I can do this multiple times. Each time I void my previous ballot, betraying my previous customer.
Then comes election day, then I show up in person and cast a physical ballot for the party that I favor. As a buyer, my customers have no way of knowing I didn’t void the preliminary ballot by showing up on election day.
Note that frauding vote buyers this way is also possible in most election systems that have non-digital preliminaries.
- If every time you vote you get a receipt for that vote that can be checked if it's still valid then you can send that receipt to the buyer and he can then check that your vote is still according to his purchase - If you can only check that the receipt was registered but not if it's still valid you can't check that your vote was correctly counted because you don't know if the vote has been changed after in multiple possible ways - If you can check that the vote actually is for candidate A at any time you can sell that access to the buyer for him to confirm - If the only way to avoid all this is to also cast an actually secret vote on election day the buyer now just needs to make sure you don't go to the polling place. Posting spotters at the door is not too hard.
I don't see a way for you to actually be able to confirm your vote was counted and not having at the same time the ability to sell your vote in a verifiable way. Perfect verification isn't needed either. If you're selling your vote to the mob you'll have second thoughts about failing to deliver. If you make the process easier "honest" sellers will create the market.
> Note that frauding vote buyers this way is also possible in most election systems that have non-digital preliminaries.
Most I know are actually harder because you only get the single mail-in ballot so you can't do the double or triple voting. If you can show up on the day and invalidate your mail-in then part of same can be done. Depending on how the invalidation of the mail-in is done it can be even sketchier. But I don't consider mail-in and absentee paper votes to have enough security guarantees either way. Paper ballots, in a box, counted by adversaries is the gold standard. Everything else has a high burden of proof.
Someone with a paper ballot can photograph their ballot with a phone of spycam, to prove their vote to a buyer.
It's easy enough to deploy spotters without being found out. Just deploy spotters as exit pollers, they're already part of any modern election :)
And thinking about it some more the Estonian system seems perfect for vote selling. You just provide your ID card and PIN in the last day of early voting and get it back the day after the election. The buyer can vote in your name and hold your ID card to make sure you can't vote in the booth.
Not necessarily. It is possible to have verifiability and receipt freeness:
https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
> The demands of voting are incredibly unsuited to digital systems and definitely to any online voting.
Clearly you need to do more research before making such sweeping claims.
I know these methods, but they were not used in OPs suggestion. They fix this issue and introduce others.
> Clearly you need to do more research before making such sweeping claims.
On the contrary, I'm willing to double down on my claim. I'm willing to provide either a breach or a denial of service for any digital or online voting system you care to describe.
Electronic/Online voting is like catnip for programmers. We can consistently overcomplicate things and create these horribly complex constructs because we're sure there must be a solution. After all software is eating the world. Voting is however one of the few situations where the lack of sophistication of pen and paper works in your favor significantly.
You knew it but didn’t mention it as an obvious neutralizer of your objection, in the context of a discussion about possibility (“you could”)? I doubt that.
> I'm willing to provide either a breach or a denial of service for any digital or online voting system you care to describe.
There are many systems in the literature. What are your credentials in this field? Are you a cryptanalyst?
> Voting is however one of the few situations where the lack of sophistication of pen and paper works in your favor significantly.
This is as myopic as saying “E-commerce and e-banking are some of the few situations where the lack of sophistication of pen and paper works in your favor significantly. The demands of e-commerce and e-banking are incredibly unsuited to digital systems and definitely to any online systems.”
This is baseless and useless. I've discussed this online in several situations, including on hacker news. If you really want to check this feel free to see my comment history here and on reddit.
> There are many systems in the literature. What are your credentials in this field? Are you a cryptanalyst?
There are plenty of systems in the literature, even ones I am happy to stipulate right now are 100% cryptographically sound for the purpose of the discussion. The kinds of attacks you'd use against them are not to break the crypto. They're to break the usage of the system by common citizens and eliminate all trust from the election. Once you do that you no longer have a functioning democracy.
> This is as myopic as saying “E-commerce and e-banking are some of the few situations where the lack of sophistication of pen and paper works in your favor significantly. The demands of e-commerce and e-banking are incredibly unsuited to digital systems and definitely to any online systems.”
eCommerce and eBanking have very different needs, so the query/replace doesn't work. In banking you both accept that some people in the banks have access to your data and that transactions can be reverted. None of that applies to voting where the process has to at the same time avoid leaking who you're voting for, provide accurate counts, and be trusted by the average citizen. Those properties are simply not possible without a traditional paper count done by adversaries.
