Debian decides to allow secret votes
lwn.net
lwn.net
Debian had a vote with 4 options:
Option 1 "Hide identities of Developers casting a particular vote"
Option 2 "Hide identities of Developers casting a particular vote and allow verification"
Option 3 "Reaffirm public voting"
Option 4 "None of the above" (NOTA)
The objection raised here is that Option 3 and Option 4 can be considered to be the same depending on how you interpret them (ie; "None of the above" vs "Keep public ballots" which can be said to implicitly suggest none of the above at the same time). If those two were represented as a single "NOTA" option, that option would have won the ballot in terms of votes.
Assuming I understand this anyway. The way the votes are reflected is confusing to me
The discussion seems to be about ballots with 3 > 2 > 4, and when 3 was eliminated the votes went to 2, allowing it to pass. That's a bit strange because you'd expect a ballot to always have 3 next to 4 since they are so similar.
I do think ranked choice voting is dumb and adds low value and high complexity. This thread with hundreds of comments affirms that notion.
To me, Debian Developer feels more like a position of responsibility and representation than a member of the public. But I'm not one, and I don't know what the expectations are.
Also 3 and 4 were not similar. 3 would have changed the constitution to require public voting, 4 would simply do nothing and leave the issue an unanswered question.
This wasn't the general public. This was a few hundred people who carefully follow and care about the Debian project. I'm highly skeptical anyone who voted was "confused".
If you wanted voting secrecy but were unhappy with the proposed implementations of option 1 and 2, you'd vote 4 > 3, leaving room for future alternative proposals.
If you were against any form of voting secrecy, you'd vote 3 > 4, shutting the door on future proposals.
If you remove A as a choice, or B, people might go with their next preferred option instead of just not voting at all, etc.
This means you can't know for sure that results would equal the same with or without that option, because you cannot actually assume all actors will vote the same every time. To even begin to think such a thing as true is just asinine when the world proves to us on a daily basis that people are willing to compromise on their beliefs all the time. (No offense.)
In normal elections we see this with people who don't like any choice, but don't want to spoil their ballot. So they pick their next best favorite.
This means that if A is removed, people might pick B or C instead just because A isn't there.
People are tricky. Hard to pin down what's exactly going to happen every time. There are distinguishable patterns and such; but ultimately you can't rely on them as if they are infallible.
Of course people might not necessarily act rationally but you've got to draw a line somewhere, otherwise elections are simply undefined behaviour and talking about properties of elections becomes meaningless.
But, no, you cannot safely recalculate that result, because by and large people are the representation of chaos. undefined behavior is the norm, not defined behavior. Defined behavior is only present in any of our societies because of 'social norms', which is the only reason I relent and say that some assumptions might be possible. But I will not agree that you can 'safely' recalculate that result just using whatever assumptions some person arbitrarily has deemed 'good enough to trust'.
That kind of thinking is why most polls are actually wrong, but taken as good enough. (Yes, I'm one of those people who nit picks the randomness of their selection biases.)
P.S.
All it takes to swing an election in favor of the underdog is a single new revelation. All it takes is for people to suddenly question their previous choices. A & B might be their norm; but people can be swayed to choose C or D if the situation is right.
This is why we can't really trust assumptions without some sort of evidence to back them. At which point they stop being assumptions...
Otherwise you're just arguing the vote is invalid because it would have ended differently in a rerun, and you have to stop somewhere.
For those that are wondering (like I was);
Google & Wikipedia:
"The Schulze method selects a single winner using votes that express preferences. The method can also be used to create a sorted list of winners. Therefore, if several positions are available, the method can be used for this purpose without modification, by letting the k top-ranked candidates win the k available seats."
The issues arises from how the 3:1 ratio is calculated. Which is by comparing the number of “change it” votes to the number of the “None of the above (NOTA)” votes (this is my understanding of from the email thread).
As a result the number of NOTA directly impacts the number to approval votes needed to win, as a simple majority isn’t enough. Thus having a NOTA option, and an option that looks like a NOTA can create confusion which splits the NOTA vote, because voting “keep public vote” above NOTA, which reduces the number of counted NOTA votes, and increases the number of “change it” votes (as all non-NOTA votes are considered “change it” votes, regardless of practical impact, at least that my understanding from the thread). Thus reduces number of approval votes need to achieve the super majority.
As this vote was won by a single vote, voter confusion on how choice ordering regarding the NOTA option could have swung vote against the intentions of the voting members.
[1] https://en.m.wikipedia.org/wiki/Benevolent_dictator_for_life
Looks like Option 1 and 2 were similar enough to "split the vote" too. What would have happened if 1 and 2 were combined and 3 and 4 were combined?
If the ballot were different, the results would be too. You can't take the results of one ballot and mush them around to support a hypothetical result; see also counting of the 'popular vote' for US president, a ballot which has never been tried, and whose results are unknowable.
A vote for 4 says (to me, not a qualified voter) I don't like the current voting, and hiding identities is also undesirable; if this choice is selected, the status quo must be continued until a new alternative is voted upon, but there's clearly desire to do so. If option 3 were selected, the status quo had clearly won, and the issue should be considered settled for whatever timeframe Debian considers appropriate.
