Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

451–460 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#451

Earlier quoted context omitted.

We have a major party candidate right now saying his political opponents should face a firing squad and you’re asking “why try to hide something that can leak?” https://x.com/atrupar/status/1852209432878342308

"Let's put her with a rifle..." Since when do people facing firing squads get issued a rifle of their own? How do you explain this language he is using? To me it's clear he meant "put her in combat facing a squad of adversaries" (US Army squads are 9 men, USMC are 13), essentially calling her a coward/chickenhawk.

Sure if you omit the times he's called for televised military tribunals for Cheney, an American citizen who has never served in the military. As already addressed below, the fact that he's "weaving" (deliriously free-associating) various arguments together isn't a good defense.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#452

Earlier quoted context omitted.

Yeah it’s just a polite retelling of the crazy Trump nonsense that was laughed out of court by every judge who looked at it and the rest is just misunderstandings from casual election observers who refuse to do one iota of research about how things work. The accusations are always vague as well since each time you zoom in on one it’s completely anodyne but you need the distance to keep up the specter of something nef…

> Yeah it’s just a polite retelling of the crazy Trump nonsense that was laughed out of court by every judge who looked at it and the rest is just misunderstandings from casual election observers who refuse to do one iota of research about how things work. The majority of the cases relating to that election were dismissed for various technicalities, not on merit. As in the judges didn’t laugh them out of the court ba…

I think it’s worth remembering that Trump’s AG, campaign, and RNC lawyers were all clear that he lost fairly. The cases he brought trying to overturn the results were most commonly rejected not on technicalities but because he couldn’t show evidence of a wrong, and were often dismissed with prejudice and in a surprising number of cases the possibility of penalties for frivolous lawsuits which you just don’t tend to see at that level because the national players have not historically been trawling for anything they could possibly use.

There’s a good list here, and it makes it clear that these cases were simply not going anywhere. The rulings aren’t technicalities like “you filed at 12:01 and the deadline was 11:59” but the failure to provide evidence of a problem even occurring in real life.

https://en.wikipedia.org/wiki/Post-election_lawsuits_related...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#453

Earlier quoted context omitted.

Almost every democratic country on Earth today does it like that, and all democratic countries have done it like that for the last 100-200 years. Counting paper ballots is just not that hard. Machines are infinitely more complex and exploitable. Plus, you have the extra layer of public perception: it's much easier to convince a chunk of the public that all the machines in some area are miscounting, than it is to conv…

that all human vote counter in those areas are miscounting, and all in the same direction. And you can send observers that can watch the entire process.

>watch the entire process.

"Entire" is the keyword here.

Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place.

Anyone and everyone can watch someone count paper ballots, noone can watch a computer count electronic ballots.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#454
post #416

Earlier quoted context omitted.

In paper based systems, you and other volunteers do most of the counting, alongside representatives of all parties. None of the problems I described exist in such a system: you can't add a million votes unless you convince a whole lot of volunteers and representatives of the parties that they are real votes. You can't put multiple votes in unless none of those same people see you. If one volunteer attempts to change…

“In paper based systems, you and other volunteers” No, 99.99% of “you” go home and “trust the system” to some poll workers, many with major bias and incentives. Many of “you” don’t turn out to vote or are disenfranchised by simply living too far from the polling place or not being able to take time off work, when you could have just voted from your app. Certain parties even rely on suppressing turnout. (Can you guess…

I'm pretty sure there are more than 20,000 polling workers in the USA, so no, it's not 99.9% who go home and trust. And most importantly, for every republican there is a democrat and vice versa, in every polling place, auditing the process in real time.

And the reason you can fix this at the polling station level is simple: as long as the entire state is not captured by a single party (in which case no real elections are happening), the rest of the state can come in and fix the bad locations.

Related to your points:

1. If there are more ballots than registered voters, this is easy to check. It's even better than a private key system, as extra registrations can also be caught on the day of polling, if people actually come in and vote again, whereas extra private keys being handed out will not see an election official again.

2. There is no way to actually "prove anonymously how you voted". To move the needle in any way, you have to come out personally and say "I know I voted like this, but the system shows me as voting like that, here is what it shows when I present my private key". And either way, this is actually a weakness of the system, as it allows trustworthy vote selling.

3. I don't understand how this is supposed to be any easier than in the current system. You still won't know how many people were legally allowed to be registered in that district, so what are you comparing against?

4. No, the threat surface is the entire electronic system. Someone can attack the system and prevent voters from getting private keys, issue corrupted keys, allow more keys than were registered, present the results differently from what is stored in the merkle tree, use side channels to decrypt private keys, exfiltrate data about individual voters, and who knows how many other ways. Plus, if you can vote from anywhere, you can be coerced, especially by family or caretakers, to vote in their presence, or disclose your private key so they can vote in your name themselves.

And all this assumes the system is an actually secure Merkle tree. In reality, it would just be a computer program that takes your vote and shows you some data. What is actually running on the server is impossible for you to know unless you are given access to the hardware and software.

