I want a national voting system with distributed ledgers in every state, and to add to that, every state has a copy of every other states voting records by virtue of having to validate the transactions. There's obviously lots of particulars around this, such as what to do with absentee ballots that are mailed in. This is a hypothetical use, at least in my mind.
Another one, more for the finance industry. A few years back, I paid my rent with a moneygram. A few weeks later, I got a phone call from the rental office telling me that moneygram rejected the payment and that I needed to call moneygram. Upon calling them, they said that they had record of me buying the moneygram (or whatever the hell it actually is), but that their system didn't have a record and there wasn't much they could do beyond give me a refund. How in the actual hell does a payments company have a problem like that? As a developer, I'm left to wonder if this was caused by some errant production release that wiped records, or a developer who ran a script from a well-known runbook that wiped out critical data (read: Amazon S3), or maybe even fraud somewhere in the pipeline. Why don't they have this data distributed and backed up in offline systems? If the government is willing to throw the book at financial fraud crimes (Unless you are Jamie Dimon), then there aught to be some kind of mandate that we have a verified ledger of electronic financial activities. The even scarier thing, to me, is that I thought they would have been doing that already...
Those are a few potential uses from my perspective.
Payments is definitely something blockchain can do better in some cases
I am in general a blockchain skeptic - I think in most cases, there’s just enough trust to just use a centralized database - but voting seems like a good usecase for blockchain, as it provides voters with a receipt and it’s designed for auditing provenance.
This is, in fact, undesirable. If verifiability is possible by an individual someone can ask you (under thread of violence) to verify that you did or did not vote a certain way. It's especially undesirable if verification can be performed a long time after the vote is completed because laws and social mores can change turning a previously innocent vote into a black mark.
There are probably even better methods to further protect both anonymity and verifiability. I don’t know if the group at (2) is still active, but the graphic presented there looks like a good setup—-though I think they are after vote-from-home, while my linked comment still makes use of polling places.
(1) https://news.ycombinator.com/item?id=14921442
(2) https://followmyvote.com/cryptographically-secure-voting/
But I figure we could tag each vote with a unique hash that's generated by, and known only to, the voter.
Then, when all votes are cast, the database can be made public, including the hashes. Then each voter can check that their vote has been registered correctly, without the government knowing who voted what way.
This wouldn't be good enough, though. We want to make it impossible to confirm to anyone else which way you voted, even if you want to, in order to prevent vote-selling.
> But what about someone who claims their vote was eliminated after voting occurred? There's no way to verify that either way.
You mean someone who cast a vote but then doesn't see it turn up on the public voting database? I imagine we could solve that with crypto. In my model: when you vote, you are given a cryptographically-signed proof-of-vote that is tied to your unique hash.
> would not be possible using a blockchain
Unless I'm missing something (which is entirely possible), I've shown that blockchain isn't the only solution.
Let me reiterate: I am a blockchain skeptic. I think that, for the most part, it's a solution looking for a problem, and there's enough trust in most interactions that it's not worth the trouble. I just think voting is one of the rare instances where it does make sense.
True, the voter can prove that tampering happened, as the signature receipt they are given is specific to their voting choice (as well as to their secret hash).
How would a blockchain fare against a 51% attack? What secret/proof does the voter have that an imposter doesn't have? Is each person issued a 'votecoin'? How could we maintain voter anonymity?
My complaint about bitcoin itself is that rather than creating a virtual currency, we really created a virtual commodity; that is, it's the closest we've come to creating a virtual item that has the properties of scarcity and non-transferability of physical items. I think that's bad for a currency, but good for auditing votes.
So we're trusting the voting machines? Doesn't that defeat the point? Surely they should be able to run on public networks while honouring Kerckhoffs's principle: A cryptosystem should be secure even if everything about the system, except the key, is public knowledge.
That's the whole mission here, no?
> they may just see a normal voting machine at their precinct, beep-boop the screen and go home. The value would be in being able to audit the entire vote chain, which we currently don't do.
But if there's no 'voter identity' in the system at all, what's stopping a malicious government from just synthesising the whole blockchain?
Maybe. I'm not married to much - I'm just defending that voting is one of the rare cases where I think blockchain has value. We currently trust the voting machines, so even if we do it with the voting machines, it's still an improvement on what we're currently doing.
> But if there's no 'voter identity' in the system at all, what's stopping a malicious government from just synthesising the whole blockchain?
Not much! So we either have to allow individuals voters to get a receipt and verify their votes (which can introduce problems), or we have to print paper receipts which are kept on site. Yes, those can be printed out as a bad actor synthesizes a new blockchain, but paper ballots can be faked, too.
To me, the mission is creating an easily auditable voting record, which we do not have now.
Indeed, and that's a huge mistake. Should have stuck with paper ballot. The high-tech solution isn't always better. In this case, it seems pretty clear that it's far worse. The Diebold voting machines, for instance, have been shown to be a joke.
I like Scheneier's idea that perhaps machines could have some value as supplemental machinery to a paper ballot https://www.schneier.com/cgi-bin/mt/mt-search.cgi?search=vot...
> I'm just defending that voting is one of the rare cases where I think blockchain has value
> the mission is creating an easily auditable voting record
I don't see any link between these two. I'm not convinced there'd be any value in a blockchain.
> paper ballots can be faked, too
But it's far harder to do so at scale than with voting machines, particularly if the voting machines are poorly implemented, which they invariably are.
There's an enormous difference between trusting the government to _count_ the votes correctly and trusting the government to _record_ the votes correctly, and I think this is actually the point. How do you enable voting _without_ trusting the government?
