Unfortunately, explaining them to Joe Q. Public in such a way that he's going to trust your election is a very tough sell, whereas counting paper is a much easier process to explain.
And that's before you begin worrying that the developer of your whizz-bang mathematically-provable voting system is a) going to win the bid to build it for the government, b) implements it correctly, and c) isn't subverted while doing so.
You can either couple every vote to a voter and risk oppressive monitoring of votes at scale or coercion at micro level, OR you can have decoupled voting proving that your vote was counted, but not have convincing proof that your vote or anyone else's are accurate.
Please prove me wrong because I would love it if it was possible.
Edit: Booth/paper-voting solves this by:
* linearly scaling cost of multi-party verification of identity at time of voting
* your vote being anonymous and being decoupled from you at time of deposit
* you trust the system at scale since each step in the chain-of-custody has many-eyes-verification
* vote amount is grouped by location so vote insertion can't happen at scale without coordinating with each involved polling place to fudge each of their numbers
* you can't insert into one area without having a random 100k population increase in a polling place overnight
It allows any voter to verify their vote was accurately recorded in the reported total. The usual argument against is you need a lot of people to verify, and most won't. That's probably true when everyone is confident in the outcome, but I'm not so sure it works be true if there was a wiff of fraud in the air.
> how can you prove that innumerable votes were added to the record, or that your vote is correct?
In Australia it's easy to prove no votes to the record because everyone on the rolls must vote, or they get fined. Ergo total votes must equal the number of people on the roll minus the number fined. As for "your vote was counted" - read the Wikipedia article. These systems do prove that, while keeping your ballot secret.
> It allows any voter to verify their vote was accurately recorded in the reported total. The usual argument against is you need a lot of people to verify, and most won't. That's probably true when everyone is confident in the outcome, but I'm not so sure it works be true if there was a wiff of fraud in the air.
There are a number of application details which wildly alters whether it's workable or not, where workable leans fairly close to current scalable cost, in which case the added benefit is minimal.
> In Australia it's easy to prove no votes to the record because everyone on the rolls must vote, or they get fined. Ergo total votes must equal the number of people on the roll minus the number fined. As for "your vote was counted" - read the Wikipedia article. These systems do prove that, while keeping your ballot secret.
Yes, but only by using as much verification as paper ballot casting, which is already provably robust and even more verifiable due to decentralization.
Skimmed these:
https://www.usenix.org/legacy/event/sec05/tech/full_papers/k...
https://www.researchgate.net/publication/277296393_Pret_a_vo...
I'm not sure what you are getting at here. A voter can not verify their vote in the current paper systems. Using these systems they can.
There are two kinds of attacks: typically classes as retail and wholesale. Retail attacks happen at the front end: stuffing ballot boxes, coercion, vote buying. As the effort involved roughly corresponds to the number of votes altered changing a large enough volume of votes to alter the outcome will be detectable using robust social systems, which boils down to teams of people watching each other.
Wholesale attacks happen when the vote is processed after they have been cast. An example is altering vote counting machine to lie about the votes counted. As they can systemically alter large numbers of votes they can be very difficult to detect even using statistical megtods. They are impossible to pull off when everything is done manually as teams watching teams still works, and you have to corrupt a lot of people. But when you introduce automation and machinery they voting system becomes vulnerable to this sort of manipulation.
Yes, "just continue to do everything manually using pencil and paper" does mostly eliminate wholesale attacks. But the reality is we are ditching pencil and paper for more automated processes. A famous example is a Diablo voting machine in some USA state, failed before regurgitating it's vote count (the "Volusia Error"). A man with a screw driver duely arrived, modified things, and handed over what he said was the correct vote count.
We are automating voting with voting machines and vote tabulators for good reasons. They are easier to use, particularly for the disabled, they are faster, they are cheaper than redundant teams of people, and they more accurate than manual methods. They are already arrived, and their use will only grow over time. Pleas like yours to "just use paper" are having little effect on their inceasing adoption.
The other option is to insist these machines and systems are end to end cryptographically verifable. That makes wholesale attacks these automated systems facilitate detectable. Currently we are deploying these systems without such safeguards. IMO this is insanity.
In the current paper systems you don't have to, as you know what you put on it before it got anonymized and counted as one vote by the teams watched by teams.
> Using these systems they can.
In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion.
In general, I agree with everything you write except for this paragraph:
> We are automating voting with voting machines and vote tabulators for good reasons. They are easier to use, particularly for the disabled, they are faster, they are cheaper than redundant teams of people, and they more accurate than manual methods. They are already arrived, and their use will only grow over time. Pleas like yours to "just use paper" are having little effect on their inceasing adoption.
