Anyone associated with the Debian project have any insight on why voting is not secret and/or any other large os projects doing the same that could chime in?
Anyone associated with the Debian project have any insight on why voting is not secret and/or any other large os projects doing the same that could chime in?
- centralization (there must be a central, corruptible place where the voters are authenticated or the votes are counted)
- software is untrustable: https://www.win.tue.nl/%7Eaeb/linux/hh/thompson/trust.html
The USA has had a Diebold voting scandal. Other countries are using a paper-based voting process which can be supervised by third parties.
https://en.wikipedia.org/wiki/Premier_Election_Solutions#Sec...
Relevant watching: Tom Scott: Why Electronic Voting Is Still A Bad Idea
https://www.youtube.com/watch?v=LkH2r-sNjQs
One possible solution could be ZCash ( https://eprint.iacr.org/2017/585.pdf ) but it has had its own problems ( https://www.coindesk.com/zcash-team-reveals-it-fixed-a-catas... ).
Paper voting is extremely expensive to scale compared to a website that lets you vote. Everyone could get a notification on their phone when they are asked to vote on something as opposed to having to fill out paper and send it somewhere to be counted.
I don't understand the argument of reducing cost of elections and scaling. The current paper system in place in most works (at least in European countries where I've witnessed the process) and doesn't need to scale more. If actors in a democracy can't afford such a system, and the occasional (once, twice a year) walk to the voting place, 15 minutes wait and fellow-citizen interaction, can't we accept they don't care for voting and participating and stop listening?
I'm all for accommodation of special cases (people with reduced mobility or unability to be in contact with other people) but we already have the necessary systems in place (mail-in or vote delegation).
Literally one of the last places I'd check for change or optimization. It works, leave it alone, I'll happily pay the 3 or 10eur a year.
That doesn't have to be the case though, that's a political decision to staff voting booths like that. It's also trivial to fix.
Elections taking place on tuesdays instead of weekends for some reason, low polling-places-per-voters ratio (though numbers are hard to find), ballots with multiple non-trivial questions, etc.
Before turning to voting machines, there's a lot that could be changed at every level. Moving Election Day to weekends would be a good start.
See, no need for fancy tech. Paid officials and unpaid volunteers manning everything.
How about if we could scale ballots to such an extent that a citizen can vote from wherever/whenever on all issues they're interested in[1], not just a head of state election every X years? Wouldn't that be a more democratic process ?
I believe it would, and that paper ballots won't get us there.
[1] A current instance of this is the Swiss voting system: https://en.wikipedia.org/wiki/Voting_in_Switzerland
And making people vote on issues they're interested in just makes me think only extremes will be heard and counted, and I would have to give my opinion on a bunch of things I don't really care about, or am not quite competent enough. To me, the democratic vote should be a precious rare thing, to elect a representative or a bunch of them, and trust them to do a non-too-shitty job of it.
Referendums, IMO are among the worst democratic moments in my republic, and I feel my concitoyens (from talking to some, and reading what they say in polls or public forums) don't really vote on the specific subject but on a global policy rant. It's a place to vent, not to decide ; when your elected ruler throws up his hands and gives you back the wheel at the last moment, with little context, FSD-style.
Indeed, the voting is less about getting people you want to have power, but more about preventing people you don't want from getting power (or retaining the power). Votes don't directly affect the actual policy decisions that representatives make afterwards, you're not legally bound to fulfill your campaign promises. What voting process does instead is telling the society, ‘See, the elected officials are not massively hated by the people, no need for a concern’.
The thing about representative democracy is that your representative is still your representative even if you didn't vote for them.
When the ballot process can be done in the morning with your coffee and toast, maybe more people would be inclined to apply judgement and vote in good faith.
