4 ms·
> And how does it count votes per candidate then? Codes can be simply be computed as HMAC(secret key, SIN + candidate) or something similar, the user and any a
by shittyadmin 8y ago
> And how does it count votes per candidate then?
Codes can be simply be computed as HMAC(secret key, SIN + candidate) or something similar, the user and any attacker without the secret key just has a random string of bits.
You do realize votes are tallied by computer currently, right? Most of these just rely on phone-based systems that often expose interfaces to news orgs and such. The sort of interface I'm talking about would actually lead to less exposure in many ways from a security standpoint.
- lb1lf 8y ago...how does the user know his vote is valid and added to the tally? Changing a vote to be for another candidate is not the only way to influence an election; you could have votes for the 'wrong' candidate be thrown out as invalid, too.
- shittyadmin 8y ago> ...how does the user know his vote is valid and added to the tally? I could say the same thing currently - how do you know that vote you placed on a voting machine actually counted? > you could have votes for the 'wrong' candidate be thrown out as invalid, too. That's why you have codes that have no public mapping to candidates as I already suggested - I even suggested a primitive way to do so.
- zAy0LfpBZLC8mAC 8y ago> I could say the same thing currently - how do you know that vote you placed on a voting machine actually counted? Which is a reason for introducing an even less secure system how? Yes, voting computers are a huge security problem. Which is why they should be banned. > That's why you have codes that have no public mapping to candidates as I already suggested - I even suggested a primitive way to do so. As I mentioned above: Thinking of securing an election like securing a bank is doing things completely wrong. "The public" is not the primary attack vector you have to defend against. "The public" is who is supposed to have the power in an election. Entrenched powers is what you have to defend against.
- lb1lf 8y agoAs for voting machines, I don't know, I cannot know - and, luckily, in my jurisdiction they don't exist. I'd be happy with voting machines if all they did was keep a running tally - have them print a ballot, have the voter deposit this ballot in an urn - if the result (gotten from the voting machine as the polls close) is disputed, recount the paper ballots, end of discussion. As for the second part, I misread your initial post -apologies.
- umanwizard 8y ago> You do realize votes are tallied by computer currently, right? Not in countries that take elections seriously, for example almost anywhere in Europe. Sadly it’s true of the US, but it doesn’t have to be that way.
- CaptainZapp 8y agoYou do realize votes are tallied by computer currently, right? In Switzerland, were you vote on referendums up to three times a year [which can be pretty complex issues] votes are cast on paper and counted manually. Vote counting is semi volountary, but rather well paid, at about 32$ an hour in Zurich. First results, with the exception of parliamentary votes, which are more complex, are in two hours after the polling places close. Final results usually don't take longer than four or five hours. Please don't come with the argument that it's a small country, which can not be compared to a huge country like the US. Its' a matter of scaling appropriately on a communcal level and being willing to spend money on it. Of course this has a price, but the question to ask is: Is it not worth the price to guarantee the integrity of your democratic system?
- zAy0LfpBZLC8mAC 8y ago> Codes can be simply be computed as HMAC(secret key, SIN + candidate) or something similar, the user and any attacker without the secret key just has a random string of bits. In other words: The codes do identify who voted for what, which is contrary to your original claim. The attacker not having the secret key is an inacceptable requirement for voting systems, as the election is run by those in power, but has to be able to remove them from power. > You do realize votes are tallied by computer currently, right? No, where I live they don't. The consitutional court of Germany ruled that voting computers are illegal to use here for reasons of election transparency and integrity. > The sort of interface I'm talking about would actually lead to less exposure in many ways from a security standpoint. No, not as far as the relevant attack vectors are concerned. If you think of securing an election like securing a bank, you are completely off the track.
- deleted 8y ago[deleted]