Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

381–390 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#381
post #360

Earlier quoted context omitted.

What do you audit if both the tally and the paper ballot are consistent? The only check possible is the voter checking themselves before they hand over the paper ballot.

Are you saying that the only check possible is looking at it while its in your hand?

The problem stated was that the marker machine lies 1 out of 15 entries. The paper would contain an incorrect selection occasionally. So, yeah, it would require no one noticing during the act.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#382

Earlier quoted context omitted.

This has me wonder if highschools should start teaching the basic concepts of cryptography so that we eventually do end up with a common understanding of blockchains, password managers, passkeys, or any other technologies that we end up using in our day-to-day lives for crucial tasks.

That wouldn't help for this case. Even a PhD in cryptography and computer science doesn't help you in any way be convinced that a particular machine is securely counting your votes. If you want to be convinced of that, you have to audit the code and the hardware specs and the network code and everything in between to ensure that the system: (a) implements the claimed algorithms, (b) does so correctly and free of side…

This is wrong.

You don’t need a Ph D or inspect code to know that your vote is included in a Merkle tree.

And you can verify that the vote total matches what is in the Merkle tree for your district, and the national Merkle tree of districts.

You can also verify that each voter was issued a unique token, which went through a mixer.

About the only thing you can’t verify is that the agency giving out the token hasn’t been corrupted and gave a lot of voting tokens to fake people, or multiple voting tokens. That part (preventing sybil attacks) is why Voter ID laws exist throughout the world.

But reducing the attack surface to widespread corruption issues involving voter registration, is much better than having those AND problets merely counting the ballots by hand, as when eg Al Gore lost to George W Bush in 2000.

The other thing you can’t verify is that other people’s vote wasn’t tampered with — unless THEY report it. Which is why the voting system should require voters confirming votes from multiple devices that verify your cryptographically signed choices, eg vote on a laptop then scan QR code from that laptop with your phone and approve, just as you would with a web payment request in your bank app, crypto wallet or WhatsApp sign-in request. Because voting is not as valuable to people as securing their bank account, this requirement must be enforced on all voters. This way one company eg Google or Apple can’t spoof the interface.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#383
post #354
post #297

Earlier quoted context omitted.

First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others But honestly, I think the whole idea of being able to prove how you voted being dangerous is overblown. The same people who say you don’t need an ID to vote because it’s a non-issue then come up with fantasy scenarios of masses of people being forced to prove how they voted, or bribed to do it LOL.

> But honestly, I think the whole idea of being able to prove how you voted being dangerous is overblown. Well you’re wrong.

Okay. People wrong about not needing voter ID.

Simple. They’re wrong.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#384
post #81

Earlier quoted context omitted.

I never understood the desire to have any kind of machine at all. Paper ballots are a perfectly efficient and scalable system used for many large elections. Even if complicated machines are theoretically safe against malfeasance, keeping it simple increases public confidence.

Tell me you're under 24 years old without telling me you're under 24 years old. The US 2000 election was a fiasco of the failures of paper ballots. Officials spent weeks scrutinizing ballots and to this day nobody thinks they got it correct to within the margin of error. That's when electronic machines came in. They are not necessarily better, but nobody who lived through that nightmare thinks fondly of the clarity o…

> They are not necessarily better, but nobody who lived through that nightmare thinks fondly of the clarity of paper ballots.

I lived through that, it wasn't that big a deal, and I still think fondly of the clarity of paper ballots. No system is perfect, but paper ballots work and work well.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#385
post #364
post #297

Earlier quoted context omitted.

First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others But honestly, I think the whole idea of being able to prove how you voted being dangerous is overblown. The same people who say you don’t need an ID to vote because it’s a non-issue then come up with fantasy scenarios of masses of people being forced to prove how they voted, or bribed to do it LOL.

> First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others I doubt it, and I suspect if you try to point at a specific system to implement you will find that that none exist even in theory. I can verify I voted with zero knowledge, yes. But I can't verify who I voted for . So I can put candidate A into the machine, it switches to candidate B and we can all prove I voted in…

“Literally zero make the voter’s vote public”

In most US states I can get a voter’s database and “party affiliation”. I was shocked that thus info is publicly available, and all the people’s addresses and driver’s license info are also stored there (and can be leaked)

And make no mistake, these databases are regularly leaked / hacked: https://qbix.com/blog/2023/06/12/no-way-to-prevent-this-says...

In fact there is a law for states to create and maintain this information. https://ballotpedia.org/Availability_of_state_voter_files

The “party affiliation” is a very good (around 95%) proxy to how they’re going to vote when they show up, as long as the two-party system dominates, which is why I say the whole “ability to prove your vote” thing is overblown, since your party affiliation at registration is already known, even publicly:

https://www.pewresearch.org/politics/2023/07/12/voting-patte...

Explain how Estonia is able to reliably and securely do online elections, if only paper elections are secure:

https://e-estonia.com/how-did-estonia-carry-out-the-worlds-f...

Many times, people claim that technology would never be able to do a good job at what humans do manually — and almost always this has been proven wrong after a while: https://www.coindesk.com/tech/2020/03/12/in-defense-of-block...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#386
post #319

Earlier quoted context omitted.

