once in writing or in speaking heard it referenced this way. American by itself references the USA, North or South America references the regions.
we're talking entirely different tectonic plates - plates that don't even touch. plates that will eventually shift such that you there will be no possible land travel, and a widening gulf (admittedly in the distant future). not to mention different cultures, hemispheres, etc.
https://www.sta.be.ch/sta/de/index/wahlen-abstimmungen/wahle... (German)
is there a comparison of this voting system versus the others that exist?
Nobody says you can not run electronic voting, its just hard to do it securely. India does not do it securely.
See here for lots of information (India should be mentioned somewhere: https://media.ccc.de/search/?q=voting)
Which is why I was asking the question on comparison. Because I'm not able to figure out if it is yet-another-voting-system... or something this is peer reviewed and secure.
The problem with a weekly vote of confidence is you're just going to motivate massive chronological engineering such as doing everything unpopular the same week and taking the lumps and hoping no one notices, or playing mixing games that have nothing to do with good governance to ram something unpopular thru the same week something happy happens (or possibly refusing to do something popular until a stockpile of equal and opposite unhappiness accumulates).
Its not bad that both good and bad things happen simultaneously, its bad that they have to be stockpiled and delayed until they match up for weekly election reasons.
I can only imagine how awful this would work for situation where the government is sort of expected to lie for awhile, longer than a week anyway. Foreign diplomacy, military action, negotiations of all kinds, sometimes faking people out for more than a week is necessary to achieve victory in the longer term (like on a scale of months years decades centuries)
Another problem with weekly confidence votes is what happens if the government gets tossed out three times in a month, as could happen if the electorate are generally pissed off. You can't really form a government and operate and judge its operation in a mere week.
Now maybe an annual confidence vote is achievable. Maybe. Or maybe one weekly no confidence vote means little more than internal "WTF are we doing" conversations, but more than 7 no confidence in a 13 week quarter means they all resign, something like that.
https://en.wikipedia.org/wiki/Electronic_voting_in_Brazil
Still, I would not trust an electronic system unless it printed a paper receipt behind a glass window, and dropped it into a box when I hit the submit button.
And I don't know if the source code be provided to every voter on request, as voting is the service provided by the machine.
Edit: Yeah, there are exemptions for voting machines in [A]GPLv3.
I'd love to know what the Swiss themselves think about this system.
To any Swiss people on HN :
— Do you feel this had a positive impact on society?
— Maybe more important, would you recommend this to other governments?
So there's no fault in not knowing!