19 ms·
DARPA Is Building a $10M, Open-Source, Secure Voting System
- deogeo 8y agoOpen source, open hardware? What a joke. Neither are resistant to chip/compiler level attacks such as https://www.schneier.com/blog/archives/2018/03/adding_backdoor.html https://www.schneier.com/blog/archives/2018/03/adding_backdo... and https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html That's all assuming the voting machine is actually running the software/hardware they tell you - how would a voter check? The article briefly mentions "That receipt does not permit you to prove anything about how you voted, but does permit you to prove that the system accurately captured your intent and your vote is in the final tally,". But if that receipt doesn't let you prove anything about how you voted, how can you tell from it that your vote was captured 'correctly'? The machine can print anything on the receipt! Then there is the question - what problem is e-voting trying to solve? Hand-counting scales perfectly and is extremely difficult to covertly tamper with. So the only 'problem' e-voting solves is that of being unable to covertly and fully subvert elections.
- deleted 8y ago[deleted]
- kevin_thibedeau 8y ago> That's all assuming the voting machine is actually running the software/hardware they tell you - how would a voter check? Have dedicated hardware compute a hash from the content of program ROM on demand with a button press and present it on an auxilliary 7-segment display. Compare against the hash of the vetted image. No software need be involved. At some point in the process, machines will be used for tabulation. You have to trust the hardware to some extent. Just keep it as simple as possible to minimize confounding complexity that an attacker can hide in.
- deogeo 8y agoIf the compiler was compromised, how do you know the vetted image is correct? If the hardware was compromised, then the software will still hash to the correct value. And once the attacker knows where you're getting the dedicated hardware for the hash, he can compromise that as well. And the entire system relies on the people implementing it to not have been compromised. Because if they were, if the government itself compromised the machines, the voters could never tell. How good is a voting system that only works if your government is honest?
- zAy0LfpBZLC8mAC 8y ago> Have dedicated hardware compute a hash from the content of program ROM How do you check the circuit of that hardware? How do you know the ROM you are reading is the ROM the CPU is executing from? How do you know the CPU is the architecture you think it is and the program means what you think it means? > You have to trust the hardware to some extent. No, you don't, and you shouldn't. You can do all of that calculation by hand. And at the very least you can check a random selection by hand. > Just keep it as simple as possible to minimize confounding complexity that an attacker can hide in. In other words: Don't use electronics. You can't get simpler than pen and paper.
- unethical_ban 8y agoI think it's unfair to say there is no point in e-voting besides malice. e-Voting could make it easier / cheaper to deploy polling stations, collect ballots faster, and potentially to use more complex (but more fair and accurate) voting methods like Ranked Choice or others. As for the "We won't tell you how you voted but you can validate it", my first guess would be some kind of PKI where you are given the equivalent of a private key, and your results are signed. There are issues trusting hardware vs. trusting the sight of paper and two humans, I get that. But it's worth researching.
- cyphar 8y ago> e-Voting could make it easier / cheaper to deploy polling stations, collect ballots faster, and potentially to use more complex (but more fair and accurate) voting methods like Ranked Choice or others. In Australia we use IRV (what you call ranked-choice) and we don't have any forms of electronic voting for federal elections, and the overwhelming majority of votes cast in state elections are paper ballots (which are hand-filled). You don't need e-Voting to solve that problem.
- unethical_ban 8y agoMaybe not for IRV specifically, though it would arguably be easier anyway. There are more esoteric (see, mathematically dependent) voting systems that meet the Condorcet criterion.
- cyphar 8y agoSure, but computer vote tallying and e-Voting are not the same thing.
- jonahhorowitz 8y agoYour votes are still probably counted by a computer. In San Francisco, we use optical scan ballots. This system is very similar. It prints out a ballot that you validate and feed into an optical scan machine. Marking the ballot is electronic, which allows for more language choices, assistance for hearing impaired people, etc.
