Live data from Hacker News

UK Government Officials Infected with Pegasus

citizenlab.ca

101–110 of 381 posts

Re: UK Government Officials Infected with Pegasus

#101

Earlier quoted context omitted.

As much as I might want to believe in "one person, one vote" defining a democracy, I don't think it does. It's certainly not in the dictionaries I look it up in (e.g., [1]), and it's not like we don't carve out exclusions even in the most democratic societies (e.g., a 15-year-old would have a hard time finding a place where they could vote). Heck, my understanding is you don't even need to have elections for a democr…

It does though - "rule of the majority" in the Webster definition implies one person, one vote. If you work out the mathematics starting from n=2, and then by induction it holds. If not one-person/one-vote then for every n, there exists a set of weights, for which one person can usurp the popular vote. In the US, due to the electoral college, some state resident's vote counts for more than others which is why the los…

Note majority rule isn't in the definition either, it's just strongly correlated. As the simplest example, a democracy that required 55% of the votes wouldn't stop being a democracy. For more different examples, see the lottery system I linked to, or imagine variations thereof (e.g., half the population votes one year, half the next year, etc.).

Also, I don't think the age-limit is a red herring in this case to be honest, since it's another manifestation of "who is a person". Claiming a 17yo is not a person in the US but is a person in Argentina undermines the notion that there's a universal definition of democracy (even one that has an age cutoff)... which is the premise of this entire argument! Otherwise we're acknowledging different societies can differ on whose votes they care about, and still be democracies. (Which I think is fine: we merely need a fair & just definition of democracy. It just isn't as simple as "one person, one vote", is all.)

Re: UK Government Officials Infected with Pegasus

#102
post #14

And what were GCHQ, MI6 and NCSC doing to protect our prime-minister at this time? We have a problem in democratic nations. I've written about it here [1]. Bruce Schneier has also addressed it in his own way. Our lack of any framework for civic cybersecurity is a disgrace. People in future ages will look back on our time as a wild-west. A solution can only come from a ground-up awareness through education. [1] http:/…

> And what were GCHQ, MI6 and NCSC doing to protect our prime-minister at this time? Nobody is perfect - but there are people who blatantly ignore ITSEC best practices and are therefore almost unprotectable.

> Nobody is perfect - but there are people who blatantly ignore ITSEC best practices and are therefore almost unprotectable

This is tangential to this story however. Even people who follow best practices can get owned when ex-Mossad/8200 agents armed with dozens of zero days and millions of dollars come after them.

Re: UK Government Officials Infected with Pegasus

#103

I'm surprised this isn't a major diplomatic incident between the UK and Israel too, since the Israeli intelligence company was supposedly "closely monitoring how their customers were using the software" or akin to that. Like, yeah, blame the UAE mostly for this but let's also have a discussion about why this was sold to anyone who would pay with no oversight at all. Western countries need to do better.

> Western countries need to do better

Yeah, I agree. The western nations which built their lead through brutal colonialism and presently maintain that lead with neo-colonialism structures where brutal governments (Saudi Arabia, Israel, UAE) do the dirty work which they (western countries) ostensibly condemn.

How about this: let’s have the western countries leave the world alone. Let’s have the western countries abandon their profit by misery business models (eg western arms industries which profiteer by instigating conflict and supplying aggressors).

Re: UK Government Officials Infected with Pegasus

#104

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Yeah, not like there's any sort of transparent way to audit a public chain of data blocks representing votes associated with an anonymous certificates that would allow end users (verified with registration cards and authorized with their mobile device biometrics) to check their votes were recorded correctly and for 3rd parties to easily audit the vote totals.

That's a problem that hasn't been solved at all by the current applications of cryptography.

Even if my computer gets hacked, as long as I can trivially search my "confirmation id" from another device to ensure it's what I cast, I'm going to see if it was or wasn't tampered with.

Having public records of votes on a per vote basis with multiple layers of cryptographic signatures at each stage of processing them would be a world of improvement over the current system, both client side and server side attacks considered.