And I think I speak a truism when I say that more deciding power for each citizen is a better kind of democracy than representative democracy. What I'm hearing from you are just hypotheticals that nobody can be sure of without actually trying a system like this. Basically that's all I'm saying, the current democratic process leaves a lot of citizens without proper representation and probably we need to move in a direction where that's not true any more. We need to look at alternative ballot systems which would allow that. If the current political strata are wrecked in the process, all the better.
So do ZKP based voting systems.
>voter verification
What do you mean by this? If you mean signatures you can have people sign their signature on their phone or desktop.
>I can actually show up and vote once every few years
This is a lot of friction which prevents many people from voting.
Assuming no vulnerabilities on the ZKP system, a perfect implementation and no information leak from other sources.
> What do you mean by this?
I assume that ensuring that the person voting is who they claim they are. If someone steals the certificates of that person, they could impersonate them.
> This is a lot of friction which prevents many people from voting.
In Spain (and I guess in a lot of other countries) voting in-person means walking to the closest polling center (99% of the time it's less than 10 minute walk) on a Sunday, picking up the paper, doing the queue (maybe another 10 minutes) and walking out. The alternative is mail-in voting, which usually takes a few minutes of walking to the closest post-office, signing some documents and waiting for the ballot to come. Compare that with getting the certificates, storing them securely, downloading the program to do the voting, installing it, praying it works, then using the program and cast the vote. Think of all the people who aren't good with computers, and how easy would it be for them to do all those steps correctly.
In the ideal case I agree that electronic voting systems would be better. But the world is not ideal, quite a lot of things can go wrong with them because of their complexity and detecting those issues will be difficult. On the other hand, paper voting is fairly simple, the number of things that can go wrong is low and easy to detect by anyone.
Only if you're an expert cryptographer, else you're deferring to the authority.
> Paper voting is extremely expensive to scale
That's a feature.
At least it’s still provable, a plenty of people can afford to hire their own cryptographers to do verification. Foreign observers can also do the same.
Electronic voting can be much better, but it is of course not a terribly easy problem to solve.
For what it’s worth, I don’t believe that paper voting is particularly problematic. But I do think that electronic voting could make voting easier and more accessible.
> But I do think that electronic voting could make voting easier and more accessible.
I don't think so. Think of all the people who have difficulty with basic computer/phone tasks, either because of knowledge or accessibility issues. Do you think all the steps to securely cast votes with an electronic system are going to be easier and more accessible for them?
I don’t think an in-person electronic voting system needs to be any more difficult than current paper ballots.
That's still deferring to the authority. The cryptographer I paid to says it’s all verified, these 1,000,000 people believe them, so naturally I must believe too because why would they lie – is that how it goes? Why not then just drop this whole voting thing, managing keys, checking proofs – why waste time on all this, just let cryptographers announce the results? You trust them, right? They're smart, they'll probably make good decisions.
Paper ballots which can be counted by hand reasonably efficiently enforce a low-tech process that is understood by literally everyone, is resistant to fraud at scale, and leaves massive amount of literal paper trail for audit with no extra provisions. If a citizen wants to be an observer – they just go and see ballots counted. If ZKP were used then what, why only qualified cryptographers are allowed to be qualified observers? Is this really a necessary requirement for a voting process?
That's a bug, not a feature. The point of not doing that with paper voting is that it makes selling your vote difficult, as nobody else can verify what you voted for. You on the other side know that you put the ballot in the box and can stay around to see if the votes in the box get accurately counted.
With electronic voting you lose that. You either have to blindly trust the system or by allowing vote verification make it easy for others to sell the votes.
It's a trade off. I want to be able to prove that my vote was counted. How can I trust that my voice was actually heard by the system?
>as nobody else can verify what you voted for.
You can mitigate this problem by giving people a way to fake any vote outcome. The voter knows how to verify their actual vote, but someone else would not be sure if what they verified was real or fake. Also I doubt this type of buying votes with verification is that big of an actual thing. You can trivially do it with paper voting to by just asking them to stream themself voting or by taking a picture of their ballot.
