Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

431–440 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#431
post #37

Paper ballots have very boring failure modes and need no explanation or technical support. When you see a system more complex than paper ballots, know that the additions are not there on your behalf .

I disagree. I believe there are people who want results sooner rather than later. The greater the delay, the more annoyed folks become. Recording votes in _both_ paper and electronic form allows for the auditability of paper and the speed of electronic calculations. (Side note: I also believe that hand-counting of ballots can be tedious, and humans performing tedious, repetitive tasks are prone to error. See [1].) [1…

People can want it fasted and people can become annoyed, but that's their choice. An election can be counted and verified only so quickly, it doesn't matter if people want it faster or not.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#432

Earlier quoted context omitted.

I disagree. I believe there are people who want results sooner rather than later. The greater the delay, the more annoyed folks become. Recording votes in _both_ paper and electronic form allows for the auditability of paper and the speed of electronic calculations. (Side note: I also believe that hand-counting of ballots can be tedious, and humans performing tedious, repetitive tasks are prone to error. See [1].) [1…

Why should you compromise on security because you're impatient? Have the voter vote on paper; since it's only two candidates, this can be postcard-sized. Scan the postcards for the fast results, check and double check by hand (or visual if there's a picture taken by the scanner).

It isn't only two candidates. In my state we have 5 presidential candidates on the ballot along with 12 other local elections and ballot measures.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#433
post #223

Earlier quoted context omitted.

I guess for me personally I don't deny that Joe Biden won the contest as performed. I just question the contest themselves. After all, if made up my own election law and ran an election, and declared my candidate the winner, no one would listen to me, but that's what happened here, which we know based on scotus's interpretation of whether secretaries of state can change rules the way they did in Pennsylvania.

> that's what happened here What precisely happened here? Can you specify which ruling you’re talking about and why you think it’s so significant?

I am going to take a guess as to what the GP was referring to: In 2020, Pennsylvania was one of the states that made many changes to how their elections work under the guise of the pandemic. But they changed their rules at the last minute once more in a way that may have altered Pennsylvania’s outcomes.

Existing state law meant ballots had to be received by 8 p.m. on Election Day in order to be counted. The Democratic Party filed a lawsuit to extend that deadline and the Pennsylvania state Supreme Court (not SCOTUS) made a highly controversial ruling that extended the deadline to the following Friday. This extension would have helped Biden (given his party filed the lawsuit to force the change), and given they barely won the state (Biden had 50.01%), there is a good chance it affected the outcome.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#434

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

It is important that the voting system have credibility for everyone - regardless of party. Has anyone done a ground up exercise of rethinking the process and the involved technologies from a cybersecurity standpoint? It would be great to offer voters verification of their votes while maintaining secrecy. But right now I feel like we are stuck, with one half the country having doubts about the process and the other h…

> But right now I feel like we are stuck, with one half the country having doubts about the process and the other half insisting that it is absolutely perfect.

It's not correct that one half of the US insists that the election process is absolutely perfect. There have been countless investigations, inquiries etc. and the process is being continuously reviewed. One half of the US insists that the process shouldn't be changed to the detriment of minority groups without any actual evidence that problems exist (as the investigations etc. did not result in such evidence), yet the other half still insists that the problems occur and the evidence is just hidden too well, and the process must be changed without ensuring that minority groups aren't affected more than other groups.

This is not a situation with two equal sides.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#435
post #21

I hate the narratives around voting security in the US. One side says that it is totally secure, basically 0 fraud, most secure election in history, etc etc. The other side claims that the election was completely stolen from them by voting machines. Neither of these claims is right. Personally, I doubt the election was stolen. I know of a handful of cases of voter fraud both anecdotally ("My mom [in a retirement home…

The side that says there's virtually 0 fraud is correct, and the other side is living in a fantasy land because they feel their party is becoming less and less relevant. That side has never produced an iota of proof that there is widespread fraud of that it has affected elections in major races, especially the presidential one. Sometimes "both sides" works in an argument, but when one side has all the proof and the o…

US election process is a joke. Pretending otherwise is some sort of gaslighting that could backfire.

If 'one side' break the silent understanding of 'do not criticize our complex, convoluted and arcane election process', well, bad luck if 'the other side' defends it instead of agreeing there is a need to do something about it.

I don't like how about every question becomes some sort of thrench warfare around strawman extremes.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#436
post #352

Earlier quoted context omitted.

It avoids dangling chads and improperly filled bubbles which were both used to steal the 2000 presidential election. I have never used such a machine but the UX could be a lot clearer than the analog filp-and-punch machines used in Florida in 2000. I don’t love software in the voting process but printing the choices is verifiable and reduces ambiguity in the voting process.

It seems like quite a stretch to say the 2000 election was stolen. There were definitely ballot issues, but Gore challenged it and ultimately decided of his own accord to concede. He could have continued the challenge and drawn the process out, throwing in throwing in the towel to allow the process to end was his choice, it wasn't stolen.

