23 ms·
Blockchain voting is overrated among uninformed but underrated among informed
- somenewaccount1 5y ago*says the guy whom built and has significant financial interest to voting based networks.
- deleted 5y ago[deleted]
- KronisLV 5y agoCould it be that the informed and uninformed are simply at different stages of the Gartner hype cycle? https://en.m.wikipedia.org/wiki/Gartner_hype_cycle https://en.m.wikipedia.org/wiki/Gartner_hype_cycle The informed might now become fully aware of all the limitations and problems with it which might cause them to swing too far the other way, in contrast to their previous optimism. At the same time, however, being aware of these limitations hasn't become mainstream, so the uninformed have to go off of other information - marketing materials and hand wavy explanations of how blockchain will eventually be good for a large variety of problems. The truth probably lies somewhere in the middle, as it has with most technologies.
- tehjoker 5y agoWhile the US system is completely ossified and unresponsive to popular demands, proposals to make voting on everything both ignore the power dynamics at play, voter fatigue, and history. In the 1789 French revolution, they did try having votes to try to get more and more government officials elected after the overthrow of the ancien regime, but the votes were so frequent that people stopped showing up and the elections became barely legitimate. Other than that, software elections are prime for tampering, and even if they are determined to be secure by experts, suddenly the mechanisms of democracy are opaque to the masses and become untrustworthy. Making votes less understandable de-legitimizes them. Lastly, the reason for the ossification of American democracy is due to the fundamental oligarchical design of the 1787 constitution that explicitly saw mass politics as mob rule and feared it. They designed the branches of government as a series of baffles to counter popular sway over policy making, hence a Presidency that requires a vote so large they are responsible to no one in particular (though originally they were elected indirectly by electors), a Senate that was indirectly elected and designed to void popular proposals coming from the house, and a supreme court with lifetime terms that are totally unelected. As an aside, their theory of the separation of powers was that the elites would be mostly in agreement on fundamental issues and fight over control of the branches of government. They were in large part wrong, factions of opposing interests developed and managed to capture the entire government in cycles (so we are living in an edge failure case of the original design). This system, plus the domination of the economy by wealthy interests, first the slave owning planter class and later the capitalist corporate class, prevents and subverts popular democracy at every turn except where the public's preferences coincide with the real rulers. Voting is simply a preference expressed to the rulers. It doesn't in any way carry a mechanism for enforcement and enactment and is highly susceptible to all kinds of manipulation, especially when voters are individualized and do not deliberate in organizations and vote in blocks. If you want your voice heard, take to the streets and/or join an independent party that include non-electoral tactics such as strikes.
- ouid 5y ago>Needless to say, this entire post is predicated on good blockchain scaling technology (eg. sharding) being available. Of course, if blockchains cannot scale, none of this can happen. But so far, development of this technology is proceeding quickly, and there's no reason to believe that it can't happen. The reason to believe it can't happen is that it hasn't. like factoring large numbers.
- bpodgursky 5y agoI am inclined to believe Vitalik on this. He's been very intellectually honest and straightforward about where crypto tech is and is not progressing.
- dvt 5y agoFirst of all, this is an old article (also discussed at time of publication, I believe). Second of all, it seems to be a headline-grab during the "fake election" foment of earlier this year, and contains nothing particularly substantial. I will say, it's a bit funny that Buterin's thesis is "voting would become much more efficient, allowing us to do it much more often." This is just printed as apriori true (and good -- at least in a societal sense), but our democracy (at least in the States) is representative. In my heart of hearts, I'd love to believe that a direct democracy is the "best" form of government -- tangentially, this is the argument of most DAOs. Unfortunately, I just don't think this is true. Most people are dumb, easily manipulated (not coerced, as Buterin belabors). Dumb people voting all the time is a recipe for disaster. W. E. B. Du Bois makes a great case for this in his The Talented Tenth[1]. [1] https://en.wikipedia.org/wiki/The_Talented_Tenth https://en.wikipedia.org/wiki/The_Talented_Tenth
- mariusor 5y ago> voting all the time I don't think he's arguing that voting for a presidential election should be done all the time, but you can use this mechanism for voting on things that would be unfeasible to vote on with paper ballots. Local issues that can be voted by the whole citizenry instead of just a city council. Instead of voting for people that can make decisions for you, you can make those decisions yourself alongside all others who are interested. It seems like a pretty democratic idea to me.
