Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

81–90 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#81
post #33

Earlier quoted context omitted.

The concept of xyz "villages" at DefCon was always pretty silly. Very little, if anything, new is going to come out when people have no real time or access to these devices. Combine that with the technical skill of the average attendee and you get results like this. Anyone in security could threat model every single of these attacks on the back of a napkin in about six minutes. It is sad that you can replace hard dri…

They tried to. The companies manufacturing the devices refused.

Rule one (1) for voting machines should be something along the lines of making examples available for testing to all main political parties; and at cost price to all people who are electoral candidates.

The parties then can have them analysed and choose whether to use them or not, perhaps something like all those with more than 10% of the vote previously could decide whether to use machines or human counting; full consensus required.

Rule two (2) should be something along the lines of all votes requiring an agreed sampling to be counted via alternative methods.

You could even have a sample of electoral wards not use the machines at all - that would suggest irregularities if there was tampering, as the hand [machine] counted wards would have different voting preferences to the others.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#82

Earlier quoted context omitted.

When you are voting for a dozen candidates and a dozen ballot measures, it takes time to read through all of them and make sure you are marking the correct boxes, even when you know how you will vote in advance.

This is another reason (along with preventing remote hacks etc.) that vote-by-mail[1] is much more reasonable. It provides you with as much time as you need to look up candidates and issues. 1: https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon

Can confirm from Colorado. They send everyone a vote by mail application whether you ask for it or not.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#83
post #77
post #2

I was surprised to read that this remote vulnerability is possible in 23 states. I thought that the United States prides itself on its democracy? How come voting machines are possible in a democracy?

This isn't a remote vulnerability, btw. The attach involves picking the lock a and inserting a device to a parallel port.

The surprising part of most of these vulnerabilities is they are hardware attacks. I had a talk with someone the other day that said she heard people were hacking votes from iPhones. The over simplification of the topic is doing just as much harm as good.

I don't know any security professional that would tell you physical access isn't equal to the ability to hack a device.

The reality is subversion of people managing processes is of a higher probability that attacks of the machines themselves. It's also not unique to electronic voting, people are always the weak link in security and will always be the weak link.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#84
post #3

The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…

> 2. Remote Attacks Proven: ​Despite insistence the fact that machines are “air gapped” from the Internet protects against all remote attacks, both DEF CON 25 and 26 found exploits to hack machines remotely, requiring physical access to the machine. Did you leave out a word?

without

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#85

This is terrifying. Full stop.

Every electronic device is hackable with physical access. Every process that has humans involved is exploitable.

I'm more alarmed at the number of people willing to complain and moan about change, yet refuse to volunteer at their local polling station. If awareness is important, we have to start somewhere, yet the vast majority of people complaining expect it to just solve itself.

Sometimes to fix a broken system you have to become a part of it and change from the inside.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#86

Really don't like how political and advocative DefCon has gotten. Finding and publishing vulnerabilities is fine. But DefCon shouldn't be advocating policy or fixes. That should be left to the government, businesses, etc. The more defcon mixes with authorities, the better.

If [the government, businesses, etc.] could not (or did not) find these vulnerabilities, most of which seem like things your average techie might have checked for, what evidence is there to suggest that [the government, businesses, etc.] know how to fix them either?

The same could be said for any system where a vulnerability is found.

Vulnerabilities exist, it's the efforts we put into addressing them that matters. Yelling about one party or the other being responsible won't solve the problem. The first steps to a big fix would simply be locking down processes, things that can be done by volunteers joining in the efforts of their local and or state voting agencies.

It's easy to sit on the sides lines and say this and that are wrong, I'd rather see more people standing up and trying to find solutions that work.

I volunteer and we are always short and no one every seems to "have the time". The quality of candidates that do volunteer are all over and would have far greater an impact with more tech exposed individuals instead of the common retirees that I work with.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#87
post #7

Earlier quoted context omitted.

> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.

When you are voting for a dozen candidates and a dozen ballot measures, it takes time to read through all of them and make sure you are marking the correct boxes, even when you know how you will vote in advance.

U.S. ballots also randomize the candidates' names, so that you can't scan each new list quickly by alphabet or political party to look for the person you intend to vote for. The result is that it takes more than a few seconds of sustained concentration to make sure that you're marking your ballot as intended. That's especially true when individual offices attract many small-party candidates.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#88
post #77

Earlier quoted context omitted.

This isn't a remote vulnerability, btw. The attach involves picking the lock a and inserting a device to a parallel port.

The surprising part of most of these vulnerabilities is they are hardware attacks. I had a talk with someone the other day that said she heard people were hacking votes from iPhones. The over simplification of the topic is doing just as much harm as good. I don't know any security professional that would tell you physical access isn't equal to the ability to hack a device. The reality is subversion of people managing…

The first new attack described in last year's report was that you could DoS a machine by removing its CPU.

Which, sure, is something to think about. But it's not what I think people are imagining when you say "voting machine hacking."

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#89
post #7
post #3

The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…

> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.

The last time I voted, earlier this year, there were some 20+ races on the ballet and something like 60 candidates. It takes time to read through all that and choose correctly. With voting machines there is also extra UI, in my case related to the dial mechanism and back/next/submit buttons used for "checking boxes".

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#90

Earlier quoted context omitted.

When you are voting for a dozen candidates and a dozen ballot measures, it takes time to read through all of them and make sure you are marking the correct boxes, even when you know how you will vote in advance.

This is another reason (along with preventing remote hacks etc.) that vote-by-mail[1] is much more reasonable. It provides you with as much time as you need to look up candidates and issues. 1: https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon

I don't know about Oregon, but in Washington you also get a thick voter pamphlet that goes over all the candidates and issues in great detail, including candidates' statements about themselves. For initiatives (referendums), it even has statements by pro and con groups, and rebuttals of each others' statements. And you get that way in advance of the election, too, so there's plenty of time to go over it and do any additional research you feel necessary.

Here's an example from this year.

https://www.kingcounty.gov/~/media/depts/elections/how-to-vo...

Post reply on HN