Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

1–10 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#4
post #2

Is voting fraud at stake here or leak info over who voted? Is it possible to infer who voted what from the leak?

No, because of the way CO runs elections. But it is possible to gin up fraud claims and then resort to violence if the candidate who did this before loses again.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#5
Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#6
The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc.

The US voting machines are just waiting to be hacked, just a matter of when, not if.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#7
post #5

Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.

Can you brute force a BIOS password without prolonged physical access?

The leak does increase the risk of a single trusted insider messing with the system, though.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#8
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Regarding Indian voting machines, there is also randomization involved at various levels during distribution making it difficult to game the system but still I always wonder if there is any way to hack the system. I hope people in charge have a process to continuously evaluate the security procedures and improve it.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#9
post #8
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Regarding Indian voting machines, there is also randomization involved at various levels during distribution making it difficult to game the system but still I always wonder if there is any way to hack the system. I hope people in charge have a process to continuously evaluate the security procedures and improve it.

I never understood the desire to have any kind of machine at all. Paper ballots are a perfectly efficient and scalable system used for many large elections. Even if complicated machines are theoretically safe against malfeasance, keeping it simple increases public confidence.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#10
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Curious to know more. Is there a good source of information on the security of the hardware and software used for elections India.

As an Indian citizen I see the casual lack of security mindset in large swathe of things implemented by both public and private actors. Many things get better only though iterative failures and corresponding reactive fixes.

What type of failures and improvements have happened here, or instances of demonstrated hardness against those with motivation and access to machinery.

Post reply on HN