nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
November 2014
- 49 participants
- 189 messages
Webcast now: "Privacy, Surveillance, and Rebuilding Trust in Tech"
by J.C. DE MARTIN
Webcast live now:
http://cyber.law.harvard.edu/events/luncheon/2014/11/Smith
[Today] Privacy, Surveillance, and Rebuilding Trust in Tech
A Conversation with Microsoft GC Brad Smith and Professor Jonathan Zittrain
Tuesday, November 4, 2014 at 12:00 pm
Harvard Law School campus
Wasserstein Hall, Room 1015
[Event at capacity] Please join the live webcast here at 12:00 pm.
Co-sponsored by the Harvard Journal of Law and Technology (JOLT)
#TrustInTech
Nov. 4, 2014
Fwd: [governance] Two IETF Internet-Drafts about human rights and censorship
by J.C. DE MARTIN
-------- Forwarded Message --------
Subject: [governance] Two IETF Internet-Drafts about human rights and
censorship
Resent-Date: Tue, 04 Nov 2014 14:49:07 +0100
Resent-From: d004620(a)polito.it
Date: Tue, 4 Nov 2014 14:47:59 +0100
From: Stephane Bortzmeyer <bortzmeyer(a)internatif.org>
Reply-To: governance(a)lists.igcaucus.org, Stephane Bortzmeyer
<bortzmeyer(a)internatif.org>
To: governance(a)lists.igcaucus.org
Next week is the 91th IETF meeting and, at the security meeting, these
two new Internet-Drafts will be discussed:
https://tools.ietf.org/html/draft-doria-hrpc-proposal
Work has been done on privacy issues that should be considered when
creating an Internet protocol [see the excellent RFC 6973, or
working groups like DPRIVE, for DNS privacy. S.B.]. This draft suggests that similar
considerations may apply for other human rights such as freedom of
expression or freedom of association. A proposal is made for
initiating IRTF [Internet Research Task Force] work researching the
possible connections between
human rights and Internet standards and protocols. The goal would be
to create an informational RFC concerning human rights protocol
considerations.
https://tools.ietf.org/html/draft-hall-censorship-tech
This document describes the technical mechanisms used by censorship
regimes around the world to block or degrade internet traffic. It
aims to make designers, implementers, and users of Internet protocols
aware of the properties being exploited and mechanisms used to censor
end-user access to information. This document makes no suggestions
on individual protocol considerations, and is purely informational,
intended to be a reference.
Nov. 4, 2014
Re: [nexa] Sistemi di voto elettronico
by Alessandro Mantelero
Scusa, forse mi è sfuggito, ma non mi pare che risulti chi
sia l'autore del commento.
Poichè vengono espressi giudizi, credo che conoscerne la
fonte possa essere a tutti utile.
AM
On Tue, 04 Nov 2014 14:45:00 +0100
mutek <mutek(a)riseup.net> wrote:
> Il martedì 4 novembre 2014 09:21:08 CEST, Fabio
>Pietrosanti - lists ha scritto:
>> Ciao a tutti,
>>
>> volevo condividere un piccolo esercizio che realizzai un
>>paio d'anni fa
>> sull'analisi ed elaborazione di un sistema di voto
>>elettronico per
>> l'italia, inclusivo di una stima di budget per
>>l'implementazione ed
>> esecuzione.
>>
>> E' frutto di un paio di giorni di lavoro, quindi
>>limitato ma è stato un
>> esercizio stimolante che magari può essere utile a
>>qualcun'altro in
> futuro:
>>
>> Innovazione ed efficienza del sistemi di voto
>> https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
>>
>> Razionali di budget
>> https://docs.google.com/spreadsheet/ccc?key=0Ak268BK3W4GVdGUyMXhsNjhBdDVTN1…
>>
>
> con massimo rispetto questi due documenti non dicono
>molto ed in particolare la parte numerica sintetica è di
>impossibile accettazione da parte di qualsiasi scienziato
>ai fini del proseguimento di questo tentativo.
>
> Pero trovo interessante aggiungere un elemento di
>valutazione che potrebbe servire ad integrazione, in
>particolare per chi non lo conoscesse c'è un ricercatore
>David Bismark che ha prodotto un lavoro su un sistema di
>voto elettronico verificabile:
>
> Prêt à voter: a voter-verifiable voting system
> http://dl.acm.org/citation.cfm?id=1720427&CFID=594648987&CFTOKEN=72520885&p…
>
> riferimento usabile:
> http://www.pretavoter.com/
>
> una spiegazione pratica qui:
> http://evoting.bismark.se/verifiable-electronic-voting/
>
> un sommario veloce:
>
> Prêt à Voter is a voting system that provides
>verification of the ballot. It allows voters to verify
>that their votes have been included in the count while
>ensuring their vote remains secret. It also assures the
>integrity of the election - that the final result
>corresponds to the votes cast - and allows independent
>verification of the count. Prêt à Voter provides voters
>with a familiar voting experience, integrated with an
>electronic system to process the votes and to provide the
>security guarantees. The system supports elections
>involving selection of a single candidate, selection of
>multiple candidates, lists of preferences, and multiple
>races on a single ballot.
