Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

51–60 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#51
post #5

Virginia went back to paper ballots and optical ballot scanning several years ago. I think the only drawback to this approach is storing the ballots for X years after an election (takes up space). But, it's far more secure and easy for everyone to do. Just like taking a high school test... pencil in the circle. https://en.wikipedia.org/wiki/Optical_scan_voting_system

I don't like to double post, however after skimming parts of the linked PDF, it turns out that the style of optical scanners you are talking about are actually in there.

One of the models (the ES&S M650) might be the actual scanners you are talking about, and that model has a number of terrifying vulnerabilities!

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#52
post #10

There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district…

I have a counter proposal:

Demonstrate a model election. As in show what it looks like, explain all the bits.

Voter registration, candidate filing, ballot production, poll books, signature verification, tabulation, ballot summary reports, etc.

This will equip laypersons with the knowledge of what to fight for as they reform (improve) their local elections.

FWIW, the gold standard is paper ballots cast at poll sites, tabulated when the polls close. Variations may be desirable, eg postal ballots to enfranchise, but know the tradeoffs.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#53

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

Did you even read the comment you're replying to?

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#54

Earlier quoted context omitted.

American elections are more complicated. A typical November ballot will have upwards of 20 choices on it, for national, state, county, anf municipal positions, judges, and referendums.

Around here, typical to have 1 to 3 federal races, 5 to 8 statewide offices, 10 to 20 county and municipal contests, a handful of judge retention questions, and 1 to 20 other referendums. About half the races are usually uncontested. It may take some time to fill out a ballot paper. But the act of voting itself is inserting the ballot paper into the locked and monitored ballot box, which takes a second or two. My pol…

Yes, electronic voting machines are the problem. That is what this article is about.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#55
Really don't like how political and advocative DefCon has gotten.

Finding and publishing vulnerabilities is fine. But DefCon shouldn't be advocating policy or fixes. That should be left to the government, businesses, etc. The more defcon mixes with authorities, the better.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#56

Earlier quoted context omitted.

Oh wow, did they really call it that? I mean it's not wrong, the net neutrality debate is about deregulating the internet by the government so that the ISPs can regulate it. But you have to know what more freedom for ISPs can entail. I mean if it was called Unlimited Gun Use Freedom it could be a name for legalized murder.

I totally made it up, but it's not far. For example, here in MO they put a ballot initiative titled "Right to Farm" on the ballot and advertised it as "we're protecting your right to farm! Standing up for the small family farmers!" when in reality it keeps people from having standing to sue a factory farm when runoff from a pig farm pollutes their land.

After California Prop 8 (vote for gay marriage! Where "yes" meant "prohibit it" and "no" meant "don't prohibit it") California adopted a measure where the AG has to verify that ballot measure titles are neutral.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#58

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

Right, you should do that, but not all voters have the means to research beforehand.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#60
post #33
post #9

Here's a quick summary of the machines that they have reported vulnerabilities in. I've used [ed] to mark where I'm adding relevant content not present in the report. In my non-professional opinion, none of these vulnerabilities seem earth-shattering, although the potential lack of paper trails makes some of the touch-screen systems very dicey. Both of the touch-screen systems have the option of a voter-verified pape…

The concept of xyz "villages" at DefCon was always pretty silly. Very little, if anything, new is going to come out when people have no real time or access to these devices. Combine that with the technical skill of the average attendee and you get results like this. Anyone in security could threat model every single of these attacks on the back of a napkin in about six minutes. It is sad that you can replace hard dri…

They tried to. The companies manufacturing the devices refused.
Post reply on HN