Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Inside the voting booth you pick an identified ballot and are given a zero knowledge proof that it corresponds to the candidate you want. The fact that it's a zero knowledge proof prevents you from using it to convince other people.

The video I linked has a good example where you get 1000 envelopes all claiming to contain "Obama", so you open and verify 999 of them at random and use that as evidence that the one you didn't unseal is good. You can't then use that to convince a third party, because they didn't get to pick the envelope to not open. The video also addresses lots of other security issues; you should watch it.



My concern would be in proving that the envelope you didn't open is the same one that made it into the final count. If you have no more connection with it after you leave the booth, you can not verify that the letter wasn't tampered with (and also no one can coerce you into showing who you voted for). Any way that lets you verify that the last envelope wasn't tampered with would also let some third party see who you voted for.

Anything the machine electronically presents you with can be modified on a compromised machine, while physical printout that can be used later to verify will either be unable to prove that your vote wasn't switched (though it can prove that your vote was counted) or it will be able to prove you did vote for who you choose, the latter case meaning that a third party can then use this to know who you voted for.


You're attacking the parts of the analogy that don't apply to the actual cryptography. Best way to see how they get around the issue you're talking about is to watch the video.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: