Rendered at 18:24:22 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
rho4 7 hours ago [-]
> After the voting period there will be a record
of all the votes without the name of the voter. It will instead contain
a cryptographic hash. You will receive a secret after you have voted
that can be used to calculate that hash. This allows you to verify
that your vote is in the list. This secret is sent in an encrypted
mail.
I've always wanted this for mail-in voting. E.g. print a random secret on the voting form I receive per mail. Afterwards publish the complete vote-count on the web, with the choice and a hash of the secret. So I can check that my vote was recorded, and only once, and correctly.
I understand there might be a lot of reasons for why it could fail in practice, but it would be a start.
rubendev 6 hours ago [-]
I think the main problem with this is that you can be paid/coerced to vote for someone and be able to easily prove that you voted for the person they wanted. It’s easier to vote for the person you actually wanted to vote for, and maintain plausible deniability, if you go in person to a voting booth.
compsciphd 3 hours ago [-]
the question is, what's the worst situation for society.
People not trusting the votes being counted properly or people being coerced paid to vote some way and this making it more valuable.
A plausible solution would be to significantly delay the distribution of the record. i.e. if every election was only printed out 2-4 years after the fact, it could give people confidence that the votes are being counted properly (as otherwise they would be found out eventually), but significantly reduce the incentive for the bad behavior (if one things this actually significantly incentivizes it) because it will be a long time before they can validate if what they were given is true.
jetrink 5 hours ago [-]
Could this be mitigated by allowing voters to vote multiple times and receive multiple confirmations, but only count the last vote for each person? That way an individual could prove that they voted a certain way to a third party, but there would be no way for the third party to know whether it was their final vote. Meanwhile the individual knows that they spoiled their previous vote or votes and that their final vote is included.
1123581321 5 hours ago [-]
You’d have the same issue as you’d need to be able to verify that your last vote was being counted, for displaying your vote back to you to have any value.
A scheme to be able to show coercive parties fake votes would be known to them immediately.
ImJamal 3 hours ago [-]
This wouldn't solve anything. The person doing the coercion would be able to store the hash and double check after the election if the vote was still the way they wanted.
cogman10 5 hours ago [-]
I don't take this concern seriously.
You can be paid/coerced to vote for someone even if there's total secrecy. For example, you can take your cellphone in and take a picture of your filled out ballot to collect a payment.
Unless you want to start the confiscation of cellphones before voting in person, the risk of a coerced or bought vote will always exist.
Fargren 5 hours ago [-]
In Argentina at least, you can get a fine[1] for taking a picture of your ballot. Certainly a hard law to enforce though.
In Texas, the election judges are supposed to stop you if you pull out a cellphone or any device.
Paper is all you are allowed to use during the voting process.
jancsika 4 hours ago [-]
In-person, high-risk rule-breaking that's hard to validate has a tendency to scale differently from say, pasting a value into a lottery/payment app.
I mean, compare the number of people who've flown over Barbara Streisand's property to take a picture of her house to the number of people who had a copy of said picture in their browser cache.
You can read more about this peculiar scaling factor of the internet in Bill Gates 1995 book The Road Ahead.
lefra 4 hours ago [-]
For me, the main reason that I'm against all high-tech voting solutions is that a less-than-gifted citizen must be able to check that, at least for their polling station:
- Their vote, and everyone else's, was counted exactly once.
- The number of ballots that are counted is the same as the number of people who voted.
- Votes are anonymous.
All that is easily done with a clear ballot box, a signing registry, and public counting. Adding technology to that just makes the process more difficult to trust IMO.
As for myself, you're going to have to convice me that the software + hardware that's running on election day is exactly conformant to its published source code (the source code is available, right?)
jtickle 6 hours ago [-]
The unfortunate reason this isn't doable in the US anyway, and any time someone has a great idea on how to improve elections this inevitably comes up: preventing coersion. It's difficult to balance transparent voting with ensuring that you can't prove which way you voted in exchange for money or favors.
cogman10 5 hours ago [-]
You can take a picture of your filled out ballot with a cellphone. I don't see how there isn't already a very wide open door for coercion/vote purchasing. It's not 100% fool proof, but you don't need that to sway an election, you just need enough people to follow through.
