4 ms·
Ob: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref... E
by Roboprog 7y ago
Ob: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
E voting shouldn’t exist. How badly it was implemented is moot.
- dkarl 7y agoThis isn't e-voting. The job of this software was to accomplish basically the same thing as emailing some numbers to headquarters and entering them into a spreadsheet. Precinct officials reporting their results can (and should) check that the results they reported are the same results received at the state level. You can see from the results that have been made public [0] that the precinct numbers are very easy to check by hand, and the math to combine the results can and should be independently checked by, say, copy-pasting the numbers into an Excel spreadsheet. No trust required, none of the complications involved in recording and verifying individual private ballots. Even if the software was compromised, the incorrect numbers would be detected by independent checks — the same checks you have to do anyway to guard against data entry errors and typos in Excel formulas — and the correct results could still be calculated. There was no way a hack could have done anything worse than delay the release of the results, leak the results prematurely, or possibly induce the party to release some manipulated initial results if they were careless enough not to do any internal verification before releasing the results to public scrutiny. Everything involved in running an election can be done poorly. If we unconditionally rail against software being used at all, then sure, we can show off our clean hands when something goes wrong. But we accomplish nothing to stop someone who doesn't know better from hiring a contractor who, like in this case, doesn't do the job responsibly. This software should exist. It should be subjected to an independent security audit, thoroughly tested, supplemented with user training, and trusted only if the results are independently verified at every step. Which is to say, not really trusted. But it should exist. [0] https://results.thecaucuses.org/ https://results.thecaucuses.org/
- jakeogh 7y agoIt's electronic voting. "Votes in transit" (Scott 2019): Why Electronic Voting Is Still A Bad Idea: https://www.youtube.com/watch?v=LkH2r-sNjQs https://www.youtube.com/watch?v=LkH2r-sNjQs It's also a standard incrementalism tatic.
- dkarl 7y agoThese are not votes. These are public tallies that can be verified by anyone who was present at the precincts. > It’s also a standard incrementalism tatic This assumes the public is smart enough to make an informed distinction now but will lose that ability in the future.
- BoiledCabbage 7y ago> This software should exist. You just assert this. I see no justification in your post.
- dkarl 7y agoBecause this task is going to be done by software. If it’s not software built for the purpose, it will be email and spreadsheets, with more confusion, more difficult training, and more manual data entry (hence more data entry errors) and no improvement in security. Also it can immediately provide one calculation of the results and present the data immediately for others to replicate the calculations. The more quickly we get to this step, the more opportunity for independent verification.
- BoiledCabbage 7y ago> Because this task is going to be done by software. Again nothing about this says it has to be done by software. If you've already asserted it's being done by software, then yes it will be done by software. But if you don't have that assumption, you don't reach that conclusion.