Live data from Hacker News

Cylance Discloses Voting Machine Vulnerability

blog.cylance.com

41–50 of 127 posts

Re: Cylance Discloses Voting Machine Vulnerability

#41

Dear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot…

Exactly, more people counting is not a problem. It's actually a good thing. Why not get more people involved in the electoral process? It's beyond me why anyone would want to undermine this.

Plus, I don't get the mail in states. What's up with that? Why mess with a process that works?

Re: Cylance Discloses Voting Machine Vulnerability

#42
post #6

Earlier quoted context omitted.

But you're assuming that all the officicials dealing with the machines have the same moral standards as you. It's not necessarily the voters that need to be watched...

At least in Arapahoe County, everything we did was in pairs of republicans and democrats, to ensure that it was a fair election as far as we could. This included seal checking, logging the zero counts, etc. Everything had a paper audit trail for who interacted with what, who signed off on what, and what was going on. I don't know how it worked when the machines were picked up for counting, but I assume similar measur…

> everything we did was in pairs of republicans and democrats

Question: What constitutes a Democrat or a Republican? Is registering as one enough? What guarantee is there people aren't lying about the parties they identify with?

Re: Cylance Discloses Voting Machine Vulnerability

#44

I think it's high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility. Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I'd perhaps start at https://www.verifiedvoting.org/

They don't even need to throw the election. Two or three machines with absurd results in favor of Clinton or Trump would be enough to push the county into civil unrest.

Absurd results aren't what you want, since they're readily dismissed as localized, and people could believe that hacking had no effect on the overall result. You want to prove that hacking took place, but subtly, so that people can imagine it was widespread.

More effective would be to preselect a precise number of votes for a few machines in a swing state, with totals just 3-4 percentage points higher than what polling indicates for that precinct. Email a few journalists before the election: "I'm a engineer working to hack the election for Clinton, but I'm sickened by it and I want to blow the whistle... attached are encrypted tallies for the voting machines we compromised in precinct XXX. I know we have a team in YYY and I think in ZZZ, but I wasn't able to get data for those machines out. Decryption keys will follow Nov 15th."

Re: Cylance Discloses Voting Machine Vulnerability

#45

I think it's high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility. Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I'd perhaps start at https://www.verifiedvoting.org/

I bet you that's the main reason they don't want to open-source it for independent verification -- you would find code so dirty and hackable that you would wonder which state actors actually did NOT hack.

Re: Cylance Discloses Voting Machine Vulnerability

#46
post #6

Earlier quoted context omitted.

But you're assuming that all the officicials dealing with the machines have the same moral standards as you. It's not necessarily the voters that need to be watched...

At least in Arapahoe County, everything we did was in pairs of republicans and democrats, to ensure that it was a fair election as far as we could. This included seal checking, logging the zero counts, etc. Everything had a paper audit trail for who interacted with what, who signed off on what, and what was going on. I don't know how it worked when the machines were picked up for counting, but I assume similar measur…

Did third parties get representation?

Re: Cylance Discloses Voting Machine Vulnerability

#47
post #6

Earlier quoted context omitted.

At least in Arapahoe County, everything we did was in pairs of republicans and democrats, to ensure that it was a fair election as far as we could. This included seal checking, logging the zero counts, etc. Everything had a paper audit trail for who interacted with what, who signed off on what, and what was going on. I don't know how it worked when the machines were picked up for counting, but I assume similar measur…

> everything we did was in pairs of republicans and democrats Question: What constitutes a Democrat or a Republican? Is registering as one enough? What guarantee is there people aren't lying about the parties they identify with?

that's a risk you have to take, at some point. you eventually have to trust that someone isn't lying, somewhere along the chain.

what else could be done to further vet volunteers? you can't interrogate people or drug them with serums for the truth, so I think it's safe to assume registering is enough.

so, to answer your question, I doubt there is any "guarantee" other than the fact that these are volunteers and you'd have to be a real idiot to falsely register to ensure you can tilt the scales...of bipartisan pairs of Arapahoe County poll volunteers.

Re: Cylance Discloses Voting Machine Vulnerability

#48

I think it's high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility. Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I'd perhaps start at https://www.verifiedvoting.org/

Exactly this.

If stuxnet is possible, a voting machine should be a piece of cake.

Re: Cylance Discloses Voting Machine Vulnerability

#49
post #6

Earlier quoted context omitted.

At least in Arapahoe County, everything we did was in pairs of republicans and democrats, to ensure that it was a fair election as far as we could. This included seal checking, logging the zero counts, etc. Everything had a paper audit trail for who interacted with what, who signed off on what, and what was going on. I don't know how it worked when the machines were picked up for counting, but I assume similar measur…

> everything we did was in pairs of republicans and democrats Question: What constitutes a Democrat or a Republican? Is registering as one enough? What guarantee is there people aren't lying about the parties they identify with?

I don't know about the system in that particular county, but the system in most democracies is that any candidate has the right to appoint a representative to be present. In practice this means that the parties run down their lists of volunteers; depending on how many volunteers they have in a particular area it might be very easy for someone to get appointed as such. (In the last Canadian election, I turned up on election day to volunteer for a friend who was a candidate for a major party, and six hours later I was an Official Candidate Representative scrutinizing the vote counting.)

Re: Cylance Discloses Voting Machine Vulnerability

#50
post #47

Earlier quoted context omitted.

> everything we did was in pairs of republicans and democrats Question: What constitutes a Democrat or a Republican? Is registering as one enough? What guarantee is there people aren't lying about the parties they identify with?

that's a risk you have to take, at some point. you eventually have to trust that someone isn't lying, somewhere along the chain. what else could be done to further vet volunteers? you can't interrogate people or drug them with serums for the truth, so I think it's safe to assume registering is enough. so, to answer your question, I doubt there is any "guarantee" other than the fact that these are volunteers and you'd…

> that's a risk you have to take

Well, obviously. But the risk can be high or low, right? You could either let any random voter you don't know walk in and become a volunteer after filling out a form, or you could let maybe ~50 people that the party's head/nominee personally trust pick a set of volunteers nationally based on e.g. personal knowledge or some concrete evidences of their past contributions and allegiance to the party. Or something else; there are lots of possibilities here. So I'm asking what the criteria are so I can understand how likely it is for something to go wrong here... I obviously understand nothing 100% bulletproof, so there's no need to point that out.

Post reply on HN