The only way to properly poll that is either rank choice voting or a second vote after voting to change or not.
[1] https://en.wikipedia.org/wiki/Schulze_method
https://www.newsweek.com/russian-politician-discovers-2-men-...
I don't follow this point. I'm not an American, but my understanding is counting via simple popular vote vs "electoral college" doesn't change the ballot itself, you still vote for the president directly; it just changes the way the ballots are counted.
Are you suggesting either something on the ballot is different, or that people would making a different vote if it was counted differently?
Many people don’t vote at all because their preferred president has a 0% chance of winning their state and the vast majority of states are winner-take all with the electoral votes
The point is that you can't possibly know how all those interactions among voters would play out if you did in fact update the rules
Two changes would happen. A lot of people who don't vote today because their state either heavily favours the 'wrong' candidate or the 'right' candidate will already win by a massive margin, would start voting, since all of sudden their vote matters a lot more.
Secondly, and more importantly, candidates would campaign very differently. In todays system gaining 1-2 percentage points in swing states like Arizona, Georgia or North Carolina is worth infinitely more than gaining 5 percentage point in California, New York or Massachusetts, and politicians on both sides campaign accordingly. In a popular vote scenario those extra 5 points in California could swing the election which would change the entire focus of not only the campaign, but possibly even the type of policy and even candidates that the parties put forwards.
Already a big issue that big cities vote one way while rural voters go another way.
It's not right that a voter in Maine or New Hampshire, which have 1.3 million people and are roughly even between the two major parties, has a high probability of changing the outcome with their vote, while a voter in California or Texas - which have 30 times as many people - is essentially irrelevant to the outcome.
Maybe it's hard to imagine the United States of American to become 50 independent countries but isn't the way you keep them united is by promising the smaller ones that they won't be trampled on by the big ones?
If you spread 49.9% of the population evenly in a system where states vote rather than individuals, you've insured that this minority gets no representation.
What election are you referring to where the Germans democratically gave Hitler power? His best "fair" election results saw his party get ~35% of the vote, and he only got the largely ceremonial chancellorship through backdoor deals. By the time he became president nobody could consider the elections fair.
Yes, but in the US, at least, it's gotten to the absurd opposite where the minority is more or less assured a majority of votes. In order to avoid tyranny of the majority, we've more or less codified tyranny of the minority.
It would be more helpful to describe what a state of affairs looks like that doesn't result in large population states, who already maintain the gift/grift of cultural hegemony, running the country.
To take a step back, I've lived in both rural areas and major cities (I currently live in one). Rural folks being represented in government is not an issue and I find it kind of odd that people try to make it an issue like this. I'm fine having my agenda compete with theirs.
there were no metropolis like we have them today back then. City were considered gigantic with with only a few hundred thousand people -- which is maybe a largish town nowadays
Nobody said that rural people being represented is an issue, its nonetheless a fact that they're overrepresented, as they have disproportionate voting power. That term doesn't mean that they shouldn't be represented, it means that they have proportionally more voting power then a person living in a city does.
You spoke so certainly about the subject that that was not apparent. Maybe it should have been a question instead?
> there were no metropolis like we have them today back then
In the US there were, and the early development of the US is the reason for the electoral college. You had sprawling cities like NYC having to vote next to people who took months to get to the East coast for voting. Their problems were very different and the electoral college helped balance the concerns of cities that have easy access to imports and labor with areas that had no such things. On the larger scale it helped protect smaller states and territories from the policy and influence of larger states and territories. Again, their problems are very different, and in current day translate to what we end up referring to as urban, suburban, and rural.
> Nobody said that rural people being represented is an issue, its nonetheless a fact that they're overrepresented,
In the US they're not and you still haven't answered my original question, which is how are they overrepresented. You're just stating that's a fact, but it's really not.
Thats why I'm stating it as a fact,as it sounds like very simple logical connection. It could be a misunderstanding on my part, but it always sounded like a very straightforward situation to me.
There's lots of issues in the US to solve. Voting, imo, is just the pet issue of the losing party.
Every form of democracy is flawed, and it's important to be aware of them. Otherwise things tend to kinda spiral out of control, which they arguably already have in a lot of western nations with wanton corruption and completely insane people getting elected.
[0] Which is also a problem. You know how everyone says the EU is undemocratic? It's for the same reason why we have an Electoral College - the whole "federal government represents states instead of people" thing.
The grass sure is greener on every other side.
States are abstract political entities; it's people who matter.
People are represented in the House by population (less so than they should be since we refuse to let the lower chamber grow in size) and in the Senate by state.
The President of the United States represents every United States citizen everywhere on the planet. The holder of that office should be elected by a majority, preferably with some form of expression of ranking preference, of those voters regardless of what political entity they are currently in or connected to.
That's clearly true, in addition to the obvious fact that campaigning would change dramatically. The OP's point however was that we don't know the extent to which it's true.
