10 ms·
SF gets $1.5M to experiment with online voting, EFF others horrified
- mgsafari 5y ago[dead]
- Iefthandrule 5y agoThis lack of transparency, public oversight, and engagement seems to be a trend. I would love to hear how other cities have managed to steer their elected officials into community oversight. Financial influence cannot be the only option.
- pm_me_your_quan 5y agoThis is a terrible idea. Paper ballots work, are secure, and the processes are well understood. The value an attacker could garner via control over elections is enormous, so there's a big incentive to do so.
- deleted 5y ago[deleted]
- baggy_trough 5y agoPerhaps that’s a feature, not a bug.
- mgsafari 5y agoFaggots love to suck dick don't you know?
- verdverm 5y agoPeople will not trust voting systems they cannot understand the workings of. This is one reason digital voting should not be a thing.
- lrvick 5y agoImagine we start putting cryprokitties technology to better use. 1. Voter registration cards are manufactured with in the US with tight supply chain controls. 2. US based security researchers with a history of vulnerability identification are qualified and selected at random to hands-off oversee that manufacturing process is free of supply chain attacks. Firmware builds similarly are done deterministically on different platforms overseen by different security research firms, etc. 3. Electronic cards are picked up in person, at random, after traditional voting registration is complete. 4. Each card generates two subkeys via a KDF. A public "verify" keypair and unlimited private "vote" keypairs. 5. The user publishes a signed statement to a public database with their "verify" keypair including their real name and voter registration number. 5. Every election, a private "vote" keypair is allowed to sign a digital vote ballot to this public database. 6. Voters are required to view the public database at a later date to confirm their random vote keypair signed their intended values. They publish a signed statement that their verification was complete. 7. The vote is only considered valid when the the number of verified statements matches the number of cast votes, or after a cutoff time if the difference is not enough to change the outcome. 8. The vote database is forever public and can be counted and verified by anyone at any time. --- Yes there is some handwaving here but I really feel we have the technical tools to have provably accurate digital voting. This becomes possible when most citizens have enough education to understand and trust cryptography. That would require a generation of much better education. We should vote on that.
- throwaway81523 5y agoThis has no obvious advantages over paper ballots, takes nerds to operate, and fails the usual requirement that digital voting be receipt-free. https://duckduckgo.com/?q=receipt-free+voting https://duckduckgo.com/?q=receipt-free+voting
- lrvick 5y agoThe advantage is people could vote remotely, thus avoiding excuses about not having time or mobility. It also makes it practical to vote much more often allowing more direct democracy.
- 5y ago
- AutumnCurtain 5y ago1.5 million seems woefully inadequate for just the security element of a pre-established plan. > The internet voting project is, for reasons unclear, categorized under the Open Source Voting project, despite “open-source” not being mentioned in the grant paperwork, Jerdonek, an open-source voting proponent, says. Open-source voting technology uses public computer code to process paper ballots. It is unrelated to online voting. On Tuesday, San Francisco Supervisors began crafting legislation to conduct a long-awaited open-source voting pilot. This really concerns me.
- mgsafari 5y agoWhat about voting for an entire month without having to show id even though you have to show id to buy alcohol and cigarettes?
- onecommentman 5y ago1.5 M might be a nice number to start with as a bounty to anyone who demonstrably cracks the online voting system. Perhaps premiums paid if the vote tally numbers can be manipulated to be special numbers…pi, or a repeating pattern like 837-5309.
- ddingus 5y agoOptical scan is not hard, and is provable in election terms. As long as the record of voter intent is NOT electronic, the election can be hailed into court and sorted out worst case.
- vgeek 5y agohttps://xkcd.com/2030/ https://xkcd.com/2030/
- tester34 5y agoat Edge e-voting devices protected with military grade cryptography using elliptic lines, backed by blockchain based auditable backend and stored in webscale database via JSON over HTTPs secured by certified authority
- mgsafari 5y agoThis is a very un-democratic sick joke. You currently can't go anywhere without the SF vax pass. No bars, restaurants, gyms, nothing. YOU MUST SHOW VAX PASS EVERYWHERE! Yet, you can vote online? Without identification? We recently had a CA recall election and anyone could vote for a whole entire month. No ID - NOTHING! I personally received my neighbor's ballots whom I could've easily wrote in Larry Elder (obviously I dutifully returned to their mailbox). You must have id to buy cigarettes, alcohol, but to vote? Fuck it. The "officials" in charge of this should be arrested. Immediately.
- mgsafari 5y ago[flagged]
- ddingus 5y agoElectronic Voting has been proven to be untrustworthy. Increasingly complex systems featuring a mix of tokens and crypto have costs that exceed simple, human readable ballots and do not add any value. I can only conclude the driving force is to undermine democracy with what is basically a man in the middle attack. There is literally trillions of dollars in value there. Not exactly great for the disenfranchised. Vote by mail works and we should be using it.
- throwntoday 5y agoVote by mail is an equally awful idea. We should instead not have a single day to vote and allow people to cast their votes over the course of a week or so, with legislation for employers to give employees at least one day off to vote. Voting in person is the most fool-proof way of maintaining some sense of democracy.
