Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

191–200 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#191
post #127

Earlier quoted context omitted.

Virality is not an indicator of accuracy or authority. Do you dispute this?

I don’t understand your comment. Are you claiming that the video is fake? — if not, what’s your comment referring to with “accuracy”? — how is “authority” relevant at all, when discussing video of a malfunction?

Provably digitally altered fake videos of voter fraud were made and disseminated by Russia during the US 2020 election. Non-partisan institutions put a lot of energy in trying to debunk these operations which basically suit America's adversaries and, absent of critical thinking, many people become unwitting participants in their disinformation campaigns.

By eating away at the trust of non-partisan institutions that are established to maintain free and fair elections, autocracies like Russia, Iran, China, etc., move up in the world at the expense of internal divisions in the US.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#192
post #67

Earlier quoted context omitted.

Before 2020 the only allegations of significant fraud or other shenanigans I remember were immediately after elections and were dropped shortly afterwards when no evidence could be found for them. Note that the Bush/Gore election issues were not allegations of fraud or any intentional shenanigans. The issue there was a badly designed ballots and/or badly designed voting machines that let to a large number of spoiled…

What I meant was, the security of electronic voting machines in general . Prior to Trump, it was afaict an accepted fact among software people that closed source electronic voting machines were sitting ducks ripe for hacking. We went from "don't trust Diebold" to "how dare you question Dominion." Whether or not an election has actually ever been hacked at the voting machine level is a separate conversation.

Hasn't every other type of computing system been hacked? These systems are so insecure they're leaking passwords on the internet and smart people somehow still believe they've never been tampered with. Trillions of dollars on the line and ability to shape policy for the most powerful economy and military on planet earth but for sure, there's never been any hacks even though we're openly leaking passwords and social security numbers on the internet.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#193
post #143
post #133

Earlier quoted context omitted.

In traditional voting, there is a pretty decent chance you know the person who does the counting or can find someone in your community who can personally vouch for them. Living in my small town at one stage, I knew several of the tabulators personally and all of them by reputation. That is an extreme case, but even in a city these people are somewhat known quantities. With a voting machine that wasn't verified by a h…

Seriously? You are saying that you just trust some people not to manipulate the votes? Why not use a Merkle Tree or a Blockchain to verify that your vote was included in the total ? They were invented to remove trust in middlemen. Mutually distrusting parties can maintain the vote tallying. That’s how elections should be done.

[deleted]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#194
post #27
post #21

I hate the narratives around voting security in the US. One side says that it is totally secure, basically 0 fraud, most secure election in history, etc etc. The other side claims that the election was completely stolen from them by voting machines. Neither of these claims is right. Personally, I doubt the election was stolen. I know of a handful of cases of voter fraud both anecdotally ("My mom [in a retirement home…

This is a wild amount of both-sidesing in a case where one side has evidence and the other is literally an unsubstantiated conspiracy theory at a scale where you could not keep the secret. Most secure in history is (in my state) is correct. There are more pointless safeguards than have ever existed. If you were willing to go with the results of any election pre 2020 then you should be overjoyed at how much more "secu…

Junk mail democracy is the most insecure model for an election I could possibly conceive. Other than entrusting closed source software companies with tabulating votes.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#195
post #143
post #133

Earlier quoted context omitted.

In traditional voting, there is a pretty decent chance you know the person who does the counting or can find someone in your community who can personally vouch for them. Living in my small town at one stage, I knew several of the tabulators personally and all of them by reputation. That is an extreme case, but even in a city these people are somewhat known quantities. With a voting machine that wasn't verified by a h…

Seriously? You are saying that you just trust some people not to manipulate the votes? Why not use a Merkle Tree or a Blockchain to verify that your vote was included in the total ? They were invented to remove trust in middlemen. Mutually distrusting parties can maintain the vote tallying. That’s how elections should be done.

Doesn't the Blockchain, by design, record what is entered into it? So couldn't someone then figure out how you voted?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#196

Earlier quoted context omitted.

Ironically America's fragmentary and incoherent electoral system makes it extremely hard to steal an election there.

You say "fragmentary and incoherent", I say "decentralized".

Decentralised could be each counter putting 5000 or so ballots into piles with people wandering around witnessing for various parties all working a rigid process accross the nation. Each count publically announced in the room before witnesses.

Totally standardised, coordinated, and decentralised. But fragmented (structuraly) or incoherent.

But agree would be a million times worse with a single electronic system

Re: Colorado scrambles to change voting-system passwords after accidental leak

#197
post #143
post #133

Earlier quoted context omitted.

In traditional voting, there is a pretty decent chance you know the person who does the counting or can find someone in your community who can personally vouch for them. Living in my small town at one stage, I knew several of the tabulators personally and all of them by reputation. That is an extreme case, but even in a city these people are somewhat known quantities. With a voting machine that wasn't verified by a h…

Seriously? You are saying that you just trust some people not to manipulate the votes? Why not use a Merkle Tree or a Blockchain to verify that your vote was included in the total ? They were invented to remove trust in middlemen. Mutually distrusting parties can maintain the vote tallying. That’s how elections should be done.

That seems like it'd be impossible to implement. Either I'd have a record that I voted with no way to confirm who my vote was counted for, or I'd be able to prove that I voted for a specific candidate which opens a Pandora's box of problems (either coercion for voting for the wrong candidate or bribes for provably voting for a specific candidate).

I mean sure, if someone can come up with a workable blockchain-based system that would be good, but I don't think that is an in-practice option on the table right now.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#198

Earlier quoted context omitted.

It's been the method of voting in Oregon for 25 years and Colorado for 10 years, when does the regret start? The current states that have all mail voting are also some of the least religious states in the country, you'd think the religious states would be pushing for it given the scenario you laid out. Colorado also had the second highest voter turn out nationwide in 2020 which supports the claim that all mail voting…

Of course mailing ballots increases turnout. That wasn’t the question. The question was how do we determine if the votes are fraudulent, for example someone filling out a ballot for their elderly parents against their will.

Colorado does signature matching and ballot tracking. My signature has changed since I registered to vote here and I was notified in one election about it not matching and had to cure my ballot. If someone voted under my name, I would be notified of the processing of my ballot and could object to it. Ease of voting/security is still an important balance. I could easily create a 100% secure election and it would disenfranchise a lot of voters.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#199
post #72

Earlier quoted context omitted.

What do you do when duplicate serial numbers start showing up? I'm assuming you won't know who was issued which serial number, and if it's truly randomized you wouldn't even know where they were sent.

Then you have clear proof of election fraud and the FBI, NSA, etc can get to work. Invalidate the election results and do a new one.

> Invalidate the election results and do a new one.

The chaos that would ensue from this is staggering.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#200
post #143

Earlier quoted context omitted.

Seriously? You are saying that you just trust some people not to manipulate the votes? Why not use a Merkle Tree or a Blockchain to verify that your vote was included in the total ? They were invented to remove trust in middlemen. Mutually distrusting parties can maintain the vote tallying. That’s how elections should be done.

Doesn't the Blockchain, by design, record what is entered into it? So couldn't someone then figure out how you voted?

(without making any claim about "block chains for voting are good/bad")

Not really. Generally if you want to privately check something like this, you encrypt it for the recipient (government), and sign it with something that only you know. So the contents are hidden from everyone and nobody knows anyone's signature, but you can prove that your item is in the list, unmodified, and is therefore counted.

And then the chain would provide a quick way to check for "has not been modified since I checked", without needing to do the full check again.

Post reply on HN