- abakker 8y ago>The systems Galois designs won’t be available for sale. But the prototypes it creates will be available for existing voting machine vendors or others to freely adopt and customize without costly licensing fees or the millions of dollars it would take to research and develop a secure system from scratch. I guess the devil is always in the details. "freely adopt and customize" to me says that the code will not be verifiable or open source anymore? Or that the implementation could be flawed. Open sourcing the code, and then letting commercial entities change it, cut corners, make money, etc seems to be a good way to ensure that all the hard work that went into designing the system is rapidly compromised.
- masswerk 8y agoIsn't there a law in the US prohibiting public institutions from competing with private businesses? This may provide a cause for not rolling it out, but rather handing it over to private enterprises for implementation. Edit: I recall the US having to withdraw from the Human Genome Project because of this as soon as a private enterprise claimed it as a field of business.
- ashelmire 8y agoNo, that’s not true. I’m unaware of such a law and could point to many counter examples. The human genome project was declared “complete”.
- masswerk 8y agoActually, the HGP was on the verge of being scrapped, but then the U.K. came to the rescue with a major investment to make up for the US. If I recall this right, the US enterprise (Celera) wanted to take an algorithmic shortcut in mapping and verifications, by this overtaking the HGP regarding final results in order to provide the data as a paid service. This happened 7 years before the scheduled finalization of the HGP. Eventually, they finished in a tie. (However, this has been some years ago now and I'm not a US citizen.)
- Keverw 8y ago
- swalsh 8y agoMy ideal voting system would allow me to have a real time feed of votes as they come in, so that at the end of the night I can check my records vs the "official" records. Names can be detached, all I need is a Ballot id. BallotId can be something as simple as the hash of RegisteredVoterId + password + Salt + ElectionId. As long as the voter remembers their password, they can look up their record, and the record can be a fully public record with anominity.
- michaelbuckbee 8y agoA feature/detriment of per vote verification is that it opens up the entire system to vote buying - are you describing verifying that your vote happened, or who it was cast for?
- tzs 8y agoNot necessarily. Systems that allow you to verify that your vote was included and counted toward the candidate you selected in the booth, but do not allow you to prove to a third party who you voted for, are known, such as Scantegrity [1]. It sounds like the new system has this feature, and also another key feature of Scantegrity which is that the tallying can be done publicly and independently verified. From the article: > The optical-scan system will print a receipt with a cryptographic representation of the voter’s choices. After the election, the cryptographic values for all ballots will be published on a web site, where voters can verify that their ballot and votes are among them. > “That receipt does not permit you to prove anything about how you voted, but does permit you to prove that the system accurately captured your intent and your vote is in the final tally,” Kiniry said. > Members of the public will also be able to use the cryptographic values to independently tally the votes to verify the election results so that tabulating the votes isn't a closed process solely in the hands of election officials. > “Any organization [interested in verifying the election results] that hires a moderately smart software engineer [can] write their own tabulator,” Kiniry said. “We fully expect that Common Cause, League of Women Voters and the [political parties] will all have their own tabulators and verifiers.” [1] https://en.wikipedia.org/wiki/Scantegrity https://en.wikipedia.org/wiki/Scantegrity
- equalunique 8y agoI'm a fan of Galois, so I'll keep tabs on this project.
- danpalmer 8y agoAgreed. I was about to write this off as a boring project that might go nowhere, but I have a huge confidence that Galois will treat this with the gravitas necessary from a computing and security theory point of view. It might still go nowhere, but I expect there will be very interesting developments as a result of it.
- nathan_long 8y ago> Kiniy said Galois will design two basic voting machine types. The first will be a ballot-marking device that uses a touch-screen for voters to make their selections. That system won’t tabulate votes. Instead it will print out a paper ballot marked with the voter’s choices, so voters can review them before depositing them into an optical-scan machine that tabulates the votes. Galois will bring this system to Def Con this year. This sounds great: paper trail, no chance of "hanging chads" or bad handwriting, verifiable by the voter at the moment before scanning and hand-countable if necessary.
