4 ms·
Good idea honestly, the security issues are greatly overblown - especially if we can simply make this a mailer with "if you want to vote for this candidate, ent
by shittyadmin 8y ago
Good idea honestly, the security issues are greatly overblown - especially if we can simply make this a mailer with "if you want to vote for this candidate, enter this code/scan this qr code", where nothing about that code identifies the candidate they voted for.
And it'd definitely help to improve voter turnout, just look at studies on how poll lines impact future voting behavior...
- zAy0LfpBZLC8mAC 8y agoSo, how do you count the votes each candidate gets if nothing about that code identifies the candidate they voted for? Also, you think this system is sufficiently secure to secure access to trillions of dollars? Because that is what elections are about.
- shittyadmin 8y agoOn an optically isolated (phyiscally receive only) server which only receives codes sent from the application servers. > Also, you think this system is sufficiently secure to secure access to trillions of dollars? Because that is what elections are about. More secure than Diebold machines to be certain.
- zAy0LfpBZLC8mAC 8y ago> On an optically isolated (phyiscally receive only) server which only receives codes sent from the application servers and produces results. And how does it count votes per candidate then? > Yes. More secure than Diebold machines to be certain. That seems very questionable.
- shittyadmin 8y ago> And how does it count votes per candidate then? Codes can be simply be computed as HMAC(secret key, SIN + candidate) or something similar, the user and any attacker without the secret key just has a random string of bits. You do realize votes are tallied by computer currently, right? Most of these just rely on phone-based systems that often expose interfaces to news orgs and such. The sort of interface I'm talking about would actually lead to less exposure in many ways from a security standpoint.
- lb1lf 8y ago...how does the user know his vote is valid and added to the tally? Changing a vote to be for another candidate is not the only way to influence an election; you could have votes for the 'wrong' candidate be thrown out as invalid, too.
- shittyadmin 8y ago> ...how does the user know his vote is valid and added to the tally? I could say the same thing currently - how do you know that vote you placed on a voting machine actually counted? > you could have votes for the 'wrong' candidate be thrown out as invalid, too. That's why you have codes that have no public mapping to candidates as I already suggested - I even suggested a primitive way to do so.
- zAy0LfpBZLC8mAC 8y ago> I could say the same thing currently - how do you know that vote you placed on a voting machine actually counted? Which is a reason for introducing an even less secure system how? Yes, voting computers are a huge security problem. Which is why they should be banned. > That's why you have codes that have no public mapping to candidates as I already suggested - I even suggested a primitive way to do so. As I mentioned above: Thinking of securing an election like securing a bank is doing things completely wrong. "The public" is not the primary attack vector you have to defend against. "The public" is who is supposed to have the power in an election. Entrenched powers is what you have to defend against.
- lb1lf 8y agoAs for voting machines, I don't know, I cannot know - and, luckily, in my jurisdiction they don't exist. I'd be happy with voting machines if all they did was keep a running tally - have them print a ballot, have the voter deposit this ballot in an urn - if the result (gotten from the voting machine as the polls close) is disputed, recount the paper ballots, end of discussion. As for the second part, I misread your initial post -apologies.
- 8y ago
- lolc 8y ago> simply That one word you can never use to describe electronic voting with secret ballot. Sure it may be made easy, but it won't ever be simple.
- deleted 8y ago[deleted]