5 ms·
Don't want to turn this into another 'blockchains can solve anything' discussion - but I do feel some form of blockchain tech could be an effective way to solve
by crypt1d 8y ago
Don't want to turn this into another 'blockchains can solve anything' discussion - but I do feel some form of blockchain tech could be an effective way to solve e-voting.
Here's why:
- A central authority(government) can control issuance of new keys and maintain the association between keys and personal information. There are already plenty of gov ID cards which support digital signatures and can be used to sign voting keys as well. At the same time personal info would not show up on the blockchain.
- Blockchain explorers would be used as a way to verify the votes are legit by virtually anyone
- NVOs, governments, etc can run the blockchain nodes to ensure integrity of the blockchain
In combination with well designed UIs we can have simple voting apps that can make e-voting a breeze (see the Smart-ID implementation for a great example of such tech).
Obviously the attack vector shifts to the gov servers running the key issuance but its easier to do opsec on a datacenter level than on individual voting machines scattered around the country. There's also a question of the integrity of the voting app, but that can/should be open-sourced and audited.
We obviously have the tech and the capabilities to create very effective e-voting solutions. Would even go so far as to say that a proper solution would drastically change the way we think about voting - it would make on-boarding a lot easier and provide some form of 'direct' democracy that we are already seeing flourish in countries like CH. So it seems very shady to me that we end up with BS like this thats very easily exploited and discarded as ineffective.
- involans 8y agoHow do you preserve the secrecy of the ballot with a blockchain? Wanting to verify that an elector has voted but obscuring who for seems like a challenge.
- refset 8y agoPartially homomorphic encryption can be used for vote tallying, see: https://heliosvoting.org/faq https://heliosvoting.org/faq (which uses ElGamal)
- moviuro 8y ago> - A central authority(government) can control issuance of new keys and maintain the association between keys and personal information. [...] This means that you can tie a vote to a key, thus a person? That's not how voting should work. Any vote cast must be secret. Or what's to prevent any one group from blackmailing you (or any other voter)? > Voting app You mean that a thug could coerce me into casting my vote from home?... > There's also a question of the integrity of the voting app, but that can/should be open-sourced and audited. + constantly verify that the machine was not tampered with (evil maid) + make sure the hardware was not compromised (supply chain attacks) + ... on TONS of devices?... > We obviously have the tech and the capabilities to create very effective e-voting solutions. No, clearly we don't! The current paper ballot model has been battle-tested since elections became a thing. See https://www.youtube.com/watch?v=w3_0x6oaDmI https://www.youtube.com/watch?v=w3_0x6oaDmI
- crypt1d 8y ago> That's not how voting should work. Any vote cast must be secret. Or what's to prevent any one group from blackmailing you (or any other voter)? Fair point, but they do not have to maintain the association with the voting keys. Derivative keys can be signed without it imho. > You mean that a thug could coerce me into casting my vote from home?... Dont be naive, things like this happen already even with paper votes. See https://en.wikipedia.org/wiki/Bulgarian_train https://en.wikipedia.org/wiki/Bulgarian_train > + constantly verify that the machine was not tampered with (evil maid) + make sure the hardware was not compromised (supply chain attacks) + ... on TONS of devices?... I agree that's a problem that needs consideration, but we've solved many such issues before. There are quite a few ID, banking, authentication, etc. apps running quite fine and well on consumer devices. E-voting is a general term that describes methods of voting that involve electronics. While some solutions are indeed terrible, that doesn't mean all are.
- moviuro 8y ago> Dont be naive, things like this happen already even with paper votes. See https://en.wikipedia.org/wiki/Bulgarian_train https://en.wikipedia.org/wiki/Bulgarian_train That's weird. I don't understand that "filling" paper ballots. In France, we get to pick N papers with only one candidate's name printed on each. We then discard and seal in the envelope the papers we want once we're in the "isolation room". > I agree that's a problem that needs consideration, but we've solved many such issues before. No, we never had the entire destiny of any one country rely on a single piece of tech running on untrusted devices. Banks can contact any individual if their logins were leaked or if their money transfer appear suspicious; but as votes cast must be kept secret, you can't do anything similar with voting. > E-voting is a general term that describes methods of voting that involve electronics. While some solutions are indeed terrible, that doesn't mean all are. Still waiting for a viable solution - so far I don't know of one.
- lucozade 8y ago> A central authority(government) can control issuance of new keys and maintain the association between keys and personal information One of the key features of a secret ballot voting system is that there's no practical way to tie a voter to a vote. If you have a direct relation between a voter and a unique key, and that key and a vote, you've basically built an automated corruption system. And a lot of people might not be entirely comfortable with the assertion that it's fine, only the government knows who you voted for.
- crypt1d 8y agoPoor choice of wording on my end, I was coming up with the idea on the fly. I'm sure someone else can come up with something better with a bit more thinking :) The association between vote keys and personal info does not need to exist. ID keys have to be issued by the gov but the vote signature keys can be derived from them and/or signed by a 3rd party like an NVO or a combination of govs/NVOs.
- lucozade 8y agoHaving tried, it's a little more difficult than applying a bit more thinking. Specifically, the criteria that you can't trace a voter to a vote but you need to ensure a voter only has one vote (or at most one if voting isn't mandatory) is really hard to reconcile. I also happen to believe a way might be found but by handwaving "zero knowledge proof" in the same way that you're handwaving blockchain.
- batiste 8y agoI don't think the blockchain provides any value at all because you cannot verify if a transaction is valid without having a list of authorized voter... And that can only be the Gvt. If you have already a list of public keys for each voter why do you even need a blockchain to verify anything? You just through the list of signed votes to ensure uniquness, and you can confirm you personal vote is genuine but that is all you can do.