> Voting with Prêt à VoterA compted ballot
>
> Voters mark their selection on a paper ballot form in
>the usual way against the candidates available. The key
>novelty is that the candidates are listed in a random
>order, which varies from ballot to ballot.
>
> When the vote has been written on the ballot paper, the
>candidate list is detached and destroyed. The result is a
>marked voting slip which indicates the position of the
>vote, but not who it is for. The voting slip is read into
>the system, and a receipt is returned to the voter. The
>receipt records the position of the marked vote and the
>voter retains the receipt for later confirmation of the
>vote.
>
> The right hand side of a ballotAfter the poll, the
>system publishes on a public web bulletin board the
>receipts of all the votes it has accepted. Any voter can
>confirm that their vote has been included in the ballot,
>by looking up their receipt and checking that their
>receipt matches what is published. This also provides
>protection against fraud: if votes are not included, then
>voters can use their receipts to challenge the process.
>
> The system works the same way if there are multiple
>votes or preferences to be cast.
>
> How it works
>
> To be able to process the votes after they have been
>cast, the voting slip includes a code (included as a 2-D
>bar code) containing the candidate list in encrypted
>form. The encryption means that the list cannot be
>extracted without a threshold number of decryption keys,
>and each of these keys is held by a different trusted
>party within the system.
>
> A ballot form can be randomly audited and its code
>decrypted to confirm that the candidate list has been
>printed correctly.
>
> Once the votes have been cast, the system shuffles them
>together and decrypts them using the decryption keys to
>identify the choices indicated on the marked voting
>slips. The votes can then be tallied to obtain the
>election result.
>
> The shuffling of all the votes means that no individual
>voting slip or receipt can be linked to any particular
>reconstructed vote. This protects the secrecy of the vote
>even with the receipt.
>
> As well as publishing the accepted voting slips, the
>bulletin board also lists all of the decrypted votes. The
>shuffling and decryption is done in a verifiable way:
>independent parties can confirm that the published list
>of decrypted votes corresponds to the published list of
>received voting slips. This means that the votes to be
>counted are exactly the votes that were cast. However,
>independent parties cannot link any particular voting
>slip to any particular vote.
>
> Once all the reconstructed votes are published, then
>anyone can check that the counting has been done
>correctly.
>
> Secret Ballot
>
> The system provides the same level of ballot secrecy as
>systems currently in real use. Even though a receipt is
>provided, it does not leak any information about the
>voter's choice of candidate.
>
> The marked position on the receipt does not leak
>information The receipt only contains the marked position
>of the vote, and not who the vote was for. The fact that
>the list of candidates was random means that the marked
>position could correspond to any choice, and so the
>chosen candidate cannot be identified from the position
>of the vote cast.
> The encrypted candidate order does not leak Although
>the candidate order is included on the ballot slip to
>allow the vote to be reconstructed, this is strongly
>encrypted, and cannot be decrypted without all of the
>decryption keys. These are distributed to trusted parties
>across the election system, and no-one has more than one
>key.
> The bulletin board does not leak information The
>shuffling of the votes before decryption ensures that the
>receipt cannot be associated with its decrypted version.
>An external party only knows that the receipt corresponds
>to some decrypted vote on the list, but cannot know
>which.
>
> These measures together ensure that the vote associated
>with a receipt cannot leak. The system provides ballot
>secrecy.
>
> Integrity: end-to-end verifiability
>
> The Prêt à Voter system provides transparent assurance
>that the final result reflects the votes cast.
>
> Each stage that the votes go through in the system, from
>vote casting, through to the election result itself, can
>be independently verified.
>
> All cast votes are included Voters themselves confirm
>that their votes have been included in the tally, by
>checking their receipts on the web bulletin board.
> All included votes are correctly decrypted Checking
>that the shuffling and decryption have been done properly
>can be carried out by independent parties. The way the
>cryptography is used means that as well as decrypting the
>votes, the system also publishes mathematical proofs that
>the decrypted votes correspond to the collection of votes
>that were included. These proofs can be independently
>verified by anyone.
> The decrypted votes are correctly counted Since the
>decrypted votes are made public, anyone can independently
>carry out the count and check the official result.
>
> Once all the reconstructed votes are published, then
>anyone can check that the counting has been done
>correctly. The integrity of the election is ensured by
>these checks, and does not need to rely on trust in the
>voting equipment or the election officials.
>
>
> buona lettura
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
--
Avv. Alessandro Mantelero, PhD
Aggregate Professor, Politecnico di Torino
Director of Privacy and Faculty Fellow, Nexa Center for
Internet and Society
Research Consultant, Sino-Italian Research Center for
Internet Torts at Nanjing University of Information
Science & Technology
Programme Coordinator, Double Degree program in Management
and IP Law, Politecnico di TorinoTongji University of
Shanghai
http://staff.polito.it/alessandro.mantelero
http://works.bepress.com/alessandro_mantelero/
Politecnico di Torino
Corso Duca degli Abruzzi, 24
10129 Torino - Italy
in libertate fortitudo
Nov. 4, 2014
Re: [nexa] Sistemi di voto elettronico
by mutek
addeundum:
sto notando che non è possibile scaricare l'articolo su ACM che comunque è
disponibile qui:
http://www.pretavoter.com/publications/PretaVoter2010.pdf
Il martedì 4 novembre 2014 14:45:00 CEST, mutek ha scritto:
> Il martedì 4 novembre 2014 09:21:08 CEST, Fabio Pietrosanti -
> lists ha scritto:
>> Ciao a tutti,
>>
>> volevo condividere un piccolo esercizio che realizzai un paio d'anni fa
>> sull'analisi ed elaborazione di un sistema di voto elettronico per
>> l'italia, inclusivo di una stima di budget per l'implementazione ed
>> esecuzione.
>>
>> E' frutto di un paio di giorni di lavoro, quindi limitato ma è stato un
>> esercizio stimolante che magari può essere utile a qualcun'altro in
> futuro:
>>
>> Innovazione ed efficienza del sistemi di voto
>>
https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
>>
>> Razionali di budget
>>
https://docs.google.com/spreadsheet/ccc?key=0Ak268BK3W4GVdGUyMXhsNjhBdDVTN1…
>>
>
> con massimo rispetto questi due documenti non dicono molto ed
> in particolare la parte numerica sintetica è di impossibile
> accettazione da parte di qualsiasi scienziato ai fini del
> proseguimento di questo tentativo.
>
> Pero trovo interessante aggiungere un elemento di valutazione
> che potrebbe servire ad integrazione, in particolare per chi non
> lo conoscesse c'è un ricercatore David Bismark che ha prodotto
> un lavoro su un sistema di voto elettronico verificabile:
>
> Prêt à voter: a voter-verifiable voting system
> http://dl.acm.org/citation.cfm?id=1720427&CFID=594648987&CFTOKEN=72520885&p…
>
> riferimento usabile:
> http://www.pretavoter.com/
>
> una spiegazione pratica qui:
> http://evoting.bismark.se/verifiable-electronic-voting/
>
> un sommario veloce:
>
> Prêt à Voter is a voting system that provides verification of
> the ballot. It allows voters to verify that their votes have
> been included in the count while ensuring their vote remains
> secret. It also assures the integrity of the election - that the
> final result corresponds to the votes cast - and allows
> independent verification of the count. Prêt à Voter provides
> voters with a familiar voting experience, integrated with an
> electronic system to process the votes and to provide the
> security guarantees. The system supports elections involving
> selection of a single candidate, selection of multiple
> candidates, lists of preferences, and multiple races on a single
> ballot.
> Voting with Prêt à VoterA compted ballot
>
> Voters mark their selection on a paper ballot form in the usual
> way against the candidates available. The key novelty is that
> the candidates are listed in a random order, which varies from
> ballot to ballot.
>
> When the vote has been written on the ballot paper, the
> candidate list is detached and destroyed. The result is a marked
> voting slip which indicates the position of the vote, but not
> who it is for. The voting slip is read into the system, and a
> receipt is returned to the voter. The receipt records the
> position of the marked vote and the voter retains the receipt
> for later confirmation of the vote.
>
> The right hand side of a ballotAfter the poll, the system
> publishes on a public web bulletin board the receipts of all the
> votes it has accepted. Any voter can confirm that their vote has
> been included in the ballot, by looking up their receipt and
> checking that their receipt matches what is published. This also
> provides protection against fraud: if votes are not included,
> then voters can use their receipts to challenge the process.
>
> The system works the same way if there are multiple votes or
> preferences to be cast.
>
> How it works
>
> To be able to process the votes after they have been cast, the
> voting slip includes a code (included as a 2-D bar code)
> containing the candidate list in encrypted form. The encryption
> means that the list cannot be extracted without a threshold
> number of decryption keys, and each of these keys is held by a
> different trusted party within the system.
>
> A ballot form can be randomly audited and its code decrypted to
> confirm that the candidate list has been printed correctly.
>
> Once the votes have been cast, the system shuffles them
> together and decrypts them using the decryption keys to identify
> the choices indicated on the marked voting slips. The votes can
> then be tallied to obtain the election result.
>
> The shuffling of all the votes means that no individual voting
> slip or receipt can be linked to any particular reconstructed
> vote. This protects the secrecy of the vote even with the
> receipt.
>
> As well as publishing the accepted voting slips, the bulletin
> board also lists all of the decrypted votes. The shuffling and
> decryption is done in a verifiable way: independent parties can
> confirm that the published list of decrypted votes corresponds
> to the published list of received voting slips. This means that
> the votes to be counted are exactly the votes that were cast.
> However, independent parties cannot link any particular voting
> slip to any particular vote.
>
> Once all the reconstructed votes are published, then anyone can
> check that the counting has been done correctly.
