Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

511–520 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#511
post #416

Earlier quoted context omitted.

“In paper based systems, you and other volunteers” No, 99.99% of “you” go home and “trust the system” to some poll workers, many with major bias and incentives. Many of “you” don’t turn out to vote or are disenfranchised by simply living too far from the polling place or not being able to take time off work, when you could have just voted from your app. Certain parties even rely on suppressing turnout. (Can you guess…

I'm pretty sure there are more than 20,000 polling workers in the USA, so no, it's not 99.9% who go home and trust. And most importantly, for every republican there is a democrat and vice versa, in every polling place, auditing the process in real time. And the reason you can fix this at the polling station level is simple: as long as the entire state is not captured by a single party (in which case no real elections…

Thank you for engaging point by point. Let’s look:

1) Easy to check by whom? With paper, it’s a bunch of people yelling to the news they saw discrepancies. In USA, we have probably the most expensive election in the world and we heard it all in 2020 from sour Republicans. To this day many people believe the election wasn’t secure and was “stolen”, including with physical ballots being shipped in, etc. On the one hand you have people yelling and on the other side you have people saying it’s all fine. Just like after a Venezuela or Belorussia election or the Crimea referendum. None of that would be the case if the elections could just have a standard way to be run, same as we now have electronic standards for DNSSEC or certificate PKI the EVM or IEEE standards. We can do things at scale because of standards. We could remove most of the uncertainty.

2) You don’t have to come out and reveal your PII, in order to publish a complaint as a voter. You’d just have to reveal that you know the private key, here is your receipt signed by the vendors in the system, and here is the actual result the UX vendors reported. The reputation of the vendor would be PROVABLY destroyed, all those receipts would be entered as evidence and they’d have to pay reparations in lawsuits. All because people were forced to double-check from 2 devices. The UX vendor would face chilling effects far larger than currently, for tampering with an election. None of this requires PII of the claimants.

3 and 4. You say it’s the whole system but proceed to list only things related to registration. Which, I already said, remains an issue, but the actual voting can be done on a phone. All your concerns could be also done with a banking app etc. where far more money is at stake than a single vote, yet people use them all the time.

I am not sure how you are supposed to impersonate a person unless you steal their phone, and then force them to open the voting app and enter their biometrics, just for a lousy vote — and you’d have to do this all across town at scale? Nan.

If you’re saying that a bank can “roll back a transaction” if you report losing your app, and somehow the election reaching finality (like a blockchain transaction) is a negative, then you’re saying that

As for people losing their private keys or phones or maybe so poor they can’t afford to have a computer or whatever, they can register to vote in person. If they failed to update their registration, though, before the election, and they can’t vote from their phone, it’s the same issue as if they didnt register at all. So they didn’t vote. But on net there is a much bigger turnout.

5. Okay we agree here. And this isnt an academic point — Al Gore would have been president if they could have counted the votes faster, we could have probably avoided the entire Middle East being on fire, the rollback of US civil liberties, maybe even prevented 9/11 with NORAD, and finally could have avoided the current disastrous wars in Ukraine etc. since Bush was the one to push them into NATO back in 2008 when the Ukrainian public strongly opposed NATO membership until 2014, but he worked with Yuschenko to do it anyway (https://www.pewresearch.org/global/2010/03/29/ukraine-says-n... and https://en.wikipedia.org/wiki/Referendums_in_Ukraine)

I think we both know that a corrupt government would not want to secure elections with merkle trees and publish them online. Too much chance of being caught, and they’d have no way to fudge the results reliably. By making decision-making cheap, the public in every country would be welcomed to hold regular referendums on topics (like California Proposition XYZ) and the governments would be MORE accountable to the people. (Personally, I think provably random polling is superior to voting, due to turnout issues, but that’s another story).

