There are statistical methods to count a small number by hand (+ corroborate with poll results) to ensure a degree of consistency. Chi-squared distributions and stuff (I'm not a mathematician, but I'm sure there's some statistical method to verify the results without counting everything by hand).
The main problem with blockchain is that it requires everyone to trust the blockchain. With humans counting by hand, you don't require any trust. As long as the ballots are properly stored, you can always recount the results.
- System needs to ensure everyone votes only once
- Ensure each person meets the qualifications to vote
- Ensure ballots cannot be counterfeit or additional ballots inserted somehow
- Ensure votes are confidential throughout the process
- Ensure voters cannot prove their votes to others
- Ensure the people counting are trusted or the results checked / verified
- Ensure all ballots are actually counted
One significant negative with the paper ballot method is that voters cannot confirm the last point. I have no way of confirming that my ballot was actually counted and contributed to the final tally's.
With electronic voting, you potentially need a single person with a computer on the other side of the globe exploiting a security flaw, that will inevitably be there. Whoever claims to write bug free software is a conman.
I also don't want to be able to verify my vote. If I can, that means that somebody else also can. Given how tech-illiterate the average human is, voting crypto keys will be littered all around the internet.
Right, I should have been more clear. You typically do want voters to be able to prove that they voted and that their vote was counted, but you do not want voters to be able to prove the contents of their vote (who they voted for).
https://rangevoting.org/RivSmiPRshort.html
>- Ensure all ballots are actually counted
aren't these two contradictory?
With electronic voting I pretty much lose the ability to verify my vote wasn't changed. With paper I can achieve a high level of confidence that a significant number of votes didn't get changed as lots of people with opposing interests are watching each other.
With electronic voting:
- I can't read the code since it's likely closed source (and not many people can read code)
- Even if it's open source I can't verify that the code I verified is running the code I verified. A USB port is a security risk, any printout can be forged and finally I certainly wouldn't be allowed to inspect the machine's insides. And this is ignoring all the other code on the machine in stuff like the touch screen controller etc.
- So given that the code is a blackbox, I can't verify that my vote hasn't been changed silently, especially since the crypto token I'm given doesn't allow me to verify my vote.
Whereas, with paper ballots, the average person is able to understand the risks and be able to mitigate them. Especially, since you'll have people with opposing votes trying to find the other side cheat.
Elections are too important and people are motivated to try and hack them, since the likelihood of getting caught hacking is much smaller than the massive effort you'd need to materially affect a paper ballot.
With a blockchain-based system, every voter would count everyone else's votes
Given that experts already know how to secure elections and that traditional tech solves the problem just fine, Blockchain would almost certainly lose.
Election tech experts like Verified Voting, Black Box Voting, and Ed Felton & co at Princeton already know how to secure elections, but for whatever reason that knowledge hasn't promulgated to all the local election officials in the country that make the decisions on how they're run and what tech they use. That's the real problem, not a lack of secure voting knowhow/tech.
What's unique about blockchain compared to paper ballots is, everyone has access to every ballot if every ballot was recorded on the blockchain, which is unfeasible with physical paper ballots. The slow speed of consensus is also less of an issue for elections than it is for financial transactions.
That being said, use of blockchain alone doens't make a election secure.
Paper ballots win, hands-down, in that respect.
Blockchains are better then opaque electronic voting machines, but not entirely better then paper.
If your crypto system has non-verifiability of who you voted for as a requirement. How do you prove that the code actually running on the machine didn't change the vote?
Especially seeing as actual machines have code other than the election software running on it, think touch screen controllers, etc..
I'm not sure how blockchains allow for that.
With keys, you can verify your vote was counted and not tampered with. If you don't want people to know how you voted, destroy your key.
I'll admit that this still has the some of the same flaws as paper ballots: government doesn't track which key/ballot is assigned to you, and effectively centralized issuing of keys/ballots. But the advantage is: it's harder to forge or tamper with a ballot
There's no such thing as perfect security. The problem of secure elections is how secure is secure enough?
How many keys/ballots can you feasibly steal before getting caught? Is that number significant enough to change an election? Historically, it hasn't been.
If you can prove how you voted, this will be the subject of vote buying (or negative retaliation for failure to prove “correct” votes.) History has demonstrated that over and over again, which is why secret ballots for normal public elections and recorded votes in representative bodies where you want voters to be held accountable are norms.
Why not? I'd like to know that my ballot was counted properly.
And that everyone whose vote was counted was a valid voter.
And that everyone whose vote was counted, was counted how they intended (but not the content).
You're right if you mean that some of those desirable properties might be irreconcilable, but that's not the same as saying I shouldn't be able to validate correct counting outright; that's exactly what allows votes to be changed after the fact.
IIRC, it is possible to use homomorphic encryption to get all of that and have an end-to-end auditable system that maintains differential privacy (impossibility of detecting a change in the outcome by removing one vote). But I don't know the details of such a system.
Imagine a sketchy untraceable site on tor that'll give $20 for every public key that voted "the correct" way.
During the gilded age, voter buying was a particularly bad problem, so we have a history of this attack in the united states.
But in that case, your objection is to "being able to prove to others that you voted one way". Not to "being able to prove to yourself that you were counted as voting one way".
Equating the two makes to harder to evaluate what is and isn't possible with different schemes like e.g. homomorphic systems.
There are zero-knowledge proof systems that can convince exactly one person of a claim but not others (because the one person chose random challenges that others' can't trust not to have been revealed in advance)
Be careful what assumptions you're depending on!
It's also to protect the voter against retaliation; imagine if the government can discriminate based on how you voted. You can always destroy paper ballots; it's difficult to destroy public blockchain ledgers.
Right -- my point was that the parent was equating the two, but that's throwing the baby out with the bathwater. It's great that you can't prove to others how you voted, but not if it allows a third party to overwrite your vote without your knowledge!