Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

321–330 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#321

Earlier quoted context omitted.

Virginia purged 1600 non-citizens from their voter rolls and a Chinese student actually voted in Michigan. Clearly requiring citizenship to register as a voter is not sufficient. Poll volunteers should be verifying citizenship.

One person voting who is not allowed is as bad (in terms of fidelity of the vote to legal voters' intentions) as one person being kept from voting who is allowed. There is copious evidence that these purges, and the atmosphere of fear they create, cause far more harm than they prevent.

I’m trying to think of this from the point of view of the “null hypothesis”. Typically, I have heard that you want to design your system so that Type II errors are more serious.

This is where it gets confusing for me because your comment makes me think that people can’t agree on whether it’s a more serious mistake to allow an ineligible person to vote or whether we end up stopping (hopefully temporarily) an eligible voter from exercising their right.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#322
post #6

The Indian Voting Machines are the answer. No operating system, no passwords, no connections, no bruteforcing anything, system on a chip, so widely distributed devices that hacking even a few of them is challenging, etc. The US voting machines are just waiting to be hacked, just a matter of when, not if.

Curious to know more. Is there a good source of information on the security of the hardware and software used for elections India. As an Indian citizen I see the casual lack of security mindset in large swathe of things implemented by both public and private actors. Many things get better only though iterative failures and corresponding reactive fixes. What type of failures and improvements have happened here, or ins…

Electronic Voting Machine/Elections in India https://www.youtube.com/watch?v=vlHJZrXrnyQ

The Electronic Voting Machines (EVMs) do simple counting of key presses and keep tally of the totals.

The machines are not reprogrammable, run on alkaline batteries and have no WiFi/Bluetooth, USB or ethernet.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#323
post #287

Earlier quoted context omitted.

Denmark has a smaller population than New York City, America is a very large place.

Italy has 60M people and paper ballots, results are out the next day. Population does not matter since polling stations can be scaled up proportionally. I've been in voting where we had a dozen ballots per person (referendums) so this would be more than the total paper ballots in the US, it works fine. Minor miscounts happen but nobody has ever seriously questioned the overall vote results.

Uh no. This election I had a president, two senators, a state senator, a state assembly, a county executive, city council, school board, prosecutor recall, and half a dozen ballot measures. It took four legal size paper surfaces.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#324

Earlier quoted context omitted.

In my locale there is a header on the physical ballot that contains a bunch of barcodes, presumably to make your votes machine readable. It then prints the votes in text below. I absolutely hate that fact. I am a human, I cannot read barcodes without a computer. Therefore, I cannot tell if the important part of what was recorded is correct. Not sure if Colorado's are the same...

The value of absolute transparency is why nothing will beat paper ballots written and marked in plain English counted by hand with anyone and everyone who cares about election integrity watching the process.

I mean, if you're willing to spend that much, and it'll be very expensive, then sure. It's just technophobia - machines are going to be more accurate than a human (who also can make a mistake!).

Re: Colorado scrambles to change voting-system passwords after accidental leak

#325

Earlier quoted context omitted.

> Colorado does signature matching and ballot tracking. Don't know about Colorado but many other states have been sending ballots to dead people as well as people who are not resident anymore. The potential for fraud is huge

The signature matching would be the first line of defense against that. They would also be notified of deaths by the department of health and the social security administration. Broadly speaking though, whenever potential cases of fraud of investigated, very few end up being substantiated and the fraud that is committed is caught up front. https://apnews.com/article/2022-midterm-elections-voting-gov... https://www.rm…

> They would also be notified of deaths by the department of health and the social security administration.

Is your claim that the social security administration sends a death notification to the deceased person's voter registrar?

https://www.ssa.gov/dataexchange/stateagreements.html

Re: Colorado scrambles to change voting-system passwords after accidental leak

#326
post #151

Earlier quoted context omitted.

