4 ms·
Oh, hi. I'm Mike Specter, lead author on the MIT report [1], and have been involved in other voting-related research projects [2,3]. LMK if you all have any q
by mspecter 7y ago
Oh, hi.
I'm Mike Specter, lead author on the MIT report [1], and have been involved in other voting-related research projects [2,3].
LMK if you all have any questions!
1. https://internetpolicy.mit.edu/wp-content/uploads/2020/02/SecurityAnalysisOfVoatz_Public.pdf https://internetpolicy.mit.edu/wp-content/uploads/2020/02/Se...
2. http://people.csail.mit.edu/rivest/pubs/PSNR20.pdf http://people.csail.mit.edu/rivest/pubs/PSNR20.pdf
3. https://www.belfercenter.org/sites/default/files/files/publication/StateLocalPlaybook%201.1.pdf https://www.belfercenter.org/sites/default/files/files/publi...
- dmix 7y agoThe article mentions: > The clients do not interact with the blockchain directly, so there is no blockchain verification code in the client. So if all client requests are routed through the same centralized API endpoint before hitting the blockchain, nor validated after the fact, whats the point of the blockchain? Just some public "ledger" of what the server ultimately sends out? Ideally, at a minimum, you would be given a token for your vote which you can then follow up and see it on the ledger. Even if you don't get to wait for 'confirmation', it's still a public signal that something is not right.
- mspecter 7y agoThat's a wonderful question. The honest answer is that I have no idea. In the version we reverse engineered, there's no proof of inclusion of any of the data in the blockchain in the client, and the receipt system was via a PDF. The vote selections (ballot?) are also never signed by the client. It's also worth noting that, according to the ToB article, the backend blockchain is a permissioned hyperledger instance, which runs PBFT[1] rather than proof of work. PBFT is controllable with roughly 1/3 of the network, 100% of which has been controlled by the company. [1]http://pmg.csail.mit.edu/papers/osdi99.pdf http://pmg.csail.mit.edu/papers/osdi99.pdf
- the_snooze 7y agoIs there any technical/security benefit at all to private blockchains? Or even more generously, lightly-mined public blockchains? It seems that in either of those scenarios, you lose the decentralized validation and consensus brought about by a bunch of people incentivized to compete with one another to burn electricity.
- nordsieck 7y ago> Is there any technical/security benefit at all to private blockchains? It really depends on what you want out of your blockchain. For example, the backend of git is essentially a blockchain. It's extremely useful, even for a solo developer.
- mspecter 7y agoTo push this further, I was working on a research paper with Ron Rivest, Neha Narula (head of MIT's decentralized currency initiative), and Sunoo Park (a wonderful applied cryptographer) on whether blockchains in general could be helpful in casting and tallying. We're skeptical. See: http://people.csail.mit.edu/rivest/pubs/PSNR20.pdf http://people.csail.mit.edu/rivest/pubs/PSNR20.pdf
- eyegor 7y agoBut if everyone used a public blockchain, with proof of work + user-level signatures for each vote cast, wouldn't it be far more auditable than any current system? Ignoring implementation details, reaching a point where anyone could have a way to audit that their vote was counted (correctly) seems very useful. Using this sort of model, it theoretically wouldn't matter who completes the proof of work as long as the results are audited.
- baobabKoodaa 7y agoYou don't need blockchain to enable voters to verify "that their vote has been counted correctly". Several cryptographic voting schemes already provide this feature (for example, Civitas and Floating Receipts).
- smacktoward 7y ago> whats the point of the blockchain? My bet would be: marketing. Blockchain is hot, blockchain is sexy -- at least among people who aren't really technically inclined. (The technically inclined passed over the blockchain hype curve several years ago.) There are tons of blockchain projects out there whose only real use for the blockchain is to be able to slap "now with blockchain!" on the sales materials.
- rsynnott 7y ago> whats the point of the blockchain Er... the word 'blockchain', obviously. Catnip to a certain type of VC.
- munk-a 7y agoWithin the article this statement was made > Trail of Bits engineers said Voatz' code was written intelligibly and free of many common security foibles, but added “it is clear that the Voatz codebase is the product of years of fast-paced development.” The summary goes on to list several technical flaws, such as a lack of test coverage and documentation, infrastructure provisioned manually without the aid of infrastructure-as-code tools, vestigial features that have yet to be deleted, and nonstandard cryptographic protocols. That honestly sounds pretty good in terms of software quality, adding additional tests for proofs and ramping up ops are both addressable problems - especially if handled by a government sponsored team. But... How confident are you that we could reach a well engineered and proofed electronic voting platform that also adheres to theoretical rules around vote security? And which component of that, adherence to theoretical requirements and perfected development practices, do you see as a larger hurdle to overcome going forward?
- mspecter 7y ago> How confident are you that we could reach a well engineered and proofed electronic voting platform that also adheres to theoretical rules around vote security? I don't think we can with the current commodity devices / ecosystem, even assuming that voting system software is well-written. Keeping electronic-only systems secure from nation-state level adversaries is hard.
- micimize 7y agoI understand that current solutions to electronic voting are unsatisfactory, but I am fairly baffled by: > It remains unclear if any electronic-only mobile or Internet voting system can practically overcome the stringent security requirements on election systems Like, we can adequately secure banking software. With proper considerations and processes for the problem domain (i.e. user follow up / validation, alerts on suspicious vote changes) I don't see why securely implementing electronic voting is considered near-impossible, and has so few advocates.
- roywiggins 7y agoMany bank transactions can be reversed, and the ones that can't can be covered by insurance or self-insurance. You can't practically speaking reverse a tainted election. Anyway, I'll let Tom Scott take it: https://www.youtube.com/watch?v=LkH2r-sNjQs https://www.youtube.com/watch?v=LkH2r-sNjQs
- mspecter 7y agoTo put this in short-hand: "We bank online, we buy all sorts of stuff online, why not vote?" The biggest reason is that banking and other financial transactions have a very different threat model from voting. In particular, voting requires a secret ballot. In addition to preventing an adversary from learning how you voted, a secret ballot requires you to be unable to prove how you voted, to prevent vote selling and coercion. So, unlike financial transactions, how you do validation / remediation of failures is very unclear. Ben Adida has a blog post with further thoughts here (https://benlog.com/2007/03/02/on-voting-banking-and-bad-analogies/ https://benlog.com/2007/03/02/on-voting-banking-and-bad-anal...).
- micimize 7y agoHmm, I hadn't fully grokked the facet of the problem domain. I guess you could give users a spoofing mode, that allowed them to fake any ballot / action. Or possibly, if there was a window of time in which they could change their ballot freely. Maybe making such features both secure and accessible would be nearly impossible though.
- 7y ago