An obvious example of people making a different vote would be in California - I know more than one Republican who either didn't vote or voted for a 3rd party 'statement' candidate for president because they knew that all of the electoral votes in CA were going to the Democrat anyway.
Undoubtedly the same thing happens with Democrats in TX or TN or wherever Republicans hold a huge majority and Electors are winner-take-all.
That's a difference without distinction, though. If option 4 were to win, then, what would they then do? The exact same thing as if option 3 were to win -- keep the status quo -- no? The idea that an option 4 win might also get people to consider other voting systems isn't really relevant; you don't vote to consider things that you will then put to vote. You just consider them, and then have a vote. So the "legal" outcome of this vote would be identical if either option 3 or 4 had won.
IMO the DPL is correct that this election was constructed poorly: they should have had either option 3 or 4 in there, not both. But I think that might just be a "too bad" situation: since there are no provisions in the constitution for a "do over", I think the only reasonable thing to do is to accept the results of the election, change the voting system, and then propose a new vote to potentially change it back, but this time more carefully consider the options on the ballot.
Unfortunately, because of the supermajority requirement, this probably won't work as intended. Just because options 3+4 on the current vote (had they been combined into a single option) may have been enough to cause the supermajority requirement to fail, it doesn't mean that there will be a supermajority (in a new vote) to switch back to public voting.
I think they screwed up, but in order to preserve confidence in their system, they'll have to suck it up and live with it.
What kind of hairbrained nimrod came up with that idea!?
You can't have mixed voting methods and still call it fair in any respect. Any chance there could be tampering should be considered not just to be happening, but to be assured to happen. "Secret ballots" of any sort when everyone else is not partaking in said "Secret ballots" just creates a skew towards unfairness and improper results. Assuming those ballots truly are secret and not just pseudo-secret. If true secret, then there is no way to track properly for sure if there is tampering...
I doubt anyone with Debian is going to be listening to me on this; but perhaps they should.
Debian crew: No. Normal voting methods only dammit.
Like they are going to listen though. In the meantime, I'll be using a different version of Linux. Debian has been dead to me for a long time now.
>I'll be using a different version of Linux.
I'm not disagreeing with the rest of your reply, but these are nonsensical statements in context. It's presenting an assumption that the governance systems in other versions are better. I've seen a lot of projects with BDFL leaders and no voting whatsoever. Linux itself is famous for permanently keeping a BDFL in charge and not really having voting, so in some sense we might be able to say they all suffer from a lack of voting methods in some areas.
People not being able to cast their vote without having to fear repercussions is justification enough for secret votes.
Sorry, wrong in every possible sense of the word. The only true way for an individual to be free from the consequence of placing their vote is for voting to be anonymous.
Any argument that a voter must face direct repercussions for their vote makes voting pointless.
> Anonymous voting should be enjoyed by the masses, never the ones representing them.
Well, since the debian voters are not, as far as a I know, elected by voters themselves, they are not representing anyone.
So far as I can tell, it's "RMS defended Marvin Minsky" and "RMS said something about sex with teenagers not being super terrible many years ago".
Also, was the Minsky thing related to Epstein? Because if so, it's hard to blame Minsky for falling victim to a international intelligence operation that also ensnared presidents, financiers, and movie moguls, all of whom are far more shrewd and worldly than any mathematician has a right to be. And the right thing would be to blame the foreign power that was doing the ensnaring, IMHO.
It goes without saying that all the commercial distros are disqualified. Anything with a (B)DFL is obviously disqualified. Anything run by a small cabal that could easily communicate in an out of band way is disqualified. What do you have left?
It's about the 3:1 supermajority requirement that was needed for Option 1 and Option 2.
It turns out that their rules for dealing with this work by comparing those options against NOTA only; the problem is that it's plausible that many of the voters didn't realise this.
Yet Another case for approval voting over like, all other voting systems.
And that the super majority was achieved by 1 vote. So in some sense it was a cliff hanger.
But 3 to 1 is a large margin, which likely has a bit of fat. I'm not uncomfortable with it.
Anyone associated with the Debian project have any insight on why voting is not secret and/or any other large os projects doing the same that could chime in?
Reasons against secret voting were expressed in ballot option C:
- centralization (there must be a central, corruptible place where the voters are authenticated or the votes are counted)
- software is untrustable: https://www.win.tue.nl/%7Eaeb/linux/hh/thompson/trust.html
The USA has had a Diebold voting scandal. Other countries are using a paper-based voting process which can be supervised by third parties.
https://en.wikipedia.org/wiki/Premier_Election_Solutions#Sec...
Relevant watching: Tom Scott: Why Electronic Voting Is Still A Bad Idea
https://www.youtube.com/watch?v=LkH2r-sNjQs
One possible solution could be ZCash ( https://eprint.iacr.org/2017/585.pdf ) but it has had its own problems ( https://www.coindesk.com/zcash-team-reveals-it-fixed-a-catas... ).
Paper voting is extremely expensive to scale compared to a website that lets you vote. Everyone could get a notification on their phone when they are asked to vote on something as opposed to having to fill out paper and send it somewhere to be counted.