But even with that, it seems like the better course of action is criminalizing such coercion (which is already illegal). Anyone doing something like that on a scale large enough to matter would be caught rather quickly.
markus92 5 hours ago [-]
There’s places where taking photos inside the voting box is illegal for this exact reason.
johndough 4 hours ago [-]
This could be prevented if the government offered photos of ballots with votes for download. But generative AI can also fake it well enough these days. (Of course, this is less of a concern in countries where taking photos of ballots is not allowed.)
garaetjjte 4 hours ago [-]
It's not secret to the administrator though, as they could know who was assigned what secret. I think it could work like: before voting, you go to an office where they verify your identity and let you randomly pick envelope containing unique number from a box. After voting all votes are published and you can verify your vote was counted, but nobody else knows your number.
surgical_fire 6 hours ago [-]
For something like voting on decisions for some open source project, sure.
For actually voting on representatives it would be an absolute disaster.
scj 5 hours ago [-]
Don't blame me, I voted for Jia Tan!
TacticalCoder 6 hours ago [-]
[flagged]
penchant 8 hours ago [-]
The choices are oddly and not consistently worded. "Ban LLM contributions from Debian via Social Contract", "A cautious approach to generative AI", "Debian is created by humans" and "Avoid the use of LLM: climate destruction is a deal breaker" all in one list? Sounds like several people wrote them and did not agree on the form.
pm215 7 hours ago [-]
This is the way general resolutions in Debian generally work. There's a lot of pre-vote discussion where different people and groups propose and draft their preferred options, to produce what they feel is the best expression of their position. If you can get enough seconders for your proposal it goes on the ballot, with the text you chose and your seconders agreed with. There isn't any requirement for the options to use consistent terminology or avoid overlap, and no overarching editorial process to impose consistency (which would be tricky anyway in cases like this where terminology choices and overall framing can be part of the disagreement between people.)
penchant 2 hours ago [-]
Thank you for a valuable response; I did not know this.
Tomte 8 hours ago [-]
> Sounds like several people wrote them and did not agree on the form
Of course several people wrote different position statements to vote on.
Did you expect one Debian developer to cook up half a dozen possible stances he is not even personally invested in? Are you constantly surprised that election programs of different parties are worded differently (and use different fonts)?
penchant 2 hours ago [-]
Obviously not, you misunderstood my point. And the election programs comparison makes no sense.
cromka 7 hours ago [-]
Dude, chill with the strawman and the aggression. Bad day?
forestrywat 4 hours ago [-]
Fwiw, I perceive no aggression in their post.
Tomte 7 hours ago [-]
There is no aggression, and "dudeing" me makes me disregard you immediately anyway.
5 hours ago [-]
DANmode 5 hours ago [-]
If we’re disregarding people based on how they express themselves, Keybase is owned by Zoom now…
datakan 7 hours ago [-]
Tried to decipher this but seems a bit convoluted. If the Kernel now allows LLM code, then what will Debian do if they ban LLM code? Choice 7 and choice 8 seem pretty clear that the project simply can't continue under those circumstances.
pm215 7 hours ago [-]
Neither choice 7 nor 8 attempt to forbid packaging of any upstream project with LLM contributions like the kernel.
Choice 7 says "The proposal does not cover indirect contributions, i.e. those originating from upstream works.". It's only making requirements on Debian work specifically.
Choice 8 says "We also acknowledge that LLM usage can be hard if not impossible to detect and that Debian as a distribution cannot really impose LLM policies on other projects we package and distribute. Therefore this text is just a position statement." It doesn't impose any requirements at all on anybody, even for debian specific work: it just says "we'd prefer it if you don't use this technology".
datakan 7 hours ago [-]
Understood and thank you. I guess my next question is, then what's the point of this? Seems like saber rattling or virtue signaling.
pm215 7 hours ago [-]
A lot of work and code is Debian specific, and so there's a choice to be made about LLM use for that code, as there is for any project. And there are questions about LLM use in mailing list discussions, bug reports, and other non code interactions. Most of the options take a position on that (i.e. impose some rules for those contributions) one way or another.
What other projects choose on the question is interesting and might inform the choice, but what e.g. the kernel opts for doesn't control what Debian decides for itself, any more than the kernel's choice imposes any requirements on Rust or glibc or gcc.
forestrywat 4 hours ago [-]
What is the point of setting standards on the way we work? It's an exercise in democratic decision making. Some people dislike ai for entirely legitimate reasons, and they want to see if others in their community agree. (And if so, set boundaries on the way they work.)
You gotta stop seeing "virtue signaling" every time someone holds a belief different than your own.
AndrewDucker 6 hours ago [-]
They care about it. And want there to be an official position about it.
Qwertious 5 hours ago [-]
It means that for any patches submitted directly to Debian, they can blanket reject it if it has signs of AI without having to properly evaluate the patch on it's merits (which is onerous and easily DDOSed).
throwaway27448 5 hours ago [-]
What virtue would be signaled in this case and to whom?
23151-aa15 6 hours ago [-]
While it would be desirable to ban all packages that use AI, Debian has its own code to protect.
They cannot ban all packages because Torvalds has been bought by the sponsors of the Linux Foundation and has already used the "AI is a tool" talking point from the corporate manuals.
Debian and Linux partly started as resistance projects against Microsoft, so a moral stance is expected and welcome anyway.
We'll see if the Canonical people who always vote for corporations or the idealists win. If Canonical wins this, Debian is obsolete.
amelius 6 hours ago [-]
Well, they could try to prove the correctness of that LLM-based kernel code.
If it passes, then they could use it, no?
z3ratul163071 3 hours ago [-]
omg the choices. amazing i drive most vms on os maintained by pontificious nutjobs.
waisbrot 2 hours ago [-]
That's an interesting topic you might meditate on. Microsoft would never hold such a vote. Would you be better off with their OS? Debian is one of the more free-as-in-speech distributions; would you rather run your VMs on one that had tighter integration with for-profit groups?
lowsong 4 hours ago [-]
Proposal A would of course be the best option, but requires a two thirds majority for... some reason. Proposals B, C, D, E are all defeatist policies that appeal to a "here to stay" narrative. Proposal G is potentially workable but has so many carve-outs to be practically useless, leaving only Proposal H as a workable policy if A fails to pass.
4 hours ago [-]
abc123abc123 8 hours ago [-]
Jesus Christ on a pogo stick! How difficult should it be? If someone sends you code that is well documented and easy to understand, you accept. I someone sends you code that is bad or incomprehensible, you reject it.
Who the f*ck cares who made it? A monkey could have made it for all I care. If it does what it claims to do, and I understand how, it's all good.
No, the copyright issue is nonsense. That is handled by contract where the contributor is responsible, alternatively, by code submissions of smaller size where copyright loses its meaning, or just base your project in a jurisdiction where it is a non issue.
For 99.99% of the open source projects potential copyright violations is a complete non-issue.
hashar 7 hours ago [-]
Copyright IS an issue to Debian, and always has been for the last 30 years or so. They are, rightfully so, extremely picky when it comes to respecting copyright and licensing. It is the 0.01%.
> Who the f*ck cares who made it? A monkey could have made it for all I care. If it does what it claims to do, and I understand how, it's all good.
Copyright laws do care. As an example one can send a patch claiming its their own but because they had do it under their employer duty, the copyright might well be associated to their employer rather than them individually. Does the patch does what it claims to? Surely. Is that a copyright infringement? DEFINITELY SO.
The copyright rationale for the first proposition (Choice 1: Ban LLM contributions from Debian via Social Contract):
> 1. Copyright
> -------------
>
> LLM output has very unclear legal status: it may be possible to copyright on its own merits, or not; it may be affected by all of the licenses and copyrights in the training data, or not.
