We do not need this. It isn't even a solution in search of a problem it's a problem in search of a place to explode.
A rundown on some of their security: https://mobile.twitter.com/GossiTheDog/status/10266038003653...
We do not need this. It isn't even a solution in search of a problem it's a problem in search of a place to explode.
A rundown on some of their security: https://mobile.twitter.com/GossiTheDog/status/10266038003653...
It seems like blockchain would allow everyone to be able to check that their vote counted, in an anonymous yet totally transparent and verifiable way.
If you want to, you can go to the polling place and observe the box with the ballots all the way through to counting and registering the totals.
That's why some states don't allow you to take a picture of a ballot that you filled out. They're trying to prevent you from confirming that you voted a certain way.
Secondly, there are states where you can vote by mail. Do you know if vote selling is a big problem in those states?
The state republican party still makes occasional claims of voter fraud, but those are exceedingly rare -- something like 54 ballots out of 4 million in the 2016 election cycle -- and they mostly come down to people voting in Oregon and in another state at the same time.
The only reported case of election fraud I can remember was in 2016 and done by a republican, in which she tossed out a bunch of democratic voter ballots. That's it.
For two decades of elections, Oregon hasn't had a problem with election integrity. They do, however, have a consistently high turnout, which they attribute to vote-by-mail.
And this is a real issue, vote buying and cohersion has historically been the most common voter fraud mechanism in the US. It's a major part of how the Boss Tweed and his associates ran New York.
It's not about you selling your vote, it's about coercion. If your vote is verifiable, then you can be threatened with bodily harm for not voting a certain way, and/or for failing to verify that you voted a certain way.
Your freedom to sell your vote is worth less than someone's freedom to vote free of intimidation or threat of violence.
This is less ideal than voting in person for everyone, as it still has failure cases like sufficiently abusive relationships. But it's an overall improvement over the previous system. Significantly more of the population votes in practice, making the vote a better measure of the ever-nebulous "will of the people".
Or have a person follow you and see what you do. Which would've worked all times I've voted here in Sweden.
I'm certainly not going to pay you to vote the way I want without proof of delivery.
The fact that you cannot personally verify whether your vote gets counted is a feature, not a bug.
An example: https://en.wikipedia.org/wiki/Scantegrity
You can watch if you want, or even be a part of the counting. IIRC most paper ballot schemes have the counting be public in some form or another, so that opposing factions can call each other out if someone is cheating in some way.
Blockchains for election administration are a digital form of physical chain of custody. Like when you move boxes between locations.
You're thinking of crypto voting schemes. None of which have proven feasible in the wild.
The Australian ballot form of election administration means private voting, public counting. For example, dropping your ballot into a box at a poll site.
Any process enabling any kind of post mortem verification is more akin to accounting, eg open ledger with credits and debts. That's the opposite of a secret ballot.
What.
By voting you commit a change to the blockchain. The system should report back your "commit hash". Said hash is public (as is the entire blockchain), guaranteed to be unique, and counts towards the overall balance.
In contrast - a paper ballot can disappear. Your vote can be manipulated. All without any trace.
Having studied this stuff for over a decade (now inactive), I believe, but cannot definitively prove that paper ballots cast at poll sites is the most robust against attack. FWIW, the election integrity community concurs.
Security research and knowledge has progressed a lot in the last decade. It'd probably be worthwhile to circle back and apply the state of the art to this domain.
(Alas, saving democracy doesn't pay very well, so it's unlikely that it'll be me doing the work this time around.)
Here's how a Blockchain voting system can work:
1. Person casts vote using a voting machine.
2. Voting machine commits a change to a publicly available blockchain. The commit includes metadata such as the actual choice you made. It can optionally include even more metadata, such as "place of vote", "timestamp", "gender", "age".
3. Your vote has been cast, and the blockchain has been been modified.
4. The voting machine prints a "receipt". Your receipt includes a "commit hash". You can use the hash to see, identify and verify your record has been registered with the blockchain. So can everyone else.
5. When the voting is done - a simple python scripts traverses the blockchain - counting how many votes were given to each candidate.