It's a bit more complicated than that. Gore lost the initial vote count in Florida. He wanted to recount. That was fine. He lost the recount, but it was closer. Then he wanted specific recounts - to recount the precincts where he thought he would gain the most votes in another recount, and to not recount the ones where Bush would gain votes. Also there were calendar issues - the December date where they have to cast their Electoral College votes was coming up.

It went to the Supreme Court. The SC made two rulings. First, in a 7-2 vote, they ruled that Gore couldn't recount just in specific spots - if they were going to recount, they had to recount everywhere. Second, in a 5-4 ruling, they ruled that they couldn't keep recounting - they had to meet the December deadline with what they had.

That second ruling is what people are talking about when they say the election was "stolen".

Personally, I think the SC was right. Recounting only where you'll gain is cheating - you're trying to win, not trying to have an honest count. And if Florida had missed the deadline, and Gore had won because none of Florida's votes counted toward the Electoral College? That would have been stealing the election. It also would have been a violation of the Voting Rights Act and a bunch of other things.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#437
post #434

Earlier quoted context omitted.

It is important that the voting system have credibility for everyone - regardless of party. Has anyone done a ground up exercise of rethinking the process and the involved technologies from a cybersecurity standpoint? It would be great to offer voters verification of their votes while maintaining secrecy. But right now I feel like we are stuck, with one half the country having doubts about the process and the other h…

> But right now I feel like we are stuck, with one half the country having doubts about the process and the other half insisting that it is absolutely perfect. It's not correct that one half of the US insists that the election process is absolutely perfect. There have been countless investigations, inquiries etc. and the process is being continuously reviewed. One half of the US insists that the process shouldn't be…

> One half of the US insists that the process shouldn't be changed to the detriment of minority groups

This trope that minorities are affected by voter ID laws doesn’t pass the slightest scrutiny. It’s also just plainly offensive and racist to assume minorities can’t show the basic competency to obtain ID when you already need it for so many things. Where were these complaints when everyone, including minorities, had to show documentation around their vaccination status for various things? Why isn’t this issue in every other country that does require ID to vote in elections?

> without any actual evidence that problems exist (as the investigations etc. did not result in such evidence)

A system not designed to generate data for such investigations will not turn up evidence. Just like with poorly designed software systems.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#438

Earlier quoted context omitted.

Provably digitally altered fake videos of voter fraud were made and disseminated by Russia during the US 2020 election. Non-partisan institutions put a lot of energy in trying to debunk these operations which basically suit America's adversaries and, absent of critical thinking, many people become unwitting participants in their disinformation campaigns. By eating away at the trust of non-partisan institutions that a…

You're comparing apples and oranges in an attempt to distract from the topic by invoking the Russian disinformation trope. The video is provably authentic, and it elicited an official response from the local government. End of story. By your logic, if it appears on social media at all, it never happened.

No, I’m explaining the need for critical thinking, not that all stories of voter fraud/manipulation are immediately bunk. The default of credulity is much more troublesome as it allows for misinformation to be promulgated and be given unearned credence - it gives adversarial actors ‘authority’ one might say. It’s also important to note that in terms of actual fraud, audits and challenges from 2020 show that the system works, contrary to widespread public outrage on the issue

Re: Colorado scrambles to change voting-system passwords after accidental leak

#439

Earlier quoted context omitted.

Can you brute force a BIOS password without prolonged physical access? The leak does increase the risk of a single trusted insider messing with the system, though.

"Can you without prolonged access?" Hahaha have you heard of any of the three letter agencies and what they have on hand? Do you know what a rainbow table is? Is this a tech forum, or just newbies trolling experts?

I guess I wasn't clear. I'm asking you to describe exactly what scenario you're imagining. You can't simply assume the attacker already has the bios password hash. How do they get that? And if they can get that, why do they still need to brute force the bios password? Why can't they do what they need to do already?

Do you know of a vulnerability that allows someone to access the bios password hash but can't also be used to hack the election without bothering with the bios password?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#440
post #143

Earlier quoted context omitted.

Seriously? You are saying that you just trust some people not to manipulate the votes? Why not use a Merkle Tree or a Blockchain to verify that your vote was included in the total ? They were invented to remove trust in middlemen. Mutually distrusting parties can maintain the vote tallying. That’s how elections should be done.

The advantage of just counting in public and having other people vouch is that it is easily understandable by everyone. If you use the blockchain, how many people can be convinced that the election was stolen with some techspeak? Do you think the average citizen understands enough cryptography to validate that the election was legit?

In this day and age the counting should at least be live streamed. Almost every big box store in the US already has a self checkout area that's almost equipped for this task (it has the hardware and the software, just not the physical layout). Publicly (like a public park, not like a "public" school) verifiable vote counting shouldn't be a hard problem.
Post reply on HN