Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

501–510 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#501

Earlier quoted context omitted.

[flagged]

Or they work at an old folks home.

Ah: turns out it was a postman.

https://www.npr.org/2024/11/02/nx-s1-5174151/election-2024-v...

> County officials in Pennsylvania confirmed to local news outlets that the man filmed in the video was an acting postmaster, doing his job. After the video went online, he began receiving threats.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#502

Earlier quoted context omitted.

I really don’t want to burst your bubble… but do you not realize this is seen as a joke abroad? e.g. In Hanoi, American officials, diplomats, and executives are rushing to wine and dine people who literally celebrate the defeat of ‘American force’ in public, on the record, every year. They treat even a random third secretary for some party committee 100km from Hanoi much much better than the 90th percentile upper mid…

I'm confused. You're upset that America has made peace with Vietnam and treats its diplomats to courtesy state dinners and such? Who cares? The Cold War ended almost 30 years ago. I don't live in the past. I look forward to a glorious future, where we can even work with dirty commies. If the people of Vietnam don't like their government, they should feel free to overthrow it.

I’m not upset? It’s a factual example, that’s what ‘e.g.’ means…

It’s not some fanfiction story I made up while reading a novel…

Re: Colorado scrambles to change voting-system passwords after accidental leak

#503
post #317

Earlier quoted context omitted.

I believe the idea is that random audits check whether the barcode matches the human-readable part, and in the extremely unlikely even problems are found they simply hand-recount _all_ the ballots ignoring the barcode.

Can you find any website or document that validates that these "random audits" are done? By whom and on what cadence? I've not been able to find anything like this. Just hand-waving, assertions that "someone does something," and so on.

> I've not been able to find anything like this. Just hand-waving, assertions that "someone does something," and so on.

(Taking a bit more pointed tone than I usually would, because of the amount of misinformation around this general topic and because of annoyance at people putting less effort in than election workers, from secretaries of state down to volunteers, and casting shade from the laziness of their armchair. Thank you to all the people spending their time trying to secure elections!)

Did you try searching for "colorado voting audit"?

There's a page on their SOS site... https://coloradosos.gov/pubs/elections/auditCenter.html

Which even has a YouTube video on the process... https://m.youtube.com/watch?v=oKgSKh4utNo

Re: Colorado scrambles to change voting-system passwords after accidental leak

#504
post #13

The only way to get an honest electronic vote is by giving realtime visibility on who voted what and where publicly. Everything else is a scam. It would mean no secrecy of vote, but I think that secrecy of vote is for places that are new to democracy. It could be anonymised to a point a clever system of personal certificats, but the idea is that in a 100 people district, the citizens should be able to count themselve…

> Everything else is a scam. There is no evidence of voting systems in the US being "scams". This monster under the bed mentality is getting tiresome.

Yes. These are all social problems.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#505
post #319

Earlier quoted context omitted.

Let's say they get rid of the barcodes and only show the human readable text. How does that prove any better or worse that the machine counted the vote the way it says it did on the slip? The presence of the barcodes doesn't do anything to reduce the trustworthiness of the system

It starts with being able to tell that the information was encoded correctly when I submitted it. Tell me this: what is the advantage of a barcode, over a scantron-esque system where I can see which item I chose because a dot is filled in? The scantron-esque system is still efficiently machine readable; we've had scantron since I was a kid. The difference is, I can verify with my own two eyes that the information is…

>It adds another layer of safety. Do we still have to be able to trust the rest of the system? Yup. But I cannot trust anything at all if I cannot even verify that my vote was submitted correctly in the first place.

I don't disagree that it's strictly better, but the improvements in security are marginal. Any audits/recounts would be done by looking at the human readable part of the ballot, and would therefore be unaffected. Moreover, regardless of whether there's barcodes or not, you'd want to conduct proactive recounts to mitigate any risk for tampered/broken machines. In that case, getting rid of barcodes wouldn't add any security in practice.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#506
Computers anywhere in the vote casting process introduce new, additional failure modes. These modes may be intentional (hacking) or unintentional (misconfiguring the paper size of the ballots). They may be mundane (power failure, out of ink) or esoteric (logic error). Even computerized counting has a nonzero error rate (so does human counting, but that can be challenged by human observers).

