9 ms·
The correctness of cryptographic voting systems is determined by their publicly observable behavior, not by their internal implementation. It's the protocol tha
by Strilanc 7y ago
The correctness of cryptographic voting systems is determined by their publicly observable behavior, not by their internal implementation. It's the protocol that's secure, not the specific hardware or software implementation. So the attack you're describing doesn't really apply.
- pauljurczak 7y ago"publicly observable behavior" is a bit of a misnomer - general public can indeed observe ElectionGuard in action, but it will not know what it sees. Fortunately, Microsoft advocates using paper ballots as a backup.
- sideshowb 7y agoCool, thanks for correcting me there
- deleted 7y ago[deleted]
- yorwba 7y agoHaving a cryptographically secure voting protocol doesn't protect you if the human-computer interface is compromised to alter the votes as they are being entered into the system. You get a code to verify that "your" vote was counted correctly, but because you're not supposed to be able to prove who you voted for to prevent vote-buying, you can't tell that the voting machine has slipped you the wrong code. It may not be an admissible attack in the model within which protocols are proven secure, but it's still an attack that could affect real-world systems.
- useerup 7y agoHomomorphic cryptography allows you to track your vote without revealing the vote content (who you votes for), but at the same time vote tallying is possible on the encrypted votes in a process that is verifiable. Of course the trust only comes with understanding of the mathematics.
- codedokode 7y agoBut you cannot observe it. You see that someone with a hash X has voted. How do you know whether it was a real person, a real person voting under boss supervision, a real person who actually didn't take part in elections, or just sysadmin inserting records into the database?
- couchand 7y agoThat question applies equally to a paper ballot.
- kazagistar 7y agoWatch person enter booth with fresh ballot, watch person leave booth with filled ballot, and check to see that person doesn't take pictures of their ballot. Seems pretty clear they voted and their vote can't be influenced.
- couchand 7y agoThough the article is light on details, it does seem to provide for an identical level of verification. I'm more than happy to be corrected if I'm missing something, but it sure sounds like they are proposing an effectively identical verification scheme.
- Faark 7y ago- You see the number of records aggregated, it should not exceed the amount of voters - You can somehow identify your own vote and thus verify it was properly counted - Everyone else can do the same, thus fraudsters would have to find a protocol weakness to add additional votes One attack vector might be whatever you use to identify your vote. Aka find a way to make two people think the same record is their own vote, then use the other yourself. This seems like a tricky problem, since everyone shouldn't just be able to see their own vote was included but also not not be able to show others how you voted. The article seems to indicate they solved this somehow, but I'm not familiar enough with the details / homomorphic encryption to understand that or even just trust that specific kind of encryption.