Same guy has been running a $14.88 promotion for a month (14/88 is a recognised US far-right symbol: https://www.adl.org/resources/hate-symbol/1488 )

Do you also believe Walmart is marketing chocolate cookies to hate groups or is the price an unfortunate coincidence when they do it? https://www.walmart.com/ip/President-s-Choice-The-Decadent-C...

How many products does Walmart sell, though? I don't think they advertise on 'right side broadcast network', which also inexplicably advertises 'Trump combat knives' during his rallies.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#327

Earlier quoted context omitted.

> Colorado does signature matching and ballot tracking. Don't know about Colorado but many other states have been sending ballots to dead people as well as people who are not resident anymore. The potential for fraud is huge

The signature matching would be the first line of defense against that. They would also be notified of deaths by the department of health and the social security administration. Broadly speaking though, whenever potential cases of fraud of investigated, very few end up being substantiated and the fraud that is committed is caught up front. https://apnews.com/article/2022-midterm-elections-voting-gov... https://www.rm…

That kind of argument is open to criticism of survivorship bias.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#328
post #57

Earlier quoted context omitted.

>I hear some people say "but we use paper ballots". Then why do you have a BIOS password? If it's all paper where does the computer fit in? All of this is honest curiosity, I'm not sure how the voting system works. Not sure about Colorado specifically, but in many jurisdictions voters mark paper ballots, which go into a machine to be tabulated, and are finally deposited into a box for safe keeping/future recounts.

I voted early in person in Colorado a few days ago. Use a machine to entry my votes. Votes were printed onto a piece of paper. I checked to make sure the marks on the paper matched what I entered into the machine and then dropped it into the ballot box (not a machine just a box that collected the ballots). It was pretty sane and didn't seem like there was a lot to worry over related to the electronic entry system. As…

1. If all the machine does is mark who you voted on paper than what is the point of the machine over a pencil? 2. If it does more (for example count your vote) then how did you know that it actually did that?

Either way it smells extremely fishy to me.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#329

Earlier quoted context omitted.

The value of absolute transparency is why nothing will beat paper ballots written and marked in plain English counted by hand with anyone and everyone who cares about election integrity watching the process.

I mean, if you're willing to spend that much, and it'll be very expensive, then sure. It's just technophobia - machines are going to be more accurate than a human (who also can make a mistake!).

>machines are going to be more accurate

Says who? Also, what does "accurate" here actually mean?

Speaking as someone who actually understands computers and machines: I agree with the commons (who are simpletons with regards to computers and machines) that machines cannot be trusted to be "accurate" (whatever that means) or even trusted in general.

Especially when a simpler, confirmable-by-anyone method exists: Having someone count paper ballots by hand in the presence of anyone and everyone. That includes mistakes and errors. The value here is anyone and everyone can and will immediately understand (and thus accept) what is going on.

Also, why are we even putting the integrity of the very foundation of our democracy on the table in exchange for convenience and cost of all things? Are we serious? It should be a good thing we are taking precious time and money to make sure our democracy is working properly. I thought democracy was actually fucking important.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#330

Earlier quoted context omitted.

CO resident here. CO mails paper ballots to everyone* about a month before election day. You can choose to vote in person, or mail in/drop off your paper ballot anytime prior to election night. My understanding is what while the ballots are paper, many (all?) are tabulated digitally. It certainly appears to be laid out in a way that benefits digital reading, and i believe that is what the machines in question are res…

An interesting aside: I’m an overseas Colorado voter. They lump me in with the military voters so my voting process is super easy (I’m sure certain groups would love to make this harder, but not for the troops). I get an email that my ballot is ready, I go to the CO website, authenticate with my SSN (fucking yikes), fill out my ballot online, print a copy to pdf, slap a digital signature on there, and email it back t…

When you disregard basic voting security, everything becomes super easy. Mail-in voting allows for vote buying, the only way to avoid this is by having a private in person voting booth so the person voting cannot prove to the outside world who they voted for.

Even this isn't secure now, because everyone can just photograph their voting card within the booth.

Post reply on HN