Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

411–420 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#411

Earlier quoted context omitted.

The value of absolute transparency is why nothing will beat paper ballots written and marked in plain English counted by hand with anyone and everyone who cares about election integrity watching the process.

And we should dye the thumb of those that already voted.

I’m not sure what problem that solves that crossing voters of a list doesn’t already solve. What about mail in and early voting?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#412
post #42

Earlier quoted context omitted.

Notice the Cheneys and John Boltons of the world also have seemed to flipped with them.

I am happy to say, I've never been on the side of a Cheney. Go me!

I find that unlikely. They are very publicly voting D this round. So that implies you are voting R, but that means you likely voted R with Bush. Did you vote against Bush but for Trump?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#413
post #143

Earlier quoted context omitted.

Seriously? You are saying that you just trust some people not to manipulate the votes? Why not use a Merkle Tree or a Blockchain to verify that your vote was included in the total ? They were invented to remove trust in middlemen. Mutually distrusting parties can maintain the vote tallying. That’s how elections should be done.

In a hand count you might get the odd bad actor, but you're unlikely to get large scale systematic bias, which is much easier to introduce in a machine counting system.

“the odd bad actor” is incredibly optimistic, almost like there is already a bias against ever digitizing or using cryptography for adding security to a manual process with tons of ways to corrupt an election

Elections around the world do not match this optimistic characterization. If they did, we’d all trust the outcomes of:

Belarus’ election of Lukashenko

Venezuela’s election of Maduro

Crimean 2014 referendum

Kosovo’s independence referendum

(Note you probably think the last one was a lot more reliable than the first three — a lot of it has to do with living in a certain part of the world and believing the national media, which is only possible because the voting system and results can be so untrustworthy as to not allow regular people around the world to check anything, so propaganda is given free reign. Science and reliable knowledge usually doesn’t work this way.)

In fact, let’s be clear… the “dictators” WANT the elections to have many ways to corrupt them, they WOULDN’T want a blockchain or merkle tree, that should tell you a lot

And the “war hawks” in countries like USA who oppose their geopolitical rivals also want the elections and referendums to not be secure and clear, so they can cast doubt on them (eg Crimea) while at the same time claiming others (like Kosovo) are completely legit and justify unprecedented actions .

As an aside, the vast majority of both Crimea[1] (94%) and Kosovo[2] (99%) that turned out to vote in referendums in 1991 voted for independence, so we all pretty much know what the public wanted later too, but it doesn’t affect the spin put on the later referendums and conflicts anyway

If elections were secured by cryptography, the People around the world would have far more confidence, rather than listening to their own media propaganda spin the ambiguities, and the wars might even be avoided.

1. https://en.wikipedia.org/wiki/1991_Crimean_autonomy_referend...

2. https://en.wikipedia.org/wiki/1991_Kosovan_independence_refe...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#414
post #280

Earlier quoted context omitted.

I live in one of if not the most critical county in the entire country this election. It's going to be insane here. This week alone we've had Bill Clinton, Bernie Sanders, and Tim Walz stumping here. https://newrepublic.com/article/187597/pennsylvania-election...

I’m in the opposite scenario - my vote will not matter since my county/state is not close to 50/50. It’s a laughably depressing system. I think (without any supporting evidence) the national election system was designed to fit to the standards of transportation and communication 200+ years ago. It was actually feasible to vote per state then send one dude on horseback to DC to cast the vote for the whole state. That’…

Should there be no balance between state size? California always determining the president and ensuring Montana and Rhode Island are never campaigned in?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#415
post #407

Earlier quoted context omitted.

So you agree that you can't verify that the system has one and only vote tabulated for every person that actually voted, or that the vote they intended is the one that got counted. So, you agree that you can't trust the results of this election. Furthermore, if you check and find out that your own vote was incorrectly counted, you can't actually do anything about it, unless voter anonimity is not guaranteed: if you c…

No, I said that reducing the attack surface to a subset of the problems you normally have is good and makes elections cheaper . That’s what cryptographic protocols, including blockchain, do in general. They replace the need to trust corruptible middlemen, with a protocol that is infeasible or extremely hard to subvert, and which leaves traces of the subversion. Crypto is used all the time such as when you use cryptog…

In paper based systems, you and other volunteers do most of the counting, alongside representatives of all parties. None of the problems I described exist in such a system: you can't add a million votes unless you convince a whole lot of volunteers and representatives of the parties that they are real votes. You can't put multiple votes in unless none of those same people see you. If one volunteer attempts to change a vote, another one will stop them. If you think your vote was miscounted, a re-count can be issued, with even more observers, and the exact same artifacts are available for all to see (how do you fix an error in the Merkle tree, even if everyone agrees it happened?). Even if you have an extremely corrupt county, that doesn't generally matter in the grand scheme of things; and its extremely unlikely, as any citizen in that county can stop the corruption by simply participating in the process themselves.

Wide-scale voter fraud of this kind is simply impossible in a paper system. The only times it happens is like in Belarus, where it's not "an election", it's a public show that looks like an election, but where the result is pre-determined. The Merkle tree would show the same thing there: it's a mock election to make it look like a mock democracy. Lukashenko wouldn't have stopped leading the country even if miraculously the election would have shown he lost. Or, it can happen in other more complex and more discoverable ways, such as busing voters around to physically vote multiple times in multiple (preferably far away) polling places.