This design ensures transparency and security. No compromises. You as an individual can know for a fact that your vote has been cast, and has been counted. As a society, we can finally verify and make sure our elections were fair game.
This same model can be extended to the blockchain approach, but isn't using a blockchain to solve the ballot-stuffing problem - just using a conventional paper technique.
Some future system may find a new balance. Perhaps that new system no longer demands a secret ballot. Because the risks changed. (Note that some jurisdictions require a secret ballot, so YMMV.)
So if you want to supplant the Australian ballot with a different system, please start there. Explain the context, assumptions, risks, tradeoffs.
Because piecemeal changes to our existing system, without regard for the whole, has caused a mountain of heartache.
FWIW, I've been pondering "temporary privacy". Perhaps an embargo on all the election data for the critical time span. A friend of mine proposed (draft legislation) making all of the materials and documents available after an election is certified. For post mortem inspection. So you could feed all the ballot images into your own tabulator software. Or do your own signature comparisons. A huge change, because right now election data will be destroyed after certification (exactly when is per jurisdiction).
My polling station is less than 200m away. I have never waited more than two minutes to vote. All voting is with a pen on a paper ballot.
Once the precinct closes, you are allowed to stay and observe the counting. Because each polling place serves only a couple hundred voters, it is easy to follow the counting. As long as it is possible to do so without interfering, everyone can observe so closely they can read the actual ballots and verify that they are sorted into the correct piles. You can then watch the counting of those piles close enough to verify the count.
Later, you can go online and look up the row for your precinct in a spreadsheet.
This is end-to-end verifiability, and it is neither expensive nor unable to scale: A national election in Germany will see about 40 million voters.
What's most important: Unlike blockchain or any other online voting scheme, the whole process is easily understandable by everyone.
In times were every institution is suspected to be corrupt, being merely safe is not enough. It needs to be safe in a way that does not rely on experts in cryptography to say so.
I have seen only one valid objection to using this process in the US: It is far more common there to have elections with dozens of individual races and ballot issues. Germany usually has just two individual questions to be voted on, and maybe five when local and national races fall on the same day. Considering this, it would still be possible to use the process for the top X races on a given election day.
The key issue they try to solve is how to let you check your vote was counted without being able to prove who you voted for to anyone else, thus preventing coercion attacks.
Most of them rely on paper, but some [1], provide reasonable guarantees about online voting.
None of it involves blockchain.
[0]: https://en.wikipedia.org/wiki/Scantegrity [1]: https://heliosvoting.org/
I fill out the paper ballot, so no matter what I've voted. It is really clear how to use the system, and I'm not waiting on technology no matter what happens next.
Then I roll it into the machine itself and it goes into a locked box attached to the machine.
There is always a paper record.
The machines and votes are tied together so auditing is straightforward.
In "electionese":
Ballots issued, marked, and cast at a poll site.
Ballots tabulated at poll site the moment the polls close.
All materials and gear distributed from and to a central count.
All handling done in public in the presence of reps of all significant stake holders, election observers.
Receipts, logs, seals for everything.
Source: Was a poll inspector for years.
It's all the security of physical ballots, with the speed of electronic, and very specific / targeted auditing ability that benefits both the electronic and physical domains.
Even as a geek utterly opposed to most all use of computers for tabulation, I came to believe the biggest threat to election integrity is change. We just have to stop shaking the ant farm every few years. Whatever changes are warranted, they need to be slow, deliberate, methodical. Because it all really comes down to the people (admins, voters, candidates, observers, etc), their domain knowledge, expectations, and experience.
As Alistair Cockburn wrote, good people can make even bad processes workable.
PS- Belatedly response, sorry. Got rate limited yesterday.
I won't knock blockchain completely, because I don't believe I'm smart enough to, and it likely has many useful applications, but I feel like half the time I hear about blockchain, this quote is applicable.
1. like paper money, anonymous - my vote should be secret.
2. Hard to do large scale fraud or manipulation - not being efficient or automatable is a feature guys...
3. Physically going to the polls, voting in public, yet private at the end really makes it hard to put pressure on people to vote one way or another. Compare that to voting electronically at home or in church or at work....