You can say whatever you like but when the rubber meets the road, corrupt officials and their detractors overseas (the war hawks looking to cast doubt on any way to figure out what, say, the actual people of Crimea or Donetsk want) both prefer paper ballots and the effective inability to cast absentee ballots when you fled the country or were internally displaced. While cryptocurrency allows you to take your money with you while fleeing a war zone, the crypto-voting would let you vote from anywhere as long as you had registered as a citizen back before being displaced etc.

It’s literally technology you can add to secure things and corrupt governments avoid it, war hawks across the world hipe they don’t use it, and you are arguing that even adding it makes things less secure and less reliable.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#512

Earlier quoted context omitted.

So is she unable to vote? Virginia has same day registration, so it would seem like a non-issue for a citizen.

I have to assume same day registration would require documentation to (re) prove your citizenship. If you can't find your birth certificate or similar on that day it would be an issue that your previously valid registration was removed and you aren't able to go through the process again in one day.

It depends on the state but generally just requires proof of address or ID, I registered in Illinois with nothing but a phone bill.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#513

Earlier quoted context omitted.

>machines are going to be more accurate Says who? Also, what does "accurate" here actually mean? Speaking as someone who actually understands computers and machines: I agree with the commons (who are simpletons with regards to computers and machines) that machines cannot be trusted to be "accurate" (whatever that means) or even trusted in general. Especially when a simpler, confirmable-by-anyone method exists: Having…

Machines are amazing at counting things without losing their place. I'd trust an ATM's counted stack of bills over a human's (for sure if they only each got one try). I've written some code at a previous job to simplify data entry. The previous method was adding numbers from a stack of papers, with a calculator. I trust my code to add up the numbers on the computer over a human reading them from a printout and enteri…

> Humans make mistakes. A lot.

To put some numbers on this, from my experience.

Health insurance manual claims processors (who usually average ~5 years of experience) can do 95+% accuracy, at speed (a few minutes), at scale. That's counting and verifying multiple things against processing rules.

General data entry, from less trained folks, tends to average around 85% accurate (i.e. 15 mistakes + 85 entries correct, out of 100 entries).

Re: Colorado scrambles to change voting-system passwords after accidental leak

#514
post #506

Computers anywhere in the vote casting process introduce new, additional failure modes. These modes may be intentional (hacking) or unintentional (misconfiguring the paper size of the ballots). They may be mundane (power failure, out of ink) or esoteric (logic error). Even computerized counting has a nonzero error rate (so does human counting, but that can be challenged by human observers). Computers add cost for acq…

It's important to recognize that the US system involves many more races and questions on the ballot than in other (especially parliamentary) systems. Electronic-free counting in many states would significantly extend counting times; many voters have 20+ choices to make, and each of these choices would have to be counted and tracked, which introduces failure modes of their own.

Counting by hand makes sense when each ballot paper has one race; when each ballot has 25 items, using robust optical scan systems common in testing makes sense. Electronic systems also open new options for improved accessibility, as long as all systems produce a physical record, ideally that is counted as itself, rather than a receipt for an electronic count.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#515
post #411

Earlier quoted context omitted.

And we should dye the thumb of those that already voted.

I’m not sure what problem that solves that crossing voters of a list doesn’t already solve. What about mail in and early voting?

I suppose it could help with duplicate voting since some places don't require ID to vote.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#516
post #293

Earlier quoted context omitted.

The point of voting is to kick people out of power when they piss off a clear majority thus keeping the system honest. As such getting the count absolutely correct isn’t necessarily as important vs more systemic biases like gerrymandering or voter suppression. The vote may be rigged before people started casting ballots, but that doesn’t make voting useless. It’s the strongest signals that are most important and that…

> getting the count absolutely correct isn’t necessarily as important vs more systemic biases History lesson: The 2004 Washington state governor's election was decided by a mere 129 votes, and only after multiple recounts and repeatedly "finding" boxes upon boxes of supposedly uncounted ballots in the weeks following election day kept altering the totals and overturned the original result. The election was extremely…

>and only after multiple recounts and repeatedly "finding" boxes upon boxes of supposedly uncounted ballots in the weeks following election day kept altering the totals and overturned the original result.

