Home / Blogs

Once Again, Why Internet Voting Doesn’t Work

An acquaintance said, “We trust our electronic systems to transfer millions of dollars of value; I suspect we will eventually develop schemes we will trust to record and count votes.”

Unfortunately, this is one of the chronic fallacies that make voting security experts tear their remaining hair out. The security models are entirely different, so what banks do is completely irrelevant to voting.

There are no secrets in banking. Banking transactions are all auditable; a bank has a complete list of where all the money came from and where all the money went. In most cases, the transactions can be reversed if challenged. Even if they can’t, the bank can say, “you sent $100,000 to the Third State Bank of Bezerkestan, account 5551212, too bad they won’t give it back.” Plenty of stuff is partially secret, e.g., a bank may not report your transaction details to anyone but you, but it’s not completely secret.

The key to voting security is that the contents of your ballot is secret from everyone, including you. There’s a list of who voted, there’s a list of what the votes are, and there has to be no way to link the two. Computers are really bad at that.

By John Levine, Author, Consultant & Speaker

Filed Under

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

I make a point of reading CircleID. There is no getting around the utility of knowing what thoughtful people are thinking and saying about our industry.

Co-designer of the TCP/IP Protocols & the Architecture of the Internet


Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.



Domain Names

Sponsored byVerisign

Domain Management

Sponsored byMarkMonitor

Threat Intelligence

Sponsored byWhoisXML API

IPv4 Markets

Sponsored byIPXO


Sponsored byVerisign