6 ms·
Internet voting has two essential, unpatchable vulnerabilities: voters cannot vote anonymously and are exposed to external pressure. That's why we have voting
by makeitsuckless 12y ago
Internet voting has two essential, unpatchable vulnerabilities: voters cannot vote anonymously and are exposed to external pressure.
That's why we have voting booths: so people are guaranteed to be able to vote without someone looking over their shoulder (or pointing a gun at their heads).
If people cannot vote in total freedom and anonymity, it's not a truly free and democratic vote.
We should stop trying to "solve" everything with technology. Some things should be "hard", because it's essential to get it right.
- codeka 12y agoThat would be a problem if internet voting was the only option, but surely if the "normal" way of voting was still to come in to the polling place on the day and cast a paper vote, then online voting as an option for people who are unable to make it to the polling place on the day is not a bad idea?
- xroche 12y agoHow do you solve the coercion problem ? How do you solve ballot corruption (ie. I'm selling my vote on ebay) ?
- tomjen3 12y agoCan you do that even now? I can trivially bring a cellphone into a voting booth and take a picture even now.
- the8472 12y agoThat picture could be shooped, therefore it does not provide proof to the coercing party. The threat model for coercion-resistance is providing proof to someone after you have cast your vote. The threat model for anonymity is that an observer - either a 3rd party or someone colluding with the voting authority - that does not have access to the voting client itself. Voting-at-gunpoint coercion as threat model cannot really be defended against because it basically implies that the attacker has full control over the voter. Even some scheme that would allow vote retraction/recasting wouldn't help since the attacker could simply keep threatening the voter until the election is over.
- pjc50 12y agoThis is illegal in the UK, although not enforced: http://www.halsburyslawexchange.co.uk/election-day-selfies/ http://www.halsburyslawexchange.co.uk/election-day-selfies/
- shawabawa3 12y agoWe already have postal votes, don't see how internet votes would be worse
- chasing 12y agoLet's say I'm trying to force you to vote for my candidate. Am I going to be happy with you taking the option of going to the polling place to vote privately? No. You'll do it right here where I can watch you click the button for my guy.
- codeka 12y agoCoercion is a problem even with paper ballots, though. I could force you to take a picture with a cell phone of who you voted for on threat of violence.
- weland 12y agoThis. It's pretty common practice around some parts of the world.
- tveita 12y agoAny modern voting system should provide deliberate protection against this by letting you claim to have voted for any candidate. Let's say you're in the voting booth and have taken the picture. You can then do at least one of the following: - Exchange your ballot for a blank one and fill it out again - Fill in the check box and vote for your real candidate - Spoil your vote
- fiblye 12y agoI think mail-in ballots are the best option. Oregon does them, but I'm not sure what other places do. Every voter gets a ballot mailed to them far in advance of election day along with a booklet outlining the benefits/consequences of measures we're voting for, what each potential representative wants to do, etc. You can take the time to research all available options and make an informed vote, then mail your ballot in at your convenience or drop it off at any library. Far, far better than having to get up early in the morning and being around people who might attempt to grill you before/after you vote. Less chance of votes being manipulated since there's a paper trail, too. I really don't know why the rest of the US doesn't do it this way.
- pjc50 12y agoThat's definitely a "head of household can enforce votes" system, and in countries without strong ID systems is especially vulnerable to creating nonexistent voters. Edit: relevant link on insecurity of voter registration in "the United Kingdom's shambolic electoral system": http://www.bailii.org/ew/cases/EWHC/QB/2013/2572.html http://www.bailii.org/ew/cases/EWHC/QB/2013/2572.html
- fiblye 12y agoSure, but you need to sign your ballots, and if someone's forcing you to sign your ballot or forging your signature, it's a crime. There's far less social pressure when you can fill out your ballot whenever and wherever than needing to line up somewhere and deal with the social pressure of voting "properly." No method is perfect, but I think the issues with mail-in ballots are nowhere near as bad as the problems voting booths present.
- pjc50 12y agoWhat social pressure is there in the voting booth? What do you mean by voting "properly"?
- underwater 12y agoIs that really a problem? There's nothing stopping anyone from pointing a gun at my head and demanding I transfer all my savings to their account. That would have more impact on my personal wellbeing than someone stealing my vote. But we don't ban internet banking.
- atlantic 12y agoIf somebody steals your savings, one person is affected - you. And while pointing a gun to one person's head will work, it won't scale. But if somebody works out how to steal an electronic vote, such a solution is likely to scale, and to compromise the outcome of the election, which would have a massive collective impact.
- grrowl 12y agoPostal voting has two essential, unpatchable vulnerabilities: anyone can open an envelope and can be exposed to external pressure. People are exposed to enough pressure just by virtue of having to interact with politically passionate people just to get to the booths. In many cases, they don't check photo ID, just evidence of enrollment. At very least, I'd like to see internet voting implemented without low-hanging security issues, enough confidence in their implementation to open-source the code, and with the backing of security researchers and organisations like the EFF. At least if we had issues like guns being pointed to heads and potential invalid double-votes, we could discuss them in the context they deserve.