As for Estonia, they'll come to regret this system sooner or later. It can work for a while, but there is no doubt that the system will get hacked, or the losing party will be able to convince enough people that it got hacked even if it didn't. Someone will accidentally publish private keys, like in this Colorado case. The system will go down on election day because of a bug. Who knows which one will be first, but it'll end their experiment. The rest of the world will continue with paper voting and not face such problems.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#416
post #407

Earlier quoted context omitted.

No, I said that reducing the attack surface to a subset of the problems you normally have is good and makes elections cheaper . That’s what cryptographic protocols, including blockchain, do in general. They replace the need to trust corruptible middlemen, with a protocol that is infeasible or extremely hard to subvert, and which leaves traces of the subversion. Crypto is used all the time such as when you use cryptog…

In paper based systems, you and other volunteers do most of the counting, alongside representatives of all parties. None of the problems I described exist in such a system: you can't add a million votes unless you convince a whole lot of volunteers and representatives of the parties that they are real votes. You can't put multiple votes in unless none of those same people see you. If one volunteer attempts to change…

“In paper based systems, you and other volunteers”

No, 99.99% of “you” go home and “trust the system” to some poll workers, many with major bias and incentives. Many of “you” don’t turn out to vote or are disenfranchised by simply living too far from the polling place or not being able to take time off work, when you could have just voted from your app.

Certain parties even rely on suppressing turnout. (Can you guess which party does that in USA? Hint: it’s the one that closed 1600 polling stations right after the Voting Rights Act got neutered, and then got mad about mail-in ballots ruining their carefully laid disenfranchisement plans during the pandemic.).

In fact, if you want the election to be “secured by multiple distrusting parties”, that is exactly what byzantine-fault-tolerant cryptographic protocols (which power many blockchains) are designed to do.

(how do you fix an error in the Merkle tree, even if everyone agrees it happened?). Even if you have an extremely corrupt county, that doesn't generally matter in the grand scheme of things; and its extremely unlikely, as any citizen in that county can stop the corruption by simply participating in the process themselves.

You are literally arguing from a double standard. In a paper election, somehow “any citizen” by themselves can stop the corruption… by simply participating in the process.” Yeah sure one guy exposes the entire corrupt county, with no ability to prove how anyone voted, why didn’t a single Belarussian and Venezuelan think of that? LOL” And on the other hand, when you have tons of anonymous irrefutable proofs by participants submitted publicly, you throw up your hands and say “what can we do to fix the merkle tree, even if we all knew it was corrupt?” The point of the trre is to catch errors, prove them and publish the proofs widely. As a society, you then have the proof nexessary to fix errors the same way you’d normally do it — by identifying the corrupt districts, and having a recount or revote just there. And bringing those responsible for tampering to justice.

If you stop conflating all the things and unpack them, you’ll see that adding cryptography makes things strictly better:

1. You have more chances to catch if there have been extra votes cast because the private keys are coming from tokens handed out at registration. In a paper election you might have corruption at registration AND all manner of ballot stuffing later too.

2. Everyone can check their vote and report a discrepancy. Not just the volunteers at the polling places. And all because they can prove how they voted and do it anonymously!

3. Everyone can see exactly which districts are corrupt in giving out fake voter registrations, and where there’s smoke, there’s fire. They can do an audit and guess what, the cryptographic signatures are helpful for creating a PROVABLE trail that implicates the system.

4. The attack surface reduces to pretty much just the voter registration sybil attacks. Eliminating a whole class of problems on actual election day.

5. The results are reported to everyone reliably and quickly, or even in real-time (though the latter is “too good” because it might affect how later voters vote).

There’s practically not a single problem that adding cryptography creates, which wasn’t already present in the paper system. And you know all this because if you honestly asked yourself whether dictators, who want sham elections, would want to do their next election with cryptographic signatures and merkle trees or not — what would be your answer? Be honest. And think about what that means for your argument.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#417
post #5

Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.

these machines aren't hooked up to the internet, how are you going to brute force every machine that a community uses and also requires physical proximity?

Are the machines physically incapable of internet?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#418
post #5

Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.

Can you brute force a BIOS password without prolonged physical access? The leak does increase the risk of a single trusted insider messing with the system, though.

"Can you without prolonged access?" Hahaha have you heard of any of the three letter agencies and what they have on hand? Do you know what a rainbow table is? Is this a tech forum, or just newbies trolling experts?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#419

Earlier quoted context omitted.

Can you brute force a BIOS password without prolonged physical access? The leak does increase the risk of a single trusted insider messing with the system, though.

I personally don't put much trust in the security of BIOS vendors. My desktop's motherboard straight up displays the BIOS password if you read the right EFI boot variable (obfuscated with some proprietary "encryption" algorithm with a hard coded key). Based on previous reports on the security of devices like these, I wouldn't be surprised if a quick flash dump of the NVRAM is enough to crack the password in seconds a…

Every vote counts. The problem is that some votes are counted twice.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#420
post #43

Earlier quoted context omitted.

Our credibility has been suddenly made synonymous with how willing we are to go to war on behalf of other countries . We are not But I think any attack on an American force will get you a quick lesson on our credibility, which, as an American, is all I really care about. Similarly economically, good luck not participating in the American markets.

I really don’t want to burst your bubble… but do you not realize this is seen as a joke abroad? e.g. In Hanoi, American officials, diplomats, and executives are rushing to wine and dine people who literally celebrate the defeat of ‘American force’ in public, on the record, every year. They treat even a random third secretary for some party committee 100km from Hanoi much much better than the 90th percentile upper mid…

Hanoi? Are you refering to pulling out of Vietnam made the US seem like a joke? Or that the locals are wrong to celebrate that?
Post reply on HN