Skip to content

PEV subversion #1

Description

@danielrichman

I was wondering if you had considered this / whether this method for subverting the post election verification process would actually work:

  • election between candidates A and B; B would win by a small margin but malicious people trusted with access to the voting server would like A to win
  • everyone that votes for B is assigned a voting token from a small set; that is, multiple people voting for B are assigned the same token
  • extra voting tokens for non-existent voters are created so that (the number of unique tokens) = (the number of people that voted). All of these tokens are used to cast votes for A.
  • in the PEV, everyone that voted for B checks that the token they were assigned has indeed been associated with a vote for B, and suspect nothing. They have no reason to reveal their token as they believe their vote to be counted correctly, so won't notice that >=two people have the same token

Other fun scenarios:

  • election between candidates A and B; again B would win by a small margin, but A's supporters would like A to win / cause chaos.
  • votes for A claim they've all been assigned the same token, when in reality the election was not fixed. The election system has no way of refuting this claim?

An idea?

Voting token could be hash(salt + identity of voter); salt being unique per voter; salt revealed to voter. Identifying voters from the published list requires breaking the hash; a voter can demonstrate that a token is theirs by revealing the salt; assigning two voters the same token requires finding a collision.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions