← Back to list

One Human, One Vote

A privacy-preserving, publicly verifiable voting system: a ballot that stays private to you, a count that’s permanent and checkable by…

Hopeioum · 2026-06-13 04:20 · 0 claps · 11.6 min read
#voting #privacy #digital-identity #cryptography #decentralization
Open on Medium ↗
Wiki topics: OPS · LLMOps & Inference CRY · Crypto & Web3 🔒 · Cybersecurity 🏛️ · Politics

One Human, One Vote

A privacy-preserving, publicly verifiable voting system: a ballot that stays private to you, a count that’s permanent and checkable by anyone, and a vote no one can trace back to you. Judged by harm to none.

One Human, One Vote, No Name

One Human, One Vote, No Name

I have spent the last few weeks writing about identity you can take back, the idea that you should be able to prove who you are without your face being filed away in a vault, a central database of faces that can be breached, sold, or turned against you. None of this means working around the current rules that protect people. It works inside them. A harder question shows up on its own, and it is the one I could not put down.

If you can prove you are a real, single human without a vault, can you cast a vote with that same proof, a unique receipt only you can produce? One person, one vote, counted exactly once, kept secret, and impossible to suppress?

Almost every design I have ever seen reaches for the same dangerous shortcut, a central record that knows both who is eligible and, in the worst version, how each person voted. A list of who is allowed to vote is ordinary and necessary, every election already keeps one. The danger is the second half, the moment that list also carries the link between you and your ballot, or gets paired with a central store that holds your face. That is the vault. So I held myself to the harder standard, the same one from the identity work: keep the eligibility list, refuse the link to the ballot, and build no central store of faces. Not a safer vault. No vault at all.

One honest thing before we go further, because a sharp reader will reach for it right here. When I say no vault, I mean this voting system builds none. I do not mean none exists. Your driver’s license photo already sits in a state database today, and that is a real vault. This piece does not solve that. What it does is make sure the vote itself adds nothing to that pile and never ties you to your ballot. The database your face already sits in for your driver’s license or ID is a separate process and central store, and it is not this one.

How one vote moves through this, start to finish

Before any of the machinery, here is the whole thing in plain steps, the path one vote takes from beginning to end in this process. It is built around voting in person, at a supervised booth, not an app and not a website, and that booth can be a regular polling place or one brought to where you are.

  1. Before election day, you start with the driver’s license or state ID you already carry, issued the way it is today. This piece is about the vote, not how your current ID gets issued. Here you simply use the ID you already have, nothing new to sign up for.
  2. At the booth, in person, a quick check confirms it’s really you, the way many states already check ID today. You are confirmed eligible, and nothing more about you is exposed.
  3. From the instant you are confirmed, your identity is set aside. A curtain drops, and nothing that moves forward carries your name. In the privacy of the booth, you cast your vote, and what travels is a one-time stamp, not you.
  4. Your vote is sealed into a count anyone can verify, with no name attached. Your stamp works once, so a second vote in your name, anywhere, is rejected.

That is the entire promise in one breath: verified once, cast in private, counted forever, and never tagged back to you. Everything below is how each of those steps actually holds.

The three things it has to do

When I sat down to define this, I refused to start with the cryptography. I started with what a person actually needs.

First, the vote has to be cloaked. Not just private as a courtesy, but unlinkable to you, so no one can trace your ballot back to you and punish you for how you voted. People do not speak freely when retaliation is possible.

That one property is doing more work than it looks. Here is what the cloak actually protects:

  • Retaliation. No government, employer, landlord, or neighbor can tie your ballot back to you and make you pay for how you voted.
  • Vote-buying. A vote you cannot prove you cast a certain way is a vote no one can buy, because the buyer can never confirm he got what he paid for.
  • Coercion. An abusive partner or a controlling boss cannot force your hand, because they can never check that you obeyed.
  • Manipulation. Operatives cannot profile you by how you vote and feed you pressure built from it.
  • Profiling. Your vote never becomes a data point that resurfaces against you later, in a job, a loan, or your own community.
  • Fear among the vulnerable. People in abusive homes, mixed-status families, or hostile workplaces can vote honestly without gambling their safety to do it.

Strip the cloak away and every one of those doors opens. That is the why.

Second, exactly one vote per actual human. Not one per account, not one per device, not one per document, because all of those can be faked or stacked. One per living person.

Third, no double-dipping across places. No matter how many places someone keeps a home, they still get one vote, not one for every address. The fix should not punish everyone with friction to stop the few who would try.

Fourth, harm to none. A system that only works for people with a passport, a smartphone, a fixed address, and the ability to reach a booth is not a fair system, it is an exclusion machine with good branding. The people at the edges are the test, not a rounding error. The goal is a 98% outcome.

The one trick that does most of the work

Here is the part that surprised me. The first two needs, secrecy and one-vote, look like two separate problems. They are not. They are one problem, and a single idea solves both at once.

Picture the list of everyone eligible to vote, but instead of names, each person is a sealed token only they can open. When you go to vote, you do two things at the same time. First, you prove you are one of the people on that list without ever showing which one, the way you could prove you hold a key to a door without ever showing the key. That gives you the cloak. Second, your token produces a one-time stamp for this election. The system has never seen that stamp before, so your vote counts, and if your stamp ever shows up again, the second one is thrown out.

Secrecy and one-human-one-vote, solved in the same motion. You proved you belong without being named, and you can only stamp once.

The cryptography under this has real names, and the full technical version, the proofs, the stamps, the sealed list, lives in the repository for the people who can help build it. You do not need those names to trust how it works, which is why they stay there and not here.

The third need, the multiple-homes problem, then falls out for free. The stamp is tied to the election, not to the polling place, so one person makes one stamp per election, and a second attempt is rejected no matter where it is cast. Where you live becomes a detail attached at sign-up, not a loophole.

One thing to be clear about, because it changes how all of this should read. Nothing here invents a new authority that hands out a voting credential from nowhere. Your place on that list is established the same way it already is today, through the identity documents and validation you already go through to register, your driver’s license or state ID, your Social Security record, the proofs your state or government already asks for. What happens at the booth varies, some states check a photo ID and some check none, but the identity-proofing that registration already runs exists everywhere, and that is where your credential comes from. The proof rides on top of the validation we already have. It does not replace it with someone new to trust.

Where the no-vault identity comes in

All of that depends on one thing being true, that each spot on the eligible list really does belong to one real, single human. This is where my earlier work on No Vault identity does its job, the approach where you prove you are one real person on your own device, with no central store of faces.

One thing to picture first, because it keeps the process straight. Your phone carries the cloaked key, your proof, not the ballot box. You bring it to the booth, it proves you are eligible, and you still cast your vote in the private booth, the same as you do now.

You enroll once. Your face is checked on your own device, on the same secure chip your phone already uses to unlock, and it is never pooled into a central store. From that one check you receive a credential bound to a single purpose, and after that your actual face is never touched again. Everything that travels afterward is useless to anyone who grabs it, the same way your phone login is useless to a thief. And if a credential ever leaks, it can be cancelled and reissued, because what was kept was never your face, it was a scrambled version of it that cannot be turned back into a face.

What stays on the record is not your face. It is a small signed note that says this person was verified, agreed, and is still eligible, kept on a shared, tamper-proof record that you own and can revoke. Only the note lives there. The face never does.

In voting terms, the supervised enrollment is the one careful moment where eligibility is set. The booth does two jobs. It is supervised at the door, where it confirms you are eligible and takes the one-time check, and private behind the curtain, where you cast unobserved. That privacy is the secret-ballot standard everywhere, whether the setup is a curtain, a screen, or a folder. After that, your device unlocks your ballot locally, the proof says same person without revealing who, and the signed note is the eligibility record you control. Enroll once, every check on your own device, nothing pooled.

The tally no one can erase

A secret ballot is only half of trust, it isn’t visible truth, yet. The other half is a count that cannot be quietly suppressed or rewritten after the fact. That is the permanence layer I wrote about in my first piece in this series: a record of what happened that is permanent, that anyone can check, and that no one can quietly rewrite, while still showing nothing about how any single person voted. Private to you, permanent for everyone.

And here is the part most people miss. The damage to an election does not come only from fraud that actually happens. It comes from no one being able to prove, either way, that it did not. That uncertainty is the corrosion, it is what lets anyone claim anything. A count that anyone can check ends the argument by making the answer a matter of verification instead of whose word you take.

Put the two halves together and that is the conclusion the whole design drives toward. The result stands in the open, countable and checkable by anyone who doubts it, and inside that public count not one vote can be walked back to the person who cast it. A result everyone can verify, a ballot no one can unmask.

