Earlier quoted context omitted.
> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.
American elections are very rarely one box. Generally there's a whole series of offices being elected separately, and probably several different measures of various sorts being voted on directly.
DEF CON report on vulnerabilities in US election infrastructure [pdf]
31–40 of 145 posts
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#32Earlier quoted context omitted.
And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes. An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about every…
> An electronic scanning system could easily be vulnerable to many of the same issues that are presented here In New York City, optical scanners are used. As a check, random precincts’ ballots are manually tallied. This is a good compromise between cost and security. (There are additional checks, like a public and private count and vote aggregates being publicly posted at every precinct at the end of the night. Obser…
Do they significantly improve accuracy? Do they save a significant amount of money? Do they increase the speed that things are tallied, and does that make a significant difference or improvement anywhere (because unless i'm missing something, getting results a few hours earlier is not a good reason to lessen the security of an election)?
I genuinely don't know, and I'd love to see more information if anyone has it on this.
Because to me, without knowing all of the details, it reads like "we trade some security to save costs by just not tallying some precincts at random".
If it's saving a significant amount of money, to the point where the state is much better off because of it, or if the usage of them somehow increases turnout by decreasing the time it takes to count votes, then I would agree with you. But without evidence like that, I'm sitting here wondering why these machines keep getting used.
Often times things that seem like they shouldn't be secure often are, and I'd love to be wrong about this one.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#33Here's a quick summary of the machines that they have reported vulnerabilities in. I've used [ed] to mark where I'm adding relevant content not present in the report. In my non-professional opinion, none of these vulnerabilities seem earth-shattering, although the potential lack of paper trails makes some of the touch-screen systems very dicey. Both of the touch-screen systems have the option of a voter-verified pape…
Anyone in security could threat model every single of these attacks on the back of a napkin in about six minutes. It is sad that you can replace hard drives in voting machines, but of course that's expected and rather obvious.
It'd be neat if DefCon would use some of its money and sponsor a device roadshow. Ship these things around to different labs and makerspaces for month long stints. Sign up someone who has a vague idea of what he or she is doing that can guide and teach others on weekends. Let people do real work and not just marketing.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#34There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district…
I feel I could spend well over a week going through trying to learn more about each point made.
I've also heard some people claim that a lot of these voting machines are no longer used.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#35The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…
> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#36Here's a quick summary of the machines that they have reported vulnerabilities in. I've used [ed] to mark where I'm adding relevant content not present in the report. In my non-professional opinion, none of these vulnerabilities seem earth-shattering, although the potential lack of paper trails makes some of the touch-screen systems very dicey. Both of the touch-screen systems have the option of a voter-verified pape…
The concept of xyz "villages" at DefCon was always pretty silly. Very little, if anything, new is going to come out when people have no real time or access to these devices. Combine that with the technical skill of the average attendee and you get results like this. Anyone in security could threat model every single of these attacks on the back of a napkin in about six minutes. It is sad that you can replace hard dri…
It's just another reason why voting machines (or vote counting machines) are so dangerous. Even if the public had the ability to audit and verify the machines are working correctly, they aren't allowed to.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#37Earlier quoted context omitted.
> An electronic scanning system could easily be vulnerable to many of the same issues that are presented here In New York City, optical scanners are used. As a check, random precincts’ ballots are manually tallied. This is a good compromise between cost and security. (There are additional checks, like a public and private count and vote aggregates being publicly posted at every precinct at the end of the night. Obser…
But what is the motivation for the optical scanners? Why do away with a system that has proven to work and has known, mitigatable (is that a word?) downsides with one that is consistently found to have dangerous gaps in security and time and time again found extremely vulnerable? Do they significantly improve accuracy? Do they save a significant amount of money? Do they increase the speed that things are tallied, and…
> Do they improve accuracy?
I think they pretty clearly would increase accuracy, modulo any potential tampering. Some of this is structural -- each ballot has multiple elections, some in which the same candidate can be featured multiple times under different party affiliations. Tallying this by hand seems intrinsically error-prone. It's arguable that simplifying the ballot could help both tallying and voting, but given the current design optical scanning seems like a huge increase in accuracy.
> do they save a significant amount of money?
Once again, I suspect yes -- tallying the votes by hand takes a lot of time and a lot of people. Poll workers aren't well-compensated by any means, but there's still a cost.
> Do they increase the speed that things are tallied, and does that make a significant difference or improvement anywhere (because unless i'm missing something, getting results a few hours earlier is not a good reason to lessen the security of an election)?
I think yes to the first and a matter of opinion on the second. I'm with you that speed of results is either a non-goal or an anti-goal -- states that release precinct-level results when voting is still open elsewhere in the country are implicitly engaging in electioneering in my mind, and should be explicitly forbidden from doing so.
An automated system combined with random manual tallies seems pretty good to me from a security standpoint. As an aside, in addition to the random tallies I believe there is a process where any party can request a certain number of explicit audits if they feel that the results seem questionable from a given precinct, and an additional layer of election supervisors who can make a non-partisan request if there are inconsistencies from previous election cycles) seems like
In New York I would prefer that the focus be on distributing voter information earlier and more widely would be a much better use of time than further changing the actual voting. When I lived in Washington state, you got a voter information guide with all the candidates and ballot measures, statements for and against, and an explicit statement as to what is being voted on, well in advance of the election. In New York, half the time I have to really dig to even find out what is going to be on my ballot, and finding the full text of ballot measures is an exercise in futility as you try to navigate through the NY Department of State to try to find the information. Third-party sources like local newspapers actually do a significantly better job than the state does here.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#38I was surprised to read that this remote vulnerability is possible in 23 states. I thought that the United States prides itself on its democracy? How come voting machines are possible in a democracy?
(In case you're not from the US: our government is largely a representative democracy, not a direct democracy, with a few exceptions, such as California's proposition system.)
I would say that voting machines are also a niche issue: whether that's good or not, IDK, but most candidates (I feel) would rather discuss their positions on more mainstream topics such as gun control issues, gay rights, abortion, economics issues (particularly vague economic issues), whether or not we should build a wall, etc. Technology is a rare issue, and even rarer to see a candidate demonstrate an understanding of the facts in the issue.
Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#39Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]
#40Earlier quoted context omitted.
usually many options to pick 1 from.
American elections are more complicated. A typical November ballot will have upwards of 20 choices on it, for national, state, county, anf municipal positions, judges, and referendums.
It may take some time to fill out a ballot paper. But the act of voting itself is inserting the ballot paper into the locked and monitored ballot box, which takes a second or two.
My polling place is filled with tables and chairs and cardboard privacy dividers, but has just one ballot box, with a scanner-tabulator on top of it.
The electronic voting machines that take the place of the paper ballot are the problem. You need dozens per polling place, and each one is expected by design to be alone with a voter, with physical access and privacy, for tens of minutes. I presume by default that any jurisdiction using them is actively promoting the hacking of their own elections, and such presumption must be rebutted only by exposure of the facts of the process that would mistrust the communications coming from those boxes as compromised and potentially malicious. I cannot fathom how it would even be possible to secure such devices. At least the scanner-tabulators attached to ballot boxes can be watched continuously.