- lalaland1125 5y agoThe whole setup of blockchain voting ignores the vast economic pressures at play here. Blockchains only work if the payoff for cheating the system is lower than the cost of PoS or PoW or whatever consensus mechanism is at play. The issue is that the results of major elections have truly massive economic consequences. A president of the US has a powerful say over trillions of dollars in funding. Meanwhile, total mining revenue for something like Bitcoin is "only" $18 billion per year.
- Stevvo 5y agoNo, because if there is a 51% attack, Everyone can see it.
- lalaland1125 5y agoAt that point, why use miners if you aren't relying on them for security?
- mariusor 5y agoLike I said a little higher in this thread, I don't think that the concept of electronic voting using a blockchain ledger needs to be mapped on the concept of cryptocurrencies. The way I'm thinking this can work is having an organization (the tallier) that creates ledgers for a particular vote (ie, a specific question being asked: Should our city allow construction on Lot A1?) The "voter" can submit a request to participate in this vote in an "enrollment" step. The success of this process leaves the voter with a public/private key that is known to the "tallier" (the public part) and allowed to vote but is not a direct way of identifying the "voter". In the voting period, the above key can be used by the voter to cast a ballot (a yes or a no in the example), the payload of the vote can not be decrypted unless you are the tallier, from the outside you can only see that a particular key has cast a ballot. The tallier can see that one of the enrolled keys has cast the ballot, it decrypts the vote and adds it to the tally. Once the voting ends, the tally is finalized and the ledger is closed and archived. Why does this require blockchain ledgers, you might ask. Because the information in the ledgers, the voting one and the enrollment one need to be public and at the same time tamper proof. If there's another technology that can offer that, maybe it should also be a candidate, but personally I haven't researched enough to know of one. :)
- space_fountain 5y agoI think the Tom Scott video on electronic voting from years ago remains the most convincing argument to me that it's a bad idea (https://www.youtube.com/watch?v=LkH2r-sNjQs https://www.youtube.com/watch?v=LkH2r-sNjQs). To summarize, even assuming you can solve properties like correctness, censorship resistance, privacy and coercion resistance. The fundamental problem with digital is that any exploit of any of these properties you ever have scales really well. Messing with a paper election requires a lot of people working together across the entire country. A digital hack just requires one smart person
- villasv 5y agoYet many rich democracies have been using electronic voting without issue. There’s an entire field of science and engineering for securing digital democracy, don’t take a single YouTuber as your source (ftr, I like Tom Scott’s videos too)
- SXX 5y agoWhat countries except of Estonia actively using digital voting?
- mariusor 5y agoPersonally I'm not convinced that an attack against an electronic ledger can scale in all cases. If the model of an electronic vote relies on individual keys having cast votes (following something like a vote enrollment), the attacker will have to spoof all those keys for the result to look authentic and at the same time be malicious. Depending on how those "keys" have been generated in the enrollment, this could be difficult to scale. The most basic premise would be that the "tallier" and the voter create this key together, and once committed to the ledger can't be tampered with by any of them. A vote must be signed with this key. The voter can override their vote at any time while the election runs. (This is something that I'm paraphrasing from the article actually) This does not scale as it requires a malicious actor to hijack enrollment and voting for a large number of voters. If enrollment is being done based on a physical device (eg, electronic ID card) it's even less so.
- smitty1e 5y agoI didn't read this thoroughly enough for much comment, but this jumps out: > But voting also requires some crucial properties that blockchains do not provide: > Privacy: you should not be able to tell which candidate some specific voted for, or even if they voted at all While the content of the ballot is sacred, the act of participating in the election cannot be. The pollbook is a database, with all of the security and maintenance hassle a database implies. As an election officer and ballot Luddite, I also think that elections argue for lower tech in the case of the ballots. Tech is swell (reponding on a a Galaxy Note 10+ here) but tangible ballots seem a hedge against shenanigans that no multi-page mathematical proof of block-chainy grooviness can penetrate.