I don't understand the argument of reducing cost of elections and scaling. The current paper system in place in most works (at least in European countries where I've witnessed the process) and doesn't need to scale more. If actors in a democracy can't afford such a system, and the occasional (once, twice a year) walk to the voting place, 15 minutes wait and fellow-citizen interaction, can't we accept they don't care for voting and participating and stop listening?
I'm all for accommodation of special cases (people with reduced mobility or unability to be in contact with other people) but we already have the necessary systems in place (mail-in or vote delegation).
Literally one of the last places I'd check for change or optimization. It works, leave it alone, I'll happily pay the 3 or 10eur a year.
That doesn't have to be the case though, that's a political decision to staff voting booths like that. It's also trivial to fix.
Elections taking place on tuesdays instead of weekends for some reason, low polling-places-per-voters ratio (though numbers are hard to find), ballots with multiple non-trivial questions, etc.
Before turning to voting machines, there's a lot that could be changed at every level. Moving Election Day to weekends would be a good start.
See, no need for fancy tech. Paid officials and unpaid volunteers manning everything.
How about if we could scale ballots to such an extent that a citizen can vote from wherever/whenever on all issues they're interested in[1], not just a head of state election every X years? Wouldn't that be a more democratic process ?
I believe it would, and that paper ballots won't get us there.
[1] A current instance of this is the Swiss voting system: https://en.wikipedia.org/wiki/Voting_in_Switzerland
And making people vote on issues they're interested in just makes me think only extremes will be heard and counted, and I would have to give my opinion on a bunch of things I don't really care about, or am not quite competent enough. To me, the democratic vote should be a precious rare thing, to elect a representative or a bunch of them, and trust them to do a non-too-shitty job of it.
Referendums, IMO are among the worst democratic moments in my republic, and I feel my concitoyens (from talking to some, and reading what they say in polls or public forums) don't really vote on the specific subject but on a global policy rant. It's a place to vent, not to decide ; when your elected ruler throws up his hands and gives you back the wheel at the last moment, with little context, FSD-style.
Indeed, the voting is less about getting people you want to have power, but more about preventing people you don't want from getting power (or retaining the power). Votes don't directly affect the actual policy decisions that representatives make afterwards, you're not legally bound to fulfill your campaign promises. What voting process does instead is telling the society, ‘See, the elected officials are not massively hated by the people, no need for a concern’.
The thing about representative democracy is that your representative is still your representative even if you didn't vote for them.
When the ballot process can be done in the morning with your coffee and toast, maybe more people would be inclined to apply judgement and vote in good faith.
And I think I speak a truism when I say that more deciding power for each citizen is a better kind of democracy than representative democracy. What I'm hearing from you are just hypotheticals that nobody can be sure of without actually trying a system like this. Basically that's all I'm saying, the current democratic process leaves a lot of citizens without proper representation and probably we need to move in a direction where that's not true any more. We need to look at alternative ballot systems which would allow that. If the current political strata are wrecked in the process, all the better.
So do ZKP based voting systems.
>voter verification
What do you mean by this? If you mean signatures you can have people sign their signature on their phone or desktop.
>I can actually show up and vote once every few years
This is a lot of friction which prevents many people from voting.
Assuming no vulnerabilities on the ZKP system, a perfect implementation and no information leak from other sources.
> What do you mean by this?
I assume that ensuring that the person voting is who they claim they are. If someone steals the certificates of that person, they could impersonate them.
> This is a lot of friction which prevents many people from voting.
In Spain (and I guess in a lot of other countries) voting in-person means walking to the closest polling center (99% of the time it's less than 10 minute walk) on a Sunday, picking up the paper, doing the queue (maybe another 10 minutes) and walking out. The alternative is mail-in voting, which usually takes a few minutes of walking to the closest post-office, signing some documents and waiting for the ballot to come. Compare that with getting the certificates, storing them securely, downloading the program to do the voting, installing it, praying it works, then using the program and cast the vote. Think of all the people who aren't good with computers, and how easy would it be for them to do all those steps correctly.
In the ideal case I agree that electronic voting systems would be better. But the world is not ideal, quite a lot of things can go wrong with them because of their complexity and detecting those issues will be difficult. On the other hand, paper voting is fairly simple, the number of things that can go wrong is low and easy to detect by anyone.
Only if you're an expert cryptographer, else you're deferring to the authority.
> Paper voting is extremely expensive to scale
That's a feature.
At least it’s still provable, a plenty of people can afford to hire their own cryptographers to do verification. Foreign observers can also do the same.
Electronic voting can be much better, but it is of course not a terribly easy problem to solve.
For what it’s worth, I don’t believe that paper voting is particularly problematic. But I do think that electronic voting could make voting easier and more accessible.
> But I do think that electronic voting could make voting easier and more accessible.
I don't think so. Think of all the people who have difficulty with basic computer/phone tasks, either because of knowledge or accessibility issues. Do you think all the steps to securely cast votes with an electronic system are going to be easier and more accessible for them?
I don’t think an in-person electronic voting system needs to be any more difficult than current paper ballots.