Re: UK Government Officials Infected with Pegasus

#105
post #40

Earlier quoted context omitted.

There's so much that's factually wrong with this comment I don't know where to start. 1. The UK does have a Bill of Rights (It's different in England and Scotland). The English one pre-dates the US Bill of rights by a century[0]. 2. It does have a constitution, but not a written constitution in the American sense[1]. 3. The Queen doesn't nominate Bishops; she rubber stamps nominations by a committee who are approved…

I stopped reading around: "Protestants may have arms for their defence suitable to their conditions and as allowed by law;" and something about (only) Ireland repealed it in [1]. In [2] it says, quite straight faced, that "The Constitution of the United Kingdom or British constitution comprises the written and unwritten arrangements that establish the United Kingdom of Great Britain and Northern Ireland as a politica…

“If you think for a minute, is it not the case that every dictator in the world has a bill of rights, every banana republic, every republic has a bill of rights?”

- Antonin Scalia

A constitution without the ecosystem and institutions to carry it out is meaningless paper. Institutions without a constitution, but with a long history of case law can be just.

Governments are systems but people aren't computers and laws aren't source code.

Re: UK Government Officials Infected with Pegasus

#106
post #104

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Yeah, not like there's any sort of transparent way to audit a public chain of data blocks representing votes associated with an anonymous certificates that would allow end users (verified with registration cards and authorized with their mobile device biometrics) to check their votes were recorded correctly and for 3rd parties to easily audit the vote totals. That's a problem that hasn't been solved at all by the cur…

> verified with registration cards and authorized with their mobile device biometrics

What does "verified" even mean here? At the end of the day, you need to convert it to some cryptographic key, and then that key is vulnerable to attack: either it's kept in the voting machine, in which case the machines themselves are a single point of failure, or else it's given to voters, in which case their insecure phones, computers, etc are easily compromised to get the keys.

Checking your votes doesn't help: a significant number of people do not vote. An attacker can submit votes on behalf of those people using their keys and noone will know, and even if you find someone who claimed that they didn't vote, how would you ever prove it either way?

The advantage of a physical system is that there is no single point of failure: changing the overall election result requires a physical presence at multiple polling locations. All electronic voting solutions are intrinsically worse in that respect.

Re: UK Government Officials Infected with Pegasus

#107

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Does having a paper trail generated exactly after voting help? This is the system that's followed in India. I tried to think of ways it could fail but it seemed pretty fool proof as far as I can think. I'm pretty sure I might have missed some corner case

Re: UK Government Officials Infected with Pegasus

#108
post #82

Earlier quoted context omitted.

Quoted post unavailable.

Quoted post unavailable.

Don't talk anything like that on HN, thanks, no matter what you are responding to. Read the "In comments" section of https://news.ycombinator.com/newsguidelines.html

Re: UK Government Officials Infected with Pegasus

#109

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

I’ve always wondered they we’ll get the cyberpunk future we envisioned when people decide physical media is the sweet spot between paper/written representation and digital media. Like old cdrom style discs that can only possibly be write-once, and the provenance of the data on it depends on the physical presence of the media itself. Not that I’m necessarily advocating for it. Just they seems like a plausible future.

For voting integrity, the vote that is saved needs to be human-readable (the voter should be able to make sure that the digital part of the machine didn't change their vote), so digital storage is right out.

Re: UK Government Officials Infected with Pegasus

#110

This is a bit of a tangent but I think reports like these strengthen the argument against electronic voting. There's basically no way of building a secure electronic voting system that can beat the security and auditability properties of old school pen and paper voting.

Generally a lot of voting security experts advocate for paper ballots with electronic counting. It is very robust, efficient, has great fallback, and lots of systems available to keep secure.

The issue is verification - how do you verify the elctronic count was accurate? And if you're going to manually count it to verify the electronic count, then why have the electronic count in the first place?
Post reply on HN