The only "good" reason would be cost, but I wouldn't agree that it's a worthy trade-off. They could be easier to use, but it seems generally to be prone to UI issues making it unclear who/what you're voting for.
I'm sure their use will grow over time, but it won't be for any reasons that are good for democracy.
True. But the "secret ballot in a polling booth using paper" systems are disappearing. 32% of Australian votes aren't done that way now.
> In theory, yes. In practice, barely. If it was easy/practical it would be intrinsically susceptible to coercion.
It can be reduced to scanning a QR code in an app. It is a bit of a mystery to me why you think that isn't easy, practical or is susceptible to coercion.
Because "scanning a QR code in an app" would lead to:
1) integrity loss, ie reduction of peers in the secret sharing concept.
and/or
2) privacy loss, ie vote coercion, "show me you voted for our dear leader or something bad happens".
You can either confirm your encrypted ballot is present, OR you can decrypt it before being cast, in which case it can't be cast anymore. Unless I'm missing something they're mutually exclusive. The entire premise of the mix net is not being able to verify what you voted for, only that your vote is there, right?
> 1) integrity loss, ie reduction of peers in the secret sharing concept.
> 2) privacy loss, ie vote coercion, "show me you voted for our dear leader or something bad happens".
Following your instincts instead of doing the work required to understand Prêt à Voter will lead you to that conclusion. Your instincts are wrong in this case. Neither of your claims are true. The first paragraph of the Wikipedia page makes that plain. It says in part:
> In particular, Prêt à Voter enables voters to confirm that their vote is accurately included in the count whilst avoiding dangers of coercion or vote buying.
In case you haven't thought about it, vote buying is the hardest problem to solve for secret ballots. It is hardest because both the voter and a malicious third party are working cooperatively to corrupt the system. If you come up with a system that prevents that, you've pretty much solved all retail voting attacks. Prêt à Voter makes a vote verifiable, while ensuring votes can't be sold.
While you can't sell your vote with the typical implementation of Prêt à Voter, you can do it with your favoured paper ballot system:
1. Mallory obtains an authentic, blank ballot, and fills it in way he wants. Perhaps he does that by voting, pocketing the ballot paper, and putting the dummy in the ballot box.
2. Mallory gives the pre-filled ballot to a voter willing to sell his vote for an agreed sum outside the voting booth, where the transaction can't be detected. The voter isn't given his payment yet.
3. The voter goes into the secure voting place and is given a blank ballot. In the privacy afforded to him to cast a secret ballot he pockets the blank ballot, replacing it with the pre-filled ballot given to him by Mallory.
4. The voter casts the paid for vote.
5. The voter meets with Mallory in their secret spot, hands over the blank ballot and gets paid.
Rinse, lather and repeat all the way to winning the election.
If you haven't seen that little caper described before you will find it surprising. I did. But it is nowhere near the surprise you will get from spending the time to learn how Prêt à Voter achieves what appears to be impossible.
This is from the actual paper, not wikipedia:
> C. Audit of ballot forms Voters may wish to check that the order of candidates claimed to be encrypted on the right-hand side does indeed correspond to the list printed on the left-hand side. If this were not the case then a vote cast for one candidate may be considered after decryption as a vote for a different candidate. To provide such reassurance, voters may elect to ‘audit’ a ballot form. This involves removing the left-hand side of the ballot form, and asking the system to decrypt the candidate list from the onion on the right-hand side. The voter can then check that the decrypted list matches the list of candidates printed on the left-hand side. In principle, this audit can be carried out as often as the voter wishes. This gives the voter confidence that the ballot forms have been correctly constructed.
> However, the voter is not allowed to cast a vote on a decrypted ballot form. Once the candidate list associated with a onion is known, vote privacy, and hence resistance to coercion and vote-selling, is lost. The audit process gives an individual voter confidence that the ballot forms are correctly constructed, but does not allow her to check the ballot form that she is using to cast the vote.
What I said in GP is that you can't verify WHAT you voted for AFTER the fact, because the concept of coercion hinges on being able to threaten or pay for something the victim can provide. It's a logical proof, you can't design that away. I'm not saying it's not a valid trade-off.
Agreed, you can't prove you voted in a particular way in any system that prevents vote buying. I'm struggling to see why that is relevant to this discussion.
What Prêt à Voter does is allow you to confirm that your vote was counted accurately. Its magic is it does that without revealing how you voted. You've now read the paper and you didn't contest that, so I'm guessing you concede it's true.
My point above was the two claims you made, ie scanning a QR code in an app would somehow lead to integrity loss, and/or privacy loss in Prêt à Voter system are wrong. You don't seem to be contesting that either, so I guess you now concede they are indeed wrong.