That's still deferring to the authority. The cryptographer I paid to says it’s all verified, these 1,000,000 people believe them, so naturally I must believe too because why would they lie – is that how it goes? Why not then just drop this whole voting thing, managing keys, checking proofs – why waste time on all this, just let cryptographers announce the results? You trust them, right? They're smart, they'll probably make good decisions.
Paper ballots which can be counted by hand reasonably efficiently enforce a low-tech process that is understood by literally everyone, is resistant to fraud at scale, and leaves massive amount of literal paper trail for audit with no extra provisions. If a citizen wants to be an observer – they just go and see ballots counted. If ZKP were used then what, why only qualified cryptographers are allowed to be qualified observers? Is this really a necessary requirement for a voting process?
That's a bug, not a feature. The point of not doing that with paper voting is that it makes selling your vote difficult, as nobody else can verify what you voted for. You on the other side know that you put the ballot in the box and can stay around to see if the votes in the box get accurately counted.
With electronic voting you lose that. You either have to blindly trust the system or by allowing vote verification make it easy for others to sell the votes.
It's a trade off. I want to be able to prove that my vote was counted. How can I trust that my voice was actually heard by the system?
>as nobody else can verify what you voted for.
You can mitigate this problem by giving people a way to fake any vote outcome. The voter knows how to verify their actual vote, but someone else would not be sure if what they verified was real or fake. Also I doubt this type of buying votes with verification is that big of an actual thing. You can trivially do it with paper voting to by just asking them to stream themself voting or by taking a picture of their ballot.
>You either have to blindly trust the system
Having someone else count votes without the ability for you yourself to count votes and check to see if your vote was included is the opposite of blindly trusting the system.
Most vote countings are public. I can go to my polling place, cast my vote, check that nobody tampers with the box, watch how they count every vote correctly, ensure that the written tallies are correct, and then verify that the central system tallies match with those I counted.
Also, you're assuming the system is perfectly implemented. In reality, such a system will be complex, will have many more pieces than the ZK system itself (and those pieces will have vulnerabilities), and will require users to do more which will also be prone to errors and vulnerabilities.
I don't understand the insistence on electronic voting for elections. It's less transparent to laypeople, offers small benefits and adds significant complexity both in the implementation and use.
It's not so much selling votes, as to discourage voter intimidation: The husband forces his wife, the boss forces his subordinates, the local mafia forces their victims to vote a particular way.
I don't know the rules in the USA, but in the UK it is generally forbidden to stream yourself voting or take a photo in the polling station. Maintaining the secrecy of ballots is high priority.
Someone might still privately take that picture of their ballot paper, after all there's a private voting booth; the officials wouldn't know. You're allowed to say you made a mistake and ask for a replacement ballot paper, so you could show your boss the version they want to see, and then vote differently.
Except we allow postal voting pretty much willy nilly, especailly in areas where intimidation can happen
Lack of postal votes makes the ballot less fair and representative, because it affects people with systematic bias in relevant sub-populations (wealth, working conditions, age, health, etc) and areas.
In areas where intimidation can happen... for going to the polling station. (All the intimidator has to do is post menacing guards, soldiers, etc. outside the station or on the routes to it. There are plenty of news reports of this happening in some countries. I'm not aware of this in the UK though.)
So the question is whether you get a more fair and representative vote outcome by allowing postal voting, or by disallowing it.
The balance of trade-offs has led to UK policy allowing postal votes, encouraging each individual to fill out and seal their vote in private, and use statistical and other investigation methods to look for signs of fraud, while maintaining a high standard of secret ballots when voting in person.
That might not be the balance that works best in other countries. In the UK it is said by the Electoral Commission that there is no evidence that postal voting has changed electoral outcomes to date, but some attempts at large scale fraud were discovered and prevented.
It's quite easy to see how a secret ballot can be not secret if the (typically patriarch) says "lets fill the forms out together and I'll take them all in"
So in Germany postal voting is secured against selling votes.
It's not about selling, which would be easy to detect like all large conspiracies. It's about subtle coercion that postal voting can enable.
Political machines exploiting nursing homes, pushing absentee ballots on the elderly, etc are already problematic, and allowing field GOTV teams to collect this type of data in mass is would make expanding these operations in size and scope.
You’d also create the new problem of hyper-partisan people crying about voter fraud. You’ll have a bunch of lunatics running around with fake ballot receipts to push whatever narrative they are trying to push.
In my state, it’s illegal to take pictures of ballots at the poll, and there are bipartisan poll inspectors that will shut that down if it happens.
I think you're wrong. A bug would be if you could tell how a vote was cast, not if it was counted.
Vote selling is a pretty nasty problem to work around.
The problem of unscrupulous operators can be circumvented if the votes are in a public ledger where the voter can backtrack their vote to the ledger "yes, its' my vote, nobody tempered with it", but the vote in the ledger can not be linked to the voter.