Any one wanting to understand why any of these changes occurs will be illuminated by better understanding the business models of the vendors and the appropriations (budgets) of the jurisdictions.
During the HAVA bonanza, which brought us the touchscreens, vendors envied high tech valuations, so repackaged themselves as product companies.
When that fad went bust (market saturation), vendors repackaged themselves as service companies. With a big difference from their prior incarnation. Changing from time & materials to charging a fee for every task for every voter every election.
Before, you'd buy ballots for expected turnout plus 10%.
Now, (with vote-by-mail) you buy the whole ballot packet, for every voter every election.
Before, you'd pay 10 cents for every voter signature verified.
Now, you pay for signature verification services for every voter every election.
It's astonishing how each and every step of the process has been monetized (rent seeking).
--
Huh. It just now occurs to me there's probably a better way to summarize the business practices of the vendors:
Just imagine what IT vendors like Oracle do to maximize revenue applied to election administration.
Vote by mail and extended voting hours are much more effective solutions for people who otherwise couldn't find the time to vote.
Sweden has this plus early voting and we have between 85% and 90% participation in our elections. The early voting of course make it easier to manipulate votes.
So, just make sure you throw out all your extra ballots and you're fine.
Edit: 2016 US General
1. How about low voter turnout, so elections aren’t representative of what the people want. An app would increase voter turnout by a lot, especially the younger vote.
2. How about letting less mobile people to vote. Or people who are not able to take off work that day. (https://www.vice.com/en_us/article/zm9j85/i-couldnt-vote-bec...)
3. How about being able to count elections in time to call them, instead of things where Bush gets elected because some guys ran out of time, and then it turns put Gore would have won?
Aren’t these important enough problems for a democracy to solve?
Instead of simply downvoting, why not actually address what I am saying! I am going to go point by point.
Sure, absentee ballots are a thing, but guess what. People like apps. If it’s secure enough for everyone’s banking needs, why not for a vote?
You can make the same argument about money — that banking apps are a honeypot for thieves etc. And yet we have made banking apps so so secure that you’d use them to move thousands of dollars.
If everyone voted from their phone, it could be anonymous and cryptographically secure. And a Merkle tree would record all results.
What is the issue? Every problem you point out with electronics can be done with paper ballots, too.
The interface can lie to you? Has been done with butterfly ballots and others.
The vote counting process is rigged? Have different groups audit the process.
In fact, having cryptographically secure receipts makes it extra easy and fast to verify votes. Al Gore would have won, because they wouldn’t have has to take so much time for a recount:
https://m.youtube.com/watch?v=qcz6NSyxrfQ
Instead of throwing our hands up and saying “oh, X is an issue!” why not simply work on fixing the issue?
So let’s run down the issues:
1. Not enough access to phones and computers
Fine, people without phones can still vote the old fashioned way.
2. Stealing a phone
A very inefficient way to fake a vote
3. Interfaces that lie to you
Ignoring the fact that machines already do this (https://youtu.be/EV_c1-YTk8M) the interfaces would need to be audited by different groups using each other’s interfaces in an anonymous manner (not like when Uber’s greyball https://amp.theguardian.com/technology/2017/mar/03/uber-secr... ). This is the general problem of the Trusted Computing Base.
4. Anonymity
Listen, should we know how every person voted?? We do now! Thanks Government. Best Voting System Ever (https://www.forbes.com/sites/leemathews/2018/10/16/millions-...)
Erm sorry. The solution. Token mixing. You get one token per person, but then they go through a cryptographically securd mixer before being used to sign your vote. Kind of like with Monero rings.
5. Accountability
How can we prove the votes happened the way you wanted them to?
Well, YOU still have your token on YOUR phone (no one else does) so your app can audit the Merkle tree.
Zero-Knowledge Proofs would be overkill here because proving how you voted to someone else is important (See #3, above). In addition, ZK proofs are a bit ivory-tower idealistic since most people don’t have the knowhow to “produce a fake alternative vote”.
The Merkle Tree can consist of smaller branches, one for each district. The results can be tallied in near real time, and verified by anyone. Results would be known in real-time.
