Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

531–540 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#531
post #460

Earlier quoted context omitted.

Are you referring to Republican Party of Pennsylvania v. Boockvar over the 3 day extension of the received date? Those ballots were collected separately but there were less than 10k of them so even if they’d been 100% Biden voters they wouldn’t have affected the outcome of a race which Biden won by 80k votes.

Yeah, and if you look at my comments, I agree that Biden won the race as run. I just question the entire legitimacy of counting any of the votes in a rogue election. I don't think rogue elections should happen. The moral hazard is too great, and it's a direct attack on democratic processes.

Yes, my point is that “rogue election” as a term is using the language of deniers. Every election has mistakes, and the pandemic especially created novel challenges, but that’s a strong term to use if the best you can say is that a statistically insignificant number of ballots were challenged with no evidence of misconduct.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#532
post #505

Earlier quoted context omitted.

It starts with being able to tell that the information was encoded correctly when I submitted it. Tell me this: what is the advantage of a barcode, over a scantron-esque system where I can see which item I chose because a dot is filled in? The scantron-esque system is still efficiently machine readable; we've had scantron since I was a kid. The difference is, I can verify with my own two eyes that the information is…

>It adds another layer of safety. Do we still have to be able to trust the rest of the system? Yup. But I cannot trust anything at all if I cannot even verify that my vote was submitted correctly in the first place. I don't disagree that it's strictly better, but the improvements in security are marginal. Any audits/recounts would be done by looking at the human readable part of the ballot, and would therefore be una…

With a scantron voting system every single voter becomes an auditor. That’s orders of magnitude more auditing than will ever be achieved by randomized barcode audits and it will catch far smaller discrepancies. Even if a machine made only one mistake ever, it would stand a chance of getting caught. Not so with barcodes.

Seems a pretty substantial difference to me.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#533
post #330

Earlier quoted context omitted.

An interesting aside: I’m an overseas Colorado voter. They lump me in with the military voters so my voting process is super easy (I’m sure certain groups would love to make this harder, but not for the troops). I get an email that my ballot is ready, I go to the CO website, authenticate with my SSN (fucking yikes), fill out my ballot online, print a copy to pdf, slap a digital signature on there, and email it back t…

When you disregard basic voting security, everything becomes super easy. Mail-in voting allows for vote buying, the only way to avoid this is by having a private in person voting booth so the person voting cannot prove to the outside world who they voted for. Even this isn't secure now, because everyone can just photograph their voting card within the booth.

Hehe you disproved your own claim. Mail-in voting does not “allow” vote buying any more than any other method of voting. It’s simply not possible for the voting system itself to prevent vote buying, if that were actually a serious problem. But where’s the evidence that vote buying is a widespread problem in the US? Imagining that something is possible doesn’t mean it’s happening, nor make it likely, nor make it a serious problem to solve. And on the flip side, the more technology we add in the name of security, the easier it is to influence elections without people knowing and without having to buy votes.

If you don’t want it to be possible for people to buy or sell votes, then you need to make sure every citizen is engaged and cares about casting their own vote, and you need to make sure the government has a stable and trustworthy system of checks and balances. And why not just make it illegal with massive fines to buy votes and post a huge bounty for anyone tattling on a vote buyer that gets prosecuted? It doesn’t seem that complicated to disincentivize vote buying in a way that eliminates any concerns about the method of voting.

Oh, hey, look: vote buying is already illegal in the US. https://www.law.cornell.edu/uscode/text/18/597

Re: Colorado scrambles to change voting-system passwords after accidental leak

#534
post #508

Earlier quoted context omitted.

>watch the entire process. "Entire" is the keyword here. Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place. Anyone and everyone can watch someone count paper ballots, noone can watch a computer count electronic ballots.

> Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place. What? There are entire systems built around doing exactly that. Embedded, military, high-trust. It's never state of the art performance or mass deployed, because most people…

>What?

There is no way to demonstrate that what is executing is the source code unless you're compiling at execution time from a local vetted copy of the source code. Is the guy who vetted the source code vetted? Who vets the vetter? Is the compiler actually compiling the source code? Is the compiler compiling as generally expected? What about bugs in the compiler? Is the source code even what it claims (binary blobs!)?