>
> Secret Ballot
>
> The system provides the same level of ballot secrecy as systems
> currently in real use. Even though a receipt is provided, it
> does not leak any information about the voter's choice of
> candidate.
>
> The marked position on the receipt does not leak
> information The receipt only contains the marked position of the
> vote, and not who the vote was for. The fact that the list of
> candidates was random means that the marked position could
> correspond to any choice, and so the chosen candidate cannot be
> identified from the position of the vote cast.
> The encrypted candidate order does not leak Although the
> candidate order is included on the ballot slip to allow the vote
> to be reconstructed, this is strongly encrypted, and cannot be
> decrypted without all of the decryption keys. These are
> distributed to trusted parties across the election system, and
> no-one has more than one key.
> The bulletin board does not leak information The shuffling
> of the votes before decryption ensures that the receipt cannot
> be associated with its decrypted version. An external party only
> knows that the receipt corresponds to some decrypted vote on the
> list, but cannot know which.
>
> These measures together ensure that the vote associated with a
> receipt cannot leak. The system provides ballot secrecy.
>
> Integrity: end-to-end verifiability
>
> The Prêt à Voter system provides transparent assurance that the
> final result reflects the votes cast.
>
> Each stage that the votes go through in the system, from vote
> casting, through to the election result itself, can be
> independently verified.
>
> All cast votes are included Voters themselves confirm that
> their votes have been included in the tally, by checking their
> receipts on the web bulletin board.
> All included votes are correctly decrypted Checking that
> the shuffling and decryption have been done properly can be
> carried out by independent parties. The way the cryptography is
> used means that as well as decrypting the votes, the system also
> publishes mathematical proofs that the decrypted votes
> correspond to the collection of votes that were included. These
> proofs can be independently verified by anyone.
> The decrypted votes are correctly counted Since the
> decrypted votes are made public, anyone can independently carry
> out the count and check the official result.
>
> Once all the reconstructed votes are published, then anyone can
> check that the counting has been done correctly. The integrity
> of the election is ensured by these checks, and does not need to
> rely on trust in the voting equipment or the election officials.
>
>
> buona lettura
>
>
Nov. 4, 2014
Re: [nexa] Sistemi di voto elettronico
by mutek
addeundum:
sto notando che non è possibile scaricare l'articolo su ACM che comunque è
disponibile qui:
Il martedì 4 novembre 2014 14:45:00 CEST, mutek ha scritto:
> Il martedì 4 novembre 2014 09:21:08 CEST, Fabio Pietrosanti -
> lists ha scritto:
>> Ciao a tutti,
>>
>> volevo condividere un piccolo esercizio che realizzai un paio d'anni fa
>> sull'analisi ed elaborazione di un sistema di voto elettronico per
>> l'italia, inclusivo di una stima di budget per l'implementazione ed
>> esecuzione.
>>
>> E' frutto di un paio di giorni di lavoro, quindi limitato ma è stato un
>> esercizio stimolante che magari può essere utile a qualcun'altro in
> futuro:
>>
>> Innovazione ed efficienza del sistemi di voto
>>
https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
>>
>> Razionali di budget
>>
https://docs.google.com/spreadsheet/ccc?key=0Ak268BK3W4GVdGUyMXhsNjhBdDVTN1…
>>
>
> con massimo rispetto questi due documenti non dicono molto ed
> in particolare la parte numerica sintetica è di impossibile
> accettazione da parte di qualsiasi scienziato ai fini del
> proseguimento di questo tentativo.
>
> Pero trovo interessante aggiungere un elemento di valutazione
> che potrebbe servire ad integrazione, in particolare per chi non
> lo conoscesse c'è un ricercatore David Bismark che ha prodotto
> un lavoro su un sistema di voto elettronico verificabile:
>
> Prêt à voter: a voter-verifiable voting system
> http://dl.acm.org/citation.cfm?id=1720427&CFID=594648987&CFTOKEN=72520885&p…
>
> riferimento usabile:
> http://www.pretavoter.com/
>
> una spiegazione pratica qui:
> http://evoting.bismark.se/verifiable-electronic-voting/
>
> un sommario veloce:
>
> Prêt à Voter is a voting system that provides verification of
> the ballot. It allows voters to verify that their votes have
> been included in the count while ensuring their vote remains
> secret. It also assures the integrity of the election - that the
> final result corresponds to the votes cast - and allows
> independent verification of the count. Prêt à Voter provides
> voters with a familiar voting experience, integrated with an
> electronic system to process the votes and to provide the
> security guarantees. The system supports elections involving
> selection of a single candidate, selection of multiple
> candidates, lists of preferences, and multiple races on a single
> ballot.
> Voting with Prêt à VoterA compted ballot
>
> Voters mark their selection on a paper ballot form in the usual
> way against the candidates available. The key novelty is that
> the candidates are listed in a random order, which varies from
> ballot to ballot.
>
> When the vote has been written on the ballot paper, the
> candidate list is detached and destroyed. The result is a marked
> voting slip which indicates the position of the vote, but not
> who it is for. The voting slip is read into the system, and a
> receipt is returned to the voter. The receipt records the
> position of the marked vote and the voter retains the receipt
> for later confirmation of the vote.
