Live data from Hacker News

UK Government Officials Infected with Pegasus

citizenlab.ca

141–150 of 381 posts

Re: UK Government Officials Infected with Pegasus

#141
post #104

Earlier quoted context omitted.

Yeah, not like there's any sort of transparent way to audit a public chain of data blocks representing votes associated with an anonymous certificates that would allow end users (verified with registration cards and authorized with their mobile device biometrics) to check their votes were recorded correctly and for 3rd parties to easily audit the vote totals. That's a problem that hasn't been solved at all by the cur…

Being able to easily validate what individual people voted for is exactly the opposite of what you want in a voting system, as it make vote buying/selling trivial. I suggest looking into the huge list of previous electoral fraud for all the different kind of attacks that need to be defended against: https://en.wikipedia.org/wiki/Electoral_fraud

Voter coercion and retaliation for voting 'the wrong way' is probably even more important than vote buying/selling.

A key feature of a secret ballot is that it must remove the ability for anyone to verify how you voted even with your cooperation (no matter if willing, coerced or bought) - you must have plausible deniability i.e. any reasonable "demonstration" to others how you voted must be possible even if you actually voted differently.

Re: UK Government Officials Infected with Pegasus

#142
post #57

Earlier quoted context omitted.

> I'm surprised this isn't a major diplomatic incident between the UK and Israel too Are you really surprised? I'd be surprised if the UK and its media made a fuss about it. Certainly we won't be making a fuss about it here in the US that's for sure. I'd imagine russia and china wishes they had 1/10th the influence that israel has in the US/UK. Say what you want about israel, but for such a tiny country, it punches f…

When 11 US diplomats in Uganda turned up with NSO Pegasus Malware on their phones, the US government responded by listing NSO as a covered Entity and forbidding any US company from buying or selling with it without express permission of the USG- Dell can't sell them monitors or laptops without the State Department publishing written, specific permission. Several US congresspersons advocated for even harsher response…

Sure, the US effectively blacklisted NSO, but they did nothing to Israel. Imagine if a Russian business was found to have hacked State Department employees phones. Would being a private company prevent Russia from being blamed, particularly if they had the kind of state connections NSO had?

Re: UK Government Officials Infected with Pegasus

#143

Can’t phone vendors have people pose as a client to NSO to get access to the latest RCE and patch it?

In general, no.

Two aspects. The first is client vetting - such organizations (I have in mind a particular organization that's not NSO but also has products which rely on RCEs) simply don't sell at all to random companies - I'm not sure if they sell to companies at all as all the published cases have been from the government sector, but in any case they already know all the potential clients they might have, it's not like there are many of them in the world. And it's not trivial for Apple to falsely pose as, for example, the intelligence agency of Bolivia in a way that's not easily discovered. Also, in the specific case of NSO, every new client will likely require approval from Israel government for the 'arms' export license, and is likely to be vetted by Israeli intelligence agencies which are considered to be quite competent.

The second aspect is that such organizations generally are very wary of actually giving access to RCEs themselves - in many cases they will sell access to the use of RCEs, where the buyer won't get the ability to get the exploit but rather the seller will run the exploit themselves. Of course there are exceptions, but any less trustworthy clients (e.g. if selling to some USA local law enforcement which realistically aren't as secure as FBI) simply won't get the opportunity to compromise the 'goose that lays golden eggs'.

Re: UK Government Officials Infected with Pegasus

#144

Earlier quoted context omitted.

Generally a lot of voting security experts advocate for paper ballots with electronic counting. It is very robust, efficient, has great fallback, and lots of systems available to keep secure.

This is what a lot of states get wrong, with the voting machine itself being the gateway to entering your vote and having it read. For the machines in my Georgia county, it prints a paper ballot that you drop it into a counting/scanner machine, but the issue is that the only thing on the paper is a QR code that is likely encrypted (nothing readable when scanned with a standard QR reader), so there really isn't a way…

This is how it works in India: Once we click the button for a candidate, There will be light highlighting the selection on the voting machine. A printer that is connected to the voting machine prints the voted candidate symbol (and name?) and shows us the printed paper through a glass for a few seconds for verification and then drops it in.

Later during the counting procedure, random ballots are counted for both. If someone arises some issues about the voting, those are then counted using printed ballot papers.

Re: UK Government Officials Infected with Pegasus

#145
post #107

Earlier quoted context omitted.

Does having a paper trail generated exactly after voting help? This is the system that's followed in India. I tried to think of ways it could fail but it seemed pretty fool proof as far as I can think. I'm pretty sure I might have missed some corner case

If you're going to have a paper trail for an electronic system, then why not just use the paper system? It's like there's a pro-electronic movement that's looking for every excuse to move to electronic... Ok, so we go electronic. We put in all these extra checks and balances to account for it's downsides. It runs well. People start questioning the need for the checks and balances, since it's so full-proof. So we remo…

In India at least there is a lot of votes to manually count. Electronic just makes things smoother. As for people questioning the need I didn't hear anyone raising the during the last election I followed. Besides I'm pretty sure either the election commission of India or the various opposition parties will point out the problems with having just electronic vote records. As far as electronic voting with paper trail goes I see it as just a normal paper based voting system with an automated counting system that can be easily verified

Re: UK Government Officials Infected with Pegasus

#146
post #124

Earlier quoted context omitted.

