13 ms·
What Happened with West Virginia’s Blockchain Voting Experiment?
- DanCarvajal 7y agoWhat other states are experimenting with memes?
- blaser-waffle 7y ago"We don’t really know—and that’s worrisome." Isn't the point of the blockchain that you always know?
- maeln 7y agoAs far as i understand, the software used ("Voatz") is a private blockchain and there is no public information about who runs what. As far as we know, Voatz could control all the peers in their blockchain making them able to change the vote as they please.
- mjparrott 7y agoYes, this. Voatz is holding a lot of power here and I can only imagine how well their solution is implemented. Do state or local governments even understand what they do?
- pavlov 7y agoDavid Gerard, a prominent blockchain skeptic who generally does his homework well, writes that Voatz is "running Hyperledger on four nodes [...] it’s just a single-user clustered database". [1] [1] https://davidgerard.co.uk/blockchain/2018/06/05/the-west-virginia-voatz-blockchain-voting-pilot-another-single-user-blockchain-as-a-database/ https://davidgerard.co.uk/blockchain/2018/06/05/the-west-vir...
- iamnotacrook 7y agoIf the blockchain is published can't people check 1) that the votes add up to the correct totals and 2) that their vote is reflected in the blockchain?
- lukeschlather 7y agoA blockchain (at least one used like this) is not the right tool here. Really, all you need is some sort of publicly-defined machine-readable representation of your vote that gets a digital signature locally on your device. You have an open-source app that can sign the vote payload. Then you send the signed payload to the server where it gets added to a plaintext repository. At this point it would be good to use a signed chain (like git for example) and at this point you "commit" your vote with a timestamp and send the result back to the client. (Commit hash and timestamp.) Then later, you could just look for the commit sha and timestamp. Of course this means anyone with access to your signature can see who you voted for. Which is a general shortcoming of signature-chain systems. Another way of doing it might be to have two different blockchains. One has signatures + votes and the other has only the signatures. The one with only the signatures is publicly posted, and the one with signatures + votes is privately audited. The trouble is deciding whether you value anonymity or integrity more. Of course, in this case it's not clear what the people involved value, since the blockchain is private and just a database that anyone can recreate from scratch at any time.
- maeln 7y agoYou could check that the vote adds up, but you cannot check that the vote are correct. Since Voatz is basically a private blockchain, there is no way to check that the blockchain was tampered with, or even saved the correct votes, before the it has been made public (which will be after the vote). The only way would be to have a mechanism for people to check if there vote was correctly saved at any point. And this is a very big problem, has having a way to know who vote for who in a democracy is a very very very big no no.
- magashna 7y agoWell you can't really know even if you go and submit a paper ballot. If you could verify your vote, you could sell it. I don't know if that's still a realistic scenario these days when Tammany Hall isn't literally beating people for votes, but it's a reason why you can't tie a vote to yourself individually.
- sarbaz 7y agoYou should check out Threeballot for a simple counterexample. The idea is that you xor together 3 ballots when you vote, but one of the three ballots is published. You have a 1/3 chance of catching manipulation.
- RL_Quine 7y agohttps://en.wikipedia.org/wiki/Helios_Voting https://en.wikipedia.org/wiki/Helios_Voting Helios does it far better, and way before all of this "blockchain" hype, no cryptocurrency required.
- TurningCanadian 7y agoThat's pretty neat. Are you aware of the weakness though? https://en.wikipedia.org/wiki/ThreeBallot#Broken_Encryption https://en.wikipedia.org/wiki/ThreeBallot#Broken_Encryption
- JauntyHatAngle 7y agoAlways know what? The initial point of a blockchain was to provide a mechanism for consensus in a system with multiple parties that lack trust for each other and with no Central arbiter. Can we access this blockchain to view the votes? No? Then it's opaque to us. It's a private blockchain.
- h4l0 7y agoBlockchain for voting sounds like a terrible invitation to a terrible party. Voting is already a delicate subject which is really hard to secure on information systems. Researchers have spent decades to figure out a perfect solution but came short. Blockchain has already surpassed its boundaries for multiple reasons. However, voting should be beyond that line. There are many questions that need to be answered before even thinking about using blockchain for voting. - How will identification work? - What is the proof-of-work scheme? - How can you be sure that every vote ends up in the ledger? Transactions usually get lost and sometimes takes few tries to reach to miner. - Most important property is that not a single vote should be traced back to its caster. Blockchain is all public, how are you going to anonymize everything? IP addresses of transaction owners are already open. Edit: Formatting.