You made those incorrect claims after I pointed out your earlier claim that checking your vote in a Prêt à Voter system is so difficult no-one would do it was also wrong, as it boils down to scanning a QR Code with an app. I guess you had to concede that is indeed pretty easy, so you invented those incorrect "facts" to prove scanning a QR Code couldn't work for other reasons. But it does work.
It's not a good track record, is it? One invented fact after another, all in an effort to prove end-to-end verifiable voting is somehow worse or less secure than our current paper systems.
That's also wrong of course, but worse than that many of our current systems aren't the "secret ballots cast in a secure polling place" system you are assuming we use. They are postal, or electronic, or worse the combination of the two we call internet voting. These electronic systems are particularly susceptible to wholesale attacks, and in my view they need something like Prêt à Voter to have a hope of being as secure as the old paper systems.
I will concede one thing. Personally I doubt in an election everyone thought was well run that many people would bother checking their vote was counted correctly, but that's not because it's hard, it's for the same reason we don't recount every paper ballot if it isn't close - why bother? But if there was a whiff of fraud in the air, it seems likely a lot of people would do the check, particularly if the Prêt à Voter receipt was recorded on their phone when they voted. That way they would not even have to scan a QR Code. They just feed the receipt to the checking app when the election results are published.
However, I would also suggest reading the guidelines, specifically these:
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".
In fact, the one isn't nearly as big of a privacy concern (if any at all). I wouldn't be surprised if someone told me the former could be done with some XOR scheme, but proving that both you voted and your vote counted for a specific candidate while keeping that a secret is a much more difficult task
Just have a code show the truth (for you to verify) and a second code to show a lie (in case of threats).
After your name is checked off, you then proceed to a booth where you mark a piece of paper before folding and placing that paper into a plastic collection box on the way out.
It's very analog and the electoral commission have no way to know if you actually voted or who you voted for. They only know that you turned up to the polling station and gave them your name.
I assume the number of people who turn up at the polling station, only to walk away without voting is so small that it's not seen as a problem to solve.
The receipt would id candidate
Guy with sledgehammer is at least a block waylay, and everyone knows that everyone votes, by law.
Personally, my concern is that with mail in ballots some nutjob that believes there's ballot stuffing can set fire to the ballotbox and even though they're caught it's a major inconvenience to get a replacement ballot and the websites that show your ballot is received take days to update.
But I still love mail in voting. My state sends a candidate brochure with it and I can take my time to actually look up all those random candidates' policies. It takes me hours to actually fill out my ballot but that's a feature, not a bug (there's nothing preventing you from along party lines but frankly I'd be happier without parties)
But you can already do that, regardless of mail in voting or not?
Not to mention the peer pressure. What asshole is going to stand in the booth for hours voting? I got to get to work!
Sure, you can do all this at home but there's a clear convenience when having both in hand
[1] - https://www.brennancenter.org/our-work/research-reports/voti...
If thousands of people were told "you already voted" when they showed up, then that would be very very obvious.
They also really do look at signatures and contact voters to cure ballots if they're unsure.
Hell, the fact that so many people have been looking for massive voter fraud for about a decade now and haven't is pretty telling. People aren't good at keeping secrets and if it's being done at scale it would be uncovered or leaked. Accidents and stupid people happen, but that works both ways
[1] - https://ballotpedia.org/Election_results,_2024:_Analysis_of_...
This is why many of the election fraud claims focused on lax signature verification of ballots as well as the lax mail in ballot address locations. I feel that IL elections are probably more secure, but only because the state is solidly one party and comically gerrymandered anyways.
But technically, yes, a ballot harvester could send ballots on your behalf if they have enough information about you.
And the biggest problem of this all is that it's basically impossible to prove because there's no meaningful identifier at any given point in the process. The only real evidence you'd have is a bad signature, yet in 2020 some states ceased comparing signatures and signature comparison was, in general, bizarrely under attack by certain interest groups.
You cannot "fabricate" votes, because all mail-in ballots are associated with a voter. Or rather, you put your ballot in an envelope and the envelope is associated with you. When your ballot is received, you are marked as voted and other ballots are invalid. The envelope is stored as proof of who voted and the ballot is kept separately to be tallied.
Ballot counting is done in public (you can go watch!) and there are a lot of safeguards and crosschecks. It's intended to make any fraud very obvious and incredibly difficult to scale.
The government knows who is a citizen and who isn't lol, they literally have the records.
Voter rolls are very closely scrutinized. Dead people are, in fact, taken off the rolls. There is essentially ~no voter fraud and ~no instance of non-citizens voting in this country. Yes, it's audited and studied. Yes, they keep the data and you can audit it.
You're literally complaining about it being easier for people to participate in democracy, and you should stop.
Everything's a conspiracy when you don't know how anything works.