>You either have to blindly trust the system
Having someone else count votes without the ability for you yourself to count votes and check to see if your vote was included is the opposite of blindly trusting the system.
Most vote countings are public. I can go to my polling place, cast my vote, check that nobody tampers with the box, watch how they count every vote correctly, ensure that the written tallies are correct, and then verify that the central system tallies match with those I counted.
Also, you're assuming the system is perfectly implemented. In reality, such a system will be complex, will have many more pieces than the ZK system itself (and those pieces will have vulnerabilities), and will require users to do more which will also be prone to errors and vulnerabilities.
I don't understand the insistence on electronic voting for elections. It's less transparent to laypeople, offers small benefits and adds significant complexity both in the implementation and use.
It's not so much selling votes, as to discourage voter intimidation: The husband forces his wife, the boss forces his subordinates, the local mafia forces their victims to vote a particular way.
I don't know the rules in the USA, but in the UK it is generally forbidden to stream yourself voting or take a photo in the polling station. Maintaining the secrecy of ballots is high priority.
Someone might still privately take that picture of their ballot paper, after all there's a private voting booth; the officials wouldn't know. You're allowed to say you made a mistake and ask for a replacement ballot paper, so you could show your boss the version they want to see, and then vote differently.
Except we allow postal voting pretty much willy nilly, especailly in areas where intimidation can happen
Lack of postal votes makes the ballot less fair and representative, because it affects people with systematic bias in relevant sub-populations (wealth, working conditions, age, health, etc) and areas.
In areas where intimidation can happen... for going to the polling station. (All the intimidator has to do is post menacing guards, soldiers, etc. outside the station or on the routes to it. There are plenty of news reports of this happening in some countries. I'm not aware of this in the UK though.)
So the question is whether you get a more fair and representative vote outcome by allowing postal voting, or by disallowing it.
The balance of trade-offs has led to UK policy allowing postal votes, encouraging each individual to fill out and seal their vote in private, and use statistical and other investigation methods to look for signs of fraud, while maintaining a high standard of secret ballots when voting in person.
That might not be the balance that works best in other countries. In the UK it is said by the Electoral Commission that there is no evidence that postal voting has changed electoral outcomes to date, but some attempts at large scale fraud were discovered and prevented.
It's quite easy to see how a secret ballot can be not secret if the (typically patriarch) says "lets fill the forms out together and I'll take them all in"
So in Germany postal voting is secured against selling votes.
It's not about selling, which would be easy to detect like all large conspiracies. It's about subtle coercion that postal voting can enable.
Political machines exploiting nursing homes, pushing absentee ballots on the elderly, etc are already problematic, and allowing field GOTV teams to collect this type of data in mass is would make expanding these operations in size and scope.
You’d also create the new problem of hyper-partisan people crying about voter fraud. You’ll have a bunch of lunatics running around with fake ballot receipts to push whatever narrative they are trying to push.
In my state, it’s illegal to take pictures of ballots at the poll, and there are bipartisan poll inspectors that will shut that down if it happens.
I think you're wrong. A bug would be if you could tell how a vote was cast, not if it was counted.
Vote selling is a pretty nasty problem to work around.
The problem of unscrupulous operators can be circumvented if the votes are in a public ledger where the voter can backtrack their vote to the ledger "yes, its' my vote, nobody tempered with it", but the vote in the ledger can not be linked to the voter.
Existing voting systems do have a countermeasure, if not a fantastic one: creating a trail of physical artifacts that can be manually audited to verify vote totals, and a roll of accepted votes to compare the count of said physical artifacts against. It's not fantastic because the error rates on those physical artifacts are stupendous, but tampering with votes at scale can then require (a) physical access, which humans are well-equipped to reason about, and (b) generating and destroying big piles of said physical artifact, which is expensive and expensive to hide. The gold standard of tampering with physical elections that we know of is basically denying observers the chance to audit, which is rightly considered suspicious.
