> From: A. Erickson
> Well, that's true but that's not the only reason. I also
> don't want any bullying based on votes down the line.
> "Well, you voted that but now you're voting this?!" It's
> not really fair. I don't want the tally to be misused.

well, unfortunately, in a system that has to have accountable votes, that's
not really avoidable except through social engineering.

> If we have to keep a record somehow and there's no way
> to guarantee total anonymity then I think we should
> discuss who has access to this data and make sure that
> there are safeguards in place to keep it as anonymous
> as possible.

the only people that would have access to the data are those with access to
the machine or the database (directly or via serverside language that can
connect to the database).  even then they'd have to put some work into
reversing out who belonged to what vote.

i don't want to mess with putting safeguards in to protect the vote as that
will just slow down the application.

> If, as Ron mentioned -- we need to use that data then,
> if possible, that should be stated beforehand and
> before the vote finalizes. Then whoever has access to
> the data can go and fetch it.

i think the individual vote results should be viewable by the "owner" of the
vote/poll in question.