Existing voting systems do have a countermeasure, if not a fantastic one: creating a trail of physical artifacts that can be manually audited to verify vote totals, and a roll of accepted votes to compare the count of said physical artifacts against. It's not fantastic because the error rates on those physical artifacts are stupendous, but tampering with votes at scale can then require (a) physical access, which humans are well-equipped to reason about, and (b) generating and destroying big piles of said physical artifact, which is expensive and expensive to hide. The gold standard of tampering with physical elections that we know of is basically denying observers the chance to audit, which is rightly considered suspicious.
Tampering with electronic votes at scale does not have these cost properties. We can magnify costs without giving voters the ability to prove their votes to a third party (I am aware there are probabilistic constructions), but all such constructions (a) are much harder for the average voter to reason about than monitoring physical access (humans are quite optimized for monitoring physical access), yet (b) requires voters to actually audit their own votes and report non-inclusion en masse. You can see why this is a non-starter.
So the common person will probably not understand the cryptographic underlayers of this theoretical new system, they need to have confidence "in the science". I know that doesn't sound as good, but we're heading towards a world where computing literacy is increasing, so in some years that could be possible.
Which means somebody can hold a gun to your head and force you to prove that you voted and that your vote counted.
That is not, to put it mildly, desirable in an election.
More importantly (with both postal voting and in-person voting) it's impossible to perform these attacks after the fact, but if you have a receipt of your vote it can be done at any time after you vote.
This would risk exposing yourself, and in turn, the intimidator.
But if only one ballot is mailed per citizen, they can be reasonably sure you didn't vote for the competition.
> it's possible to check for yourself that your vote was actually counted and not ignored.
Let's say you voted for candidate A and didn't find your vote. How can you prove that you really voted for A?
> Everyone could get a notification on their phone when they are asked to vote on something as opposed to having to fill out paper and send it somewhere to be counted.
Voting with such system is equivalent to publishing results without any actual voting.
With ZKP it would look something as follows:
1. Encrypt a vote with a commonly known public key and publish it to the bulletin board.
2. Shuffle the votes and producing a ZKP proof of correctness assuring that only votes from bulletin board where shuffled, no vote were added, removed or modified.
3. Tally the votes and produce a proof of correct decryption.
The argument is that since authorities does not know the choice of the voter they would accept the vote to the authenticated and public bulletin board which would prevent vote omission.
Let's say bulletin board software replaces the vote with 20% probability. You post your vote for candidate A and see that it didn't appear on the board (because the board replaced it with vote for candidate B, but you don't know about it). How can you prove that you tried to vote for A and not for B? The records show that you have voted, and as voting is anonymous it is impossible to know how you voted.
Of course, there are other ways to meddle with such election. For example, you see that the turnout is 99%. How can you verify this number? The government refuses to publish a list of voters because GDPR doesn't allow that. And even if the country publishes this list how you can verify that the list doesn't contain fictious voters?
It's best to illustrate it with the ElGamal cryptosystem. Let's say that system officials have set up keypair `sk`, `pk = g^sk` and let everyone know `g, pk`. To submit a vote, the voter selects an option corresponding to a message `m` and encrypts it with a freely chosen randomization factor `r` and obtains a tuple `(g^r, m*pk^r)`. He signs this encryption under their name and sends it to the bulletin board.
The last bit is whether to allow everyone to see that you have or have not voted so whether the fact that you have participated in the elections. There seems to be the consensus in the literature that the signature should be concealed from the public and be allowed to verify only for independent auditors.
> Let's say bulletin board software replaces the vote with 20% probability. You post your vote for candidate A and see that it didn't appear on the board (because the board replaced it with vote for candidate B, but you don't know about it). How can you prove that you tried to vote for A and not for B? The records show that you have voted, and as voting is anonymous it is impossible to know how you voted.
One way to preserve the integrity of the bulletin board is that upon receiving a `vote <- ((g^r, m*pk^r), sig)`, the bulletin board issues a signature on the `vote` and returns it to the voter for the latter to assert for the vote to not be changed. Even when the signature is not present on the bulletin board, the voter can check the presence of `(g^r, m*pk^r)` as the randomization factor makes it unique for each voter.
> Of course, there are other ways to meddle with such election. For example, you see that the turnout is 99%. How can you verify this number? The government refuses to publish a list of voters because GDPR doesn't allow that. And even if the country publishes this list how you can verify that the list doesn't contain fictious voters?
The fictitious voters are indeed a thing if we can't trust the independent auditors of the bulletin board. Personally, I would never support an internet voting system where the result of the elections would lay on the integrity of a few trusted auditors who have special access to do so. Thus I would greatly prefer for the voter lists (the signatures) to be public in spite of losing participation anonymity.
And thus is impossible to hack at scale.
It costs $x to run an election and count the votes for Y thousand peple voting for a position, that scales pretty much linearly - have 1 ballot and 1,000 votes costing say $100, have 1 ballot and 1 million votes and it costs no more than $100,000
I think numerous cases of electoral fraud over the course of global history prove this statement wrong.
The systems we have for voting in Washington DC seem to be a best-of-both-worlds approach. There are touchscreen kiosks that you use to make your choices, then the kiosk prints out a properly marked paper ballot that it asks you to verify. Then you take your ballot over to the normal scanning machines. You can also request an unmarked ballot and fill it by hand if you prefer.
