Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

241–250 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#241
post #79

Earlier quoted context omitted.

> What did it record? Who knows? How is it any different than traditional voting, where you drop your ballot into a black box and trust the poll workers would count it correctly? You can do random spot checks select boxes to make sure the machine is tabulating correctly. If they're all correct, you can be reasonably sure the others are correct as well, unless your adversary has incredible luck.

In a serious voting system the paper ballots are saved and can be recounted by hand. I've worked in elections in Sweden, and all elections are recounted at least twice, by different people.

*ahem*

> and are finally deposited into a box for safe keeping/future recounts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#242

Earlier quoted context omitted.

The issue in the US is compounded further as running elections is left up to not only the states, but the individual municipalities in those states and typically run at the county level. Each with their own rules, whether or not ID verification is mandatory or literally illegal, style of voting (mail vs in-person), ballot design/UX, what languages the ballots are in (are ballots in Sweden in anything but Swedish?) an…

On the flip side; it makes it incredibly difficult to pull off wide scale fraud. Instead of having to compromise a single system, you are forced to compromise dozens or hundreds of systems run by people with opposing ideologies

On the flip side: it makes it incredibly difficult to notice you were a subject of a wide scale fraud.

You need to know an every single system and you can't look for discrepancies what would be obvious in the environment with a standardised system.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#243

Earlier quoted context omitted.

Then you have clear proof of election fraud and the FBI, NSA, etc can get to work. Invalidate the election results and do a new one.

'Just do a new election' is not a valid fallback.

Not valid why? Lack of political will, or logistically unfeasible?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#244
post #5

Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.

these machines aren't hooked up to the internet, how are you going to brute force every machine that a community uses and also requires physical proximity?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#245
post #62
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Just use paper, and count by hand on the day. You need to present an election system that will convince Joe Q. Public, who is almost certainly not as tech-literate as this forum, is probably not even white-collar or university educated, and likely also suspicious of globalisation. "Tamper-proof Indian system-on-a-chip" does not have that property. Otherwise you get increasingly unhinged arguments over the election re…

A high speed electronic ballot reader with a mechanical counter display. So you can stand there and watch it count. Then run it through a duplicate machine. It should say the same thing.

Appropriately documenting these occurrences should not be hard. Appropriately archiving them would be moderately difficult but would serve as the evidence of the final tally. The final tally of all precincts could then be calculated by any number of independent organizations.

There can't be any hard to understand computer voodoo, deleteable audit logs, or single vendor reporting the final tally. No one should trust that anyways.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#246

Earlier quoted context omitted.

Yeah it’s just a polite retelling of the crazy Trump nonsense that was laughed out of court by every judge who looked at it and the rest is just misunderstandings from casual election observers who refuse to do one iota of research about how things work. The accusations are always vague as well since each time you zoom in on one it’s completely anodyne but you need the distance to keep up the specter of something nef…

I guess for me personally I don't deny that Joe Biden won the contest as performed. I just question the contest themselves. After all, if made up my own election law and ran an election, and declared my candidate the winner, no one would listen to me, but that's what happened here, which we know based on scotus's interpretation of whether secretaries of state can change rules the way they did in Pennsylvania.

>After all, if made up my own election law and ran an election, and declared my candidate the winner, no one would listen to me, but that's what happened here, which we know based on scotus's interpretation of whether secretaries of state can change rules the way they did in Pennsylvania.

1. what happened in Pennsylvania?

2. why did a SCOTUS with 6-3 majority of republicans decide to side with Biden, of all people?

3. you haven't answered my previous question. what specific "irregularities" lead to you to not believe the official election results?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#247
post #151

Interestingly, a website set up to document voter fraud by Mike 'My Pillow' Lindell has collected hundreds of election law violations, many in Colorado. For some reason they are all dated for the future though. Might be a warning signal about not populating your database where the public can watch you doing it. https://archive.ph/smlSQ (capture of https://electionnexus.com from earlier today)

Same guy has been running a $14.88 promotion for a month (14/88 is a recognised US far-right symbol: https://www.adl.org/resources/hate-symbol/1488 )

The ADL is a joke of an organization. Professional bullies.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#248
post #200

Earlier quoted context omitted.

Doesn't the Blockchain, by design, record what is entered into it? So couldn't someone then figure out how you voted?

(without making any claim about "block chains for voting are good/bad") Not really. Generally if you want to privately check something like this, you encrypt it for the recipient (government), and sign it with something that only you know. So the contents are hidden from everyone and nobody knows anyone's signature, but you can prove that your item is in the list, unmodified, and is therefore counted. And then the ch…

Assuming uncontrolled public access to the blockchain, couldn't this also be used to prove to others that you voted "correctly", facilitating vote buying schemes?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#249
post #57

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

>I hear some people say "but we use paper ballots". Then why do you have a BIOS password? If it's all paper where does the computer fit in? All of this is honest curiosity, I'm not sure how the voting system works. Not sure about Colorado specifically, but in many jurisdictions voters mark paper ballots, which go into a machine to be tabulated, and are finally deposited into a box for safe keeping/future recounts.

I voted early in person in Colorado a few days ago. Use a machine to entry my votes. Votes were printed onto a piece of paper. I checked to make sure the marks on the paper matched what I entered into the machine and then dropped it into the ballot box (not a machine just a box that collected the ballots). It was pretty sane and didn't seem like there was a lot to worry over related to the electronic entry system.

As to how the votes on the ballots are tallied - if those machines are compromised seems like a definite problem -- though there is at least the option to hand count the ballots to compare against ...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#250
post #8

Earlier quoted context omitted.

Regarding Indian voting machines, there is also randomization involved at various levels during distribution making it difficult to game the system but still I always wonder if there is any way to hack the system. I hope people in charge have a process to continuously evaluate the security procedures and improve it.

I never understood the desire to have any kind of machine at all. Paper ballots are a perfectly efficient and scalable system used for many large elections. Even if complicated machines are theoretically safe against malfeasance, keeping it simple increases public confidence.

In the case of India, keep in mind that the country still has a significant illiteracy rate (about 20% as of 2018) and plenty of people who have literally never used a paper form in their lives. One of the key design goals of the machines is to try and reduce the education needed as much as possible while still keeping things more private and efficient than voice votes.
Post reply on HN