The issue is verification - how do you verify the elctronic count was accurate? And if you're going to manually count it to verify the electronic count, then why have the electronic count in the first place?

A small, statistically representative sample of the paper ballots are counted by hand and compared against the electronic count. If discrepancy arises, a more thorough audit is performed.

Interesting, makes sense. Is this actually the recommended resolution process by the vendors as well or is this something that needs to be approved and adopted by each voting precinct?

Re: UK Government Officials Infected with Pegasus

#147

Earlier quoted context omitted.

It does though - "rule of the majority" in the Webster definition implies one person, one vote. If you work out the mathematics starting from n=2, and then by induction it holds. If not one-person/one-vote then for every n, there exists a set of weights, for which one person can usurp the popular vote. In the US, due to the electoral college, some state resident's vote counts for more than others which is why the los…

Note majority rule isn't in the definition either, it's just strongly correlated. As the simplest example, a democracy that required 55% of the votes wouldn't stop being a democracy. For more different examples, see the lottery system I linked to, or imagine variations thereof (e.g., half the population votes one year, half the next year, etc.). Also, I don't think the age-limit is a red herring in this case to be ho…

> "As the simplest example, a democracy that required 55% of the votes wouldn't stop being a democracy."

Good point. Considering that 55% is > 50%, would we not say that anything that requires more than 50%, is a supra-majority system? In a multi-party system, they sometimes require some thresholds which requires runoffs but I would consider them supra-majority or supra-variations on the majority rule.

> Claiming a 17yo is not a person in the US but is a person in Argentina undermines the notion that there's a universal definition of democracy... which is the premise of this entire argument!

Societies the world over different notions of what constitutes legal age for driving, marriage, enlisting and in general to be considered of age. Voting is just one more manifestation of that inconsistency.

Your other point about lottery systems does seem interesting but could we not say that term-limits are a (poor) version of a lottery system? Term limits have pros-and-cons and those would transfer to the lottery system, namely lack of institutional knowledge to run a govt in which case the bureaucracy (also called the deep state in fringe literature) would dominate.

Re: UK Government Officials Infected with Pegasus

#148
post #57

Earlier quoted context omitted.

> I'm surprised this isn't a major diplomatic incident between the UK and Israel too Are you really surprised? I'd be surprised if the UK and its media made a fuss about it. Certainly we won't be making a fuss about it here in the US that's for sure. I'd imagine russia and china wishes they had 1/10th the influence that israel has in the US/UK. Say what you want about israel, but for such a tiny country, it punches f…

I don't know about Russia, but China doesn't let people from other nationalities to occupy positions of power especially in foreign policy, in which they're completely right. This is the main weakness of the USA and UK. They will let foreign born people to raise to power and dictate self servicing policies, many times in detriment to their own population. For example, take Henry Kissinger: a german born person, he sp…

The UK is quite xenophobic as it is. No need for extra laws to prohibit foreigners to ascend to positions of power. Your peers will take care of that. I'm quite surprised that an UK born citizen of Pakistani heritage is currently the mayor of London. Maybe Labour is less xenophobic that the others.

Re: UK Government Officials Infected with Pegasus

#149

Earlier quoted context omitted.

I stopped reading around: "Protestants may have arms for their defence suitable to their conditions and as allowed by law;" and something about (only) Ireland repealed it in [1]. In [2] it says, quite straight faced, that "The Constitution of the United Kingdom or British constitution comprises the written and unwritten arrangements that establish the United Kingdom of Great Britain and Northern Ireland as a politica…

> Britain does not have a written constitution but it is followed (how?), Pretty much the same as in the US/Australia/etc where written constitutions exist: the courts strike down unconstitutional laws or acts.

In the absence of a written constitution whatever is unconstitutional is the ad-hoc interpretation of the Justices (or whatever they are called in the UK). There are arguments in the US about strict constructionists vs. judicial activism in regards to justices and judgements.

How do those debates and decisions happen in the UK? Do they just go with whatever the Judiciary deem to be constitutional zeitgeist of the land?

Re: UK Government Officials Infected with Pegasus

#150
post #132

Earlier quoted context omitted.

Generally a lot of voting security experts advocate for paper ballots with electronic counting. It is very robust, efficient, has great fallback, and lots of systems available to keep secure.

I think the problem is who builds it. I wouldn’t trust election software that wasn’t open source with a lot of eyeballs on it. Diebold wasn’t exactly a shining example to set. Preferably a non profit organization backing it and then having it adopted as a standard. I just don’t see that happening in the US where voter obstruction is part of at least one party’s strategy.

Open source doesn’t actually matter here. A closed source electronic system should work just as well. Why?

The way it should work is the machine should just print out a scantron AND a human legible copy (probably with a bar code linking the two). The person submits both by hand. You get early results by counting the scantron. Before certification, there is a statistically significant manual counting of the human legible ballots. For tighter races you recount all. The linked barcode lets you also statistically cross-validate in case there was a discrepancy between the machine readable copy printed and the hand ballot (you sample randomly).

Open source means absolutely 0 here. There are too many vectors of attack (eg physically compromising a machine, chain of custody, malware etc). Better to assume the machine is compromised and build a system that doesn’t care.

Post reply on HN