- simongr3dal 8y agoI hate being outright dismissive but it sounds like an expensive html/pdf form with a printer attached. I do agree that the paper trail is a great thing. I'm not fundamentally against electronic voting, but I haven't heard of a system that can really compete with the simplicity and verifiability of the immutablility you get from paper ballots inside ballot boxes being watched over by interested parties on all sides.
- nathan_long 8y ago> I hate being outright dismissive but it sounds like an expensive html/pdf form with a printer attached. I don't think that's dismissive at all. That's what it is, and it sounds good to me. Basically the computer is a scribe with perfect handwriting that fills out the paper ballot for the voter while the voter watches. Absolutely any voter is qualified to assert whether the ballot contains the votes they intended to cast. From there, you could have the voter carry the ballot and drop it in a box that's being observed by any number of interested parties, providing old-fashioned accountability. Counting by scanner is an optional time saver, with hand counts as the alternative / double-check.
- snuxoll 8y agoDon't forget that electronic voting machines can have accessibility features that paper ballots lack - having a glorified form printer is actually a sound design that lets us gain these benefits without the negatives.
- Entangled 8y agoSoftware is perfectible, skinware is not. As long as corruptible human beings are in charge, there will be room for fraud.
- k_sh 8y agoYou're right, but that doesn't mean it's a waste of time to design systems more resilient to the human element.
- reaperducer 8y agoSoftware is perfectible, skinware is not. As long as corruptible human beings are in charge, there will be room for fraud. Skinware writes the software. (Is "skinware" the new "wetware?")
- bdamm 8y agoCorruptible humans will always be in charge, until Terminator. The question is, how much corruption are we willing to put up with, how would we know it is happening, and how robust are the apparatus for correcting those abuses?
- hannasanarion 8y agoA corrupt human being can change one vote, or a few hundred if they're very industrious, in a paper ballot system. A corrupt human being can change every vote in an electronic ballot system. I would rather use the system where fraud is difficult and expensive and low-impact.
- tdcbfdct3 8y agoMore information about the idea: https://en.wikipedia.org/wiki/End-to-end_auditable_voting_systems https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
- sagitariusrex 8y agoI don't believe that putting a price tag on a piece of software legitimizes it for a given use case. I get this same feeling from posts that say "Product X written in language Y". While I agree that there exists a right programming language for a given task, it is not in itself a reason to use product X.
- anth_anm 8y agoMy design uses paper and pen. Deployment requires mailing ballots out and having places where people can come in to fill them out. 10 million dollars please.
- TomMarius 8y agoHow is that better than whatever we have now?
- JustSomeNobody 8y agoThe pens in poor neighborhoods have ink.
- config_yml 8y ago/wooosh
- Barrin92 8y agoI legitimately don't understand what's the invention here. If all you're trying to do is avoiding having an invalid or ambiguous ballot and you print out a paper copy anyway, why invest 10 million into a new system instead of just using some bog standard computer + printer? If you're going to get the physical ballot anyway what's the point?
- bdamm 8y agoSystems comprising entirely of pen/paper and manual counters with oversight by the parties, where sufficient engagement in the community provides the volunteer manpower to oversee the election, are impervious to electronic interference.
- MBCook 8y agoHow well does it work for people with motor disabilities? Vision disabilities? Does an X mean a choice or they crossed out their choice? What happens when the pens run out of ink? What if they can’t read English? Helpers? What do you pay them? Can they understand that dialect of that obscure language? Do you trust them not to lie about what they’re marking on the ballot for someone? The truth is electronic voting machines have upsides. Having the system fill out the ballot which the voter then hands in seems like an almost ideal use to me. It’s totally verifiable but can help many people who wouldn’t be able to vote without help.
- deleted 8y ago[deleted]
- bluedino 8y agoCould this be a useful application of blockchain?
- mspecter 8y agoNo.
- zachguo 8y agoCan you elaborate? It seems each vote would be harder to tamper if blockchain is applied. (or some other techniques chaining data together to be verified)
- thanatos_dem 8y agoCould be a good application of hash chaining as it has existed since the 80’s. Block chains wouldn’t add much value over that here, however.