The kiosks can provide a wide range of assistive tech (larger fonts, instructions in a variety of languages, and headphone jack for audio prompts). They also help ensure you do not miss a question - you must explicitly choose "skip" - and they help ensure you select between 0 and N choices in choose-N questions. Also they print a clearly-marked ballot which helps avoid ambiguities like if somebody partially fills a circle by hand.
And best of all, the end product is still a physical, auditable piece of paper.
The US should go back to hand-counted pen and paper voting.
That said, we in the Zcash community have usually used another system when holding secret-ballot votes within our community: Helios.
This isn’t a rocket science problem. Best bet is to set mandatory requirements that machines must meet to get federal funding, let companies compete.
Security people tend to hand wave about election tally machines because it gets eyeballs. The reality is they work mostly fine, and the risks associated with them are usually more about process than nerd stuff.
With that in mind, it's not clear that just because Debian embraces some of the trappings of democracy, it should also insist on the secrecy of the ballot. Non-secret ballots have their advantages too - even your cited "free democratic countries" use them at the parliamentary level.
What would you think about the ones that did?
Representatives toeing party lines is seen as an impoverishment to democracy.
Excess transparency means representatives will pander only for votes/money/attention, it's for example why every televised American congressional session makes you lose braincells. Because they're only talking to the TV, they're not actually deliberating.
Important to whom, other than themselves in the next election?
That's how democracy works. Pandering for votes and then acting on behalf of your voters interests is kind of the point.
Im honestly kind of shocked to be reading this on HN in 2022. This is the kind of thing monarchists said in 1684.
>money
Legislative secrecy is a great way of letting money corrupt democracy since it eliminates the feedback loop between the legislator acting on behalf of monied interests and being democratically punished for it at the next election.
(Full disclosure: In spite of what I wrote above, I did vote NOTA above all other options. I am not confident that I'm ready to change the status quo.)
I would argue a software project and a nation state is not the same kind of organisation.
I am not involved in debian, so I would not judge what is the best system for them, but for example a group of friends making a decision on where to party, make sports, vacation, etc. - would secret voting here make sense? I don't think so. When people are not afraid to speak their mind - then a real consensus can be faster found. So I do not really think "secret voting" must be a standard. It depends on the organisation (and the size, people involved, etc).
> but for example a group of friends making a decision on where to party, make
> sports, vacation, etc. - would secret voting here make sense?
"Hey Bob, if you vote for having the party at Dave's house, I'll not suggest to Mary that the cigarettes were anything but tobacco, whaddayasay?"But they can still be my wife's friend's husband, and that's how I am going to treat them.
Sounds impractical.
You are swapping cause and effect and are implying that making voting secret creates fear. This is plain wrong.
Or do you practice secret voting in decision making among your friends?
I didn't.
> Or do you practice secret voting in decision making among your friends?
Now you are making a strawman. But I'll answer anyways. If I had a simple way to do anonymous polls with friends (e.g. an app) I would certainly use it because it would be a fun experiment.
But this is besides the point. Social pressure exists amongst coworkers, volunteers, friends, families and even couples. A lot of it.
That's why secret voting is useful in many environments even where people trust each other.
So can you explain then, where I implyed "that making voting secret creates fear"?
By stating, that there is no need for secret voting, when people are not afraid?
If so, you might want to study basic logic (again). You cannot just reverse statements and implications and jump to conclusions
There can be secret voting, with people scared to speak their minds and secret voting with people not afraid to speak their minds.
And there can be open voting with people scared to speak their minds and open voting with people not afraid to speak their mind.
I think secret voting is only useful, for situations with fear involved. No more, no less.
I mean, I think it's OK that only DDs get to vote; but the Debian Project is supposed to be transparent, so I'd like to be able to find out how people voted.
Many DDs (most?) also work on other Linuxen, and are not particularly committed to "The Debian Way". My guess is that most Debian users use mainly Debian.
If users had had some representation in the systemd decision, I think it would have gone the other way. Package developers naturally don't want to have to target two init systems; I suspect a plurality of users are server admins, who would have been likely to vote down systemd.
It's hard to see how user representation could be made to work though; I don't want users to be able to tell DDs how to work. I just wish users had a bit more than zero voice.
I'm very, very confident that that would be a bad idea. I, for one, would retire as a DD if (non-DD) users were given a vote. Listening to user input can of course be really great, but as soon as I have to follow rules made by outsiders, it starts feeling way too much like work and too little like fun. I maintain mostly very unimportant packages, so what I'd do isn't that big of a deal, but I suspect this attitude would be echoed in many other DDs.
> Many DDs (most?) also work on other Linuxen, and are not particularly committed to "The Debian Way".
Really? I doubt that. Apart from some overlap with Ubuntu (which is a Debian derivative anyway), I would definitely guess that it's not that many. But this is just as anecdotal as your statement, of course. I rarely see people say "in [insert distro], we usually do it like this" or the like on the mailing lists.
