Live data from Hacker News

Utah voting system fending off 1B hacking attempts per day

utahpolicy.com

181–190 of 220 posts

Re: Utah voting system fending off 1B hacking attempts per day

#181

Earlier quoted context omitted.

I have an ID. Last time I renewed it I specifically spurned the "Real ID" option. Which supposedly means I can't get on an airplane. I have since been on an airplane. But not one that required a loss of dignity. I did not provide a driver license to my employer. I have worked legitimately for them every day for many years. I did not provide a driver license to my ISP. I can't fathom why my bank would need to know if…

Which supposedly means I can't get on an airplane. I have since been on an airplane. But not one that required a loss of dignity. You'll apparently "lose your dignity" in October [1]. I can't fathom why my bank would need to know if I am allowed to drive. An ID and a driver's license are not necessarily the same thing. [1] http://www.businessinsider.com/tsa-changes-deadline-for-real...

This is completely separate from voting issues, but I tend to avoid settings where I am treated like a suspect. I certainly don't pay people specifically to treat me like a suspect. As you might guess, this means that I don't do business with commercial airlines.

It also means that I avoid sporting events that require pat-downs. Or neighborhood parties that require criminal background checks. Or schools with metal detectors at the entrance.

In general, if an event is so sketchy and risky that it requires those measures, I take it as a signal to avoid that event. When I see somebody dressed in full combat gear I know I am not where I want to be.

Re: Utah voting system fending off 1B hacking attempts per day

#182

Earlier quoted context omitted.

I grew up in a town smaller than that. How many adults do not have a driver's license, which is acceptable id for voting?

I have no way to count them. But I can give you one off the top of my head. My dad. Incidentally, he owns two cars.

Incidentally, he owns two cars.

If he drives them, he will rightfully be arrested. If he wants to bail out of jail after his arrest, the bondsman will require ID. No ID, and he sits there in jail until his case is heard several months down the line.

With respect to your other claims, you seem to be of the belief that a Driver's License and an ID are necessarily the same thing. They are not. You can easily acquire an ID card that is not a driver's license.

Re: Utah voting system fending off 1B hacking attempts per day

#183
post #85

Earlier quoted context omitted.

IDs are not issued automatically in the US; they take money and effort to acquire. Therefore as implemented in the US, voter IDs are a poll tax. Unsurprisingly, this makes voter ID a political issue: those who benefit from poll taxes support them, and those whose voters are suppressed by poll taxes oppose them.

I think it would be reasonable to create a national ID card system and fund it through taxes. It could replace driver licenses and social security cards. I do not know why it would be unreasonable to require such a card for voting. It could also serve as a PKI system with the govt acting as a CA (i.e. manage issuance and revocation). There are non zero benefits. And this doesn't have to operate like a poll tax. I don…

The reason this hasn't been done is that historically it was taken as a given that the Federal Government were the last people you wanted to do something like that.

The U.S. is a union of States each with different cultures, attitudes, histories, and needs. It was recognized early on that A STRONG Federal government given responsibility to do ANYTHING at a nationwide scale would quickly rustle jimmies as people would begin to feel more and moredisenfranchised by having institutions forced upon them by people who didn't live there.

Common sense thus dictated the country be run from the bottom up. Delegating only certain unquestionable authority to the Federal Government so as to provide a framework for settling disputes between States, and leaving States to handle their own affairs.

It seems to have become more in vogue for issues to end up bubbling straight to the National Congress without passing through a State first.

Nowadays with mainstream media gushing to its various audiences the National Congress seems to have taken center stage, but there is also increased unrest by those uninterested in having their State's ability to run itself as it will usurped by the Federal.

Re: Utah voting system fending off 1B hacking attempts per day

#184
post #21

Paper ballots, no machines and especially no machines connected to the internet...if we were able to get that crazy bug into Iranian nuclear reactors without direct transfer from Internet, then you can bet North Korea, Russia, Israel, and China will pour billions to do the same thing. Voting ID cards too, though I admit I don’t know enough about that. Even if it costs billions to get it done, confidence in fair and f…

How about Estonia and their online voting? No machines connected to the internet seems like it works there.

Re: Utah voting system fending off 1B hacking attempts per day

#185
post #180
post #156

Earlier quoted context omitted.

The California voting guide for June 2018 is 96 pages long: http://voterguide.sos.ca.gov/pdf/complete-vig.pdf The info associated with each ballot measure is considerably more extensive than you seem to realize.

That's because there are so few votes. Imagine having one single exam at the end of 4 years of education.

No, this is the 2018 guide for the primary election. That is less than 2 years after the 2016 general presidential election. In 4 more months, there will be another 2018 guide for the general election. That means there will be 6 elections in 4 years, not counting any special elections:

http://vigarchive.sos.ca.gov/

You don't even know how many votes we have even though they are so purportedly few. Imagine what little the average voter knows.

Re: Utah voting system fending off 1B hacking attempts per day

#186

Earlier quoted context omitted.

But kill NAFTA. In the US there's really not any community of non-English speaking citizens, so whatever to your complaints about integration, the kids desperately want to integrate (and the parents usually agree). And of course the whole thing where foreigners are scary is as much a modern panic as anything. In periods of pretty open immigration, lots of states didn't require citizenship to vote: https://en.wikipedi…

> In the US there's really not any community of non-English speaking citizens Source? lol

There are hundreds of thousands if not millions of Spanish speaking people and families living in LA, NYC, Miami etc. Many business in the area offer their services in Spanish, and there are enough entertainment options in Spanish that there isn't much of a need to learn English to get by day to day.

Re: Utah voting system fending off 1B hacking attempts per day

#187

Earlier quoted context omitted.