Feel free to point out where you previously discussed receipt freeness. And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt free?
> The kinds of attacks you'd use against them are not to break the crypto. They're to break the usage of the system by common citizens and eliminate all trust from the election.
You're going to have to be more specific about what you mean.
> the process has to at the same time avoid leaking who you're voting for
This is called receipt freeness, which we just discussed.
> provide accurate counts
This is called universal verifiability, which is also perfectly attainable by e-voting systems.
> be trusted by the average citizen
You've provided no reason to think that citizens will never trust e-voting systems. The very article of this thread provides a counterexample, and it's not even the most secure.
> Those properties are simply not possible
This is just flat-out wrong. It is perfectly possible to have all of the above properties simultaneously.
I'm not going to go around spelunking on my old comments to prove to you that your attacks on me are unfounded. Do your own homework if you care about this for some reason but this is getting extremely aggressive for no reason.
> And if you did, then why didn't you mention it in your comment, which gives the false impression that any verifiable voting system cannot be receipt free?
The point of my comment was to explain that what appears to be a common solution to a problem that we'd use in any kind of electronic system breaks down other stuff in electronic voting. I wasn't about to go 10 rounds of "but you could do X and then be broken by Y". My point isn't that there aren't clever ways to engineer digital systems for electronic voting, is that however you do that you end up with something that can be attacked in horrible ways. See below for an example.
> You're going to have to be more specific about what you mean.
Since you haven't provided a voting system for me to attack I'll try with what I consider to be a very good one:
- You vote by pressing a button or touchscreen at your polling place
- A paper ballot is printed with your vote that you verify and drop into a traditional ballot box to be counted as usual
- A receipt is printed with some code that you can later use to check that your vote was counted in a cryptographically secure way
- Paper ballots are tallied locally as usual, electronic results are sent encrypted to a central server that can be later used for vote count verifications
- The electronic count and the paper count are done in parallel and both published. You expect small differences in the count (mostly from human error in the paper count) but as long as the results match up to a low difference you trust your election.
- There are no flaws in any of the crypto and all the polling officials are honest (this last part is something the paper system does not depend on)
So this seems strictly better than a paper election right? You get the electronic count just as the polls close, the safety that you can later check that your vote was counted electronically, and the double-check of the paper count to fall back on. So here's how I attack it if I'm just a skilled hacker working alone:
- Work as a tech at one of the polling places and intentionally miscalibrate touchscreens. People will register wrong results and get some stories out that strange things happened in some polling places.
- Pick polling places where a minority is heavily represented and break those machines in particular. At worst some extra coverage, at "best" the election gets skewed because those polling places start having long lines and people walk away.
- Spread some malicious code to the general population through any of the normal means (Android apps, unpatched vulnerabilities, etc). I just need to get a small number of common citizens. Have that code intercept the place where you check if your vote was counted and tell you it was not. Hopefully you'll recheck in a clean machine and be satisfied. If possible target politicians and the actual losing candidates in the election so that they are particularly worried that the election was stolen from them.
- Finally hack into the central server where you do the checks to see if your vote was counted and make checks fail randomly.
At the end of this you have seeded pretty deep distrust over the election. Depending on how skilled the hacking is it may be enough to break down the trust in your democracy. I'm not willing to take that risk. But now if you're a very well funded hacker group or a state actor you can do more:
- Hack the network providers and selectively DoS the verification server for minorities or parts of the country that voted against the winner.
- Infiltrate the supply chain of a few of the thousands of suppliers of the voting machines and plant hardware level bugs that are time coded or just cause random errors (e.g., the touchscreen bugs)
- Hack the networks used to communicate votes from polling places and DoS those so that the count is delayed
- If you can hack the power grid have power cuts in polling places. If you were voting on paper it wouldn't matter but now you can't vote
- Do all those again in targeted polling places looking for minorities and/or populations that are very skewed from the national average to entice maximum distrust
- After enough doubt is created manipulate social networks based on those cases to nudge the population into thinking the election is rigged. It only takes a small percentage of the population believing that before you have a crisis on your hands (think yellow vests in Paris).
At the end there's a very high chance your election is now fully distrusted and the country is in chaos. Even if it doesn't work 100% of the time it only takes one or two successful events globally for people to distrust these systems, whichever they are.
