Live data from Hacker News

CISA: The November 3rd election was the most secure in American history

cisa.gov

21–30 of 211 posts

Re: CISA: The November 3rd election was the most secure in American history

#21

Earlier quoted context omitted.

I'd rather have someone hack 1700 local elections than one 'national standard' quite frankly. The inefficiency delights me

People are always rallying to add blockchain for voting without realizing that the paper ballot is a proof of work that predates it by a significant margin.

Yep. I approve both measures

Re: CISA: The November 3rd election was the most secure in American history

#23
The first thing that came to mind was that quote from the Richard Jewell movie (which is a good watch). Jewell's lawyer has a secretary with an Eastern European accent and they are talking about a newspaper article where the gov't says they have evidence that Jewell is the Olympic Park bomber.

“Where I come from, when the government says someone's guilty that's how you know they're innocent,” she says. “It's different here?”

Re: CISA: The November 3rd election was the most secure in American history

#24

Eight states[0] still have electronic voting systems without paper backups. They're un-auditable. I'm not going to weigh in on the current politics of this situation, but US Election security is awful, now, and since at least 2000. I actually did my degree thesis on designing electronic voting systems (and built one), and ultimately concluded it was impossible to make them fully secure. The best you can do is paper b…

I'd rather have someone hack 1700 local elections than one 'national standard' quite frankly. The inefficiency delights me

Yea that's the only way to do it.... instead of some sort of software that's bad like a malicious software or Malware if you will that changes votes silently

Re: CISA: The November 3rd election was the most secure in American history

#25

Eight states[0] still have electronic voting systems without paper backups. They're un-auditable. I'm not going to weigh in on the current politics of this situation, but US Election security is awful, now, and since at least 2000. I actually did my degree thesis on designing electronic voting systems (and built one), and ultimately concluded it was impossible to make them fully secure. The best you can do is paper b…

What’s your thinking on the “request” process of mail-in ballots? To me, it’s wild to think all one needs to request a ballot is a name, address and ssn... and on top of all of that, you can get the ballot sent to a different address...

This quickly goes down the rabbit hole of identity and identity theft in the USA in a more broad sense. Our entire system is build on similarly flimsy "identity" from banking, to medical records, and even getting copies of a birth certificate/driver's license.

I would say though that "scale matters." If an electronic voting system is compromised the "scale" could be the entire state, and millions of votes, but each time a mail ballot is stolen via identity theft, you're risking it being detected/getting caught, so it ultimately scales to fewer than thousands of potentially problematic votes (which is bad, but not democracy breakingly so, like electronic/computer voting insecurity).

Re: CISA: The November 3rd election was the most secure in American history

#26

Eight states[0] still have electronic voting systems without paper backups. They're un-auditable. I'm not going to weigh in on the current politics of this situation, but US Election security is awful, now, and since at least 2000. I actually did my degree thesis on designing electronic voting systems (and built one), and ultimately concluded it was impossible to make them fully secure. The best you can do is paper b…

I'd rather have someone hack 1700 local elections than one 'national standard' quite frankly. The inefficiency delights me

I don't think you need to hack 1700 local elections to swing the vote.

Re: CISA: The November 3rd election was the most secure in American history

#27
On what basis? Because there aren't any rumors of Russian meddling being sowed by the opposition this time? There are multiple states with no paper audit trail, closed source electronic voting machines, multiple dubious last-minute decisions made around postal ballots due to COVID, no easy way to verify the voter roll.

Making a claim like this reeks of partisanship.

Re: CISA: The November 3rd election was the most secure in American history

#28
Many techies want Biden. Others want Trump. Many would probably prefer someone else. But very, very few would see the integrity of this election as more than an intern-level joke.

If you've ever worked in an environment where money was changing hands (banking, trading, etc) or where security was the real deal (three-letter agencies), or even in the insurance industry, you know that election integrity controls are a half-baked freshman project by comparison.

(For myself, I don't care who wins. I don't believe it matters. But don't piss on me and tell me it's raining.)

Re: CISA: The November 3rd election was the most secure in American history

#29

Eight states[0] still have electronic voting systems without paper backups. They're un-auditable. I'm not going to weigh in on the current politics of this situation, but US Election security is awful, now, and since at least 2000. I actually did my degree thesis on designing electronic voting systems (and built one), and ultimately concluded it was impossible to make them fully secure. The best you can do is paper b…

Do you have a copy of your thesis online? I’d be curious to learn more.

Re: CISA: The November 3rd election was the most secure in American history

#30
post #5

TIL, electronic voting machines are CLOSED SOURCE (hardware and software) - that should be completely unacceptable in an open democracy. It makes me wonder how a statement like this can be proved. > There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised When it comes to something as important as elections the mantra should be: don't trust. verify.

I don’t see security flaws with closed source software that prints backup paper ballots. If anything, it’s better than an open source machine that doesn’t print a paper backup. Those paper backups can be even audited by the voter at the moment they vote. You’re not going to be dumping the source code from a voting machine that is in use.

There’s no need to compromise. When it comes to making elections trustworthy, we should pull out all the stops, even if it’s slightly inconvenient to make the software open source.
Post reply on HN