My contention is that when there are things like you describe going on, it's usually fairly obvious to people (even those who can't count) because they weren't able to do the all points observation that the process allows.
I'm describing elections where you can literally watch the box before it is sealed, to being opened, to having the votes counted and the count being published. If you're in a place where you are not able to do that, then yes, of course, you're running a high risk that the election is not fair.
You don't even need people to be unbiased, you just need a selection of people with different allegiances who will be able to cry foul if they see something happening that is not right because they think it will damage their side.
But with technology we can have far greater certainty
I have yet to see any technological solution that gives greater certainty than the ballot box system. Most of them allow the voter to prove their vote or involve many more actors that must be trusted. They also provide new central points of attack, where a well run paper vote is very distributed.
Half the country cries foul based on observational samples but without systemic proof, and the other half of the country says they're inventing stories and cherry-picking irregularities, and that there are just as many irregularities in the other direction to cancel them out.
And the average citizen, of course, has absolutely no idea what to think. Both sides sound entirely plausible. And even if there was manipulation, nobody has any idea if it changed the outcome by 0.1% (a few bad actors) or by 10% (the president directed it), if it was enough to tip an election or not.
By introducing foolproof technological verification, all this goes away. And I don't understand how you think this doesn't exist -- isn't this HN post just one example of multiple proposals?
foolproof technological verification, all this goes away. And I don't understand how you think this doesn't exist
Well, firstly, having some familiarity with software, it's rare to come across 'foolproof' used as an adjective, even with formally proved correct pieces of code.
But, I accept that it's possible that if implemented correctly, something like the most modern forms of things like Pret a Voter might be pretty secure. However, it's going to be harder for a normal human to check that Pret a Voter is implemented correctly than to check that a paper ballot system is implemented correctly.
For example, in Pret a Voter, the group of tellers and only the group of tellers have the ability to recover the original order. This would allow them to decrypt any of the posted receipts, if they shared that knowledge with someone nefarious, it provides perfect means for vote coercion. If the process is not run correctly and they are colluding, they could have the chance to choose a decryption that provides the right result.
If you implement Pret a Voter correctly, with a group of ideologically distinct tellers, and you involve them at the right points in the process, and not at other points, and you have a non-colluding auditor check they are doing their job correctly, then everything is fine, but in practice, how is a voter going to get that confidence?
Ultimately, I find myself agreeing with Bruce Schneier. "The problem isn't the math, it's the human procedures around the math. I don't think a cryptographic voting system would be an improvement, because that's not the weakest link." https://www.schneier.com/blog/archives/2006/11/voting_techno...
Comments
My contention is that when there are things like you describe going on, it's usually fairly obvious to people (even those who can't count) because they weren't able to do the all points observation that the process allows.
I'm describing elections where you can literally watch the box before it is sealed, to being opened, to having the votes counted and the count being published. If you're in a place where you are not able to do that, then yes, of course, you're running a high risk that the election is not fair.
You don't even need people to be unbiased, you just need a selection of people with different allegiances who will be able to cry foul if they see something happening that is not right because they think it will damage their side.
I have yet to see any technological solution that gives greater certainty than the ballot box system. Most of them allow the voter to prove their vote or involve many more actors that must be trusted. They also provide new central points of attack, where a well run paper vote is very distributed.
I like Schneiers analysis of the papal election protocol: https://www.schneier.com/blog/archives/2005/04/hacking_the_p...
Except it's not, which is the whole point.
Half the country cries foul based on observational samples but without systemic proof, and the other half of the country says they're inventing stories and cherry-picking irregularities, and that there are just as many irregularities in the other direction to cancel them out.
And the average citizen, of course, has absolutely no idea what to think. Both sides sound entirely plausible. And even if there was manipulation, nobody has any idea if it changed the outcome by 0.1% (a few bad actors) or by 10% (the president directed it), if it was enough to tip an election or not.
By introducing foolproof technological verification, all this goes away. And I don't understand how you think this doesn't exist -- isn't this HN post just one example of multiple proposals?
Well, firstly, having some familiarity with software, it's rare to come across 'foolproof' used as an adjective, even with formally proved correct pieces of code.
But, I accept that it's possible that if implemented correctly, something like the most modern forms of things like Pret a Voter might be pretty secure. However, it's going to be harder for a normal human to check that Pret a Voter is implemented correctly than to check that a paper ballot system is implemented correctly.
For example, in Pret a Voter, the group of tellers and only the group of tellers have the ability to recover the original order. This would allow them to decrypt any of the posted receipts, if they shared that knowledge with someone nefarious, it provides perfect means for vote coercion. If the process is not run correctly and they are colluding, they could have the chance to choose a decryption that provides the right result.
If you implement Pret a Voter correctly, with a group of ideologically distinct tellers, and you involve them at the right points in the process, and not at other points, and you have a non-colluding auditor check they are doing their job correctly, then everything is fine, but in practice, how is a voter going to get that confidence?
This is ignoring very real usability concerns (that in some cases can be politically weaponized to disenfrancise particular segments of the population). https://www.usenix.org/system/files/conference/jets15/jets_0...
Ultimately, I find myself agreeing with Bruce Schneier. "The problem isn't the math, it's the human procedures around the math. I don't think a cryptographic voting system would be an improvement, because that's not the weakest link." https://www.schneier.com/blog/archives/2006/11/voting_techno...