What about the hardware? Are there any black box enclaves? Bugs? Does it actually crunch as would be generally expected of a number cruncher? Does it even have the vetted software?

All this complexity and anyone would be fully within their right to say "I don't and won't trust this."

Meanwhile, someone counting paper ballots by hand can be immediately understood by anyone and everyone. It's simple and it's brutally effective. So what if the process takes time? Good stuff usually takes time, what's the rush? So what if the human counter(s) screw up? Human errors are inevitable, that's why you count multiple times to confirm the results can be repeated.

The most secure, most hardened, most certified ballot counting machine cannot compare to a simple human counting paper ballots in witness of anyone and everyone.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#535

Earlier quoted context omitted.

On the flip side; it makes it incredibly difficult to pull off wide scale fraud. Instead of having to compromise a single system, you are forced to compromise dozens or hundreds of systems run by people with opposing ideologies

Wide scale fraud isn't necessary when elections are decided by 10k votes.

Which 10k votes?

How are you going to have 5 digit numbers of fraudulent voter registrations ready to deploy in all of the critical areas, but also ready to enjoy intense public scrutiny before and after the election. Voter registration databases are public, more or less, so you need to figure out how to fool the people running the election as well as the third party watchers, statisticians, academics, journalists and the veritable army of people who could have their entire career made by uncovering fraud.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#536
post #506

Computers anywhere in the vote casting process introduce new, additional failure modes. These modes may be intentional (hacking) or unintentional (misconfiguring the paper size of the ballots). They may be mundane (power failure, out of ink) or esoteric (logic error). Even computerized counting has a nonzero error rate (so does human counting, but that can be challenged by human observers). Computers add cost for acq…

It's important to recognize that the US system involves many more races and questions on the ballot than in other (especially parliamentary) systems. Electronic-free counting in many states would significantly extend counting times; many voters have 20+ choices to make, and each of these choices would have to be counted and tracked, which introduces failure modes of their own. Counting by hand makes sense when each b…

I would suggest that the solution is less voting. Ballots are insanely complicated and there’s absolutely zero knowledge the average person has about whether any of the people are good candidates. So then they turn to their favorite voting guides which just shifts the power to unaccountable political groups instead of making the single representative you elect responsible for figuring it out. And there’s too many elections - non presidential year elections give the power to a motivated and vocal minority which is not what you want because it lets shit stirrers seize control when no one is paying attention.

Parliamentary systems are the only democratic systems I’m aware of that ever features more than 2 parties in a FPTP system as well.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#537
post #460

Earlier quoted context omitted.

I am going to take a guess as to what the GP was referring to: In 2020, Pennsylvania was one of the states that made many changes to how their elections work under the guise of the pandemic. But they changed their rules at the last minute once more in a way that may have altered Pennsylvania’s outcomes. Existing state law meant ballots had to be received by 8 p.m. on Election Day in order to be counted. The Democrati…

Are you referring to Republican Party of Pennsylvania v. Boockvar over the 3 day extension of the received date? Those ballots were collected separately but there were less than 10k of them so even if they’d been 100% Biden voters they wouldn’t have affected the outcome of a race which Biden won by 80k votes.

I am referring to a case filed by the Democratic party of Pennsylvania (not republicans), and I don’t recall the numbers off the top of my head but when it was in the news it was expected that the case would affect a few million votes from mail in ballots that had not yet been returned. Mail in ballots were mostly requested by Democratic voters. The ruling also had some other changes that I can’t recall. Also I forgot to mention that state supreme court deciding the case had a Democratic supermajority.

To me this situation felt like a manipulation of the election process that is outside of the norms, especially for it to happen so late. That was a few years ago but it is an example situation that causes many to still feel the election was “stolen”. I think lots of people use that term to also include actions that are technically legal but feel unfair.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#538
post #506

Computers anywhere in the vote casting process introduce new, additional failure modes. These modes may be intentional (hacking) or unintentional (misconfiguring the paper size of the ballots). They may be mundane (power failure, out of ink) or esoteric (logic error). Even computerized counting has a nonzero error rate (so does human counting, but that can be challenged by human observers). Computers add cost for acq…

scanned paper ballots. simple, fast, auditable. humans are WAY more error prone than computers at counting.

so then the attack becomes introducing enough error at critical counts such that it affects the result without being regarded as having been tampered with

pretty easy if your company produced the machines

Re: Colorado scrambles to change voting-system passwords after accidental leak

#539
post #462

Earlier quoted context omitted.

