Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

51–60 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#51
post #26
post #16

Earlier quoted context omitted.

There are ways of doing this using encryption so that the person will know what their own vote is in a way that others don't.

"Prove that you voted for Putin or you are out of a job".

Which is what troubles me about making auditable digital voting systems. I'm not sure how you could do it while preserving the secret ballot.

About the best I can come up with is a QR code displayed on the screen and on a printout that you can compare with a third party phone app. Machine results are tabulated, and the QR code sheet is put in a lock box separately. This at least provides some way to compare what the computer says you voted versus the QR backup ballot for audits. I'm sure there are holes in my idea.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#52

Earlier quoted context omitted.

I never understood the desire to have any kind of machine at all. Paper ballots are a perfectly efficient and scalable system used for many large elections. Even if complicated machines are theoretically safe against malfeasance, keeping it simple increases public confidence.

Scalable? Not for same-day. I'd be fine waiting a few days if needed, though. Heck, early voting means I wait for weeks now. Ranked choice voting is essentially doing multiple elections at a time, having to recount portions of votes every time a candidate drops out. That's a lot easier with computers. I think the totals from every precinct could be made public in a way that they are verifiable from a central database…

The UK manages to produce results within a few hours and all ballots, at least for general elections, are hand counted.

I agree that for voting systems other than FPTP it is more work and may take longer - but it’s not an intractable problem.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#53

Earlier quoted context omitted.

I never understood the desire to have any kind of machine at all. Paper ballots are a perfectly efficient and scalable system used for many large elections. Even if complicated machines are theoretically safe against malfeasance, keeping it simple increases public confidence.

Scalable? Not for same-day. I'd be fine waiting a few days if needed, though. Heck, early voting means I wait for weeks now. Ranked choice voting is essentially doing multiple elections at a time, having to recount portions of votes every time a candidate drops out. That's a lot easier with computers. I think the totals from every precinct could be made public in a way that they are verifiable from a central database…

Same-day? It is not a problem at all. For example Finland calculates enough paper ballots in hours to give a definitive result, I am sure there are other countries that manage it as well. Your imagination is stuck in the world of voting practices of your side of the pond.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#54
post #17

Earlier quoted context omitted.

More bits of paper. The ballot papers around here are bloated oversize monstrosities (picture A3 sized) due to the number of parties and candidates but you get a separate one for each election. Unfortunately not every area is paper only.

Here we don't even put names on the ballot, instead there is number assigned for each, this scales up to hundreds of candidates. This does prevent write ins, but I see no reason why you could not have own ballot for each purpose and then say colour code them and append letter or two in front of each candidate for each election.

[dead]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#55
post #34

No one has mentioned 2FA. I suspect the passwords are not all that is needed.

I’ve never seen or heard of 2FA being needed for BIOS access. However maybe we could consider “physical presence” as one type of factor, which does reduce the risk a lot.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#56
post #37

Paper ballots have very boring failure modes and need no explanation or technical support. When you see a system more complex than paper ballots, know that the additions are not there on your behalf .

Colorado uses paper ballots. It's an all-mail voting state so every voter is mailed a paper ballot which is then dropped off or mailed back.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate.

There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are people watching and photographing other family members voting within polling places, and uploading the photographs to social media with parental pride. In many places, this is not even criminal anymore.

Paper ballots, with voters having no method to prove who they voted for (no-receipt), in a private booth.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#57

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

>I hear some people say "but we use paper ballots". Then why do you have a BIOS password? If it's all paper where does the computer fit in? All of this is honest curiosity, I'm not sure how the voting system works.

Not sure about Colorado specifically, but in many jurisdictions voters mark paper ballots, which go into a machine to be tabulated, and are finally deposited into a box for safe keeping/future recounts.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#58

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

CO resident here.

CO mails paper ballots to everyone* about a month before election day. You can choose to vote in person, or mail in/drop off your paper ballot anytime prior to election night.

My understanding is what while the ballots are paper, many (all?) are tabulated digitally. It certainly appears to be laid out in a way that benefits digital reading, and i believe that is what the machines in question are responsible for.

* for some definition of "everyone"

Re: Colorado scrambles to change voting-system passwords after accidental leak

#59

Earlier quoted context omitted.

Colorado uses paper ballots. It's an all-mail voting state so every voter is mailed a paper ballot which is then dropped off or mailed back.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

[flagged]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#60

Earlier quoted context omitted.

Colorado uses paper ballots. It's an all-mail voting state so every voter is mailed a paper ballot which is then dropped off or mailed back.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

It's been the method of voting in Oregon for 25 years and Colorado for 10 years, when does the regret start? The current states that have all mail voting are also some of the least religious states in the country, you'd think the religious states would be pushing for it given the scenario you laid out. Colorado also had the second highest voter turn out nationwide in 2020 which supports the claim that all mail voting is good for increasing access to voting.
Post reply on HN