- bushin 8y agoYes.
- MrXOR 8y agoGood news. An Agora voting system's fork powered by SGX/TrustZone and verified by Cryptol?
- MrXOR 8y agoMore than it: https://www.darpa.mil/news-events/ssith-proposers-day https://www.darpa.mil/news-events/ssith-proposers-day
- pmoriarty 8y agoSay goodbye to democracy wherever electronic voting is rolled out.
- jonahhorowitz 8y agoYou still have paper ballots - with audits.
- pmoriarty 8y agoThose audits are only triggered when the vote counts are close enough, within a certain margin. Since whoever controls or hacks the machines gets to set the vote counts, the audit only happens if they want it to.
- jonahhorowitz 8y agoIn California[0] we audit 1% of all ballots, regardless of the outcome. [0] - https://www.sos.ca.gov/elections/voting-systems/oversight/county-one-percent-manual-tally-reports/ https://www.sos.ca.gov/elections/voting-systems/oversight/co...
- pmoriarty 8y agoWhat does that prove? Your electronic voting machine could completely tell you the truth about every ballot you ask it about, but lie about the total.
- jonahhorowitz 8y agoBecause we count an entire precinct and check the totals. We don't just ask it what it got for individual ballots.
- bushin 8y agoBut think of the children!
- 8y ago
- sverige 8y agoWhy does this keep coming up? What is the compelling argument against paper ballots? There is no need for results to be known immediately, so how does making voting an exercise done by computers make anything better, particularly when computers are much more vulnerable to remote interference?
- hansjorg 8y agoBecause paper ballots increase the cost of manipulating elections.
- Pharmakon 8y agoIronically the one recent confirmed case of a rigged election in the U.S. was rigged through paper absentee ballots.
- buzzerbetrayed 8y agoIs it really ironic when pretty much all voting is done with paper? Of course the rigged voting would have been through paper ballots when that is what we use.
- Pharmakon 8y agoIt’s ironic when I’m responding to someone framing the use of paper ballots as a security feature, yes.
- jacques_chester 8y agoAnd it was detected. That's a big part of the advantage of paper ballots. The cost of subversion is high because more people need to be in on any conspiracy to subvert the system. More conspirators means more and more incentive to defect against co-conspirators. Electronic systems do not scale subversion cost with electorate size. But they do scale the payoff of subversion.
- brenschluss 8y ago
- LinuxBender 8y agoHave there been any competitions to make an open source, highly scalable and verifiable anti-tampering voting system? Maybe even a competition to see how few resources can be allocated to facilitate millions of simultaneous voters? i.e. "did it in 50 lines of python!" like the javascript 1k competitions. [1] [1] - https://js1k.com/ https://js1k.com/
- zAy0LfpBZLC8mAC 8y ago> Have there been any competitions to make an open source, highly scalable and verifiable anti-tampering voting system Yes, for thousands of years. The result is called the paper ballot. You cannot have a verifiable anti-tampering voting system using computers. You need verifiability by the general public. Auditing a microchip is not something members of the general public know how to do, and in any case, it detroys the chip, so it's kinda useless anyway.
- LinuxBender 8y agoAre those tamper proof? I recall some engineers testifying before congress about specifically making paper ballot systems that were designed to allow altering results. DieBold I think? I don't have a link handy, but it seems that is just as fallible. Or do you mean hand written ballots? Does anyone still use those? And yeah, the digital ones have been hacked at DefCon by children. (their parents taught them how to hack the devices, so I guess that is cheating) Maybe throw in some Blockchain or did I use a BS Bingo term?
- zAy0LfpBZLC8mAC 8y ago> Or do you mean hand written ballots? Does anyone still use those? Yes. The constitutional court of Germany ruled that electronic voting is essentially illegal in Germany due to all the inherent flaws, so all elections are done with pen and paper, ballot boxes, and manual counting.
