6 ms·
I'm not a security expert either, but my very first thought was that if we've successfully maintained a public ledger of financial transactions ( blockchain via
by dcherman 10y ago
I'm not a security expert either, but my very first thought was that if we've successfully maintained a public ledger of financial transactions ( blockchain via bitcoin ), then that technology seems useful for large scale voting which is nothing more than another series of transactions.
Maybe someone more educated about blockchain could illustrate some of the pros/cons about using it in this manner?
- eridius 10y agoAn immediate huge problem is the fact that the blockchain works because the signer can prove their ability to sign, but voting is supposed to be anonymous. If every vote was a transaction then every vote would be public knowledge, but anonymity of voting is one of the cornerstones of our voting process.
- paulmd 10y agoProbably solvable. Here's one solution that would only require registration of write-ins (which many states already do). Issue everyone a secret key (the digital equivalent of a ballot). They publish hash($key, $name). There are only N values for $name so that can be solved in O(N) time, but without knowledge of $key you couldn't determine whom someone voted for. For the sake of the user you could even pre-compute the hash values so it literally becomes "publish this string to vote for X". You could authenticate the user by having them give their pubkey at their secretary of state. The pubkey signs the hash like a standard blockchain transaction.
- Spivak 10y agoHere's the problem. Anyone who has $key could determine who they voted for. Not only would the average person not know how to sufficiently protect this key but it makes votes trivially verifiable by the voter which is equally as bad.
- paulmd 10y agoWell, I disagree that having keys be trivially verifiable by the voter is a problem. That's a selling point - you can be sure that your vote wasn't altered in-transit. In fact that's largely the point of the system. This is a general problem with absentee/mail voting, though, and it's a strong argument. If your boss/spouse/etc is being an asshole there's little to stop them from coercing you to show your paper absentee ballot, marking it in for you, etc. Yes, it's illegal, but what are you going to do about it after your at-will employment is terminated without cause next month? In the privacy of a voting booth, you can vote however you want and nobody will ever know. It's real easy. I think you can still keep votes secret if you have in-person voting. Just have the secret key never leave the polling place, it's equivalent to collecting the ballot after tabulation (we have paper ballots that are run through a ScanTron machine, we don't get to keep the ballots). You get a printout of the hash values you selected (but not the key) and can validate that the hash exists on the blockchain afterwards (signed by the polling place's private key), but there's no proof as to what the particular hash values actually indicated. Really though you have to trust that people will treat their electronic ballot with just as much import as their paper ballot. I don't think an electronic works without some kind of secret key/token.
- eridius 10y agoIf you haven't seen it, Spivak's other comment explains why you don't want voters to be able to verify their vote later (https://news.ycombinator.com/item?id=12923958 https://news.ycombinator.com/item?id=12923958).
- paulmd 10y agoI don't think you actually read my comment. His point is fully responded to.
- Spivak 10y ago> but voting is supposed to be anonymous It's actually much much worse than that. Votes not only have to be anonymous but not verifiable by the voter (i.e. they should have no way to prove who they voted for after their ballot is submitted). You don't want to live in a world where rioters could target anyone who couldn't prove they voted for their candidate or domestic violence for the same reason. Also, if votes are verifiable then it becomes easy for a person to buy votes or for companies to offer 'incentives' to vote for a particular candidate.
- kobeya 10y agoA cabal of miners can censor transactions. If those transactions are ballots, then all it takes is a cabal of 3-4 people (who run the mining pools) to decide the result of the election.
- grzm 10y agoThere's no reason to use the blockchain for this. There are existing methods that allow people to be able to confirm their vote is included in the final tally without revealing (by choice or otherwise) what their vote is. See Punchscan or Scantegrity for examples. - https://en.wikipedia.org/wiki/Punchscan https://en.wikipedia.org/wiki/Punchscan - https://en.wikipedia.org/wiki/Scantegrity https://en.wikipedia.org/wiki/Scantegrity This slidedeck from Ron Rivest (yes, that Rivest) gives a good overview of secure and auditable voting: Auditability and Verifiability of Elections ACM-IEEE talk March 16, 2016 https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf https://people.csail.mit.edu/rivest/pubs/Riv16x.pdf