- aazaa 5y agoThis article reminds me of every other article I've seen about blockchain voting. None of them start with a threat model. None of them talk about what's broken with voting. Mostly they just dive into technology, relying on the reader's imagination to address these points. Here are some simple questions: 1. What are you trying to protect in a vote? 2. Why can't an SQL database with whatever levels of cryptographic assurance you'd like to add do the job? 3. What does a blockchain add to (2) that no other technology does, regardless of cost? These questions are never answered, and indeed they are not answered here either. Instead, these articles lead with technology and rarely get around to what matters. Often there's something like this included in the article: > Blockchains are a technology which is all about providing guarantees about process integrity. If a process is run on a blockchain, the process is guaranteed to run according to some pre-agreed code and provide the correct output. No one can prevent the execution, no one can tamper with the execution, and no one can censor and block any users' inputs from being processed. No. A block chain is a timestamping mechanism. Within certain very narrow boundaries, it makes certain guarantees about the relative ordering of events. A tamper-resistant log file? Yes. A solution to voting? Does that involve relative event ordering? If so, is that the central problem? Electronic cash systems like Bitcoin will work work just fine without a blockchain, provided they can solve the double spending problem. Bitcoin solved it with a system for ordering transactions based on proof-of-work. There are other solutions, but all suffer from censorship pressures in ways that Bitcoin does not.
- JadeNB 5y ago> 3. What does a blockchain add to (2) that no other technology does, regardless of cost? Not defending blockchain, but this seems like an absurdly high standard. To me, the cost of a technology is definitely one factor in evaluating what is better or worse for solving a given problem.
- wccrawford 5y agoI somewhat agree, but with the amount of money that has already been spent on failed electronic voting systems, I think "regardless of cost" is pretty accurate here.
- 5y ago
- ggm 5y agoNon repudiation and transactional sequencing and public Ledger, no problem. Merkle trees, no problem. Block chain is instant problem. It's just crap marketing of fundamental concepts that we need and do use. It's like confating good statistical methods with marginal use cases for the techniques.
- jdavis703 5y agoMost people understand that you can trade speed or quality. I do not understand why the uniformed public thinks learning about potentially inaccurate election results quickly is preferable to accurate election results slower.
- nemetroid 5y agoI'm happy that this article recognizes the need for coercion resistance. But the second problem is stated too weakly: the issue isn't that voting software is insecure, it's that it's too complex. You could convince a person who doesn't know how to read that paper ballots are a working system (vote box is empty; votes go into box; box is emptied and all votes tallied). Only a small fraction of society could be convinced of the correctness of the tallying scheme in Fig. 2. You could argue that there are a lot of facets of modern society that the average citizen doesn't understand the details of, but voting is the cornerstone of democracy. Public trust in the voting system is crucial. The only way to reliably achieve that is through an understandable system, and so far the only understandable voting system I've seen is paper ballots.
- SubiculumCode 5y agoI agree, and I am no Luddite. The voting system cannot cryptographically secure, but beyond the comprehension of the majority of the populace.
- nuerow 5y ago> the issue isn't that voting software is insecure, it's that it's too complex. That's a great point, and quite understated. However, perhaps the key factor is not complexity itself, but being able to be trustworthy and transparent enough to ensure that the whole process is unquestionably fair. If anything, recent events demonstrate that, even if elections are free and fair, electoral systems can and will be attacked with the goal of casting doubt on the outcome to try to subvert its results. Any part of an electoral system that relies on non-trivial processes that are not easy to explain, understand, or verify is a part of the process whose credibility can and will be attacked.
- henrikschroder 5y agoIf you've followed the entire "voting fraud" debacle of the 2020 presidential election, there were an absolutely brutal amount of outlandish ideas of how the vote was manipulated using technology. Something something satellites and the Vatican and CIA killing people over a briefcase in Frankfurt and Hugo Chavez' spirit and Dominion voting machines and the router logs and mysterious traffic and Chinese IP addresses and god knows what else kind if idiocy was dreamed up. But all of that, every single crazy piece of it, is completely irrelevant, because at the end of the day there exists a collection of paper ballots that represent how people voted in the election. Anyone can count and recount those ballots to their hearts content, and doing so is incredibly simple. You just divide the ballots into piles according to what their vote is for, and then you count the size of the piles. Anyone can do that. Children can do that. Senior citizens can do that. No technology required, no technological understanding is required, and no technological bullshittery can cast uncertainty on the result, as the Arizona fraudit hilariously discovered when they divided the paper ballots into piles and counted them and got the same result as before. The way to solve the problem of untrustworthy technology is not to have some geniuses come up with a bulletproof crypto-secure blockchain buzzword voting scheme that us mere nerds can understand after having it explained to us. The solution is to remove technology completely from the equation, and paper ballots and envelopes and urns are the way to do that.