- LinuxBender 8y ago
- pooya13 8y agoWith voting systems the hardware implementation should be both open source and open to investigation by the public throughout its lifecycle (from manufacturing to operation).
- rabi_penguin 8y agoGalois has a reputation for being one of the most visible and well-known shops associated with Haskell. I'm curious to see what they can accomplish. A little bit of poking showed this[0] coming up -- I definitely wonder if that's around the same direction they'll be taking. [0]https://galois.com/project/csfv-crowd-sourced-formal-verification/ https://galois.com/project/csfv-crowd-sourced-formal-verific...
- bkmeneguello 8y agoEveryday someone trying to "fix democracy"
- thanatos_dem 8y agoI use this premise as one of my architectural interview questions- design a voting system. Having asked it dozens of times, I’ve come to the conclusion that I don’t trust anyone to build a voting system. I like it as a question tho, since it’s open ended enough to really let the candidate focus on the domains interesting to them; scalability, security, data modeling, whatever they want really.
- tommd 8y agoThat's a huge leap from "arbitrary candidates can't give a satisfactory answer during an interview" to "I don't trust it can be done." Do you apply the same test to cryptographic algorithms?
- deleted 8y ago[deleted]
- LifeLiverTransp 8y agoRelephant xkcd in the room : https://xkcd.com/927/ https://xkcd.com/927/
- lpolzer 8y agoNow if only they would introduce something like Single Transferable Vote (entertaining CGPGrey video: https://www.youtube.com/watch?v=l8XOZJkozfI https://www.youtube.com/watch?v=l8XOZJkozfI), or another more effective voting system. Probably won't happen though, as it would seriously shake up politics as we know it.
- folli 8y agoMaybe they'll succeed were Switzerland has just recently failed: https://www.technologyreview.com/the-download/613107/a-major-flaw-has-been-found-in-switzerlands-online-voting-system/ https://www.technologyreview.com/the-download/613107/a-major...
- gsich 8y agoNothing beats paper.
- samirm 8y agoscissors does
- IshKebab 8y ago> Members of the public will also be able to use the cryptographic values to independently tally the votes to verify the election results so that tabulating the votes isn't a closed process solely in the hands of election officials. This sounds like they are using homomorphic encryption?
- jpgfunk 8y agoMax Kaye from the Flux party has been building a blockchain based one here https://github.com/voteflux/THE-APP https://github.com/voteflux/THE-APP It's open source and it's actually got a sound philosophy behind it. It's near completion and hopefully it'll change the way we vote globally (not just in Aus)
- ykevinator 8y agoThe Republicans will never allow this
- masswerk 8y agoThought experiment: Have, like in aviation, units built of two separate, but parallel architectures designed and built by unrelated, independent manufacturers with software written by independent teams in different languages and deploy them redundantly. (E.g., Airbus does this.) Now you have cranked up the cost for any manipulations to the requirements of successfully attacking two separate architectures in the same realtime timeframe, maybe at several redundant units at once. Leaving the message path. So you're still screwed. (Simply, because the win to cost ratio may be near to infinity. If we have concerns regarding personal messages, how could we possibly guarantee for this one?) Enter the paper trail and printers. – However, does anyone remember the Xerox scanner debacle of misarranged and falsely duplicated data by the compression algorithm, or the debates about Obama's birth certificate (due to image portions duplicated by the compression algorithm)? Things like these went unnoticed for years. What we may learn from this, a) there's no perfect system involving software, b) if we do not want to invest as much in democracy as we do in shuffling around a few people by aviation, how may we be worth it? Anyway, voting methods shouldn't be about cost reduction.
- grepper 8y agoFor those who were perhaps intrigued, as I was--here is a bit more information I found through a cursory search about how Airbus's consensus system works. Interesting stuff. [0][1] [0] https://aviation.stackexchange.com/questions/15234/how-does-the-airbus-flight-computers-voting-system-work https://aviation.stackexchange.com/questions/15234/how-does-... [1] https://aviation.stackexchange.com/questions/21744/how-do-redundancies-work-in-aircraft-systems https://aviation.stackexchange.com/questions/21744/how-do-re...