Computers add cost for acquiring the computers and training the staff. Computers add complexity and complexity usually reduces the reliability of a process. In a process like voting, that also reduces confidence in the process. This and the cost alone make it unclear why anyone would want to spend the money to electronicize vote casting and counting.

People have been voting without benefit of electronics for thousands of years.

In the vast majority of countries where paper ballots are used and counted by hand, the count is almost invariably completed the day of the election.

Conversely, in the US, where we spend lots of money to acquire, maintain and operate computers to “assist” in voting and vote counting, now we have many jurisdictions who say that they cannot complete counting on Election Day.

It boggles my mind that anyone still supports involving computers in vote casting and counting.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#507

Earlier quoted context omitted.

Virginia purged 1600 non-citizens from their voter rolls and a Chinese student actually voted in Michigan. Clearly requiring citizenship to register as a voter is not sufficient. Poll volunteers should be verifying citizenship.

> Virginia purged 1600 non-citizens from their voter rolls and a Chinese student actually voted in Michigan. Clearly requiring citizenship to register as a voter is not sufficient. Poll volunteers should be verifying citizenship. Over the last 20 years there's no record of a non citizen voting in VA. As a poll worker myself, there's nothing we would check election day that was that wasn't already checked during regis…

Understood. The point of verifying citizenship at the polls is a stop gap response to intelligible voters being on the rolls. The registration is broken. To ensure everybody is a legal voter something additional needs to be done until the rolls can be fixed.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#508

Earlier quoted context omitted.

that all human vote counter in those areas are miscounting, and all in the same direction. And you can send observers that can watch the entire process.

>watch the entire process. "Entire" is the keyword here. Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place. Anyone and everyone can watch someone count paper ballots, noone can watch a computer count electronic ballots.

> Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place.

What?

There are entire systems built around doing exactly that. Embedded, military, high-trust.

It's never state of the art performance or mass deployed, because most people would rather have performance and cost optimized over assurance, but it exists and is in production use.

You verify hardware, chain of custody from production to delivery, track every deployed piece of hardware, then lock the firmware and enforce restrictions on anything that executes after that.

It's not easy or cheap (or foolproof, as anything can be exploited), but it's also not impossible. And substantially hardens security.

And for simpler systems with lower performance requirements, completely achievable.

F.ex. voting machines don't need to be running 16-core, hyperthreaded CPUs running multi-process operating systems

Re: Colorado scrambles to change voting-system passwords after accidental leak

#509
post #79

Earlier quoted context omitted.

> What did it record? Who knows? How is it any different than traditional voting, where you drop your ballot into a black box and trust the poll workers would count it correctly? You can do random spot checks select boxes to make sure the machine is tabulating correctly. If they're all correct, you can be reasonably sure the others are correct as well, unless your adversary has incredible luck.

In traditional voting, the votes get counted by humans, supervised by other humans. If you want to spend the time and energy, you can be one of those humans. It's completely different from a machine count. Humans have human failure modes, which are easily accounted for. Machines have random failure modes, and complex ways of being attacked. And all of the machines can be wrong in one direction at the same time, which…

>Even random spot checks don't work for machines if the machine has some way of detecting it is being checked.

That's theoretically a possibility, but it's trivially defeated by choosing which ballot boxes to spot check after the machines have finished counting.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#510
post #462

Earlier quoted context omitted.

> One half of the US insists that the process shouldn't be changed to the detriment of minority groups This trope that minorities are affected by voter ID laws doesn’t pass the slightest scrutiny. It’s also just plainly offensive and racist to assume minorities can’t show the basic competency to obtain ID when you already need it for so many things. Where were these complaints when everyone, including minorities, had…

> This trope that minorities are affected by voter ID laws doesn’t pass the slightest scrutiny. It is well-supported by actual research (e.g. [1]) AND by simple logic. Every single point you brought up has a clear counter argument - why didn't you respond to any of them? Have you simply never heard anyone mention them? > It’s also just plainly offensive and racist to assume minorities can’t show the basic competency…

I certainly don’t think we should restrict voting to landowners but maybe having a minimum requirement for citizens to participate in democracy (having an ID) isn’t a bad thing.

I think the concern with not requiring ID is that it could allow non-citizens to vote. Making it illegal for non-citizens to vote also disproportionately affects minorities, but that doesn’t justify changing that.

Do you know any minorities personally who have struggled to get an ID? Most minorities I know would be pretty offended by that implication.

Post reply on HN