The scary thing about what I just described is that plenty of it is indistinguishable from what is already happening in some cases in US elections today. I'm willing to hope that the US case is just pure incompetence, but the attack surface is very large and we've seen that foreign state actors are extremely motivated to meddle with elections. I expect more examples of this in the future, particularly since the actual systems deployed are incredibly poor compared to this one.
> This is called receipt freeness, which we just discussed. > This is called universal verifiability, which is also perfectly attainable by e-voting systems.
Yep both of these are possible as long as the crypto is sound. No current electronic voting system actually clears that bar, most have no crypto at all. But there's no reason you couldn't do it at enormous extra cost if you had enough extremely competent people dedicated to the problem. I still haven't seen a good argument why you'd want to though. Which is the second part of this problem. If there are no advantages why do it? Proper paper counts are cheap, well tested and get results 2 or 3 hours after the polls close. The US is notorious for not being able to do that but it's routinely done across the world with no issues.
> You've provided no reason whatsoever to believe that citizens will never trust e-voting systems, and there is strong evidence against this from the fact that they are perfectly willing to engage in e-commerce and e-banking.
See the above attack scenarios for why I definitely think citizens should never trust any electronic voting system. The difference for eCommerce and eBanking is that under any of those attack scenarios you just go to the bank branch and sort things out, including reverting transactions. You can't do that with your vote. Once the verification system fails the whole election fails and the faith in your democracy plummets. None of those attacks are specific to this system either. They're just relying on the flexibility of computers versus the extreme lack of features of pen and paper.
> This is just flat-out wrong and reflects your ignorance of the subject. It is perfectly possible to have all of the above properties simultaneously.
At this point it's on you. Feel free to improve on the above system to try to get the three properties. It's extremely unlikely you'll be able to just from the nature of computers and computer networks. We put up with all their extra complexity for all the extra value they bring. I couldn't be having this discussion with a person I don't know that is most likely half way across the world without the internet. But all that complexity plays against you when you're trying to secure a vote. You don't need to change the vote to destroy an election. You just have to seed enough distrust that the process is no longer accepted.
The most important characteristic of the voting process is that you are able to convince those who lost that they've really lost and what computers/networks have in abundance is failure modes and corner cases. Couple that with the lack of knowledge of the general population (and certainly of most politicians) about technology and it's very easy to attack an election by just engineering doubt over the whole system even if all the failures that you induce were designed for.
Whether it's incompetence or foreign attack, the damage done will be the same in both cases, so it's a terrible system to use either way.
You're asking me to prove a negative. I merely said I doubted you knew about receipt freeness because you didn't even mention it as an obvious counterpoint to your claim, which is a reasonable conclusion. If you consider that an “extremely aggressive attack”, fine. It is easy for you to prove me wrong, you just have to point out the comment in question.
In the meantime, I'll continue to assume you either had no idea what receipt freeness was, or deliberately created the false impression that a verifiable voting system cannot be receipt free.
> I wasn't about to go 10 rounds of "but you could do X and then be broken by Y".
You've failed to show that receipt freeness introduces something else that fundamentally "breaks" which wasn't in the original system, despite repeatedly claiming this is so (see also "They fix this issue and introduce others", a claim made with absolutely zero evidence).
> So here's how I attack it if I'm just a skilled hacker working alone:
So you just assume you can achieve all of this for any e-voting system. Fantastic argument. Really convincing. You may as well have said "Here's how I would attack and infiltrate banking networks or current voting systems surreptitiously. See, we can never trust either of these!" That's just laughable.
> At the end there's a very high chance your election is now fully distrusted and the country is in chaos. Even if it doesn't work 100% of the time it only takes one or two successful events globally for people to distrust these systems, whichever they are.
Clearly wrong as evinced by Estonia's voting system, even in the face of its demonstrated security flaws.
> The scary thing about what I just described is that plenty of it is indistinguishable from what is already happening in some cases in US elections today.
...and it hasn't led to the collapse of the voting system.
> If there are no advantages why do it?
Are you asking what the advantages of e-voting are?
> The difference for eCommerce and eBanking is that under any of those attack scenarios you just go to the bank branch and sort things out, including reverting transactions.
You're assuming banks are always aware of attacks, which is just not true.
> At this point it's on you.
