Label the online results by voting site. Keep a count at each site of the number of people that voted. Verify this count more or less matches the results posted online.
Label the online results by voting site. Keep a count at each site of the number of people that voted. Verify this count more or less matches the results posted online.
As for the counts, where I vote my name is recorded in a book and then I cast my ballot. So it should be possible to verify that the book tally and vote tally match.
You can write your identifier down, but you could also go online and look up any other identifier you want and use that one instead. The public ledger results could be timestamped so you can correlate your vote with the on chain results, but given a large enough election thousands of votes should be coming in every <unit of time the ledger uses> and you could pick any one that voted the way your sponsor wanted to claim to be your own.
It is only a problem if results don't come in in real time I think. Trying to photograph the display would be just as much of a problem as taking a picture of your ballot today. The broad point is to convey the UUID in the only untrustable memory store, the human brain.
Spitballing here: What if you get the receipt with UUID and your choices, then at a separate kiosk only in the polling ststion you can enter your UUID to view the full results as posted online. Along with your UUID and results, a hash of the two is displayed and can be printed onto your receipt. Before leaving the station, you must detach and dispose of the plaintext voting choices, but you can hang onto the UUID + hash.
At any time in the future, you can enter your UUID into the site, which will compute and display only the hash, giving you verification of no tampering but not disclosing any results to nefarious third parties.
You did say "a good clean way" though, so perhaps that analogy is inappropriate :)
Maybe it could be explained in terms of one of those "superhero name generators"[0], where the initials used come from your UUID and the superhero name chunks come from your voting choices. Sure, a hash is a lot more mathematically complicated but the principle remains the same (to the point of the possibility of two different UUIDs and voting choices ending up with the same hash, just as anyone having the initials DJT will become The Incredible Golden Tornado).
[0]http://weknowmemes.com/wp-content/uploads/2013/10/superhero-...
Unfortunately, this system is neither trustworthy nor correct, as adding new UUIDs to the rolls defeats the system.
A voting system is a security system that has to work in the presence of bad actors.
If you add new UDIDs, you'll throw off those numbers.
P.S. You keep writing "UDID", but you really mean "UUID". The UDID is a specific implementation of unique device identifiers. They have nothing to do with individual people.
i tried to fix two things with my proposal: changing votes and adding votes.
let’s hear some concrete criticisms and suggestions.
i dont feel like the current systems are particularly thoughtfully designed. we could probably do better in this HN thread. :)
If you don't present a design, you won't find anyone to critique it. My suggestion is to design something and then present it.
No. You will need to perform a lot more work at system details, algorithms, interactions, interfaces, components, etc.
Declaring "UUID" isn't really a design. It's not even a workable idea, yet.
Here is one design for a voting system, which had been posted to HN last year. http://www.economist.com/sites/default/files/nyu.pdf
Some of my review of it: https://news.ycombinator.com/item?id=13144302
Your only actual criticism was
> Unfortunately, this system is neither trustworthy nor correct, as adding new UUIDs to the rolls defeats the system.
Which I explained was defended against by having counts at each voting site which could be compared to the online results.
Your (non) response to that was non-specific attacks on the non-planness of my plan as a whole.
Even non-planness attacks should be able to be made specific. You should be able to point to a specific unaccomplishable thing or missing detail... (Perhaps you could complain that I haven’t specified how to collect and save the voting site voter count tallies, which would be fair, but also seems solvable...)
I'm not going to do your work for you. You might find people willing to work with you, but the odds are slim until you have a unique idea or something more than a single sentence. Literally thousands of people have discussed UUIDs, including the two links that I sent to you.
It's a high-level idea, dude. You made one specific critique, which I refuted, and now you're criticizing the idea as uncriticizable because it doesn't have enough of the details specified.
Thanks for playing, I guess.