>
> The right hand side of a ballotAfter the poll, the system
> publishes on a public web bulletin board the receipts of all the
> votes it has accepted. Any voter can confirm that their vote has
> been included in the ballot, by looking up their receipt and
> checking that their receipt matches what is published. This also
> provides protection against fraud: if votes are not included,
> then voters can use their receipts to challenge the process.
>
> The system works the same way if there are multiple votes or
> preferences to be cast.
>
> How it works
>
> To be able to process the votes after they have been cast, the
> voting slip includes a code (included as a 2-D bar code)
> containing the candidate list in encrypted form. The encryption
> means that the list cannot be extracted without a threshold
> number of decryption keys, and each of these keys is held by a
> different trusted party within the system.
>
> A ballot form can be randomly audited and its code decrypted to
> confirm that the candidate list has been printed correctly.
>
> Once the votes have been cast, the system shuffles them
> together and decrypts them using the decryption keys to identify
> the choices indicated on the marked voting slips. The votes can
> then be tallied to obtain the election result.
>
> The shuffling of all the votes means that no individual voting
> slip or receipt can be linked to any particular reconstructed
> vote. This protects the secrecy of the vote even with the
> receipt.
>
> As well as publishing the accepted voting slips, the bulletin
> board also lists all of the decrypted votes. The shuffling and
> decryption is done in a verifiable way: independent parties can
> confirm that the published list of decrypted votes corresponds
> to the published list of received voting slips. This means that
> the votes to be counted are exactly the votes that were cast.
> However, independent parties cannot link any particular voting
> slip to any particular vote.
>
> Once all the reconstructed votes are published, then anyone can
> check that the counting has been done correctly.
>
> Secret Ballot
>
> The system provides the same level of ballot secrecy as systems
> currently in real use. Even though a receipt is provided, it
> does not leak any information about the voter's choice of
> candidate.
>
> The marked position on the receipt does not leak
> information The receipt only contains the marked position of the
> vote, and not who the vote was for. The fact that the list of
> candidates was random means that the marked position could
> correspond to any choice, and so the chosen candidate cannot be
> identified from the position of the vote cast.
> The encrypted candidate order does not leak Although the
> candidate order is included on the ballot slip to allow the vote
> to be reconstructed, this is strongly encrypted, and cannot be
> decrypted without all of the decryption keys. These are
> distributed to trusted parties across the election system, and
> no-one has more than one key.
> The bulletin board does not leak information The shuffling
> of the votes before decryption ensures that the receipt cannot
> be associated with its decrypted version. An external party only
> knows that the receipt corresponds to some decrypted vote on the
> list, but cannot know which.
>
> These measures together ensure that the vote associated with a
> receipt cannot leak. The system provides ballot secrecy.
>
> Integrity: end-to-end verifiability
>
> The Prêt à Voter system provides transparent assurance that the
> final result reflects the votes cast.
>
> Each stage that the votes go through in the system, from vote
> casting, through to the election result itself, can be
> independently verified.
>
> All cast votes are included Voters themselves confirm that
> their votes have been included in the tally, by checking their
> receipts on the web bulletin board.
> All included votes are correctly decrypted Checking that
> the shuffling and decryption have been done properly can be
> carried out by independent parties. The way the cryptography is
> used means that as well as decrypting the votes, the system also
> publishes mathematical proofs that the decrypted votes
> correspond to the collection of votes that were included. These
> proofs can be independently verified by anyone.
> The decrypted votes are correctly counted Since the
> decrypted votes are made public, anyone can independently carry
> out the count and check the official result.
>
> Once all the reconstructed votes are published, then anyone can
> check that the counting has been done correctly. The integrity
> of the election is ensured by these checks, and does not need to
> rely on trust in the voting equipment or the election officials.
>
>
> buona lettura
>
>
Nov. 4, 2014
Re: [nexa] Sistemi di voto elettronico
by mutek
Il martedì 4 novembre 2014 09:21:08 CEST, Fabio Pietrosanti - lists ha
scritto:
> Ciao a tutti,
>
> volevo condividere un piccolo esercizio che realizzai un paio d'anni fa
> sull'analisi ed elaborazione di un sistema di voto elettronico per
> l'italia, inclusivo di una stima di budget per l'implementazione ed
> esecuzione.
>
> E' frutto di un paio di giorni di lavoro, quindi limitato ma è stato un
> esercizio stimolante che magari può essere utile a qualcun'altro in
futuro:
>
> Innovazione ed efficienza del sistemi di voto
> https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
>
> Razionali di budget
> https://docs.google.com/spreadsheet/ccc?key=0Ak268BK3W4GVdGUyMXhsNjhBdDVTN1…
>
con massimo rispetto questi due documenti non dicono molto ed in
particolare la parte numerica sintetica è di impossibile accettazione da
parte di qualsiasi scienziato ai fini del proseguimento di questo
tentativo.