- masswerk 8y agoThanks for the complementary links! Regarding Xerox scanner compression issues, compare this great CCC-talk by David Kriesel, "Traue keinem Scan, den du nicht selbst gefälscht hast" [0] – Sorry, German only. [0] https://www.youtube.com/watch?v=7FeqF1-Z1g0 https://www.youtube.com/watch?v=7FeqF1-Z1g0 [1] http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_... (Didn't MS's PDF-viewer have similar issues?)
- systematical 8y agoFinally. I've been saying this for years, as I'm sure others have.
- weej 8y agoTitle is misleading. This is 3rd party contractor that won an RFP bid yo push out hard copy verification of ballot and voter's choice with some "DARPA techniques". Not quite the secure confidential system with data integrity I was hoping for. > We will show a methodology that could be used by others to build a voting system that is completely secure. This really feels like a Proof-of-concept or reference architecture, at best.
- weej 8y agoThat said, at least it's progress in the right direction (I Hope). We'll see how it turns out.
- rossdavidh 8y ago"This really feels like a Proof-of-concept or reference architecture, at best." I think that's DARPA's primary mission, though, isn't it?
- l00sed 8y agoCan anyone attest to this new system's engagement or possible effects on blockchain technology?
- cabalamat 8y ago> allow voters to verify that their votes were recorded accurately This sounds like it means it's no longer a secret vote and voters can be bribed or blackmailed to vote a particular way.
- themacguffinman 8y agoOnly if the voter is allowed to keep the receipt. The system could require voters to put the paper in a box before they leave like we do now.
- jacques_chester 8y agoYou know what has the best paper trail? Paper ballots.
- ebj73 8y agoSecure hardware sounds like the wrong idea, I think. I think the correct idea will be something more similar to block chains. A system where the security of the system lies in the ability for anyone to make a copy of the voting data at any point in time. So there will be multiple copies of the voting data, owned both by the authorities and by ordinary people. If the authorities try to tamper with the central copy of the voting data, it will be checked by the multiple copies owned by the general public. I think that's the general idea one should pursue. Not "secure hardware".
- magwa101 8y agoFinally
- andrewstuart 8y agoDARPA Is Building a $10M, Open-Source, Secure Voting System fact: DARPA Is Building a $10M, Open-Source Voting System ambition: secure
- chiefalchemist 8y agoNot to sound overly cynical but open source isn't a panacea. Yes, it adds transparency. That's a positive. But that doesn't ensure it'll work. As for secure, if it's connected to the internet, then it's always going to be a target. It seems to me, that - if voting integrity is priority #1 - a return to traditional analogue voting should be given strong consideration.
- asdf333 8y agoso awesome
- crb002 8y agoBad DARPA. Any centralized control is corrupting. You need analog and decentralized to make cheating costly to pull off.
- oldpond 8y agoFor a good chuckle, search Youtube for Diebold voting machines. LOL.
- zestyping 8y agoAnyone building or designing voting systems should first be familiar with the concept of _software independence_. https://en.wikipedia.org/wiki/Software_independence https://en.wikipedia.org/wiki/Software_independence It's an extremely important and useful concept, and should form the basis of the first question (or one of the first) asked of any voting system provider.
- Beefin 8y agoWhat I truly don’t understand is why we can’t vote with our phones in this age
- zanny 8y agoBecause you cannot verify your phone is not compromised at either a software or hardware level. You would need independently verifiable hardware and all software running on a closed system (ie, no third party modifications to running software which would mean at most a trusted sandbox for other applications outside the proven path) to be able to trust it to reliably take your vote. Thats on the order of correctness provability that NASA puts into launch vehicles but NASA doesn't have to contend with hostile actors seeking to undermine their software and hardware.