- a-dub 5y agoi've always thought the way to do this would be to combine paper based ballots with multiple counting apparatus that are operated by the competing parties and the state. i fill out my slip and i run it through the red machine, the blue machine and the county machine. they all display a hash/sum of the total counts thus far, i verify each machine has the same thing on its display, i put my paper into the lockbox at the end and done. then when the election is over, the counts agree or they don't, and if they don't there's a big public rescanning. of course the big threat is coercion. if one of the parties put a camera on their machine that sees me put my slip in, or they're counting ballot sequences, they can match my vote to my identity... but... since each party has representatives present to watch over their machines, they also can also check the machines of each other for those sorts of things. (ops and election watching become one and the same) it would just be cheap document cameras and socs with open source software. totally doable, i think. you could even have like, different hardware architectures for each group if you wanted to protect against nationstate level hardware attacks. also, i'm sure there are things in that rich literature of voting crypto that could also help with obscuring voter identity... but hey, this would be a good start. it's not blockchain, but it takes one of the biggest ideas from cryptocurrency, i think. (double/triple entry accounting)
- alistairSH 5y agoThis is (very roughly) wheat we do now on most US elections. There are reps from all parties involved in manual counting and dispute resolution.
- a-dub 5y agosure, but there's this notion of "oh the election is crap because shady things happened in the back room." if you have three counts, which shouldn't get out of sync in the first place, then the margin for contesting the election shrinks considerably! although, of course, there is no technical fix for someone who trolls the process if they don't get what they want. i do think there's value in making it feel a lot more like there's less blind trust in times of contentious elections though. maybe it would just be theater and not really achieve much more than what we have today in terms of real security, but if by showing realtime hashes of the counts that agree as a voter scans their votes in each machine, especially if one of those machines is operated by people they trust, increases trust in the process, then it seems a great net win.
- knownjorbist 5y agoHN's perception of what's going in the decentralization and crypto sphere - commonly grouped under the "web3" moniker - is startlingly out of touch. There is incredible engineering going on and I know it's hard to see past the cryptobro noise, but the cypherpunk thing we all fetishized in our early years is happening _now_, not in the 80s and 90s.
- SXX 5y agoI am actually involved in web3 app development, but do you have any examples of where any of this engineering even applyable to real world problems? I see a lot of potencial, but so far only real use I see is crypto being good financial system replacement for people living in failed state / authoritarian regimes. It's enough to justify it's existence, but who suppose to want web3-powered tech in countries with working law? And why?
- knownjorbist 5y agoI think decentralized identity has a lot of potential. Using a web3 app was kind of an eye-opening experience to me - I didn't make an account, and the developer of the app isn't managing the data involved. There's tradeoffs here from a usability and security standpoint(now I'm responsible for everything and nobody can help me if I lose my keys). But I think this stands some existing preconceptions about the way the web _has_ to work(just because it always has worked that way) on their head.
- acdha 5y agoThe three questions I always ask for an identity solution: 1. What's the barrier to using your app? Past experience suggests that large numbers of people will drop off as difficulty ramps up unless you're either giving away money or gate-keeping something people have to use (e.g. your insurance company's signup process can be terrible up to the point that you switch). 2. Who handles impersonation? (e.g. how do you keep someone from making the news by registering “donaldjtrump” and posting something?) 3. Who handles user error or compromise? e.g. if my phone or laptop is stolen, how screwed am I?