Pero trovo interessante aggiungere un elemento di valutazione che potrebbe
servire ad integrazione, in particolare per chi non lo conoscesse c'è un
ricercatore David Bismark che ha prodotto un lavoro su un sistema di voto
elettronico verificabile:
Prêt à voter: a voter-verifiable voting system
http://dl.acm.org/citation.cfm?id=1720427&CFID=594648987&CFTOKEN=72520885&p…
riferimento usabile:
http://www.pretavoter.com/
una spiegazione pratica qui:
http://evoting.bismark.se/verifiable-electronic-voting/
un sommario veloce:
Prêt à Voter is a voting system that provides verification of the ballot.
It allows voters to verify that their votes have been included in the count
while ensuring their vote remains secret. It also assures the integrity of
the election - that the final result corresponds to the votes cast - and
allows independent verification of the count. Prêt à Voter provides voters
with a familiar voting experience, integrated with an electronic system to
process the votes and to provide the security guarantees. The system
supports elections involving selection of a single candidate, selection of
multiple candidates, lists of preferences, and multiple races on a single
ballot.
Voting with Prêt à VoterA compted ballot
Voters mark their selection on a paper ballot form in the usual way against
the candidates available. The key novelty is that the candidates are listed
in a random order, which varies from ballot to ballot.
When the vote has been written on the ballot paper, the candidate list is
detached and destroyed. The result is a marked voting slip which indicates
the position of the vote, but not who it is for. The voting slip is read
into the system, and a receipt is returned to the voter. The receipt
records the position of the marked vote and the voter retains the receipt
for later confirmation of the vote.
The right hand side of a ballotAfter the poll, the system publishes on a
public web bulletin board the receipts of all the votes it has accepted.
Any voter can confirm that their vote has been included in the ballot, by
looking up their receipt and checking that their receipt matches what is
published. This also provides protection against fraud: if votes are not
included, then voters can use their receipts to challenge the process.
The system works the same way if there are multiple votes or preferences to
be cast.
How it works
To be able to process the votes after they have been cast, the voting slip
includes a code (included as a 2-D bar code) containing the candidate list
in encrypted form. The encryption means that the list cannot be extracted
without a threshold number of decryption keys, and each of these keys is
held by a different trusted party within the system.
A ballot form can be randomly audited and its code decrypted to confirm
that the candidate list has been printed correctly.
Once the votes have been cast, the system shuffles them together and
decrypts them using the decryption keys to identify the choices indicated
on the marked voting slips. The votes can then be tallied to obtain the
election result.
The shuffling of all the votes means that no individual voting slip or
receipt can be linked to any particular reconstructed vote. This protects
the secrecy of the vote even with the receipt.
As well as publishing the accepted voting slips, the bulletin board also
lists all of the decrypted votes. The shuffling and decryption is done in a
verifiable way: independent parties can confirm that the published list of
decrypted votes corresponds to the published list of received voting slips.
This means that the votes to be counted are exactly the votes that were
cast. However, independent parties cannot link any particular voting slip
to any particular vote.
Once all the reconstructed votes are published, then anyone can check that
the counting has been done correctly.
Secret Ballot
The system provides the same level of ballot secrecy as systems currently
in real use. Even though a receipt is provided, it does not leak any
information about the voter's choice of candidate.
The marked position on the receipt does not leak information The
receipt only contains the marked position of the vote, and not who the vote
was for. The fact that the list of candidates was random means that the
marked position could correspond to any choice, and so the chosen candidate
cannot be identified from the position of the vote cast.
The encrypted candidate order does not leak Although the candidate
order is included on the ballot slip to allow the vote to be reconstructed,
this is strongly encrypted, and cannot be decrypted without all of the
decryption keys. These are distributed to trusted parties across the
election system, and no-one has more than one key.
The bulletin board does not leak information The shuffling of the votes
before decryption ensures that the receipt cannot be associated with its
decrypted version. An external party only knows that the receipt
corresponds to some decrypted vote on the list, but cannot know which.
These measures together ensure that the vote associated with a receipt
cannot leak. The system provides ballot secrecy.
Integrity: end-to-end verifiability
The Prêt à Voter system provides transparent assurance that the final
result reflects the votes cast.
Each stage that the votes go through in the system, from vote casting,
through to the election result itself, can be independently verified.
All cast votes are included Voters themselves confirm that their votes
have been included in the tally, by checking their receipts on the web
bulletin board.
All included votes are correctly decrypted Checking that the shuffling
and decryption have been done properly can be carried out by independent
parties. The way the cryptography is used means that as well as decrypting
the votes, the system also publishes mathematical proofs that the decrypted
votes correspond to the collection of votes that were included. These
proofs can be independently verified by anyone.
The decrypted votes are correctly counted Since the decrypted votes are
made public, anyone can independently carry out the count and check the
official result.