It's not "on me". It's been mathematically proven that a system can possess these properties simultaneously. For example, see
https://link.springer.com/chapter/10.1007/978-3-540-24691-6_...
> You've failed to show that receipt freeness introduces something else that fundamentally "breaks" which wasn't in the original system, despite repeatedly claiming this is so (see also "They fix this issue and introduce others", a claim made with absolutely zero evidence).
The issues that are introduced are exactly all that attack surface that I described how to exploit. You keep insisting that the math checks out but that's not in dispute. The mathematical properties of a well designed electronic system are fine. It's the actual engineering realities of such a system that makes it massively easier to exploit. All those examples I gave and many more are now failure modes you have and didn't before.
> Are you asking what the advantages of e-voting are?
Yes. I live in a country that has heavily invested in e-government but runs very efficient paper elections. I go in on a Sunday at my convenience and get the results for the whole country 2 or 3 hours after the polls close, extremely accurate predictions maybe an hour after. I know of no advantage electronic voting would bring that would be worth the extra cost, let alone the risk and complexity. It's a (very poor) solution looking for a problem.
It's also important to realize that the mere suspicion of other people selling their votes is enough to undermine confidence in the system.
And confidence in the system is pretty much the only thing you have to optimize for.
But that is still pointless cause the person you sold your vote can be physically next to you, or you can film yourself voting.
Online voting is unsafe, and should only be used if any other option is unfeasible.
There are no circumstances where online political voting should be used. Ever.
If you get 10 years in prison for trying to buy votes, and the government offers a standing reward of say, $100,000 for evidence that leads to a conviction, all of the sudden you have to pay substantially more than $100k/vote, which means that it's completely impractical to engage in.
Politicians also tend to do all sorts of crazy, risky and/or illegal things to get elected or for personal profit. Nixon and Trump spring readily to mind.
If the reward is large enough, someone will risk it. Sometimes the reward doesn't even have to be large at all -- witness rich celebrities shoplifting, for instance.
People can also be compromised and blackmailed in to committing crimes, or otherwise feel desperate and at the end of their ropes, so they'll try anything.
That's to say that such laws shouldn't be made, but I am skeptical that they'll be enough.
A countermeasure might be an undisclosed deadline lottery: a guaranteed voting window until some time t, then allow corrections until an individually randomized cutoff moment t+x, with a sufficiently big range for x (up to two days, perhaps?). Don't provide feedback wether a correction went through or not to make it even more opaque to a possible buyer.
People free from interference would simply make their first vote their real one, cast safely before the earliest possible deadline.
There is. In the Estionial election it is something like the day before election day. But even if there wasn’t if you need to spend the time and effort to coerce your agent for anything longer then few hours, buying enough votes to sway any election is going to be unfeasible.
It's not a problem because there is too much "friction". Vote buying is already not impossible but way too hard to establish itself. When it becomes gradually easier it still won't be a problem, because it is still not yet established. So you allow even more changes that make it easier, because it's not a problem yet. Call it a slippery slope argument all you like, but there is a crazy amount of inertia in the absence of vote buying that is protecting democracy now, but that will turn against us once it is overcome. When barriers are lowered so far that the inertia is overcome, the same inertia will make it incredibly hard to get rid of vote buying again. Keeping honest people honest is orders of magnitude easier than making them if they are not. I would not want to risk it without a promises of truly significant gains and I just don't see those with e-voting.
But vote buying is not even the problem I would focus on. Much more pressing is the form of soft coercion that is enabled by allowing voting in what I would call "unchecked privacy": imagine you are part of a group where everybody assumes that all would vote the same. There is a documented tendency (proudly showing off your ballot on Twitter) to scrap vote secrecy in favor of virtue signaling for "the cause", whatever cause that might be. As soon as there is a group with supposedly aligned opinions, the true believers will tend to erode secrecy and establish an expectation that the others follow. Maybe your spouse won't beat you, maybe your friends won't shun you for insisting on voting in secret, but the easy path is to just go with the flow and play along. "What difference does a single vote make?" Optional secrecy is a serious weakness to the democratic process.
That entails basically going to people, buying a voting slip and casting it on their behalf. Or better, buying packs of slips from officials. For e-voting it would be the same.
Sure, you can increase jail time and reward revealing it, but that is not a panacea, as the existence of _any criminal activity_ proves.
Keep in mind that you need to check the vote on a different device than what you voted on.