4 ms·
> It's enough for the average voter to trust that some other people - independent experts - are able to verify the vote. I don't agree. This is plausible withi
by nihzm 2y ago
> It's enough for the average voter to trust that some other people - independent experts - are able to verify the vote.
I don't agree. This is plausible within a coesive electorate, but it feels like moving the problem. What guarantees that the experts are trusted by the voters? And more importantly, assuming that at some point the system (experts) is trusted, how is the trust in the voting system retained over time? (e.g. in case of disagreement over the results)
I have argued in another thread like GP that because the ultimate purpose of voting systems is to collectively take decisions, and because disagreements are very common when deciding, the system needs to be able to justify itself to retain the electorate's trust. Otherwise it will eventually be replaced by a different voting system (or tyranny).
A proxy for this is of course simplicity. If the voting system is clearly understood by everyone, it is more easy to persuade a losing party that the outcome is correct. Conversely, if a voting system needs high expertise to be understood, it is more difficult to bring everyone to agree on the result. So the latter is less robust than the former, especially if the disagreement is over a result that is close to a tie. A self-correcting mechanism is important to keep the voting system in place.
In appendix B of your thesis you raise an interesting point I had not considered.
> As an extreme example, consider the case where a voting system
lacks verifiability, is trusted by the public, and is compromised by a
foreign superpower: the people have lost their democracy and do not
even realize it. Compare that to a hypothetical case where a voting
system has perfect verifiability, thus can not be compromised (without
triggering a new election etc.), and, for whatever reason, is not trusted
by the people.
> Clearly, the outcome where people are suspicious of a perfectly
functioning voting system is superior to the outcome where people
are blindly trusting a compromised voting system. We hope that this
outlandish example is enough to support our argument that verifiability
is more important than trust.
The external threat is a very valid point but I do not think that this is sufficient to absolutely conclude that verifiability is more important than trust. If the system is rigged, it may eventually displease the electorate to the point that it will eventually be replaced.
Unless, the rigged system doesn't displease the electorate and is essentially a hidden benevolent dictator, which would be an interesting situation. Only in that case verifiability could unambiguously be more important.
- rraghur 2y agoExperts to verify but overall the entire system available for inspection to the populace at will (so open source, reproducible builds, verifiability) etc There will still be questions around compromised keys/secrets I suppose in this case paper ballots win
- baobabKoodaa 2y agoSure the people can overthrow a government with a revolution, but the situation deteriorating to that point is pretty much the worst case scenario I can imagine.
- nihzm 2y agoBut do you agree that there needs to be something that keeps reinforcing the collective trust in the voting system such that this worst case scenario is not reached? If so, do you have an idea what that something could be when using a complex e-voting system? The best I can come up is to educate the public, but that is almost wishful thinking. rraghur says in the siblilng comment that keeping the voting systme open via OSS / reproducible builds / etc could be a source of trust, but I don't think that is sufficient for most people. We need a stronger argument, and I don't have one.
- baobabKoodaa 2y agoOf course there needs to be some level of public trust in the elections. I think that trust could come from the E2E verifiability of the voting system, and related to that, trust in the ability of independent experts to verify that the election was conducted fairly. (When the result of an election is verifiable by third parties, there is no longer a need to audit what software is running on the official machines, so there is no need for reproducible builds etc.)
- nihzm 2y agoIt is possible, at least in principle, to have people trust that techonolgies such as E2E are secure and reliable. Indeed in some countries that is the case, but my point was slightly different. If you concede that we cannot have everyone understand (to take an example) E2E verifiability, then this technology cannot justify its own correctness to everyone. This means it is necessary to have a (possibly small) group of experts to educate / persuade the public that E2E verifiability actually works. But my point is essentially: why should they do it? There is no structural incentive for them to do so, other than the virtue of being a good citizen. There needs to be something that keeps reinforcing public trust. Self-evident systems do not require for this incentive structure to exist / be built. I fear that this could end up becoming akint to the erosion of trust in scientific evidence for political decisionmaking. Science was considered very trustworthy by most people at some point, but because there is little to no incentive for the scientists to inform the public about why what they do works (other than perhaps their personal desire to share the cool thing they are working on) and because scientific results are usually very complex there has been a pretty steady decline in trusting scientific evidence.