Live data from Hacker News

Utah voting system fending off 1B hacking attempts per day

utahpolicy.com

201–210 of 220 posts

Re: Utah voting system fending off 1B hacking attempts per day

#201
post #112

Earlier quoted context omitted.

There are realistic systems that are operationally secure by the given standard. Nuclear launch systems are the obvious example. “Best practice” is a euphemism for whatever it is the majority does. Nobody ever got fired for buying IBM. That’s not even reasoning. Finally, your paragraph about sandboxing is ill considered, but not that wrong. First all programs have operational semantics, the only question is how well…

> There are realistic systems that are operationally secure by the given standard. Nuclear launch systems are the obvious example. AFAIK there aren't really any examples of production systems that have meaningful, formally verified security properties without gaping holes. Do you have a good paper about the full stack formalization/verification of a nuclear launch system? > “Best practice” is a euphemism for whatever…

> Do you have a good paper about the full stack formalization/verification of a nuclear launch system?

Bwahahaha you're funny.

> If you try to formalize everything, you'll drown. If you strategically concede defeat and admit that some parts of the system aren't possible to formalize, you can get a lot of strong guarantees.

You're contradicting yourself again. There's a reason why weakness is a strength in formalisms.

Re: Utah voting system fending off 1B hacking attempts per day

#202
post #21

Paper ballots, no machines and especially no machines connected to the internet...if we were able to get that crazy bug into Iranian nuclear reactors without direct transfer from Internet, then you can bet North Korea, Russia, Israel, and China will pour billions to do the same thing. Voting ID cards too, though I admit I don’t know enough about that. Even if it costs billions to get it done, confidence in fair and f…

The election integrity gold standard is paper ballots cast at poll sites tabulated on site when the polls close. Aka the Australian Ballot (private voting, public counting).

Any deviation from that lessens election integrity. Which may be okay, because maybe the trade off makes it worthwhile. For instance, absentee ballots and early voting enfranchises people. But the there is no free lunch with voting systems and these decisions must be measured.

Re: Utah voting system fending off 1B hacking attempts per day

#203

Earlier quoted context omitted.

The first is a good idea, but the second is not. Voter ID cards are historically used to make it harder to vote and thus compromise elections. In person fraud is very uncommon, and it would be very difficult for a foreign government to pull off a large scale interference without being detected. After all, we struggle to get people to show up to vote once already! The idea of mass ballot fraud seems difficult to count…

Voting requires ID in almost every other western democracy, including Canada. The rest of the world see it as very reasonable to identify yourself at a polling station. It's odd that this is so contentious in the US. https://en.wikipedia.org/wiki/Voter_ID_laws

The USA also has the separate hurdle of registering to vote. Administered by the States. YMMV.

No one would object to voter ID requirements if it wasn't weaponized to disenfranchise voters.

The fix is automatic, universal voter registration. Just like every other mature democracy.

Re: Utah voting system fending off 1B hacking attempts per day

#204

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/List_of_U.S._communities_where...

So first of all, the numbers on that page support my point without whinging over definitions. But if you look at what I said, I didn't say anything about language spoken at home or primary language or anything like that, I explicitly said community of non-English speaking citizens , which pretty clearly means people that don't speak English anywhere .

That's cherry picking at best. Have you been to Anaheim, Stanton, Santa Ana, the entire agricultural belt of California?

Re: Utah voting system fending off 1B hacking attempts per day

#205
post #18
post #17

How can the cost of securing these systems be less than the cost of using a fully paper system?

You can use the same argument for banks.

No you can’t, your analogy is absurd. Canada uses a fully paper system for federal elections and the costs of manually counting are negligible, and still completed the evening of. The same can be said of American elections before the allure of electronic systems took hold.

Re: Utah voting system fending off 1B hacking attempts per day

#207

Earlier quoted context omitted.

I think the point was that you get attempts on /wp-admin.php even if you're not running wordpress at all. I mean, my personal blog is a static collection of HTML pages and I still see /wp-admin.php in logs. In fact, I've long wondered whether this isn't a great opportunity; I'd like to make a script that went through logs and got every IP trying to access such a path, and adds those IPs to a blacklist that gets dropp…

Careful, because of nat that's also a way to ban potential legit users.

I started commenting but I deleted everything half way because I hadn't thought about public WiFi access points. I remember we used to do temporary IP bans on the English Wikipedia if there was too much abuse but it was only for editing. 4chan bans are also for posting afaik. I don't know of a blanket refusal to connect ban for a web server.

Would it be ok to ban an entire IP just because someone from that IP has a compromised machine? I remember this argument that if there is obviously malicious traffic coming from an IP address, the right solution is to block traffic at the next stop, usually the ISP supplying Internet access to that connection. Failing that, the back end should disconnect the ISP and failing that, the other peers should disconnect from the malicious peer. But I don't know how practical it is...

Re: Utah voting system fending off 1B hacking attempts per day

#208

Earlier quoted context omitted.

7% of US households don't have a bank account.[1] Many people live in walkable areas, carpool, or rely on transit. Visiting a doctor doesn't require ID. Taking a train or plane (or a bus) is easier with ID but possible without. [1] https://www.fdic.gov/householdsurvey/

That's surprisingly high! Although I'd assume the total number of people have IDs is greater than the count of those who have bank accounts since there are multiple activities which require IDs (only one being opening a bank account).

You can even open a bank account without government-issued photo ID. It's just harder.

Re: Utah voting system fending off 1B hacking attempts per day

#209

Earlier quoted context omitted.

The first is a good idea, but the second is not. Voter ID cards are historically used to make it harder to vote and thus compromise elections. In person fraud is very uncommon, and it would be very difficult for a foreign government to pull off a large scale interference without being detected. After all, we struggle to get people to show up to vote once already! The idea of mass ballot fraud seems difficult to count…

> Voter ID cards are historically used to I'm so sick of this excuse. The correct response is "... so let's not do that this time, mkay?" Specifically, make them absolutely free-as-in-beer and only require minimal time and effort to obtain (benchmark: proof of address is too much effort). You do this explicitly on the basis that voting is a universal right and requiring money for it is abhorrent, as is any other obst…

If the entire point is to disenfranchise a voting base, why would the entity pushing for the adoption concede these barriers?

If I am throwing a wall up, I generally don't build ladders into the wall itself.

Re: Utah voting system fending off 1B hacking attempts per day

#210

Earlier quoted context omitted.

It works here. Voting fraud is incredibly rare.

How do we know it's incredibly rare? What evidence would we need to know that all persons voting are actually valid voters? Absence of evidence is not evidence of absence. We have cases in California of people voting with their dead relatives' ballots. This a lot easier with voting by mail.

We know because many manhours of research has vetted this topic and the consensus is clear: there are very few cases of in person voting fraud in the United States.

Very few meaning about 250 cases over a 15 year period.

Millions upon millions of votes are cast during this timeframe.

Frankly, I expect more fraud to naturally exist, like you.

But it just isn't a problem in the US.

Voting by mail is a state level thing, not every state has the option to vote by mail.

Ideology aside, it is a solution looking for a problem.

Post reply on HN