Tampering with electronic votes at scale does not have these cost properties. We can magnify costs without giving voters the ability to prove their votes to a third party (I am aware there are probabilistic constructions), but all such constructions (a) are much harder for the average voter to reason about than monitoring physical access (humans are quite optimized for monitoring physical access), yet (b) requires voters to actually audit their own votes and report non-inclusion en masse. You can see why this is a non-starter.
So the common person will probably not understand the cryptographic underlayers of this theoretical new system, they need to have confidence "in the science". I know that doesn't sound as good, but we're heading towards a world where computing literacy is increasing, so in some years that could be possible.
Which means somebody can hold a gun to your head and force you to prove that you voted and that your vote counted.
That is not, to put it mildly, desirable in an election.
More importantly (with both postal voting and in-person voting) it's impossible to perform these attacks after the fact, but if you have a receipt of your vote it can be done at any time after you vote.
This would risk exposing yourself, and in turn, the intimidator.
But if only one ballot is mailed per citizen, they can be reasonably sure you didn't vote for the competition.
> it's possible to check for yourself that your vote was actually counted and not ignored.
Let's say you voted for candidate A and didn't find your vote. How can you prove that you really voted for A?
> Everyone could get a notification on their phone when they are asked to vote on something as opposed to having to fill out paper and send it somewhere to be counted.
Voting with such system is equivalent to publishing results without any actual voting.
With ZKP it would look something as follows:
1. Encrypt a vote with a commonly known public key and publish it to the bulletin board.
2. Shuffle the votes and producing a ZKP proof of correctness assuring that only votes from bulletin board where shuffled, no vote were added, removed or modified.
3. Tally the votes and produce a proof of correct decryption.
The argument is that since authorities does not know the choice of the voter they would accept the vote to the authenticated and public bulletin board which would prevent vote omission.
Let's say bulletin board software replaces the vote with 20% probability. You post your vote for candidate A and see that it didn't appear on the board (because the board replaced it with vote for candidate B, but you don't know about it). How can you prove that you tried to vote for A and not for B? The records show that you have voted, and as voting is anonymous it is impossible to know how you voted.
Of course, there are other ways to meddle with such election. For example, you see that the turnout is 99%. How can you verify this number? The government refuses to publish a list of voters because GDPR doesn't allow that. And even if the country publishes this list how you can verify that the list doesn't contain fictious voters?
It's best to illustrate it with the ElGamal cryptosystem. Let's say that system officials have set up keypair `sk`, `pk = g^sk` and let everyone know `g, pk`. To submit a vote, the voter selects an option corresponding to a message `m` and encrypts it with a freely chosen randomization factor `r` and obtains a tuple `(g^r, m*pk^r)`. He signs this encryption under their name and sends it to the bulletin board.
The last bit is whether to allow everyone to see that you have or have not voted so whether the fact that you have participated in the elections. There seems to be the consensus in the literature that the signature should be concealed from the public and be allowed to verify only for independent auditors.
> Let's say bulletin board software replaces the vote with 20% probability. You post your vote for candidate A and see that it didn't appear on the board (because the board replaced it with vote for candidate B, but you don't know about it). How can you prove that you tried to vote for A and not for B? The records show that you have voted, and as voting is anonymous it is impossible to know how you voted.
One way to preserve the integrity of the bulletin board is that upon receiving a `vote <- ((g^r, m*pk^r), sig)`, the bulletin board issues a signature on the `vote` and returns it to the voter for the latter to assert for the vote to not be changed. Even when the signature is not present on the bulletin board, the voter can check the presence of `(g^r, m*pk^r)` as the randomization factor makes it unique for each voter.
> Of course, there are other ways to meddle with such election. For example, you see that the turnout is 99%. How can you verify this number? The government refuses to publish a list of voters because GDPR doesn't allow that. And even if the country publishes this list how you can verify that the list doesn't contain fictious voters?
