I was wondering if you had considered this / whether this method for subverting the post election verification process would actually work:
- election between candidates A and B; B would win by a small margin but malicious people trusted with access to the voting server would like A to win
- everyone that votes for B is assigned a voting token from a small set; that is, multiple people voting for B are assigned the same token
- extra voting tokens for non-existent voters are created so that (the number of unique tokens) = (the number of people that voted). All of these tokens are used to cast votes for A.
- in the PEV, everyone that voted for B checks that the token they were assigned has indeed been associated with a vote for B, and suspect nothing. They have no reason to reveal their token as they believe their vote to be counted correctly, so won't notice that >=two people have the same token
Other fun scenarios:
- election between candidates A and B; again B would win by a small margin, but A's supporters would like A to win / cause chaos.
- votes for A claim they've all been assigned the same token, when in reality the election was not fixed. The election system has no way of refuting this claim?
An idea?
Voting token could be hash(salt + identity of voter); salt being unique per voter; salt revealed to voter. Identifying voters from the published list requires breaking the hash; a voter can demonstrate that a token is theirs by revealing the salt; assigning two voters the same token requires finding a collision.
I was wondering if you had considered this / whether this method for subverting the post election verification process would actually work:
Other fun scenarios:
An idea?
Voting token could be
hash(salt + identity of voter); salt being unique per voter; salt revealed to voter. Identifying voters from the published list requires breaking the hash; a voter can demonstrate that a token is theirs by revealing the salt; assigning two voters the same token requires finding a collision.