Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

631–640 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#631
post #62
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Just use paper, and count by hand on the day. You need to present an election system that will convince Joe Q. Public, who is almost certainly not as tech-literate as this forum, is probably not even white-collar or university educated, and likely also suspicious of globalisation. "Tamper-proof Indian system-on-a-chip" does not have that property. Otherwise you get increasingly unhinged arguments over the election re…

Ironically in the US the current nonsense about election fraud might push electronic ballots further. If you're going to cry wolf over paper ballots then you might as well do whatever you want, literally nothing will ever satisfy them. There's no sense even trying to appease.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#632

Earlier quoted context omitted.

>It's not actually about how the ballot is interpreted by downstream hardware and software. That's a different issue. To me, this seems like the only part worth worrying about, and any solution to it should satisfy your concerns as well. Every ballot should have a UUID that the voter takes with them (or make it a hash of their voter registration number or something). As soon as the ballot is processed, the results ar…

> Every ballot should have a UUID that the voter takes with them (or make it a hash of their voter registration number or something). As soon as the ballot is processed, the results are posted to a public place. Voters can then confirm their ballot was recorded accurately. Opening the door for vote bribery or voter intimidation. $1,000 for every tag proving you voted for my candidate. If you don't prove you voted for…

You can already do that today by having people take a photo of their ballot. Or just buy their signed but otherwise blank mail-in ballot and complete it at gangster HQ. Or give them the money and don't require proof at all, because most people will just do what they agreed to do.

This doesn't happen today because it isn't scalable and is easy to get caught and prosecuted. Electronic manipulation is more appealing because it does not require interacting with people.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#633

Earlier quoted context omitted.

I don't really have an opinion about the man outside of "growing a business", but how on earth does this benefit him? I don't know where on earth you got "authority" from as i didn't invoke this concept at all.

> What the hell would a tech/business guy have to say about elections and why would anyone listen?

[deleted]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#634
post #330

Earlier quoted context omitted.

When you disregard basic voting security, everything becomes super easy. Mail-in voting allows for vote buying, the only way to avoid this is by having a private in person voting booth so the person voting cannot prove to the outside world who they voted for. Even this isn't secure now, because everyone can just photograph their voting card within the booth.

After your very last sentence, I’m not even sure what your point is here. You just listed a bunch of reasons you don’t think mail in ballots are safe, and then ended with saying the alternative also isn’t safe from vote buying. Vote buying also does not appear to be a problem in the US electoral system, as another commented pointed out: in order to make a difference in the election, you’d have to buy enough votes tha…

Yea no, I get that, it's just that voting was still secure up until smartphones were ubiquitous. Now it's not.

It's not just about vote stealing per se, it's about any third party infraction of individual voting rights. It may not matter on a large scale, but it matters to individuals.

Not only that, but it matters that bosses can't coerce workers into voting for someone, or an abusive spouse, or any third party who might have an interest in swaying an election. It often doesn't take much to sway an election.

It becomes very problematic when a victim is unable to vote for someone who would stop abuse. For example, Russia decriminalizing spousal physical abuse. That same thing could happen anywhere, and then you'd have every asshole abuser at home forcing their family to vote for their choice.

Not having secure voting is a real problem, and one that is now unsolved thanks to smartphones.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#635
post #330

Earlier quoted context omitted.

When you disregard basic voting security, everything becomes super easy. Mail-in voting allows for vote buying, the only way to avoid this is by having a private in person voting booth so the person voting cannot prove to the outside world who they voted for. Even this isn't secure now, because everyone can just photograph their voting card within the booth.

Do you have any evidence this is happening? In order to swing an election, you'd have to buy a lot of votes. That's a lot of people to rat you out. You're proposing that secret vote-buying conspiracy is going on and thousands of people are all keeping their mouth shut in order to keep getting that... $10, $50, $100 bribe?

I'm not proposing any of that. I'm just saying that voting isn't secure, and that has very real implications. See my other response for more detail.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#636

Earlier quoted context omitted.

