Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

101–110 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#101
post #62
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Just use paper, and count by hand on the day. You need to present an election system that will convince Joe Q. Public, who is almost certainly not as tech-literate as this forum, is probably not even white-collar or university educated, and likely also suspicious of globalisation. "Tamper-proof Indian system-on-a-chip" does not have that property. Otherwise you get increasingly unhinged arguments over the election re…

Unfortunately, hand-counting causes more errors than electronic counting, except in very small communities.

Ref.: https://www.brennancenter.org/our-work/research-reports/hand...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#102

Earlier quoted context omitted.

> The US voting machines are just waiting to be hacked, just a matter of when, not if. The US election system is very distributed and fragmented - there is virtually no standardization. Even in the tightest margins for something like President you'd need to have seriously good data to figure out which random municipality voting system(s) you'd need to target to actually affect the outcome.

Ironically America's fragmentary and incoherent electoral system makes it extremely hard to steal an election there.

You say "fragmentary and incoherent", I say "decentralized".

Re: Colorado scrambles to change voting-system passwords after accidental leak

#103

Earlier quoted context omitted.

[flagged]

Another example of "Everything looks suspicious when you don’t know how anything works."[0] Mailed ballots are verified against voter registrations and signatures are checked against the signature on file. This woman with a bunch of ballots for former residents of her apartment would gain essentially nothing and open herself to serious criminal penalties if she tried to vote as anyone except herself. [0] https://www.…

[flagged]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#104

Earlier quoted context omitted.

It's been the method of voting in Oregon for 25 years and Colorado for 10 years, when does the regret start? The current states that have all mail voting are also some of the least religious states in the country, you'd think the religious states would be pushing for it given the scenario you laid out. Colorado also had the second highest voter turn out nationwide in 2020 which supports the claim that all mail voting…

Oregon should never be the gold standard for how to do anything, ever. Can they even pump their own gas yet?

Recently, yes :)

https://www.cnn.com/2023/08/06/us/oregon-drivers-pump-own-fu...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#105

Earlier quoted context omitted.

CO resident here. CO mails paper ballots to everyone* about a month before election day. You can choose to vote in person, or mail in/drop off your paper ballot anytime prior to election night. My understanding is what while the ballots are paper, many (all?) are tabulated digitally. It certainly appears to be laid out in a way that benefits digital reading, and i believe that is what the machines in question are res…

[flagged]

Once you look past individual anecdotes, the actual rate of voter fraud with mail voting is tiny compared to the voting population. https://www.washingtonpost.com/politics/minuscule-number-of-...

Re: Colorado scrambles to change voting-system passwords after accidental leak

#106

Please correct me where I'm mistaken. * This password list has been public for a long time, and is easy to access: hidden excel column on a public spreadsheet. * BIOS access means the intruder can change boot devices, boot their own OS, infect the BIOS with a virus, change boot devices back, compromise the vote host OS. * Keycard security isn't tight security. Any amature physical penetration tester would just use a…

[flagged]

[flagged]

Re: Colorado scrambles to change voting-system passwords after accidental leak

#107

Earlier quoted context omitted.

Are you saying the video was made by an election worker prepping machines in a back room? These were deployed machines used in early voting. The amount of willingness to excuse incompetency here is unbelievable.

Incompetence is not malice. I just googled for more info: https://eu.usatoday.com/story/news/politics/elections/2024/1... > Laurel County Clerk Tony Brown addressed the issue in a statement, saying the machine was temporarily taken out of service while an investigator from the Attorney General's Office was called to inspect the machine. Investigators tried to recreate the anomaly and were able to do so after spending…

I would just like to say, thank you for doing the work of locating a news post about the situation. That really helps ensure we are talking about the same thing. And it allows us to review the situation ourselves.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#108
post #55
post #34

No one has mentioned 2FA. I suspect the passwords are not all that is needed.

I’ve never seen or heard of 2FA being needed for BIOS access. However maybe we could consider “physical presence” as one type of factor, which does reduce the risk a lot.

Also, the article mentioned "partial passwords". I take that to mean the BIOS password was two parts, and only one part of the password was exposed.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#110

Earlier quoted context omitted.

[flagged]

Once you look past individual anecdotes, the actual rate of voter fraud with mail voting is tiny compared to the voting population. https://www.washingtonpost.com/politics/minuscule-number-of-...

>Once you look past individual anecdotes, the actual rate of voter fraud with mail voting is tiny compared to the voting population. https://www.washingtonpost.com/politics/minuscule-number-of-...

that's hardly reassuring given how close this election is going predicted to be.

>The median scenario from our forecast has Ms Harris winning her pivotal 270th electoral-college vote by less than half a percentage point.

https://archive.is/uk388

https://www.economist.com/united-states/2024/10/31/what-to-w...

Post reply on HN