If you have a public database then you can sign votes into it, but how do you ensure that the government won't simply delete votes it doesn't like? Pretty soon you get to the idea that each vote should be incremental to all the votes before it, so no one can manipulate the previous votes... and you get a blockchain.
A blockchain would allow you to separate the act of voting from the tallying of votes, which would be an enormous improvement over the current 'check everyone's eligibility at the door and don't mention how many people you turned away'.
Of course, in neither data format do you have any way of actually authenticating the other votes, by design. Maybe the vote in the block before yours was a dead person, or never existed at all, how would you know? (this is what the crypto world calls a "sybil attack") Whoops, looks like we're back to trusting a centralized authority (the government, who issues the voter tokens). So why do we need millions of computers hashing away, again?
Fundamentally, one of the design features of voting is that it's un-verifiable, i.e. you can say you're voting Bush and go into the booth and vote Gore, and nobody can prove otherwise. Otherwise you could have personal threats against you (boss/spouse/etc) and if you have a ticket that can be verified to show you voted Gore then you could suffer personal harm. Verifiability to the public is actually an bug in the system here - it should be verifiable to the government and no one else. The best systems produce a paper token that is retained at the voting site. You can then validate the number of tokens against the voting rolls/etc, but the "evidence" stays in the possession of the government (who we've already agreed must be trusted anyway since they're the ones maintaining voter rolls/issuing tokens and ballots/checking IDs/etc).
I forget what the name of the theorem is, that says identifiers like domain names or onion names can either be unique/authentic, intelligible, or decentralized, pick any two. Well, you can also say that ballots can either be publically verifiable, trustless, or private, pick any two (where "guaranteed one-per-person" is a form of trust). Blockchain doesn't escape this, it is just a different format for the data (Merkle tree vs flat CSV).
In many European countries we do have that, as we carry our national ID cards[0] that have their own private key for signing documents and authenticating. Signing a vote securely isn't a problem but then the problem comes on how you sign it and keep it anonymous simultaneously. Also of course we trust that the state doesn't keep the private keys somehow when creating new cards.
[0] https://en.wikipedia.org/wiki/National_identity_cards_in_the...
If you are worried that the government is going to change the vote tally, should you not also be worried that the government will generate fake keys to vote in the election, or simply add rows with fake signatures? You need to verify that those rows are authentic, and that's not possible while maintaining a private ballot. The only defense is to have someone who can say "I.C. Wiener is not a real person", whether that's the government or the public.
Private-ballot voting only works with the government as an "oracle". The government is the defense against sybil attacks (multiple voting, etc). You can have other systems if you are willing to let people see how each other voted, but private-ballot voting is pretty ingrained at this point.
--- theory stuff:
A trivial solution to the problems that blockchain approaches is "majority-wins". You take a vote and whatever the most participants agree is the "true" history wins (eg electing a master node in a distributed system). But how do you prevent one attacker from pretending to be a lot of people (aka a sybil attack)?
What blockchain provides is a solution for sybil attacks - participants are individually financially incentivized to burn the maximum amount of power they can, and an attacker must burn more than the rest of them combined to succeed.
As a general statement, "private" blockchains make little sense in that context, since you've removed the Red Queen's Race that provides the sybil-resistance. Most people are better off just using a database, since they really have no need of sybil-resistance anyway. The participants are trusted (f.ex when electing a master node in a distributed system), or can agree to trust some oracle (the party who runs the server). A regular database works fine for these cases.
Without the cryptocurrency attached, what you really have is Merkle trees, not a blockchain. I love Merkle trees, I use them all the time in my filesystem (ZFS). But the "shape" of the data on disk does not provide any particular benefits in terms of consensus-resolution. For things like voting, distributing the vote tabulations as a flat CSV would be just as effective as distributing them as a Merkle tree.
That's what I mean by the difference between counting votes and recording votes. All the dead people throughout history could record a vote, but that's doesn't mean they all have to count in terms of who gets elected.
All you would need is a private key given to you by the government that is associated with your identity that you use to sign your vote. Then the government can only count the votes by the identities it trusts.
Also, you are still fundamentally trusting a centralized authority - the government who issues the keys, and the same government you were worried about fudging the vote count. Maybe the government is adding people who don't exist (sybil attack), and the "signatures" on some of those votes are just random noise, how do you know? So your scheme gains you nothing.
At the end of the day, the only trustless scheme for voting is being able to tie votes back to names so that illegitimate votes can be challenged by the public. Any other scheme requires you to trust the government to count votes fairly, or issue keys/voter tokens fairly (we can call these a "ballot"). Blockchain doesn't change this, and if we want to get rid of the secret ballot we don't need Blockchain to do so.
Edit: Example - people vote against unpopular candidate Paul. Paul then stages a coup and takes control of government. He then asks you to provide a receipt that you voted for him on the blockchain or all your property is confiscated by the state.
I mean, "I can't" is an honest answer here, since its unrecoverable and many people won't care enough to try to verify their votes.
He might want to to punish enemies or reward supporters; “control of government” id, in practice, not infinite power, and people often use such a position to, first and foremost, secure the position.
> I mean, "I can't" is an honest answer
Which is a reason Paul might want to let it be known that some form of accountability will be asked in advance. (Which he also might due to push the actual vote results; if it is projected to be close, expecting a cost for voting the “wrong” way if one candidate wins will likely shift some votes.)
Despite being so simple, the paper ballot is quite hard to improve upon without making mistakes. Moreover, a democracy should probably have the requirement that the voting process is transparent and understandable for all citizens.
The first attempts at electronic voting (if at all) should probably be made in countries like Estonia where all citizens have e-ID cards with cryptographic key pairs you can use for some oldschool cryptographic voting schemes.