Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

111–120 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#111
With partisanship rising to bitter, angry levels in the US while trust in just about every social group on the decline outside of the record defenders, my nightmare scenario has been a contested election result. Having no way to establish to friend, neutral third parties if there was/was not fraud means we can only rely on people's trust in each other to find a reasonable solution. That seems unlikely to end well right now., so all I can hope for is that we dont have such results.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#112

Earlier quoted context omitted.

>Does voter ID improve election security? It does not.

If one defines "election security" as "ensuring that each voter is registered, is alive and present, votes only once, and votes only in the correct location," then obviously requiring voters to legally identify themselves, just as they do when doing any number of everyday activities that involve local government, improves election security. Your assertion seems a bit knee-jerk.

None of those things you've mentioned requires voter ID, so I'm not sure why you're advocating for a solution that fixes nothing you claim is an issue.

Specifically: You can figure out if a voter is registered by cross-checking with the voting rolls, you can figure out if someone is alive by cross-checking obituaries and the other two issues can similarly be figured out by cross-referencing across all elections in a state. None of this requires strict voter ID to figure out and while it's possible that identities could be hijacked to vote for a certain person I believe but voter fraud is incredibly rare in practice.

Additionally all of those checks actually open up more avenues for hackers or less honest individuals to take advantage of said systems. For example dropping a bunch of people off of voter rolls to ensure that they have trouble voting or can't meet the deadline, mistakenly registering people as deceased and so forth. One of the major fears during the possible election tampering was that by altering voter roles you could shift the outcome of an election.

I think your assertion seems more knee-jerk than the person you're responding to.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#113

Earlier quoted context omitted.

>Does voter ID improve election security? It does not.

If one defines "election security" as "ensuring that each voter is registered, is alive and present, votes only once, and votes only in the correct location," then obviously requiring voters to legally identify themselves, just as they do when doing any number of everyday activities that involve local government, improves election security. Your assertion seems a bit knee-jerk.

To be honest, Voter ID addresses a made up problem. Search for wikipedia for 'Voter ID laws in the United States'.

Regardless of your political persuasion, I suggest you read a bit about how these voting machines are built. Assuming you are in tech, you will be horrified. Do you feel comfortable knowing your voting machine was written in VBA with a Excel spreadsheet as the backing data store? This is the level of incompetence we are dealing with. Integrity of our elections is an incredibly important issue for both parties, and this was a problem before Trump, Russia and the 2016 election.

I also suggest you read up on the stuxnet virus if you want to see what a determined state actor can create given unlimited resources.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#114
post #90

Earlier quoted context omitted.

This is another reason (along with preventing remote hacks etc.) that vote-by-mail[1] is much more reasonable. It provides you with as much time as you need to look up candidates and issues. 1: https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon

I don't know about Oregon, but in Washington you also get a thick voter pamphlet that goes over all the candidates and issues in great detail, including candidates' statements about themselves. For initiatives (referendums), it even has statements by pro and con groups, and rebuttals of each others' statements. And you get that way in advance of the election, too, so there's plenty of time to go over it and do any ad…

Yeh its pretty great. I used the pamphlet and googme to look up all of thr candidates while I had some beer. Best voting experience ever.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#115
All this fear of foreign hacks when voter fraud is a big issue. By that I mean dead people voting, vote counting, foreign nationals voting and tampering at the polls.

Whatever. We can ignore that and follow media narratives on foreign hacking instead...

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#116
post #7
post #3

The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…

> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.

In other countries people usually just vote for a few offices or questions at a time. American voters are often presented with 30, 40 or even 50 ballot questions.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#117

Earlier quoted context omitted.

I was just going to post that. I'm concerned that since election security is not (just) a technological problem, that very little will be done to improve it in the foreseeable future. I'm from Idaho which is currently conservative by close to a 2/3 majority, but remember growing up that we had many liberal elected officials like Cecil Andrus and Frank Church. From my perspective, democrats are working to improve elec…

> From my perspective, democrats are working to improve election security while republicans are not. Does voter ID improve election security? Which party opposes voter ID laws?

It does not.

The question you should be asking is what party advocates for voter ID laws in the absence of any evidence to their necessity.

Voter ID laws are a solution to a problem that does not exist to allow political parties that advocate them to suppress votes at will. There is no existing need for voter ID laws and voter ID would not prevent tampering with voting machines.

It may be a worthwhile exercise to see what states advocate insecure voting methods (machines) and voter ID laws.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#118

Earlier quoted context omitted.

> From my perspective, democrats are working to improve election security while republicans are not. Does voter ID improve election security? Which party opposes voter ID laws?

The opposition to voter ID laws is usually down to the implementation details of them that make them non-viable - for example, requiring costly IDs that are also difficult to get (while also closing facilities that issue them in some areas which just happen to vote a certain way). A well-written voter ID law - one that truly guarantees the right to vote for every citizen eligible to do so - might well get enough bipa…

Voter ID laws solve a problem that does not exist. I do not support pointless laws that open us up to further abuse by partisans.

Voter ID laws have been written in a way that they can be systematically (and I believe deliberately) abused to disenfranchise minorities. This is done by setting unreasonable office hours or locations to obtain voter IDs among other methods.

There is no need for voter ID laws and so there will be no bipartisan support for them unless both sides are interested in vote suppression.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#119

Earlier quoted context omitted.

Elections are not national defense. State and local governments have been handling their own elections since before the country was founded. This is a good thing , because it keeps elections close to the people, accountable to the people. The last thing we need is nationalized elections. That would make all of our elections vulnerable together. And that includes federal funding for state and local elections, because…

All it means is a foreign entity like Russia just attacks each state differently. It won't stop them. Clearly, we are doing literally what you're saying, and it hasn't worked. Elections, in the 21st century, should fall within the range of national defense. Power grids and other types of infrastructure are, why not the democratic infrastructure like elections and voting? > The last thing we need is nationalized elect…

I don't totally agree with the OS analogy. The federal government should not have absolute control over how individual states run their elections. The federal government can provide guidelines and basic requirements but it is important that states be allowed to make their own decisions as much as possible.

State's rights are comparable to redundancy in the software world but really these analogies are strained.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#120

Earlier quoted context omitted.

Did you even read the comment you're replying to?

My fault, I missed > even when you know how you will vote in advance.

I still think you missed the point, though... the point of the finding was that the hack takes less time alone with the machine than the average voter takes to vote.... therefore, a hacker won't arouse suspicion while they are doing the hack.

It doesn't matter if there are things a voter can do to speed up voting, it only matters that it still wouldn't be suspicious if someone was in the booth for 2 minutes.

Post reply on HN