Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

181–190 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#181
post #67

Earlier quoted context omitted.

> One side says that it is totally secure, basically 0 fraud, most secure election in history Additionally, the sides have completely flipped. Utterly bizarre.

Before 2020 the only allegations of significant fraud or other shenanigans I remember were immediately after elections and were dropped shortly afterwards when no evidence could be found for them. Note that the Bush/Gore election issues were not allegations of fraud or any intentional shenanigans. The issue there was a badly designed ballots and/or badly designed voting machines that let to a large number of spoiled…

What I meant was, the security of electronic voting machines in general.

Prior to Trump, it was afaict an accepted fact among software people that closed source electronic voting machines were sitting ducks ripe for hacking.

We went from "don't trust Diebold" to "how dare you question Dominion."

Whether or not an election has actually ever been hacked at the voting machine level is a separate conversation.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#182

Earlier quoted context omitted.

There are a LOT of elections in the US. Where I live we have ~30 different things to vote on this election. So the incentive to automate things are bigger here.

So does Denmark, why do you assume it's any different? Counting doesn't take that long when you split it across 10K voting districts, which is what the U.S. did for most of its existence. We want ACCURATE elections free from corruption and hacks. You can't undo a fucked up election.

I'm from Sweden where we only have 3 things to vote on (national, county, and city). I assumed Denmark was similar.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#183
post #5

Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.

Can you brute force a BIOS password without prolonged physical access? The leak does increase the risk of a single trusted insider messing with the system, though.

I personally don't put much trust in the security of BIOS vendors. My desktop's motherboard straight up displays the BIOS password if you read the right EFI boot variable (obfuscated with some proprietary "encryption" algorithm with a hard coded key).

Based on previous reports on the security of devices like these, I wouldn't be surprised if a quick flash dump of the NVRAM is enough to crack the password in seconds already. Perhaps voting machine manufacturers have finally made it too difficult to disassemble these machines in a short amount of time, but that's historically not been very difficult.

I would reckon the access time needed to hack+access the BIOS lies in the area of "a few minutes, twice", not the kind of prolonged physical access you'd need to brute force the password.

That's not exactly "someone posing as a voter could hack the machine", luckily, but then again apparently at least one hacker at DEF CON found a vulnerability in voting machines this year that won't be fixed before the upcoming American elections, so who knows if there's an exploit like that lying around.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#184

Interestingly, a website set up to document voter fraud by Mike 'My Pillow' Lindell has collected hundreds of election law violations, many in Colorado. For some reason they are all dated for the future though. Might be a warning signal about not populating your database where the public can watch you doing it. https://archive.ph/smlSQ (capture of https://electionnexus.com from earlier today)

That would support Colorado having a robust system then and we shouldn't be concerned just like the SoS says. If their system was bad, they wouldn't be catching the voter fraud.

The article isn't clear whether they self reported or were made aware. The affidavit mentioned someone reported they had accessed the passwords multiple times before it was taken down. Seems to me someone reported it to the GOP.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#185

Earlier quoted context omitted.

> The US voting machines are just waiting to be hacked, just a matter of when, not if. The US election system is very distributed and fragmented - there is virtually no standardization. Even in the tightest margins for something like President you'd need to have seriously good data to figure out which random municipality voting system(s) you'd need to target to actually affect the outcome.

Ironically America's fragmentary and incoherent electoral system makes it extremely hard to steal an election there.

The 2000 election was decided by 500 votes. You think it would be unfeasible to flip 500 votes in a critical swing state with such a system?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#186

Earlier quoted context omitted.

> One side says that it is totally secure, basically 0 fraud, most secure election in history Additionally, the sides have completely flipped. Utterly bizarre.

Good thing we fixed the hanging chad issue. Did Republicans anywhere try to "secure elections" in a way that didn't involve curtailing voting rights? Improving voting machines, systems, counting, etc. in a way that partisan leadership couldn't mess with? Georgia, I predict, will be a shitshow this year.

I live in one of if not the most critical county in the entire country this election.

It's going to be insane here.

This week alone we've had Bill Clinton, Bernie Sanders, and Tim Walz stumping here.

https://newrepublic.com/article/187597/pennsylvania-election...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#187

    "In addition to the Department of State Employees and in coordination with county clerks, these employees will only enter badged areas in pairs to update the passwords for election equipment in counties and will be directly observed by local elections officials from the county clerk's office.
This is a bit weird. Someone having a perfectly legitimate excuse to fiddle with voting machines, urgently, two days before elections.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#188
post #66
post #41

Earlier quoted context omitted.

If the speed of tabulation is the main reason then why are results no longer known by election night? They're saying it might be days again. When we had paper ballots, we knew that night. (For America)

>When we had paper ballots, we knew that night. (For America) You forgot about 2000. Also, the main reason for the delays are mail-in ballots, which could be delayed for days/weeks, depending on how lenient the deadlines are.

2000 was punch cards and it came down to a razor thin 500 votes in a single swing state.

By law the mail-in ballots have to be in by election day.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#189
post #57

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

>I hear some people say "but we use paper ballots". Then why do you have a BIOS password? If it's all paper where does the computer fit in? All of this is honest curiosity, I'm not sure how the voting system works. Not sure about Colorado specifically, but in many jurisdictions voters mark paper ballots, which go into a machine to be tabulated, and are finally deposited into a box for safe keeping/future recounts.

FTA: “Colorado voter votes on a paper ballot, which is then audited during the Risk Limiting Audit to verify that ballots were counted according to voter intent.”

Re: Colorado scrambles to change voting-system passwords after accidental leak

#190

I think all US folks reading this should volunteer at their county's Registrar of Voters (or equivalent agency for their county). Spend one election working at a polling place, and another election working at the RoV HQ. See what it's like to go through the training, and what things are like on Election Day, and in the days leading up (for places that allow early voting, drop-off, etc.).

This is a very good suggestion. The internet discourse gets further and further from reality in a lot of areas. Engaging in the actual reality of the voting system is an excellent 'touch grass' opportunity for people passionate about the election.
Post reply on HN