The explanations given in the wikipedia article seem pretty plausible.

https://en.wikipedia.org/wiki/2004_Washington_gubernatorial_...

I don't see how it's any different what happened in the 2020 election, where Trump appeared to win at first, but a bunch of mail-in ballots (which were counted later) turned it around. While I can see why it might seem superficially suspicious, such phenomena is inevitable if the pool of mail-in (or other forms of voting liable to get delayed/incorrectly rejected) ballots lean one side.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#517

Earlier quoted context omitted.

There's a corollary to the fallacy of appeal to authority, which is that it's also a fallacy of rejecting an idea outright on the grounds it doesn't come from an authority. It's an insightful observation whether or not you like Bezos.

I don't really have an opinion about the man outside of "growing a business", but how on earth does this benefit him? I don't know where on earth you got "authority" from as i didn't invoke this concept at all.

> What the hell would a tech/business guy have to say about elections and why would anyone listen?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#518

Earlier quoted context omitted.

Thanks for the added detail, that's roughly what I remembered as well but definitely a better timeline. I don't actually remember hearing people describe the election as stolen at the time. I know people weren't happy about it, but either I just lost that memory over time or "stolen" is a newer description of 2000 now that its become so commonplace today. Either way, I have a hard time seeing an election that was rec…

I was in High school at the time, I definitely remember a feeling that the election was stolen and that Bush was not rightfully elected. I don't remember the general feeling going away until after 2001. There was a large partisan divide at that time.

The difference between then and now was that Gore put the country before himself and conceded.

You can be unhappy with a result, and maybe even see a path towards changing it, but at some point politicians owe it to their country to support its core democratic institutions.

Clearly and publicly accepting well-audited voting results should be first requirement for presidential candidates.

(Said as someone who has thoughts about the 2000 election, but respects what Gore did as a patriotic choice)

Re: Colorado scrambles to change voting-system passwords after accidental leak

#519
post #511

Earlier quoted context omitted.

I'm pretty sure there are more than 20,000 polling workers in the USA, so no, it's not 99.9% who go home and trust. And most importantly, for every republican there is a democrat and vice versa, in every polling place, auditing the process in real time. And the reason you can fix this at the polling station level is simple: as long as the entire state is not captured by a single party (in which case no real elections…

Thank you for engaging point by point. Let’s look: 1) Easy to check by whom? With paper, it’s a bunch of people yelling to the news they saw discrepancies. In USA, we have probably the most expensive election in the world and we heard it all in 2020 from sour Republicans. To this day many people believe the election wasn’t secure and was “stolen”, including with physical ballots being shipped in, etc. On the one hand…

Since Bush was the one to push them into NATO back in 2008 when the Ukrainian public strongly opposed NATO membership until 2014, but he worked with Yuschenko to do it anyway.

Except he did not "push them into NATO in 2008". 2008 was the year that Ukraine's membership application was formally rejected by NATO, and there it has sat, in the doghouse, ever since. But Putin invaded anyway, because the NATO noise was never the reason he invaded in the first place.

The most significant consequence of the Bush presidency was probably the criminally insane invasion of Iraq -- which arguably did encourage Putin to go into Ukraine, on equally vacuous and fraudulent pretexts. "If they can get away with it, then why can't I?" was apparently his thinking.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#520

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

It is important that the voting system have credibility for everyone - regardless of party. Has anyone done a ground up exercise of rethinking the process and the involved technologies from a cybersecurity standpoint? It would be great to offer voters verification of their votes while maintaining secrecy. But right now I feel like we are stuck, with one half the country having doubts about the process and the other h…

Paper ballots are standard and the majority of states require ID to vote.

There was someone using the Michigan voter file (which has a line in it for each change to the voters record, so repeats voters) to claim that someone was voting dozens of times. They weren't airing a legitimate concern about the voting system, they were sowing discord by lying about how it works.

Your framing of the situation is reductive and cartoonish.

Post reply on HN