Live data from Hacker News

CISA: The November 3rd election was the most secure in American history

cisa.gov

61–70 of 211 posts

Re: CISA: The November 3rd election was the most secure in American history

#61
post #5

TIL, electronic voting machines are CLOSED SOURCE (hardware and software) - that should be completely unacceptable in an open democracy. It makes me wonder how a statement like this can be proved. > There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised When it comes to something as important as elections the mantra should be: don't trust. verify.

Not only that. Vendors can deploy unknown, unapproved firmware updates: https://www.politico.com/news/2020/11/04/georgia-election-ma...

They deployed a mystery closed-source software update right before the election. No matter which way you slice this, it's sheer incompetence and smells fishy (even if it isn't fraud).

If you want to project security, you don't do this kind of thing. It's insane. It's like the plot of a Hollywood movie.

Re: CISA: The November 3rd election was the most secure in American history

#62

https://www.forbes.com/sites/alisondurkee/2020/11/12/pennsyl... I don't understand how you can say the Election was the "most secure" when you literally have a Court in Pennsylvania throw out 10,000 ballots! If the system was so "secure" it shouldn't have even gone to the Courts in the first place and instead the electoral system should have found out the discrepancies on its own! The truth is that US electoral syste…

> I don't understand how you can say the Election was the "most secure" when you literally have a Court in Pennsylvania throw out 10,000 ballots!

Because that wasn't an election security issue, and it wasn't (at least you source does not say it was) 10,000 ballots. “It is unclear how many ballots will be affected by the ruling, but [...] Philadelphia County, the largest county in the state, only flagged 2,100 ballots that had identification issues.” And this wasn't affecting all the ballots flagged with ID issues, only those that were cured after the original deadline and before the challenged extended deadline.

> If the system was so "secure" it shouldn't have even gone to the Courts in the first place and instead the electoral system should have found out the discrepancies on its own!

It...did detect them on its own. The Court case is about the legal authority for the administrative mitigation.

Re: CISA: The November 3rd election was the most secure in American history

#63

Eight states[0] still have electronic voting systems without paper backups. They're un-auditable. I'm not going to weigh in on the current politics of this situation, but US Election security is awful, now, and since at least 2000. I actually did my degree thesis on designing electronic voting systems (and built one), and ultimately concluded it was impossible to make them fully secure. The best you can do is paper b…

Canadian here. We still count ballots the old fashioned way and get our election results out the night of the election (typically). Presumably that scales linearly.. more voters means more ballot boxes and more officials counting and auditing. This seems like a solved problem to me. Why doesn't/wouldn't this work in the US? My guess is the complexity of your ballots -- we typically vote for one person and every coupl…

One of the main reasons it is taking so long is the volume of mail-in ballots is extremely high compared to prior elections. And on top of that, in several states, Republicans were adamant that vote tabulation not begin early to deal with this volume, with the entirely foreseeable result that counting took far longer than necessary.

Re: CISA: The November 3rd election was the most secure in American history

#64
post #5

TIL, electronic voting machines are CLOSED SOURCE (hardware and software) - that should be completely unacceptable in an open democracy. It makes me wonder how a statement like this can be proved. > There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised When it comes to something as important as elections the mantra should be: don't trust. verify.

If it would hard or impossible to produce evidence of tampering, it’s easy for that statement to be true.

Re: CISA: The November 3rd election was the most secure in American history

#65
A laptop and USB drive used to program voting machines were stolen right before the election according to the Associated Press. [1]

The company who claims they cannot be used to manipulate machines has a laundry list of serious security lapses and incompetence. [2] Including remote-access to voting machines?!?! uncovered by the New York Times in 2018. [3]

[1] https://apnews.com/article/voting-machines-voting-custodio-e...

[2] https://en.wikipedia.org/wiki/Election_Systems_%26_Software#...

[3] https://www.nytimes.com/2018/02/21/magazine/the-myth-of-the-...

Re: CISA: The November 3rd election was the most secure in American history

#66

In order to secure the vote we need open source machines, verifiable ballots (including online verification), complete chain of control, body cams on anyone handling ballots, transparency to public and party observers via cameras, multiple isolated tabulations (verifying they all agree), and also strongly verifiable voter ID. Nothing in this process should be left up to chance. I don’t accept the stance that a lack o…

> verifiable ballots (including online verification)

Is this at odds with secret ballots?

Re: CISA: The November 3rd election was the most secure in American history

#67
post #5

TIL, electronic voting machines are CLOSED SOURCE (hardware and software) - that should be completely unacceptable in an open democracy. It makes me wonder how a statement like this can be proved. > There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised When it comes to something as important as elections the mantra should be: don't trust. verify.

Not only are they closed source, but insanely sometimes they have REMOTE ACCESS enabled. [1]

The companies involved can only be described as utterly incompetent in security. [2]

[1] https://www.nytimes.com/2018/02/21/magazine/the-myth-of-the-...

[2] https://en.wikipedia.org/wiki/Election_Systems_%26_Software#...

Re: CISA: The November 3rd election was the most secure in American history

#68

Earlier quoted context omitted.

I don’t see security flaws with closed source software that prints backup paper ballots. If anything, it’s better than an open source machine that doesn’t print a paper backup. Those paper backups can be even audited by the voter at the moment they vote. You’re not going to be dumping the source code from a voting machine that is in use.

There’s no need to compromise. When it comes to making elections trustworthy, we should pull out all the stops, even if it’s slightly inconvenient to make the software open source.

Does any company offer a competitive voting machine with open source software?

Re: CISA: The November 3rd election was the most secure in American history

#69

Earlier quoted context omitted.

To me it’s wild that anyone would want voting to be anything but universal. Shouldn’t they send ballots to every person legally allowed to vote?

Every person legally allowed to vote should be able to vote. No votes should be cast by people not allowed to vote. Mail-in ballots are not secret ballots and that's dangerous. There's a reason a workplace cannot be unionized in the US without a true secret ballot.

Mail-in ballots are secret ballots. The way they work is that they have two envelopes: you put your ballot in the inner envelope, which has no indication of who is casting the ballot. All of that information is on the outer envelope. When processing the ballot, the information is checked on the outer envelope; once verified, the inner envelope is then handed to another station to be opened and fed into the counting machine while the outer envelope is discarded.

Re: CISA: The November 3rd election was the most secure in American history

#70
post #61

Earlier quoted context omitted.

Not only that. Vendors can deploy unknown, unapproved firmware updates: https://www.politico.com/news/2020/11/04/georgia-election-ma...

They deployed a mystery closed-source software update right before the election. No matter which way you slice this, it's sheer incompetence and smells fishy (even if it isn't fraud). If you want to project security, you don't do this kind of thing. It's insane. It's like the plot of a Hollywood movie.

do you have a source for this? i don't doubt it's true, i am compiling evidence for claims like this
Post reply on HN