|
|
|
|
|
by jaimeyap
2577 days ago
|
|
Some schemes could require the person to remember a passphrase (not printed out) that is mixed in with the one-time-token to compute the final verifier token. > you can be "encouraged" to send an email to bigbrother@example.com with your national ID number and your token Would the system providing some sort of plausible deniability token give enough cover for this? Is this a problem at scale? Also... they can do this to you for your email, and social media logins too right? > Or the day after the election, in each office at work everyone can just meet and show their token while cheering for the current government. I don't understand why this is fundamentally different than todays world where people wear MAGA hats or drive around with Obama/Biden bumper stickers. Sure it's not cryptographically verifiable. But it's certainly "good enough" for all practical purposes. |
|
---
If each one has a secret passphrase, nobody can verify that the total is calculated correctly.
If people can choose their own passphrase, they can be forced to use one. I like "Fr33dom!"
If the passphrase is calculated automatically, just make the combination of the token with a different passphrase generate a nonsensical result (if you have 10 parties, generate a number between 1 and 100000 for security reasons), so people can't lie. And make people send the email with the national ID, token and passphrase.
Here in Argentina the old method (100 year ago) to vote was that everyone go to the local voting site, and everyone vote in public raising their hand, someone count the votes and send the result to the central location. (The historical details may be inaccurate. But it was something similar.)
Obviously, people can be forced to not go to vote, or people that voted against the local political chief can be pressure to change their votes, or never vote again, or just hit until they understand their error.
It was a long fight to get secret votes, some people even died for the right of a secret vote. I guess other countries have similar stories.
It's difficult to imagine the problems without a recent similar story in your own country. Let's assume you are from USA. Just imagine that during McCarthyism people that were requested testify in the committee has to first say their national ID, token and passphrase to be sure that they didn't vote for the Communist party. Anyone that refuses gets blacklisted automatically for national security reasons.