Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

401–410 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#401

Earlier quoted context omitted.

Virginia purged 1600 non-citizens from their voter rolls and a Chinese student actually voted in Michigan. Clearly requiring citizenship to register as a voter is not sufficient. Poll volunteers should be verifying citizenship.

Virginia also purged my sister-in-law from the voter rolls, a naturalized citizen. Let's just say, I am not amused.

So is she unable to vote? Virginia has same day registration, so it would seem like a non-issue for a citizen.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#402
post #386

Earlier quoted context omitted.

It starts with being able to tell that the information was encoded correctly when I submitted it. Tell me this: what is the advantage of a barcode, over a scantron-esque system where I can see which item I chose because a dot is filled in? The scantron-esque system is still efficiently machine readable; we've had scantron since I was a kid. The difference is, I can verify with my own two eyes that the information is…

Pretty sure GP is saying a scantron-style one can still be flipped or offset at the destination. They use position on the ballot, not OCR, to determine what the vote is.

It's not actually about how the ballot is interpreted by downstream hardware and software. That's a different issue.

It's about the ability for the voter to determine that their own part of the process -- the recording of their own vote -- is done correctly in every respect.

Each step of the system has to be verifiable as correct for the system to be trustworthy. As it stands right now, I cannot visually verify that my own vote produced a correct printed ballot. I have no way of doing that.

This removes one of the most critical safeguards. If something in the software (malicious or otherwise) records an incorrect barcode, I have absolutely no way of knowing.

That's a problem.

Garbage in, garbage out.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#403

Earlier quoted context omitted.

To what end? Local to me, an “trained” election volunteer was still questioning voter’s citizenship at the polls. I’d say this was a fluke if the GOP hadn’t spent the last umpteen months pushing all this non-citizen voting nonsense. https://wapo.st/3AsIvnf

Except non-citizens have voted. And the Democrats found Virgina over removing confirmed non-citizens from the voter rolls. Why would anyone support keeping illegible voters on the rolls? We all know why.

Nobody is going to argue that non-citizens should be on the voter rolls. They are going to be upset if your method for taking them out is too coarse and removes legitimate voters, though.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#404

Earlier quoted context omitted.

We have a major party candidate right now saying his political opponents should face a firing squad and you’re asking “why try to hide something that can leak?” https://x.com/atrupar/status/1852209432878342308

It’s pretty clear that he is saying that Liz Cheney is a war hawk but might change that stance if she found herself on the other side of said hawking. Your statement is technically correct but like many other interpretations of his statements, forgoes context and intent to make an easy point.

The context is that he has been publicly calling for a televised military tribunal for Cheney (who is not in the military) for quite a while now, but since he’s a senile old man who “weaved” this into an argument against hawkishness, the right wing can play dumb.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#405

Earlier quoted context omitted.

Colorado uses paper ballots. It's an all-mail voting state so every voter is mailed a paper ballot which is then dropped off or mailed back.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

And now the abuser can just say "show me a picture of your ballot" since we all take our phones into the booth. And the abuser might stand in line and watch to see if you get a second ballot. And you could quickly use photo editing software to fake it, but the abuser might run analysis...

Where is the line of accepted risk?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#406
Are paper ballots and hand counting such a big problem? To me there is something special with the pageantry and ceremony of physically going to a central location to vote, filling out a ballot, physically placing it in a collection box, and then having another human count it. All that pageantry trumps whatever efficiency you get from automating this process with computers, and mobile phones and databases and internets.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#407
post #382

Earlier quoted context omitted.

This is wrong. You don’t need a Ph D or inspect code to know that your vote is included in a Merkle tree. And you can verify that the vote total matches what is in the Merkle tree for your district, and the national Merkle tree of districts. You can also verify that each voter was issued a unique token, which went through a mixer. About the only thing you can’t verify is that the agency giving out the token hasn’t be…

So you agree that you can't verify that the system has one and only vote tabulated for every person that actually voted, or that the vote they intended is the one that got counted. So, you agree that you can't trust the results of this election. Furthermore, if you check and find out that your own vote was incorrectly counted, you can't actually do anything about it, unless voter anonimity is not guaranteed: if you c…

No, I said that reducing the attack surface to a subset of the problems you normally have is good and makes elections cheaper. That’s what cryptographic protocols, including blockchain, do in general. They replace the need to trust corruptible middlemen, with a protocol that is infeasible or extremely hard to subvert, and which leaves traces of the subversion. Crypto is used all the time such as when you use cryptographic hashes to detect tampering, or merkle proofs to prove something was included correctly in a larger part.