> Debian Policy and the DFSG require absolute clarity for licensing and copyright[1][2]. Software and other contributions written conventionally by humans with unclear copyright or license status are not allowed in Debian; LLM output should not have a special exception to this.
This rationale states if there is doubt about the copyright of the code, it not suitable for inclusion. Until I guess LLM output get a clarification regarding who is the author of its output.
acdha 7 hours ago [-]
> No, the copyright issue is nonsense
This is wishful thinking for any project of Debian’s size. You not wanting to deal with it doesn’t mean that people won’t get sued.
forestrywat 4 hours ago [-]
I care how they made it. Would you accept code made by forced labor? Prison labor? From every country/government? What if the code is stolen? What if the code is plagiarized? What if the author is going online and loudly harassing people and encouraging harassment of other maintainers?
There's so, so many reasons to understand and care about the how.
23151-aa15 6 hours ago [-]
Funding for the 100,000th vibe coding startup is running out?
ImPostingOnHN 5 hours ago [-]
Your post contains several questions, but also several strong indications that you don't care about the answers unless you agree with them already. Would you say that is fair?
rlpb 7 hours ago [-]
It sounds like you would be in favour of Choice 5.
chuckadams 5 hours ago [-]
I do believe one of the rules around here is "don't fulminate". Your point doesn't get across as well when people have to stand clear of the flying spittle.
aeuropean12 7 hours ago [-]
How conservative.
throwaway27448 5 hours ago [-]
Is that a bad thing? Not everyone needs to chase VC money
VCFundedGenYer 5 hours ago [-]
TIL being climate conscious is "conservatism"....
z3ratul163071 3 hours ago [-]
being "climate conscious" wrt LLMs is equivalent sign of brainwashing like the covid mask wearing in 2026 or the emoji / flag / pronouns soup on social media.
rfgplk 6 hours ago [-]
Considering Debians in-house projects are effectively swiss cheese in terms of security, banning LLMs is pure lunacy. Not to mention that an average college kid could port their whole codebase in a day with Claude (see the dozens of fully fledged homegrown Rust kernels/OSs written by teenagers). They're fighting a losing battle.
xena 4 hours ago [-]
Please demonstrate by porting Debian to Rust with your Claude subscription. You have the weekend. Get started!
125asgf 6 hours ago [-]
> see the dozens of fully fledged homegrown Rust kernels/OSs written by teenagers
This isn't Musk's X feed.
surgical_fire 6 hours ago [-]
Yes, and I'll be waiting patiently for some AI-slop Rust port of Debian to gain any traction.
Any day now.
I am not saying if they should or should not accept AI contributions, but this sort of comment misses the point so hard that is laughable.
lowsong 4 hours ago [-]
> an average college kid could port their whole codebase in a day with Claude
I've always wanted this for mail-in voting. E.g. print a random secret on the voting form I receive per mail. Afterwards publish the complete vote-count on the web, with the choice and a hash of the secret. So I can check that my vote was recorded, and only once, and correctly.
I understand there might be a lot of reasons for why it could fail in practice, but it would be a start.
People not trusting the votes being counted properly or people being coerced paid to vote some way and this making it more valuable.
A plausible solution would be to significantly delay the distribution of the record. i.e. if every election was only printed out 2-4 years after the fact, it could give people confidence that the votes are being counted properly (as otherwise they would be found out eventually), but significantly reduce the incentive for the bad behavior (if one things this actually significantly incentivizes it) because it will be a long time before they can validate if what they were given is true.
A scheme to be able to show coercive parties fake votes would be known to them immediately.
You can be paid/coerced to vote for someone even if there's total secrecy. For example, you can take your cellphone in and take a picture of your filled out ballot to collect a payment.
Unless you want to start the confiscation of cellphones before voting in person, the risk of a coerced or bought vote will always exist.
[1]https://www.perfil.com/noticias/politica/elecciones-2025-de-...
