It would be too burdensome with pencil and paper. Alternatives are useful.
Discussion, debades and more generally exchanging opinions with others and pondering the options before committing to a decision are important if not essential for proper functioning of democracy. This necessarily takes time. How would real-time voting make things more democratic? I see no advantage in making the process hasty. If anything, it would trivialize the process, like voting for a game show on television, which would definitely be bad.
There are methods for preventing all the issues Tom Scott raises.
In college I worked in a research lab building accessible voting systems. We regularly ran test elections with the deaf and blind community. Its both amazing to see how adapted a person can become to living in a world that assumes a certain level of physical ability. Its also amazing to see how horribly inaccessible most voting systems are.
With paper ballots, for example, you are usually limited to sitting in a booth with a poll worker and telling them how to fill in your ballot. That does technically work, but breaks voter privacy and you have no way of knowing if they filled it in right because, well, you can't see the ballot.
Already a solved problem, e.g.:
> On election day and at advance polls, your polling station will have tactile and braille voting templates that you can use to mark your ballot. Simply fit your ballot into the template and use the braille and embossed numbers to find the space next to your chosen candidate's name.
* https://www.elections.ca/content.aspx?section=vot&dir=spe/to...
Another part of our goal was to build a voting system that was accessible by default, meaning everyone was able to use the same device regardless of any disabilities they may have.
The problem is that when you can verify that your own vote has been counted a certain way, that can be used to influence the vote. $100 Amazon gift card if you verify that you have voted Purple. Lack of verifiability has been a feature to prevent a voter from willingly participating in manipulation.
I can think of a method that allows a voter to decrypt the ballot payload only coupled with one or more keys from the parties that organized it. Ie, if I as an individual want to see the vote, I can't. But if I suspect my vote has been tampered with I can ask the organizers to audit it, and with both our keys, I can see the payload. (This is just back of the napkin theorizing, it might have other issues)
Ie, if a malicious entity wants to make sure that the votes they have bought are corresponding with what they asked, they need to go through a more difficult process than just asking the people they bought from to reveal their vote.
Because of potential malware on the client's device that can manipulate a vote before it is cast.
Sure you can generate all these secret codes but then why wouldn't a briber ask for you to take a picture or video of the screen with all the codes and secret? OCR and computer vision is quite good nowadays and most people are carrying a video camera in their pocket, so the process can potentially be scaled. Bonus points if its install the Purple App and ask the voter to point their camera at the screen with all the codes. Double bonus points if the app generates a nice easy password for the used to plug in to be used as your secret.
And the thing is that it doesn't need to be super accurate. Even if its only budgeted with $10 million worth of $100 gift cards and it's only about 70% of the cards were getting the desired outcome, that's still 70,000 votes going purple. Especially if you limit it to being the first 100,000 confirmed voters, you'll still get people participating if they think there is still hope for getting a card. Even more if you're convincing voters that are only voting for the sake of a gift card and don't actually care about the result of the election.
And ultimately that's just one of several attack vectors I can think of. And I'm not a smart person; I'd go as far to say that I'm actually pretty stupid. I can't imagine what a room full of actually smart folks with NSA-like budget and NSA-like permissions can come up with. Remember the gigantic mess with Dual_EC_DRBG in the FIPS 140-2 standard?
Regarding your suggested attack vector, where the briber asks for a video of the screen showing how the number is displayed on the screen, this can be resolved with fake credentials. When creating a fake PIN code, the voter can specify inputs and outputs to the device with which the video can be taken. Fake credentials can further create fake credentials, so it is not possible to distinguish them.
I assumed this from the parent post
>> Something being hard does not mean that it should not be tried.
As opposed to paper voting, which does not have the issues raised by Tom Scott. If that is not what you meant, don't you agree that a more high-tech solution, complete with unspecified but granted methods that mitigate the security problems, requires more expertise and makes the process of voting as a whole more difficult than the low tech one? (eg infra / software maintenance, robustness to outage, educating people on how to use it, ... everything discussed by other threads)
> ballot is a publicly accessible encrypted ledger, where the votes exist publicly
It is cool, but I do not see how this improves upon voting on paper by mail.
Sure, it takes more expertise to run a ballot, but not more expertise to cast a ballot. And that's where the democratic process fails in most of the western world at the moment. Entire demographics are not interested in voting due to the higher bar of going through the motions of going to a ballot booth and casting a paper ballot.
In a world where it's possible to vote from your personal mobile device there doesn't need to be a whole circus and the entire country needs to stop in its tracks for the election day. It can be just another day, another weekend, or another week. You can vote for the smallest things that are interesting for you. Local issues need not to be left to the latitude of mayors or councils, but you could now vote on them from the comfort of your own home.
I'm not overlooking it, self-interested political parties are, but you are conflating the authentication problem with the voting problem. Moving to electronic voting does not solve the authentication problem, it just adds one more problem.
> You think in 10,000 years it will still be impossible to run a vote electronically?
Yes.