- HelloMcFly 5y ago> Vote by mail is an equally awful idea. Based on what evidence, exactly? We don't have to argue hypotheticals here - it's been working great across multiple states for many years. > We should instead not have a single day to vote and allow people to cast their votes over the course of a week or so, with legislation for employers to give employees at least one day off to vote. Love all of these ideas too.
- throwntoday 5y agoThere should be no doubt in anyones mind regarding the validity of results. Things like a national voter ID, and being in person except for the most extreme circumstances where someone cannot physically be there, ensures that. It's been working great most of the time but it should be a system that always works. We don't need to speak hypotheticals, the news is fraught with articles about people not receiving their ballots, being told they already voted by mail when they go in person, people double voting, voting in someone elses name, etc.
- 5y ago
- HNTA_1 5y agoIf SF city was a person, $1.5M would barely cover breakfast and parking for a day.
- gjvnq 5y agoOnline voting should be limited to: 1) Open ballot elections. (e.g. lawmakers voting on a nomination) 2) Small consequences elections. (E.g. flag change) 3) "Non binding elections" (i.e. opinion polls with huge sample size and marketing) 4) Small groups of tech savvy people.
- redis_mlc 5y agoHow the US ended up using electronic voting machines is through ADA requirements, convincing state officials that they had to budget and choose one. That deadline was why it appeared they were all "upgrading" in lockstep. Note that Dominion voting systems, used by 26 states in the 2020 election, appears to be owned by the CCP.
- LinuxBender 5y agoIf there is going to be online voting, then at a bare minimum there must be a public anonymous API that can be used with the voters key material to validate their entire voting choices actual choices not counts so that random people at random times can validate that every specific detail they entered was not tampered with, even if this requires semi-technical people to validate, then fraudsters will know there is a risk of being caught. Even one invalid record must trigger an audit by a truly independent third party. Voter keeps a copy of what they submitted along with checksums and cryptographic signatures. Audit logs must be proven immutable with a chain of custody and attestation throughout the entire system. Even admins of the system must not be able to tamper with it even if their life depended on it. Look to vaulting appliances for some mediocre examples on how to start this process. This will need to be a better implementation than the vaulting appliances however and I can not imagine anyone building this for $1.5M. Whatever is built must be submitted to the public for penetration testing along with a large bug bounty program. Invite the best penetration testers from all around the world and encourage them to use whatever hacking and social engineering methods they can dream up and provide them with full legal immunity and a low bar to entry.
- manfre 5y agoThe ability to prove you made a specific vote will never happen. This is to prevent vote selling.
- LinuxBender 5y agoUnderstood. I've actually heard that before, though it does not change my personal belief that anything short of what I described is not a voting system. It has always been my opinion that every voting system in human history has by design been a facade. But that is an unpopular opinion. Buying millions of votes is risky at best. Hacking millions of votes is trivial if the system is purpose built to facilitate this. Every few years an engineer testifies before congress they were required to make the system weak and then the public quickly forgets because the higher priority is for the public to have confidence in the system. I do not know how to break the public out of this loop. Maybe this is how it is supposed to work.
- awill88 5y agoCan’t we just vote on a blockchain? With asymmetrically encrypted transactions? I mean perhaps elections should not be conducted online, but surely the integrity would be improved if governments were to require votes be tallied on a blockchain.. just a thought
- diveanon 5y agoIf only there were some means of establishing consensus via a distributed and publicly verifiable means. DAO’s are the future of governance, they are proven working in the wild and should replace the archaic systems we allow others to manipulate in the name of “governance”.
- bitcharmer 5y agoWhat are DAOs?
- diveanon 5y agoDecentralized Autonomous Organizations. They are a commonly used form of governance for many established defi protocols and networks.
- ddingus 5y agoFor reference, these are what are required for a just, trustworthy election: Anonymity. No voter shall be linked to a personally identifiable record of their vote intent. Freedom. Voters may vote or not. Transparency. A human readable, physical record of voter intent shall be recorded from each voter. This record is used directly for the final tally. Oversight. The law, means, methods, records, shall be performed and made available to the watchful public eye. The problem areas for electronic voting are: No linking of voters to expressions of voter intent. The record of vote cast. When voters express intent to a machine, the actual physical expression ends up as a smudge of grease on some input device. The machine interprets that fleeting expression used for the final tally. Any electronic vote is, by the nature of the technology, a vote by proxy thus placing voters in a position of forced trust, unable to require their actual vote record be hauled into court if needed, and the record is subject to manipulation the voter will have no knowledge of. Even worse? Voters cannot verify their vote record captured by the machine reflects their vote intent. The display may show them something, anything at all and who are they to know what actually got recorded, if anything at all was? Banking gets around this by personally identifiable transactions, double, triple records, receipts and other means and methods people can use to understand whether the right thing happened, and or was manipulated. Anonymonity denies us all these tools. The product of that is we really need to use a physical expression of the voter intent if we were to have any chance at all of having a trustworthy election. At the moment of that expression, the voter has a chain of trust between their own internal intent and the mark they made on the physical media. After that moment has passed it doesn't come again, and that is the one and only opportunity to correctly capture and then make use of voter intent in an election.