> This trope that minorities are affected by voter ID laws doesn’t pass the slightest scrutiny. It is well-supported by actual research (e.g. [1]) AND by simple logic. Every single point you brought up has a clear counter argument - why didn't you respond to any of them? Have you simply never heard anyone mention them? > It’s also just plainly offensive and racist to assume minorities can’t show the basic competency…

I certainly don’t think we should restrict voting to landowners but maybe having a minimum requirement for citizens to participate in democracy (having an ID) isn’t a bad thing. I think the concern with not requiring ID is that it could allow non-citizens to vote. Making it illegal for non-citizens to vote also disproportionately affects minorities, but that doesn’t justify changing that. Do you know any minorities p…

> I certainly don’t think we should restrict voting to landowners but maybe having a minimum requirement for citizens to participate in democracy (having an ID) isn’t a bad thing.

Come on, you can't mean this in good faith as a response to my previous comment. It's a fact that minorities are less likely to have government ID, and that it's on average harder for them to acquire it. This is not "a minimum requirement", this is a requirement that - in the current system - deliberately shifts power by disenfranchising voters.

> I think the concern with not requiring ID is that it could allow non-citizens to vote. Making it illegal for non-citizens to vote also disproportionately affects minorities, but that doesn’t justify changing that.

It is already illegal for non-citizens to vote, but I'm sure you know that. You also know that there is no comparison between the two things.

The worst part is: non-citizens voting would be a valid concern if there were any evidence for this happening beyond a handful of cases per election. But there isn't, because non-citizens generally don't want to risk being caught for one single additional vote. And it's not for a lack of looking - the GOP has spent millions upon millions of dollars to find anything, and they have not been able to procure evidence of non-citizens voting in any meaningful capacity. Yet apparently the rules must be changed anyway, no matter the cost to democracy.

> Do you know any minorities personally who have struggled to get an ID? Most minorities I know would be pretty offended by that implication.

Do you have anything meaningful to contribute to this discussion? Any response to any of the points I've already brought up? I don't need to bring up anecdotal evidence when this topic has been broadly researched, and basic logic leads to the same inevitable conclusion.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#540

Earlier quoted context omitted.

It seems like quite a stretch to say the 2000 election was stolen. There were definitely ballot issues, but Gore challenged it and ultimately decided of his own accord to concede. He could have continued the challenge and drawn the process out, throwing in throwing in the towel to allow the process to end was his choice, it wasn't stolen.

It's a bit more complicated than that. Gore lost the initial vote count in Florida. He wanted to recount. That was fine. He lost the recount, but it was closer. Then he wanted specific recounts - to recount the precincts where he thought he would gain the most votes in another recount, and to not recount the ones where Bush would gain votes . Also there were calendar issues - the December date where they have to cast…

Your recollection doesn’t agree with Wikipedia: https://en.m.wikipedia.org/wiki/Bush_v._Gore.

1. It was the Bush campaign that asked the Supreme Court for a stay.

2. The initial recount was triggered automatically because of the narrow margin. It was not requested by Gore. He did still lose it but by a much smaller margin than before. It turns out that 18 counties in Florida didn’t carry out the recount, although Gore never challenged this.

3. Candidates are allowed to request recounts in individual counties. Gore exercised that right in four traditionally democratic voting counties. Bush had the same right.

4. Later analysis showed that Gore would have lost the counties he requested recounts in but if Florida had properly counted ballots in the first place he would have won.

5. The Supreme Court controversy comes from Florida’s requirement to certify results within 7 days. Several of the counties that Gore requested said they couldn’t complete the recount in that time. The Florida Secretary of State didn’t extend the deadline for certification but did allow counties to continue recounts and amend their results. The Supreme Court stepped in and stayed these recounts, forcing Florida electors to accept the initially certified results and blocking any amended results.

Post reply on HN