How the pieces fit

None of these layers is new or invented for this. Each one is something I already wrote about, doing a job here. It is easier to see as a map than a paragraph:

What the vote has to do Where it comes from A cloaked ballot, private to you the balance between privacy and truth, and the proof that lets you belong without a name, both carried through the earlier pieces One human, confirmed, with no vault the No Vault identity architecture A tally no one can suppress or rewrite the permanence layer from “What If Truth Couldn’t Be Erased?” Harm to none, with an honest residual the through-line of everything I write: you judge a system by its edges

The voting system is not a new thesis bolted on top of the old ones. It is those two pieces joined, identity you can prove without a vault, put to work on a vote.

The honest part, because that is the whole point

I will not pretend this is finished or perfect, because pretending is exactly the failure I write against. Here are the open problems, named in the open.

The weak-secret problem. A single face simply does not carry enough unique information to act as a strong, unbreakable secret on its own, and researchers have rebuilt recognizable faces from data that was supposed to be protected. My answer is not to fight that, it is to step around it. The face is demoted to a simple check on your own device, and the real work of keeping each person unique is carried by the eligibility layer, not by the face.

Key recovery. Keys you hold yourself are wonderful for privacy and brutal when they are lost. The hard rule is that recovering a lost key must never quietly rebuild the central store we just spent all this effort removing. This is unsolved, and I am saying so.

The enrollment moment. There is one unavoidable instant where a raw face exists, the moment you first enroll, which in practice is when you appear in person to get or renew your ID and your face is captured that one time. The supervised booth is this design’s answer to that instant, but it is still the most sensitive moment in the whole system, and it deserves to be treated that way.

My honest target for reach is around 98%. The remaining slice, the people hardest to include, is named rather than buried. That is the standard.

And because naming the slice means actually naming it, here is who gets reached and who does not, instead of hiding the gap inside a percentage:

  • Most voters: a supervised, private booth, the way it works now.
  • Service members in conflict zones: a supervised, private booth stood up on base, inside a safe zone.
  • Citizens living abroad: booths at embassies and consulates.
  • Remote and rural communities: mobile booths brought to them.
  • Voters with disabilities and the homebound: the booth comes to them, with accommodations, wherever it physically can.
  • The honest residual, the last 1 to 2%: people in places with no US presence, or where reaching one is dangerous. The only fallback left for them is a weaker remote channel, the one mode that gives up the booth’s protection against coercion, and that is stated here, not hidden.

The line I will not cross is letting that residual harden into a permanent second tier. The rule is to keep bringing a booth to a hard case before ever dropping that person into the weaker lane, because a system where the marginalized get the less-secure path by default is its own quiet harm, and that would fail the one test that actually matters.

And the person without a phone is not left hanging. The answer lives one layer down, in how the credential is issued and carried: a card can hold it where a phone cannot, and the duty to put that means in every eligible hand sits with the issuing system, not with the voter. That layer is the architecture’s territory, not this piece’s. The point here is only that no one is turned away for lacking a device, because the device was never meant to be the gate.

The one thing no math can do

When you follow all three needs down, they collapse into a single hard problem: establishing that each credential belongs to exactly one real, eligible human. The cryptography to do everything after that, the secrecy, the single stamp, the proof no one can fake, is largely settled and genuinely strong. But no math can create personhood. It cannot, by itself, decide who is a real and singular human. That root is the whole game, and anyone who tells you their voting system has solved it cleanly is either confused or selling something.

I would rather show you the hard root than hide it.

The groundwork and the code

If you want the earlier groundwork, start with What If Truth Couldn’t Be Erased? and No Vault at All: The Build.

This design did not come from me alone, and the project treats crediting people correctly as a feature, not a footnote. The technical foundation draws on work by Edgar Salinas and the upstream authors named in the repository.

If you read this and found yourself asking, but how does the proof actually work, that question is exactly what the repository is for. This piece is the plain version. The repository is the technical one, with every layer tagged honestly for what already exists, what is partial, what is still to build, and what no system can yet solve:

HopeClary/TheOnlyVote

Start with the README, it links to the rest. If your work is in there and the credit is wrong or missing, that is a bug, open an issue and we will fix it.

This is the best way I know how to contribute for change, so I am contributing it in the open, where it can be checked.


메타데이터
post_id
0a7589301c5b
slug
one-human-one-vote-0a7589301c5b
url
https://medium.com/@hopeioum/one-human-one-vote-0a7589301c5b
canonical_url
https://medium.com/@hopeioum/one-human-one-vote-0a7589301c5b
author_url
https://medium.com/@hopeioum
status
ok
fetched_at
2026-06-17 12:55:42