Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

311–320 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#311
post #297
post #197

Earlier quoted context omitted.

That seems like it'd be impossible to implement. Either I'd have a record that I voted with no way to confirm who my vote was counted for, or I'd be able to prove that I voted for a specific candidate which opens a Pandora's box of problems (either coercion for voting for the wrong candidate or bribes for provably voting for a specific candidate). I mean sure, if someone can come up with a workable blockchain-based s…

First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others But honestly, I think the whole idea of being able to prove how you voted being dangerous is overblown. The same people who say you don’t need an ID to vote because it’s a non-issue then come up with fantasy scenarios of masses of people being forced to prove how they voted, or bribed to do it LOL.

> masses of people being forced to prove how they voted, or bribed to do it LOL

Would you believe that in some households, the husband considers his wife's vote as his property? And that there are lots of households like this?

It doesn't have to be a singular mass of people being coerced by a single entity. Lots of wives being coerced by lots of husbands is also corrosive to elections.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#312
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Curious to know more. Is there a good source of information on the security of the hardware and software used for elections India. As an Indian citizen I see the casual lack of security mindset in large swathe of things implemented by both public and private actors. Many things get better only though iterative failures and corresponding reactive fixes. What type of failures and improvements have happened here, or ins…

[deleted]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#313
post #297
post #197

Earlier quoted context omitted.

That seems like it'd be impossible to implement. Either I'd have a record that I voted with no way to confirm who my vote was counted for, or I'd be able to prove that I voted for a specific candidate which opens a Pandora's box of problems (either coercion for voting for the wrong candidate or bribes for provably voting for a specific candidate). I mean sure, if someone can come up with a workable blockchain-based s…

First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others But honestly, I think the whole idea of being able to prove how you voted being dangerous is overblown. The same people who say you don’t need an ID to vote because it’s a non-issue then come up with fantasy scenarios of masses of people being forced to prove how they voted, or bribed to do it LOL.

I don't know if there's a lot of bribery risk, but a family member asking to see how you voted has plenty of room for coercion and abuse. It seems good that no one but you can know how you voted in principle.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#314

Earlier quoted context omitted.

I voted early in person in Colorado a few days ago. Use a machine to entry my votes. Votes were printed onto a piece of paper. I checked to make sure the marks on the paper matched what I entered into the machine and then dropped it into the ballot box (not a machine just a box that collected the ballots). It was pretty sane and didn't seem like there was a lot to worry over related to the electronic entry system. As…

In my locale there is a header on the physical ballot that contains a bunch of barcodes, presumably to make your votes machine readable. It then prints the votes in text below. I absolutely hate that fact. I am a human, I cannot read barcodes without a computer. Therefore, I cannot tell if the important part of what was recorded is correct. Not sure if Colorado's are the same...

The value of absolute transparency is why nothing will beat paper ballots written and marked in plain English counted by hand with anyone and everyone who cares about election integrity watching the process.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#315

Computer security (computer system quality in general) can't really be turned into a metric, which means it can't be understood by bureaucracies, which means it can't be valued and upheld by large public or private organizations, which means it's in shambles everywhere that well-intentioned engineers aren't upholding it out of their own personal (usually unrewarded) integrity Tale as old as time

true as it can be

Re: Colorado scrambles to change voting-system passwords after accidental leak

#316
There are two other nascent problems in Colorado this year:

Ballots printed by Fort Orange Press are failing through the scan reader. This is annoying, and small counties appear not to have rehearsed the combinations of paper and scanner. There will be a lot of hand counting, which requires party-appointed poll workers.

A notable but insignificant number of ballots in Mesa county failed to authenticate signatures and when contacted, those voters said hadn’t voted yet. Once the signature matches, the ballot becomes part of a large box, indistinguishably. This describes something like 3 ballots.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#317

Earlier quoted context omitted.

I voted early in person in Colorado a few days ago. Use a machine to entry my votes. Votes were printed onto a piece of paper. I checked to make sure the marks on the paper matched what I entered into the machine and then dropped it into the ballot box (not a machine just a box that collected the ballots). It was pretty sane and didn't seem like there was a lot to worry over related to the electronic entry system. As…

In my locale there is a header on the physical ballot that contains a bunch of barcodes, presumably to make your votes machine readable. It then prints the votes in text below. I absolutely hate that fact. I am a human, I cannot read barcodes without a computer. Therefore, I cannot tell if the important part of what was recorded is correct. Not sure if Colorado's are the same...

I believe the idea is that random audits check whether the barcode matches the human-readable part, and in the extremely unlikely even problems are found they simply hand-recount _all_ the ballots ignoring the barcode.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#318

Earlier quoted context omitted.

One person voting who is not allowed is as bad (in terms of fidelity of the vote to legal voters' intentions) as one person being kept from voting who is allowed. There is copious evidence that these purges, and the atmosphere of fear they create, cause far more harm than they prevent.

Maybe the best answer would be to just create a system where only people who are legally allowed to vote, and those that aren't allowed can't, and the provenance of any given ballot is very clear and secure.

Sounds great. How do you do that?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#319

Earlier quoted context omitted.

I voted early in person in Colorado a few days ago. Use a machine to entry my votes. Votes were printed onto a piece of paper. I checked to make sure the marks on the paper matched what I entered into the machine and then dropped it into the ballot box (not a machine just a box that collected the ballots). It was pretty sane and didn't seem like there was a lot to worry over related to the electronic entry system. As…

In my locale there is a header on the physical ballot that contains a bunch of barcodes, presumably to make your votes machine readable. It then prints the votes in text below. I absolutely hate that fact. I am a human, I cannot read barcodes without a computer. Therefore, I cannot tell if the important part of what was recorded is correct. Not sure if Colorado's are the same...

Let's say they get rid of the barcodes and only show the human readable text. How does that prove any better or worse that the machine counted the vote the way it says it did on the slip?

The presence of the barcodes doesn't do anything to reduce the trustworthiness of the system

Re: Colorado scrambles to change voting-system passwords after accidental leak

#320
post #287

Earlier quoted context omitted.

> I believe there are people who want results sooner rather than later In Denmark all ballots are hand-counted. It takes about 6 hours from polls close to every precinct reporting a preliminary result. Wanting it faster isn't really necessary, other than to feed the 24/7 news machine.

Denmark has a smaller population than New York City, America is a very large place.

Italy has 60M people and paper ballots, results are out the next day. Population does not matter since polling stations can be scaled up proportionally.

I've been in voting where we had a dozen ballots per person (referendums) so this would be more than the total paper ballots in the US, it works fine.

Minor miscounts happen but nobody has ever seriously questioned the overall vote results.

Post reply on HN