Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

221–230 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#221

Earlier quoted context omitted.

Colorado does signature matching and ballot tracking. My signature has changed since I registered to vote here and I was notified in one election about it not matching and had to cure my ballot. If someone voted under my name, I would be notified of the processing of my ballot and could object to it. Ease of voting/security is still an important balance. I could easily create a 100% secure election and it would disen…

> Colorado does signature matching and ballot tracking. Don't know about Colorado but many other states have been sending ballots to dead people as well as people who are not resident anymore. The potential for fraud is huge

The signature matching would be the first line of defense against that. They would also be notified of deaths by the department of health and the social security administration. Broadly speaking though, whenever potential cases of fraud of investigated, very few end up being substantiated and the fraud that is committed is caught up front.

https://apnews.com/article/2022-midterm-elections-voting-gov...

https://www.rmpbs.org/blogs/news/colorado-noncitizens-deceas...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#222

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

CO resident here. CO mails paper ballots to everyone* about a month before election day. You can choose to vote in person, or mail in/drop off your paper ballot anytime prior to election night. My understanding is what while the ballots are paper, many (all?) are tabulated digitally. It certainly appears to be laid out in a way that benefits digital reading, and i believe that is what the machines in question are res…

An interesting aside:

I’m an overseas Colorado voter. They lump me in with the military voters so my voting process is super easy (I’m sure certain groups would love to make this harder, but not for the troops). I get an email that my ballot is ready, I go to the CO website, authenticate with my SSN (fucking yikes), fill out my ballot online, print a copy to pdf, slap a digital signature on there, and email it back to the SOS who presumably prints it out and throws it in with the rest, and then get an email saying my vote has been counted.

It’s amazing how easy voting can be when we want it to be.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#223

Earlier quoted context omitted.

Yeah it’s just a polite retelling of the crazy Trump nonsense that was laughed out of court by every judge who looked at it and the rest is just misunderstandings from casual election observers who refuse to do one iota of research about how things work. The accusations are always vague as well since each time you zoom in on one it’s completely anodyne but you need the distance to keep up the specter of something nef…

I guess for me personally I don't deny that Joe Biden won the contest as performed. I just question the contest themselves. After all, if made up my own election law and ran an election, and declared my candidate the winner, no one would listen to me, but that's what happened here, which we know based on scotus's interpretation of whether secretaries of state can change rules the way they did in Pennsylvania.

> that's what happened here

What precisely happened here? Can you specify which ruling you’re talking about and why you think it’s so significant?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#225

Earlier quoted context omitted.

Once you look past individual anecdotes, the actual rate of voter fraud with mail voting is tiny compared to the voting population. https://www.washingtonpost.com/politics/minuscule-number-of-...

Because of how the electoral college works, and because of how tight the margins are, you don't need to have or enable fraud on a massive scale to cheat. All that's needed is putting your thumb on the scale in a few select jurisdictions and that could tip the scales one way or the other. It's within the realm of probability that the presidential election will be decided by < 50k voters nationwide.

Yep.

But you have to know which 50k voters in which state, and be able to put your thumb on the scales without tipping off the dozens of people who are professionally employed to prevent exactly this scenario.

More than a few people have been caught trying to cast just a single extra vote.

How in the world are you going to pull off a massive conspiracy like in the midst of the most scrutinized election in the world.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#226

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

It is important that the voting system have credibility for everyone - regardless of party. Has anyone done a ground up exercise of rethinking the process and the involved technologies from a cybersecurity standpoint? It would be great to offer voters verification of their votes while maintaining secrecy.

But right now I feel like we are stuck, with one half the country having doubts about the process and the other half insisting that it is absolutely perfect. It isn’t enough for the process to be either correct or trustworthy. It has to be both.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#227
post #215

"In addition to the Department of State Employees and in coordination with county clerks, these employees will only enter badged areas in pairs to update the passwords for election equipment in counties and will be directly observed by local elections officials from the county clerk's office. This is a bit weird. Someone having a perfectly legitimate excuse to fiddle with voting machines, urgently, two days before el…

As Jeff Bezos said a few days ago: "Voting machines must meet two requirements. They must count the vote accurately, and people must believe they count the vote accurately. The second requirement is distinct from and just as important as the first." This is not an election where we can afford doubt.

Bezos? What the hell would a tech/business guy have to say about elections and why would anyone listen? He has a newspaper to speak for him, why is he saying this stuff under his own name?

Edit: i was out of the loop but apparently bezos decided to throw his chips out the window for little benefit to himself (or anyone). Just goes to show the wealthy are just as capable of being morons as the rest of us

Re: Colorado scrambles to change voting-system passwords after accidental leak

#228
post #67

Earlier quoted context omitted.

Before 2020 the only allegations of significant fraud or other shenanigans I remember were immediately after elections and were dropped shortly afterwards when no evidence could be found for them. Note that the Bush/Gore election issues were not allegations of fraud or any intentional shenanigans. The issue there was a badly designed ballots and/or badly designed voting machines that let to a large number of spoiled…

What I meant was, the security of electronic voting machines in general . Prior to Trump, it was afaict an accepted fact among software people that closed source electronic voting machines were sitting ducks ripe for hacking. We went from "don't trust Diebold" to "how dare you question Dominion." Whether or not an election has actually ever been hacked at the voting machine level is a separate conversation.

> Prior to Trump, it was afaict an accepted fact among software people that closed source electronic voting machines were sitting ducks ripe for hacking. We went from "don't trust Diebold" to "how dare you question Dominion."

We didn’t, you’re just grossly over-simplifying a couple decades of history. In the 2000s, there were some very bad electronic voting systems which did not maintain paper records or printed receipts which which were never validated. That lead to tons of criticism – and better designs.

In 2020, nobody said “how dare you question Dominion” because the whole point was that we _don’t_ trust Dominion and use systems which are designed to be verifiable and the results had been independently checked multiple times.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#229

Earlier quoted context omitted.

In a serious voting system the paper ballots are saved and can be recounted by hand. I've worked in elections in Sweden, and all elections are recounted at least twice, by different people.

The issue in the US is compounded further as running elections is left up to not only the states, but the individual municipalities in those states and typically run at the county level. Each with their own rules, whether or not ID verification is mandatory or literally illegal, style of voting (mail vs in-person), ballot design/UX, what languages the ballots are in (are ballots in Sweden in anything but Swedish?) an…

On the flip side; it makes it incredibly difficult to pull off wide scale fraud.

Instead of having to compromise a single system, you are forced to compromise dozens or hundreds of systems run by people with opposing ideologies

Re: Colorado scrambles to change voting-system passwords after accidental leak

#230

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

In texas you pick your items on computer and it spits out a paper ballot that you can look at to verify it's what you voted for. The info is also included in a qr code like form for a reader. In the event that something looks off it can be verified by humans. I figured something similar was done all over.
Post reply on HN