> There are people in America who live under this threat today Women under threat of their spouse beating them to death for voting "incorrectly"? Can you link to some examples of this? Like testimony of women who came forward fearing their spouses, not just in general terms but on this specific issue of voting?

You don't think domestic abusers try to control their partners' right to vote under threat of physical violence? What parts of the country have you lived in?

I am open to the idea that it is possible, but many things are possible. I'm asking you to share information that supports your assertion. You still haven't done so. It appears you're dodging the question. Do you have documented examples or data, or not?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#637

Earlier quoted context omitted.

I don't really have an opinion about the man outside of "growing a business", but how on earth does this benefit him? I don't know where on earth you got "authority" from as i didn't invoke this concept at all.

> What the hell would a tech/business guy have to say about elections and why would anyone listen?

[deleted]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#638
post #539

Earlier quoted context omitted.

> I certainly don’t think we should restrict voting to landowners but maybe having a minimum requirement for citizens to participate in democracy (having an ID) isn’t a bad thing. Come on, you can't mean this in good faith as a response to my previous comment. It's a fact that minorities are less likely to have government ID, and that it's on average harder for them to acquire it. This is not "a minimum requirement",…

> Come on, you can't mean this in good faith as a response to my previous comment. I sincerely do, I don’t know what else to tell you. > It is already illegal for non-citizens to vote, but I'm sure you know that. In many states, non citizens can vote in state or municipal elections just not the federal. In states without Voter ID, a non citizen could easily register with an electric bill. It would be illegal, but it…

> In many states, non citizens can vote in state or municipal elections just not the federal. In states without Voter ID, a non citizen could easily register with an electric bill. It would be illegal, but it would be very hard to prosecute.

Let's play this scenario through. You're a non-citizen and risk being found by registering to vote. You get a provisional ballot (since you can't have registered properly before, as that would have been validated and found). This provisional ballot will be counted once your registration is validated, which it won't be, since you're a non-citizen. So what is the exact danger here?

> I think you bring up great points in a challenging and partisan topic. I’m just outlining some of the concerns that people have with not requiring Voter ID. You can dismiss them as invalid if you want! But I think you would have more luck trying to prevent the disenfranchisement of minorities if you wouldn’t dismiss all of these concerns out of hand.

Thanks, but I'm not dismissing them out of hand, I'm asking for evidence that these things actually happen. If that evidence exists I'll gladly agree that election security must be improved.

> Again, you’ve made a fairly strong case that voter ID disproportionately affects minorities, but you haven’t made the case that wide swaths of voting citizens are actually disenfranchised, nor have you made an argument that justifies abandoning the concept of election security altogether.

Of course I haven't made an argument that justifies abandoning the concept of election security altogether, because who would want that? I want elections to be secure, just like everyone else.

I think I've made a pretty good case that enough voting citizens would be disenfranchised. Why does it have to be wide swaths? Why should you be allowed to disenfranchise even a small percentage of voters, even though you have no evidence that your security concerns are actual issues?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#639

Earlier quoted context omitted.

I don't really have an opinion about the man outside of "growing a business", but how on earth does this benefit him? I don't know where on earth you got "authority" from as i didn't invoke this concept at all.

> What the hell would a tech/business guy have to say about elections and why would anyone listen?

I can't see what you're referring to. Maybe you can show me.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#640
post #133

Earlier quoted context omitted.

In traditional voting, there is a pretty decent chance you know the person who does the counting or can find someone in your community who can personally vouch for them. Living in my small town at one stage, I knew several of the tabulators personally and all of them by reputation. That is an extreme case, but even in a city these people are somewhat known quantities. With a voting machine that wasn't verified by a h…

> In traditional voting, there is a pretty decent chance you know the person who does the counting or can find someone in your community who can personally vouch for them. Voting in my area is managed by my county. There's 1.1M people in my county and it's not even the biggest in my state. I'm supposed to personally know all of the few hundred people working the election out of 1.1M spread across 2,200sq km?

No.
Post reply on HN