I mean, compare the number of people who've flown over Barbara Streisand's property to take a picture of her house to the number of people who had a copy of said picture in their browser cache.
You can read more about this peculiar scaling factor of the internet in Bill Gates 1995 book The Road Ahead.
- Their vote, and everyone else's, was counted exactly once.
- The number of ballots that are counted is the same as the number of people who voted.
- Votes are anonymous.
All that is easily done with a clear ballot box, a signing registry, and public counting. Adding technology to that just makes the process more difficult to trust IMO.
As for myself, you're going to have to convice me that the software + hardware that's running on election day is exactly conformant to its published source code (the source code is available, right?)
But even with that, it seems like the better course of action is criminalizing such coercion (which is already illegal). Anyone doing something like that on a scale large enough to matter would be caught rather quickly.
For actually voting on representatives it would be an absolute disaster.
Of course several people wrote different position statements to vote on.
Did you expect one Debian developer to cook up half a dozen possible stances he is not even personally invested in? Are you constantly surprised that election programs of different parties are worded differently (and use different fonts)?
Choice 7 says "The proposal does not cover indirect contributions, i.e. those originating from upstream works.". It's only making requirements on Debian work specifically.
Choice 8 says "We also acknowledge that LLM usage can be hard if not impossible to detect and that Debian as a distribution cannot really impose LLM policies on other projects we package and distribute. Therefore this text is just a position statement." It doesn't impose any requirements at all on anybody, even for debian specific work: it just says "we'd prefer it if you don't use this technology".
What other projects choose on the question is interesting and might inform the choice, but what e.g. the kernel opts for doesn't control what Debian decides for itself, any more than the kernel's choice imposes any requirements on Rust or glibc or gcc.
You gotta stop seeing "virtue signaling" every time someone holds a belief different than your own.
They cannot ban all packages because Torvalds has been bought by the sponsors of the Linux Foundation and has already used the "AI is a tool" talking point from the corporate manuals.
Debian and Linux partly started as resistance projects against Microsoft, so a moral stance is expected and welcome anyway.
We'll see if the Canonical people who always vote for corporations or the idealists win. If Canonical wins this, Debian is obsolete.
If it passes, then they could use it, no?
Who the f*ck cares who made it? A monkey could have made it for all I care. If it does what it claims to do, and I understand how, it's all good.
No, the copyright issue is nonsense. That is handled by contract where the contributor is responsible, alternatively, by code submissions of smaller size where copyright loses its meaning, or just base your project in a jurisdiction where it is a non issue.
For 99.99% of the open source projects potential copyright violations is a complete non-issue.
> Who the f*ck cares who made it? A monkey could have made it for all I care. If it does what it claims to do, and I understand how, it's all good.
Copyright laws do care. As an example one can send a patch claiming its their own but because they had do it under their employer duty, the copyright might well be associated to their employer rather than them individually. Does the patch does what it claims to? Surely. Is that a copyright infringement? DEFINITELY SO.
The copyright rationale for the first proposition (Choice 1: Ban LLM contributions from Debian via Social Contract):
> 1. Copyright
> -------------
>
> LLM output has very unclear legal status: it may be possible to copyright on its own merits, or not; it may be affected by all of the licenses and copyrights in the training data, or not.
> Debian Policy and the DFSG require absolute clarity for licensing and copyright[1][2]. Software and other contributions written conventionally by humans with unclear copyright or license status are not allowed in Debian; LLM output should not have a special exception to this.
This rationale states if there is doubt about the copyright of the code, it not suitable for inclusion. Until I guess LLM output get a clarification regarding who is the author of its output.
This is wishful thinking for any project of Debian’s size. You not wanting to deal with it doesn’t mean that people won’t get sued.
There's so, so many reasons to understand and care about the how.
This isn't Musk's X feed.
Any day now.
I am not saying if they should or should not accept AI contributions, but this sort of comment misses the point so hard that is laughable.
Nobody is stopping you, please go ahead.