- heavyset_go 5y agoBlockchain voting is how we get a world where no one trusts the results of elections because very few people have the knowledge and experience to understand and audit such a system. Should an election be called into question, suddenly the public must rely on only a handful of oracles that can interpret the votes and assure everyone that everything is fine because of "crypto" and "blockchains". With paper voting, anyone who can count can participate in a recount or audit. In comparison, there are multitudes more experts who can audit an election via paper votes. > Over the long term, insisting on paper permanently would be a huge handicap to our ability to make voting better. One vote per N years is a 250-year-old form of democracy, and we can have much better democracy if voting were much more convenient and simpler, so that we could do it much more often. I'm not willing to sacrifice trust and the easy ability to verify elections, or hand control of democracy over to technologists, just so we can vote via apps on our phones.
- tshaddox 5y agoOf all the complaints about blockchain voting this seems to me like one of the least valid ones. People don't have the slightest clue how traditional vote counting and recount procedures work until sometimes goes wrong and it makes the news, and at that point it's literally impossible for the average citizen to do any form of auditing whatsoever.
- heavyset_go 5y ago> People don't have the slightest clue how traditional vote counting and recount procedures work until sometimes goes wrong and it makes the news And yet we can pull almost anyone off the street from both sides of the political aisle to participate in a non-partisan recount or audit and have it work out, which is what happens. We can't do that with blockchains.
- tshaddox 5y agoSure, but it's still a tiny portion of people who can be chosen to count the votes, and each one can only verify that they themselves have counted accurately.
- deleted 5y ago[deleted]
- LinuxBender 5y agoI will be the odd one out, but I am not sold on the idea of blockchain. Unless something has changed radically, blockchain depends on trusting the entities that host the ledgers. Creating shell organizations that appear to be separate entities is one of the oldest cons. For me blockchain adds nothing but complexity and greater risk of obfuscation and deception. For me a better system would be something closer to the certificate transparency system. There should be a way I can match something I know + something I hold to a cryptographic log entry that is publicly available but not reversable to my identity. If I dispute my vote record, I can challenge it using my secret information and quickly expose that my votes were tampered with. All of that said, our current systems are possibly the worst convoluted highly-hackable-by-design systems. Engineers have testified before congress that they were told to make them weak intentionally. This just leads to engineers being silenced. Pen-testers get in trouble for exposing these systems being intentionally weak. It feels like this is the desired end-state as it just keeps happening.
- 13415 5y ago> If I dispute my vote record, I can challenge it using my secret information and quickly expose that my votes were tampered with. How can a legitimate challenge be distinguished from one by malicious actors who want to nullify the election even though their votes were counted correctly?
- LinuxBender 5y agoBecause this isn't a count. This is a signature that can be verified with my data as my entry along with a series of hex codes that represent each voting item and selection. A tiny python script could be used in conjunction with the key material to quickly see if the public record has parity. Any citizen can verify their data. If even one record has been tampered with, an audit is invoked.
- JanisErdmanis 5y agoThis is a great point. Often this issue is not raised due to necessity of coercion resistance which prevents voters to prove how they voted. In absence of such requirement voters may as well be able to issue a message which invalidates the vote and can be collected by a third party. Then the invalid votes tallied collectively could be used as legitimate reason for nullifying election result.
- michaelmrose 5y agoWere we willing to give up the secret ballot we could vote online trivially with any device with the benefit of a hardware token to prove your identity. We could then publish the results of everyone's vote with the help of a plain Jane web server and database and verify the integrity of the election by polling a random sample of people to ensure their published vote matched their vote while allowing anyone who wants to change their vote prior to certification to do so. Results at certification would be in exact accord with the people's votes it would also be massively corrupted by undue influence of ones neighbors, family, employers, spiritual leaders, anyone with the money to buy votes, and so forth. I do not understand how we could maintain a secret ballot and rely on a public registry of votes even if turning public vote into actual results required a secret. I also don't understand how the public could be sure that such results weren't silently corrupted even if it could in theory work.
- sparkie 5y agoAll "blockchain voting" ideas miss the real threat model: Who issues the ballots, and how can you possibly know that Sybil has not been issued many? No blockchain is going to solve this. Not ETH, and not Altman's Eye scanning surveillance coin. At best a blockchain voting system can be used to audit that your own vote has not been tampered with, but you cannot possibly know who every other voter is to assert that Sybil has not voted more than once. Get real.