And this for elections which are increasingly decided (in terms of flipping the electoral college one way or the other) by votes in the tens of thousands to low hundreds of thousands. So the scale of fraud in US elections is likely greater than the minimum margin of electoral college victory in them.
--
You also are substantially overstating the degree of organization of voter rolls. Voting in the US is heavily decentralized by design, which is what enables various states to have completely different electoral systems. But more specifically voter rolls are maintained by the states themselves and that, in turn, is typically further decentralized down to counties themselves.
This leaves a significant degree of inconsistency. In general I do not think that double voting or completely ineligible voting is a significant factor - nowhere near as much as voting on the behalf of others, but it certainly happens. For instance thousands of mail in votes were rejected because they came from dead people, and it is highly unlikely that 100% of these attempts were caught.
https://www.bbc.com/news/uk-politics-26487418
The article quotes one Mr Richard Mawrey QC:
> "Postal voting on demand, however many safeguards you build into it, is wide open to fraud… on a scale that will make election rigging a possibility and indeed in some areas a probability."
> "Now I know that there is a very strong political desire to keep the present system. What I'm saying is that if you keep the present system, then however many safeguards you create, fraud and serious fraud is inevitably going to continue because that is built into the system."
You never can be too careful!
Also, maybe someone inside will take their ballot from them.
IMHO this voting thing is too risky. We should just go back to having a ruling family /s
The closest I can think of is rare cases like this: https://en.wikipedia.org/wiki/Bushel%27s_Case
You can try to google-translate [this, for example](https://holod.media/2024/03/08/soprotivlenie-putinu/#h-3-%D0...)
As far as I know, these votes have gone mostly unchecked before electronic voting, but after that, they’ve started voting straight from the workplace computers. There were, of course, a lot of straight-up falsifications as well.
That said, our pen-on-paper voting isn’t too legit either :’)
I encourage everyone to look up the relevant sources, easy to find.
Vote for me and I'll increase your pensions, the other guy wants to decrease your pensions.
Vote for me and I'll increase wages of gov workers and civil servants, the other guy wants to fire gov workers.
VOte for me and I'll increase your welfare and give you free* housing.
etc... etc.The gov has masses of people that depend on the gov's generosity that they can leverage with a carrot on a stick to swing the majority in their favor. You don't need to put a gun to their head. The gun to their head is the threat of losing those government provided perks.
That's how elections are won in Europe, just promise the boomers(largest voter base) higher pensions. That's why nobody who campaigns on reforming the pension system will ever win an election.
Party A) Keep the 80% discount in the electricity and gas bills
Party B) Reduce inflation from 200% y.o.y. to 50% y.o.y.
Party C) [I don't remember]
Party D) "A normal country"
---
PS: D was a slogan, they got less than 5% of the votes.
People do, in fact, threaten or coerce their spouse and that extends to voting.
Being able to audit from a secure counting room and being able to produce an always-available-online permanent record is different.
Even if you ignore the pencil they give you and use a pen, you can simply tear or damage the paper, take it back to the elections officer, ask for a new ballot, and fill that out instead. We make it as hard as possible to coerce a vote while maintaining secret voting (noting that it is definitely still possible, just hard).
- collect blank ballots (usually 2 pieces of paper, one for the House, one for the Senate) at the entry,
- walk over to the booth,
- fill out your ballot in secret at the booth (taking as long as you like),
- fold the ballots,
- walk over to the ballot boxes,
- drop the folded ballots into the corresponding box (House ballot in the House box and Senate ballot in the Senate box),
- then leave.
As no-one sees what you write at the booth, you can vote legally, draw pictures on your ballot, write obscenities, write nothing, or a combination.
At this point, if the voter has not checked in yet, we can refuse to do so. Either way, if the phone/camera is still out after the judge has asked and shown them the law, judge is to immediately call the constable's office (police), who have been positioned nearby (but never directly at any vote center, due to possible intimidation). The constable can and will remove the man from the vote center. (It's never escalated that far!) (arresting that voter for any length of time might be problematic on election day for obvious reasons).
The most common complaint is "but I wrote up all my selections on there!" and for these voters we can provide a paper "sample ballot" and even a pen and they are free to mark their selections outside of the room and then come back to vote on the machine. One location was a church that was even gracious enough to allow a gentleman to AirPrint his notes.
Also of note, we do not have any kind of a "booth", however, the machines are typically placed rather far apart, and no one is allowed to queue at or near the machines, or linger there after voting, so I believe that privacy is effectively maintained. (Workers including judges are not even allowed to linger there unless assisting a voter who has specifically asked for help, and even then, there's more rules - if the voter needs help actually making the selections for candidates, now you need at least one judge and one clerk, one of whom must observe and ensure that the voter's selections were made correctly.)
We also got rid of the problematic "digital only" machines several years ago, but this post is too long already.