- sarbaz 7y agoWhat are the problems with researchers' solutions? There are some very good ideas out there.
- malnourish 7y agoI'm not familiar with the problems OP is referring to, but from my reading, most issues, in both security and methodology, have revolved around implementation.
- deleted 7y ago[deleted]
- Spooky23 7y agoBlockchain doesn’t have to be all public and doesn’t require proof of work. You can have closed system blockchain schemes.
- RL_Quine 7y agoSo a system with trusted parties? Sounds like a database, so we can ignore the blockchain bit entirely.
- mjparrott 7y agoIt seems undemocratic to hide behind “proprietary technology” to describe the vote counting process. It’s a public process.
- jrumbut 7y agoJust use paper ballots. The only useful election technology is scantron. We do not need this. It isn't even a solution in search of a problem it's a problem in search of a place to explode. A rundown on some of their security: https://mobile.twitter.com/GossiTheDog/status/1026603800365330432 https://mobile.twitter.com/GossiTheDog/status/10266038003653...
- theseadroid 7y agoMany people can't afford to take the day off for voting. And even mail ballots are allowed, making the process easier would encourage more participation. Is this not a problem worth solving?
- jacobush 7y agoYes, it's worth solving. Here's another suggestion - make voting day a holiday.
- lalaland1125 7y agoThat's not actually possible in the sense that declaring a day a holiday doesn't actually prevent employers from giving people shifts. If anything, restaurants and stores actually retain more staff during holidays. The only people a holiday would affect would be people working high end jobs that probably wouldn't have issues voting anyways. Vote by mail and extended voting hours are much more effective solutions for people who otherwise couldn't find the time to vote.
- jacobush 7y agoFine, bring out the heavy law-making artillery then. Make it mandatory to give staff time off to go voting with heavy penalties for non-compliance and some kind of nice carrot for compliance.
- badwolf 7y agoAs well as early voting, and vote by mail.
- jimhefferon 7y ago> Voatz’s website states that “a paper ballot is generated on election night” and is tallied “using the standard counting process at each participating county.” What that means is the voter’s vote is sent to the county clerk staff as a PDF, and the county clerk staff prints it out and puts it into the scanning tabulator. ?So at some point your vote is printed out on a paper, and scanned? Doesn't seem all that anonymous, for one thing.
- yum_tasty 7y agoAn anonymous id is attached to the pdf. Not the users specific name/information. "The county clerks were able to conduct a pre-tabulation audit (unprecedented in US election history) by comparing anonymized copies of the voter verified digital receipts with the marked paper ballots prior to feeding the paper ballots into the scanners for seamless tabulation alongside the primary voting system."
- jimhefferon 7y agoCan you say more? How do the clerks know it is a voter from their district without a name, or other identifying information?
- yum_tasty 7y agoThis is the Voatz blog response to the slate story. It's where I got the above quote from. https://blog.voatz.com/?p=997 https://blog.voatz.com/?p=997
- jimhefferon 7y agoThanks. I don't get the anonimization. I live in a town of 5000, and I wonder how many overseas ballots the Town Clerk sees. Total speculation on my part, but it would not surprise me if it was 1.
- mobilefriendly 7y agoI live in West Virginia and anything dealing with the state government has to start with an assumption that it is being done for corrupt reasons. Ask first how a contract or project financially benefits key state officials or their family. I can't emphasize enough how predatory and corrupt the government is here. Both leading Republican candidates for governor are under federal corruption investigations. There's a reason West Virginia is losing population and remains among the poorest states in the USA. Where West Virginia isn't corrupt, it is incompetent. The state can't even provide safe drinking water for its people, or even create a framework for official electronic signatures-- it has no business innovating in voting tech. West Virginia is the last place you want as your laboratory for voting technology.
- duxup 7y agoI suspect the incompetence is by design to some extent. If you like small government, cripple it and then you've got an excuse to limit its reach and continue to cut.