Let's say they get rid of the barcodes and only show the human readable text. How does that prove any better or worse that the machine counted the vote the way it says it did on the slip? The presence of the barcodes doesn't do anything to reduce the trustworthiness of the system

It starts with being able to tell that the information was encoded correctly when I submitted it. Tell me this: what is the advantage of a barcode, over a scantron-esque system where I can see which item I chose because a dot is filled in? The scantron-esque system is still efficiently machine readable; we've had scantron since I was a kid. The difference is, I can verify with my own two eyes that the information is…

Pretty sure GP is saying a scantron-style one can still be flipped or offset at the destination. They use position on the ballot, not OCR, to determine what the vote is.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#387
post #57

Earlier quoted context omitted.

>I hear some people say "but we use paper ballots". Then why do you have a BIOS password? If it's all paper where does the computer fit in? All of this is honest curiosity, I'm not sure how the voting system works. Not sure about Colorado specifically, but in many jurisdictions voters mark paper ballots, which go into a machine to be tabulated, and are finally deposited into a box for safe keeping/future recounts.

I voted early in person in Colorado a few days ago. Use a machine to entry my votes. Votes were printed onto a piece of paper. I checked to make sure the marks on the paper matched what I entered into the machine and then dropped it into the ballot box (not a machine just a box that collected the ballots). It was pretty sane and didn't seem like there was a lot to worry over related to the electronic entry system. As…

And I guess you didn't sign the paper or in any way had means to ensure it wasn't printed with the opposite candidates vote in the next room.

Neither did you have the opportunity to also vote for the other color of the uniparty and cross check the ballots to see they printed identically and according to selection

Re: Colorado scrambles to change voting-system passwords after accidental leak

#388
post #364
post #297

Earlier quoted context omitted.

First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others But honestly, I think the whole idea of being able to prove how you voted being dangerous is overblown. The same people who say you don’t need an ID to vote because it’s a non-issue then come up with fantasy scenarios of masses of people being forced to prove how they voted, or bribed to do it LOL.

> First of all zero-knowledge proofs allow you to verify stuff without being able to prove it to others I doubt it, and I suspect if you try to point at a specific system to implement you will find that that none exist even in theory. I can verify I voted with zero knowledge, yes. But I can't verify who I voted for . So I can put candidate A into the machine, it switches to candidate B and we can all prove I voted in…

If everyone got a unique prime number and a running total vote product was available, I always thought this would be a neat solution. Still susceptible to the goon-with-a-wrench technique I think

Re: Colorado scrambles to change voting-system passwords after accidental leak

#389
post #369

Earlier quoted context omitted.

Are we talking about "Voter ID"? If so, isn't that being constantly derailed by the democrats? Just like all the issues with illegals and the border wall, which they don't seem to want to fix and make it impossible.

> Just like all the issues with illegals and the border wall, which they don't seem to want to fix and make it impossible. How do you reconcile that with: Senate Republicans block border security bill as they campaign on border chaos ( May 24, 2024 ) Nearly every GOP senator, along with six Democrats, voted to filibuster a bipartisan bill designed to crack down on migration and reduce border crossings. The vote caps…

That's the bill that would have facilitated illegal immigration, not stopped it. It sounds decent at first, providing a mechanism to lock down the border, but the "average of 4000 encounters" are 4000 who apply for asylum with a hearing at some future date and are released into the country in the meantime.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#390
post #369

Earlier quoted context omitted.

Are we talking about "Voter ID"? If so, isn't that being constantly derailed by the democrats? Just like all the issues with illegals and the border wall, which they don't seem to want to fix and make it impossible.

> Just like all the issues with illegals and the border wall, which they don't seem to want to fix and make it impossible. How do you reconcile that with: Senate Republicans block border security bill as they campaign on border chaos ( May 24, 2024 ) Nearly every GOP senator, along with six Democrats, voted to filibuster a bipartisan bill designed to crack down on migration and reduce border crossings. The vote caps…

As you are not an American, let me educate on what that bill did.

Much like the "Inflation Reduction Act" which was a clean energy bill that had nothing to do with inflation, the bill did the exact opposite of what it claimed.

- It funded billions of dollars for the NGOs which were aiding illegal immigration

- It normalized and allowed historically high illegal levels of immigration (10x normal)

- It removed the standard process for adjudicating asylum by judges and made it part of the federal ICE

- Required the US to fund lawyers for all people who were charged with illegal immigration (12 million in the last 4 years)

- It gave $60 billion to Ukraine, 3x more than border security [1]

- It gave $14 billion to Israel, $10B to Gaza, $2B for conflicts in the Red Sea, $4B to Taiwan

During this period where 12 million (3.4% of US population) people have crossed the border for residency illegally, many of which have been flown in by the US federal government, the federal government has sued Texas repeatedly while they are trying to build a border wall. They have flown in percentages of whole populations to US swing states to try to build voters. And illegal immigrants count in the census which determines US electoral votes.

The reason the GOP voted against it is because it was a wishlist for the Democratic party. There is nothing more complicated about it than that. If the GOP was such fear mongers, as you say, they'd vote for a bill that ameliorated their concerns.

[1] https://www.reuters.com/world/us/us-senate-unveils-118-billi...

Post reply on HN