Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

251–260 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#251
post #96

Earlier quoted context omitted.

The idea is that the machine just provides a preliminary count, a official manual count happens over the following several hours. If there's a discrepancy then the only the manual count counts and the machine can be identified as problematic.

No manual count happens unless the results of the election are in question (very close race, evidence of impropriety, etc.)

Selective audits are standard practice though, where issues can trigger a broade r manual recount

Re: Colorado scrambles to change voting-system passwords after accidental leak

#252

Earlier quoted context omitted.

I think random, serialized paper ballots are the way to go. When the polls close you know the serial numbers of every vote cast, so no new serial numbers should be added to that unless a very good reason. Keep them or destroy them afterwards is another issue, but it's a step in the right direction. I have some distrust in the American voting system, first with the computerized systems, but also that federal elections…

https://www.cpr.org/2024/10/08/vg-2024-how-your-vote-gets-co... Colorado ballot envelopes already have a bar code - essentially your "serial number". I feel like I'm taking crazy pills because everyone who thinks there's widespread election fraud seems to not know anything about how elections work.

> who thinks there's widespread election fraud seems to not know anything about how elections work.

Does your knowledge imply the system is perfect? Is there more than one type of voter fraud? Do we mean just one or two particular federal elections or all elections at every level? What about internal party elections, have those all been extremely fair and above board lately?

There's obvious advantages to perpetrating this class of fraud. Historically we know this fraud has interfered in all types of elections at all levels. Why would this not continue to be a target?

I mean, even in your link, Step 1 includes mailing ballots in. Even recently we've seen the simple flaws in this insecure mechanism. How could you have such a level of confidence in this system? The fact the smart and well meaning people do is all the more reason to engage this subject more rigorously.

Perhaps a more generous interpretation to people making these claims is to understand that we are still not doing a good enough job at making our elections secure, easy, free and fair. For Hacker News this should easily be understood to be a technical challenge and one that the USA has yet again completely failed to succeed at.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#253
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

> The US voting machines are just waiting to be hacked, just a matter of when, not if. The US election system is very distributed and fragmented - there is virtually no standardization. Even in the tightest margins for something like President you'd need to have seriously good data to figure out which random municipality voting system(s) you'd need to target to actually affect the outcome.

> to figure out which random municipality voting system(s) you'd need to target to actually affect the outcome.

As you said, no standardization, which means all precincts reports on wildly different time intervals, if you can interfere with just tallying during or after the fact, and you can get the information on other precincts before any other outlets, you could easily take advantage of this.

It's essentially the Superman II version of interfering with an election. Just put your thumb on the scale a little bit everywhere on late precincts all at once.

The fact that so many states let a simple majority of their state take _all_ electors actually makes this possible. If more states removed the Unit Rule and went like Nebraska and Maine this would be far less effective.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#254

Earlier quoted context omitted.

Yeah it’s just a polite retelling of the crazy Trump nonsense that was laughed out of court by every judge who looked at it and the rest is just misunderstandings from casual election observers who refuse to do one iota of research about how things work. The accusations are always vague as well since each time you zoom in on one it’s completely anodyne but you need the distance to keep up the specter of something nef…

I guess for me personally I don't deny that Joe Biden won the contest as performed. I just question the contest themselves. After all, if made up my own election law and ran an election, and declared my candidate the winner, no one would listen to me, but that's what happened here, which we know based on scotus's interpretation of whether secretaries of state can change rules the way they did in Pennsylvania.

It might just be the neuro-spicy in me but Pennsylvania seems morally in the right here even when the courts ruled against them. The rules as set are really dumb and Pennsylvania was counting valid unambiguous ballots. The election as run was to me better than the one following the letter. How shitty would it be to have your vote thrown out because you didn't put it in the special double envelope that's for preserving your anonymity— the state doesn't give a shit if the ballot is anonymous when counting.

I get that this is a privileged take because broadly speaking the more people vote overall the better Democrats do but it's really hard to fault throwing out fewer ballots. Like turnout is already so low and a person took the time to make their voice heard. People already feel like their vote doesn't matter, dqs for arbitrary reasons aren't helping.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#255
Computer security (computer system quality in general) can't really be turned into a metric, which means it can't be understood by bureaucracies, which means it can't be valued and upheld by large public or private organizations, which means it's in shambles everywhere that well-intentioned engineers aren't upholding it out of their own personal (usually unrewarded) integrity

Tale as old as time

Re: Colorado scrambles to change voting-system passwords after accidental leak

#256
Electronic voting is a horrible idea. We should reform the voting system to something that doesn't require counting massive numbers of votes.

But also, the idea of a president or prime minister is dumb. In fact, nobody needs a federal/national government. We should just have a mayor for each city or region and if they need to decide on something which affects the nation as a whole, the mayors of all cities/regions should just get together vote for it.

When is something truly a national matter? Almost never. In those extremely rare cases, representatives can get together and vote.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#257

I think all US folks reading this should volunteer at their county's Registrar of Voters (or equivalent agency for their county). Spend one election working at a polling place, and another election working at the RoV HQ. See what it's like to go through the training, and what things are like on Election Day, and in the days leading up (for places that allow early voting, drop-off, etc.).

To what end? Local to me, an “trained” election volunteer was still questioning voter’s citizenship at the polls. I’d say this was a fluke if the GOP hadn’t spent the last umpteen months pushing all this non-citizen voting nonsense. https://wapo.st/3AsIvnf

> To what end?

You'll know what to do.

I worked a total of eleven elections, from primarily elections to general elections. I even worked a special recall election where the recall was the only thing on the ballot. I was a volunteer for all of them. I worked as a "Polling Place Inspector", which means I was 'in charge' of a single polling place: I did the setup & teardown, reached out to the other polling place's poll workers to confirm they'll be there, and scheduled breaks etc..

