I've had the following idea for a while and was wondering if anyone can point out the flaw:
Imagine a system where every individual has their own public/private key pair (backed by tying it to their SSN). You then have two SQL tables:
CREATE TABLE voterVote (
id INT,
category VARCHAR(255),
vote VARCHAR(255),
PRIMARY KEY (id,category)
);
CREATE TABLE voterVoteId (
voter_id INT PRIMARY KEY,
voter_city VARCHAR(255),
vote_id INT FOREIGN KEY REFERENCES voterVote(id)
);
Both tables are published. The one thing I forgot to mention though is that the vote_id is encrypted with the users public key. This way any individual voter can check that his vote is what is should be and people on the whole can check that votes were tallied properly. Furthermore, we dont need to worry about hacking compilers, etc. because this can be done on the internet. The last thing we need to worry about is that the machine is lying to people when they go to check their vote. The only solution to this is to have the code which decrypts the persons row in the voterVoteId open source, but still since the protocol is open source and the data is open source, we can bet that there exists one honest person to build a tool to check. One more thing: how can we tell that extra rows werent added to VoterVote? We can check that the number of people in a city matches the number of keys issued to every person in that city (which again is backed by SSN).This will probably fail miserably at something simple I've overlooked, but it was fun to dream up :)