- JanisErdmanis 5y agoOne of the most common faulty belief in voting system proposals including those considered in the article is that it is that it is fine to trust elite that the system is working as specified. This assumption goes long before any cryptography were considered and is just more elaborate version of Edison's voting machine. Newer designs have recognized the need to prevent authority to know who voted for what. However in doing so they do obstruct the evidence that a legitimate voter had voted at most once. Often the evidence includes either to trust the system or officials with confidential access who can audit the system which can be meaningful if the system is software independent. However then we are left with problem that auditors may collude... In the end the system is very expensive to maintain and ironically state elections have been more expensive than voting with a paper ballot schemes. The net result is that elections electronic voting systems are equivalent to a single ballot box which is supervised by a small elite. The electronic part just have made it possible. In this absurd reality we may as well substitute elections with taking surveys.
- acomar 5y ago> A blockchain is also a k-of-n trust model; it requires at least half of miners or proof of stake validators to be following the protocol, and if that assumption fails that often results in a "51% attack". So why is a blockchain better than a special purpose bulletin board? The answer is: setting up a k-of-n system that's actually trusted is hard, and blockchains are the only system that has already solved it, and at scale. Suppose that some government announced that it was making a voting system, and provided a list of 15 local organizations and universities that would be running a special-purpose bulletin board. How would you, as an outside observer, know that the government didn't just choose those 15 organizations from a list of 1000 based on their willingness to secretly collude with an intelligence agency? just admitting you have the same problem then trying to brush past it doesn't work. why on earth would intelligence agencies allow anyone but groups they can influence or outright control to be miners and why should anyone trust that this isn't the state of the system? you're solving the wrong problem. you can't technology your way out of political problems: those still need to be hashed out between people.
- joshspankit 5y ago“My answer is simple: voting would become much more efficient, allowing us to do it much more often.” This here is (I think) the key to fixing democracy. If the citizens can vote on not just the leaders, but every long-term decision faced by the country, then we’d see people become far more invested, and much less likely to divide on party lines that are essentially grey areas anyway.
- henrikschroder 5y agoNo, you get the opposite: Voter fatigue, and in the end only the cranks show up to vote for their pet issues.
- joshspankit 5y agoMaybe, but remember we’re not talking about making people show up. What I’m imagining is a bit of a utopia, but: - Voting from a personal device that every citizen can use problem-free, no matter where they are - Clear language about what the choices are, and what will be affected - Open and available clear-language information for people who choose to dig deeper - Ways to discuss the pros and cons without being subject to scrutiny or chilling effects Yes people could still get fatigued. But I suspect much less so than they are by a vote that happens every 4 years and does not let them participate in the stuff that moves fast.
- henrikschroder 5y ago> Voting from a personal device that every citizen can use problem-free, no matter where they are Which means there would be no protections against vote coercion or vote buying. > But I suspect much less so than they are by a vote that happens every 4 years and does not let them participate in the stuff that moves fast. The problem is that there's so much of politics that moves fast, but is also incredibly boring and irrelevant for the vast majority. The whole point of representative democracy is that we elect representatives that have the same values as we do, and then we let them deal with all the boring crap so that we don't have to. The mistake you're making is assuming that everyone would be equally interested in every single issue that came up for a public vote, and that is just simply not the case. Just look at California that often have referendums on the ballot, and what an incredible shit-show those usually are.
- bob229 5y agoBlockchain is the answer to nothing, it is absolute trash with no use case except for cranks and criminals. Stop wasting our time
- aneutron 5y agoI started reading the article with a pitchfork in my hand ready to shout "BUT THE 51% ATTACK", only to be very slowly disarmed by a very reasonable argument. That being said, I still share the sentiment of some of the commenters here, whereas the complexity of the operation has the potential to derail the whole democratic process. Even with paper ballots, the U.S.A already has almost half of its voters going into frenzies about how the "process" cannot be trusted. That is, the process of reading check-marks on a paper and tallying the ballots, which is almost primitive compared to the protocols the article is suggesting. If we were to use a complex suite of protocols, we could easily have another "vaccine" situation, where again almost half of the U.S.A. don't want to get the vaccine because it's "too complex to know if it's safe" (despite the basic building blocks of it being understood and having almost universal use). I do wish I could vote from my phone, or from my computer though. That would be awesome.