The fictitious voters are indeed a thing if we can't trust the independent auditors of the bulletin board. Personally, I would never support an internet voting system where the result of the elections would lay on the integrity of a few trusted auditors who have special access to do so. Thus I would greatly prefer for the voter lists (the signatures) to be public in spite of losing participation anonymity.
And thus is impossible to hack at scale.
It costs $x to run an election and count the votes for Y thousand peple voting for a position, that scales pretty much linearly - have 1 ballot and 1,000 votes costing say $100, have 1 ballot and 1 million votes and it costs no more than $100,000
I think numerous cases of electoral fraud over the course of global history prove this statement wrong.
The systems we have for voting in Washington DC seem to be a best-of-both-worlds approach. There are touchscreen kiosks that you use to make your choices, then the kiosk prints out a properly marked paper ballot that it asks you to verify. Then you take your ballot over to the normal scanning machines. You can also request an unmarked ballot and fill it by hand if you prefer.
The kiosks can provide a wide range of assistive tech (larger fonts, instructions in a variety of languages, and headphone jack for audio prompts). They also help ensure you do not miss a question - you must explicitly choose "skip" - and they help ensure you select between 0 and N choices in choose-N questions. Also they print a clearly-marked ballot which helps avoid ambiguities like if somebody partially fills a circle by hand.
And best of all, the end product is still a physical, auditable piece of paper.
The US should go back to hand-counted pen and paper voting.
That said, we in the Zcash community have usually used another system when holding secret-ballot votes within our community: Helios.
This isn’t a rocket science problem. Best bet is to set mandatory requirements that machines must meet to get federal funding, let companies compete.
Security people tend to hand wave about election tally machines because it gets eyeballs. The reality is they work mostly fine, and the risks associated with them are usually more about process than nerd stuff.
I mean, I think it's OK that only DDs get to vote; but the Debian Project is supposed to be transparent, so I'd like to be able to find out how people voted.
Many DDs (most?) also work on other Linuxen, and are not particularly committed to "The Debian Way". My guess is that most Debian users use mainly Debian.
If users had had some representation in the systemd decision, I think it would have gone the other way. Package developers naturally don't want to have to target two init systems; I suspect a plurality of users are server admins, who would have been likely to vote down systemd.
It's hard to see how user representation could be made to work though; I don't want users to be able to tell DDs how to work. I just wish users had a bit more than zero voice.
I'm very, very confident that that would be a bad idea. I, for one, would retire as a DD if (non-DD) users were given a vote. Listening to user input can of course be really great, but as soon as I have to follow rules made by outsiders, it starts feeling way too much like work and too little like fun. I maintain mostly very unimportant packages, so what I'd do isn't that big of a deal, but I suspect this attitude would be echoed in many other DDs.
> Many DDs (most?) also work on other Linuxen, and are not particularly committed to "The Debian Way".
Really? I doubt that. Apart from some overlap with Ubuntu (which is a Debian derivative anyway), I would definitely guess that it's not that many. But this is just as anecdotal as your statement, of course. I rarely see people say "in [insert distro], we usually do it like this" or the like on the mailing lists.
> If users had had some representation in the systemd decision, I think it would have gone the other way. Package developers naturally don't want to have to target two init systems; I suspect a plurality of users are server admins, who would have been likely to vote down systemd.
I refuse to get into a discussion about what "a plurality of users" might think about systemd, but you illustrate my first point really well: once we have to start doing things we ourselves don't want to do, by order of some outsider, it's no longer fun. It's work. I expect to be paid for work. And I expect outsiders to stay out of my fun.
Reasons against secret voting were expressed in ballot option C:
The politicians in a parliament should vote publicly, so they can be held accountable for their voting behavior. The people want to check if the politicians they elected actually vote for the things they promised in parliament.
(In the case of Debian: I have no idea if this situation is more like an election or voting in parliament, and I have no opinion on the topic.)