- rtkwe 8y agoTL;DR: hardware security, software security, authentication of voters, and the tech literacy of the average person. Because now instead of securing centralized voting locations and machines you somehow have to create perfectly secure software running on you Aunt Flourence's machine with 51 tool bars and 3 different bot nets installed and also make sure she can use it properly and securely. Oh also now you're accepting votes as bits over the internet giving nation states probably the juiciest target and the widest possible attack surface (see securing every voters computer). Even using something like the IME and secure enclaves to take the computation outside the the range of your average exploit it's still vulnerable to attack. Then even if you've perfectly secured the hardware and software you're just left with the largest login/key infrastructure problem of all time with the average voter having to understand how to not be tricked into not actually using your secured software and hardware environment...
- hello_tyler 8y agoThank god. Now this is a good investment. They should be getting 10x that budget though.
- known 8y agoI doubt it can fix https://en.m.wikipedia.org/wiki/Electoral_fraud https://en.m.wikipedia.org/wiki/Electoral_fraud
- myth2018 8y agoSounds good. But in practice it's complicated.. In Brazil we have been using electronic voting systems for 20 years. Since then, there's been absolutely NO EVIDENCE of fraud. Specialists are regularly invited to know the code and try to find vulnerabilities (the code wasn't open-sourced, and personally I don't think it should). And, even so, the losing parties ALWAYS claim there's been some fraud, and a significant part of their respective voters buy such discourse. There's been turnover of power pretty regularly in most parts, and even this doesn't stop folks of accusing electoral fraud. Last year, thanks Whatsapp, the debate's gained special contours. Lots of malicious people shared videos showing fake frauds, which were dismissed after some hours. There's been also lots of stupid people mistyping into the ballot and screaming around with a camera accusing a fraud. It was a bit of a mess and things tend to get serious in very tight scores, since there won't be a safe, auditable way of recounting the votes without having to fully believe in the government agency responsible for operating the system. The system makes the process extremely efficient. We are 100 million voters, voting is mandatory, and we always know the winners within a couple of hours past the end of the voting process. But..
- stankypickle 8y agoSecure voting system... right... I wonder how this will unfold... =/
- kajecounterhack 8y agohttps://www.youtube.com/watch?v=HVmHruNg6m0 https://www.youtube.com/watch?v=HVmHruNg6m0 This amazing talk by Ben Adida is really relevant. He has worked on solving voting for a long time now and does a great job here of breaking down some of the salient parts of the problem.
- specialist 8y agoI have the impression that Ben Adida is no longer advocating cryptographic voting technologies. Which is encouraging. https://www.usenix.org/conference/enigma2019/presentation/adida https://www.usenix.org/conference/enigma2019/presentation/ad...
- tomc1985 8y agoSurely it doesn't cost $10m to build a secure ballot form. Existing solutions have had so many obvious flaws that it seemed like e-voting companies weren't actually interested in accurately counting votes. They really need 50+ people to make a checkbox form and print the result?
- teawrecks 8y agoAllowing everyone to verify that their vote was counted as they intend is a start, but....I'm not saying it has to use block chain, but for its veracity to actually be openly verifiable, the voting ledger has to be publicly visible.
- exolymph 8y agoVotes can't be public. Leads to coercion.
- justanegg 8y agocastles and pitchforks is better
- fergie 8y agoEvery now and again you realize that US government actually does a lot of stuff right.
- keymone 8y ago$10M sounds like spare change for DARPA?
- westernculture 8y agoWoahhhh
- ataturk 8y agoI know it is being beaten to death, but a major issue with voting is the counting part. The counting is where the fraud is being perpetrated (and no, I'm not so naive to think it doesn't happen). Seattle. Minneapolis. Milwaukee. Detroit. Philadelphia. Broward County. And those are just recent examples. I think there is counting fraud from sea to shining sea. What are we going to do to make the vote counters less able to rig the vote and cease "finding" boxes of absentee ballots or whatever at the last minute with 99% precincts reporting?
- NicoN00b 8y agoIronic that an Oregon-based company is fixing voting machines, when Oregon has a paper-based vote-by-mail system that has encountered few problems.