Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

301–310 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#301
post #150

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

Here’s a telling interview by someone doing journalism rather than running cover: https://youtu.be/NLi-0WI-f7M?si=o8qktF4d25E3oJ-s It’s interesting that she made excuses for herself but previously had no quarter for someone who landed in similar position.

It's only interesting when you oversimplify the two situations for the express purpose of sowing distrust.

The only reason you've left out the details that Tina Peters actually facilitated physical access to voting machines with both required passwords, while this current leak was not even sufficient for someone to repeat Peters' actions, is that it would be absolutely devastating to your entire argument.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#302

I think all US folks reading this should volunteer at their county's Registrar of Voters (or equivalent agency for their county). Spend one election working at a polling place, and another election working at the RoV HQ. See what it's like to go through the training, and what things are like on Election Day, and in the days leading up (for places that allow early voting, drop-off, etc.).

That seems like a massive waste of time and energy compared to just implementing mail in voting for everyone like Washington and Oregon have for so many years.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#303

Interestingly, a website set up to document voter fraud by Mike 'My Pillow' Lindell has collected hundreds of election law violations, many in Colorado. For some reason they are all dated for the future though. Might be a warning signal about not populating your database where the public can watch you doing it. https://archive.ph/smlSQ (capture of https://electionnexus.com from earlier today)

That’s quite weird. Specifically to the BIOS password story, nearly every county has a dusty ol computer on that list. These appear to be backup systems revived on-demand.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#305

Earlier quoted context omitted.

One person voting who is not allowed is as bad (in terms of fidelity of the vote to legal voters' intentions) as one person being kept from voting who is allowed. There is copious evidence that these purges, and the atmosphere of fear they create, cause far more harm than they prevent.

Maybe the best answer would be to just create a system where only people who are legally allowed to vote, and those that aren't allowed can't, and the provenance of any given ballot is very clear and secure.

Just make a system that works, why hadn’t anyone else thought of that?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#306

Earlier quoted context omitted.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

> ... when they see entire church memberships filling out their ballots together ... Are you able to cite any evidence for this sort of conspiracy, or is this mainly conjecture? My search came up short. While one can certainly imagine it taking place, particularly in smaller groups, I expect there are both federal and likely also state laws that would make such activities illegal. At the very least, it would seem har…

That doesn't seem like the kind of thing that ends up in news. Are members of the congregation going to snitch on their "family"? If it happens it is something you would only know from experience.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#308
post #133
post #79

Earlier quoted context omitted.

> What did it record? Who knows? How is it any different than traditional voting, where you drop your ballot into a black box and trust the poll workers would count it correctly? You can do random spot checks select boxes to make sure the machine is tabulating correctly. If they're all correct, you can be reasonably sure the others are correct as well, unless your adversary has incredible luck.

In traditional voting, there is a pretty decent chance you know the person who does the counting or can find someone in your community who can personally vouch for them. Living in my small town at one stage, I knew several of the tabulators personally and all of them by reputation. That is an extreme case, but even in a city these people are somewhat known quantities. With a voting machine that wasn't verified by a h…

What do you do when you know the vote counter and don't trust them?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#309

I think all US folks reading this should volunteer at their county's Registrar of Voters (or equivalent agency for their county). Spend one election working at a polling place, and another election working at the RoV HQ. See what it's like to go through the training, and what things are like on Election Day, and in the days leading up (for places that allow early voting, drop-off, etc.).

What are examples of things one might learn doing this?

Whether your local precinct uses paper ballots as suggested by the internet.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#310

Earlier quoted context omitted.

The advantage of just counting in public and having other people vouch is that it is easily understandable by everyone. If you use the blockchain, how many people can be convinced that the election was stolen with some techspeak? Do you think the average citizen understands enough cryptography to validate that the election was legit?

This has me wonder if highschools should start teaching the basic concepts of cryptography so that we eventually do end up with a common understanding of blockchains, password managers, passkeys, or any other technologies that we end up using in our day-to-day lives for crucial tasks.

> common understanding of blockchains

This is funny because as a CS grad, I cringe about 75% of the time when blockchain enthusiasts make pitches that are oblivious to the workings of blockchains, the tech underneath, and their alternatives.

If the blockchain community can't understand blockchain, it's going to be nigh impossible to convey comprehension to the general public.

The general public generally just wants the authorities whose job it is to manage voting to do so in a competent manner. It's worth noting that there's really only been one candidate for national election in modern history who has called into question the fairness of our elections. (And then only when he lost.)

Most of us understand that the folks who work for the Secretaries of State are generally doing the best they can with the resources we provide, and we don't want to provide more resources so they can do a "better" job.

Post reply on HN