6. But realtime reporting will affect voters!
Yes, and it currently already does, with Ohio, Michigan, and so on. The current system makes some states way more important than others:
https://www.nationalpopularvote.com/campaign-events-2016
Why not require all states to have primaries at the same time and not reveal the results til the end? This is a political, not technological, solution.
The only one major problem I see with electronic voting is #3, the trusted computing base. I listed the main solution above, but I am sure there will be many improvements on it.
Improved accessibility from the status quo has minimal marginal effect on turnout. https://www.eac.gov/documents/2017/02/23/will-vote-by-mail-e...
> 2. How about letting less mobile people to vote. Or people who are not able to take off work that day.
Paper mail-in ballots are a well-established way to accomplish this, though they do have their own risks---specifically vote-buying and coercion. My county in California also allows curbside voting by appointment, which is pretty great for elderly voters.
>3. How about being able to count elections in time to call them, instead of things where Bush gets elected because some guys ran out of time, and then it turns put Gore would have won?
This is already a solved problem with precinct-counted optical scanned ballots.
I highly recommend you volunteer to be a poll worker the next time there's an election in your state. You'll learn a lot about the real problems on the ground. For example, in my precinct during the 2018 midterms, we encountered an issue with the voter rolls: the city had recently renamed a street but a lot of people's registrations still reflected the previous name, which slowed things down significantly.
Peer pressure, culture of voting (your neighbors noticing they didn't see you at the poll site).
Competitive races.
On the flip, there are many things which counteract vote suppression:
Universal, automatic voter registration (just like all other mature democracies).
Reenfranchise felons.
Fair redistricting.
Adequate funding for election administration.
--
I've not seen any data suggesting that digital voting schemes have or may boost voter participation. And there's numerous cases where such systems disenfranchised voters.
- Voting in private on a phone app. The opportunity for coercion is huge. The brilliant thing about putting a cross on paper in a booth on your own and dropping into a box, is no-one knows how you voted - so no comeback.
- Anything in software has the opportunity for a large scale attack. The incentive for doing such attacks is large. Look at all the energy put into gerrymandering etc today - Why risk it?
- the ability to do a sensible audit is beyond most people - auditing a pile of paper is easy - anyone can participate. Software you'd need to trust a small priesthood - that's not democracy, and it's totally dangerous ( forget algorithms, the weak points are people ).
I'd also question your premise that low voter turn out is largely due to inconvenience. Sure for some, but I'd argue lack of participation is largely riven by other factors - like nobody worth voting for....
Finally paper system is easily adaptable - want a box for write ins? Move to single transferable vote? Just print different paper and people doing the counting can adjust - no software re-writes.
How is that true, when I just posted that voter database have been leaked
https://www.zdnet.com/article/us-voter-records-from-19-state...
and they contain (per Wikipedia):
Personal data frequently included in a voter database:
Voting history (including federal, sub-national, primary, municipal, or special election voting history)
Name
Physical address
Mailing address
Phone number
Party membership or affiliation
Absentee or military voter designations
Source of voter registration, i.e., DMV/MVA, Public Assistance Office, etc.
Ethnicity or emerges race hypothesis
Gender
Birth date or age range
https://en.wikipedia.org/wiki/Voter_database
Not only that, but some states consider this public information!
If you know how a district voted, why not coerce the entire district? After all, if you have access to unlimited coersion powers, you’d be wasting them on a couple individuals.
I say if someone has the power to coerce others to that extent, we have bigger problems in our democracy. They can, for example, coerce members of the opposing party to stay home and not vote.
In short, I think this is a fantasy problem. There are far easier ways to fake a vote (like this: https://beta.washingtonpost.com/politics/2018/12/06/gop-was-...) and the app would prevent those.
“All registered Republican voters who submit proof they were home that day will receive $50 cards”
The most additional information you can glean from this is what primary a person voted in anyways. These are just participation history and registration information. Do explain how I can figure out which candidate someone voted for in the general from this information?
you cannot have one without the other if your intent is to protect the system and to be honest you only need paper ballots as a receipt to allow verification in case of suspected interference. we have already seen that some paper ballot designs are more prone to fraud than others.