What would you think about the ones that did?
Representatives toeing party lines is seen as an impoverishment to democracy.
Excess transparency means representatives will pander only for votes/money/attention, it's for example why every televised American congressional session makes you lose braincells. Because they're only talking to the TV, they're not actually deliberating.
Important to whom, other than themselves in the next election?
That's how democracy works. Pandering for votes and then acting on behalf of your voters interests is kind of the point.
Im honestly kind of shocked to be reading this on HN in 2022. This is the kind of thing monarchists said in 1684.
>money
Legislative secrecy is a great way of letting money corrupt democracy since it eliminates the feedback loop between the legislator acting on behalf of monied interests and being democratically punished for it at the next election.
(Full disclosure: In spite of what I wrote above, I did vote NOTA above all other options. I am not confident that I'm ready to change the status quo.)
Seems like you answered your own question right there. A faction inside the project want to intimidate and punish people who don't conform to group think and a larger faction wants to squash that possibility.
I would argue a software project and a nation state is not the same kind of organisation.
I am not involved in debian, so I would not judge what is the best system for them, but for example a group of friends making a decision on where to party, make sports, vacation, etc. - would secret voting here make sense? I don't think so. When people are not afraid to speak their mind - then a real consensus can be faster found. So I do not really think "secret voting" must be a standard. It depends on the organisation (and the size, people involved, etc).
> but for example a group of friends making a decision on where to party, make
> sports, vacation, etc. - would secret voting here make sense?
"Hey Bob, if you vote for having the party at Dave's house, I'll not suggest to Mary that the cigarettes were anything but tobacco, whaddayasay?"But they can still be my wife's friend's husband, and that's how I am going to treat them.
Sounds impractical.
You are swapping cause and effect and are implying that making voting secret creates fear. This is plain wrong.
Or do you practice secret voting in decision making among your friends?
I didn't.
> Or do you practice secret voting in decision making among your friends?
Now you are making a strawman. But I'll answer anyways. If I had a simple way to do anonymous polls with friends (e.g. an app) I would certainly use it because it would be a fun experiment.
But this is besides the point. Social pressure exists amongst coworkers, volunteers, friends, families and even couples. A lot of it.
That's why secret voting is useful in many environments even where people trust each other.
So can you explain then, where I implyed "that making voting secret creates fear"?
By stating, that there is no need for secret voting, when people are not afraid?
If so, you might want to study basic logic (again). You cannot just reverse statements and implications and jump to conclusions
There can be secret voting, with people scared to speak their minds and secret voting with people not afraid to speak their minds.
And there can be open voting with people scared to speak their minds and open voting with people not afraid to speak their mind.
I think secret voting is only useful, for situations with fear involved. No more, no less.
With that in mind, it's not clear that just because Debian embraces some of the trappings of democracy, it should also insist on the secrecy of the ballot. Non-secret ballots have their advantages too - even your cited "free democratic countries" use them at the parliamentary level.
There was a debian poll that people were afraid to vote in because they expected harassment for their position[1]. That poll raised the question of secret voting.
In my mind, the best option for Debian going forward would be to have public voting records, but have each future poll include a single option at the bottom for "Redo this poll as anonymous".
If more than (for example) 10% of the votes are for redoing the poll as anonymous, then redo it as anonymous.
They way they are doing it now makes it an all or nothing way for every issue that will be voted on in the future. My simplistic proposal above allows polls to be anonymous based on whether a minority feel that they will be harassed by a majority.
[1] Whether or not their expectation was realistic or not is irrelevant.
Because the voting developers are part of "governance". They are like senators. Nobody allows secret votes in government. When senators vote, their votes are public for many reasons.
I wonder what the pros/cons would be for parliamentary votes being SECRET in a democracy...
Secret ballots in parliament would help mitigate the effects of bribery because there would be no way to confirm a quid pro quo.