Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

121–130 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#121
post #96

Earlier quoted context omitted.

You get to feed the ballot into the (literal) black box yourself, it beeps and tells you your vote has been recorded. What did it record? Who knows?

The idea is that the machine just provides a preliminary count, a official manual count happens over the following several hours. If there's a discrepancy then the only the manual count counts and the machine can be identified as problematic.

No manual count happens unless the results of the election are in question (very close race, evidence of impropriety, etc.)

Re: Colorado scrambles to change voting-system passwords after accidental leak

#122
post #92

Earlier quoted context omitted.

[flagged]

My point is “video of thing happening on social” media is worth essentially nothing these days

Yeah, if it is a problem then the person that cannot vote for their intended candidate (I presume it's a two step process - select, then confirm) should flag it up at the officials and the machines shut down / replaced / fixed and its manufacturer shitcanned. There's procedures for this, and instead of ragebaiting on social media there should be a firm and conclusive response.

Nothing wrong with paper votes.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#123

Earlier quoted context omitted.

Colorado uses paper ballots. It's an all-mail voting state so every voter is mailed a paper ballot which is then dropped off or mailed back.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

> ... when they see entire church memberships filling out their ballots together ...

Are you able to cite any evidence for this sort of conspiracy, or is this mainly conjecture? My search came up short. While one can certainly imagine it taking place, particularly in smaller groups, I expect there are both federal and likely also state laws that would make such activities illegal. At the very least, it would seem hard to hide at scale.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#124
post #37

Paper ballots have very boring failure modes and need no explanation or technical support. When you see a system more complex than paper ballots, know that the additions are not there on your behalf .

I disagree. I believe there are people who want results sooner rather than later. The greater the delay, the more annoyed folks become. Recording votes in _both_ paper and electronic form allows for the auditability of paper and the speed of electronic calculations. (Side note: I also believe that hand-counting of ballots can be tedious, and humans performing tedious, repetitive tasks are prone to error. See [1].) [1…

Why should you compromise on security because you're impatient? Have the voter vote on paper; since it's only two candidates, this can be postcard-sized. Scan the postcards for the fast results, check and double check by hand (or visual if there's a picture taken by the scanner).

Re: Colorado scrambles to change voting-system passwords after accidental leak

#125

Earlier quoted context omitted.

Colorado uses paper ballots. It's an all-mail voting state so every voter is mailed a paper ballot which is then dropped off or mailed back.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

> [...] when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate.

That's a felony isn't it?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#126
post #76

Earlier quoted context omitted.

Which is what troubles me about making auditable digital voting systems. I'm not sure how you could do it while preserving the secret ballot. About the best I can come up with is a QR code displayed on the screen and on a printout that you can compare with a third party phone app. Machine results are tabulated, and the QR code sheet is put in a lock box separately. This at least provides some way to compare what the…

>About the best I can come up with is a QR code displayed on the screen and on a printout that you can compare with a third party phone app. That's definitely not secret. If you can audit it on your phone, baddies can force you to show your phone to verify that you voted "correctly".

It's not, but I'm saying you have the option to compare the two with an outside reference at the time of voting. You keeping the result on your phone after would be entirely your decision.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#127

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

[flagged]

Virality is not an indicator of accuracy or authority. Do you dispute this?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#128
post #79

Earlier quoted context omitted.

You get to feed the ballot into the (literal) black box yourself, it beeps and tells you your vote has been recorded. What did it record? Who knows?

> What did it record? Who knows? How is it any different than traditional voting, where you drop your ballot into a black box and trust the poll workers would count it correctly? You can do random spot checks select boxes to make sure the machine is tabulating correctly. If they're all correct, you can be reasonably sure the others are correct as well, unless your adversary has incredible luck.

Historically, you open the box and count them in front of anyone who wants to watch — using enough polling sites that’s a relatively short task at each.

Moving ballots, machine counting, etc are all relatively modern inventions — and seem to greatly weaken the consensus mechanism for little benefit.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#129

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

[flagged]

[deleted]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#130

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

[flagged]

Those aren't used in Colorado, so what's the relevance?
Post reply on HN