4 ms·
> "Using a blockchain cannot (ever) tell you if your vote was counted." What. By voting you commit a change to the blockchain. The system should report back y
by uasm 7y ago
> "Using a blockchain cannot (ever) tell you if your vote was counted."
What.
By voting you commit a change to the blockchain. The system should report back your "commit hash". Said hash is public (as is the entire blockchain), guaranteed to be unique, and counts towards the overall balance.
In contrast - a paper ballot can disappear. Your vote can be manipulated. All without any trace.
- newaccoutnas 7y agoNot in the system they used, it was private. As has been noted elsewhere, it would be trivial to have the majority of peers could be under nefarious control
- hanniabu 7y agoThat's a failure of their implementation. That doesn't discount every implementation. I feel too many here are too quick to dismiss alternative.
- specialist 7y agoIt's hard to directly compare the attack surface area of various systems. And yes, ballots have been disappeared, injected, etc. One of the prerequisites of Australian ballot election administration is having sufficient observers. But the same is true of any "trustworthy" process. Having studied this stuff for over a decade (now inactive), I believe, but cannot definitively prove that paper ballots cast at poll sites is the most robust against attack. FWIW, the election integrity community concurs. Security research and knowledge has progressed a lot in the last decade. It'd probably be worthwhile to circle back and apply the state of the art to this domain. (Alas, saving democracy doesn't pay very well, so it's unlikely that it'll be me doing the work this time around.)
- uasm 7y ago> "I believe, but cannot definitively prove that paper ballots cast at poll sites is the most robust against attack" Here's how a Blockchain voting system can work: 1. Person casts vote using a voting machine. 2. Voting machine commits a change to a publicly available blockchain. The commit includes metadata such as the actual choice you made. It can optionally include even more metadata, such as "place of vote", "timestamp", "gender", "age". 3. Your vote has been cast, and the blockchain has been been modified. 4. The voting machine prints a "receipt". Your receipt includes a "commit hash". You can use the hash to see, identify and verify your record has been registered with the blockchain. So can everyone else. 5. When the voting is done - a simple python scripts traverses the blockchain - counting how many votes were given to each candidate. This design ensures transparency and security. No compromises. You as an individual can know for a fact that your vote has been cast, and has been counted. As a society, we can finally verify and make sure our elections were fair game.
- the_snooze 7y agoNot a fan of the secret ballot?
- thenewnewguy 7y agoThe problem, I think, is that you couldn't prove votes weren't _added_, unless there's some smart way to solve this problem. Obviously you couldn't inject too many votes or the total would seem suspicious. But considering US election turnout varies you could probably get away with a few percent, which could easily swing a close election.
- jcrawfordor 7y agoCommon solution with existing precinct tabulators: each voter is issued both an anonymous ballot and a permit with identifying information. After marking the ballot, the ballot is inserted into the tabulator and the permit is retained in a file with the tabulator. At the end of each day, the number of votes recorded by the tabulator should match the number of permits, which contain the identifying information and so can be audited against the pollbooks. This same model can be extended to the blockchain approach, but isn't using a blockchain to solve the ballot-stuffing problem - just using a conventional paper technique.
- specialist 7y agoOur current system is the Australian ballot. Private voting, public counting. It's a battle hardened, field tested design which best balances the needs of society with the needs of the individual. Some future system may find a new balance. Perhaps that new system no longer demands a secret ballot. Because the risks changed. (Note that some jurisdictions require a secret ballot, so YMMV.) So if you want to supplant the Australian ballot with a different system, please start there. Explain the context, assumptions, risks, tradeoffs. Because piecemeal changes to our existing system, without regard for the whole, has caused a mountain of heartache. FWIW, I've been pondering "temporary privacy". Perhaps an embargo on all the election data for the critical time span. A friend of mine proposed (draft legislation) making all of the materials and documents available after an election is certified. For post mortem inspection. So you could feed all the ballot images into your own tabulator software. Or do your own signature comparisons. A huge change, because right now election data will be destroyed after certification (exactly when is per jurisdiction).