I worked in Orange County, California, which is the county between Los Angeles and San Diego. At the time, it was very right-leaning. It may be so today, but that doesn't matter for this post.

Fun fact: In Orange County, poll workers are the only people who are allowed to question (or "challenge") a person's right to vote. The general public are not. How do I know that? Because it's one of the things I was taught during training. You can see it mentioned in [2], on page 11, under "What Are Observers NOT Allowed To Do?". (In the document, "precinct board" means "the poll workers".)

Now, three situational "pop quizzes" related to the situation from the article. In all three, you are a poll worker. Note that I will refer to procedures that were in place in Orange County, CA, not Fairfax County, VA:

Pop Quiz #1: Someone has arrived to vote, and you do not believe they are eligible to vote, what do you do?

Answer #1: You are challenging a voter. You have the voter vote provisionally. Their ballot would be sealed in the envelope, and their information (plus an explanation of why you're having them vote provisionally) would be on the envelope. The challenged voter would take a receipt with them, giving them a phone number to call, should they want to check up on the status of their vote after the election.

Fun Fact: Challenging a voter without probable cause is a felony in the State of California. How do I know that? Because it's in the instructional handbook that every poll worker gets, when they go through training. You can find Orange County's handbook for the 2018 election at [1].

Pop Quiz #2: Someone at the polling place, who is not a poll worker, is challenging peoples' right to vote. What do you do?

Answer #2: Call the dedicated polling place helpdesk, letting them know about the incident. Depending on the person's behavior, you may ask them to leave, or you may skip directly to calling the police. Your polling place inspector would have already looked up the phone number of the nearest police station, or you could just call 911.

Fun Fact: As part of polling place supplies, I received a county mobile phone. I was specifically instructed to charge it up in advance of election day. They were always chunky Nokia phones, which felt like they could be used as a weapon in an emergency.

Finally, to address your question…

Pop Quiz #3: Another poll worker is challenging a voter, and you believe the challenge is unlawful. What do you do?

Answer #3: If you are not able to dissuade the poll worker into allowing the voter to vote normally, then you have them vote provisionally. The most important thing is to get the voter through the process, and their provisional envelope into the box. Once that is done, you reach out to the polling place helpdesk, letting them know who did what.

Indeed, quoting from the article you linked, "After the [polling place] manager intervened, Burrell-Aldana was allowed to vote." The article does not say, but I expect the polling place manager was already planning on how to communicate the incident back to headquarters, and was keeping an eye on that poll worker.

If you had volunteered for this election, and you happened to be in the situation from this article, then you would have known what to do. :-)

[1]: https://ocvote.gov/fileadmin/user_upload/elections/gen2018/T...

[2]: https://ocvote.gov/election-library/docs/Election%20Observat...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#258

Earlier quoted context omitted.

Unfortunately, hand-counting causes more errors than electronic counting, except in very small communities. Ref.: https://www.brennancenter.org/our-work/research-reports/hand...

It's not so much about errors tbh - paper votes can be re-counted as often as needed. The fear is that voting machines are insecure, its input or results tampered with, and then you can't do a recount. Unless they generate a paper receipt as well that the voter has to confirm before the vote is counted.

> paper votes can be re-counted as often as needed

That's not exactly what happened in Florida 24 years ago.

In principle I don't really disagree, but just saying the problems run rather deeper than just hand-counting vs. electronic voting. The one time a recount actually would have been useful it was stopped for highly legalistic reasons that are hard to explain to a normal person. Not only that, it's highly likely – perhaps even probable – that Gore won Florida, although we'll never know for sure.

I see no reason it would play out any different today. We all saw what happened during the last election.

Not only that, with the full-on cult of Trump and the perceived victimhood of his supporters, I'm not really sure to what degree hand counts can always be trusted. Given the very small margins in some states, even a very small error rate (malicious or otherwise) can really matter. Perhaps this is paranoid, but I fully expect Trumpdroids to try to cheat. Any idiot can cheat a handcount "by accident" (prove it otherwise), but actually tampering with voting machines is operationally much more complex, and not something any ol' yahoo can easily pull off (need not just technical knowledge, but also physical access).

tl;dr: it's all pretty fucked no matter what.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#259

I think all US folks reading this should volunteer at their county's Registrar of Voters (or equivalent agency for their county). Spend one election working at a polling place, and another election working at the RoV HQ. See what it's like to go through the training, and what things are like on Election Day, and in the days leading up (for places that allow early voting, drop-off, etc.).

To what end? Local to me, an “trained” election volunteer was still questioning voter’s citizenship at the polls. I’d say this was a fluke if the GOP hadn’t spent the last umpteen months pushing all this non-citizen voting nonsense. https://wapo.st/3AsIvnf

Virginia purged 1600 non-citizens from their voter rolls and a Chinese student actually voted in Michigan. Clearly requiring citizenship to register as a voter is not sufficient. Poll volunteers should be verifying citizenship.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#260
post #27

Earlier quoted context omitted.

This is a wild amount of both-sidesing in a case where one side has evidence and the other is literally an unsubstantiated conspiracy theory at a scale where you could not keep the secret. Most secure in history is (in my state) is correct. There are more pointless safeguards than have ever existed. If you were willing to go with the results of any election pre 2020 then you should be overjoyed at how much more "secu…

Junk mail democracy is the most insecure model for an election I could possibly conceive. Other than entrusting closed source software companies with tabulating votes.

So why do red states who have every incentive to remove vote-by-mail entirely not do so? You can vote by mail in every state, lots of red states are no-excuse.
Post reply on HN