Which supposedly means I can't get on an airplane. I have since been on an airplane. But not one that required a loss of dignity. You'll apparently "lose your dignity" in October [1]. I can't fathom why my bank would need to know if I am allowed to drive. An ID and a driver's license are not necessarily the same thing. [1] http://www.businessinsider.com/tsa-changes-deadline-for-real...

This is completely separate from voting issues, but I tend to avoid settings where I am treated like a suspect. I certainly don't pay people specifically to treat me like a suspect. As you might guess, this means that I don't do business with commercial airlines. It also means that I avoid sporting events that require pat-downs. Or neighborhood parties that require criminal background checks. Or schools with metal de…

"As you might guess, this means that I don't do business with commercial airlines."

It must be wonderful to be able to fly private, but that isn't an option for most of the people that are the subject of this conversation.

Re: Utah voting system fending off 1B hacking attempts per day

#188

Earlier quoted context omitted.

No, what is preposterous is that you cant imagine people with no employment, no bank account, nor vehicle to drive living in the US. Those people have a right to vote even if you aren't impressed with their quality of living.

...living in the US. Those people have a right to vote Living in the US and having the right to vote are not the same thing. Illegal aliens, temporary and permanent residents, and other people of varying status live in the US but cannot legally vote, at least in federal elections.

There are "people with no employment, no bank account, nor vehicle to drive living in the US" who are U.S. citizens. Disenfranchising them is unamerican.

Re: Utah voting system fending off 1B hacking attempts per day

#189

Earlier quoted context omitted.

I have no way to count them. But I can give you one off the top of my head. My dad. Incidentally, he owns two cars.

Incidentally, he owns two cars. If he drives them, he will rightfully be arrested. If he wants to bail out of jail after his arrest, the bondsman will require ID. No ID, and he sits there in jail until his case is heard several months down the line. With respect to your other claims, you seem to be of the belief that a Driver's License and an ID are necessarily the same thing. They are not. You can easily acquire an…

I was responding specifically to a claim that people without a car must be poor and on government support. That was followed by a question about how many adults don't have Driver's Licenses. To the first claim I responded with experience of people without cars who were not poor. To the second question I provided experience with people that don't have a Driver's License.

To your statement, I will respond by letting you know that he does not drive. I agree that he should be arrested if he is found driving without a license.

I will also point out that you have made some of the same poor assumptions as the first comment. If he wants to bail out of jail after his arrest, he will open his wallet and pay cash for his bail. If he doesn't actually have the cash in his wallet, he may send his driver to retrieve more cash.

People without a Driver's License are not necessarily poor. Or uneducated. Or dim-witted.

Re: Utah voting system fending off 1B hacking attempts per day

#190
post #112

Earlier quoted context omitted.

> If you can’t define the operational semantics of a system then you can’t rigorously convince yourself or anyone else that it is “secure.” Well. This means no one can provide any security guarantee for any remotely realistic system because no modern stack has a completely understood&formalized operational semantics. But I definitely know that some systems are much more secure than others! So this seems like a situat…

There are realistic systems that are operationally secure by the given standard. Nuclear launch systems are the obvious example. “Best practice” is a euphemism for whatever it is the majority does. Nobody ever got fired for buying IBM. That’s not even reasoning. Finally, your paragraph about sandboxing is ill considered, but not that wrong. First all programs have operational semantics, the only question is how well…

> There are realistic systems that are operationally secure by the given standard. Nuclear launch systems are the obvious example.

AFAIK there aren't really any examples of production systems that have meaningful, formally verified security properties without gaping holes.

Do you have a good paper about the full stack formalization/verification of a nuclear launch system?

> “Best practice” is a euphemism for whatever it is the majority does. Nobody ever got fired for buying IBM. That’s not even reasoning.

1. Companies are sometimes sued, successfully, for not following "best practices". And on technical merits. Ex, Toyota lawsuits.

2. It most definitely is reasoning! Here's the cartoon derivation: "If I buy IBM I do not get fired. Therefore, I will buy IBM". This is reasoning about the social system, not the technical system. But then, security is both a technical problem and a social problem. $Billions on formal verification can't stop the simplest of phishing attacks.

> First all programs have operational semantics, the only question is how well understood they are.

Well... I guess technically. But that's not typically what people mean when they say something "has a(n operational) semantics".

Typically when people say "X has an operational semantics" they mean "someone has actually tex'd/coq'd/pencil'd the transition rules and maybe proved things about them".

Example: If I implement a programming language without doing any theory and you ask if I have an operational semantics, the only non-confusing answer is "no" or perhaps "the semantics is defined by the implementation of the compiler", which is just a tongue-in-cheek way of saying "no". This doesn't mean that no operational semantics exists, it just means I haven't written it down in the form of transition rules or a coq file or whatever.

If I give my language a denotational semantics and you ask if I have an operational semantics, I'll say "no". But again, that doesn't mean that the operational semantics don't exist. It just means I haven't written them down and proven a correspdonence.

> I’m surprised you’re taking issue with that since you give a great example thereof.

I think you missed the fundamental moral of the sandboxing example: perfect is the enemy of good enough.

Sandboxes allow for security guarantees without formalizing every aspect of the system. In fact, I conjecture that these sorts of "don't try to formalize everything" approaches toward formal security guarantees are really the only ones that scale.

If you try to formalize everything, you'll drown. If you strategically concede defeat and admit that some parts of the system aren't possible to formalize, you can get a lot of strong guarantees. As long as the concessions are strategic. Ex, sandboxing whenever the permissions interface is simple but the implementation is complex and the failure modes permit sandboxing.

Or, to put that observation in a pithy phrase: "perfect is the enemy of good enough."

Post reply on HN