Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

41–50 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#41

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

Oh wow, did they really call it that?

I mean it's not wrong, the net neutrality debate is about deregulating the internet by the government so that the ISPs can regulate it. But you have to know what more freedom for ISPs can entail.

I mean if it was called Unlimited Gun Use Freedom it could be a name for legalized murder.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#42

Earlier quoted context omitted.

But what is the motivation for the optical scanners? Why do away with a system that has proven to work and has known, mitigatable (is that a word?) downsides with one that is consistently found to have dangerous gaps in security and time and time again found extremely vulnerable? Do they significantly improve accuracy? Do they save a significant amount of money? Do they increase the speed that things are tallied, and…

I don't have any specific data here, just a gut feel. > Do they improve accuracy? I think they pretty clearly would increase accuracy, modulo any potential tampering. Some of this is structural -- each ballot has multiple elections, some in which the same candidate can be featured multiple times under different party affiliations. Tallying this by hand seems intrinsically error-prone. It's arguable that simplifying t…

I'm not sure I agree that they increase accuracy to the point that it would be worth the downsides. A room full of people who all don't trust one another I feel can do a fairly good job of reducing the errors down to a minimum. Again, I could be wrong, and I'd love to see a study or some research in this area that proves me wrong! (after all, history shows us that a crowd of like-minded people are capable of some very shitty things without some kind of checks and balances)

And while I'm sure they save some money, is it worth it? I'd like to get an idea of the scale involved. Because saving a few hundred thousand dollars a year for a state would make it absolutely not worth it in my opinion, but a few hundred million might be.

And finding exact numbers is extremely hard (at least for me), combined with the fact that these companies basically never release that kind of information, and I know it's not the best idea to read into these things, but I can't help but think that they would release these numbers if they were significant and showed the company saving tons of money for the state.

But i completely agree that there are much better things we can do to improve voting overall (personally my vote is for changing to a "ranked voting" system), but these machines still feel like a giant red flag to me. There's not a lot that can be done to swing an election by just a few people, but put some kind of electronic or computerized system in the mix, and now there's one dock worker that has access to a large number of the machines as they get shipped, and now you have a single point of failure.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#43
post #8
post #5

Virginia went back to paper ballots and optical ballot scanning several years ago. I think the only drawback to this approach is storing the ballots for X years after an election (takes up space). But, it's far more secure and easy for everyone to do. Just like taking a high school test... pencil in the circle. https://en.wikipedia.org/wiki/Optical_scan_voting_system

And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes. An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about every…

>An electronic scanning system could easily be vulnerable to many of the same issues that are presented here.

While in school in the 80's I learned that the standardized tests the school were administering didn't mean anything. They had no barring on my ability to graduate or go to college so I stopped caring about them. This opened up the freedom to do things like fill out multiple bubbles per line and otherwise get creative. About a month after filling out a test like this I got called into the office along with my parents. I was a pretty well known hacker at the time, running a couple local BBS's and whatnot. The state superintendent of schools was in the meeting and demanded to know what I did to their test scanning system. It turns out that I most likely caused a buffer overflow as line after line of multiple answers on the bubble sheet caused the system to crash. It took them weeks to figure out it was my test and in the mean time deadlines were being missed, etc.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#44
From the "Next Steps" section in the report:

>Congress Must Fund Election Security:​ National defense is not the role of state and local government. Further, no state or local government will ever be able to raise enough capital to defend itself from a determined nation state. Thus, having codified the basic security standards developed by local election officials above, Congress must finance the implementation of these security standards.

Well. We tried: https://www.pbs.org/newshour/politics/republicans-block-bid-...

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#45
post #10

There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district…

This is great to say, but just wanting something doesn't get it done. How could we be proactive and accomplish this? I don't have any of the necessary skills, or the audience. This is really important to put attention toward because that is the only way to get those in power to care. How can we find the right people to make digestible press packages about this, and how do we get it published by people?

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#46
post #8

Earlier quoted context omitted.

And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes. An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about every…

> An electronic scanning system could easily be vulnerable to many of the same issues that are presented here In New York City, optical scanners are used. As a check, random precincts’ ballots are manually tallied. This is a good compromise between cost and security. (There are additional checks, like a public and private count and vote aggregates being publicly posted at every precinct at the end of the night. Obser…

In California audits are required by law but in the 2016 primary a number of municipalities (San Diego and Los Angeles and others) said, "Well the audits cost too much so we just won't do them" and nothing happened.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#47

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

Oh wow, did they really call it that? I mean it's not wrong, the net neutrality debate is about deregulating the internet by the government so that the ISPs can regulate it. But you have to know what more freedom for ISPs can entail. I mean if it was called Unlimited Gun Use Freedom it could be a name for legalized murder.

I totally made it up, but it's not far. For example, here in MO they put a ballot initiative titled "Right to Farm" on the ballot and advertised it as "we're protecting your right to farm! Standing up for the small family farmers!" when in reality it keeps people from having standing to sue a factory farm when runoff from a pig farm pollutes their land.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#48
post #8

Earlier quoted context omitted.

And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes. An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about every…

>An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. While in school in the 80's I learned that the standardized tests the school were administering didn't mean anything. They had no barring on my ability to graduate or go to college so I stopped caring about them. This opened up the freedom to do things like fill out multiple bubbles per line and otherwise get…

[deleted]

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#49

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

The previous comment specifically says reading to make sure you are voting correctly even if you know how you are going to vote. Having voted in California, I can confirm it takes a sizable amount of time to check your ballot even when you have a cheat sheet with you.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#50
post #13
post #8

Earlier quoted context omitted.

And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes. An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about every…

I agree, but the optical scanners are like 1000 times better than wirelessly accessible Windows XP laptops... which is what they replaced. One step at a time ;)

[deleted]
Post reply on HN