Once all the reconstructed votes are published, then anyone can check that
the counting has been done correctly. The integrity of the election is
ensured by these checks, and does not need to rely on trust in the voting
equipment or the election officials.
buona lettura
Nov. 4, 2014
Re: [nexa] Sistemi di voto elettronico
by M. Fioretti
On 2014-11-04 09:21, Fabio Pietrosanti - lists wrote:
> Ciao a tutti,
>
> volevo condividere un piccolo esercizio che realizzai un paio d'anni fa
> sull'analisi ed elaborazione di un sistema di voto elettronico per
> l'italia, inclusivo di una stima di budget per l'implementazione ed
> esecuzione.
>
> E' frutto di un paio di giorni di lavoro, quindi limitato ma è stato un
> esercizio stimolante che magari può essere utile a qualcun'altro in
> futuro:
>
> Innovazione ed efficienza del sistemi di voto
> https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
Cito dal documento:
##############################################################################
E’ fondamentale sottolineare come le operazioni di voto e scrutinio
debbano continuare ad essere eseguibili e verificabili senza l’ausilio
di alcuna tipologia di strumento tecnologico o competenza particolare.
Le operazioni di voto, cioè la primaria modalità con cui il cittadino
esprime la propria intenzione, non possono essere gestite per tramite di
macchinari di votazione elettronici ma devono rimanere basate
sull’utilizzo di carta e penna.
Le operazioni di scrutinio possono essere coadiuvate dalla tecnologia
(scansione ottica digitale) per aumentarne l’efficienza ma deve essere
sempre mantenuta la possibilità di verifica manuale, da parte di
cittadini privi di strumenti o competenze particolari.
Si dovrà valutare l’adozione di soluzioni di verifica che consentono al
cittadino di verificare in modo sicuro e segreto l’esito dello scrutinio
del proprio voto tramite internet. [8]
##############################################################################
Il mio commento: BENE, grazie! Concordo pienamente su voto che deve
rimanere con carta e penna e scrutinio manuale o quasi. Finalmente un
discorso serio, basato sulla realtà. Però, proprio per questo:
il titolo di quel documento fa danno al suo contenuto, che non se lo
merita! Chiamarlo "votazioni elettroniche" lo accomuna a tutta la fuffa
di voto effettivamente con computer, in seggio o da casa, di cui invece
il documento stesso
dimostra i limiti. Il titolo giusto secondo me dovrebbe essere "Gestione
digitale dei risultati del voto" o qualcosa del genere
a parte questo, mi sembra che l'ultima frase "soluzioni di verifica che
consentono al cittadino di verificare" sia in contraddizione insanabile
con la concretezza del resto del documento. Come aggiungere una funzione
del genere senza compromettere la
segretezza del voto? "Permettere di verificare il proprio voto da casa"
a gente che nell'80% dei casi ancora usa "123456" come password, ha
modem e pc non aggiornati eccetera... mi sembra condizione necessaria e
SUFFICIENTE per ritrovarsi con N malware, impossibili da fermare in
tempo utile, che comunicano a chi li diffonde come hanno votato tutti
quelli che se li sono beccati.
Per la cronaca, queste mie considerazioni vengono dalle mie posizioni
generali sul voto elettronico che ho riassunto qui:
http://stop.zona-m.net/it/2014/06/voto-online-o-elettronico-ancora-no-grazi…
http://www.pionero.it/2013/02/25/voto-elettronico-o-elezioni-digitali-la-se…
Marco
--
http://mfioretti.com
Nov. 4, 2014
Re: [nexa] Sistemi di voto elettronico
by Alessandro Mantelero
Ciao Fabio,
A prima lettura mi pare un buon punto di partenza,
soprattutto perché si fa carico del problema della
verifica democratica del foto. Per esperienza in gruppi di
ricerca sul tema, solitamente i tecnici si entusiasmano
per il voto elettronico e trascurano la parte delle
garanzie democratiche.
Tra i casi di studio aggiungerei l'Estonia, con i limiti
emersi.
A presto,
A.
On Tue, 04 Nov 2014 09:21:08 +0100
Fabio Pietrosanti - lists <lists(a)infosecurity.ch> wrote:
> Ciao a tutti,
>
> volevo condividere un piccolo esercizio che realizzai un
>paio d'anni fa
> sull'analisi ed elaborazione di un sistema di voto
>elettronico per
> l'italia, inclusivo di una stima di budget per
>l'implementazione ed
> esecuzione.