- mobilefriendly 7y agoIt isn't really small government culture-- both Republican candidates were very recently Democrats (the state has flipped parties). It is more a pervasive culture of natural resource extraction and disdain for the public's health and safety. Probably a function of the "resource curse". https://en.wikipedia.org/wiki/Resource_curse https://en.wikipedia.org/wiki/Resource_curse
- no_wizard 7y agoWhat I find interesting after reading the linked wikipedia article is that the USA as a whole is not suffering from the resource curse. I wonder, just tangentially, because: 1. We are net exporters of many vital resources (food, in particular wheat and corn, is one I can think of off hand) 2. We have an abundance of natural resources and a wide variety of those natural resources to grow our economy 3. At various stages in history, we were basically the word's largest exporter of raw and manufactured goods and materials. Yet, we aren't classified as having suffered through this. Odd right? Or is my casual understanding just incorrect?
- apo 7y agoWhat little has been described offers plenty of attack surface. The white paper has this to say about how paper copies of votes are printed out: > When the polls close, members of each county clerk’s staff insert two cryptographically secure thumb drives into the vendor’s administrative portal laptop. Once the two thumb drives are verified, votes on the blockchain are automatically assembled as PDF files for each county. The Secretary of State’s office sends each county one PDF file containing all the marked ballots submitted by voters of that county. The clerk’s staff prints the ballots on cardstock with a ballot printer capable of printing up to 20” two-sided ballots (see Fig. 4). Each printed ballot contains the anonymous ID of the voter (see highlight in Fig. 5). Tabulation and the consolidation of results is done automatically by scanning the paper ballot into the precinct tabulator of the primary voting system (see Fig. 6). https://sos.wv.gov/FormSearch/Elections/Informational/West-Virginia-Mobile-Voting-White-Paper-NASS-Submission.pdf https://sos.wv.gov/FormSearch/Elections/Informational/West-V... How do the clerks get these thumb drives? What's the protocol for storage until used? Who has access to them? What physical security features do the drives implement? If I were going to attack this system, the thumb drives seem like a juicy target with plenty of social engineering opportunities.
- lucasrabreu 7y agoChuck Rhoades stopped it
- otabdeveloper4 7y agoPresumably, it went wherever all the other 'blockchain experiments' went.
- nebulous1 7y agoTransparency/verifiability seems like almost the only half-way decent reason to use a blockchain for voting. And then they do it using a closed source undocumented proprietary blockchain.
- josefx 7y agoUntil your boss fires you for not voting to the company line, of course not officially. Having a verifiable can turn into a double edged sword for many reasons.
- robomartin 7y ago"But how secure and accurate was the 2018 vote? It’s impossible to tell because the state and the company aren’t sharing the basic information experts say is necessary to properly evaluate whether the blockchain voting pilot was actually a resounding success." ...and that's when I stopped reading.
- dcolkitt 7y agoBlockchain is a buzzword, but we've already had strong cryptographic protocols for voting that predate Satoshi. We've known for decades how to conduct elections where every vote is provably counted, any individual vote is completely anonymous, and the identity of every voter participant is provable (i.e. preventing ballot stuffing). [1]https://en.wikipedia.org/wiki/End-to-end_auditable_voting_systems https://en.wikipedia.org/wiki/End-to-end_auditable_voting_sy...
- yum_tasty 7y agoWe've used horses for centuries... How dare anyone suggest that trains, planes or auto-mobiles could be useful.
- grepthisab 7y agoReally bad take. Blockchain offers no benefits to what provably worked in the past, whereas there are many advantages to planes, etc. over horses.
- yum_tasty 7y agoThat's completely inaccurate. 1. Every vote further secures the blockchain voting process. The only way to overcome this is with a 51% attack, so every vote cast further ensures the validity of the entire chain. 2. The chain can be public and anonymous, which gives every voter a verifiable way of understanding their vote. They can look and ensure that their vote was cast exactly as they intended, but it also allows administrators a way to review the votes. The core part that the article got wrong was that county administrators have a definite way of pre-tabulating as well as tabulating votes.
- rebuilder 7y agoThis seems so preposterous I have a hard time believing the story is being reported correctly. The state or Voatz are apparently unwilling to prove their system is secure. What are they going to do if someone disputes the results of the election?
- egypturnash 7y agoVoatz. Voatz. Yes, let's trust a bunch of people who think "Voatz" is a good, adult name for a tool for a crucial part of the process of democracy.