Live data from Hacker News

Cylance Discloses Voting Machine Vulnerability

blog.cylance.com

121–127 of 127 posts

Re: Cylance Discloses Voting Machine Vulnerability

#121
post #52

Earlier quoted context omitted.

let's take this a step further: two republicans, one falsely registered as a democrat, have been paired off at the polling station in Araphaoe County. the lie was bought, the fraud complete. now what?

The "real" Republican sees his "Democrat" counterpart attempt to tamper with the machine and saying "trust me, I'm doing it for the Republicans". They yell for assistance.

that's about what I figured. I can't see a clear benefit or advantage to having one rogue false registrant make a single pair weighted towards one party or the other.

Re: Cylance Discloses Voting Machine Vulnerability

#122

Earlier quoted context omitted.

I have been an election worker. We were asked to sign the attestation envelopes in advance. I trust further checks were conducted higher up. But at our level, protocol was ignored.

I hope to God you refused and reported this. That's completely illegal and could get you in a lot of hot water - not to mention the potential for enabling vote fraud.

I refused. Everyone else complied. I wrote a letter to the Board of Elections and our state's Attorney General but never heard back.

Re: Cylance Discloses Voting Machine Vulnerability

#123
post #99

Earlier quoted context omitted.

Sure. And they could also spoil all the votes with an armed robbery - at many polling stations, there's no actual police presence until/unless someone calls them in. The main intent of all the security measures is that any such tampering be obvious, and that it be clear whose votes (or at least, which precincts' votes) were compromised.

Sure, but that doesn't address an attack that certain precincts that vote a specific party line could be compromised. If 100 attackers at 100 precincts slit some seals than that could swing a swing state

When you have a consistent pattern of ballot spoilage, elections are not counted as normal; at that point you'd have court cases, recounts, assorted forensic attempts to verify valid votes, etc. The system is not a rigid machine - it is a set of rules for the common case, and a set of safeguards that trigger special-case handling.

Re: Cylance Discloses Voting Machine Vulnerability

#124

Earlier quoted context omitted.

I'd say anywhere that people can literally have to choose between their job and their vote is not "working", which is why it needed messing with. Its hard for a lot of people to get to a specific location on any given day - there's no good reason today that a week in bed with the flu should prevent you from voting. Or that it should be harder to vote if you have three kids and no babysitter, or are on crutches, or wo…

> or work an irregular schedule at a minimum wage job The law in California[0] guarantees you the right to vote even if you are scheduled that day. You can take up to two hours off the beginning or end of your shift to vote if necessary. For other states...[1] [0]: CEC§14000 http://www.leginfo.ca.gov/cgi-bin/displaycode?section=elec&g... [1]: http://www.findlaw.com/voting-rights-law.html

There have been polling stations reported with multi hour queues. I'm pretty sure California does not guarantee you the right to vote in person, because it doesn't say you must be given as many hours as you need. But it's ok, because california allows vote by mail.

Re: Cylance Discloses Voting Machine Vulnerability

#125
post #2

I worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn't pictured is the physical security performed with them. Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the e…

Suppose the election ends, and it's time to verify the seals. Oops, they are broken. Now what?

All the seals can do is cast doubt on the results. You can't bring back the voters to try again. Even if you could, time has passed and they might vote differently. You could toss out the results, but that affects things too.

If you toss out the results, an example attack is: break the seals in areas with undesired voters

Similar attacks can be done if you call voters back. Maybe this allows for more-favorable hours or different media exposure.

Re: Cylance Discloses Voting Machine Vulnerability

#126

Earlier quoted context omitted.

I hope to God you refused and reported this. That's completely illegal and could get you in a lot of hot water - not to mention the potential for enabling vote fraud.

I refused. Everyone else complied. I wrote a letter to the Board of Elections and our state's Attorney General but never heard back.

Next time, call the news media. Be sure to pick places biased each direction. If time runs out, I suppose 9-1-1 is an option.

Re: Cylance Discloses Voting Machine Vulnerability

#127

Dear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot…

> Why can you not just do paper voting with simple ballots, like in Canada?

Many districts use paper ballots with optical scanners but this is totally up to the discretion of the county/state.

Post reply on HN