HN user

throwaway9995

7 karma
Posts0
Comments5
View on HN
No posts found.

The elections being discussed are performed over the internet, on the voters own computer. Where would the paper audit log be created, and how would you ensure it accurately reflects what the voter chose on his (possibly compromised) PC?

Edit: See the answer by user relix in this thread. This system does not solve the two issues I raised. As with all of these systems, they have to choose between "secure (verifiable) ballot" and "secret ballot". Estonia has clearly chosen the former.

The problem with that is that now people can be pressured to vote in certain ways, as they can prove after the fact how they voted. This has not been a big problem in first world countries for a long time - but I don't think that's because people have fundamentally changed, but rather that nobody tries it because the paper ballot system effectively stops such voter intimidation/manipulation.

Based on the first link, it looks like the system does not solve the second concern (privacy of the ballot) at all.

If the user can verify how his vote was counted (in the example, using a smartphone app), then someone applying pressure on the voter can force him to verify that he voted the "right" way.

This is my problem with all these e-voting systems. They throw away hundreds of years of development in ballot security, assuming all those problems that have historically followed elections no longer apply.

That said, not everybody is enthusiastic about uploading their country’s secrets onto the cloud. The opposition party, the leftist Central Party, is against it, just as it opposes electronic voting — insisting both initiatives pose too many potential security risks.

But Kotka says all the data will be encrypted and impossible to access or erase without authorization. “You would have to bring the whole Internet down,” he explains, describing it as “untouchable.”

Whenever valid privacy and security concerns are raised with government IT systems (e-voting, centralised health care records, etc), this seems to be the kneejerk reaction: "No, it's all encrypted, you don't need to worry about it."

As a result, it's seems to be completely impossible to have a real discussion of the problems. In this case, this statement does nothing to answer the concerns, and yet it seems it placated the reporter.