You then replied essentially: “well since you still have some problems, you can’t trust the election… the paper way is the only right way”.

Some people might be wilfully misunderstanding because it’s “cool to rag on blockchain” or whatever. People who always repeat a refrain like “this is simply the only right way to do things” are trying to convince not by arguments but by pushing a dogma. And most skeptics of technologies have been wrong, including skeptics of airplanes, computers, etc.

Estonia for example is already doing secure elections online for years, explain that https://e-estonia.com/how-did-estonia-carry-out-the-worlds-f...

The hand recount took too long and the Supreme Court stepped in and “just picked a winner”. Which later counts showed to have been the wrong result. Citing the machine counting alongside it doesnt really help your case because the machine counting was all kinds of ad-hoc and hybrid things (including the dreaded silly “butterfly ballots”) which is exactly what people advocate for, when they try to argue for avoiding a fully consistent and uniform electronic system. They want all the little variations and manual counting “so no one can hack the whole thing”. So yes it’s a perfectly valid argument to point out that delays caused by this led to the wrong outcome (and had consequences like ignoring Bin Laden, allowing 9/11, the invasion of Iraq, clamping down on civil liberties in USA, raiding Social Security etc.)

All the problems you cited above are present in the current system — including having to prove how you voted to challenge the results. Except in the current system there are far more problems, including not even being able to physically show up at the polling place (because it is too far), or proving that the poll workers corrupted your vote, added extra ballots, literally anything. Out of sight out of mind I guess.

And across the world, elections are done even worse. Consider the recent election of Lukashenko in Belarus. People in districts where he got 80% were trying to ask around who voted for him and complained that very few had said they did. It’s all arguments based on hearsay. That is the flip side of not being able to prove how you voted. In fact if they wanted to know how you voted, in your manual system, they could just take a camera outside the booth and look at timing to know when you voted. Or just put a camera in the booth. But in fact it’s far worse than that, the voter databases include driver’s licenses and addresses and social security numbers, in most US states, AND party affiliation is 94% correlated to how you vote so all this paper ballot “security theater” to prevent “being ABLE to prove how you voted” gets you nowhere: https://ballotpedia.org/Availability_of_state_voter_files

And oh yeah… in the system I described you can anonymously challenge the results because you have cryptographic signatures but your own private key came out of a mixer, so you don’t need to identify yourself to prove your vote didnt match what’s in the system. Enough complaints and we ALL know which districts were corrupt, and very quickly.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#408

Are paper ballots and hand counting such a big problem? To me there is something special with the pageantry and ceremony of physically going to a central location to vote, filling out a ballot, physically placing it in a collection box, and then having another human count it. All that pageantry trumps whatever efficiency you get from automating this process with computers, and mobile phones and databases and internet…

They don't create billions of dollars for election machine makers.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#409
post #18

Earlier quoted context omitted.

But, there is still someone somewhere that distribute the certificats and can link you to your vote so why try to hide something that can leak. It will leak.

We have a major party candidate right now saying his political opponents should face a firing squad and you’re asking “why try to hide something that can leak?” https://x.com/atrupar/status/1852209432878342308

A firing squad implies execution. It is quite disingenuous to pretend the quote is about that.

The quote is about her in a war setting with a rifle of her own.

Maybe 'Battle Royale' or 'Hunger Games' as an execution but that is kinda far fetched.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#410

Earlier quoted context omitted.

I mean, if you're willing to spend that much, and it'll be very expensive, then sure. It's just technophobia - machines are going to be more accurate than a human (who also can make a mistake!).

Almost every democratic country on Earth today does it like that, and all democratic countries have done it like that for the last 100-200 years. Counting paper ballots is just not that hard. Machines are infinitely more complex and exploitable. Plus, you have the extra layer of public perception: it's much easier to convince a chunk of the public that all the machines in some area are miscounting, than it is to conv…

that all human vote counter in those areas are miscounting, and all in the same direction.

And you can send observers that can watch the entire process.

Post reply on HN