>
> E' frutto di un paio di giorni di lavoro, quindi
>limitato ma è stato un
> esercizio stimolante che magari può essere utile a
>qualcun'altro in futuro:
>
> Innovazione ed efficienza del sistemi di voto
> https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
>
> Razionali di budget
> https://docs.google.com/spreadsheet/ccc?key=0Ak268BK3W4GVdGUyMXhsNjhBdDVTN1…
>
> --
>Fabio Pietrosanti (naif)
> HERMES - Center for Transparency and Digital Human
>Rights
> http://logioshermes.org - http://globaleaks.org -
>http://tor2web.org - http://ahmia.fi
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
--
Avv. Alessandro Mantelero, PhD
Aggregate Professor, Politecnico di Torino
Director of Privacy and Faculty Fellow, Nexa Center for
Internet and Society
Research Consultant, Sino-Italian Research Center for
Internet Torts at Nanjing University of Information
Science & Technology
Programme Coordinator, Double Degree program in Management
and IP Law, Politecnico di TorinoTongji University of
Shanghai
http://staff.polito.it/alessandro.mantelero
http://works.bepress.com/alessandro_mantelero/
Politecnico di Torino
Corso Duca degli Abruzzi, 24
10129 Torino - Italy
in libertate fortitudo
Nov. 4, 2014
Sistemi di voto elettronico
by Fabio Pietrosanti - lists
Ciao a tutti,
volevo condividere un piccolo esercizio che realizzai un paio d'anni fa
sull'analisi ed elaborazione di un sistema di voto elettronico per
l'italia, inclusivo di una stima di budget per l'implementazione ed
esecuzione.
E' frutto di un paio di giorni di lavoro, quindi limitato ma è stato un
esercizio stimolante che magari può essere utile a qualcun'altro in futuro:
Innovazione ed efficienza del sistemi di voto
https://docs.google.com/document/d/1xutcvqEwe2tvcUhTh7eSEyf3_CS_sv4-saC8RlK…
Razionali di budget
https://docs.google.com/spreadsheet/ccc?key=0Ak268BK3W4GVdGUyMXhsNjhBdDVTN1…
--
Fabio Pietrosanti (naif)
HERMES - Center for Transparency and Digital Human Rights
http://logioshermes.org - http://globaleaks.org - http://tor2web.org - http://ahmia.fi
Nov. 4, 2014
Berkman Center Webcast live oggi ore 18 - Privacy, Surveillance, and Rebuilding Trust in Tech
by Giuseppe Futia
Privacy, Surveillance, and Rebuilding Trust in Tech
http://cyber.law.harvard.edu/events/luncheon/2014/11/Smith
<http://cyber.law.harvard.edu/events/luncheon/2014/06/sigal>
<http://cyber.law.harvard.edu/events/luncheon/2014/06/sigal>
*A Conversation with Microsoft GC Brad Smith and Professor Jonathan
Zittrain*
Today, 6.00 pm
Webcast live: http://cyber.law.harvard.edu/interactive/webcast
http://nexa.polito.it/berkman-webcast-live
One of the enduring issues in cyberspace is which laws apply to
online activities. We see this most clearly today in the reaction to
revelations about government surveillance: on one hand, individuals
are increasingly seeking assurances that their content is protected
from government overreach, while governments want to ensure they
have access to information to enforce their laws, even if that
content is stored outside their borders. We see this same tension in
debates over privacy protection for data placed on line by
consumers. This discussion will explore the role of law in
protecting our rights in the physical world online, the
complementary roles of law and technology in achieving this
protection, and the need for governments to come together so that
companies (and customers) don't face conflicting legal obligations.
About Brad
Brad Smith is Microsoft's general counsel and executive vice
president of Legal and Corporate Affairs. He leads approximately
1,100 legal, business and corporate affairs professionals spanning
55 countries and is responsible for the company's legal work, its
intellectual property portfolio, patent licensing business, and the
company's government affairs, public policy, corporate citizenship
and philanthropic work. He also serves as Microsoft's corporate
secretary and its chief compliance officer. Brad joined Microsoft in
1993, and before becoming general counsel in 2002 he spent three
years leading the LCA team in Europe, then five years serving as the
deputy general counsel responsible for LCA's teams outside the
United States.
About Jonathan
Jonathan Zittrain is the George Bemis Professor of Law at Harvard
Law School and the Harvard Kennedy School of Government, Professor
of Computer Science at the Harvard School of Engineering and Applied
Sciences, Vice Dean for Library and Information Resources at the
Harvard Law School Library, and co-founder of the Berkman Center for
Internet & Society. His research interests include battles for
control of digital property and content, cryptography, electronic
privacy, the roles of intermediaries within Internet architecture,
human computing, and the useful and unobtrusive deployment of
technology in education.
He performed the first large-scale tests of Internet filtering in
China and Saudi Arabia, and as part of the OpenNet Initiative
co-edited a series of studies of Internet filtering by national
governments: /Access Denied: The Practice and Policy of Global
Internet Filtering/; /Access Controlled: The Shaping of Power,
Rights, and Rule in Cyberspace/; and /Access Contested: Security,
Identity, and Resistance in Asian Cyberspace/.
He is a member of the Board of Directors of the Electronic Frontier
Foundation and the Board of Advisors for /Scientific American/. He
has served as a Trustee of the Internet Society and as a Forum
Fellow of the World Economic Forum, which named him a Young Global
Leader. He was a Distinguished Scholar-in-Residence at the Federal
Communications Commission, and previously chaired the FCC's Open
Internet Advisory Committee. His book /The Future of the Internet --
And How to Stop It/ predicted the end of general purpose client
computing and the corresponding rise of new gatekeepers. That and
other works may be found at <http://www.jz.org>.
Nov. 4, 2014