5. Sure, this is a clear advantage.

You are severely underestimating the risks of an electronic system, and only looking at the purely theoretical logical core. All of the systems around it, through which you interact with the core system, and all of the human factors around using the systems, are a huge attack surface. For example, would you trust this system and issue your vote from a phone or PC which you know is infested with malware? If not, then you have to agree that every device is part of the attack surface of this system.

Finally, in relation to your challenge, elections held by dictators are only meant to look like elections in more legitimate countries. So, if most countries hold paper elections (which is by far the majority), then the dictators will put on a show like that. If the majority of countries used electronic voting, dictators would also get electronic voting machines. Still, I don't know of any dictator that bothers to make a show of how free and correct are their elections.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#455

Earlier quoted context omitted.

Mail-in ballots are worst of all, and the people who advocate for their expansion will regret it when they see entire church memberships filling out their ballots together, checking each other to make sure they voted correctly, and shunning, expelling, or firing people who don't participate. There are currently many heads of household voting for their entire families, and even aside from mail-in ballots, there are pe…

I agree. All those Kamala ads about wives in the polling place defying their misogynistic husbands miss the fact that those controlling husbands would demand that their wives receive mail-in ballots, and then use intimidation and pressure to ensure the vote. The fact that this is rarely discussed probably means that it rarely actually happens. Political beliefs between husbands and wives are usually quite correlated,…

It's nice to hear how effective that ad was at getting under people's skin.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#456
post #350
post #47

Earlier quoted context omitted.

Yes drop boxes and mail in ballots with no signature verification and the counting done largely by one side of the partisan divide (county/state employees) is totally 100% secure what could go wrong? Those conspiracy nuts just don't get it.

Every polling place and every vote-counting center is open to observers from both parties, by law. Your idea that one party is shut out of this system has no basis in reality.

Nope.

There is a lawsuit right now in Georgia over the decision by some locations to accept ballots over the weekend without GOP observers present. Counting without bipartisan observers happened frequently in 2020.

Also "observers" weren't mentioned in my original post. Just because someone watches a count is irrelevant to my original points.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#457

Earlier quoted context omitted.

> If there is a risk that a husband would beat his wife in this case and that she could not leave him, there is no way that any form of electronic vote would change her life, or even her childrens. People who protect this system will probably rig the votes to keep it or a similar one. What? There are people in America who live under this threat today, and yes voting can actually change important parts of their lives.

> There are people in America who live under this threat today Women under threat of their spouse beating them to death for voting "incorrectly"? Can you link to some examples of this? Like testimony of women who came forward fearing their spouses, not just in general terms but on this specific issue of voting?

You don't think domestic abusers try to control their partners' right to vote under threat of physical violence?

What parts of the country have you lived in?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#458

Earlier quoted context omitted.

It seems like quite a stretch to say the 2000 election was stolen. There were definitely ballot issues, but Gore challenged it and ultimately decided of his own accord to concede. He could have continued the challenge and drawn the process out, throwing in throwing in the towel to allow the process to end was his choice, it wasn't stolen.

It's a bit more complicated than that. Gore lost the initial vote count in Florida. He wanted to recount. That was fine. He lost the recount, but it was closer. Then he wanted specific recounts - to recount the precincts where he thought he would gain the most votes in another recount, and to not recount the ones where Bush would gain votes . Also there were calendar issues - the December date where they have to cast…

Thanks for the added detail, that's roughly what I remembered as well but definitely a better timeline.

I don't actually remember hearing people describe the election as stolen at the time. I know people weren't happy about it, but either I just lost that memory over time or "stolen" is a newer description of 2000 now that its become so commonplace today.

Either way, I have a hard time seeing an election that was recounted and challenge GED all the way to the Supreme Court as stolen. Contentious for sure, but that sounds like the system working as intended rather than theft.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#459
I don’t know why this is so hard in America.

All other developed countries make this work, what are Americans lacking?

The system is just: - Keep a list of citizens allowed to vote

- Print paper ballots with the names of the candidates

- ask for a proper ID with photograph

- collect the votes

- count them by hand with the oversee of representatives of the candidates

That’s it, that’s all there’s to it and we count 99% of the votes in less than 6h.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#460
post #223

Earlier quoted context omitted.

> that's what happened here What precisely happened here? Can you specify which ruling you’re talking about and why you think it’s so significant?

I am going to take a guess as to what the GP was referring to: In 2020, Pennsylvania was one of the states that made many changes to how their elections work under the guise of the pandemic. But they changed their rules at the last minute once more in a way that may have altered Pennsylvania’s outcomes. Existing state law meant ballots had to be received by 8 p.m. on Election Day in order to be counted. The Democrati…

Are you referring to Republican Party of Pennsylvania v. Boockvar over the 3 day extension of the received date? Those ballots were collected separately but there were less than 10k of them so even if they’d been 100% Biden voters they wouldn’t have affected the outcome of a race which Biden won by 80k votes.
Post reply on HN