- atirip 12y agoIn Estonia the pressure issue is solved. One can vote as many times needed. When first vote was given under pressure, one can vote differently later. As many times is needed. Internet voting is not possible on the voting day, only before. That assures that when one has no possibilty to vote without pressure in internet, one has possibility to vote traditionally. Traditional vote overturnes e-vote.
- tomjen3 12y agoWhats to prevent the government from checking who voted what then later on then?
- atirip 12y agoThe best answer to this is probably that "the government" could run DNA tests on all the paper votes too...
- pjc50 12y agoDoesn't need to be that complicated. The UK system has a (paper) record of ballot paper numbers.
- jacques_chester 12y agoThe difference is that this would cost hundreds of millions of dollars and require a flawless conspiracy of thousands of people. Versus one guy and a SELECT statement.
- atirip 12y agoYou do not have any idea whatsoever how those systems are built, do you? Everything is logged, and logs changes are logged and logs change logs are logged and all those logs are signed and when the logger looses connection to loggable, then this is logged too and that is logged too. And finally. The interest of knowing of who voted who is virtually zero. I admit that the principle of anonynous voting is good and needs to be guarded, but the real harm of leak is virtually zero too. The most bigger threat is manipulation of results.
- baddox 12y agoThe government could promise to maintain anonymity for online voting, and it wouldn't be any more or less believable than for in-person voting. It would be trivial to subtly mark ballots to track who voted for what, or heck, even hide cameras in the booths.
- the8472 12y ago>voters cannot vote anonymously Is it information-theoretically impossible to devise a cryptographic protocol that allows all the desired properties of voting (verifiability, anonymity, preventing double-votes, ....)? I recall that there exist some protocols that provide at least some of those. If it's not impossible then it's not unpatchable. Someone just has to come up with the right method to do it.
- janpieterz 12y agoCould you elaborate a little bit more on those protocols that you mention? Massively interested in those!
- the8472 12y agoI've mostly read about them in passing, but a quick google search turns up some results. They seem to rely on at least partially homomorphic encryption. https://vote.heliosvoting.org/ https://vote.heliosvoting.org/ ftp://ftp.inf.ethz.ch/pub/crypto/publications/HirSak00.pdf http://www.inf.unideb.hu/~ahuszti/papers/5142-Huszti_megjelent.pdf http://www.inf.unideb.hu/~ahuszti/papers/5142-Huszti_megjele...
- janpieterz 12y agoSweet, thanks for the effort!
- moopling 12y agoInterestingly https://vote.heliosvoting.org/faq https://vote.heliosvoting.org/faq gives the answer no to "Should we start using Helios for public-office elections?" on the grounds the people's computers are too easily compromised for this to viable. So perhaps the issue is not the protocol at all?
- the8472 12y agoaccording to the technical paper they don't even attempt to provide any form of coercion-resistance, so that would already fail one of the criteria usually required of public elections. But yes, computer security certainly is a problem. But I think it's not intractable. We manage to get online-banking to work with acceptably low compromise rates despite huge monetary incentives to attack them. So maybe if they handed out small, non-personalized cryptographic devices (similar to TAN generators) that can do all the essential operations and talk to a smartphone to retrieve a ballot and submit the vote then e-voting could work. It would essentially be your own little portable voting booth. It's important though that the device should be separate from the key used to vote, so you could swap devices and re-cast your vote if you consider it compromised for any reason.
- tomjen3 12y agoNormally I would agree with you, but only if we insist everything has to be completely over the internet. If we make it so that voters have to collect a random token from a box (ie you stick your hand in and take one) and that they have to show id to get to pick one then there is no way to vote twice (at least not without a fake id) and no way to connect the voter to the vote. It does require on site access but that could be allowed over a period of several months if need be. We already have voting by mail, of course, but this way you get to wait until election day to cast your actual vote and it is too easy to connect the vote to the voter. The issue with a gun being pointed to the head could be solved rather easily by issuing every voter a random number of votes and marking on as special (perhaps it comes in another envelope). All none special votes are automatically ignored, so you would gain nothing by pointing the gun at somebodys head. This also solves the software trust problem: allow an open specification and an API test endpoint and somebody will write an open source voting program. As a bonus the software could submit the votes to an api at all the registered parties and any news org so that everybody could agree on the count.
- pjc50 12y agoThe physical vote token is an interesting idea that I've not seen before.
- mukyu 12y agoThere is nothing that prevents an online voting system from having a truly secret ballot. There is a class of algorithms[0] designed to compute a verifiable result from private inputs without revealing those inputs. One of the major applications of them being researched is voting.[1][2][3] [0] http://en.wikipedia.org/wiki/Secure_multi-party_computation http://en.wikipedia.org/wiki/Secure_multi-party_computation [1] https://eprint.iacr.org/2014/075 https://eprint.iacr.org/2014/075 [2] http://arxiv.org/abs/1502.07469 http://arxiv.org/abs/1502.07469 [3] https://www.iacr.org/cryptodb/data/paper.php?pubkey=2203 https://www.iacr.org/cryptodb/data/paper.php?pubkey=2203