> If users had had some representation in the systemd decision, I think it would have gone the other way. Package developers naturally don't want to have to target two init systems; I suspect a plurality of users are server admins, who would have been likely to vote down systemd.
I refuse to get into a discussion about what "a plurality of users" might think about systemd, but you illustrate my first point really well: once we have to start doing things we ourselves don't want to do, by order of some outsider, it's no longer fun. It's work. I expect to be paid for work. And I expect outsiders to stay out of my fun.
Seems like you answered your own question right there. A faction inside the project want to intimidate and punish people who don't conform to group think and a larger faction wants to squash that possibility.
I wonder what the pros/cons would be for parliamentary votes being SECRET in a democracy...
Secret ballots in parliament would help mitigate the effects of bribery because there would be no way to confirm a quid pro quo.
The politicians in a parliament should vote publicly, so they can be held accountable for their voting behavior. The people want to check if the politicians they elected actually vote for the things they promised in parliament.
(In the case of Debian: I have no idea if this situation is more like an election or voting in parliament, and I have no opinion on the topic.)
Because the voting developers are part of "governance". They are like senators. Nobody allows secret votes in government. When senators vote, their votes are public for many reasons.
There was a debian poll that people were afraid to vote in because they expected harassment for their position[1]. That poll raised the question of secret voting.
In my mind, the best option for Debian going forward would be to have public voting records, but have each future poll include a single option at the bottom for "Redo this poll as anonymous".
If more than (for example) 10% of the votes are for redoing the poll as anonymous, then redo it as anonymous.
They way they are doing it now makes it an all or nothing way for every issue that will be voted on in the future. My simplistic proposal above allows polls to be anonymous based on whether a minority feel that they will be harassed by a majority.
[1] Whether or not their expectation was realistic or not is irrelevant.
https://www.google.com/amp/s/amp.theguardian.com/world/2013/...
I'd be shocked if they didnt also have their claws into debian's operations for similar reasons.
I'd not be very surprised if they were indirectly behind this push either. The fact that this seems to be inspired by the people backing the very obvious hatchet job done on Richard Stallman only makes me more suspicious that its motives are anything but pure.
The biggest threat model here is probably the NSA using its assets to sway votes (probably unknowingly for most if not all, if they are influenced by a third party they dont know is fronting the NSA). Secrecy will make it that much easier to corrupt votes.
Tolerating a bit of personal abuse and cracking down on it separately is probably preferable to the existential threat to free software this presents.
You try to twist something that's quite horrible, namely voter corruption through public opinion as if it is somehow "disinfecting" anything. The mob mentality of the internet is best kept away from any voting base.
It is not "disgusting" that we be allowed to question their decisions.
Every introduction of democracy or futherance of democracy has been castigated by autocrats as rule by mob.
The sickening irony here is that it looks like this was done to try and protect the identities of members of the mob who tried and failed to cancel Stallman.
Since when do Debian developers owe the public anything?
They don't represent you, they don't owe you anything and you are absolutely not in a position to demand anything from them.
If you're not happy with how the project is run, you're free to use something else. If you want developers to be accountable to you, you can hire them and make them sign a contract.
> We will be guided by the needs of our users and the free software community.
> We will place their interests first in our priorities.
Another one of their stated values is:
> We will not hide problems
They're only "on your behalf" if you had a part in picking them. Did you vote for or nominate them? If not, no they are not working on your behalf and you have no right to see how they vote.
Original (non-Google AMP) URL: https://www.theguardian.com/world/2013/sep/05/nsa-gchq-encry...
It’s hard to believe that it’s more than eight years since the Snowden revelations. Tempus fugit.
From the outside looking in, it looks like another obvious SJW coup.
Note that that still points to the dummy tally (a tally that lists who voted, but not what they voted for), but the project secretary usually publishes the real thing within a few days of vote ending.
Seems like there should be few things the developers cannot do openly, but can do secretly if 'empowered', and there perhaps ought to be a public record and transparency around any incidence or accusations of vote-bullying or vote-buying.
[1] https://en.wikipedia.org/wiki/Debian_Social_Contract
[2] https://www.debian.org/doc/manuals/developers-reference/deve...
Look at systemd, if you voted against having only one init system back in the day, you would be subject to backlash or it could be understood as support for the Devuan forkers.
1. Should we have a vote to amend yes no higher threshold to pass.
2. If yes should we hide identities of developers casting a vote yes no
3. If yes should we allow verification yes no
Arguably 3 is a ridiculous question so ought to be safely omitted.
Arguably it would be reasonable to require more than 10% to cast a vote as well.
All we know now is that a single digit percentage of Debian developers prefer to vote anon.
Given the low turnout there is little reason not to respect the present result but have another smarter vote.
Not that there’s anything wrong with an organization holding forth on “issues of the day,” per se. But there is an iron law, effective ever since GamerGate-style tactics of “collecting receipts” and cross-platform and offline hounding became normalized as righteous retribution rather than harassment and bullying: your organization can have at most two of (1) transparency, (2) candor; (3) broader social relevance.
This at least let's those people know they are in the minority without people feeling like they might get blacklash.